1. Introduction
Rhumb Inc, a corporation incorporated in the State of Delaware, United States of America (Delaware State File Number 10727282), operating the platform and website at aquina.ai under the names Aquina, Aquina.ai and Aquina Ship OS (“Aquina”, “we”, “us”, “our”), provides an end-to-end maritime software platform delivered as Software-as-a-Service to shipping companies, ship managers, ship owners, charterers, agents and other maritime enterprises (each a “Customer”).
This Privacy Policy explains how we collect, use, disclose, store, transfer and protect personal data in connection with:
- our website, marketing pages, blogs, webinars and enquiry forms (“Website”);
- the Aquina Ship OS platform, its modules, mobile and vessel applications, APIs and integrations (“Platform” or “Services”); and
- our sales, support, onboarding, training and professional-services interactions.
By accessing the Website or using the Platform, you acknowledge that you have read and understood this Policy. If you do not agree with it, please do not use the Website or the Platform.
2. Our two roles: controller and processor
Understanding which role we occupy is essential, because it determines who you should contact about your data.
2.1 Aquina as a data controller
We act as the controller (or, under certain laws, the Data Fiduciary or Business) for personal data we collect for our own purposes, including:
- Website visitors and users subject to our cookies and analytics;
- prospects, leads and business contacts who submit enquiries, request demos or subscribe to communications;
- authorised representatives and signatories of Customers, for contracting, billing and account administration;
- job applicants, vendors, partners and our own personnel.
For this data, we determine the purposes and means of processing, and this Policy governs our practices.
2.2 Aquina as a data processor
When a Customer uses the Aquina Ship OS Platform, that Customer uploads, generates or transmits data concerning its own crew, seafarers, shore staff, vessels, voyages, customers, suppliers and counterparties (“Customer Data”). In respect of personal data within Customer Data, the Customer is the controller (or Business) and Aquina is the processor (or Service Provider).
We process such data only on the Customer’s documented instructions, as set out in the Master Subscription Agreement, Order Form and Data Processing Addendum (“DPA”) executed with that Customer.
Important. If you are a seafarer, crew member, shore employee, contractor, agent, vendor or counterparty of a Customer, and you wish to access, correct, delete or object to the processing of your personal data held in the Platform, please contact that Customer (your employer, manning agent or ship manager) as the controller. If you contact us directly, we will, where we can identify the relevant Customer, refer your request to them and confirm to you that we have done so. We are not permitted to act on such requests without the Customer’s authorisation.
Sections 4 to 8 of this Policy describe our controller-side practices. Section 10 describes our processor-side commitments.
3. Scope and applicable laws
We are a United States company serving Customers that operate internationally. This Policy is designed to operate consistently with, as and where applicable:
- the EU General Data Protection Regulation (2016/679) and the UK GDPR, where we process data of individuals in the European Economic Area or the United Kingdom;
- the California Consumer Privacy Act as amended by the CPRA, and comparable state privacy laws including those of Virginia, Colorado, Connecticut, Utah and Texas (see Section 8.4);
- the Singapore Personal Data Protection Act 2012;
- the Digital Personal Data Protection Act, 2023 (India), where a Customer or individual is in India;
- the UAE Federal Decree-Law No. 45 of 2021 and the data protection regulations of the DIFC and ADGM; and
- other applicable data protection laws in jurisdictions where we or our Customers operate.
Where the requirements of two applicable laws differ, we apply the standard that offers the higher level of protection to the individual, to the extent legally permissible.
This Policy does not apply to third-party websites, applications, port systems, class society portals, flag administration systems, AIS providers, or customer-side systems that we may link to or integrate with. Those are governed by their own privacy notices.
