Privacy Policy
Last updated: 31 May 2026
ReefDesk ("we", "us", "our") provides a SaaS platform for diving resorts and dive centres. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and the rights you have under the EU General Data Protection Regulation (GDPR), the UK GDPR, and similar laws.
1. Data controller
For visitors to reefdesk.io and customers signing up directly on our platform, ReefDesk is the data controller. You can reach our privacy team at privacy@reefdesk.io.
For guests of a resort using ReefDesk to manage their bookings, the resort is the controller and ReefDesk is the processor under a separate Data Processing Agreement.
2. What we collect
Account data (customers)
- First name, last name, email, hashed password
- Resort label and tenant code
- Billing plan and (when applicable) billing details processed by our payment provider
Resort operational data (processor role)
- Guest names, contact details, dates of stay, room assignments
- Dive certification level, dive medical declarations (special-category data)
- Invoices, payment status, internal notes added by resort staff
Marketing data
- Email addresses submitted via the pricing-page popup or newsletter
- UTM parameters and the page you came from
Technical data
- IP address, user-agent, log of login attempts and API calls
- Cookies (see section 7)
3. Why we process it (legal bases)
- Contract — to deliver the service you signed up for.
- Legal obligation — invoicing, tax records, security incident logging.
- Legitimate interest — security audit log, abuse prevention, basic product analytics.
- Consent — marketing emails, non-essential cookies. You can withdraw at any time.
4. Who can see your data
Your data is stored in an isolated tenant database. The only people with access are:
- Users you explicitly create inside your resort account.
- ReefDesk staff, only when you raise a support request, and always logged in the audit trail.
- Our sub-processors listed below.
5. Sub-processors
- Hetzner Cloud (Germany / Finland) — application hosting.
- Resend (USA, EU sub-processor available) — transactional email delivery.
- hCaptcha (USA) — bot protection on signup.
- Stripe (Ireland / USA) — payment processing, when applicable.
6. International transfers
Where sub-processors are based outside the EEA, transfers are protected by the European Commission's Standard Contractual Clauses (2021/914).
7. Cookies
- Essential: session cookie (`amed_session_*`), CSRF token, language preference. Required for the service to function — no consent needed.
- Functional: cookie consent state (`reefdesk_cookie_consent`), currency preference (`reefdesk_currency`), lead-popup suppression (`reefdesk_lead_popup_seen`). Stored only after your explicit consent.
- We do not run third-party analytics, advertising or fingerprinting trackers.
You can change your cookie choice at any time by clicking Cookie settings.
8. Retention
- Account data: while your subscription is active, plus 90 days.
- Invoices and accounting data: 10 years (legal requirement).
- Audit log: 12 months minimum.
- Marketing leads: 24 months from the last interaction, or until you unsubscribe.
9. Your rights
Under GDPR you have the right to access, rectify, port, restrict and erase your personal data, and to lodge a complaint with your local supervisory authority.
To exercise these rights, email privacy@reefdesk.io. We respond within 30 days. Resort admins can also use the built-in Audit & GDPR tab to export or anonymise guest data directly.
10. Security
Passwords are hashed with bcrypt. Connections use TLS 1.2+. Each tenant has its own isolated database. Backups are encrypted at rest. Admin login is rate-limited.
11. Changes
Material changes are announced by email at least 30 days before they take effect.