Customer Data Policy
Last updated: October 2026
This policy explains how Maritech Solutions, LLC handles client data during and after an engagement. It applies alongside each client's service agreement. If they conflict, the service agreement controls.
1. Your data stays yours
You own your business data, including your customers, orders, inventory, documents, and records. We access and use it only to deliver the services you've engaged us for, and never sell it or use it for anyone else.
2. Minimum necessary access
We request only the access a project needs. We use named accounts instead of shared logins wherever your systems allow, and we remove our access when it's no longer needed or when the engagement ends.
3. Credentials
We never ask for passwords by email or text. Credentials are shared and stored through a secure password manager. We recommend you change any shared credential when an engagement ends.
4. Confidentiality
Everyone at Maritech Solutions who works on your systems is bound by confidentiality obligations. We don't discuss your business, data, or results publicly, including in case studies, without your written approval.
5. AI and your data
When a solution uses AI, we configure it so your data is not used to train AI models, and we use providers that commit to this in their business terms. We tell you which AI services a solution relies on before it goes live.
6. Service providers
We use a limited set of trusted providers, such as hosting and database services, to build and run solutions. We choose providers with strong security practices and give them only the data needed for the job.
7. Security
Data is encrypted in transit, access is restricted by role, and changes to production systems are logged. Before any system goes live, it is tested against your current process so its performance is proven, not assumed.
8. If something goes wrong
If we become aware of unauthorized access to your data in a system we manage, we will notify you without undue delay, and no later than 72 hours after confirming it. We'll tell you what happened, what data was involved, and what we're doing about it.
9. When an engagement ends
Within 30 days of the end of an engagement, we will, at your request, return or export your data in a usable format; remove our access to your systems; and delete copies we hold, unless the law requires us to keep them or you ask us to continue supporting a system.