My Offshore App

Privacy Policy

My Offshore App Ltd · Company no. 17335504 · ICO registration ZC201856 · Last updated 27 August 2026

1. Who we are

MyOffshoreApp respects your privacy and is committed to protecting your personal data. MyOffshoreApp (referred to as “MyOffshoreApp Ltd”, “we”, “us” or “our”) is operated by MyOffshoreApp Ltd, a company registered in England and Wales (company no. 17335504) with registered office at Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF. We are the data controller for the personal data described in this privacy policy.

We are registered with the Information Commissioner's Office (“ICO”) (or Information Commission as it will be known following Part 6 of the Data (Use and Access) Act 2025 (DUAA)) under registration number ZC201856. Our data protection lead can be contacted by email: [email protected].

2. Scope

This privacy policy aims to give you information on how we collect and process your personal data when you use the MyOffshoreApp mobile application and/or our website (collectively referred to as the “Platform”). It explains what personal data we process, why, our lawful bases, who we share it with and your data protection rights. The Platform is intended for users aged 18 or over who are legally entitled to work in the UK (which may include EEA residents). It is not directed at children.

Our Platform may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share personal data about you. We do not control these third-party websites and are not responsible for their privacy policies and statements. When you leave our Platform, we encourage you to read the privacy policy and statements of every website you visit.

3. The personal data we collect

Personal data, or personal information, means any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:

Category Examples
Account & identity First name, surname, email address, phone number, date of birth, password credentials, home location / postcode, scheme ID, subscription status, trade and role information.
Certificates & training Certificate name, issuing body, certificate/scheme number (e.g. WINDA ID, OPITO Vantage number, IRATA number), issue and expiry dates, training provider and any document you upload as evidence of your qualifications, training and experience.
Health-related data (special category) The existence and validity/expiry of occupational medical certificates (e.g. OGUK) — see section 6 for further information.
Availability & preferences Your “available for work” status, emergency-deployment status, preferred training centre and any preferred day/hour rate you choose to publish.
Bookings Training courses that you request or book onto through the Platform and the associated training centre.
Communications Messages sent through our in-app messaging and correspondence with support.
Technical & usage Internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
Payment-related data Limited transaction references. We do not store card details. Course payments are taken by the training centre directly and card processing is handled by our payment providers.

We also collect, use and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate individuals’ use of our Platform to calculate the percentage of users accessing a specific Platform feature in order to analyse general trends in how users are interacting with our website to help improve the website and our service offering. However, if we combine or connect aggregated data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this privacy policy.

We do not collect any information about criminal convictions and offences.

4. How we collect your personal data

5. Why we use your personal data and our lawful bases for processing it

We will only use your personal data when the UK data protection legislation allows us to. Most commonly, we will use your personal data in the following circumstances:

We have set out below, in a table format, a description of all the ways we plan to use your personal data, and which of the lawful basis or bases we rely on to do so. We have also identified what our legitimate interests are where appropriate.

Purpose Data used Lawful basis (UK GDPR)
To register you as a new customer and create and run your account and certificate wallet. Account & identity, certificates and training, availability and preferences, technical & usage and payment-related data (if purchased the premium version of the Platform) Performance of a contract with you.

To process and deliver your ordering including:

  • managing payments, fees and charges; and/or

  • collect and recover money owed to us.

Account & identity, payment-related data.

Necessary to comply with a legal obligation.

Performance of a contract with you.

Necessary for our legitimate interests (to recover debts due to us).

To manage our relationship with you which will include:

  • notifying you about changes to our terms or privacy policy; and/or

  • asking you to leave a review or take a survey.

Account & identity

Necessary to comply with a legal obligation.

Performance of a contract with you.

Necessary for our legitimate interests (to keep our records updated and to study how customers use our products and services.)

Consent.

To send expiry reminders and let you book onto training session renewals. Account & identity, certificates and training and communications.

Necessary for our legitimate interests (to introduce you to relevant training centre providers and support you in maintaining your compliance with applicable legislative and regulatory requirements).

Consent.

To make your profile visible to recruiters. Account & identity, certificates and training, health-related data and availability and preferences

Necessary for our legitimate interests (to ensure your profile is seen by recruiters looking to assist employers wanting to employ staff in your industry).

Consent and explicit consent.

To process and share booking details with your chosen training centre. Account & identity and bookings Necessary for our legitimate interests (to introduce you to relevant training centre providers and enable you to book onto training courses using a centralised Platform).
To verify your certificates. Account & identity and certificates and training

Necessary for our legitimate interests (to ensure your training status has been verified using industry-bespoke databases).

Consent

To administer, operate and protect our business, our staff, others and our Platform (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data). Account & identity, certificates and training, health-related data, availability and preferences, bookings, communications, technical & usage and payment-related data

Necessary to comply with a legal obligation.

