Aquina

Privacy Policy

How Rhumb Inc — operating the platform and website at aquina.ai under the names Aquina, Aquina.ai and Aquina Ship OS — collects, uses, discloses, stores, transfers and protects personal data.

Effective 2 September 2026 Last updated 2 September 2026 Version 1.0

1. Introduction

Rhumb Inc, a corporation incorporated in the State of Delaware, United States of America (Delaware State File Number 10727282), operating the platform and website at aquina.ai under the names Aquina, Aquina.ai and Aquina Ship OS (“Aquina”, “we”, “us”, “our”), provides an end-to-end maritime software platform delivered as Software-as-a-Service to shipping companies, ship managers, ship owners, charterers, agents and other maritime enterprises (each a “Customer”).

This Privacy Policy explains how we collect, use, disclose, store, transfer and protect personal data in connection with:

By accessing the Website or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Website or the Platform.

2. Our two roles: controller and processor

Understanding which role we occupy is essential, because it determines who you should contact about your data.

2.1 Aquina as a data controller

We act as the controller (or, under certain laws, the Data Fiduciary or Business) for personal data we collect for our own purposes, including:

For this data, we determine the purposes and means of processing, and this Policy governs our practices.

2.2 Aquina as a data processor

When a Customer uses the Aquina Ship OS Platform, that Customer uploads, generates or transmits data concerning its own crew, seafarers, shore staff, vessels, voyages, customers, suppliers and counterparties (“Customer Data”). In respect of personal data within Customer Data, the Customer is the controller (or Business) and Aquina is the processor (or Service Provider).

We process such data only on the Customer’s documented instructions, as set out in the Master Subscription Agreement, Order Form and Data Processing Addendum (“DPA”) executed with that Customer.

Important. If you are a seafarer, crew member, shore employee, contractor, agent, vendor or counterparty of a Customer, and you wish to access, correct, delete or object to the processing of your personal data held in the Platform, please contact that Customer (your employer, manning agent or ship manager) as the controller. If you contact us directly, we will, where we can identify the relevant Customer, refer your request to them and confirm to you that we have done so. We are not permitted to act on such requests without the Customer’s authorisation.

Sections 4 to 8 of this Policy describe our controller-side practices. Section 10 describes our processor-side commitments.

3. Scope and applicable laws

We are a United States company serving Customers that operate internationally. This Policy is designed to operate consistently with, as and where applicable:

Where the requirements of two applicable laws differ, we apply the standard that offers the higher level of protection to the individual, to the extent legally permissible.

This Policy does not apply to third-party websites, applications, port systems, class society portals, flag administration systems, AIS providers, or customer-side systems that we may link to or integrate with. Those are governed by their own privacy notices.

4. Personal data we collect as controller

4.1 Information you provide directly

CategoryExamples
Identity and contact dataFull name, job title, company name, business email address, business telephone number, country/city, professional profile links
Enquiry and interest dataFleet size, vessel types, modules of interest, current systems in use, implementation timelines, budget range, and free-text content of your message
Account administration dataCustomer administrator names, roles, credentials issued by us, authentication factors, permission assignments
Commercial and billing dataBilling contact, registered address, tax registration numbers, purchase order references, bank or payment reference details, invoicing history
Contractual dataSignatory details, authorised representative names, KYC/KYB documentation where required by law or by our banking partners
Support and communications dataSupport tickets, chat transcripts, call notes, screenshots or logs you attach, feedback, survey responses, complaint records
Event and marketing dataRegistration details for webinars, conferences and trade events; attendance records; content-download records
Recruitment dataCV, employment and education history, references, right-to-work information, and any information you choose to include in an application

4.2 Information collected automatically

4.3 Information from third parties

4.4 Data we do not seek

We do not intentionally collect, and ask you not to submit through the Website, special-category or sensitive personal data — including health, biometric, genetic, racial or ethnic origin, religious belief, political opinion, trade-union membership, sexual orientation or criminal-record data. Sensitive data of the kind that necessarily arises in ship management — for example seafarer medical fitness certificates, next-of-kin details, passport and seafarer’s identity document data, drug-and-alcohol test outcomes, and disciplinary records — is processed only within the Platform, as Customer Data, on the Customer’s instructions and under the DPA, and never for our own purposes.

