Privacy Policy

Privacy Notice

Last updated: 24/09/2025

This Privacy Notice explains how personal data are collected, used, and protected within the Learning Management System (LMS) used by employees of WORLD MARINE SERVICES CY LTD, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR).


1. Data Controller

The Data Controller responsible for the processing of your personal data is:

WORLD MARINE SERVICES CY LTD
(your employer)

The Data Controller determines the purposes and means of processing your personal data within the LMS.


2. Data Processor

The LMS platform is technically supported and maintained by:

Synaptica2 Solutions SINGLE MEMBER P.C.

Synaptica2 Solutions SINGLE MEMBER P.C. acts solely as a Data Processor, processing personal data exclusively on behalf of and under the documented instructions of WORLD MARINE SERVICES CY LTD, in accordance with Article 28 of the GDPR.


3. Categories of Personal Data Processed

The following categories of personal data may be processed through the LMS:

  • Identification data (full name, corporate email address, department and/or position)

  • Learning and training data (course enrollment, participation, quiz responses, learning progress, completion status, training time)

  • Technical and usage data (access logs, IP-related metadata, functional and strictly necessary cookies)


4. Purposes of Processing

Personal data are processed exclusively for the following purposes:

  • Providing access to mandatory or optional training programs

  • Managing, monitoring, and documenting training participation and progress

  • Evaluating learning outcomes and compliance with internal training requirements

  • Ensuring the proper technical operation, security, and performance of the LMS


5. Legal Basis for Processing

Processing is carried out in accordance with Article 6 of the GDPR, based on one or more of the following legal grounds:

  • Performance of contractual and employment-related obligations (training requirements)

  • Legitimate interests of WORLD MARINE SERVICES CY LTD, including workforce development, compliance, and organizational effectiveness

  • Compliance with applicable legal and regulatory obligations


6. Data Retention Period

Personal data are retained only for as long as necessary to fulfill the purposes described above and in accordance with:

  • the internal data retention policies of WORLD MARINE SERVICES CY LTD, and

  • applicable legal and regulatory requirements.

Upon expiration of the retention period, data are securely deleted or anonymized.


7. Data Access and Recipients

Access to personal data is strictly limited to:

  • Authorized personnel of WORLD MARINE SERVICES CY LTD, acting within their professional responsibilities

  • Synaptica2 Solutions SINGLE MEMBER P.C., strictly for:

    • technical support,

    • system maintenance,

    • platform administration,

and only to the extent necessary, acting under the explicit instructions of the Data Controller and subject to appropriate technical and organizational safeguards.

No personal data are disclosed to third parties for commercial or unrelated purposes.


8. Data Subject Rights

In accordance with the GDPR, you have the right to:

  • Access your personal data

  • Request rectification of inaccurate or incomplete data

  • Request restriction of processing

  • Request erasure of your personal data, where applicable (“right to be forgotten”)

  • Lodge a complaint with the competent Data Protection Authority

All rights are exercised through the Data Controller.


9. Contact for Data Protection Matters

For any request, inquiry, or exercise of your data protection rights, please contact:

WORLD MARINE SERVICES CY LTD
đź“§ wms@wmservices.com

Synaptica2 Solutions SINGLE MEMBER P.C. does not independently handle data subject requests and supports the Data Controller exclusively in a technical capacity, where required.


10. Data Security

Appropriate technical and organizational measures are implemented to ensure a level of security appropriate to the risk, including access controls, system monitoring, and secure hosting infrastructure, in accordance with GDPR requirements.