Legal documents

Privacy Policy

This page explains what personal data we collect when you use DiveLog, why we process it, who we share it with, and how you can control it.

Last updated: September 2, 2026

1.Data controller

The data controller for the personal data collected through DiveLog is Enea Del Lama ("we", "us"), who determines the purposes and means of processing as data controller.

For any privacy-related request you can write to privacy@divelogs.app.

2.Data we collect

  • Account data: display name, email address, login credentials (stored encrypted), optional profile photo, certification level, language and display preferences.
  • User content: dive data (date, site, depth, times, gas mixes and pressures, notes), profiles downloaded from your dive computer, uploaded or linked photos and videos, dive buddies, dive centers, boats and equipment.
  • Usage and technical data: IP address, device and browser type, pages visited, timestamps, error logs and aggregate statistics.
  • Communications: messages and attachments sent to support.
  • Subscription data: card and billing data are collected and processed directly by Paddle (Merchant of Record). From Paddle we receive only the minimum data needed to manage the subscription (email, country, subscription status and period, last digits of the payment method).

3.Purposes and legal bases

  • Creating your account and providing the logbook — performance of a contract.
  • Managing subscriptions, the free trial and billing — performance of a contract and legal obligation.
  • Customer support — performance of a contract and legitimate interest.
  • Security, fraud and abuse prevention, access auditing — legitimate interest.
  • Product improvement through aggregate statistics — legitimate interest.
  • Service notifications by email and in-app (dive sharing, maintenance reminders, trial expiration) — performance of a contract.
  • Optional communications about product updates — consent, which you can withdraw at any time.

4.Data sharing and subprocessors

We do not sell personal data. We share it only with selected providers acting as data processors, under data processing agreements:

  • Paddle — Merchant of Record: purchases, subscriptions, payments, invoicing and tax compliance.
  • Hosting and cloud infrastructure — database, media storage, application hosting.
  • Transactional email provider — authentication emails and service notifications.
  • Google Analytics — aggregate usage statistics for the site.
  • Google Drive — only if you voluntarily connect your account to select images to attach to a dive.
  • Professional advisors (legal, tax) when strictly necessary.
  • Competent authorities, if required by law.

5.Data you share with other users

When you add a registered buddy to a dive or share a dive, the data for that dive (site, date, depth, duration, profile and any media) becomes visible read-only to the recipient, together with your display name. You can revoke a share at any time from the dive's page. Images you generate for social media contain only the data you choose to overlay.

6.International transfers

Some providers may process data outside the European Economic Area. In such cases, the transfer relies on European Commission adequacy decisions or on Standard Contractual Clauses, with additional security measures where necessary.

7.Data retention

  • Account and dive content: for the entire lifetime of the account.
  • Technical and audit logs: up to 12 months, according to the configured retention period.
  • Tax and billing documents: for the period required by applicable law (typically 10 years), managed by Paddle.
  • Support requests: up to 24 months after the request is closed.

8.Your rights

Under the GDPR, you may at any time:

  • access your data and obtain a copy of it;
  • request rectification or updating;
  • request erasure;
  • request restriction of, or object to, processing;
  • request data portability in a readable format;
  • withdraw any consent given, without affecting past processing;
  • lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).

You can update most of your data directly from the Settings page of the app. For other requests, write to privacy@divelogs.app: we respond within one month of receiving the request.

9.Security

We adopt technical and organizational measures appropriate to the risk: encryption in transit (HTTPS/TLS) and at rest, per-user data isolation via database-level access rules, the principle of least privilege for administrative access, an audit log of sensitive operations, periodic backups and monitoring of anomalous access. No system, however, is 100% secure.

11.Minors

DiveLog is not intended for individuals under 16 years of age. If you believe a minor has provided us with personal data without the consent of a parent or legal guardian, please contact us and we will delete it.

12.Changes to this policy

We may update this policy to reflect changes to the service or to applicable law. Material changes will be communicated by email or via an in-app notice before they take effect.

13.Contact

Enea Del Lama — privacy@divelogs.app. For questions about orders, payments and invoices you can also contact Paddle, Merchant of Record for our purchases, as described in the Terms and Conditions.

This document covers data processing by DiveLog. Purchases are handled by Paddle as Merchant of Record.

See also: Terms & Conditions · Privacy Policy · Refund Policy