For BuyersFor Vendors

Privacy Policy

Effective date: 26 August 2026 · Previous version: 29 May 2025

1. Introduction

RECORDS MARINE - FZCO (“Records Marine”, “we”, “us” or “our”) prioritises your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, disclose and safeguard your personal information when you use our website recordsmarine.com (the “Site” or the “Platform”) or any related services. It also outlines your privacy rights and how applicable laws protect you.

We have designed this Policy to comply with the data protection law of the United Arab Emirates and, where applicable, the European Union’s General Data Protection Regulation (GDPR) and other privacy frameworks that apply to us.

By using our Site, you agree to the practices described in this Policy. If you do not agree with any part of this Policy, please refrain from using our Site or services.

Capitalised terms not defined here — including Buyer, Vendor, RFQ, Quotation, Uploaded Document, Extracted Data and Request Content — have the meanings given in our Terms & Conditions.

2. Who We Are

The Platform is operated by RECORDS MARINE - FZCO (Dubai Integrated Economic Zones), a UAE entity licensed to use the intellectual property of RECORDS MARINE IP HOLDINGS LTD (ADGM) for the purpose of operating the Platform. RECORDS MARINE IP HOLDINGS LTD is the owner of that intellectual property and does not operate the Platform. Both companies are established in the United Arab Emirates. Some of the technical infrastructure we use to run the Platform is located in other countries, as described in Section 11; that does not make either company established outside the UAE.

Company information

Platform operator and contracting party. RECORDS MARINE - FZCO, Trade Licence No. 60836, issued by the Dubai Integrated Economic Zones Authority. Registered address: Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates.

Party that issues invoices and receives payment. RECORDS MARINE - FZCO. Card payments are collected on its behalf by the third-party payment processor named at checkout.

Owner of the Platform intellectual property (licensor). RECORDS MARINE IP HOLDINGS LTD, incorporated in the Abu Dhabi Global Market as a private company limited by shares, Registered No. 27123. Registered address: Cloud Desk D08, 11th Floor, Al Sarab Tower, Abu Dhabi Global Market Square, Al Maryah Island, Abu Dhabi, United Arab Emirates.

Data controller. RECORDS MARINE - FZCO. RECORDS MARINE IP HOLDINGS LTD is neither a controller nor a processor of personal data collected through the Platform.

Contact. General enquiries: support@recordsmarine.com. Legal, IP and RFQ content or origin notices: legal@recordsmarine.com. General contact: contact@recordsmarine.com.

Both companies are established in the United Arab Emirates. Technical infrastructure used to operate the Platform is located in other countries, as described in the Privacy Notice; the location of that infrastructure does not change the place of establishment of either company. Details of hosting locations and cross-border transfers are set out in the Privacy Notice.

Controller. RECORDS MARINE - FZCO is the data controller for personal data collected via the Platform. It operates the Platform and determines the purposes and means of the processing described in this Policy — what data is collected, why, which processors are engaged and how long data is retained. Requests to exercise your rights, and any privacy complaint, should be addressed to it.

RECORDS MARINE IP HOLDINGS LTD is not a controller or processor of your personal data. It owns the intellectual property in the Platform and licenses it to RECORDS MARINE - FZCO. It does not operate the Platform, does not determine the purposes or means of any processing, and does not receive, access, store or process personal data collected through the Platform.

Registered office of the controller:

RECORDS MARINE - FZCO Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates Trade Licence No. 60836 (Dubai Integrated Economic Zones Authority)

Contact: legal@recordsmarine.com

Data protection contact: legal@recordsmarine.com

3. Personal Data We Collect

We collect and process the following types of personal data when you interact with the Platform:

Identity and contact information. Your name, company or organisation name, job title, postal address, email address and telephone number. If you register an account, we also collect login credentials.

Professional details. If you create a business profile or claim a company listing, we collect information about your company and your role, including company details, your title or position and business contact information.

Billing and payment data. Where you purchase a Subscription: billing name and address, VAT or tax identifiers, invoice records, the last four digits and expiry of a card, payment tokens, transaction identifiers, payment status and refund or chargeback records. Full card numbers are handled by our payment processors and are not stored by us.

