Abdabis LLC GDPR & CCPA/CPRA Privacy Compliance Statement
Effective Date: August 29, 2026 · Last Updated: August 29, 2026
1. Overview and Purpose
This GDPR & CCPA/CPRA Privacy Compliance Statement ("Statement") complements the main Privacy Policy of Abdabis LLC ("Company", "we", "us", or "our") and sets forth our legal framework, operational practices, and technical standards regarding data privacy and protection.
Abdabis LLC is a single-member Limited Liability Company registered in the State of Wyoming, USA, located at 30 N Gould St #Ste R, Sheridan, WY 82801, USA. We operate the official website https://abdabis.com (the "Site") and develop enterprise Business-to-Business (B2B) digital platforms, including maritime software solutions (such as Vesselium) and associated services (collectively, the "Services").
This Statement addresses our data processing activities governed by:
- The General Data Protection Regulation (EU) 2016/679 ("GDPR") and its UK equivalent ("UK GDPR").
- The California Consumer Privacy Act of 2018 ("CCPA"), as amended by the California Privacy Rights Act of 2020 ("CPRA") (collectively, "CCPA/CPRA").
- Applicable United States federal and Wyoming state data protection standards.
2. Scope and Applicability
This Statement applies to all natural persons whose personal data is collected, stored, processed, or transferred by Abdabis LLC in connection with:
- Visitors browsing https://abdabis.com.
- Authorized business representatives, chartering managers, shipowners, freight brokers, and industry professionals participating in software demos, Design Partner programs, or non-binding Letters of Intent (LOIs).
- Corporate clients, beta testers, and users of our software platforms and web APIs.
3. Section I: European Union & UK GDPR Compliance
3.1 Data Controller Identification
For the purposes of the EU/UK GDPR, Abdabis LLC acts as the Data Controller for personal data collected directly through our Site, business communications, and enterprise interactions.
- Controller Name: Abdabis LLC
- Address: 30 N Gould St #Ste R, Sheridan, WY 82801, USA
- Privacy & Data Protection Contact: info@abdabis.com
3.2 Lawful Bases for Data Processing
Under Article 6 of the GDPR, we process personal data strictly under one or more of the following lawful bases:
- Contractual Necessity (Art. 6(1)(b)): Processing is necessary to perform a contract with you or to take pre-contractual steps at your request (e.g., setting up demo accounts, evaluating Design Partner agreements, or executing software evaluation agreements).
- Legitimate Interests (Art. 6(1)(f)): Processing is necessary for legitimate business interests pursued by Abdabis LLC, provided such interests are not overridden by your fundamental rights and freedoms. This includes securing, monitoring, and maintaining our web infrastructure and enterprise SaaS software; conducting professional B2B communications and partner outreach; and improving platform user interface workflows and feature integrations.
- Legal Obligation (Art. 6(1)(c)): Processing is necessary to comply with statutory accounting, tax, corporate reporting, or regulatory mandates in the United States and international jurisdictions.
- Consent (Art. 6(1)(a)): Where applicable, such as for non-essential web analytics cookies or explicit opt-in communications. You retain the right to withdraw consent at any time.
3.3 Categories of Data Processed
We collect and process minimal, fit-for-purpose business personal data, including:
- Identity Data: Full name, corporate title or role.
- Contact Data: Business email address, business telephone number, office address.
- Professional & Commercial Data: Company name, fleet management details, chartering preferences, feedback submitted during Design Partner testing, and non-binding LOI records.
- Technical & Usage Data: IP address, device fingerprints, browser types, operating system details, referral source, session duration, and access log data collected automatically via functional web logs.
3.4 Data Subject Rights Under GDPR
As an EU or UK data subject, you possess the following enforceable rights under Articles 15 through 22 of the GDPR:
- Right of Access (Art. 15): The right to request confirmation as to whether your personal data is being processed and to receive a copy of such data.
- Right to Rectification (Art. 16): The right to request the prompt correction of inaccurate or incomplete personal data.
- Right to Erasure / "Right to be Forgotten" (Art. 17): The right to request the deletion of your personal data where it is no longer necessary for processing purposes, or where consent has been withdrawn.
- Right to Restriction of Processing (Art. 18): The right to request that we restrict processing operations under specific legal conditions.
- Right to Data Portability (Art. 20): The right to receive your personal data in a structured, commonly used, and machine-readable format (such as CSV or JSON) for transmission to another controller.
- Right to Object (Art. 21): The right to object at any time to processing based on legitimate interests or direct business marketing.
- Right to Lodge a Complaint: The right to submit a complaint to a competent Data Protection Authority (DPA) within your EU Member State or the UK Information Commissioner's Office (ICO).
To exercise any GDPR right, contact our Data Protection Office at info@abdabis.com.
