FERNRuleFinderMaritime Knowledge. One Search.Privacy Policy
This Privacy Policy explains how PITIP-MITIM, as the operator of FERN RuleFinder, processes and protects personal information across public pages, accounts, regulatory workspaces, subscriptions, support services, and mobile access. Last updated: July 2026.
Privacy at a glance
FERN RuleFinder respects the privacy of public visitors, Free-account users, professional subscribers, organizational users, and support contacts.
Personal information is processed only for defined account, search, workspace, subscription, support, security, operational, contractual, and legal purposes.
FERN RuleFinder seeks to collect only information reasonably necessary for the relevant service or purpose.
This policy also explains how information may be processed to protect users, PITIP-MITIM, FERN RuleFinder, its developers and contributors, platform infrastructure, confidential information, intellectual property, and legal rights.
Privacy at a glance
FERN RuleFinder respects the privacy of public visitors, Free-account users, professional subscribers, organizational users, and support contacts.
Personal information is processed only for defined account, search, workspace, subscription, support, security, operational, contractual, and legal purposes.
FERN RuleFinder seeks to collect only information reasonably necessary for the relevant service or purpose.
This policy also explains how information may be processed to protect users, PITIP-MITIM, FERN RuleFinder, its developers and contributors, platform infrastructure, confidential information, intellectual property, and legal rights.
Controller and scope
PITIP-MITIM operates FERN RuleFinder and acts as the data controller for the processing described in this policy, except where an external provider acts as an independent controller for its own processing.
This policy applies to FERN RuleFinder public pages, account registration and sign-in, regulatory search workspaces, publication-module access, subscriptions, support communications, and signed-in mobile access.
The complete registered legal identity, address, and privacy contact details of the controller must be confirmed and included in the final production version of this policy and the Terms and Conditions.
Nothing in this policy changes the access rules, contractual terms, or professional responsibilities applicable to a particular user or account.
Information we process
The information processed depends on the services and functions used.
Account and identity information may include a name, email address, account identifier, authentication information, account status, access level, organization membership, and assigned role.
Subscription and transaction information may include module entitlements, subscription status, billing status, amount, currency, transaction reference, billing period, and related business records. Full payment-card or banking credentials should be processed by the applicable payment provider and should not be stored directly by FERN RuleFinder.
Search and workspace information may include regulatory queries, selected modules, filters, context choices, recent searches, saved results, bookmarks, notes, references, and related workspace activity.
Technical and security information may include IP address, device and browser information, operating system, session identifiers, timestamps, request status, diagnostic records, error information, security events, and technical logs.
Support information may include contact details, account information, the affected module or page, issue descriptions, attachments, and communication history.
How and why we use information
Personal information may be processed to create and protect accounts, authenticate users, provide regulatory search and workspace functions, restore permitted account state, manage publication-module access, administer subscriptions, process support requests, maintain service records, and meet legal obligations.
Information may also be processed to maintain platform availability, reliability, security, and technical performance; investigate failed requests or operational incidents; prevent fraud or misuse; resolve disputes; and protect legal claims.
Depending on the purpose and applicable law, processing may be based on steps requested before entering into a contract, performance of a service or subscription agreement, compliance with legal obligations, legitimate interests, or valid consent.
Where legitimate interests are relied upon, the interests of PITIP-MITIM, FERN RuleFinder, its developers, users, and service providers must be balanced against the rights and freedoms of the affected person.
Where consent is used, it may be withdrawn. Withdrawal does not affect processing that was lawful before withdrawal.
Platform integrity and protection of legal rights
PITIP-MITIM may process limited account, usage, technical, security, and support information where reasonably necessary to protect FERN RuleFinder, its users, its developers and contributors, service providers, infrastructure, confidential information, intellectual property, and legal rights.