Necessary for a recognised legitimate interest ((the national security, public security and defence, safeguarding, public task disclosure request, emergencies and crime conditions).

Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security, to prevent fraud and in the context of a business sale/disposal, acquisition, reorganisation or group restructuring exercise).

To use data analytics to improve our Platform, products/services, marketing, customer relationships and experiences. Account & identity, certificates and training, health-related data, availability and preferences, bookings, communications, technical & usage and payment-related data

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy).

Consent.

Where we rely on consent, you can withdraw it at any time (see section 11). Withdrawal does not affect any processing of personal data carried out before the withdrawal of consent. Where we rely on legitimate interests as a lawful basis for processing, we have balanced those interests against your rights and you may object (section 11).

Where we need to collect personal data by law, or under the terms of a contract we have with you, and you fail to provide that personal data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with our products or services). In this case, we may have to cancel a product or service you have with us but we will notify you if this is the case at the time.

Typically, we will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. On the basis that we make an assumption of compatibility, in accordance with the DUAA, we will not complete a compatibility test. However, if we are unsure whether the new purpose is compatible with the original purpose, we will complete a compatibility test before processing your personal data for the new purpose.

In circumstances where we need to use your personal data for an unrelated purpose, we will notify you and we will explain the legal basis which allows us to do so.

We are not required to inform you where we intend to use your personal data for research, archiving in the public interest, or generating statistics if it would involve a disproportionate effort for us to do so. We strongly recommend that you routinely check our privacy policy for any changes concerning how we collect and process your personal data.

Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

6. Health-related (special category) data

Occupational medical certificates are considered health data and the UK data protection legislation places a higher expectation on organisations to protect this information.. We will only process your occupational medical certificates with your separate, explicit consent. You can withdraw this consent at any time and, on the basis of withdrawing it, we will stop processing your occupational medical certificates.

7. Who we share your personal data with

We may share your personal data with the parties set out below for the purposes set out in the table under above:

We require all third parties to respect the security of your personal data and to treat it in accordance with the UK data protection legislation. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your personal data for specified purposes and in accordance with our instructions.

We do not sell your personal data, and we do not share it with recruiters or centres for their own marketing without your separate consent.

8. International data transfers

UK first. We are launching in the United Kingdom, and during this UK phase, all personal data (including personal data pertaining to EU and EEA residents) is hosted and processed in the UK (AWS London) and does not leave the UK. For the purpose of processing EU and EEA resident personal data, we will comply with both the UK GDPR and the EU GDPR.

Our plan. We intend to prove the model in the UK and then expand — to the EU, then the USA, Asia and Australia. As we expand, we will operate a data-residency-by-region model whereby your personal data will be stored in the region that matches your country of residence and is governed by that region's data protection law (for example, EU residents' personal data will be held in an EU region and will be governed by the EU GDPR). Your data residency follows you as an individual, not the location where you happen to work.

Before we process personal data in any new region, we will update this privacy policy, provide region-specific privacy terms where needed, appoint a representative where one is required (for example an EU representative under Article 27 of the EU GDPR), and put appropriate safeguards in place. For example:

9. How long we keep your personal data

We will only retain your personal data for as long as reasonably necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting or reporting requirements. We may retain your personal data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you. To determine the appropriate retention period for personal data, we consider the amount, nature and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal, regulatory, tax, accounting or other requirements.

By law we have to keep basic information about our customers for six years after they cease being customers for tax purposes.

10. How we protect it

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

11. Your data protection rights

Under the UK data protection legislation, you have the right to:

You can exercise most rights in the Platform (view, export, correct, delete, and manage your consents and availability) or contact us using the details in section 14 below. We will aim to respond within one month.

It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new postal address or phone number.

12. Cookies and similar technologies

Our Platform use cookies and mobile software development kit (SDKs). Please refer to our Cookie & Tracking Technologies Policy [here] for detail and your choices.

13. Changes to this privacy policy

We may update this privacy policy from time to time. We will post the updated version with a new “last updated” date and, for material changes, notify you in the Platform.

This version of the privacy policy was last updated on 27 August 2026.

14. Contact us and complaints

If you have any questions concerning this privacy policy, please contact us at [email protected] or Collingwood Buildings, 38 Collingwood Street, Newcastle upon Tyne, NE1 1JF.

You have the right to make a complaint to us regarding our processing of your personal data. In the event you are not happy with the outcome of the complaint, you have the right to make a complaint to the ICO, the UK regulator for data protection issues (http://www.ico.org.uk/). Please note that from 19 June 2026, in accordance with the DUAA, before you can submit a complaint to the ICO, you must submit a complaint to us first.