4. Personal data we collect as controller
4.1 Information you provide directly
| Category | Examples |
|---|---|
| Identity and contact data | Full name, job title, company name, business email address, business telephone number, country/city, professional profile links |
| Enquiry and interest data | Fleet size, vessel types, modules of interest, current systems in use, implementation timelines, budget range, and free-text content of your message |
| Account administration data | Customer administrator names, roles, credentials issued by us, authentication factors, permission assignments |
| Commercial and billing data | Billing contact, registered address, tax registration numbers, purchase order references, bank or payment reference details, invoicing history |
| Contractual data | Signatory details, authorised representative names, KYC/KYB documentation where required by law or by our banking partners |
| Support and communications data | Support tickets, chat transcripts, call notes, screenshots or logs you attach, feedback, survey responses, complaint records |
| Event and marketing data | Registration details for webinars, conferences and trade events; attendance records; content-download records |
| Recruitment data | CV, employment and education history, references, right-to-work information, and any information you choose to include in an application |
4.2 Information collected automatically
- Device and connection data: IP address, browser type and version, operating system, device identifiers, screen resolution, language and time-zone settings.
- Usage data: pages viewed, referring and exit URLs, links clicked, time on page, scroll depth, search terms used on our Website, session duration.
- Cookies and similar technologies: as described in Section 12.
- Platform telemetry (controller-side): aggregate performance metrics, error and crash reports, feature-adoption statistics and API latency data used to operate, secure and improve the Platform. Where such telemetry contains identifiers linked to a Customer’s users, we handle it as Customer Data under the applicable DPA.
- Security and audit logs: authentication attempts, IP address and approximate location of login, session tokens, administrative actions, and records of access to sensitive functions.
4.3 Information from third parties
- Business-contact and firmographic data from lawful B2B data providers and enrichment services.
- Publicly available sources, including company registries, maritime directories, IMO and vessel registries, trade publications and professional networking platforms.
- Referrals and introductions from partners, resellers, implementation consultants and existing Customers.
- Identity, sanctions-screening and credit-check outputs from compliance and financial-crime screening providers (see Section 5.9).
- Single sign-on identity providers, such as Microsoft Entra ID or Google Workspace, where a Customer elects federated authentication.
4.4 Data we do not seek
We do not intentionally collect, and ask you not to submit through the Website, special-category or sensitive personal data — including health, biometric, genetic, racial or ethnic origin, religious belief, political opinion, trade-union membership, sexual orientation or criminal-record data. Sensitive data of the kind that necessarily arises in ship management — for example seafarer medical fitness certificates, next-of-kin details, passport and seafarer’s identity document data, drug-and-alcohol test outcomes, and disciplinary records — is processed only within the Platform, as Customer Data, on the Customer’s instructions and under the DPA, and never for our own purposes.
4.5 Children
The Website and the Platform are intended solely for business use by adults. We do not knowingly collect personal data from any person under the age of 18, and we do not sell or share the personal data of minors. Where a Customer lawfully records dependent or next-of-kin information (which may relate to minors) within a crew or welfare module, that data is Customer Data processed on the Customer’s instructions and lawful basis. If we become aware that we have inadvertently collected data of a child for our own purposes, we will delete it promptly.
5. Why we process personal data (purposes and legal bases)
The legal bases below are expressed in GDPR / UK GDPR terms. Where another law applies, we rely on the corresponding basis available under that law — consent, performance of a contract, legal obligation, or a legitimate or specified use.
