DivemetoHeaven Logo
DivemetoHeavenPremium Liveaboard Training & Dive TravelDeep into the Ocean

Privacy

Privacy Policy

Information about the processing of personal data when using DivemetoHeaven and during inquiries, bookings, payments and the delivery of diving courses.

Last updated: 24 July 2026.

Controller

  • Fabian Messer, handelnd unter DivemetoHeaven Saonestraße 27 60528 Frankfurt am Main Deutschland
  • Privacy contact: [email protected]

Website, hosting and security

  • This website is hosted on a Hetzner server in Germany. We use Cloudflare to deliver the website reliably, defend against attacks and protect access to internal areas. This may involve processing the IP address, time of access, requested URL, previously visited page (referrer), browser and device information and security-related events.
  • Processing is carried out to provide the website securely, reliably and with protection against misuse on the basis of Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the service. Our own technical logs are stored only to a limited extent and regularly overwritten. Their retention period depends on the volume of log data generated. In the event of a specific security incident, required log data may be retained for longer exclusively to investigate and secure that incident.

Contact and travel inquiries

  • For an inquiry, we process first name, last name, email address, optional telephone number, message, inquiry purpose, preferred contact method and, where applicable, the related product. The data is processed to respond to the inquiry and provide personal advice.
  • The legal basis is Article 6(1)(b) GDPR for pre-contractual measures or a contract and Article 6(1)(f) GDPR for general communication and the orderly handling of requests.
  • Travel cannot be booked directly through this website. If you request a referral after personal consultation, we transmit the necessary contact details and information about the requested trip to an external travel agency. We will tell you which travel agency will handle the referral before transmitting your data. The legal basis is Article 6(1)(b) GDPR. We generally remove our operational copies 90 days after the confirmed transfer. A referral record limited to what is necessary is retained for three years from the end of the relevant calendar year.
  • Depending on classification, spam and test inquiries are deleted after 14 days, general inquiries after 90 days and concrete offers without a contract after six months. Legally relevant contractual correspondence may be retained for six years from the end of the calendar year. A specific legal hold may temporarily suspend deletion to the extent required.

Course and training bookings

  • For directly bookable courses and training sessions, we process the participant's name, email address, optional telephone number, participant count, selected product and session, booking status, invoice name and invoice address. For a business invoice, company, contact person and VAT ID may also be processed.
  • Processing is used for booking, capacity management, performance of the contract, communication, invoicing and evidence of the business transaction. The legal bases are Article 6(1)(b) and (c) GDPR.
  • Operational participant data that is no longer required is generally removed 90 days after the course ends or the matter is finally concluded. A reduced contract and booking record is retained for three years from the end of the calendar year. Invoices, accounting vouchers and the payment references required for them are generally retained for eight years from the end of the calendar year. Separate commercial records and annual financial statements outside the website customer record may be retained for ten years.
  • Where a booking process is not completed and no contract is concluded, we generally delete the booking, participant, invoice and payment reference data 90 days after the last activity once no payment, reservation or clarification remains outstanding.

SSI registration and course documents

  • Certain master data is required to register and certify an SSI course, in particular the participant's name, date of birth and email address. This data is entered in the SSI system or linked to an existing SSI profile. Where technical processing is handled by an external SSI Training Center, we will identify the responsible Training Center before transmitting your data. The legal basis is Article 6(1)(b) GDPR.
  • The required blank SSI course documents are sent to you by email before the course begins. You complete the documents, in particular the Training Record, medical self-declaration and Responsible Diver Code, by hand and bring the originals with you no later than the start of the course. The documents are not collected digitally through the website.
  • After the course has been completed, the non-medical information and records required as evidence of training and for certification are submitted to SSI or through the responsible SSI Training Center. Health information from the medical questionnaire is not transmitted in this process. We generally remove our own operational digital copies of registration and certification data 90 days after certification has been completed. Further retention by SSI and the responsible Training Center is governed by their own responsibilities and requirements.
  • For participants who are minors, we additionally process the necessary contact details and declarations of their legal guardians where required for the booking, safe delivery of the course and registration and certification with SSI.

Medical questionnaire (fitness to dive)

  • Before participating in a diving course or diving activity, participants must complete a medical fitness-to-dive questionnaire by hand and bring the original to the course. The questionnaire may contain information about pre-existing conditions, medication and physical limitations, as well as the participant's name, date of birth and contact details.
  • Processing serves to assess fitness to dive, protect participants' health and safety and fulfil our duty of care. The legal bases are Article 6(1)(b) GDPR for the safe performance of the contract and, where health data is concerned, explicit and separately documented consent under Article 9(2)(a) GDPR.
  • Medical information is generally processed only internally and protected against unauthorized access. It is disclosed only where necessary for medical care in an emergency or where required by law.
  • The original paper documents are retained for ten years after the later of course completion and certification and are then securely destroyed. Consent may be withdrawn at any time with effect for the future. The lawfulness of processing carried out before withdrawal remains unaffected; statutory retention obligations and the establishment, exercise or defence of legal claims may prevent immediate destruction.
  • If you submit a medical certificate for a medically justified cancellation, we require only confirmation of temporary or permanent unfitness to dive; no diagnosis is necessary. We process the certificate solely to review and administer the refund on the basis of Article 6(1)(b) and Article 9(2)(f) GDPR. The certificate is generally deleted 90 days after final processing unless it is required for longer because of a specific legal dispute.

