UpArate, operated by [COMPANY LEGAL NAME],
automates email and document work for maritime chartering desks. That
means our customers point us at commercially sensitive
correspondence, so this page errs on the side of saying plainly what
we do with it, who touches it on our behalf, and what we will never
do with it.
1. What we process
- Chartering email from the mailboxes your company
connects — subjects, bodies, senders, recipients, and
attachments (recaps, LOIs, Statements of Facts, B/Ls, and the
like).
- Documents your team uploads or that arrive as
attachments, and the voyage records the engine builds from
them.
- Account data: names, work email addresses, and
roles of the users your company gives seats to, received via
Microsoft sign-in.
- Operational logs of what the engine did and why
— kept so your managers can audit every action.
We process this data to provide the service your company signed up
for: classifying mail, drafting replies, filing documents, and
tracking voyage obligations. That is the whole list of purposes.
2. Where it lives and how it is protected
- Data is hosted on Railway infrastructure in the
EU and US, and is encrypted at rest and in
transit.
- Sign-in is by Microsoft single sign-on only —
we never see or store your users' passwords.
- Every company's data is tenant-scoped:
isolation is enforced at the database layer with row-level
security, so one customer's queries physically cannot return
another customer's rows.
3. Who processes it for us
We use a deliberately short list of subprocessors, each for one job:
| Subprocessor | What it does for us |
| Railway |
Hosting — the application and its database run there (EU/US). |
| Anthropic |
LLM processing of email and document content — classification,
extraction, and drafting. Under our agreement, this content is
not used to train models. |
| Microsoft |
Identity (sign-in) and the mail APIs through which your
connected mailboxes are read and — with authorization —
written. |
| Cloudflare |
DNS and network proxying in front of the service. |
We will update this list before adding a subprocessor that would
touch your mail or documents.
4. What we never do
- No training on your data. Your mail and
documents are not used to train our models or anyone else's. The
engine's learning about your desk's preferences stays inside your
tenant.
- No selling or sharing for advertising. Ever, to
anyone.
- No sending without authorization. Nothing
leaves a connected mailbox unless one of your operators approved
it or one of your managers set an autonomy level that explicitly
covers it.
5. How long we keep it
- Mail bodies are aged out of our mirror according
to your company's retention setting — after the window your
managers choose, the body content is deleted from our systems
while the mail remains untouched in your own mailbox.
- Documents and voyage records are kept while your
account is active, because they are the working state of your
desk.
- On termination, your company's data — mirrored
mail, documents, learned patterns — is deleted within 30 days,
save for what we are legally required to retain. We will confirm
deletion in writing on request.
6. Your rights
Because UpArate is business software, most requests come to us
through your employer, which controls the mailboxes we connect to.
If you are a user of a customer's desk — or a person whose email
passed through one — and want to know what we hold or want it
corrected or deleted, contact us and we will work it through with
the customer concerned. We respond to every request; we do not have
a “we may” posture on this.
7. Changes
As the product matures this policy will get more precise, not more
permissive. Material changes are notified to your account contact
before they take effect, and the date at the top of this page always
reflects the current version.
8. Contact
Privacy questions and requests:
[email protected],
or in writing to [CONTACT ADDRESS].
This policy is governed by the laws of
[JURISDICTION].