| # | Purpose | Legal basis |
|---|---|---|
| 5.1 | Responding to enquiries, demo requests and RFP/RFI submissions | Legitimate interests; steps prior to entering a contract |
| 5.2 | Negotiating, concluding and administering subscription agreements | Performance of a contract |
| 5.3 | Provisioning Customer deployments, issuing credentials, onboarding and training users | Performance of a contract |
| 5.4 | Providing support, incident response, bug fixing and service communications | Performance of a contract; legitimate interests |
| 5.5 | Billing, invoicing, collections, tax and statutory accounting | Performance of a contract; legal obligation |
| 5.6 | Operating, securing, monitoring and improving the Platform; capacity planning; developing new features | Legitimate interests |
| 5.7 | Marketing communications, newsletters, product announcements and event invitations | Consent, or legitimate interests for existing business contacts, with opt-out in every case |
| 5.8 | Website analytics, personalisation and advertising measurement | Consent, where required for non-essential cookies |
| 5.9 | Sanctions, export-control, anti-money-laundering, anti-bribery and fraud screening — including screening of Customers, their beneficial owners, vessels and counterparties against OFAC, EU, UK, UN and other applicable designated-party lists | Legal obligation; legitimate interests |
| 5.10 | Enforcing our terms, protecting our rights, and establishing, exercising or defending legal claims | Legitimate interests; legal obligation |
| 5.11 | Corporate transactions such as financing, audit, merger, acquisition or restructuring | Legitimate interests |
| 5.12 | Recruitment and vendor onboarding | Legitimate interests; pre-contractual steps; legal obligation |
Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that our interests do not override your rights and freedoms. You may request a summary of that assessment at admin@aquina.ai.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and may mean we can no longer provide certain features or communications.
6. Automated processing, analytics and artificial intelligence
The Aquina Ship OS Platform includes analytical, predictive and AI-assisted features — for example voyage optimisation, fuel-consumption and emissions estimation, maintenance prediction, document extraction, anomaly detection, crew-planning suggestions and natural-language assistance.
We commit to the following:
- No solely automated decisions with legal effect. Aquina does not use automated processing to make decisions about individuals that produce legal effects or similarly significant effects on them without human involvement. Where a Customer configures the Platform to support decisions about its own personnel, such as appraisal scoring or promotion readiness, the Customer is responsible for maintaining meaningful human review and for any notice, consent or impact assessment required by law.
- Training data. We do not use identifiable Customer Data to train, fine-tune or improve machine-learning models that are made available to other Customers, unless the Customer has given specific, separate, written consent. We may use aggregated, de-identified or statistically derived data that cannot reasonably be re-identified — for example fleet-level benchmarks or anonymised performance baselines — for product improvement and benchmarking, as further described in our Terms and Conditions.
- Third-party AI services. Where a Platform feature uses a third-party model provider, that provider is engaged as a sub-processor under contractual terms that prohibit use of Customer Data for the provider’s own model training, and is listed in Section 9.
- Explainability. On request through a Customer, we will provide a plain-language description of the logic, key inputs and known limitations of an AI-assisted feature.
- Human authority at sea prevails. Platform outputs are decision-support only. They do not override the judgement and overriding authority of the Master, the requirements of SOLAS, COLREG, MARPOL, the ISM Code, class rules or flag-state instructions. See the corresponding disclaimer in our Terms and Conditions.
7. Disclosure of personal data
We do not sell personal data, and we do not rent, trade or otherwise monetise it. We disclose personal data only as follows.
7.1 Within our group. To our affiliates and subsidiaries, where they perform delivery, support, engineering or administrative functions on our behalf, subject to intra-group data-transfer agreements.
7.2 To service providers and sub-processors. To vetted vendors who process data on our behalf under written contracts imposing confidentiality, security and use-limitation obligations at least as protective as those in this Policy. See Section 9.
7.3 To the relevant Customer. If you are a user of a Customer’s deployment, your account, activity and audit data is visible to that Customer’s administrators. Each Customer’s deployment is logically segregated: no Customer can access another Customer’s data.
7.4 To professional advisers. To our auditors, lawyers, insurers, bankers and accountants, bound by professional or contractual confidentiality obligations.
7.5 To authorities and in legal process. Where required by applicable law, court order, subpoena, regulator, tax authority, flag administration, port state control, or lawful government request. We will, unless legally prohibited, notify the affected Customer before disclosing Customer Data and will use reasonable efforts to challenge requests that appear overbroad or unlawful.
