Privacy Policy

Last updated: 31 May 2026

ReefDesk ("we", "us", "our") provides a SaaS platform for diving resorts and dive centres. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar laws.

1. Data controller

For visitors to reefdesk.io and customers signing up directly on our platform, ReefDesk is the data controller. You can reach our privacy team at privacy@reefdesk.io.

For guests of a resort using ReefDesk to manage their bookings, the resort is the controller and ReefDesk is the processor under a separate Data Processing Agreement.

2. What we collect

Account data (customers)

Resort operational data (processor role)

Marketing data

Technical data

3. Why we process it (legal bases)

4. Who can see your data

Your data is stored in an isolated tenant database. The only people with access are:

5. Sub-processors

6. International transfers

Where sub-processors are based outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses (2021/914).

7. Cookies

You can change your cookie choice at any time by clicking Cookie settings.

8. Retention

9. Your rights

Under GDPR you have the right to access, rectify, port, restrict and erase your personal data, and to lodge a complaint with your local supervisory authority.

To exercise these rights, email privacy@reefdesk.io. We respond within 30 days. Resort admins can also use the built-in Audit & GDPR tab to export or anonymise guest data directly.

10. Security

Passwords are hashed with bcrypt. Connections use TLS 1.2+. Each tenant has its own isolated database. Backups are encrypted at rest. Admin login is rate-limited.

11. Changes

Material changes are announced by email at least 30 days before they take effect.