Columbia Cruise Services GmbH & Co. KG and its affiliates (referred to as “we”, “our”, or “CCS”) recognise and respect the rights and privacy of individuals. This includes our applicants, current and former employees, suppliers, passengers on board the vessels we manage, and customers.
This Notice explains what we do with your personal data, whether we are considering your application for employment, continuing our relationship with you, providing you with a service, receiving a service from you, or if you are visiting our premises or our website.
It describes how we collect, handle, and process your personal data, and how, in doing so, we comply with our legal obligations. We consider privacy to be important and we are committed to protecting and safeguarding your personal data privacy rights. The use of the word “processing” in this Notice is intended to include such actions as collecting, handling, using, storing and protecting your personal data.
This Notice applies to the personal data of Data Subjects such as yourself, our Employees (on board and ashore), Crew members, Customers, Visitors, Suppliers of goods and services, Website Users, and others whom we may contact in order to collect more information about our Employees or those whom they have indicated as an Emergency contact.
If you are an Employee or Seafarer, you should also refer to the company Data Protection Policy , with which we have already provided you.
This Notice is written to comply with the applicable data protection legislation which includes, but is not limited to, the European Union General Data Protection Regulation (GDPR).
The company responsible for your personal Data (Data Controller)
Phone: ++49 40 36 13 04 – 0
Address: Grosse Elbstrasse 275 D-22767 Hamburg, Germany
For passengers, your cruise operators are also separately considered a “data controller” under European Union and UK data protection law. You can access the privacy policies of your cruise operator via their own websites.
Data Protection Officer
Name: Mr Andreas Andreou
Phone: +357 25843100
Address: Columbia House, 21 Spyrou Kyprianou Avenue, 4042 Limassol, Cyprus
How do we use personal data?
We may process personal data as part of our shipmanagement services. Such processing may include, but is not limited to, passengers’ and crew manifest, employment contracts, anti-money-laundering, risk management, claims handling, document processing, marketing, procurement, and newbuilding supervision.
What personal data do we collect?
Crew members and Employees (on board and ashore):
In order to consider you for employment, or employ you, we need to process certain information about you. We only ask for or collect details that help us provide what is required as part of your application process or employment. For example, we need information such as your name, age, contact details, education details, employment history, emergency contacts, next of kin, immigration status, passport size photos, passport copies, overalls size, bank account details, utility bills and other relevant information required for the purposes of your employment or that you may choose to share with us. Where appropriate, and in accordance with local laws and requirements, we may also collect information of a more sensitive nature, such as diversity information, information related to your health, union membership or details of any criminal convictions.
We use processors who are third parties who provide elements of services for us. We have contracts in place with our processors. This means they cannot do anything with your personal data unless we have instructed them to do it. They will not share your personal data with any organisation apart from us. They shall keep it securely, for the period we instruct.
For certain seafarers, for handling job applications, we shall use a third-party provider tool. This tool will be utilised by us to improve recruitment experience, efficiency and productivity.
Where such processing occurs, relevant privacy information shall be provided at the point of collection of personal data.
To enable shore employees to conduct our business, they have been provided with access to one another’s contact information including name, position, telephone number, work address, work e-mail address, and photograph (should you choose to provide one).
Employees should be aware that photographs and videos are taken on our premises and during events we and our legal representatives and assigns and those acting with our authority and permission organise; selections of such material may be used for company marketing purposes (for example on our website or in promotional leaflets or posters) and their image or parts of their image may appear in the material or the background of said material.
Training and maintaining proficient and qualified employees is of great importance to us and as such, various training regimes and campaigns are in place both on-board and ashore. To this end we use several training systems provided and maintained by third-party providers. These may also include automated survey service suppliers, for feedback purposes not only to improve training but other aspects of employment such as our management system or work practices.
Insurance plays an important role in our operations and is prominent in relation to the vessels we manage and the Office. We undertake claims handling for a large number of vessels which includes individual seafarer and passenger illness and injury, protection and indemnity claims involving cargo, shippers, and receivers, and hull and machinery claims involving the structure of the vessel. Similarly, we undertake claims handling for Employees who are insured under the Company policies. In all these claims, and particularly with medical claims, we process personal data which may be provided to the relevant insurer.
We operate an open reporting policy. In the interests of maintaining confidentiality and impartiality the open reporting platform and service is provided by a third party provider
For security and safety purposes when you board the vessels we manage and to meet certain legal and regulatory requirements which apply to us, we collect the Passengers’ manifest of the vessels we manage which includes information such as passengers’ booking number, full name, cabin number, birth date, passport number, passport date, passport expiration date, embarkation date.
To enable us to communicate with you and to ensure that we meet certain legal requirements such as KYC (know your customer) and AML (anti-money-laundering), we need to have certain details of yours or details of individual contacts at your organisation (such as their names, telephone numbers and e-mail addresses).
