Privacy Policy – STCW.online™
1. Who are we?
STCW online is a trade name of Emergency Control Maritime Training B.V. (ECMT). ECMT is the legal entity responsible for protecting your privacy. We care deeply about your privacy, because it is vital to protect everyone’s personal and professional safety in the digital age. The protection and security of personal data that we process is of paramount importance to us and, as an EU-based company, we have developed specific controls and protocols for any breaches relating to the GDPR and data protection laws. Our privacy strategy is to meet and exceed GDPR requirements.
2. Applies to
This Policy applies to the website www.stcw.online, the learning platform (“LMS”) www.stcw.academy and the app (“App”) for sharing content with the learner on mobile devices. The app’s communication functionality enables ECMT to collect data of learner’s (“User”) progress, including testing results (if any).
ECMT acts as the data controller and processor of personal information when you register with us or use the App to register information. This Privacy Policy applies to all interactions using the STCW online™ App and STCW.online websites, which are owned by Emergency Control Maritime Training BV, either directly, or through its partners, affiliates and re-sellers, together named as ‘we’.
Please read the policy carefully and contact us with any questions or concerns about our privacy practices. We might amend this Privacy Policy from time to time. Visit our web page (www.stcw.online) regularly in order to understand what we do. If we make changes which are relevant to your consent and underlying information, we will always notify you before you use our service.
THIS PRIVACY POLICY APPLIES TO BOTH END USERS/PARTNERS AND THEIR CLIENTS (INDIVIDUALS). END USERS OF THE LMS MUST CONSENT TO THE RETENTION OF THEIR PERSONAL DATA. INDIVIDUAL CLIENTS (LEARNERS TAKING COURSES) HAVE THE RIGHT TO REQUEST ERASURE OF THEIR PERSONAL DATA, WHERE APPLICABLE, INCLUDING WHERE RETENTION IS NOT REQUIRED BY LAW OR NECESSARY TO MEET APPLICABLE CERTIFICATION REQUIREMENTS.
IF YOU OR ANY OF YOUR CLIENTS WHOSE DATA IS PROCESSED DO NOT AGREE WITH OUR PROCESSING OF PERSONAL DATA AS DESCRIBED IN THIS PRIVACY POLICY, YOU CANNOT CONTINUE THE USE OF OUR SERVICES. IF YOU AGREE WITH OUR PRIVACY POLICY, WE HEREBY WELCOME YOU TO OUR SERVICE.
3. What information do we collect?
In order to enable on- and offline learning, we provide secure access to the LMS. The LMS collects minimal required personal data and information of the user to enable making a secure connection and to provide end-users with a certificate of proficiency (CoP) where applicable. Read below in more detail which data is used and exchanged.
When Clients want to use our paid services, they also have to provide us with payment information.
We do not have access to or keep this payment information.
We collect information when you give us feedback via our website, LMS or your App Store or a questionnaire or via the support web form on www.stcw.online. During your visit to our Website, LMS or use of the App, we automatically collect certain information about you, your visit to the service and the device you are using. The information we store includes notification access, device-specific settings and characteristics, system activity, location details, IP address, language settings and other device event information, access dates and times of your usage of the LMS. We also collect data about when and how you use the service.
4. How will the information be used?
We use your data to assist you in the best possible way. It may be used for the following reasons:
Training journey: The main reason why we collect your personal data is to supply you with our core service: assistance with your training journey.
Management and improvement of our Services: We use your information to manage our Website, App, and business and to improve our services continuously.
Marketing and Customer Service: our customer service is here to help you and we use your data to do so. We may send you email notifications and/or in-App messages, this includes emails in which we provide you with information and ask you to provide us with information about possible follow-up actions. In order to keep you informed, we may send you communications relating to our business, by email or other contact details you provided to us. If you submit personal information for publication on our Website, we will use that information in accordance with the license you grant to us.
If you opt-in for our mailing list, we may send you non-commercial communications, including our newsletter. When you use our services, we may send you a questionnaire or invite you to provide a review of your experiences with our service. We also may get in touch with you regarding feedback, inquiries, and complaints you made regarding our Website and App. We might ask you to rate us or leave information and comments on if and how we met your expectations.
Research activities: In order to support the research in remote learning, we may use your data, pseudonymized (without a direct link to your identity) or anonymized (without us being able to identify you at all), for research purposes. This may include sharing your data with carefully selected third party learning institutions. By uploading your information, including images in the App, you explicitly consent to the images being processed for the purposes of the provision of the services and to be used anonymously for the purposes of research and testing of our services. As such, your images may be reviewed by our employees or third-party consultants who work for us and who are bound by strict confidentiality.
Legal purposes: In certain cases, we may need to use your information to handle and resolve legal disputes, for regulatory investigations and compliance, or to enforce the terms of use of the service as reasonably expected. We have to comply with certain laws and (country-specific) regulations.
Contractual necessity: In order to fulfil the contract you enter into with us when you use our Services, we have to process some essential information. When you wish to use one of our paid services we may need to process your email address and payment information.
Legitimate interests: We are committed to improving and growing our service. Some of your data can help us to improve and promote our Service and Website, other data we may need for administrative, legal purposes or anti-fraud activities.
Where processing is based on your consent, you may withdraw your consent at any time by contacting us via the support web form on www.stcw.online. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal and does not affect processing based on another lawful basis.
5. Data minimization
ECMT shall ensure that personal data are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed. The detailed data fields are described below:
- the client user – who is a user of the application –
- Personal data (email address, user id, password, company, first and last name, telephone number)
- the learner user – who is a user of the application –
- Personal data (email address, user id, password, first and last name, date of birth, country and place of birth)
- the journey
- Regular personal data (learners progress, results and certification).
