Privacy Policy
Last Updated: June 2026
1. Introduction
MarineDesk AI is an enterprise procurement workflow platform operated by MarineDesk AI Private Limited. This Privacy Policy explains how we collect, use, and protect your information when you use our maritime procurement software, including the owner portal, supplier portal, email intelligence, document intelligence, and procurement workflow management features.
By using MarineDesk AI, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
We collect the following types of information to provide our procurement services:
- User Accounts: Name, email address, role (Super Admin, Admin, Procurement, Supplier, Viewer), and authentication credentials
- Company Information: Company name, address, contact details, and vessel information
- RFQ Data: Request for Quotation details, line items, specifications, vessel requirements, and delivery terms
- Quotations: Supplier quotations, pricing, terms, and response data
- Purchase Orders: PO numbers, supplier details, item specifications, quantities, and approval status
- Invoices: Proforma invoices, commercial invoices, final invoices, and payment terms
- Packing Lists: Shipment packing details, item descriptions, and quantities
- Shipments: AWB/BL numbers, tracking information, delivery status, and ETA data
- Workflow Data: Procurement workflow events, status transitions, approval records, and task assignments
- Audit Logs: System access logs, action history, IP addresses, and user activity records
- Email Metadata: Email headers, sender/recipient information, timestamps (for email intelligence processing)
- Uploaded Documents: PDFs, spreadsheets, images, and other files uploaded for processing and storage
3. How We Use Information
We use your information for the following purposes:
- Workflow Processing: Manage RFQ-to-delivery procurement workflows, track status, and coordinate approvals
- Supplier Collaboration: Enable supplier portal access, RFQ responses, and PO acceptance workflows
- Procurement Analytics: Generate supplier performance metrics, vessel analytics, and spend analysis
- Historical Intelligence: Build pricing intelligence, maker analytics, and historical procurement data
- Budget Intelligence: Track procurement budgets, spending patterns, and cost optimization insights
- Email Intelligence: Process email attachments, extract procurement data, and automate document ingestion
- Document Extraction: Extract line items, specifications, and metadata from uploaded documents
- System Security: Authenticate users, authorize access, and detect unauthorized activity
- Audit Logging: Record all system actions for compliance, security, and operational auditing
4. AI Processing Disclosure
MarineDesk AI uses artificial intelligence for the following purposes:
- Email Intelligence: Automatic extraction of RFQ data from email attachments and body content
- Attachment Intelligence: Classification and parsing of uploaded documents (PDFs, spreadsheets, images)
- Document Classification: Automatic categorization of procurement documents (invoices, packing lists, etc.)
- Entity Extraction: Extraction of line items, part numbers, quantities, and specifications from documents
Important: Human Approval Required
MarineDesk AI does not perform autonomous purchasing actions. The following always require human approval:
- Purchase Order creation
- Supplier selection and award
- Payment release and approval
- Document approval (OC, PI, CI, PL, FI, DN)
AI-generated suggestions and extracted data are presented for human review and approval before any workflow action is taken.
5. Supplier Portal Data
Suppliers using the MarineDesk supplier portal should be aware of the following:
- Supplier Submissions: Quotations, pricing, and terms submitted through the supplier portal are stored and shared with the requesting owner
- Uploaded Documents: Documents uploaded by suppliers (quotations, certificates, etc.) are stored in our secure document management system
- RFQ Responses: All RFQ responses and communications are logged for audit and workflow tracking purposes
- PO Acceptance Records: Supplier acceptance of Purchase Orders is recorded and timestamped for compliance
- Token-Based Access: Supplier portal access is secured via unique tokens and does not require account creation
6. Security Measures
We implement the following security measures to protect your data:
- JWT Authentication: Secure JSON Web Token-based authentication for all user sessions
- Role-Based Access Control: Granular permissions (Super Admin, Admin, Procurement, Supplier, Viewer) restrict data access
- Company Isolation: Data is strictly isolated by company to prevent cross-tenant data access
- Audit Logging: All system actions are logged for security monitoring and compliance
- Upload Security: File type validation, MIME type checking, size limits, and malware scanning for all uploads
- HTTPS Encryption: All data in transit is encrypted using TLS/HTTPS
- Security Headers: Implementation of X-Frame-Options, X-Content-Type-Options, Content-Security-Policy, and other security headers
- Supplier Token Hardening: Secure token-based access for supplier portals with expiration and revocation
7. Data Retention
We retain data according to the following policies:
- Active Workflow Records: RFQs, POs, invoices, and related documents are retained while workflows are active
- Archived Workflow Records: Completed workflows are retained for historical analytics and compliance purposes
- Audit Logs: System audit logs are retained for security monitoring and compliance auditing
- Uploaded Files: Documents uploaded to the platform are retained according to customer retention policies
- Account Data: User account data is retained until account deletion request is processed
8. User Rights
You have the following rights regarding your data:
- Access: Request a copy of your personal data and account information
- Correction: Request correction of inaccurate or incomplete personal data
- Deletion: Request deletion of your account and associated personal data (subject to retention requirements)
- Export: Request export of your data in a machine-readable format
- Objection: Object to processing of your personal data for specific purposes
To exercise these rights, contact us at privacy@marinedesk.in
9. International Data
MarineDesk AI operates globally with a focus on maritime operations:
- Singapore: Primary data center and operations hub
- India: Development and support operations
- UAE: Regional operations for Middle East maritime sector
- Global Maritime Operations: Data processing for vessels and operations worldwide
Data may be transferred and processed in jurisdictions where we have operations. We ensure appropriate safeguards are in place for international data transfers.
10. Contact
For questions about this Privacy Policy or your data privacy rights, please contact:
Email: privacy@marinedesk.in
Company: MarineDesk AI Private Limited
This Privacy Policy is effective as of June 2026 and may be updated periodically. Significant changes will be communicated to users via email or platform notification.