Privacy Policy
Version 1.2 — Effective date: 10 March 2026
This policy explains how Near Max Ltd collects, uses, and protects your personal data when you use Marine Inspect.
This policy explains how Near Max Ltd collects, uses, and protects your personal data when you use Marine Inspect.
1. Who We Are (Data Controller)
The data controller for your personal data is Near Max Ltd, a company incorporated in England and Wales (Company No. 09222812), trading as Marine Inspect.
Contact: support@marine-inspect.co.uk
If you have any questions about how we handle your data, or wish to exercise any of your rights, please contact us at the address above.
2. What Personal Data We Collect
2.1 Account data
When you register, we collect: your name, email address, and authentication identifiers. This data is necessary to create and manage your account.
2.2 Professional profile data
You may optionally provide your professional name, contact details, qualifications, and branding assets (such as a company logo) for inclusion in generated reports.
2.3 Survey and inspection data
The core purpose of the Service is to record and process marine survey data. This may include vessel details, inspection findings, photographs, voice notes, and location data captured during surveys. This data may contain personal data relating to vessel owners and other third parties (see section 6).
2.4 Payment data
When you make a purchase, we collect your billing name and address. Payment card details are processed directly by Stripe, Inc. We do not store your full card number, CVV, or expiry date.
2.5 Usage and technical data
We automatically collect: IP addresses, device identifiers, browser type, operating system, pages visited, feature usage, session metadata, and access logs. This data is used for security, fraud prevention, and service improvement.
2.6 Communications
When you contact us via email or the in-app support form, we retain the content of your communications and your contact details to respond and to maintain a record of the interaction.
3. How We Use Your Data and Our Lawful Basis
| Purpose | Lawful basis (UK GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b)) |
| Providing the Service (survey tools, report generation, storage) | Performance of a contract (Art. 6(1)(b)) |
| Processing payments and managing subscriptions | Performance of a contract (Art. 6(1)(b)) |
| Sending transactional emails (account notices, payment receipts) | Performance of a contract (Art. 6(1)(b)) |
| Security monitoring, fraud prevention, and abuse detection | Legitimate interests (Art. 6(1)(f)) |
| Maintaining access logs and audit trails | Legitimate interests (Art. 6(1)(f)) / Legal obligation (Art. 6(1)(c)) |
| Maintaining report verification records (surveyor name, vessel, hashes, approval timestamp, email) | Legitimate interests (Art. 6(1)(f)) — establishment/exercise/defence of legal claims (Art. 17(3)(e)) |
| Retaining financial records | Legal obligation — Companies Act 2006 (Art. 6(1)(c)) |
| Responding to support requests | Legitimate interests (Art. 6(1)(f)) |
| Improving the Service | Legitimate interests (Art. 6(1)(f)) |
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Sub-processors
To deliver the Service, we share data with the following third-party sub-processors. Each is bound by appropriate data processing agreements and provides adequate safeguards for your data.
| Sub-processor | Role | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | USA (SCCs / UK IDTA) |
| Amazon Web Services (AWS) | Cloud infrastructure, database, and file storage | UK (eu-west-2, London) |
| Clerk, Inc. | User authentication and identity management | USA (SCCs / UK IDTA) |
| Anthropic, PBC | AI-assisted report generation (processes survey content you submit) | USA (SCCs / UK IDTA) |
| PostHog, Inc. | Product analytics and usage tracking | Germany, EU (Frankfurt) — EEA (UK IDTA / SCCs) |
SCCs = Standard Contractual Clauses. UK IDTA = UK International Data Transfer Agreement. These mechanisms ensure lawful transfer of personal data to countries outside the UK/EEA under UK GDPR.
We will notify you of any material changes to sub-processors. An up-to-date list is always available at this page.
5. International Data Transfers
Your core account data and survey data are stored on AWS infrastructure in the eu-west-2 (London) region and do not leave the UK. However, some sub-processors (Stripe, Clerk, and Anthropic) are based in the United States. Data transfers to these providers are covered by UK-approved Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA), ensuring your data receives adequate protection. Usage analytics events (page views, feature interactions) are transmitted to PostHog, Inc. and stored in the EU (Frankfurt, Germany). This transfer is covered by the UK International Data Transfer Agreement (IDTA). PostHog does not receive survey content — only anonymised interaction events such as page URLs and feature clicks.
6. Your Clients' Data — Your Responsibilities
When you use the Service to process personal data belonging to third parties (such as vessel owners or clients), you are the data controller for that data under UK GDPR. Near Max Ltd acts as your data processor. This means:
- You must have a lawful basis for collecting and storing your clients' personal data.