3.5 Cross-Border Data Transfers
Abdabis LLC is based in Wyoming, United States. Personal data collected from individuals residing in the EEA or UK may be transferred to, stored, and processed in the United States or other global cloud infrastructure nodes.
To ensure an adequate level of data protection, all international transfers are executed in compliance with Chapter V of the GDPR using standard contractual clauses (SCCs), strict encryption protocols (TLS 1.3 in transit, AES-256 at rest), and restricted access controls.
4. Section II: California CCPA / CPRA Compliance
This section applies solely to residents of the State of California ("California Consumers") pursuant to the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020.
4.1 Notice of Collection of Personal Information
In the preceding 12 months, Abdabis LLC has collected the following categories of Personal Information (as defined under California law) for commercial and operational purposes:
- Identifiers: Name, business email address, IP address, and corporate account credentials. Processed for account creation, identity verification, B2B communication, and platform security.
- Commercial Information: Records of products evaluated, Design Partner status, and LOI records. Processed for software delivery, customer service, feature customization, and B2B partnership management.
- Internet or Other Network Activity: Browsing history on site, access logs, device details, and interaction analytics. Processed for system maintenance, security monitoring, and infrastructure optimization.
- Professional or Employment-Related Data: Job title, employer name, and industry sector (such as maritime chartering or brokerage). Processed for enterprise evaluation, B2B lead management, and contract negotiation.
- Sensitive Personal Information: Encrypted account passwords. Processed strictly for platform authentication and access security.
4.2 Absolute Prohibition on the Sale or Sharing of Personal Information
- NO SALE OF DATA: Abdabis LLC does not sell your personal information or commercial records to third parties for monetary or other valuable consideration.
- NO SHARING FOR CROSS-CONTEXT BEHAVIORAL ADVERTISING: We do not share consumer personal information with third parties for cross-context behavioral advertising purposes.
- NO SALE OF MINORS' DATA: We do not sell or share personal information of individuals under 16 years of age.
4.3 California Consumer Privacy Rights (CCPA/CPRA)
If you are a California resident, you have specific rights regarding your personal information:
- Right to Know / Access: You have the right to request that we disclose the categories of personal information collected, the categories of sources, the business or commercial purpose for collection, and the specific pieces of personal information collected about you in the preceding 12 months.
- Right to Delete: You have the right to request the deletion of personal information we have collected from you, subject to certain statutory exceptions (such as legal compliance, transaction completion, or security preservation).
- Right to Correct: You have the right to request the correction of inaccurate personal information maintained in our active databases.
- Right to Limit Use of Sensitive Personal Information: You have the right to limit the use of sensitive personal information strictly to what is necessary for delivering requested services.
- Right to Non-Discrimination: We will not discriminate against you (such as by denying services or altering prices) for exercising any of your CCPA/CPRA rights.
4.4 Submitting CCPA Requests
California consumers (or their authorized agents registered with the California Secretary of State) may submit a verifiable consumer request by contacting us at:
- Email: info@abdabis.com
- Mailing Address: Abdabis LLC, Attn: Legal/Privacy, 30 N Gould St #Ste R, Sheridan, WY 82801, USA
We will verify your identity by matching data points provided in your request against verified records in our system. Verification responses will be delivered within 45 calendar days of receipt.
5. Technical Security & Data Retention Standards
5.1 Technical Security Measures
Abdabis LLC maintains technical, organizational, and physical security measures engineered to safeguard personal and commercial data, including:
- Encryption: End-to-end transport layer security (TLS 1.3 / HTTPS) for all web traffic and robust AES-256 encryption for data at rest.
- Access Control: Strict Role-Based Access Control (RBAC) limiting system and database access solely to authorized personnel on a need-to-know basis.
- System Architecture: Segregated database infrastructure, continuous vulnerability assessments, and secure API gateways.
5.2 Data Retention Policy
Personal information is retained only for as long as necessary to fulfill the operational, commercial, or legal purposes outlined in this Statement, or to resolve disputes and enforce contractual terms. Once personal data is no longer required, it is securely anonymized or permanently destroyed using cryptographic erasure standards.
6. Amendments & Updates
We reserve the right to revise, update, or modify this GDPR/CCPA Compliance Statement at any time to reflect legal, regulatory, or operational developments. Any changes will be published directly on https://abdabis.com with an updated "Effective Date." Continued interaction with our Site or Services after an update indicates acknowledgment of the revised terms.
7. Contact and Data Privacy Office
If you have questions, feedback, or formal privacy requests regarding this GDPR & CCPA Statement, please direct all inquiries to:
Abdabis LLC
Data Privacy & Compliance Department
30 N Gould St #Ste R
Sheridan, WY, 82801, USA
Official Email: info@abdabis.com
Website: https://abdabis.com