Request Content, including Uploaded Documents. Where you use the RFQ feature, we process the content of your requests and any files you attach — for example requisitions, item lists, specifications, drawings, data sheets, spreadsheets and scanned or photographed documents — together with the Extracted Data we generate from them and the messages exchanged between Buyers and Vendors through the Platform. Request Content may contain personal data of your own personnel and of third parties, such as names, job titles, email addresses, telephone numbers, signatures and stamps, as well as vessel, voyage and commercial information. Section 5 explains how we process Uploaded Documents.

Usage data. Information on how you use the Platform, including technical data such as your IP address, browser type and version, device type, operating system, time zone and platform, and activity data such as pages viewed, features used, links clicked, search queries, requests sent and the dates and times of your visits.

Preferences and communication data. Your marketing and communication preferences and any other information you provide when communicating with us, including the content of emails or enquiries, feedback and other records of correspondence, and support or dispute records.

Third-party sources. We may receive information about you from third parties — for example if you authenticate through a third-party sign-in service, or if a business partner or referral source provides your details. We may also collect personal data made publicly available, such as business contact information on a company website, for the purpose of populating our directory of maritime service providers and our supplier outreach records.

Supplier outreach records. We maintain our own records of suppliers and their business contact details — including suppliers that are not registered on the Platform — which we use to distribute Requests for Quotation on behalf of Buyers. These records may contain the name, job title, business e-mail address and telephone number of individuals at those suppliers, collected from publicly available business sources, from the supplier itself, or from previous correspondence. Where we contact a supplier for this purpose we rely on our legitimate interests in operating a business-to-business sourcing service, and only where that legal basis is available to us; every such message identifies us and offers a way to decline further contact. If you are a supplier contact and do not wish to receive Requests for Quotation from us, contact legal@recordsmarine.com and we will remove you from those records.

We do not intentionally collect sensitive personal data (such as information about health, race, religion or biometric data) through the Platform, and we ask that you do not provide this type of information, including within an Uploaded Document. Our services are intended for adults and business entities; we do not knowingly collect personal data from children under the age of 18. If you believe a minor has provided us personal data, please contact us so we can remove it.

4. Cookies and Tracking Technologies

We use cookies and similar technologies to collect information automatically from your device. These help us understand how you use the Platform, personalise your experience and improve our services.

Cookies. Small text files placed on your browser or device. We use essential cookies to enable core functionality (such as keeping you logged in and retaining items in your request forms) and analytics cookies to understand user behaviour. Cookies may collect identifiers and usage information such as IP address, browser type and pages visited. You can control or delete cookies through your browser settings; disabling certain cookies may prevent some features from functioning.

Web beacons and pixels. Our emails and pages may contain small electronic files used to count users who visited a page or opened an email and for related statistics.

Analytics tools. We use third-party analytics services such as Google Analytics to collect information about Platform usage and performance. These use cookies and similar technologies to gather data about visitors, including pages visited, session duration, referral source and general location. Data may be transferred to and stored on the provider’s servers. You can opt out of Google Analytics using the Google Analytics Opt-out Browser Add-on or by disabling analytics cookies.

Tag management. We use a tag management tool to manage scripts and tags on the Platform. The tool itself does not collect personal data; data collected via tags it manages is governed by the respective tool’s policies.

User behaviour analytics. We may use user-experience analytics tools that provide heatmaps, session recordings and surveys. These may collect anonymised IP address, device type, browser information and usage patterns, with keystroke data masked.

Advertising and social media pixels. If we run advertising or social media campaigns we may use tracking pixels provided by advertising platforms. These collect information such as IP address, browser type and interactions on the Platform, and may use cookies. Data collected is pseudonymised. Use of such pixels is subject to the respective platform’s privacy policy, and you can often opt out through your account settings on those platforms.

Cloud hosting and services. The Platform and its databases are hosted on third-party cloud infrastructure. These providers may automatically collect technical information for security and performance monitoring, such as access logs including IP addresses, timestamps and errors. We have agreements in place requiring them to protect your data and use it only to provide the hosting service.

Client-side storage. We use modern web frameworks that may use your browser’s local storage for functional purposes, such as storing a session token, interface preferences or cached data. You can clear this at any time through your browser settings.

Security tools. We use security technologies including CAPTCHA services on forms to distinguish human users from bots, and firewall and monitoring services that screen traffic for malicious activity. These may analyse interactions with the Site and log device identifiers and IP addresses solely for security purposes.