We ensure that our marketing communications to you are relevant and timely.
We collect a limited amount of personal data in order to improve your experience when using our website.
This includes information such as the frequency with which you access our website, and the times that our website is most popular.
Each social media channel has their own policy on the way they process your personal data when you access their sites. If you have any concerns or questions about their use of your personal data, you should read their privacy policies carefully before using them.
We utilise the below social media channels:
LinkedIn: Their privacy notice can be found here : www.linkedin.com/legal/privacy-policy
Instagram: Their privacy notice can be found here : www.help.instagram.com/519522125107875
Photos and Videos posted on our Website and Social Media Accounts.
Where you voluntarily provide us with photos and videos of you, together with any comments for marketing and social media engagement purposes. We will use such photos, videos, and comments on our social media accounts and our website for marketing and social media engagement purposes only.
The legal basis we rely on to process your personal data is article 6(1)(f) of the GDPR. This allows us to process personal data when it is necessary for the purposes of our marketing and social media engagement legitimate interests.
The only recipients will be our website hosting provider and the social media channels listed in the Social Media section of this privacy notice, who are all in EEA countries.
We will store the photos and videos to enable us to upload them to our social media accounts and website.
We will keep them as long as we maintain our social media account and website .
When we receive such content from you, to post on our website or social media accounts. We will ask you if you would like us to refrain from mentioning your names in the post.
Where your photos or videos show other persons than yourself posing, who are not captured incidentally or are the focus of the photo or video. We will ask you to provide the necessary information to them.
Where we receive photos or videos of you from other persons than yourself. Where you are not captured incidentally or are the focus of the photo or video. We will always ask the person sending the photos or videos to us, to provide the necessary information to you.
Suppliers of goods and services
We collect a small amount of information from our Suppliers to ensure that operations work properly. We need contact details of relevant individuals at your organisation so that we can communicate with you. We also need other information such as your bank details so that we can pay for the services you provide (if this is part of the contractual arrangements between us).
As part of due diligence and in order to protect the vital interests of our Data Subjects, we will under certain circumstances collect emergency contact details.
When visiting our premises, we collect the necessary personal data required for security and notification purposes. For security purposes, we also operate a Closed Circuit Television system (CCTV). The CCTV cameras only operate in common areas of our premises and are positioned so as not to intrude on privacy. The footage is kept for no longer than a month and access is strictly regulated.
Processing relating to endemic infectious diseases
We must protect our seafarers and passengers on the ships we manage and our employees on our premises ashore from endemic infectious diseases. In the event of an outbreak, we shall take steps to control entry to our offices and ships under our management. Such steps will be in line with local authority requirements and guidelines.
Where it is necessary and proportionate to do so, before you enter our premises or board any ship, we shall ask you certain screening questions on your recent exposure to any such disease. We shall also check your temperature. We shall use this personal data concerning health to decide whether to allow you to enter our premises or board any ship.
You can refuse to answer such questions or have your temperature taken. In such cases, we can refuse entry to you on our premises or board any ship.
We have a legal obligation to protect our seafarers and employees from such health risks. It is also in the interest of other people who are at risk of becoming infected.
The legal bases we use for lawful processing
In order to conduct business and fulfil our legal, regulatory, and contractual obligations, we need to perform legitimate and fundamental processing activities. These are:
- Establishing contracts
- Maintaining contracts
- Provision of all contracted services
- Invoicing: remittance, payments, and collections
- Non-promotional communications
- Marketing and other promotional communications
- Risk management contract review
- Response to Subject Requests
- Performance measurement
- IT and telecommunication support services
- Business Continuity and Contingency Planning
- Legal and regulatory obligations
- Responding to enquiries, requests, and complaints
- Employment processing
- Workforce planning
- Training and certifications
- Emergency communications
- Interacting with other organisations, industry groups, and professional associations
- Internal ethics reporting, security, and investigations
Who will access or receive the personal data?
We need to share the personal information we process with individuals themselves and also with other organisations. The list below contains a description of the types of organisations with which we may need to share some of the personal information we process.
- Agents and brokers
- Business associates, other professional bodies, and advisers
- Central and local government
- Claimants, beneficiaries, assignees, and payees
- Claims investigators
- Complainants, and enquirers
- Courts and tribunals
- Credit reference, debt collection, and tracing agencies
- Current, past, and prospective employers
- Debt collection and tracing agencies
- Education and examining bodies
- Employment and recruitment agencies
- Family, associates, and representatives of the person whose personal data we are processing
- Financial organisations and advisers
- Healthcare professionals, social and welfare organisations
- Insurance providers
- Law enforcement and prosecuting authorities
- Learning management system providers
- Ombudsman and other regulatory authorities
- Open reporting system providers
- Other affiliated companies
- Pension schemes
- Police forces
- Private investigators
- Professional advisers
- Share Administrators
- Suppliers and services providers
- Survey and research organisations
- Training system and software providers
- Unions, trade associations, professional bodies, and employer associations
The countries where personal data will be stored, processed and/or transferred
Your personal data we collect may be stored and processed in the EU or any other country in which we or associated third parties maintain facilities. In case we need to transfer your personal data, we will take all reasonable measures to safeguard the transfer of your personal data to third parties in a manner that complies with the applicable data protection laws.