This may include detecting, preventing, investigating, or responding to:
- unauthorized access or credential misuse;
- automated scraping, bulk extraction, or abnormal request activity;
- attempted circumvention of access, quota, subscription, or security controls;
- interference with platform availability, integrity, or operation;
- fraudulent activity, abusive conduct, or misuse of support services;
- unauthorized copying, redistribution, or exploitation of protected platform material;
- suspected violations of the Terms and Conditions;
- threats, harassment, or harmful conduct directed toward users, staff, developers, or service providers;
- security incidents, disputes, complaints, or legal claims.
Relevant records may be preserved where reasonably necessary to investigate an incident, protect users, enforce contractual rights, establish or defend legal claims, comply with lawful requests, or maintain evidence.
Such processing should remain proportionate to the identified risk and should not be used as a general justification for unrelated monitoring.
Service providers and disclosures
FERN RuleFinder may use selected service providers for infrastructure, hosting, database services, authentication, communications, payment processing, security, technical monitoring, and related operational functions.
A provider acting as a processor should receive only the information necessary for the relevant service and should be subject to appropriate instructions, contractual safeguards, confidentiality requirements, and data-protection obligations.
Some external providers may act as independent controllers for their own processing. Their own privacy terms may apply when a user directly interacts with their service.
Information may also be disclosed where reasonably necessary to comply with law, respond to a court or competent authority, protect legal rights, prevent fraud or misuse, investigate security incidents, or protect users, developers, PITIP-MITIM, FERN RuleFinder, and platform infrastructure.
The final production policy should identify only providers and processing relationships that are actually in use.
Security, retention, and international transfers
PITIP-MITIM and FERN RuleFinder should apply reasonable technical and organizational measures designed to protect personal information against unauthorized access, unlawful processing, loss, misuse, alteration, or disclosure.
No internet-based service can guarantee absolute security. Users are also responsible for protecting their credentials and using appropriate device and account security.
Personal information should be retained only for as long as necessary for the relevant service, security, contractual, accounting, tax, dispute-management, record-keeping, or legal purpose.
Retention periods may differ for accounts, subscriptions, transactions, search and workspace data, support communications, technical logs, security records, and legal claims.
When information is no longer required, it should be deleted, anonymized, or otherwise handled under the applicable retention process.
Where information is processed outside the European Economic Area or another applicable jurisdiction, legally required transfer safeguards should be used.
The final production policy should include or reference a verified processor inventory, transfer assessment, and retention schedule.
User rights and request boundaries
Subject to applicable law, users may have rights to request access, correction, deletion, restriction, portability, or objection concerning their personal information. Users may also withdraw consent where processing relies on consent and may submit a complaint to the competent supervisory authority.
A rights request may be submitted through Contact Support. Reasonable identity verification may be required before a request is completed.
A personal-data request concerns personal information relating to the requesting person. It does not automatically create a right to receive:
- source code;
- system architecture;
- proprietary search methods or internal decision logic;
- confidential security information or vulnerability details;
- internal business records unrelated to the requester's personal data;
- trade secrets;
- protected intellectual property;
- confidential information belonging to PITIP-MITIM, FERN RuleFinder, developers, contributors, service providers, or other users;
- personal information relating to another person.
Requests will be assessed and fulfilled in accordance with applicable law while respecting the rights and freedoms of other persons and the protection of trade secrets, intellectual property, confidential information, and platform security.
These protections must not be used as a blanket reason to refuse a valid personal-data request. Where necessary, information should be limited, redacted, summarized, or otherwise provided in a form that protects competing rights while enabling the requester to exercise applicable rights.
Cookies and related technologies
Information about cookies, browser storage, session technologies, consent requirements, and related controls is provided in the Cookie Policy.
Technical logging does not necessarily involve cookies or device storage.
The Privacy Policy and Cookie Policy should be read together where information collected through cookies or similar technologies constitutes personal data.
Contact and policy changes
Privacy questions, data-protection requests, and concerns about account or workspace information can be submitted through Contact Support.
Requests should identify the relevant account, page, feature, or processing activity and should not include unnecessary confidential or sensitive information.
This Privacy Policy may be updated when platform functionality, processing activities, service providers, security practices, legal requirements, or technical operation change.
Material changes will be published on this page with an updated revision date.