POLICY

Privacy Policy

How we handle personal information on this website and in the services we deliver.

VERSION 2.0. EFFECTIVE 4 AUGUST 2026. NEXT REVIEW 4 AUGUST 2027.

This Privacy Policy explains how SolarisTech Inc. handles personal information, both on this website and in the services we deliver, including material uploaded to the Nautilux AI platform. It covers two different situations and deals with them separately. Where you contact us through this website, SolarisTech is the controller of your information. Where a client uploads material to Nautilux or instructs a survey, inspection or advisory engagement, SolarisTech acts as a processor on that client's instructions and under the engagement contract, and the client remains the controller.

Information we collect

From website visitors and enquirers:

  • Information you give us directly, such as your name, company, role, email, phone number and the content of your message when you contact us or request a demonstration.
  • Limited technical data collected automatically, such as pages viewed, approximate location derived from IP address, and performance data, used to operate and improve the website.
  • Correspondence and records relating to services you request or receive from us.

From client submissions to Nautilux and to our survey and advisory work:

  • Vessel documents and certificates, class and flag correspondence, technical records, drawings and commercial documents.
  • Photographs and video taken on board or uploaded by the client, which may show identifiable individuals.
  • Crew-related records, which may include names, ranks, nationality, dates of birth, certificate numbers and expiry dates, seafarer employment agreement details, hours of rest records, medical certificate validity, and training and drill records.

We ask clients not to upload personal data the engagement does not need. Where the work can be delivered from redacted crew documents, we prefer redacted documents.

Client material and crew personal data

Crew data is personal data, and parts of it are treated as sensitive personal data in some jurisdictions. We handle it accordingly.

  • We process crew records only for the purpose the client instructed, for example checking certificate validity against the safe manning document or checking hours of rest records against MLC requirements.
  • Crew records and photographs uploaded to Nautilux pass through the same automated analysis as the rest of a submission, including processing by Microsoft Azure OpenAI Service. We do not carve crew documents out of that pipeline silently, and a client who needs them excluded must tell us before uploading.
  • Our findings address the vessel's compliance position. We do not produce assessments of an individual seafarer's suitability or employment.
  • Access to crew records is restricted to the personnel working on that engagement and is logged.
  • The client, as the seafarers' employer or manager, is responsible for the lawful basis on which crew data is provided to us and for any notice given to the individuals concerned. We will support a client in meeting that obligation. We cannot discharge it for them.

Automated and AI processing

Material uploaded to Nautilux is analyzed by automated systems, including large language model and vision model processing delivered through Microsoft Azure OpenAI Service. This includes documents and photographs that may contain personal data.

  • Microsoft's enterprise terms for Azure OpenAI Service state that customer content is not used to train Microsoft or OpenAI foundation models. We rely on those terms and can provide the current version on request. They are Microsoft's terms, not ours, and we do not warrant them.
  • We do not use client material, including crew data, to train models of our own without a separate written agreement with that client.
  • Automated analysis produces draft findings only. A named SolarisTech reviewer checks findings before a report is issued. No report, finding or recommendation concerning a vessel or a person is issued on the basis of automated processing alone.
  • A client who needs automated analysis excluded from a submission must tell us before uploading. Some services cannot be delivered without it, and we will say so.

How we use information

  • To respond to enquiries and provide the services and demonstrations you request.
  • To deliver, evidence and support the engagements our clients instruct.
  • To operate, secure, maintain and improve this website and the Nautilux platform.
  • To communicate with you about a live engagement and, where permitted, about relevant updates. You can opt out of the second at any time.
  • To meet our legal, regulatory and contractual obligations, and to establish, exercise or defend legal claims.

Cookies and analytics

We use a limited set of cookies and privacy-conscious analytics to understand how the website is used and to keep it performing. We do not run advertising cookies or cross-site advertising trackers on this site. You can control cookies through your browser settings, and disabling some may affect how the site functions.

Sharing, disclosure and sub-processors

We do not sell personal information, and we do not share it for cross-context behavioral advertising. We share information with a small number of service providers who process it on our behalf under contract:

  • Amazon Web Services, cloud hosting and storage for the Nautilux platform.
  • Microsoft Azure OpenAI Service, automated analysis of uploaded documents and images.
  • Website hosting, contact form and analytics providers for this website.
  • Email and business productivity providers used to run the company.

A current, named sub-processor list, with processing locations, is available on request and is provided to clients at onboarding. We tell clients before adding a sub-processor that will handle their material. We may also disclose information where required by law, regulation, court order or valid legal process, and to protect the rights, safety and property of SolarisTech, our clients or others. Where an engagement is instructed by a lender, insurer, law firm or administration rather than by the vessel's owner, the report goes to the party who instructed it, and we identify that party before the work starts.

Retention, deletion and security

Website enquiry data is kept for as long as needed to deal with the enquiry and for a reasonable follow-up period, then deleted. Engagement material, including client-uploaded documents and images, is retained for the period stated in the engagement documents. Where nothing else is agreed, our default is seven years from delivery of the final report, reflecting the limitation periods and record-keeping expectations that apply to survey and inspection work. A client may request earlier deletion of uploaded material.

We act on that request unless we are required to retain it by law, by a legal hold, or because a claim remains unresolved, and we tell you which applies. Deletion covers primary storage and propagates to backups on the normal backup cycle. The final report, and the record that the engagement took place, are retained even where source material is deleted. We apply the safeguards described in our Information Security and Data Protection Policy to all personal information we hold. We do not hold SOC 2 or ISO/IEC 27001 certification and we do not claim either.

Your rights and international transfers

Depending on where you are, you may have rights to access, correct, delete, port or restrict the use of your personal information, to object to certain processing, and to complain to a supervisory authority. In California you may also have rights of access, deletion, correction and to limit sharing. We do not sell personal information. If you are a seafarer whose data was uploaded to us by an employer or manager, we will normally pass your request to that client, because they instructed the processing and hold the relationship with you, and we will tell you that we have done so.

SolarisTech operates from the United States and South Korea and uses cloud infrastructure in more than one country, so personal information may be processed outside the country where it was collected. Where personal data is transferred from the European Economic Area, the United Kingdom or Korea, we rely on the transfer mechanisms available under the applicable law, including standard contractual clauses with our providers. We can describe the arrangement in place for your account on request.

Questions, requests and complaints about this policy: admin@solaristechinc.com, marked for the attention of the President. SolarisTech has not appointed a statutory Data Protection Officer. Thomas H. Blenk, President and Chief Executive Officer, is accountable for privacy at the company. We may update this policy. The version and effective date above reflect the current text, and we notify clients before a change that materially affects how their material is handled.

Questions About How We Work?

Ask for our certificates, our sub-processor list, our relationship and flag representation disclosures, or the scope of any engagement. We will send them.