Privacy Policy
Effective date: 8 August 2026
This Privacy Policy explains how DinghyFleet sp. z o.o. (“DinghyFleet”, “we”, “us”) handles personal data in connection with the DinghyFleet platform, a business-to-business workspace used by yacht-charter brokers and operators to manage requests, offers, bookings and charter preparation.
DinghyFleet is designed for professionals acting in the course of a business. It is not a consumer service and is not intended for anyone under 18. Where this policy uses “personal data”, “controller”, “processor” or “data subject”, those terms have the meaning given in the EU General Data Protection Regulation (GDPR).
Who we are
The company responsible for the platform is DinghyFleet sp. z o.o., a limited liability company with its registered office at Jana Heweliusza 11/811, 80-890 Gdańsk, Poland.
DinghyFleet sp. z o.o.Jana Heweliusza 11/81180-890 Gdańsk, PolandVAT ID: PL5252724741Email: office@dinghyfleet.comWe have not appointed a Data Protection Officer, because we are not required to do so. Privacy questions, access requests and complaints should be sent to the contact address above and are handled by our team directly.
Our role: controller and processor
DinghyFleet is multi-tenant software. Each organization that signs up is an independent tenant: it decides who its members are, which workspaces it activates, which clients, yachts, requests, offers and bookings it records, and how long it keeps working with them.
We act as an independent controller for data we determine the purposes of ourselves: account and login data, organization and membership records, subscription, seat and billing data, support correspondence, security and audit logging, and the operation, security and improvement of the platform.
We act as a processor on behalf of an organization for the business content that organization puts into its workspaces — for example client contact records, charter requests, offers, booking details, uploaded documents, notes and collaboration messages. For that content, the organization is the controller: it decides what to collect, why, and on what legal basis, and it is responsible for informing the individuals concerned.
Where we act as a processor, we process the content only on documented instructions from the organization, which are given through the functionality of the platform and any data processing terms agreed with us. Organizations that require a separate data processing agreement can request one from us.
If you are a client, guest or contact of a broker or operator and you want to know why your details are stored, please contact that company first: it is the controller of that record. We will pass on requests we cannot answer ourselves.
Categories of personal data
Depending on how you interact with DinghyFleet, we may handle:
- Identity and profile data
- Name, email address, avatar image, job title or role, preferred language and time zone, phone or messaging number if you provide one.
- Authentication data
- Login credentials handled by our authentication provider, sign-in method (email link or Google), session tokens, sign-in timestamps and IP address used for security.
- Organization and membership data
- Which organization you belong to, your role and permissions, active workspaces, invitations you send or receive, and lifecycle events such as activation or removal.
- Business content
- Records your organization creates: client and contact details, charter requests, offers and pricing, bookings and charter-preparation data, yacht and operator records, documents, photos, notes and collaboration messages.
- Billing data
- Legal business name, billing address, tax identification numbers, subscription and seat quantity, payment status and invoice history. Card details are entered on Stripe's hosted pages and are never stored by us.
- Support and communication data
- Messages you send us through the in-app support surfaces or by email, and our replies, including any attachments.
- Technical and usage data
- Device and browser type, approximate location derived from IP address, pages and features used, error and diagnostic logs, and audit entries recording significant actions performed in an organization.
- Client-facing link data
- When a broker shares an offer or journey link with an end client, we process the recipient's interaction with that link (opening it, feedback given) on behalf of the broker's organization.
We do not intentionally collect special categories of personal data (such as health data) and ask you not to put such data into free-text fields.
Where the data comes from
We obtain personal data:
- directly from you, when you create an account, complete your profile, or contact us;
- from your organization's administrators and colleagues, for example when they invite you or record your role;
- from organizations using the platform, when they enter details about their clients, operators, partners or guests;
- from the sign-in provider you choose (for example Google), which returns your basic profile information;
- automatically from your device when you use the platform, through server logs and essential browser storage.
Purposes and legal bases
Where we act as a controller, we rely on the following legal bases under Article 6(1) GDPR:
- Performance of a contract — Art. 6(1)(b)
- Creating and administering accounts and organizations, giving access to workspaces and features, providing support, and delivering the subscription you or your organization purchased.
