PRIVACY NOTICE

Your information.
Your choices.

A clear view of what we collect, why we use it and how you stay in control when using PM Cirrus.

Online & Local editionsUpdated

Purposeful useAccounts, planning, support and security.

Clear choicesOptional features remain your choice.

Access to your rightsA direct route to requests and complaints.

Who we are

Argonaut Systems Ltd operates PM Cirrus. We are the data controller for personal information used to manage our customer relationships, accounts, service security and enquiries. You can contact us at support@PMCirrus.cloud.

This notice covers the PM Cirrus website, Online service, Windows Local edition and related support. It explains our approach under the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR), as amended, including by the Data (Use and Access) Act 2025. Other applicable data protection laws, including the EU GDPR where relevant, may also give you rights.

Using PM Cirrus through your organisation?

Your organisation normally decides how personal information in its vessel plans, cargo records and uploaded files is used. For that information, it is the controller and we process information on its behalf under the service arrangements. Ask your organisation about its own privacy notice; we can help route a request to the right place.

Information we handle

  • Account and contact details. Your email, username, password hash, permissions and company association, plus profile, telephone or billing details you or an authorised administrator provide.
  • Planning and operational information. Vessel and voyage records, cargo data, EDI files, saved views and other content you upload or create. These may contain personal information about you or other people.
  • Service and security records. IP addresses, browser and device details, login attempts, session identifiers, login and last-activity times, and technical errors. Authorised administrators can view account and activity information to manage access and support the service.
  • Local installation details. Account entitlements, the registered installation’s public-key identifier, login-transfer records and software version information used for licensing and updates.
  • Messages and optional settings. Enquiries, support correspondence, preferences and any settings and calibration retained from the retired gaze experiment described below.

We receive information from you, your use of the service, your organisation’s administrators and people authorised to upload or share operational records. Please include only information needed for the work you are carrying out.

Account identifiers and authentication details are needed to provide a signed-in service. If you do not supply them, we cannot create or authenticate your account. Optional camera controls are not required to use the standard planning tools.

Why we use it

Data protection law requires a lawful basis for each purpose. For information for which we are the controller, these are:

Providing your service

To create accounts, authenticate users, manage licences and provide requested features and support.

Basis: performing our contract with you; or our legitimate interest in delivering the service to your organisation where it holds the contract.

Keeping the service secure

To prevent unauthorised access, investigate errors and misuse, and manage licensed sessions.

Basis: legitimate interests in protecting users, customer information and the reliable operation of PM Cirrus.

Business administration

To respond to enquiries, maintain customer and billing records, meet legal obligations and handle disputes.

Basis: contract or steps you request before a contract; applicable legal obligations; and legitimate interests in managing business relationships and legal claims.

Optional features and communications

To provide features you choose and honour communication preferences. Camera access requires your browser permission. We obtain consent where the law requires it, including for consent-based marketing or tracking.

Basis: contract for requested service features, or consent where required. Permitted business marketing may rely on legitimate interests, subject to your right to object and electronic marketing rules.

When we rely on legitimate interests, we must balance those interests against your rights and reasonable expectations. You can object to that processing. You can opt out of marketing at any time by contacting us or using an unsubscribe option in a marketing message; essential account and service messages are separate.

Sharing and overseas transfers

Information is available to authorised people who need it to operate and support the service, and to your organisation’s authorised users according to its access arrangements. Service providers support functions such as hosting and transactional email; the application uses Microsoft Azure hosting and SendGrid for service emails.

We may also disclose relevant information to professional advisers, authorities or other parties where required by law, necessary to protect legal rights, or as part of a business transfer subject to appropriate protections.

Some application pages obtain fonts or software libraries from Google Fonts, Microsoft’s content delivery network or jsDelivr. Loading these resources sends the provider technical request information, such as your IP address and browser details. External websites you choose to visit have their own privacy notices.

Provider locations and remote support can involve processing outside the UK. Where a transfer requires protection under UK data protection law, it must be covered by an applicable adequacy arrangement or appropriate safeguards, such as approved contractual terms and any necessary additional protections. Equivalent requirements apply to EU-regulated transfers where relevant. Contact us for the locations and safeguards relevant to your service, including how to obtain a copy of applicable safeguards.

