LEGAL

Privacy Policy

Last updated: February 20, 2026

1) Who we are

This Privacy Policy describes how bukering.ai (“we”, “us”, “our”) collects, uses, discloses, and protects personal data when you access or use our website and platform (the “Services”).

Controller (Data Controller): bukering.ai
Address: Limassol, Cyprus
Email: admin@bunkering.ai

2) Scope

This policy applies to personal data processed through the Services, including account creation, quote/RFQ interactions, support requests, and communications. It does not cover third‑party websites or services linked from our Services, which have their own privacy policies.

3) Data we collect

Depending on how you use the Services, we may collect:

  • Identity & account data: name, role/title, company, username, password (hashed), user ID.
  • Contact data: email, phone number, business address.
  • Commercial & operational data: RFQs, offers/counteroffers, ports, products, vessel identifiers you submit (these may be business data, but can become personal data if linked to an individual).
  • Support content: messages, attachments you upload (e.g., PDFs), and any information you include.
  • Usage & device data: IP address, browser type, device identifiers, pages viewed, timestamps, approximate location (from IP), and diagnostic logs.
  • Cookie/analytics data: identifiers and events collected via cookies or similar technologies (see “Cookies”).

We do not intentionally collect special category data (e.g., health data). Please do not submit it.

4) How we use data

We use personal data to:

  • Provide and operate the Services (accounts, platform functionality, RFQs, dashboards).
  • Communicate with you (service messages, confirmations, updates, and support).
  • Improve performance, security, and user experience (analytics, debugging, fraud prevention).
  • Comply with legal obligations and enforce our terms.
  • Send marketing communications where permitted, and you can opt out at any time.

We may aggregate or de‑identify information for analytics and reporting; such data is no longer personal data when it cannot reasonably be re‑identified.

If you are in the EU/EEA/UK, we process personal data under one or more of these bases:

  • Contract: to provide the Services you request (e.g., account access, RFQ workflow).
  • Legitimate interests: to secure, improve, and operate our Services (balanced against your rights).
  • Consent: where required (e.g., non‑essential cookies, certain marketing).
  • Legal obligation: to comply with applicable laws, lawful requests, and recordkeeping requirements.

Where we rely on consent, you can withdraw it at any time (without affecting processing already performed).

6) Sharing & processors

We may share personal data with:

  • Service providers (processors): hosting, cloud infrastructure, email delivery, analytics, error monitoring, customer support tools, and security services.
  • Business partners: only as needed to deliver a requested service (e.g., facilitating RFQ workflows), and subject to confidentiality where appropriate.
  • Legal/Compliance: if required by law, court order, or to protect rights, safety, and security.
  • Corporate events: in connection with a merger, acquisition, financing, or sale of assets (with appropriate safeguards).

We do not sell personal data. If you use third‑party integrations, their processing is governed by their policies.

7) International transfers

Your data may be processed outside your country. Where EU/EEA personal data is transferred to countries without an adequacy decision, we use appropriate safeguards such as the EU Standard Contractual Clauses (SCCs) and additional measures where required.

8) Retention

We keep personal data only as long as necessary for the purposes described above, including:

  • While your account is active (and for a reasonable period after to support the service and compliance needs).
  • As needed for dispute resolution, security investigations, and legal obligations.
  • Backups are retained for limited periods and securely deleted/overwritten on rotation.

You may request deletion as described in “Your rights”, subject to legal exceptions.

9) Security

We implement technical and organizational measures designed to protect personal data (access controls, encryption in transit where feasible, logging/monitoring, and least‑privilege practices). No method of transmission or storage is 100% secure, but we work to protect your data with industry‑standard practices.

10) Cookies & similar technologies (EU ePrivacy + global)

We use cookies and similar technologies for:

  • Strictly necessary (authentication, session management, security).
  • Preferences (language, UI settings).
  • Analytics (understanding usage to improve the Services).
  • Marketing (where used and permitted).

In the EU/EEA and UK, non‑essential cookies should be set only after you provide consent, and you can withdraw consent at any time. You can also control cookies via your browser settings; however, disabling strictly necessary cookies may affect functionality.

11) Your rights

EU/EEA (GDPR) / UK GDPR: You may have the right to access, rectify, erase, restrict processing, object, and receive a portable copy of your data, and rights related to automated decision‑making/profiling. You also have the right to lodge a complaint with a supervisory authority.

Other regions: Depending on where you live, you may have similar rights (e.g., to access, delete, correct, and opt out of certain uses). We will respond as required by applicable law.

To exercise rights, contact us at admin@bunkering.ai. We may need to verify your identity before fulfilling requests.

Marketing preferences

You can opt out of marketing emails at any time using the “unsubscribe” link or by contacting us. Service/transactional messages (e.g., security alerts, account notices) may still be sent.

12) Children

The Services are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided personal data, contact us so we can take appropriate steps.

13) Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated version on this page and update the “Last updated” date. Material changes may be communicated via the Services or email where required.

14) Contact

For privacy questions or requests:
bukering.ai
Email: admin@bunkering.ai
Address: Limassol, Cyprus