Privacy Policy
Last updated: 2026-08-24
1. Controller
The controller responsible for data processing on this website is:
Fabian Fisahn
Dietrich-Bonhoeffer-Str. 28
10407 Berlin
Germany
Email: info@boatdata.app
2. Scope Of This Policy
This policy explains how personal data is processed when you visit this website, use its legal pages, or contact us by email. Separate mobile app processing, including premium access, subscription handling, and store-related entitlement checks, is documented in the App Privacy Policy and the Terms of Use.
3. Legal Bases Under GDPR
Processing is based in particular on:
- Article 6(1)(a) GDPR (consent), where consent is requested
- Article 6(1)(b) GDPR (contract or pre-contractual steps)
- Article 6(1)(c) GDPR (legal obligations)
- Article 6(1)(f) GDPR (legitimate interests, e.g. secure website operation)
4. Purposes Of Processing
This website is an informational page for the Boat Data app. Personal data is only processed to the extent technically necessary to provide the website, ensure security, and handle direct contact requests.
5. Hosting And Server Log Files
When this website is accessed, the hosting provider may process technical log data such as:
- IP address (possibly shortened/anonymized by the provider)
- Date and time of the request
- Requested page/resource
- Browser and operating system information
- Referrer URL
Legal basis: Article 6(1)(f) GDPR (legitimate interest in secure and stable website operation). If legally required, processing under agreements with processors follows Article 28 GDPR.
6. Content Delivery Networks, Fonts, And Third-Party Resources
This website uses externally hosted resources, including web fonts from Google Fonts (Google Ireland Limited). When loading such resources, technical request data (including IP address) may be transmitted to the provider.
Legal basis: Article 6(1)(f) GDPR (consistent presentation and performance). If mandatory in your jurisdiction, this can be switched to self-hosted assets or consent-based loading.
7. Cookies, Local Storage, And Tracking
This static website does not intentionally set tracking cookies and does not intentionally use analytics or advertising trackers.
If analytics, marketing tags, or similar technologies are added later, they should be activated only after valid consent where required by law.
8. Contact By Email
If you contact us by email, your message and contact details are processed to handle your request. Legal basis: Article 6(1)(b) and/or 6(1)(f) GDPR, depending on the nature of your request.
9. Optional Processing Activities (Only If Implemented)
If these features are introduced, additional processing may occur:
- Newsletter delivery and engagement tracking
- Contact forms and support ticket systems
- User accounts, authentication, and subscription management
- Payment processing via payment service providers
- Usage analytics, crash reporting, and performance monitoring
- Embedded third-party media, maps, or social widgets
Before activation, this policy should be updated with concrete providers, retention periods, legal bases, and user opt-out/consent mechanisms. For app subscriptions and payments, also keep the App Privacy Policy and Terms of Use aligned.
10. Recipients And Processors
Personal data may be processed by technical service providers acting as processors (for example hosting, email, infrastructure, and security providers) under applicable contractual safeguards.
11. International Data Transfers
Where data is transferred outside the European Economic Area, transfers are performed only if an adequate protection level is ensured, such as through adequacy decisions, Standard Contractual Clauses, or other lawful safeguards.
12. Data Retention
Personal data is retained only as long as necessary for the respective purpose or to comply with legal retention obligations.
13. Data Subject Rights Under GDPR
You have the right to request:
- Access to your personal data (Article 15 GDPR)
- Rectification of inaccurate data (Article 16 GDPR)
- Erasure of your data (Article 17 GDPR)
- Restriction of processing (Article 18 GDPR)
- Data portability (Article 20 GDPR)
- Objection to processing (Article 21 GDPR)
- Withdrawal of consent at any time (Article 7(3) GDPR)
You also have the right to lodge a complaint with a supervisory authority in your EU member state.
14. Right To Lodge A Complaint
You may contact any competent supervisory authority, in particular in your habitual residence, workplace, or place of the alleged infringement.
15. Automated Decision-Making
No automated decision-making (including profiling) with legal or similarly significant effect is currently carried out through this website.
16. Security Measures
Appropriate technical and organizational measures are implemented to protect data against unauthorized access, alteration, disclosure, or destruction.
17. Data From Minors
This website is not intentionally directed at children under the age where parental consent is required by applicable law. If such data is identified, it will be handled according to legal requirements.
18. Changes To This Policy
This privacy policy may be updated if legal requirements or website functionality changes. The current version is always available on this page.
Note: This policy is designed as a detailed baseline for common EU/GDPR scenarios. It does not replace legal advice for your specific business model, integrations, and jurisdictions.