Privacy Policy

Last updated: 1 September 2026

1. Who we are

Approval Ocean 360 ("the Service") is operated by MA Ocean 360 ("we", "us"), a company registered in England and Wales. For anything in this policy, contact contact@maocean360.com.

For the personal data of people who create accounts and use the Service, we are the data controller. For the content your organisation's workspace processes through its approval workflows (requests, form answers, attachments, decisions), your organisation is the controller and we act as its processor.

2. What we collect

  • Account data — your name, email address, workspace membership, department and roles, provided when your account is created or managed by your workspace administrator.
  • Workspace content — the requests, form answers, attachments, comments, decisions and signatures your organisation submits through its approval workflows.
  • Approval records — who requested, reviewed, approved, rejected, delegated or was reminded, and when. The Service exists to keep this record; it is visible to your workspace's administrators as an audit trail.
  • External approver data — where a workspace routes a step to someone outside it: that person's name, email address and their decision.
  • Technical data — IP address, browser type and timestamps in server logs, used for security and troubleshooting.

We do not run advertising or cross-site tracking. The application stores small preferences (such as your theme) in your own browser. Signing in uses session cookies from our identity service (Ocean ID) strictly to keep you signed in.

3. Why we use it, and the lawful bases

  • To provide the Service (performance of a contract) — accounts, workspaces, routing approvals, notifications, the audit trail.
  • To secure and improve it (legitimate interests) — protecting accounts, preventing abuse, fixing errors, understanding aggregate usage.
  • To meet legal obligations — records we are required to keep, and responding to lawful requests.

We do not sell personal data, and we do not use it for third-party advertising.

4. Who we share it with

Only service providers who process data for us, under contract, to run the Service:

  • Cloudflare — content delivery, DNS and security in front of the Service.
  • Railway — application hosting.
  • Neon — database hosting.
  • Resend — transactional email (invitations, reminders, approval links).
  • Sentry — error monitoring, configured to minimise personal data.
  • Stripe — payment processing, if and when your workspace purchases a paid plan. We never see full card details.

Beyond providers: your workspace's administrators and fellow members see what the workspace's own visibility rules allow, and we disclose data where the law requires it.

5. International transfers

Some providers process data outside the UK (including in the EEA and the United States). Where they do, we rely on UK adequacy decisions or appropriate safeguards such as the UK International Data Transfer Agreement / Addendum and Standard Contractual Clauses.

6. How long we keep it

  • Account data — for the life of the account, then deleted or anonymised within a reasonable period.
  • Approval records and audit trails — retained for as long as the workspace needs its records; they are the point of the product. Workspace owners control their content and can request deletion of a workspace.
  • Server logs — kept for a short rolling window for security.

7. Security

All traffic is encrypted in transit (TLS 1.2+, HTTPS enforced). Data is encrypted at rest by our hosting providers. Access is role-based inside each workspace, every consequential action is written to a tamper-evident audit trail, and administrative access on our side is restricted and logged.

8. Your rights

Under UK GDPR you can ask us to:

  • access a copy of your personal data;
  • correct it, or complete it;
  • delete it ("right to be forgotten"), where retention is not required;
  • restrict or object to how we use it;
  • receive it in a portable format;
  • withdraw consent, where consent is the basis.

Write to contact@maocean360.com and we will respond within one month. If your data reached us through your employer's workspace, we may route the request through that workspace's administrator, as their processor. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.

9. Children

The Service is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.

10. Changes

When this policy changes materially we will update this page and its date, and notify workspace administrators for significant changes. The English version of this policy is the governing version.