Diving.Software Legal
Privacy Notice
How Webase Global, Diving.Software and dive businesses handle personal data.
1. Scope and contacts
This Notice explains how personal data is handled across Diving.Management, Diving.Software and Diving.Voyage. The Platform Provider and privacy contact are identified in the Platform Identity Schedule. A booking also identifies the relevant dive Operator and its contact details.
Roles depend on purpose:
- the Platform Provider is controller for Platform accounts, security, public directory governance, billing, support, fraud prevention, legal compliance and product administration;
- Diving.Voyage is the Platform surface controlling the diver's global account/profile and preferences;
- each Operator is an independent controller for its customers, bookings, service delivery, safety, eligibility, documents, incidents, accounting and legal obligations;
- the Platform Provider acts as the Operator's processor where it stores or handles tenant data only on documented instructions, as set out in the DPA;
- Stripe acts under the roles described in its own privacy terms for payment, identity, fraud and compliance activities.
We do not treat joint controllership as the default. If a specific feature jointly determines purposes and means, the parties must document that arrangement and disclose its essence before launch.
2. Data we process
Depending on use, data includes:
- account and identity: name, email, phone, user UUID, verification, authentication and preferences;
- organization: legal/trading name, registration/tax details, addresses, contacts, staff, roles and permissions;
- diver/customer profile: date of birth, gender where provided, nationality, language, address, emergency contacts, dive level, agency, credentials, experience and last dive;
- booking and operations: participants, offers, dates, locations, price options, add-ons, notes, attendance, trips, sessions, equipment, staff assignments and service history;
- health and safety: medical questionnaire responses, physician clearance, insurance, waivers, accessibility/safety information and incident records;
- minors: age/date of birth, guardian identity/authority, consent and emergency details;
- documents: templates, versions, signatures, timestamps and evidence;
- payments: status, amount, currency, Stripe/customer/account references, fee/refund/dispute and payout information; we do not receive or store full card credentials;
- communications: support, inquiries, notifications and delivery evidence;
- technical/security: IP address, device/browser data, session, logs, CAPTCHA results, audit events and fraud signals;
- public content: business profiles, offers, images, opening hours, reviews and source/verification data.
3. Sources
Data comes from you; a booking lead or guardian; the Operator and authorised staff; Diving.Voyage profile sync; Stripe and other providers; public/authorised directory sources; and system activity. A person supplying another individual's data must be authorised and provide any required notice. Adult participants must personally complete sensitive declarations unless a lawful representative acts.
4. Purposes and legal bases
We and Operators process data as applicable to:
- create accounts, bookings and provide services — contract or steps requested before contract;
- operate workspaces, planning, documents, customer support and integrations — contract and legitimate interests in reliable operations;
- process payments, refunds, disputes and fraud checks — contract, legal obligation and legitimate interests;
- meet tax, accounting, safety, sanctions, regulatory and recordkeeping duties — legal obligation;
- protect accounts, tenants and the Platform — legitimate interests and legal obligations;
- handle health data for safe participation — explicit consent where used, or another applicable health, vital-interest, legal-claim or substantial-public-interest condition identified by the Operator under local law;
- use emergency contacts during an emergency — vital interests and legitimate safety interests;
- sync a Voyage profile into a named Operator's customer record — the user's explicit, versioned instruction/consent and the booking contract; withdrawal stops future optional sync but does not erase data independently required for a booking or law;
- send required service messages — contract or legitimate interests;
- send marketing — consent where required, with an unsubscribe option; booking or medical data is not used for unrelated marketing;
- analyse optional product usage — consent where required, or carefully assessed legitimate interests where law permits.
Consent is never bundled where another lawful basis is appropriate. Refusing optional consent does not prevent an unrelated service. Consent may be withdrawn prospectively without affecting prior lawful processing.
5. Sharing
We share the minimum necessary data with the booked Operator and authorised staff; Stripe and payment participants; hosting, email, security and support providers; professional advisers and auditors; certification/insurance or government bodies where requested, authorised or legally required; and emergency responders where necessary.
A Voyage profile is not generally visible to all Operators. A versioned booking instruction sends a snapshot to the selected Operator. The snapshot becomes that Operator's tenant customer/booking record. Later differences should be presented as controlled updates, not silent overwrite. Revoking the Voyage connection stops future sync; the Operator may retain existing booking/customer records under its own lawful duties.
We do not sell personal data. If law uses a broader definition of “sale” or “sharing” for advertising, any such activity must be separately disclosed and accompanied by required choices before activation.
6. International transfers
Providers and Operators may process data outside the person's country. Where restricted transfer rules apply, we use an adequacy decision, approved standard contractual clauses with appropriate module and supplementary measures, or another lawful mechanism. Transfer details and the current Provider Schedule are available from the privacy contact.
7. Retention
We retain data only for service, safety, legal, tax, security and claim purposes under the Retention Schedule. Operators may be legally required to retain booking, waiver, incident or financial records longer. Data under a legal hold is restricted rather than deleted. Backups expire on their rolling schedule.
8. Security
Measures include tenant scoping, role-based access, authenticated non-public routes, encryption in transit, controlled credentials, verified payment webhooks, audit records, restricted access to health/documents, backups, monitoring and incident response. No system is risk-free. Users must protect credentials and Operators must configure staff access appropriately.
9. Individual rights
Depending on law, you may request access, correction, deletion, restriction, portability, objection, withdrawal of consent and review of qualifying automated decisions. You may complain to your data-protection authority.
For Operator-controlled booking, medical, waiver or incident data, contact the Operator first; we will assist it under the DPA. For the Voyage account or Platform-controlled data, contact the Platform privacy address. We may verify identity and may retain or restrict data where law or legal claims require it. We will respond within the legally required period.
10. Children and minors
The Platform is not directed to children creating independent business accounts. Minor participation records are created only for a legitimate booking and under the Operator's age rules. A verified parent/legal guardian must provide required authority and consent. Data is limited to booking, safety and legal needs and is not used for behavioural advertising.
11. Automated decisions
The Platform may automate availability, price calculations, fraud flags, document status and workflow checks. It does not make a solely automated medical-fitness or final dive-safety decision. Where a legally significant solely automated decision is introduced, we will disclose logic, consequences and review rights before use.
12. Cookies and communications
Cookies and similar technologies are described in the Cookie Notice. Transactional and safety communications are part of the service. Marketing preferences are separate and may be changed at any time.
13. Changes
We may update this Notice as processing or law changes. We will display the new version and give appropriate notice for material changes. A new notice does not retrospectively create consent or change the frozen booking contract.