Your choices. Where required by law we obtain your consent before using non-essential cookies or tracking tools, including via a cookie banner for users in the EU/EEA. You can also control cookies through your browser settings. This Section 4 describes the categories of cookies and similar technologies we use; if you have a specific question about any of them, please contact us.

5. Automated Processing of Uploaded Documents

Where you upload a document to the Platform in order to create a Request for Quotation, we process that document by automated means so that we can pre-fill the request form for you.

What the processing involves. Optical character recognition, text extraction, format conversion, language detection and translation, categorisation, and machine-learning or artificial-intelligence based structuring of the content into items, quantities, units and other fields (the “Extracted Data”).

What we process. The uploaded file itself, the text and images it contains, the Extracted Data derived from it, and technical metadata about the processing such as file type, size, timestamps and processing status. As noted in Section 3, uploaded documents may contain personal data of your own personnel or of third parties, as well as vessel and voyage information.

Legal basis. We process this data because it is necessary to perform the service you have requested (performance of a contract, or steps taken at your request before entering into a contract). Where we additionally use aggregated or de-identified information to measure and improve recognition quality, we rely on our legitimate interests, and only where that legal basis is available to us in your jurisdiction.

You remain in control of the outcome. Extracted Data is a draft. It is displayed to you for review, and you must check and confirm it before your request is sent. We do not send a request on your behalf on the basis of automated output alone. This processing does not involve any decision about you taken solely by automated means that produces legal effects or similarly significant effects concerning you.

Providers. We use third-party document-processing and AI/ML inference providers as our processors, under contracts that restrict them to processing on our instructions. We do not permit these providers to use your uploaded documents or Extracted Data to train their own or any third party’s models, and we limit them to the retention necessary to perform the processing. We currently use Anthropic PBC (the Claude API), United States, for the machine-learning based extraction and structuring of document content. Under Anthropic’s commercial terms, inputs and outputs submitted through the Claude API are not used to train Anthropic’s models unless we expressly opt in, and we do not opt in. Anthropic retains API inputs and outputs for a limited period under its commercial data-retention policy; we do not currently operate under a zero-data-retention arrangement with Anthropic. If we add or change a document-processing provider we will update this Policy.

Retention. We retain the uploaded document and the Extracted Data for as long as needed to create, send and administer the related request, and thereafter for the period stated in Section 9, after which the file and the Extracted Data are deleted or de-identified.

Please do not upload documents containing confidential, classified, export-controlled or special-category information, or material you are not entitled to share with the vendors you address and with our processors. You can always create a request manually instead of uploading a document.

6. How We Use Your Personal Data

Providing and improving services. To deliver our services and ensure the Platform functions correctly — creating and managing your account, enabling you to search for and connect with maritime suppliers and service providers, creating and processing RFQs, distributing them to selected suppliers on and outside the Platform, and handling Quotations, processing Uploaded Documents as described in Section 5, personalising your experience, and developing new features.

Subscriptions and billing. To process Subscription purchases, invoices, renewals, refunds, chargebacks and related accounting and tax records.

Communication. To communicate with you about your account or services, including administrative and transactional communications such as confirmations, invoices, technical notices, updates, security alerts and support messages, and to respond to your enquiries, support requests or feedback.

Marketing and newsletters. To send you news, updates and marketing communications about our services where you have consented or where otherwise permitted by law. You can opt out at any time using the unsubscribe link or by contacting us. We do not sell or rent your personal data to third-party marketers.

Analytics and service improvement. To analyse and understand how users interact with the Platform, troubleshoot issues, perform research and development, and improve functionality, security and usability — including measuring and improving the accuracy of automated document processing using aggregated or de-identified data.

Fraud detection and security. To monitor for suspicious or fraudulent activity and to detect, prevent and address threats, abuse or violations of our terms and policies, including verifying accounts and identities, investigating suspicious behaviour, and handling notices about the content or origin of an RFQ.

Legal compliance. To fulfil our legal and regulatory obligations, including finance and tax regulations, sanctions and export-control screening, maintaining required business records, responding to lawful requests by public authorities and complying with court orders. We may also use your data to enforce our Terms & Conditions or to protect our rights, privacy, safety or property, and those of our users and others.

Other purposes with consent. If we intend to process your personal data for a purpose not outlined in this Policy, we will explain that purpose at the time of collection and, if required by law, obtain your consent.

We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another compatible purpose permitted by law. If we need to use it for an unrelated purpose, we will notify you and explain the legal basis or seek your consent.