All data mentioned is essential from ECMT’s perspective. The data collected is required for normal operation of the service and to issue the client (user) with a valid CoP as required by the (IMO) Member States.
6. What legal basis do we have for processing your personal data?
All data processed by ECMT must be processed on one of the following lawful bases: consent, contract, legal obligation, vital interests, public task or legitimate interests. Where consent is relied upon as a lawful basis for processing data, evidence of opt-in consent shall be kept with the personal data.
Our service can only be used when you as the end user have reached the age of sixteen (16) years or when you are older.
The application cannot deliver its full intended value without capturing the data. Access to client or learner data is regulated in such a way that the smallest possible group of persons gains access to both the client’s identity and, simultaneously, learners user data.
7. When do we share personal data?
Personal data is shared when there is information captured in a case before / during / after communication between ECMT and the user.
8. With whom do we share personal data?
ECMT has third party service providers that help us provide or improve our service. This includes service providers, payment providers and financial institutions, business partners or research institutions. Read below in more detail how your data is used and exchanged.
9. Where do we store and process personal data?
All data you provide to us and we collect from you is stored on secure cloud servers (the Servers) in the territory of the European Union. If personal data is transferred outside the European Economic Area, ECMT will ensure that an appropriate transfer mechanism and safeguards are in place as required by applicable data protection law.
Personal information may also be processed by our staff or by third-party service providers operating outside your country who work for us. Where such processing involves the transfer of personal data outside the European Economic Area, ECMT will ensure that an appropriate transfer mechanism and safeguards are in place as required by applicable data protection law. We take such steps as are necessary to ensure that third-party service providers treat your data securely and in accordance with applicable laws.
10. How do we secure personal data?
We have implemented a variety of security measures to maintain the safety of your personal information when you place an order or enter, submit, or access your personal information.
Whenever feasible and possible individual information will be encrypted, anonymized and aggregated to the level that allows practical use of the information.
To restrict access to personal information:
- We provide Secure Access Management (User id / Passwords) for the LMS.
- We use data encryption embedded in a secure HTTPs communication protocol between the mobile app and the database on the server.
- We use a secure database server. All supplied sensitive information is encrypted in the database. To protect data against accidental loss and to ensure business continuity and disaster recovery The database will have regular backup and recovery testing.
- ECMT shall ensure that personal data is stored securely using modern software that is kept-up-to-date.
- Access to personal data shall be limited to personnel who need access and appropriate security should be in place to avoid unauthorised sharing of information.
- When personal data is deleted this should be done safely such that the data is irrecoverable.
- Appropriate back-up and disaster recovery solutions shall be in place.
11. How long do we keep your personal data for?
We will retain your personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required by law or is necessary to establish, exercise or defend legal claims.
Personal data is retained only for as long as necessary for the purposes for which it is processed, unless a longer retention period is required by applicable legislation, maritime administration requirements, flag State requirements, certification requirements or contractual obligations.
STCW training and certification records: Personal data and records forming part of the STCW training, assessment, certification and verification records are retained for 50 years, in accordance with applicable national maritime requirements and ECMT’s certified quality management system.
Disposal of data means permanent deletion from the database.
If you terminate the Services and delete your account, we will retain your personal information for a period of 12 months, after which we will delete your data. We will ask for your consent to process your data anonymously for research purposes.
We will retain (electronic) documents containing personal information:
- to the extent that we are required to do so by law;
- if we believe that the documents may be relevant to any ongoing or prospective legal proceedings; and
- in order to establish, exercise or defend our legal rights (including providing information to others for the purposes of fraud prevention and reducing credit risk).
12. Breach
In the event of a personal data breach, ECMT will assess the risks to the rights and freedoms of affected individuals and take appropriate measures in accordance with applicable data protection law.
Where notification to the competent supervisory authority is required, ECMT shall notify the supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach. ECMT will also notify affected individuals where required by applicable data protection law.
13. Your rights in relation to personal data
This refers to access to personal information, correction, erasure, restriction of processing, data portability, objection and withdrawal of consent. Individuals involved in an incident can request for a report with their personal information.
At any time, you can make a request to review, correct, erase or obtain your personal data. You are also entitled to withdraw consent for the processing of the personal data we hold of you. You can do this by mail or email, using the addresses listed below.
Individuals can submit a request for erasure of their personal data, where applicable and subject to any legal or other applicable retention requirements. This also applies to the withdrawal of consent.
We will respond to your request without undue delay and, in any event, within one month of receiving your request. Where necessary, this period may be extended by up to two further months. We will inform you of any such extension within one month. Requests relating to your data protection rights are generally free of charge. Where a request is manifestly unfounded or excessive, we may charge a reasonable administrative fee or refuse to act on the request, where permitted by applicable law.
You are also entitled to lodge a complaint with the appropriate supervisory authority, depending on the country you are using our services from.
14. Compliant to law and regulations
Privacy laws and regulations vary throughout the world. Our policy is based on EU privacy laws (GDPR).
If this policy for any reason does not meet specific requirements from other governing bodies or local laws, do not use our solutions and please inform us accordingly. Void where prohibited by law.
15. Your Consent
We ask the user explicitly to accept our privacy policy in the LMS and App.
If for any reason you do not accept this policy, do not use our solutions.
16. Contact
The Websites and the Application are owned and operated by ECMT B.V., Rotterdam, The Netherlands. You can contact us by writing to ECMT, P.O. Box 59008, 3008 PA, Rotterdam or by using our Website contact form or by email to [email protected].
Privacy Contact: C. Verhoeven
Version September, 2026