Payments

  • Stripe and PayPal are used for payments. When a provider is selected, the booking, contact, amount and transaction data required for checkout, payment confirmation, refunds and fraud prevention is transmitted to that payment provider. Card and account credentials are not stored on our servers.
  • The legal bases are Article 6(1)(b) GDPR for payment processing, Article 6(1)(c) GDPR for statutory records and Article 6(1)(f) GDPR for fraud and misuse prevention. Successful, refunded or cancelled payments linked to a contract are generally retained as required booking and payment records for eight years from the end of the calendar year; failed payments without a contract are generally deleted after 90 days.

Email communication

  • Brevo is used for transactional system emails concerning inquiries, bookings, payments and waitlists. Microsoft 365 is used for personal business communication, manual delivery of blank course documents and necessary communications with partners.
  • Depending on the context, the legal basis is Article 6(1)(b), (c) or (f) GDPR. We generally delete our own copies of successfully sent transactional system emails after 30 days and permanently undeliverable messages after 90 days. Business emails in Microsoft 365 are deleted according to the retention period applicable to the respective matter.

Waitlist

  • When joining a waitlist, we process first name, last name, email address, optional telephone number, participant count, selected session, status and technically required invitation and unsubscribe data. The purpose is to manage available places and provide availability notifications. The legal basis is Article 6(1)(b) GDPR.
  • Personal data in all waitlist entries is anonymized regardless of status 14 days after the related course or training begins. Invitation tokens are valid for no more than 24 hours and are invalidated after use. Booking, payment and tax-required data is handled separately and is not removed by waitlist deletion.

Deletion and retention

  • We use technically protected deletion and anonymization processes to comply with the defined retention periods. Inquiries are first reviewed, closed and assigned to an appropriate retention category by us. Once the defined period has expired, the inquiry and the associated personal data are automatically removed from the affected website systems.
  • Personal data in waitlist entries is anonymized regardless of status 14 days after the related course or training begins. Associated personal data and website messages are deleted or anonymized. A specific legal hold may suspend a deletion that is due only for as long and to the extent required for the affected matter.
  • All other data is deleted or anonymized according to the periods stated in this policy. External recipients are responsible for deleting their own data holdings in accordance with the rules applicable to them.
  • Access-protected database backups are used exclusively for restoration and are generally retained for 30 days. Until their scheduled expiry, backups may still contain data that has already been deleted from the active system, but that data is not processed from the backups for any other purpose.

Cookies and external pages

  • At launch, we do not use optional analytics, tracking, marketing or social media services and do not set corresponding optional cookies. In particular, Google Analytics, Google Tag Manager and advertising pixels are not used.
  • Strictly necessary cookies or comparable storage may be used for security checks, protected administrative access and requested booking or payment processes. The legal basis is section 25(2) no. 2 TDDDG; subsequent data processing is based on the applicable GDPR legal bases stated above.
  • When you open the external checkout of Stripe or PayPal, the privacy and cookie information of the selected provider also applies there.

Recipients and international processing

  • Depending on the specific process, Hetzner, Cloudflare, Brevo, Microsoft 365, Stripe, PayPal and SSI may receive the data they require for their respective role. The same applies to an external travel agency or SSI Training Center where their involvement is necessary for the specific process. We will identify the responsible partner before transmitting your data. Within our operation, access is limited to persons who require it for their duties.
  • Service providers may also process data outside the European Economic Area. Where no adequacy decision exists, transfers take place only on the basis of appropriate safeguards, in particular EU Standard Contractual Clauses, or a statutory exception. Information about the safeguards used can be requested via [email protected].

Your rights

  • Subject to the statutory requirements, you have the right of access, rectification, erasure, restriction of processing and data portability. You may withdraw consent at any time with effect for the future.
  • You may object to processing based on Article 6(1)(f) GDPR on grounds relating to your particular situation. Send privacy requests to [email protected].
  • You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information, Wilhelmstrasse 7, 65185 Wiesbaden, Germany.
  • Website of the Hessian data protection supervisory authority
  • We do not make decisions based solely on automated processing that produce legal or similarly significant effects, and we do not carry out profiling. Data marked as required is needed for the contract, booking, payment or certification. Without this information, we cannot complete the relevant process.