Privacy Policy

Last Updated: July 23, 2026

AbyssOS provides an online platform for dive centers to manage bookings, schedules, customers, billing and messaging, together with a portal for divers. This Privacy Policy explains what personal data we collect, why, how we use and share it, and the rights you have. It applies to our website (abyssos.app), the AbyssOS platform used by dive centers and their staff, and the diver portal.

Who we are

AbyssOS is provided by Ocean Vector Labs (Valentin Cupif), a French micro-entreprise. We are the data controller for the personal data described in the section titled Our role below.

For any question about this policy or about your personal data, contact us at Contact@abyssos.app.

Our role

When you visit our website or hold an AbyssOS account (dive-center owners and staff), we act as the data controller of your personal data.

When a dive center uses AbyssOS to manage its own divers and customers, that dive center is the controller of its customer data, and AbyssOS acts as its processor — handling that data only on the documented instructions of the dive center. If you are a diver or customer, please also refer to your dive center for how it uses your data.

Data we collect

  • Account and identity data: name, email address, phone number, organization and role. Passwords are stored in hashed form by our authentication provider.
  • Dive-center data: business details, team members, resources, schedules and settings.
  • Diver and customer data: profile and contact details, diving certifications, booking history, and the waiver or medical-form information provided for activities, including emergency contacts.
  • Booking, scheduling and operational data.
  • Payment data: processed by Stripe. We do not store full card numbers; we keep limited billing metadata such as invoice status and amounts.
  • WhatsApp and communications data: phone numbers, WhatsApp profile names, message content and media, and delivery or read status, when a dive center connects and uses the WhatsApp channel (see the WhatsApp section below).
  • Technical and usage data: IP address, device and browser information, log data and cookies.

How we use your data

We use personal data for the following purposes, each based on a lawful ground under the GDPR:

  • To provide and operate the platform and the services you request (performance of a contract).
  • To process payments and manage billing (performance of a contract).
  • To send transactional messages and notifications, including through the WhatsApp channel where enabled (performance of a contract and our legitimate interest).
  • To provide customer support (legitimate interest).
  • To keep the platform secure and prevent fraud or abuse (legitimate interest and legal obligation).
  • To improve and develop our services (legitimate interest).
  • To communicate with business prospects about our services (consent or legitimate interest).
  • To comply with our legal and accounting obligations (legal obligation).

WhatsApp Business Platform (Meta)

AbyssOS offers an optional messaging channel built on the Meta WhatsApp Business Platform (WhatsApp Business Cloud API), which lets a dive center exchange WhatsApp messages with its customers from within the platform.

When a dive center connects WhatsApp, the data processed through Meta includes the customer phone number, WhatsApp profile name, the content of messages and any media, and delivery or read receipts.

  • Consent: dive centers must obtain the consent of their customers before initiating WhatsApp messages.
  • Opt-out: recipients can stop messages at any time by replying STOP, and opt back in with START. Opt-outs are recorded and further messages are blocked.
  • The role of Meta: Meta processes WhatsApp data under its own terms and privacy policy. We do not use WhatsApp message content for advertising or for any purpose other than delivering the messaging features of the platform.

For details on how Meta handles WhatsApp data, see the WhatsApp Privacy Policy.

Sharing and sub-processors

We share personal data with service providers that help us run the platform, under contract and only as needed:

  • Supabase — database, authentication and hosting.
  • Stripe — payment processing.
  • Meta Platforms (WhatsApp Business Platform) — messaging, where the channel is enabled.
  • Email delivery and infrastructure providers — transactional emails and hosting.

We may also disclose data where required by law, to protect our rights, or in connection with a business transfer. We do not sell your personal data.

International data transfers

Some of our providers may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards, such as the European Commission Standard Contractual Clauses, to protect your data.

Data retention

We keep personal data only as long as necessary for the purposes described in this policy, to comply with legal obligations (for example accounting records), to resolve disputes and to enforce our agreements. Diver and customer data managed on behalf of a dive center is retained according to the instructions of that dive center.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port your personal data, to object to certain processing, and to withdraw your consent at any time. To exercise these rights, contact us at Contact@abyssos.app.

You also have the right to lodge a complaint with your local supervisory authority. In France, this is the CNIL (www.cnil.fr).

If your data is managed by a dive center that uses AbyssOS, please direct your request to that dive center; we will assist them as their processor.

Deleting your data

You may request deletion of your personal data at any time by emailing Contact@abyssos.app with the subject line: Data deletion request. We will process verified requests within 30 days, subject to any data we are required to retain for legal reasons.

If you hold an AbyssOS account, you may also request account closure, which removes your profile and associated data.

For WhatsApp: replying STOP stops all further messages. To have your conversation history deleted, contact the dive center you messaged, or email us and we will coordinate the deletion with them.

Security

We use technical and organizational measures to protect your data, including encryption in transit, access controls, and storage of secrets in a dedicated vault. No method of transmission or storage is completely secure, but we work continuously to protect your information.

Minors

The platform is intended for use by dive centers and adults. A dive center may record data about minors taking part in activities; in that case the dive center is responsible for obtaining any required parental or guardian consent. We do not knowingly collect data directly from children for their own accounts.

Cookies

Our website uses essential cookies to operate and may use limited analytics. You can control cookies through your browser settings.

Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated date. Your continued use of the platform after changes take effect means you accept the revised policy.

Contact

For any question about this Privacy Policy or your personal data, contact us at:

You can also review our Terms of Service.

This document is provided for transparency and does not constitute legal advice.