7.6 In corporate transactions. To an actual or prospective acquirer, investor, or their advisers in connection with a merger, acquisition, financing, reorganisation or sale of assets, under confidentiality obligations. If personal data is transferred as part of a completed transaction, we will notify affected individuals or Customers, and the acquirer will remain bound by materially equivalent protections.
7.7 To protect rights and safety. Where necessary to prevent fraud, investigate a security incident, protect our legal rights or property, or protect the life or safety of any person — including in response to a maritime emergency, distress situation, or a search-and-rescue coordination request from a competent authority.
7.8 With your consent or at your direction, including where you instruct an integration between the Platform and a third-party system.
8. Your rights
Subject to applicable law and to verification of your identity, you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it, together with a summary of processing.
- Correction — have inaccurate or incomplete data rectified.
- Erasure or deletion — request deletion where the data is no longer necessary, consent is withdrawn, or processing is unlawful.
- Restriction — request that we limit processing in defined circumstances.
- Objection — object to processing based on legitimate interests, and object at any time to direct marketing.
- Portability — receive data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
- Withdraw consent — at any time, where consent is our basis.
- Not be subject to a decision based solely on automated processing that has legal or similarly significant effects.
- Non-discrimination — we will not deny service, charge different prices or provide a different quality of service because you exercised a privacy right.
- Complain — to us, and to a supervisory or regulatory authority.
8.1 How to exercise your rights. Email admin@aquina.ai with the subject line “Data Rights Request”, describing the right you wish to exercise. We may ask for information reasonably necessary to verify your identity, and will not use that information for any other purpose.
8.2 Response times. We will respond within thirty (30) days as a general standard; within one month for GDPR and UK GDPR requests, extendable by two further months for complex or numerous requests with notice to you; and within forty-five (45) days for requests under US state privacy laws, extendable once by a further forty-five (45) days with notice.
8.3 Authorised agents and fees. You may use an authorised agent to submit a request where applicable law permits, provided the agent supplies written authorisation and we can verify your identity. We do not charge a fee unless a request is manifestly unfounded, excessive or repetitive, in which case we will tell you the reasonable fee before proceeding.
8.4 Notice to United States residents. For the twelve months preceding the date of this Policy, the categories of personal information described in Section 4 have been collected for the purposes described in Section 5 and disclosed to the categories of recipients described in Sections 7 and 9. We confirm that:
- we do not sell personal information, and do not share personal information for cross-context behavioural advertising, as those terms are defined under the CCPA/CPRA;
- we do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit;
- where we process Customer Data, we act as a Service Provider or Processor and are contractually restricted from retaining, using or disclosing it other than to perform the Services;
- you may exercise the rights to know, access, correct, delete, opt out and limit as set out above, and appeal a denial by replying to our decision notice; and
- we honour opt-out preference signals, including Global Privacy Control, where technically detected.
8.5 Requests relating to Customer Data. As explained in Section 2.2, please direct these to the Customer that controls the data. We will assist that Customer in responding, as required by the DPA.
8.6 Marketing opt-out. Use the unsubscribe link in any marketing email, or write to admin@aquina.ai. We will continue to send essential service, security, billing and contractual notices, which are not marketing.
8.7 Complaints. Contact us first at admin@aquina.ai. We will acknowledge within 72 hours and endeavour to resolve within 30 days. If you remain dissatisfied, you may complain to your local supervisory authority — including, in the United Kingdom, the Information Commissioner’s Office; in the EEA, your national data protection authority; in Singapore, the Personal Data Protection Commission; in India, the Data Protection Board of India; and in California, the California Privacy Protection Agency or the Attorney General.
8.8 Representatives. Where we are required to appoint a representative in the European Union or the United Kingdom under Article 27 of the GDPR or UK GDPR, or a Grievance Officer under the Digital Personal Data Protection Act, 2023, details will be published in this Section and notified to affected Customers. Until then, all enquiries should be sent to admin@aquina.ai.