4.5 Children

The Website and the Platform are intended solely for business use by adults. We do not knowingly collect personal data from any person under the age of 18, and we do not sell or share the personal data of minors. Where a Customer lawfully records dependent or next-of-kin information (which may relate to minors) within a crew or welfare module, that data is Customer Data processed on the Customer’s instructions and lawful basis. If we become aware that we have inadvertently collected data of a child for our own purposes, we will delete it promptly.

5. Why we process personal data (purposes and legal bases)

The legal bases below are expressed in GDPR / UK GDPR terms. Where another law applies, we rely on the corresponding basis available under that law — consent, performance of a contract, legal obligation, or a legitimate or specified use.

#PurposeLegal basis
5.1Responding to enquiries, demo requests and RFP/RFI submissionsLegitimate interests; steps prior to entering a contract
5.2Negotiating, concluding and administering subscription agreementsPerformance of a contract
5.3Provisioning Customer deployments, issuing credentials, onboarding and training usersPerformance of a contract
5.4Providing support, incident response, bug fixing and service communicationsPerformance of a contract; legitimate interests
5.5Billing, invoicing, collections, tax and statutory accountingPerformance of a contract; legal obligation
5.6Operating, securing, monitoring and improving the Platform; capacity planning; developing new featuresLegitimate interests
5.7Marketing communications, newsletters, product announcements and event invitationsConsent, or legitimate interests for existing business contacts, with opt-out in every case
5.8Website analytics, personalisation and advertising measurementConsent, where required for non-essential cookies
5.9Sanctions, export-control, anti-money-laundering, anti-bribery and fraud screening — including screening of Customers, their beneficial owners, vessels and counterparties against OFAC, EU, UK, UN and other applicable designated-party listsLegal obligation; legitimate interests
5.10Enforcing our terms, protecting our rights, and establishing, exercising or defending legal claimsLegitimate interests; legal obligation
5.11Corporate transactions such as financing, audit, merger, acquisition or restructuringLegitimate interests
5.12Recruitment and vendor onboardingLegitimate interests; pre-contractual steps; legal obligation

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You may request a summary of that assessment at admin@aquina.ai.

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide certain features or communications.

6. Automated processing, analytics and artificial intelligence

The Aquina Ship OS Platform includes analytical, predictive and AI-assisted features — for example voyage optimisation, fuel-consumption and emissions estimation, maintenance prediction, document extraction, anomaly detection, crew-planning suggestions and natural-language assistance.

We commit to the following:

  1. No solely automated decisions with legal effect. Aquina does not use automated processing to make decisions about individuals that produce legal effects or similarly significant effects on them without human involvement. Where a Customer configures the Platform to support decisions about its own personnel, such as appraisal scoring or promotion readiness, the Customer is responsible for maintaining meaningful human review and for any notice, consent or impact assessment required by law.
  2. Training data. We do not use identifiable Customer Data to train, fine-tune or improve machine-learning models that are made available to other Customers, unless the Customer has given specific, separate, written consent. We may use aggregated, de-identified or statistically derived data that cannot reasonably be re-identified — for example fleet-level benchmarks or anonymised performance baselines — for product improvement and benchmarking, as further described in our Terms and Conditions.
  3. Third-party AI services. Where a Platform feature uses a third-party model provider, that provider is engaged as a sub-processor under contractual terms that prohibit use of Customer Data for the provider’s own model training, and is listed in Section 9.
  4. Explainability. On request through a Customer, we will provide a plain-language description of the logic, key inputs and known limitations of an AI-assisted feature.
  5. Human authority at sea prevails. Platform outputs are decision-support only. They do not override the judgement and overriding authority of the Master, the requirements of SOLAS, COLREG, MARPOL, the ISM Code, class rules or flag-state instructions. See the corresponding disclaimer in our Terms and Conditions.

7. Disclosure of personal data

We do not sell personal data, and we do not rent, trade or otherwise monetise it. We disclose personal data only as follows.

7.1 Within our group. To our affiliates and subsidiaries, where they perform delivery, support, engineering or administrative functions on our behalf, subject to intra-group data-transfer agreements.

7.2 To service providers and sub-processors. To vetted vendors who process data on our behalf under written contracts imposing confidentiality, security and use-limitation obligations at least as protective as those in this Policy. See Section 9.