7. Legal Bases for Processing Personal Data

Consent. For example, before sending you marketing emails where required by law, or before setting non-essential cookies in jurisdictions that require opt-in consent. You may withdraw consent at any time; withdrawal does not affect the lawfulness of prior processing.

Contractual necessity. Where processing is necessary to enter into or perform a contract with you — including creating and managing your account, creating and processing your requests, distributing them to suppliers on your instruction as described in Section 8, processing Uploaded Documents as described in Section 5, and administering Subscriptions and payments.

Legal obligation. Where we must process personal data to comply with a legal obligation, such as retaining transaction records for tax or accounting purposes, sanctions screening, or responding to a lawful request from an authority.

Vital interests. In rare emergency circumstances, where processing is necessary to protect someone’s vital interests.

Public interest / official authority. As a private company we generally do not carry out tasks in the public interest; we would rely on this basis only if specifically legally authorised.

Legitimate interests. Where processing is necessary for our legitimate business interests and is fair, balanced and does not unduly impact your rights — for example securing the Platform, preventing fraud, improving our services and measuring the quality of automated document processing. We will not rely on legitimate interests in jurisdictions where that ground is not recognised, including where UAE data protection law does not permit it; in such cases we ensure another valid basis applies.

If you have questions about the legal basis for any specific processing, please contact us.

8. Sharing Your Personal Data with Third Parties

We do not sell your personal data. We may share it as follows:

Service providers and data processors. Cloud hosting, technical infrastructure, database and storage providers, analytics services, email and communication providers, customer support tools, payment processors, and IT or security vendors. These providers are bound by contracts requiring them to process personal data only on our instructions and to protect it in line with applicable privacy laws.

Document-processing and AI/ML providers. As described in Section 5, we engage processors to perform optical character recognition and automated structuring of Uploaded Documents. They are prohibited from using the content to train their own or any third party’s models. Section 5 names the provider we currently use.

Suppliers we distribute your RFQ to (independent controllers). A core purpose of Records Marine is to connect maritime buyers and suppliers. When you send an RFQ, we distribute the request and the contact and company details you provide — including any Uploaded Document and the confirmed Extracted Data — to potential suppliers, so that they can quote to you.

We select the recipients. Unless you use a recipient-selection feature that we expressly offer you, we choose which suppliers receive your RFQ, and you will not necessarily see or be told at the time who they are. Recipients may include suppliers registered on our Platform and suppliers who are not registered on it, whom we contact by e-mail or other channels outside the Platform using our own supplier records. Our legal basis for this disclosure is the performance of the service you asked us to provide: sending an RFQ is your instruction to us to obtain quotations on your behalf.

What this means for you. Please include in an RFQ only information you are willing to have disclosed to a supplier you have not individually approved, and only personal data you are entitled to disclose to such recipients. If you tell us in writing, we will identify the recipients to which a specific RFQ was distributed, to the extent we still hold that information.

Recipients are independent controllers. Each recipient decides for itself how it handles the data it receives and is responsible for its own compliance. We ask recipients to use an RFQ only in order to respond to it, but we do not control them and cannot guarantee their compliance.

Buyers (for Vendors). Where you are a Vendor, the content of your Quotations and your Business Profile information is shared with the Buyers to whom you respond, who act as independent controllers in respect of that information.

Affiliates and corporate group. We may share personal data with current or future affiliated companies. Access within our corporate group is on a need-to-know basis and subject to confidentiality obligations.

Business partners. Where we offer combined or co-branded services and you choose to engage with them, we may share information about you with the relevant partner, with your knowledge or as part of the service you are using.

Legal compliance and protection. We may disclose personal data where we believe in good faith that it is necessary to comply with a legal obligation, respond to valid requests by public authorities, protect our rights or those of our users, prevent or investigate possible wrongdoing, or act in urgent circumstances to protect personal safety.

Business transfers. In a merger, acquisition, restructuring, asset sale or insolvency proceeding, personal data may be among the transferred assets. We would require the recipient to commit to privacy protections substantially consistent with this Policy.

Where third parties act as our processors, they are subject to security and confidentiality obligations under data processing agreements. Where they act as controllers, we disclose only what is necessary and ensure an appropriate legal basis for the disclosure.

9. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting or reporting requirements.

