This policy explains what personal data Sailnboat OÜ collects, why we collect it, who we share it with and what rights you have. We are established in the European Union, so the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to everything described here.
1. Who is responsible
The controller of your personal data is:
| Controller | Sailnboat OÜ (registry no. 17557623) |
|---|---|
| Address | Narva mnt 5, 10117 Tallinn, Estonia |
| Contact for data protection | info@sailnboat.com |
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection enquiries go to the address above.
2. What we collect and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Name, email, phone | Handling your booking request and communicating with you and the charter operator | Art. 6(1)(b) — performance of a contract | 7 years (accounting obligations under Estonian law) |
| Booking details: yacht, dates, base, party size | Making and confirming the reservation | Art. 6(1)(b) — performance of a contract | 7 years |
| Crew list data where the operator or local authority requires it (full name, date of birth, nationality, passport or ID number) | Legal formalities for departure, required by port authorities in several jurisdictions | Art. 6(1)(c) — legal obligation of the operator | Deleted once the charter is complete and the operator confirms it is no longer needed |
| Messages you send us | Answering your enquiry | Art. 6(1)(f) — legitimate interest in responding | As long as needed to handle the matter and any follow-up, and for as long as a related claim could still be brought |
| Account: name, email, password (stored hashed), yachts you saved | Running your account and showing you the yachts you saved | Art. 6(1)(b) — performance of a contract | For as long as you have an account. Ask us to close it and we delete it, keeping only what accounting and tax law require; copies in routine backups are overwritten in the normal backup cycle |
| IP address and browser identification | Keeping the service secure and working: investigating abuse, fraud attempts, scraping and faults | Art. 6(1)(f) — legitimate interest in network and information security (Recital 49) | As long as it remains useful for that purpose, and longer where an investigation, dispute or legal claim is open |
| Pages viewed and searches made, recorded without identifying you and without any cookie of its own | Understanding what our customers look for and cannot find, deciding which yachts to add, and improving search, ranking and the rest of the service | Art. 6(1)(f) — legitimate interest in understanding and improving our own service | As long as it is useful for those purposes. Aggregated and anonymous figures, which can no longer be traced to anyone, are kept indefinitely |
| Behaviour within a visit: time spent on a page, scroll depth, which yachts you open, save or request | Seeing which listings are useful, improving search, ranking and our own recommendation and assistant systems, and showing you yachts that fit what you are looking for | Art. 6(1)(f) — legitimate interest. No new cookie is set for this and the data never leaves us | As long as it is useful for those purposes |
| Linking one visit to another — recognising the same browser across sessions, so a search you made as a guest can be joined to your account later | Recognising you when you come back, including in a later season, so we can pick up where you left off and tell you when a yacht you liked is discounted | Art. 6(1)(a) — consent | Until you withdraw consent |
| Newsletter email address | Sending offers you asked for | Art. 6(1)(a) — consent | Until you unsubscribe |
We do not collect special categories of data (Art. 9 GDPR).
3. Measurement, personalisation and your choice
We want to be exact here, because this is where most privacy policies are vague.
Within a single visit we measure what happens on our own site: pages viewed, searches made, how long you spend on a page, how far you scroll, and which yachts you open, save or request. This does not set any cookie of its own — it rides on the session cookie the site needs to work at all — and it ends when your visit ends. We do this on the basis of our legitimate interest in understanding and improving our own service, and we describe it here so you know it happens.
Across visits, only if you agree we set one long-lived cookie so we can recognise the same browser next time. That is the part that turns separate visits into a picture of one person, so that is the part we ask permission for. It is what lets us pick up where you left off next season instead of starting from zero.
Building a picture of what you seem to be looking for — boat type, size, destination, price range — is profiling in the sense of Art. 4(4) GDPR, and we say so plainly rather than burying it.
If you have an account, your activity is connected to it, because you have told us who you are. That is part of running the service for you; it is not a cookie question.