Cookies and browser storage

PM Cirrus uses cookies and browser storage to keep sessions secure and remember requested settings. These technologies serve different purposes:

Sign-in and security cookies
Authenticate you and protect requests. Their lifetime depends on the session and sign-in options, including whether you choose to stay signed in.
Browser device identifier
The CirrusBrowserDevice cookie recognises a browser for licensed session management. It has a one-year expiry and is not an advertising identifier.
Pending login and session state
CirrusPendingLogin supports a login transition and expires after five minutes. Server-side session state has a 30-minute idle timeout; this is separate from how long you remain signed in.
Preferences and local storage
Planning layout, display and feature preferences can persist in your browser until changed or cleared. Some preferences and saved views are also stored with your account or operational data.

Storage that is strictly necessary for a service you request does not require cookie consent. Other legal exceptions can apply to requested appearance settings. Any additional use that requires consent must be explained and offered for your choice before it begins; simply reading this notice is not consent.

The current PM Cirrus pages do not embed Google Analytics or advertising remarketing tags. You can remove or block cookies and site storage in your browser, but doing so may sign you out or reset saved browser preferences. Clearing browser storage does not delete information held in your account or Local database.

The Local edition

The Windows Local edition stores its working database on your computer. That can include account information and operational records, as well as locally created backups and exports.

Local does not mean that the software never connects to Online. When connected, it can check account entitlements and available updates. Moving a login between editions exchanges account authorisation, licence and registered-installation information. Returning a login to Online does not, by itself, upload your local planning database. Explicit imports, exports and other transfers you choose are separate actions.

You and your organisation control access to the computer and copies you make. Removing the application or clearing browser storage may leave the local database, backups and exported files in place. Include those copies when arranging deletion or responding to a request about personal information.

Retired gaze experiment

Gaze Mode has been retired from Profile and Bay Views. These pages no longer load its camera or tracking code. The experiment processed camera images in your browser, without uploading camera video to PM Cirrus or requesting microphone audio. It was not facial authentication.

Previously saved settings are retained. These may include camera selection, screen and framing details, control preferences and numerical calibration and validation results. They no longer enable gaze tracking.

You can withdraw previously granted camera permission in your browser. Contact us if you want saved gaze settings or calibration removed. Ordinary mouse and keyboard use is unchanged.

Retention and security

Personal information should be kept only for as long as needed for its purpose. There is no single retention period for everything in PM Cirrus. The relevant criteria are:

  • Accounts and customer records: the duration of the service relationship and any continuing contractual, accounting, tax or legal-claim requirements.
  • Security and support records: the time needed to diagnose faults, resolve enquiries, investigate incidents and protect against misuse or claims.
  • Customer operational data: your organisation’s instructions, service agreement and any applicable legal requirements.
  • Backups and local copies: the backup lifecycle and recovery needs; copies on your own devices remain under your or your organisation’s control.

Contact us for the retention information relevant to a particular record or service. Deleting a user account does not necessarily delete shared organisational records, information subject to a legal retention requirement, or independently held exports and backups.

PM Cirrus uses authentication, access permissions and technical security measures to protect information. Passwords are stored as hashes. The protection of local databases and exported files also depends on your device security and your organisation’s access and backup arrangements.

Your privacy rights

Depending on the circumstances and applicable law, you can ask to:

  • Access your personal information and how it is used.
  • Correct inaccurate or incomplete information.
  • Erase or restrict information where the legal conditions apply.
  • Receive a portable copy of eligible information.
  • Object to processing based on legitimate interests, and to direct marketing at any time.
  • Withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing.

You also have protections relating to significant decisions about you made solely by automated processing, where applicable. Rights are subject to legal conditions and exemptions; if we cannot fulfil a request, we will explain why.

Send a request to support@PMCirrus.cloud. We may need proportionate information to verify your identity or clarify the request. We normally respond within one month and without a fee. If a lawful extension or other exception applies, we will explain the timing and reason.

Account tools are a starting point.

The Personal Data area of your account provides download and deletion options. Its download covers selected account information, including saved gaze settings; it is not a complete export of every log, support record or organisational file. Contact us for a wider request. If your login is assigned to Local, return it to Online before using account deletion.

Request your personal data

Contact and complaints

For a privacy question or complaint, email Argonaut Systems Ltd at support@PMCirrus.cloud. Describe what happened, when it happened and the outcome you would like. You do not need to use a particular form or legal wording.

We will acknowledge a data protection complaint within 30 days, investigate it, keep you informed and communicate the outcome without undue delay. If you need help making a complaint or require another accessible way to contact us, tell us in your message.

You can also complain to the UK Information Commissioner’s Office at ico.org.uk/make-a-complaint, or to your relevant data protection authority. You do not lose that right by contacting us first.

Keeping this notice current

We will update this notice when our service or data use changes and provide additional notice where required. The date at the top identifies this version. A privacy notice explains our processing; it does not ask you to waive your rights.