Privacy policy
What DiveOS collects, how guest medical data is handled, who processes it and how to export or delete it.
This is a draft. It has not been reviewed by a lawyer and will change before launch. It is published so you can see the terms we intend to hold ourselves to, not as a finished contract.
01What we collect
Three things. Your account details, so you can log in and we can bill you. Your dive centre’s data as you enter it — guests, bookings, dives, prices, invoices, staff. And the messages your guests send to the channels you connect, so they can appear in your inbox.
We do not track you around the internet, we do not run advertising pixels, and there is no third-party analytics script on the page you are reading.
02Guest medical answers
A medical questionnaire is special-category personal data and it is the most sensitive thing in the system. Every organisation’s records are isolated at the database level, so one dive centre cannot read another’s under any circumstances, and your staff see the flag that matters operationally — cleared or not cleared — without opening the answers themselves.
Two further protections are specified and not yet built: encryption of these columns with a key specific to your organisation, and an access log recording who opened which guest’s answers and when. Both will be in place before any real guest data is entered. We would rather list them here as outstanding than let you assume they already exist.
03What we do not do with it
We do not sell data. We do not share it with advertisers. We do not use your guests’ records to train machine-learning models, ours or anybody else’s. Your data is used to provide the service to you and for nothing else.
04Third-party processors
Hosting, email delivery, file storage and payment processing are provided by third parties under data processing agreements, each handling only the part they need. Card numbers go to Stripe and never reach our servers. The current list of processors is available on request and will be published here before launch.
05Retention
For as long as your subscription is active, plus the 30-day read-only window described in the terms. After that it is deleted. Signed forms are kept for the period you configure, because a liability release is a record you may need after the guest has gone home.
06Export and erasure
You can export or delete your organisation’s data from Settings at any time, without asking us.
A guest who wants their record exported or erased asks the dive centre, and your staff can act on it from that guest’s profile. You are the controller of your guests’ data; we are the processor acting on your instructions.
07Contact
Questions or complaints about how your data is handled go to [email protected].