9. Sub-processors and service providers
We engage the following categories of sub-processor. A current, authoritative list is available to Customers on request at admin@aquina.ai.
| Category | Purpose | Provider | Location |
|---|---|---|---|
| Cloud infrastructure and hosting | Compute, storage, database, backup | Amazon Web Services | Default: Asia Pacific (Mumbai), with Asia Pacific (Singapore) as its disaster-recovery region; European Union, United Kingdom and Middle East regions available per Deployment |
| Content delivery and DDoS protection | Availability, edge security | Cloudflare | Global edge network |
| Website hosting and web fonts | Serving this Website; delivering the typefaces it uses | GitHub Pages; Google Fonts | Global edge network / United States |
| Email delivery | Transactional and notification email | Transactional email provider | United States / EU |
| CRM and marketing automation | Sales pipeline, marketing communications | CRM provider | United States |
| Support desk and ticketing | Support case management | Support platform provider | United States |
| Product analytics and error monitoring | Usage analytics, crash and error reporting | Analytics and monitoring providers | United States / EU |
| Identity and access management | Authentication, single sign-on, multi-factor authentication | Identity provider | United States |
| Payment and invoicing | Subscription billing and payment processing | Payment processor | United States |
| AI and machine-learning services | AI-assisted Platform features | Enterprise model providers, contractually barred from training on Customer Data | United States |
| Maritime data services | AIS and position, weather, port, vessel-particulars and bunker-price data | Maritime data providers | Varies by provider |
| Sanctions and compliance screening | Designated-party and beneficial-ownership screening | Screening provider | United States / EU |
Change notification. For Customers, we will give at least thirty (30) days’ prior written notice, by email and by updating the list referred to above, before adding or replacing a sub-processor that processes Customer personal data. A Customer may object on reasonable data-protection grounds within that period; if we cannot offer a commercially reasonable alternative, the Customer may terminate the affected subscription without penalty for the unused prepaid term.
10. Processor commitments to Customers
Where we act as processor for Customer Data, we commit — and where required contract in a DPA — to:
- Process Customer Data only on the Customer’s documented instructions and for the purpose of providing the Services.
- Not use Customer Data for our own purposes, including advertising, resale, profiling or cross-customer model training.
- Impose confidentiality obligations on all personnel with access, and grant access strictly on a need-to-know, least-privilege basis.
- Implement and maintain the technical and organisational measures described in Section 11.
- Engage sub-processors only in accordance with Section 9, and remain responsible for their performance.
- Assist the Customer with data-subject requests, data protection impact assessments and regulator consultations.
- Notify the Customer without undue delay, and in any event within seventy-two (72) hours, of becoming aware of a personal data breach affecting their data, with the information reasonably available to us.
- Make available information necessary to demonstrate compliance, and permit audits or accept independent third-party audit reports, on reasonable notice and subject to confidentiality.
- On termination, at the Customer’s election, return Customer Data in a standard machine-readable format or securely delete it — see Section 13.
- Notify the Customer if we believe an instruction infringes applicable data protection law.
11. Security
We maintain a documented information security programme appropriate to the risks of maritime enterprise software. Measures include:
- Encryption: TLS 1.2 or higher for data in transit; AES-256 or equivalent for data at rest; encrypted backups.
- Deployment isolation: logical segregation of Customer Data, with enforced deployment-scoped access controls at the application and data layers.
- Access control: role-based access control, least privilege, mandatory multi-factor authentication for administrative and privileged access, just-in-time elevation, and periodic access reviews.
- Secure development: code review, dependency and container scanning, static and dynamic analysis, secrets management, and segregated development, staging and production environments.
- Testing: independent penetration testing at least annually and after material architectural change; ongoing vulnerability scanning with defined remediation timelines by severity.
- Monitoring: centralised logging, tamper-resistant audit trails, intrusion detection and anomaly alerting.
