Privacy Policy — Marine Forge

Operated by Elite Marine Management Pty Ltd (ABN 24 681 770 874) · 603/40 Esplanade, Surfers Paradise QLD 4217 · Contact: info@elevateai.au · Effective 28 July 2026

1. Who we are

Marine Forge (the “Platform”, “we”, “us”) is a software platform for marine service businesses to manage jobs, quotes, invoicing, inventory, purchasing and customer reporting. It is operated by Elite Marine Management Pty Ltd. This policy explains how we handle personal information and complies with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).

2. Whose information this covers

The businesses who subscribe to the Platform and their staff who hold Platform logins, and the end clients and contacts whose details our business customers enter (vessel owners, contacts, billing details). Our business customers are responsible for the personal information they enter about their own clients; we process it on their behalf.

3. Information we collect

  • Account and identity: name, email, role, and login credentials for Platform users.
  • Business and operational data: clients, vessels, jobs, quotes, invoices, purchase orders, inventory, workflows and reports entered into the Platform.
  • Accounting integration data: when a customer connects an accounting provider (Xero or MYOB), we access only what is needed to push sales invoices and supplier bills and to read the chart of accounts and tax codes. We store record identifiers and an encrypted authorisation token.
  • Email integration data: when a customer connects their own mailbox (Google or Microsoft), we access their email solely to send messages the customer composes to their clients from the Platform and to record their clients’ replies against the correct client. We store those messages and an encrypted authorisation token. We do not read, use, or share mailbox contents for any other purpose, and we do not use this data for advertising or to train models.
  • Technical data: log records of actions taken in the Platform, for security and audit.

4. How we use information

To provide and operate the Platform for our business customers; to send and receive the emails and push the invoices/bills a customer explicitly requests through their connected accounts; to secure the Platform, investigate issues and keep audit records; and to provide support. We do not sell personal information and do not use it for advertising.

5. Connected accounts (Xero / MYOB / Google / Microsoft)

Connections use OAuth 2.0; we never see or store the provider password. Access is limited to the specific organisation, company file or mailbox the customer authorises. Authorisation tokens (including refresh tokens) are encrypted at rest. A customer can disconnect at any time from Settings, which revokes our access. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Where data is stored

Platform data is hosted on Australian infrastructure (Sydney), with encrypted backups in Australia. To draft report text, limited content may be processed by our AI provider (Anthropic) on servers in the United States; no accounting credentials or mailbox tokens are sent to the AI provider.

7. How we protect information

Encryption in transit (TLS 1.2 or higher) and at rest; authorisation tokens encrypted with AES-256; per-customer data isolation enforced at the database level; multi-factor authentication for administrator accounts; access controls, audit logging and least-privilege service access.

8. Sharing and disclosure

We disclose personal information only to the provider a customer has connected (to carry out the integration they requested), to service providers who host or support the Platform under confidentiality obligations, or where required by law. We do not disclose personal information to any other third party.

9. Retention

Business and operational data is retained while the customer’s account is active and for a reasonable period afterwards, unless deletion is requested. Security and audit logs are kept for at least twelve months. On account closure, data is deleted or de-identified within a reasonable period, except where we are required to retain it by law.

10. Your rights

Under the Australian Privacy Principles you may request access to, or correction of, personal information we hold. End clients of our business customers should contact that business first. To make a request or complaint, contact info@elevateai.au. If you are not satisfied with our response you may contact the Office of the Australian Information Commissioner (oaic.gov.au).

11. Data breaches

We maintain a process to detect, assess and respond to data breaches, and will notify affected parties and the OAIC where required under the Notifiable Data Breaches scheme.

12. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the Platform or by email. The effective date above shows when this version took effect.

Elite Marine Management Pty Ltd (ABN 24 681 770 874) · 603/40 Esplanade, Surfers Paradise QLD 4217 · info@elevateai.au