- You must provide appropriate privacy notices to your clients.
- You are responsible for responding to data subject requests from your clients.
A Data Processing Agreement (DPA) governing this relationship, as required by UK GDPR Art. 28, is available at marine-inspect.co.uk/dpa and is incorporated into the Terms & Conditions by reference.
7. Data Retention
| Data type | Retention period |
|---|---|
| Account data (profile, billing, credentials) | Deleted promptly on account closure |
| Survey and inspection records | 7 years from the date of each survey (retained in anonymised form for professional liability and legal compliance; see note below) |
| Report verification records | 7 years from the date of report approval (retained independently of account status; see note below) |
| Financial and transaction records | 7 years (Companies Act 2006) |
| Terms acceptance records | Duration of account + 6 years after closure |
| Access logs and audit trails | As long as necessary for security and legal compliance (minimum 12 months) |
| Support communications | 3 years from last interaction |
Note on payment processor records: On account deletion, your Stripe customer profile (including email address and stored payment methods) is deleted. Transaction records (charges, invoices, and payment history) are retained by Stripe for statutory accounting purposes in accordance with the Companies Act 2006. Near Max Ltd's obligation to retain financial records relates to these transaction records, not to your personal contact details.
Note on survey records: When you delete your account, your personal details (name, contact information, company data, and account identifiers) are removed immediately. Survey and inspection records — the technical findings themselves — are retained in anonymised form for up to 7 years. This is because marine survey reports may be relied upon in legal proceedings, professional liability claims, or regulatory matters years after the inspection. This retention is based on Near Max Ltd's legal obligations and legitimate interests under UK GDPR Art. 17(3)(b) and (e) and cannot be waived on request.
Note on report verification records: When you approve a report in Marine Inspect, the platform creates a separate verification record containing: your professional name, the vessel name and type, the survey date, cryptographic hashes of the survey and report, the approval timestamp, and your email address (used as an identity check in the public verification lookup). This record is held by Near Max Ltd in its capacity as data controller — it is not survey content and is not part of the anonymised survey record described above. Verification records are retained for 7 years from the date of report approval. They persist even if you close your account, because reports you approved may already have been relied upon professionally, and any loss adjuster or insurer must be able to verify them independently. This retention is based on Near Max Ltd's legitimate interests and legal obligations under UK GDPR Art. 6(1)(f) and Art. 17(3)(e) (establishment, exercise, or defence of legal claims). Verification records cannot be deleted on request. Your email address is held solely as a second-factor identity check and is not disclosed to third parties querying the verification system — it is used only to confirm that the person making the verification request knows the surveyor's professional contact details.
8. Cookies
The Marine Inspect web portal uses only the following cookies:
- Session and authentication cookies — set by our authentication provider to maintain your logged-in session. These are strictly necessary for the Service to function.
- Terms acceptance cookie — a first-party cookie that records whether you have accepted the current version of our Terms, to avoid redirecting you on every page load.
We also use PostHog for product analytics. PostHog sets one first-party cookie (ph_*_posthog, 365-day expiry) and uses browser localStorage to record anonymous usage events (page views, feature interactions). The Clerk user ID is included in these events so we can associate usage patterns with an account. No survey content or personal data beyond the user ID is transmitted to PostHog. No advertising or third-party tracking cookies are used. Under UK PECR, analytics cookies require consent unless they are strictly necessary; by continuing to use the Service you consent to this analytics cookie.
9. Your Rights
Under UK GDPR, you have the following rights in respect of your personal data held by Near Max Ltd:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data (subject to legal retention obligations).
- Right to data portability — request your data in a structured, machine-readable format.
- Right to restriction — request that we restrict processing of your data in certain circumstances.
- Right to object — object to processing based on legitimate interests.
To exercise any of these rights, please contact us at support@marine-inspect.co.uk. We will respond within one calendar month as required by UK GDPR. We may need to verify your identity before processing your request.
Note: deletion of your account and export of your data are also available directly through your account Settings page.
10. Right to Complain
If you believe we have not handled your personal data in accordance with UK GDPR, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
- Website: ico.org.uk
- Telephone: 0303 123 1113
- Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF
We would appreciate the opportunity to address your concerns before you contact the ICO, so please reach out to us first.
11. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or destruction. These include: encrypted data storage and transmission (TLS), access controls, activity logging and monitoring, and regular security reviews. However, no internet transmission is completely secure and we cannot guarantee absolute security.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by bumping the Terms & Conditions version, which triggers the in-app re-acceptance flow for all users. The current version is always available at this page.
Questions about this Privacy Policy? Contact us at support@marine-inspect.co.uk
