Home

Privacy Policy

Last updated: July 2026

1. Data Controller

Seapper (currently in the process of legal incorporation), based in Spain, is the controller of the personal data collected through seapper.com and app.seapper.com.

You can contact us at privacy@seapper.com for any privacy-related questions.

2. Data We Collect

Registration data: name, email address, company name and password (stored in encrypted, irreversible form).

Usage data: pages visited, features used, session duration and other in-platform actions, for service improvement purposes.

End-client data: names, emails and identity documents of the passengers in your bookings, entered by you as the operator. You are the controller of this data; Seapper acts as processor (see section 5).

Payment data: transactions are processed entirely through Stripe, Inc. We do not store card numbers or bank details.

Technical data: IP address, device type, browser and operating system, collected automatically when accessing the service.

3. Purpose of Processing

We process your data to: provide the contracted service and manage your account; issue invoices and manage the business relationship; send you service-related communications (operational alerts, updates, support); improve the platform through aggregated and anonymised usage analytics; and comply with applicable legal obligations.

4. Legal Basis

Performance of contract (Art. 6.1.b GDPR): for everything necessary to provide the Seapper service.

Legitimate interests (Art. 6.1.f GDPR): for usage analytics to improve the product.

Legal obligation (Art. 6.1.c GDPR): for the retention of invoices and accounting records.

Consent (Art. 6.1.a GDPR): for sending marketing communications, if you have opted in to receive them.

5. Recipients of Your Data

We may share your data with the following service providers: Stripe, Inc. for payment processing (international transfer covered by Standard Contractual Clauses); Amazon Web Services (EU region) for platform hosting; and transactional email providers for service notifications.

We do not sell your data to third parties or share it for advertising purposes.

6. Retention

Account data is retained while you are a customer and for 5 additional years after cancellation for potential claims. Billing data is retained for 10 years under tax law obligations. Technical logs are deleted after 90 days. End-client data is deleted 30 days after you cancel your account, unless the law requires longer retention.

7. Your Rights

Under the GDPR, you have the right to access, rectify, erase, port, restrict or object to the processing of your personal data. To exercise any of these rights, write to us at privacy@seapper.com.

If you believe the processing of your data violates applicable law, you can lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es) or with the supervisory authority in your country of residence.

8. Security

We apply technical and organisational measures appropriate to the level of risk: TLS encryption for all communications, AES-256 encryption for stored data, role-based access controls and periodic security reviews.

In the event of a security breach affecting your data, we will notify you within the timeframes required by the GDPR.

9. Changes to this Policy

We may update this privacy policy as needed. If the changes are significant, we will notify you by email at least 30 days in advance. The "last updated" date at the top of this document reflects the current version.

10. Contact

For any questions about this policy or the processing of your data, write to us at privacy@seapper.com. We respond within a maximum of 30 days.