How long will the personal data be retained?
Retention of specific records may be necessary for one or more of the following reasons:
1. Fulfilling statutory or other regulatory requirements
2. Evidencing events/agreements in case of disputes
3. Operational needs
4. Historical and statistical purposes
Where we collect personal data for which we subsequently have no use for any business purpose we will then review and may destroy such personal data at our discretion.
The right to withdraw consent
In situations where we request and receive your consent to perform processing, we are also obliged to stop such processing if you decide to withdraw your consent. Withdrawing consent is as straightforward as giving consent. Withdrawing consent cannot be back-dated so it has no effect on processing already performed during the period of consent.
The right to access, change, delete, restrict, object, request a copy
Under certain circumstances you have rights regarding your personal data. These are:
1. Access to a copy of your personal data
2. Object to processing that you object to
3. Stop receiving direct marketing material
4. Object to decisions being taken by automated means
5. Have inaccurate personal data rectified, blocked, erased or destroyed
6. Lodge a complaint with the relevant data protection authority
7. Claim compensation for damages caused by a breach of the GDPR
If you are an employee, and wish to exercise any of these rights, please follow the relevant Company procedure. If you are not an employee, please contact CCS directly.
What happens if the personal data is not collected?
Your personal data is required for communication and setting up a contractual agreement to provide employment, products, and services. Without this data we will not be able to communicate with you or enter into a contractual agreement with you. This includes both business and employment contracts.
We need personal data to:
1. Enable consensual bilateral communications
2. Engage in pre-contractual activities
3. Honour contractual obligations
4. Be able to employ people
Without this personal data, we will not be able to perform these primary activities.
Automated decision making
We do not use automated decision making.
A cookie is a small file placed onto internet enabled devices in order to recognise a device upon recurring visits, and in turn enable a website’s features and functionalities. They are widely used in order to make websites work, or work more efficiently, as well as to provide information to the owners of the site.
Cookies may transmit information via a device’s browser with a purpose of authentication or identification via the IP address. For example, cookies enable us to identify a device, secure access to our websites, and keep track of web browsing preferences.
Cookies may also be used for recognising you as the user when you visit our website, remembering your preferences, and overall giving you a more personalised experience that’s in line with your settings.
Essentially there are two types of cookies:
- persistent cookies, and
- session cookies
A persistent cookie helps the website (and third party applications) to recognise you as an existing user, so it is easier to return and continue your existing user experience.
Session cookies are temporary cookies that remain on your device until you leave the website.
Our websites only utilise persistent cookies when any browser loads the site, essentially for keeping track and observing website visitor trends and statistics. This is applicable to various internet enabled devices, e.g. PC’s, smartphones and tablets.
Cookies may also be placed in your browser when visiting our website via third party application plugins or when using third party modules on the website. This applies when using social media “sharing” tools via third party application plugins. We do not, however, have access to details regarding your social media or personal data during this process. We can only see which pages of our website have been shared collectively over social media and how many times.
The table below demonstrates the cookies that we use and explains why we use them.
|_ga||Used to distinguish users.|
|_gid||Used to distinguish users.|
|_gat||Used to throttle request rate.|
|__utmt||Used to throttle request rate.|
|__utmc||Not used in ga.js. Set for interoperability with urchin.js. Historically, this cookie operated in conjunction with the __utmb cookie to determine whether the user was in a new session/visit.|
Controlling Cookies on your Device
Cookies on an Internet device help make the user experience of our websites better.
Most internet browsers are initially set up to automatically accept cookies. You can change the settings to block cookies or to alert you when cookies are being sent to your device, as well as delete them.
There are a number of ways to manage cookies. Please refer to your specific browser instructions or help screen to learn more about how to adjust or modify your cookie browser settings. If you use different devices to view and access this website (e.g. PC, smartphone, tablet, Smart TV) you will need to ensure that each browser on each device is adjusted to suit your cookie preferences accordingly.
For further information on Cookies, such as deleting, disabling or blocking cookies, please visit AboutCookies.org
For more specific information on how to adjust cookie configurations, please refer to your specific browser.
Changes to our Notice
Any changes we make to our Notice in the future will be posted on this page. Please check back frequently to stay informed of any updates or changes.
Where we intend to further process your personal data for a purpose other than that for which the personal data were collected, we shall provide you, prior to that further processing, with information on that other purpose and with any relevant further information.