7.3 To the relevant Customer. If you are a user of a Customer’s deployment, your account, activity and audit data is visible to that Customer’s administrators. Each Customer’s deployment is logically segregated: no Customer can access another Customer’s data.

7.4 To professional advisers. To our auditors, lawyers, insurers, bankers and accountants, bound by professional or contractual confidentiality obligations.

7.5 To authorities and in legal process. Where required by applicable law, court order, subpoena, regulator, tax authority, flag administration, port state control, or lawful government request. We will, unless legally prohibited, notify the affected Customer before disclosing Customer Data and will use reasonable efforts to challenge requests that appear overbroad or unlawful.

7.6 In corporate transactions. To an actual or prospective acquirer, investor, or their advisers in connection with a merger, acquisition, financing, reorganisation or sale of assets, under confidentiality obligations. If personal data is transferred as part of a completed transaction, we will notify affected individuals or Customers, and the acquirer will remain bound by materially equivalent protections.

7.7 To protect rights and safety. Where necessary to prevent fraud, investigate a security incident, protect our legal rights or property, or protect the life or safety of any person — including in response to a maritime emergency, distress situation, or a search-and-rescue coordination request from a competent authority.

7.8 With your consent or at your direction, including where you instruct an integration between the Platform and a third-party system.

8. Your rights

Subject to applicable law and to verification of your identity, you have the right to:

8.1 How to exercise your rights. Email admin@aquina.ai with the subject line “Data Rights Request”, describing the right you wish to exercise. We may ask for information reasonably necessary to verify your identity, and will not use that information for any other purpose.

8.2 Response times. We will respond within thirty (30) days as a general standard; within one month for GDPR and UK GDPR requests, extendable by two further months for complex or numerous requests with notice to you; and within forty-five (45) days for requests under US state privacy laws, extendable once by a further forty-five (45) days with notice.

8.3 Authorised agents and fees. You may use an authorised agent to submit a request where applicable law permits, provided the agent supplies written authorisation and we can verify your identity. We do not charge a fee unless a request is manifestly unfounded, excessive or repetitive, in which case we will tell you the reasonable fee before proceeding.

8.4 Notice to United States residents. For the twelve months preceding the date of this Policy, the categories of personal information described in Section 4 have been collected for the purposes described in Section 5 and disclosed to the categories of recipients described in Sections 7 and 9. We confirm that:

8.5 Requests relating to Customer Data. As explained in Section 2.2, please direct these to the Customer that controls the data. We will assist that Customer in responding, as required by the DPA.

8.6 Marketing opt-out. Use the unsubscribe link in any marketing email, or write to admin@aquina.ai. We will continue to send essential service, security, billing and contractual notices, which are not marketing.

8.7 Complaints. Contact us first at admin@aquina.ai. We will acknowledge within 72 hours and endeavour to resolve within 30 days. If you remain dissatisfied, you may complain to your local supervisory authority — including, in the United Kingdom, the Information Commissioner’s Office; in the EEA, your national data protection authority; in Singapore, the Personal Data Protection Commission; in India, the Data Protection Board of India; and in California, the California Privacy Protection Agency or the Attorney General.

8.8 Representatives. Where we are required to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, or a Grievance Officer under the Digital Personal Data Protection Act, 2023, details will be published in this Section and notified to affected Customers. Until then, all enquiries should be sent to admin@aquina.ai.

9. Sub-processors and service providers

We engage the following categories of sub-processor. A current, authoritative list is available to Customers on request at admin@aquina.ai.

CategoryPurposeProviderLocation
Cloud infrastructure and hostingCompute, storage, database, backupAmazon Web ServicesDefault: Asia Pacific (Mumbai), with Asia Pacific (Singapore) as its disaster-recovery region; European Union, United Kingdom and Middle East regions available per Deployment
Content delivery and DDoS protectionAvailability, edge securityCloudflareGlobal edge network
Website hosting and web fontsServing this Website; delivering the typefaces it usesGitHub Pages; Google FontsGlobal edge network / United States
Email deliveryTransactional and notification emailTransactional email providerUnited States / EU
CRM and marketing automationSales pipeline, marketing communicationsCRM providerUnited States
Support desk and ticketingSupport case managementSupport platform providerUnited States
Product analytics and error monitoringUsage analytics, crash and error reportingAnalytics and monitoring providersUnited States / EU
Identity and access managementAuthentication, single sign-on, multi-factor authenticationIdentity providerUnited States
Payment and invoicingSubscription billing and payment processingPayment processorUnited States
AI and machine-learning servicesAI-assisted Platform featuresEnterprise model providers, contractually barred from training on Customer DataUnited States
Maritime data servicesAIS and position, weather, port, vessel-particulars and bunker-price dataMaritime data providersVaries by provider
Sanctions and compliance screeningDesignated-party and beneficial-ownership screeningScreening providerUnited States / EU

