01Who this notice covers
This Privacy Notice describes how Maritime Intelligence System (MIS) handles personal information when you visit the portal, create an account, use fleet and maritime intelligence features, or contact us. The service is operated by the provider identified in your order, subscription, or account materials (the “Provider”). Those materials should identify the Provider’s legal name and contact details.
For a company account, your employer or customer may decide why crew, employee, vessel, and operational data is entered into MIS. In those cases that organization is generally responsible for that data, and MIS processes it to provide the contracted service. Contact your organization for its own privacy practices.
02Information handled
Depending on the features enabled, MIS may handle:
- Account and identity details such as name, work email, username, organization, roles, sign-in and security events, and support correspondence.
- Fleet and operational information such as vessel identifiers, AIS positions and history, voyages, routes, geofences, risk events, weather overlays, and integration settings or credentials.
- Crew information entered or synchronized by your organization, including engagement, sign-on/sign-off, history, and relevant audit records.
- Files and message details that you choose to send through Support & Contact, including the selected attachments.
- Subscription and transaction references handled with payment providers, and technical information needed to run, protect, diagnose, and improve the portal.
03How we use it
We use information to authenticate users, operate and support fleet, AIS, voyage playback, crew engagement, weather and risk features, administer subscriptions, respond to requests, secure the service, prevent abuse, meet legal obligations, and maintain operational records. We do not sell customer-provided AIS or crew data, and we do not disclose it to other customers for their independent use. Access is limited to the customer’s authorized users and service personnel who need it to operate or support the service, subject to applicable agreements and law.
When you submit a Support or Contact form, your message and permitted attachments are routed to the inbox configured by the portal administrator using the configured email provider. Files are held in memory while the request is processed and are not saved as portal ticket records. The receiving mailbox and email provider may retain message and attachment copies under their own retention and security settings.
04AIS, crew data, AI, and connected providers
AIS broadcasts and third-party maritime feeds can be public, incomplete, delayed, misreported, or otherwise outside MIS’s control. MIS may combine licensed, public, customer-supplied, and connected-provider data to display maritime information. We do not disclose customer-supplied fleet AIS positions, feed credentials, or crew records to other customers. Public or licensed AIS traffic may be shown to multiple customers; that public-feed traffic is distinct from private customer fleet and crew data.
If an administrator enables voice or AI features, voice, prompts, and the context needed to answer a request may be sent to the selected AI provider (currently configurable for OpenAI or Google Gemini) to provide that feature. MIS does not make Crew API activity payloads available to AI tools. Do not submit sensitive personal, crew, security, or commercially confidential data in AI prompts or audio unless your organization has approved that use. Third-party providers process information under their own terms and privacy notices.
The service also relies on hosting, email, identity, payment, mapping, weather, AIS, and other infrastructure providers where configured. They may process limited information as needed to provide their services. We do not authorize these providers to use customer data for their own unrelated purposes through our instructions, but their own terms may also apply to services your organization chooses to connect.
05Security and incident response
We use administrative, technical, and organizational safeguards intended to protect information, including access controls and security monitoring. No internet service, storage system, email transmission, or security control can be guaranteed to prevent every incident. We do not promise that data will always be secure, that the portal will never be compromised, or that service will be uninterrupted. If a security incident occurs, we will assess and respond and provide notices when required by applicable law or contract. Customers remain responsible for their users, devices, credentials, integrations, configuration, and their own security obligations.
06Retention and deletion
We retain information while an account or customer relationship is active and for as long as reasonably needed for the purposes above, contractual administration, security, dispute handling, legal requirements, and backup or recovery processes. Retention periods can differ by data type and customer configuration. An authorized customer administrator may request account or data deletion by contacting us; deletion from active systems may not immediately remove encrypted backups, audit records that must be retained, or copies held by email and other providers. The organization that supplied crew data should submit requests on behalf of its users where it controls that data.
07Your choices and rights
Depending on where you live and your relationship with the customer organization, you may have rights to access, correct, erase, restrict, object to, or receive certain personal information, or to complain to a regulator. The applicable law determines which rights apply and any exceptions. Contact your organization first for information it controls; you may also send us a request through the Support & Contact page. We will verify and route requests and respond as required by law.
08On-premises deployment
Organizations requiring greater control may contract for an on-premises deployment running in infrastructure they control and under their cybersecurity policies. Responsibility for infrastructure, access, backups, network exposure, patching, monitoring, and incident response depends on the deployment agreement and division of responsibilities. On-premises deployment does not by itself guarantee security or remove legal obligations.
09Changes and contact
We may update this notice as the service, providers, or legal requirements change. The current version and effective date will be published here. For privacy questions or requests, use Support & Contact and select Contact, or write to the privacy contact identified in your customer or order materials.
This published text is general product information, not legal advice. The Provider should confirm its legal identity, jurisdictions, contracts, actual data retention, vendors, security practices, and regulatory duties before relying on this draft.