- Legal obligation — Art. 6(1)(c)
- Issuing and retaining invoices and accounting records, meeting tax obligations, and responding to lawful requests from competent authorities.
- Legitimate interests — Art. 6(1)(f)
- Keeping the platform secure and available, preventing abuse and fraud, maintaining audit logs, diagnosing faults, improving the product, managing the customer relationship, and establishing, exercising or defending legal claims. We balance these interests against your rights and you may object at any time (see “Your rights”).
- Consent — Art. 6(1)(a)
- Only where we ask for it separately, for example before storing any non-essential information on your device. Consent can be withdrawn at any time without affecting processing carried out before withdrawal.
Where we act as a processor, the legal basis for processing business content is determined by the organization that acts as controller, not by us.
International transfers
We aim to keep data hosted within the European Economic Area. Some of our providers, or their sub-processors, may nevertheless process data outside the EEA — in particular for support, infrastructure operations or AI features.
Where a transfer outside the EEA takes place, we rely on an adequacy decision of the European Commission or on the European Commission's Standard Contractual Clauses together with additional technical and organisational safeguards. You can request information about the safeguards applied by writing to us at the contact address in this policy.
How long we keep data
We keep personal data only as long as needed for the purpose it was collected for:
- account and profile data: for as long as the account exists, and for a short period afterwards to handle reversals and disputes;
- business content in a workspace: for as long as the organization keeps it. Many records are archived rather than deleted so that history stays auditable for the organization; the organization decides when to remove them;
- organization lifecycle records: organizations that are deactivated or removed are retained in a read-only, audit-only state rather than erased, so that past commercial activity can be reconstructed if challenged;
- billing and accounting records: for the statutory retention period under Polish tax law (currently five years counted from the end of the calendar year in which the tax became payable);
- security, audit and diagnostic logs: normally up to 24 months, unless a longer period is needed to investigate an incident or defend a claim.
When an account is deleted, we remove or irreversibly anonymise the personal data associated with it, except where we must keep specific records for the legal or evidential reasons described above.
Security
We apply technical and organisational measures appropriate to the risk, including:
- strict tenant isolation, so that data belonging to one organization is only accessible to that organization, enforced at database level by row-level security rules;
- role-based permissions, with sensitive administrative capabilities restricted server-side;
- encryption in transit, encrypted storage at rest, and hardened access to production systems;
- logging of significant actions, regular reviews of access rules, and least-privilege service accounts.
No system can be guaranteed absolutely secure. If a personal data breach is likely to result in a risk to individuals, we will notify the supervisory authority and, where required, the affected organizations and individuals without undue delay.
Your rights
Subject to the conditions in the GDPR, you have the right to:
- obtain confirmation of whether we process your data, and a copy of it;
- have inaccurate data corrected and incomplete data completed;
- have data erased where one of the grounds in Article 17 applies;
- restrict processing, or object to processing based on our legitimate interests;
- receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, where processing is based on consent.
To exercise a right, write to office@dinghyfleet.com. We may need to verify your identity, and we will respond within one month, extendable by two further months for complex requests. If your request concerns data an organization controls, we will forward it to that organization and support them in answering it.
You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work. Our lead authority is the President of the Personal Data Protection Office (UODO), Warsaw, Poland.
Whether providing data is required
Providing your name, email address and authentication data is necessary to create an account and use the platform; without it we cannot provide the service. Providing complete billing identity and tax data is necessary to purchase a paid subscription and to issue a valid invoice.
Other data — such as your avatar, phone number or preferred language — is optional and only improves your experience. We do not make decisions producing legal effects about you based solely on automated processing, and we do not carry out profiling for that purpose.
No use by minors
DinghyFleet is offered exclusively to businesses and to individuals acting on their behalf who are at least 18 years old. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact us and we will delete it.
Changes and how to reach us
We may update this policy to reflect changes to the platform, to our providers, or to the law. The current version is always published at /privacy with its effective date. If a change materially affects you, we will give notice in the application or by email before it takes effect.
For any question about this policy or about how we handle your data, contact us:
DinghyFleet sp. z o.o.Jana Heweliusza 11/81180-890 Gdańsk, PolandVAT ID: PL5252724741Email: office@dinghyfleet.com