1. Data controller and data protection roles
MARE RISK LIMITEDBusiness Registration No. 79105162
Unit B, 11/F, 23 Thomson Road
Wan Chai, Hong Kong SAR
Telephone: +351 926 857 388 / +39 351 4607099
Email: info@marerisk.com
MARE RISK LIMITED ("we", "us", "our") is the data controller for our websites, business inquiries, marketing contacts and our own commercial relationships. We determine the purposes and means of that processing.
Where a client transmits or uploads personal data through our M.A.R.E.™ platform or a related service, including fleet records, crew details, voyage data, field reports and incident submissions, we act as processor on that client's documented instructions. The client remains controller of that data and handles requests from its own personnel in the first instance. The applicable service agreement and its data processing terms govern that relationship.
We engage operational service providers to deliver analyst, monitoring, control room and support functions. Each acts only on our instructions and is bound by written data processing and confidentiality terms.
2. Scope and applicable law
This policy applies to our websites, contact channels and online services that link to it. A client agreement, product-specific notice or employment notice may add information for a particular relationship.
We are registered in Hong Kong SAR and process personal data under the Personal Data (Privacy) Ordinance (Cap. 486). Our services reach clients and individuals in the European Economic Area, the United Kingdom and Asia. Where the General Data Protection Regulation, the UK GDPR or another data protection law applies to a particular individual or activity, we apply that law and, where the standards differ, the one that gives the individual the stronger protection.
External websites apply their own privacy policies once you leave a M.A.R.E.™ domain.
3. Personal data we collect
Information you provide
We may collect your name, employer, role, business contact details, inquiry, service interests, correspondence and information you submit through a form, email, phone call or client service.
Service and website data
Our systems and providers may process IP address, device and browser details, requested pages, dates and times, referral data, consent choices, security events, account identifiers and service activity.
Business and compliance data
Where relevant to a service or legal duty, we may process company details, contract records, billing data, vessel or voyage information, due diligence material and records needed for sanctions, fraud, security or regulatory checks.
4. Purposes and legal bases
| Purpose | Data used | Legal basis |
|---|---|---|
| Respond to inquiries and arrange demonstrations | Identity, role, contact details and inquiry | Steps requested before a contract and legitimate interests in business communications |
| Provide and support services | Account, contract, operational and correspondence data | Contract performance, legitimate interests and legal obligations |
| Protect websites and services | Technical, access and security data | Legitimate interests in security, resilience and abuse prevention |
| Meet legal and compliance duties | Identity, business, transaction and due diligence records | Legal obligations and legitimate interests in risk management |
| Send optional communications | Name, business contact details and preferences | Consent where required, or legitimate interests where permitted |
| Improve websites and services | Usage, feedback and service data | Legitimate interests |
7. International transfers
We operate internationally. Personal data may be processed in Hong Kong SAR, the European Economic Area, the United Kingdom and other countries where our providers host or support the services, including the United States.
Where data protection law requires a transfer safeguard, we rely on an adequacy decision, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or another lawful mechanism, supported by a transfer risk assessment where required. You may request information about the safeguard applied to a specific transfer.
8. Data retention
We keep personal data only for the period needed for the purposes described above. The periods below are indicative. A legal hold, an active dispute or a mandatory retention duty may extend them.
| Record | Indicative period |
|---|---|
| Inquiries that do not lead to a contract | 24 months from last contact |
| Client contract, account and correspondence records | Duration of the relationship, then 7 years |
| Accounting, billing and tax records | 7 years, or the longer period local law requires |
| Website, access and security logs | 12 months |
| Consent and cookie preference records | Duration of the choice, then 24 months as proof of consent |
| Client data processed on the platform | As instructed by the client under the service agreement |
We delete or anonymize personal data when we no longer need it.
9. Your privacy rights
Depending on the law that applies to you, you may request access, correction, deletion, restriction or a copy of your personal data in a structured, commonly used format. You may object to certain processing and withdraw consent where processing relies on consent.
We may ask for information to verify your identity, and we respond within the period the applicable law sets. If you are not satisfied with the outcome you may complain to a supervisory authority. In Hong Kong SAR this is the Office of the Privacy Commissioner for Personal Data. In the European Economic Area and the United Kingdom you may complain to the authority for your place of residence, your place of work or the place of an alleged infringement.
10. Security, automated processing and business use
We use technical and organizational controls designed to protect personal data against loss, misuse and unauthorized access, including access control, encryption in transit, segregation of client environments, logging and supplier security review. No internet service can remove all risk.
Our M.A.R.E.™ platform generates automated alerts, risk scores and route assessments. These operate on vessel, voyage, position and incident data rather than on profiles of individuals. We do not use website or platform data to take a decision based solely on automated processing that produces legal or similarly significant effects for an individual. An analyst reviews each alert in its operational context before it is relied on, and the AI Governance page explains the wider control principles.
Our websites and services are intended for businesses, shipowners, operators and maritime professionals. They are not directed at individuals under 16, and we do not knowingly collect personal data from them. If you believe a minor has provided personal data through our websites, contact us and we will delete it.
11. Contact and changes
Send privacy questions or rights requests to info@marerisk.com, or call +351 926 857 388 or +39 351 4607099. We update this policy when our processing or legal duties change. The date at the top identifies the current version.