What we use it for:
- showing you yachts that fit what you are actually looking for, instead of the same list everyone sees
- letting our assistant answer with your search in mind, so you are not asked the same question twice
- improving how our search, filters and ranking work — which listings are useful and which are not
- developing and tuning our own recommendation and assistant systems, including the models behind them
- deciding which yachts and destinations to add to the catalogue
- telling you about seasonal offers, price drops and new yachts that match what you were looking for — including in later seasons, because charter is a yearly cycle and the boat you liked may only be discounted next spring
All of this is our own work on our own service. We do not sell this data, we do not share it with advertising networks, and we do not use a third-party analytics service — there is no Google Analytics, no Meta pixel and no advertising tag on this site.
This profile does not decide anything about you. It changes which yachts we show and how we word a suggestion. It never affects a price, whether a booking is accepted, or any other decision with legal or similarly significant effects — so there is no automated decision-making within the meaning of Art. 22 GDPR.
You can withdraw that consent at any time from Cookie settings, and it takes effect immediately: we delete the long-lived cookie, drop the key that joined your visits together, and stop recognising you across sessions. Measurement inside a single visit continues, because it never depended on your consent and never identified you across visits.
If you want the data itself gone rather than just unlinked, that is a separate and stronger right (Art. 17) and we act on it — write to us and we erase it.
How long we keep things
We do not put a fixed number of days on this, because the honest answer is a criterion, not a date: we keep it while it is still useful for the purposes above, and no longer. Where an investigation, a dispute or a legal claim is open, the related records are kept until that is resolved.
In practice that means years rather than months, and the reason is the nature of the business. Yacht charter runs on a yearly cycle: someone looks in one summer and books the next, or the one after. If we forgot you between seasons we could not tell you that the catamaran you liked in Greece is now discounted — which is one of the more useful things we can do for you.
Aggregated and anonymous figures — counts, averages, "how many people searched for catamarans in Greece" — are a different matter. Once data can no longer be traced back to any person it is no longer personal data, and we keep it indefinitely.
If you would rather we did not keep it, you have two switches and both work immediately: withdraw consent from Cookie settings, or ask us to erase your data under Art. 17. We do not make you argue for it.
4. Who we share data with
We share only what is necessary, only with parties who need it:
- The charter operator you are booking with. They need your name, contact details and party information to prepare the yacht and complete the handover. They are a separate controller for the charter contract.
- The booking platform through which we reach the operator and transmit your reservation, acting as our processor under contract.
- Our payment provider, where a payment is taken online. Card details are entered directly with them; we never see or store full card numbers.
- Our hosting and email providers, acting as processors under contract.
- Public authorities, where we are legally required to disclose.
We do not sell personal data, and we do not share it for third-party advertising.
5. Transfers outside the EEA
Some charter operators are based outside the European Economic Area — for example in the Caribbean, the Seychelles or Thailand. Where you book such a charter, your booking details are transferred to that operator because it is necessary to perform the contract you asked us to arrange (Art. 49(1)(b) GDPR). Where we use processors outside the EEA, transfers are covered by the European Commission's Standard Contractual Clauses.
6. Your rights
Under the GDPR you have the right to:
- ask what data we hold about you and receive a copy (Art. 15)
- have inaccurate data corrected (Art. 16)
- have data erased where we no longer need it (Art. 17)
- restrict how we use it while a dispute is resolved (Art. 18)
- receive your data in a portable format (Art. 20)
- object to processing based on legitimate interest (Art. 21)
- withdraw consent at any time, without affecting processing already carried out (Art. 7(3))
Write to info@sailnboat.com and we will respond within one month. There is no charge.
If you believe we have handled your data unlawfully you may complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, https://www.aki.ee) or to the supervisory authority in your country of residence.
7. Security
The site is served over HTTPS. Access to personal data is limited to people who need it for their work. Passwords are stored hashed, never in readable form.
No system is perfectly secure. If a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and inform you directly where required by Art. 34 GDPR.
8. Cookies
Cookies are covered separately in our Cookie Policy.
9. Changes
If we change this policy we will update the date at the top of this page. Where a change materially affects your rights we will tell you directly.