Change notification. For Customers, we will give at least thirty (30) days’ prior written notice, by email and by updating the list referred to above, before adding or replacing a sub-processor that processes Customer personal data. A Customer may object on reasonable data-protection grounds within that period; if we cannot offer a commercially reasonable alternative, the Customer may terminate the affected subscription without penalty for the unused prepaid term.

10. Processor commitments to Customers

Where we act as processor for Customer Data, we commit — and where required contract in a DPA — to:

  1. Process Customer Data only on the Customer’s documented instructions and for the purpose of providing the Services.
  2. Not use Customer Data for our own purposes, including advertising, resale, profiling or cross-customer model training.
  3. Impose confidentiality obligations on all personnel with access, and grant access strictly on a need-to-know, least-privilege basis.
  4. Implement and maintain the technical and organisational measures described in Section 11.
  5. Engage sub-processors only in accordance with Section 9, and remain responsible for their performance.
  6. Assist the Customer with data-subject requests, data protection impact assessments and regulator consultations.
  7. Notify the Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a personal data breach affecting their data, with the information reasonably available to us.
  8. Make available information necessary to demonstrate compliance, and permit audits or accept independent third-party audit reports, on reasonable notice and subject to confidentiality.
  9. On termination, at the Customer’s election, return Customer Data in a standard machine-readable format or securely delete it — see Section 13.
  10. Notify the Customer if we believe an instruction infringes applicable data protection law.

11. Security

We maintain a documented information security programme appropriate to the risks of maritime enterprise software. Measures include:

We align our controls with recognised frameworks including ISO/IEC 27001 and SOC 2, and, for shipboard and shore integration, with the cyber-risk-management expectations of IMO Resolution MSC.428(98) and IACS UR E26 and E27. Our current certification and audit-report status is available to Customers under a non-disclosure agreement on request at admin@aquina.ai.

No system is perfectly secure. While we apply industry-recognised safeguards, we cannot guarantee absolute security. You are responsible for safeguarding your credentials, enabling available security features, and notifying us immediately at admin@aquina.ai of any suspected compromise.

Breach notification. Where a personal data breach is likely to result in a risk to individuals, we will notify the affected Customer and, where we are controller, the affected individuals and the competent authority, within the timeframes required by applicable law — including the seventy-two hour requirement under the GDPR and UK GDPR, and applicable United States state breach-notification statutes.

12. Cookies and tracking technologies

What is true of this Website today. This Website is a static informational site. It sets no cookies, runs no analytics or advertising tags, and asks for no consent, because it has nothing to consent to. It is served by GitHub Pages, which records standard server-log information including your IP address, and it loads its typefaces from Google Fonts, which receives your IP address as part of that request. The categories below describe the cookies used in the Aquina Ship OS Platform and in any future Website features; a consent banner and a Cookie Preferences control will be present before any non-essential cookie is set.

We use cookies and similar technologies, including pixels, local storage and SDKs, in the following categories:

CategoryPurposeConsent required
Strictly necessaryAuthentication, session management, load balancing, security, CSRF protection, consent-preference storageNo
FunctionalLanguage, region, time-zone and interface preferences; chat widgetYes
Analytics and performanceUnderstanding traffic, feature usage and page performanceYes
Marketing and advertisingCampaign attribution, retargeting, conversion measurementYes

Where non-essential cookies are in use, you will be presented on your first visit with a consent banner allowing you to accept all, reject all non-essential, or select categories individually. You may change your choices at any time via the Cookie Preferences link in the Website footer, or through your browser settings. Rejecting non-essential cookies will not prevent access to the Website, but some features may not function optimally.

