Legal
Privacy Policy
Last updated: 1 August 2026
1. Who we are
Marintel operates the maritime document management platform at marintel.co. In this policy, "Marintel", "we", "us", and "our" refer to the Marintel platform and its operating entity. For GDPR purposes, Marintel is the data controller for account and usage data, and acts as a data processor for documents uploaded to data rooms.
2. What data we collect
Account data: Name, email address, and authentication information when you create an account or are invited to a data room.
Usage data: Actions taken within the platform — document uploads, views, downloads, approvals — logged as part of the audit trail.
Document data: Files uploaded to data rooms, and AI-extracted data derived from those files.
Technical data: IP addresses, browser type, and session information collected automatically when you use the Service.
3. How we use your data
We use account data to authenticate you and provide the Service. We use usage data to maintain the audit trail that is a core feature of the Service and to improve platform performance. We use document data solely to provide the document management and analysis features you have requested. We do not use your transaction documents to train AI models without your explicit consent.
4. Legal basis for processing (GDPR)
For account and usage data: performance of a contract (providing the Service you've subscribed to). For document data: performance of a contract and, where applicable, your explicit consent to AI processing features. For communications: legitimate interests in operating and improving the Service.
5. Data sharing
We do not sell your data. We share data only with subprocessors necessary to operate the Service:
- Supabase (database hosting) — SOC 2 Type II, ISO 27001 certified. EU data residency available.
- Amazon Web Services (document storage, compute, transactional email) — SOC 2, ISO 27001, FedRAMP. We use US regions (us-east-1) by default; enterprise agreements can specify other regions.
- Anthropic (AI document analysis) — Documents sent for AI analysis are subject to Anthropic's data processing terms.
- Voyage AI (semantic search embeddings) — Document text is embedded for retrieval within your own workspace.
- Internet search providers — Used only by the vessel identification and valuation features, which search on vessel identifiers (name, IMO, type, size, year built). Document content is never sent to them.
5a. Personal data in AI processing
Where an AI processing step can do its job without personal data, we remove it before the content leaves our systems. Before a document's text is sent for field extraction, detected identifiers — email addresses, telephone numbers, IBAN and payment card numbers, social security, passport and national identification numbers, and personal names — are masked, and each run records which categories were masked. Search terms you type into vessel lookup are stripped of detected personal data before they are sent, and a term consisting only of personal data is not sent at all.
Some steps cannot be minimised, and we say so rather than imply a protection that does not exist: document classification and OCR receive the complete file (the original PDF or image), and the in-platform assistant receives the extracted document data for the project you are asking about, which can include names and contact details. Detection is automated, pattern-based, and deliberately conservative — it is not a guarantee that every identifier is found. The full description is in Sections 5.2 to 5.4 of the Privacy Policy available inside the platform.
6. Data retention
Account data is retained for the duration of your account. Data room documents are retained for the duration of your subscription plus a 90-day export window after cancellation. Audit trail data is retained for a minimum of seven years from the date of the logged event. You can request deletion of your personal data at any time; transaction documents in active data rooms require counterparty notification before deletion.
7. Your rights (GDPR)
If you are in the European Economic Area, you have the right to access, correct, delete, and port your personal data; to object to or restrict certain processing; and to lodge a complaint with your local data protection authority. To exercise these rights, contact privacy@marintel.co.
8. Security
We protect data with AES-256 encryption at rest and TLS 1.3 in transit, Ed25519-signed audit chains, role-based access controls, and regular penetration testing. Our security practices are described in detail at marintel.co/security.
9. Cookies
We use strictly necessary cookies for authentication session management. We do not use third-party tracking or advertising cookies.
10. Changes to this policy
We will notify you by email of material changes to this policy before they take effect.
11. Contact
Privacy questions should be sent to privacy@marintel.co.