Privacy Policy

Effective date: 8 August 2026

This Privacy Policy explains how DinghyFleet sp. z o.o. (“DinghyFleet”, “we”, “us”) handles personal data in connection with the DinghyFleet platform, a business-to-business workspace used by yacht-charter brokers and operators to manage requests, offers, bookings and charter preparation.

DinghyFleet is designed for professionals acting in the course of a business. It is not a consumer service and is not intended for anyone under 18. Where this policy uses “personal data”, “controller”, “processor” or “data subject”, those terms have the meaning given in the EU General Data Protection Regulation (GDPR).

Who we are

The company responsible for the platform is DinghyFleet sp. z o.o., a limited liability company with its registered office at Jana Heweliusza 11/811, 80-890 Gdańsk, Poland.

DinghyFleet sp. z o.o.Jana Heweliusza 11/81180-890 Gdańsk, PolandVAT ID: PL5252724741Email: office@dinghyfleet.com

We have not appointed a Data Protection Officer, because we are not required to do so. Privacy questions, access requests and complaints should be sent to the contact address above and are handled by our team directly.

Our role: controller and processor

DinghyFleet is multi-tenant software. Each organization that signs up is an independent tenant: it decides who its members are, which workspaces it activates, which clients, yachts, requests, offers and bookings it records, and how long it keeps working with them.

We act as an independent controller for data we determine the purposes of ourselves: account and login data, organization and membership records, subscription, seat and billing data, support correspondence, security and audit logging, and the operation, security and improvement of the platform.

We act as a processor on behalf of an organization for the business content that organization puts into its workspaces — for example client contact records, charter requests, offers, booking details, uploaded documents, notes and collaboration messages. For that content, the organization is the controller: it decides what to collect, why, and on what legal basis, and it is responsible for informing the individuals concerned.

Where we act as a processor, we process the content only on documented instructions from the organization, which are given through the functionality of the platform and any data processing terms agreed with us. Organizations that require a separate data processing agreement can request one from us.

If you are a client, guest or contact of a broker or operator and you want to know why your details are stored, please contact that company first: it is the controller of that record. We will pass on requests we cannot answer ourselves.

Categories of personal data

Depending on how you interact with DinghyFleet, we may handle:

Identity and profile data
Name, email address, avatar image, job title or role, preferred language and time zone, phone or messaging number if you provide one.
Authentication data
Login credentials handled by our authentication provider, sign-in method (email link or Google), session tokens, sign-in timestamps and IP address used for security.
Organization and membership data
Which organization you belong to, your role and permissions, active workspaces, invitations you send or receive, and lifecycle events such as activation or removal.
Business content
Records your organization creates: client and contact details, charter requests, offers and pricing, bookings and charter-preparation data, yacht and operator records, documents, photos, notes and collaboration messages.
Billing data
Legal business name, billing address, tax identification numbers, subscription and seat quantity, payment status and invoice history. Card details are entered on Stripe's hosted pages and are never stored by us.
Support and communication data
Messages you send us through the in-app support surfaces or by email, and our replies, including any attachments.
Technical and usage data
Device and browser type, approximate location derived from IP address, pages and features used, error and diagnostic logs, and audit entries recording significant actions performed in an organization.
Client-facing link data
When a broker shares an offer or journey link with an end client, we process the recipient's interaction with that link (opening it, feedback given) on behalf of the broker's organization.

We do not intentionally collect special categories of personal data (such as health data) and ask you not to put such data into free-text fields.

Where the data comes from

We obtain personal data:

  • directly from you, when you create an account, complete your profile, or contact us;
  • from your organization's administrators and colleagues, for example when they invite you or record your role;
  • from organizations using the platform, when they enter details about their clients, operators, partners or guests;
  • from the sign-in provider you choose (for example Google), which returns your basic profile information;
  • automatically from your device when you use the platform, through server logs and essential browser storage.