We honour Global Privacy Control signals where technically detected. Because there is no industry consensus on browser “Do Not Track” headers, we do not currently respond to DNT.

Cookies used within an authenticated Customer deployment are limited to strictly necessary and functional categories.

13. Data retention

We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.

DataIndicative retention
Website enquiry and lead data, where no contract is concluded24 months from last interaction
Marketing consent and preference recordsDuration of consent, plus 3 years as proof of consent
Customer account and administration dataTerm of subscription, plus 3 years
Contracts, invoices, tax and statutory accounting records7 years, or longer where applicable tax or corporate law requires
Support tickets and correspondence3 years from closure
Security, authentication and audit logs12 months, extended where required for an active investigation
Backups and snapshotsRolling 35 days, overwritten in the ordinary cycle
Sanctions and compliance screening records5 years from the end of the business relationship, or longer where required by anti-money-laundering or export-control law
Recruitment data for unsuccessful applicants12 months from decision, or with consent for a future-opportunities pool
Cookie and analytics identifiersUp to 13 months

Customer Data is retained for the subscription term. On termination or expiry, we make Customer Data available for export for thirty (30) days, after which — unless the Customer instructs otherwise in writing or law requires retention — we securely delete it from active systems within sixty (60) days, and from backups within the ordinary backup expiry cycle, being up to a further ninety (90) days. Certain maritime records are subject to mandatory statutory retention, for example under the Maritime Labour Convention, 2006, MARPOL record-keeping requirements, or flag-state rules. It is the Customer’s responsibility to identify such records and export them, or instruct their retention, before deletion.

Where deletion is not technically feasible — for example in immutable archives or write-once audit stores — we will securely isolate the data, block further processing, and delete it on expiry of the relevant cycle.

14. International data transfers and regional hosting

We are established in the United States, our sub-processors operate globally, and our Customers operate vessels and offices worldwide. Personal data may therefore be transferred to, stored in, or accessed from countries other than your own, including the United States, Singapore, the United Arab Emirates, India, the European Economic Area and the United Kingdom.

Where we transfer personal data across borders, we rely on one or more of the following safeguards:

We carry out transfer impact assessments where required, and apply supplementary technical measures — such as encryption with keys held in the originating region, and data-residency configuration — where a Customer requires them.

Regional hosting. Aquina is operated as a multi-region service, so that a Customer’s Deployment, and the personal data within it, can rest in the region that Customer requires. The default hosting region is Asia Pacific (Mumbai), with Asia Pacific (Singapore) as the disaster-recovery region for that Deployment. Further regions — including the European Union, the United Kingdom and the Middle East — are available, and where a Deployment is provisioned outside the default its disaster-recovery region is paired within the same geography. The region or regions applicable to a Deployment, and its data-residency commitment, are recorded in the applicable Order Form and do not change without the Customer’s agreement.

Customers with data-residency, data-sovereignty or flag-state requirements should raise them before onboarding, so the Deployment is provisioned in the right region from the outset; migrating a live Deployment between regions is a Professional Service, not a configuration change.

You may request a copy of the relevant transfer mechanism, with commercial terms redacted, at admin@aquina.ai.

15. Contact

Rhumb Inc (operating as Aquina.ai)
A Delaware corporation  |  Delaware State File Number 10727282
Registered office: 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, United States of America

All privacy enquiries, data rights requests, security reports and complaints:
admin@aquina.ai

Please mark your message “Data Rights Request”, “Security”, or “Privacy Complaint” as appropriate, so we can route it correctly. We acknowledge complaints within 72 hours and endeavour to resolve them within 30 days.

16. Changes to this Policy

We may update this Policy to reflect changes in our services, technology, legal requirements or business practices. The “Last updated” date at the top will always show the current version.

Where a change requires your consent under applicable law, we will obtain it before applying the change to your data. Continued use of the Website or the Platform after the effective date of a change constitutes acceptance of the updated Policy, except where consent is legally required.

Archived versions are available on request at admin@aquina.ai.

17. Order of precedence

If there is any conflict between this Policy and an executed Master Subscription Agreement, Order Form or Data Processing Addendum between Aquina and a Customer, the executed agreement prevails in respect of Customer Data. This Policy continues to govern our controller-side processing and the Website in all cases.