Account and profile data. Retained while your account is active. After account closure or prolonged inactivity we delete or anonymise it within ninety (90) days, unless a longer period is required for legal reasons.

Request Content — RFQs, Quotations and messages. Retained for twenty-four (24) months from dispatch, so that both parties have an accurate record of their dealings and so that we can handle disputes and transmission complaints, after which it is deleted or de-identified.

Uploaded Documents and Extracted Data. The uploaded file is retained for twelve (12) months from upload. Extracted Data forming part of a sent RFQ is retained with that RFQ. Files uploaded but never sent are deleted after thirty (30) days.

Billing and payment records. Retained for the period required by applicable tax, accounting and audit law, which is currently seven (7) years from the end of the relevant tax period under UAE tax record-keeping rules (and five (5) years for VAT records, where the shorter period applies).

Marketing data. Retained until you opt out. After you unsubscribe we may keep your contact details on a suppression list to honour your opt-out.

Legal and compliance. We may retain data longer where required by law, to resolve disputes, or where subject to a legal preservation order.

When we no longer need personal data we securely erase or anonymise it. Disposal may involve permanent deletion from active systems, secure wiping of storage devices and destruction of physical documents. Due to legal or technical constraints we may not be able to remove data immediately from backups or archives; archived data continues to be protected and isolated from active use until deletion is possible.

If you have questions about retention for a particular type of data, please contact us.

10. Data Security

We have implemented technical and organisational measures to protect your personal information from unauthorised access, use, alteration, loss or disclosure, including:

Encryption. The Platform is accessible only over HTTPS, so information transmitted between your browser and our servers is encrypted using TLS. Where appropriate we also encrypt personal data at rest.

Access controls. Access to personal data is limited to those employees, agents, contractors and service providers with a business need to know, through role-based access controls, strong password policies, multi-factor authentication where possible and regular access reviews. Our team is trained on confidentiality and is contractually bound to protect personal data.

Secure infrastructure. Our Platform and databases are hosted on secure servers with firewall protection and monitoring. Security patches and software updates are applied regularly, and we employ malware protection and intrusion detection.

Testing and auditing. We periodically test and evaluate our security measures, including security assessments, vulnerability scans and penetration testing, and review our data handling practices and this Policy.

Organisational policies. We minimise the personal data we collect and keep, apply pseudonymisation or anonymisation where feasible, and maintain an incident response plan.

Uploaded documents. Please note that a document you upload is transmitted to the Vendors you select and processed by our document-processing providers. Do not upload confidential, classified, export-controlled or special-category material that you are not entitled to share with those recipients.

No method of transmission over the Internet or electronic storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal data we will act promptly to mitigate the impact and will notify you and the relevant authorities as required by law. Please use a unique and strong password, keep your credentials confidential, and notify us immediately if you suspect unauthorised access to your account or any security vulnerability.

11. International Data Transfers

Records Marine is established in the United Arab Emirates and the Platform is operated from there. Where the servers and services we use are located in another country, that reflects the location of our infrastructure and processors only; it does not change our place of establishment, the identity of the controller, or the law governing our agreements with you. Personal data collected through the Platform is stored and processed on Amazon Web Services infrastructure located in the European Union. Content submitted for automated document processing is additionally transmitted to Anthropic PBC in the United States, as described in Section 5. Data may also be accessed from the United Arab Emirates by our own personnel in the course of operating the Platform.

Transfers from the UAE. UAE data protection law imposes conditions on cross-border transfers. We transfer data out of the UAE only in compliance with those requirements — by transferring to countries recognised as providing an adequate level of protection, or by implementing specific safeguards such as contractual protections or, where required, your explicit consent. Our primary hosting is in the European Union, which maintains a data protection regime recognised as providing a high level of protection.

Transfers to the United States. Document content sent to Anthropic PBC for automated processing is transferred to the United States. That transfer is made under a data processing agreement incorporating the European Commission’s Standard Contractual Clauses.

Transfers from the EEA, UK or Switzerland. Where personal data is transferred to a country not deemed to provide an equivalent level of protection, we rely on the European Commission’s Standard Contractual Clauses or other approved transfer mechanisms, an adequacy decision where one applies, or a permitted derogation.

Other international access. Cloud services may route or temporarily store data in other jurisdictions, and our team or authorised contractors may need to access data remotely. Our data protection measures and this Policy apply regardless of location.