- Resilience: automated backups, tested restore procedures, documented recovery point and recovery time objectives, and business continuity and disaster recovery plans.
- Personnel: background verification where lawful, confidentiality undertakings, mandatory security and privacy training, and prompt de-provisioning on role change or exit.
- Vendor management: security due diligence and contractual safeguards for all sub-processors.
- Incident response: a documented plan with defined roles, severity classification, forensic preservation, notification workflows and post-incident review.
We align our controls with recognised frameworks including ISO/IEC 27001 and SOC 2, and, for shipboard and shore integration, with the cyber-risk-management expectations of IMO Resolution MSC.428(98) and IACS UR E26 and E27. Our current certification and audit-report status is available to Customers under a non-disclosure agreement on request at admin@aquina.ai.
No system is perfectly secure. While we apply industry-recognised safeguards, we cannot guarantee absolute security. You are responsible for safeguarding your credentials, enabling available security features, and notifying us immediately at admin@aquina.ai of any suspected compromise.
Breach notification. Where a personal data breach is likely to result in a risk to individuals, we will notify the affected Customer and, where we are controller, the affected individuals and the competent authority, within the timeframes required by applicable law — including the seventy-two hour requirement under the GDPR and UK GDPR, and applicable United States state breach-notification statutes.
12. Cookies and tracking technologies
What is true of this Website today. This Website is a static informational site. It sets no cookies, runs no analytics or advertising tags, and asks for no consent, because it has nothing to consent to. It is served by GitHub Pages, which records standard server-log information including your IP address, and it loads its typefaces from Google Fonts, which receives your IP address as part of that request. The categories below describe the cookies used in the Aquina Ship OS Platform and in any future Website features; a consent banner and a Cookie Preferences control will be present before any non-essential cookie is set.
We use cookies and similar technologies, including pixels, local storage and SDKs, in the following categories:
| Category | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Authentication, session management, load balancing, security, CSRF protection, consent-preference storage | No |
| Functional | Language, region, time-zone and interface preferences; chat widget | Yes |
| Analytics and performance | Understanding traffic, feature usage and page performance | Yes |
| Marketing and advertising | Campaign attribution, retargeting, conversion measurement | Yes |
Where non-essential cookies are in use, you will be presented on your first visit with a consent banner allowing you to accept all, reject all non-essential, or select categories individually. You may change your choices at any time via the Cookie Preferences link in the Website footer, or through your browser settings. Rejecting non-essential cookies will not prevent access to the Website, but some features may not function optimally.
We honour Global Privacy Control signals where technically detected. Because there is no industry consensus on browser “Do Not Track” headers, we do not currently respond to DNT.
Cookies used within an authenticated Customer deployment are limited to strictly necessary and functional categories.
13. Data retention
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law.
| Data | Indicative retention |
|---|---|
| Website enquiry and lead data, where no contract is concluded | 24 months from last interaction |
| Marketing consent and preference records | Duration of consent, plus 3 years as proof of consent |
| Customer account and administration data | Term of subscription, plus 3 years |
| Contracts, invoices, tax and statutory accounting records | 7 years, or longer where applicable tax or corporate law requires |
| Support tickets and correspondence | 3 years from closure |
| Security, authentication and audit logs | 12 months, extended where required for an active investigation |
| Backups and snapshots | Rolling 35 days, overwritten in the ordinary cycle |
| Sanctions and compliance screening records | 5 years from the end of the business relationship, or longer where required by anti-money-laundering or export-control law |
| Recruitment data for unsuccessful applicants | 12 months from decision, or with consent for a future-opportunities pool |
| Cookie and analytics identifiers | Up to 13 months |
Customer Data is retained for the subscription term. On termination or expiry, we make Customer Data available for export for thirty (30) days, after which — unless the Customer instructs otherwise in writing or law requires retention — we securely delete it from active systems within sixty (60) days, and from backups within the ordinary backup expiry cycle, being up to a further ninety (90) days. Certain maritime records are subject to mandatory statutory retention, for example under the Maritime Labour Convention, 2006, MARPOL record-keeping requirements, or flag-state rules. It is the Customer’s responsibility to identify such records and export them, or instruct their retention, before deletion.