Who we share data with

We do not sell personal data and we do not share it for advertising. We disclose personal data only to:

  • other members of your own organization, according to the roles and permissions your administrators configure;
  • organizations you deliberately collaborate with in the platform — for example, when a broker sends a request or partnership proposal to an operator, the information contained in that exchange becomes visible to that operator, and vice versa;
  • recipients of links your organization shares, such as a client who opens an offer or charter journey link;
  • service providers acting for us under contract: our cloud application, database, authentication, file storage and email delivery infrastructure providers; Stripe Payments Europe for subscription billing, tax determination and invoicing; and providers of AI features used to assist drafting, where content you submit to those features is processed to return a result and is not used to train public models;
  • external professional advisers (lawyers, accountants, auditors) and insurers, where necessary and subject to confidentiality;
  • competent authorities, courts or acquirers in a corporate transaction, where we are legally required or permitted to disclose.

Third-party marine weather data is retrieved for the locations you look up; we do not send your identity to that provider. Every provider acting on our behalf is bound by a written contract that restricts them to processing data for us and requires appropriate security measures.

International transfers

We aim to keep data hosted within the European Economic Area. Some of our providers, or their sub-processors, may nevertheless process data outside the EEA — in particular for support, infrastructure operations or AI features.

Where a transfer outside the EEA takes place, we rely on an adequacy decision of the European Commission or on the European Commission's Standard Contractual Clauses together with additional technical and organisational safeguards. You can request information about the safeguards applied by writing to us at the contact address in this policy.

How long we keep data

We keep personal data only as long as needed for the purpose it was collected for:

  • account and profile data: for as long as the account exists, and for a short period afterwards to handle reversals and disputes;
  • business content in a workspace: for as long as the organization keeps it. Many records are archived rather than deleted so that history stays auditable for the organization; the organization decides when to remove them;
  • organization lifecycle records: organizations that are deactivated or removed are retained in a read-only, audit-only state rather than erased, so that past commercial activity can be reconstructed if challenged;
  • billing and accounting records: for the statutory retention period under Polish tax law (currently five years counted from the end of the calendar year in which the tax became payable);
  • security, audit and diagnostic logs: normally up to 24 months, unless a longer period is needed to investigate an incident or defend a claim.

When an account is deleted, we remove or irreversibly anonymise the personal data associated with it, except where we must keep specific records for the legal or evidential reasons described above.

Security

We apply technical and organisational measures appropriate to the risk, including:

  • strict tenant isolation, so that data belonging to one organization is only accessible to that organization, enforced at database level by row-level security rules;
  • role-based permissions, with sensitive administrative capabilities restricted server-side;
  • encryption in transit, encrypted storage at rest, and hardened access to production systems;
  • logging of significant actions, regular reviews of access rules, and least-privilege service accounts.

No system can be guaranteed absolutely secure. If a personal data breach is likely to result in a risk to individuals, we will notify the supervisory authority and, where required, the affected organizations and individuals without undue delay.

Your rights

Subject to the conditions in the GDPR, you have the right to:

  • obtain confirmation of whether we process your data, and a copy of it;
  • have inaccurate data corrected and incomplete data completed;
  • have data erased where one of the grounds in Article 17 applies;
  • restrict processing, or object to processing based on our legitimate interests;
  • receive data you provided to us in a structured, commonly used, machine-readable format and have it transmitted to another controller, where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time, where processing is based on consent.

To exercise a right, write to office@dinghyfleet.com. We may need to verify your identity, and we will respond within one month, extendable by two further months for complex requests. If your request concerns data an organization controls, we will forward it to that organization and support them in answering it.

You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence or place of work. Our lead authority is the President of the Personal Data Protection Office (UODO), Warsaw, Poland.

Whether providing data is required

Providing your name, email address and authentication data is necessary to create an account and use the platform; without it we cannot provide the service. Providing complete billing identity and tax data is necessary to purchase a paid subscription and to issue a valid invoice.

Other data — such as your avatar, phone number or preferred language — is optional and only improves your experience. We do not make decisions producing legal effects about you based solely on automated processing, and we do not carry out profiling for that purpose.

No use by minors

DinghyFleet is offered exclusively to businesses and to individuals acting on their behalf who are at least 18 years old. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact us and we will delete it.

Changes and how to reach us

We may update this policy to reflect changes to the platform, to our providers, or to the law. The current version is always published at /privacy with its effective date. If a change materially affects you, we will give notice in the application or by email before it takes effect.

For any question about this policy or about how we handle your data, contact us:

DinghyFleet sp. z o.o.Jana Heweliusza 11/81180-890 Gdańsk, PolandVAT ID: PL5252724741Email: office@dinghyfleet.com