Your rights regarding transfers. If you are protected by GDPR or similar laws you may request details of the safeguards we have in place, including a copy of the relevant contractual clauses. We may redact commercially confidential terms.

12. Your Rights and Choices

Your rights under GDPR, UAE data protection law and other applicable privacy laws may include:

Right to access. To obtain confirmation of whether we process your personal data and a copy of it, along with information about how we use it, who we share it with, how long we store it and the purposes for processing. This includes the right to be told which suppliers received a Request for Quotation containing your data, to the extent we still hold that information.

Right to rectification. To have inaccurate or incomplete personal data corrected or updated. You may edit much of your information directly in your account.

Right to erasure. To request deletion of your personal data in certain circumstances, including where it is no longer necessary, where you have withdrawn consent or objected and we have no overriding grounds, or where it has been unlawfully processed. Please note that where you have sent an RFQ, the Vendors who received it hold their own copy as independent controllers, and a request to them must be made directly.

Right to restrict processing. To ask us to pause processing in certain circumstances, for example while we verify the accuracy of contested data.

Right to object. To object at any time to processing for direct marketing, and to object to processing based on legitimate interests where you believe it impacts your fundamental rights.

Right to data portability. To receive personal data you have provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible, in respect of processing based on consent or contract and carried out by automated means.

Right to withdraw consent. Where we rely on consent, to withdraw it at any time. Withdrawal does not affect the lawfulness of prior processing and may not affect processing under other legal bases.

Rights in relation to automated processing. You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significant effects concerning you, unless it is necessary for entering into or performing a contract, is authorised by law, or you have given explicit consent.

We use automated processing in two places: to extract structured data from documents you upload (Section 5) and to suggest or order Vendors for a request. Neither produces a decision about you with legal or similarly significant effects: the output of document processing is a draft that you review and confirm before anything is sent, and Vendor suggestions are informational and do not restrict whom you may contact. We do not use automated processing to deny access to our services or to offer different terms to individuals without human involvement. If this changes we will update this Policy, inform you of the logic involved and ensure all legal requirements are met, including your right to request human intervention.

Right to complain to a supervisory authority. If you believe we have infringed your privacy rights you may lodge a complaint with a data protection authority — your local supervisory authority in the EU/EEA, the UAE Data Office in the United Arab Emirates, or the relevant regulator in your jurisdiction. We encourage you to contact us first so that we can address your concerns directly.

Exercising your rights. Contact us using the details in Section 14. For security we may need to request specific information to confirm your identity before fulfilling a request. We will respond within the timeframe required by law — under GDPR generally one month, extendable in complex cases. There is no fee unless a request is manifestly unfounded or excessive.

Additional rights in certain jurisdictions. If you reside in a region that provides additional rights, we will honour those rights in accordance with applicable law. To the extent any US state privacy law applies to our processing, we do not “sell” or “share” personal information as those terms are defined in that law, and we do not use it for cross-context behavioural advertising.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies or legal requirements. When we make changes we will post the updated Policy on this page and update the effective date. Any updated Policy is effective when posted unless a later date is indicated.

If we make material changes — for example if we begin processing your personal data for new purposes not previously disclosed — we will take additional steps to notify you, such as posting a prominent notice or, where appropriate and required by law, notifying you by email or through your account.

Your continued use of the Platform after changes have been posted signifies acceptance of those changes. Where a change requires your consent we will obtain it. If you do not agree with the changes you should discontinue use and may contact us regarding removal of your personal data.

14. Contact Us and Complaints

If you have questions about this Privacy Policy or our data practices, or wish to exercise your rights, please contact us at:

RECORDS MARINE - FZCO (data controller) Premises No. DSO-IFZA, IFZA Properties, Dubai Silicon Oasis, Dubai, United Arab Emirates

Email: legal@recordsmarine.com

We will endeavour to respond promptly and work with you to address any privacy-related concern in a timely and fair manner.

If you are not satisfied with our response or believe your data is being processed unlawfully, you have the right to lodge a complaint with your local data protection authority — in the United Arab Emirates with the UAE Data Office, and in the European Union or EEA with your national supervisory authority under GDPR.

Find

Records Marine is operated by RECORDS MARINE — FZCO (Dubai, UAE), Trade Licence No. 60836. The platform IP is owned by RECORDS MARINE IP HOLDINGS LTD (ADGM, No. 27123).

© 2026 Records Marine. All rights reserved