Where deletion is not technically feasible — for example in immutable archives or write-once audit stores — we will securely isolate the data, block further processing, and delete it on expiry of the relevant cycle.
14. International data transfers and regional hosting
We are established in the United States, our sub-processors operate globally, and our Customers operate vessels and offices worldwide. Personal data may therefore be transferred to, stored in, or accessed from countries other than your own, including the United States, Singapore, the United Arab Emirates, India, the European Economic Area and the United Kingdom.
Where we transfer personal data across borders, we rely on one or more of the following safeguards:
- the EU Standard Contractual Clauses (Commission Decision 2021/914) and, for United Kingdom transfers, the UK International Data Transfer Agreement or the International Data Transfer Addendum to the EU SCCs, which we offer to Customers as part of our DPA;
- an adequacy decision by the European Commission, the UK Government or another competent authority, where one applies;
- binding intra-group data transfer agreements;
- transfers permitted under the applicable law of the exporting jurisdiction, including Section 16 of the Digital Personal Data Protection Act, 2023 (India) and the transfer provisions of the Singapore Personal Data Protection Act; and
- your explicit consent, or necessity for the performance of a contract, where applicable.
We carry out transfer impact assessments where required, and apply supplementary technical measures — such as encryption with keys held in the originating region, and data-residency configuration — where a Customer requires them.
Regional hosting. Aquina is operated as a multi-region service, so that a Customer’s Deployment, and the personal data within it, can rest in the region that Customer requires. The default hosting region is Asia Pacific (Mumbai), with Asia Pacific (Singapore) as the disaster-recovery region for that Deployment. Further regions — including the European Union, the United Kingdom and the Middle East — are available, and where a Deployment is provisioned outside the default its disaster-recovery region is paired within the same geography. The region or regions applicable to a Deployment, and its data-residency commitment, are recorded in the applicable Order Form and do not change without the Customer’s agreement.
Customers with data-residency, data-sovereignty or flag-state requirements should raise them before onboarding, so the Deployment is provisioned in the right region from the outset; migrating a live Deployment between regions is a Professional Service, not a configuration change.
You may request a copy of the relevant transfer mechanism, with commercial terms redacted, at admin@aquina.ai.
15. Contact
Rhumb Inc (operating as Aquina.ai)
A Delaware corporation | Delaware State File Number 10727282
Registered office: 16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, United States of America
All privacy enquiries, data rights requests, security reports and complaints:
admin@aquina.ai
Please mark your message “Data Rights Request”, “Security”, or “Privacy Complaint” as appropriate, so we can route it correctly. We acknowledge complaints within 72 hours and endeavour to resolve them within 30 days.
16. Changes to this Policy
We may update this Policy to reflect changes in our services, technology, legal requirements or business practices. The “Last updated” date at the top will always show the current version.
- For material changes — for example a new purpose of processing, a new category of recipient, or a change in legal basis — we will provide at least thirty (30) days’ prior notice by email to registered Customer administrators, and by a prominent notice on the Website, before the change takes effect.
- For non-material changes, the updated Policy takes effect on publication.
Where a change requires your consent under applicable law, we will obtain it before applying the change to your data. Continued use of the Website or the Platform after the effective date of a change constitutes acceptance of the updated Policy, except where consent is legally required.
Archived versions are available on request at admin@aquina.ai.
17. Order of precedence
If there is any conflict between this Policy and an executed Master Subscription Agreement, Order Form or Data Processing Addendum between Aquina and a Customer, the executed agreement prevails in respect of Customer Data. This Policy continues to govern our controller-side processing and the Website in all cases.