Privacy Policy

Yachtlantis · Version 2.6 (version id 2026-09-05) · Last updated 17 September 2026

GDPR (EU/EEA) UK GDPR CCPA / CPRA LGPD POPIA PDPA (Thailand) KVKK (Turkey) nDSG (Switzerland)

1. Data Controller / Verantwortlicher

ChurchHill Holding GmbH is the data controller within the meaning of the EU General Data Protection Regulation (GDPR), the UK GDPR, and applicable national data protection laws. For users in California: ChurchHill Holding GmbH is the “business” under the CCPA. For users in Brazil: the “controlador” under the LGPD.

Contact: ChurchHill Holding GmbH, Marktplatz 17, A-3470 Kirchberg am Wagram, Austria — FN 506575p, Landesgericht St. Pölten — VAT ATU74067635 — Managing Director: Ing. Sebastian Günther — planung@ep-kolar.at

App: Yachtlantis — yachtlantis.app · Country: Austria (EU Member State)

2. Scope / Geltungsbereich

This privacy policy applies to the Yachtlantis web application (Progressive Web App), future native mobile applications, and all related services. It applies to users worldwide, including but not limited to:

3. Data We Collect / Erhobene Daten

3.1 Account Data

3.2 Boat Data

User-provided boat information: name, manufacturer, model, year built, registration number, MMSI, home port, berth coordinates, engine data, tank capacities, anchor chain length, rode type.

3.3 Usage Data

3.4 Location Data (GPS)

Yachtlantis records your position only while a recording you started is running — but while one is running, it also records in the background, with the screen off and the app not in the foreground. Position recording starts when you:

Background recording (Android app only). While a logbook trip or an Anchor Watch is running, the Android app runs a foreground service that keeps receiving GPS positions when the screen is dark or the app is in the background. Android shows this service as a permanent notification (“Aufzeichnung läuft — Position und Fahrt werden aufgezeichnet.”) for as long as it runs. The service is started only when a trip or an Anchor Watch is running and is stopped as soon as you end it; there is no recording outside those two cases, and none at all before you start the first one. The ACCESS_BACKGROUND_LOCATION permission is declared for a single purpose: so that a recording that is already running keeps receiving positions if Android restarts the service after reclaiming the app's process. In the browser (Progressive Web App) and on iOS there is no such service — there, recording stops when the screen goes dark.

How often, and what is stored. A position is requested every 3 minutes. A track point is stored every 3 minutes as well, stretched to at most 10 minutes while course and speed do not change, plus an additional point whenever your course changes by 10° or more or you have covered one nautical mile. Each stored point holds latitude, longitude, the time of the fix, speed over ground, course over ground, where the device reports it the GPS accuracy in metres, and the trip or Anchor Watch session it belongs to. While the Anchor Watch is open on screen the app additionally follows your position continuously, in order to drive the drift alarm. Who can read these points is described in Section 11; how long they are kept, in Section 7. You can revoke location permission at any time in your browser/device settings, and ending the trip or the Anchor Watch ends the recording.

3.5 Energy Data (Victron VRM)

When you connect Victron VRM, your VRM username and password are relayed through our server-side proxy to Victron's API to sign you in; they are not stored. The resulting long-lived VRM access token is stored server-side (in our Supabase database, Frankfurt/EU) together with your VRM user ID and installation ID, associated with your boat — it is not kept in your browser's local or session storage, and does not return to the browser after the initial connection. Subsequent retrieval of energy data (battery voltage, state of charge, solar yield, inverter status) is likewise relayed through our server using that stored token. Disconnecting (Boat → Victron → Disconnect) deletes the stored token from our database; revoking it in the VRM portal itself remains your own action.

3.6 Weather Data

Weather data is fetched via the Open-Meteo Marine API and Windy.com. The coordinates transmitted are those of the position the app currently holds for you — in order of preference: a running anchor watch, a running voyage, the last recorded position, a live NMEA position, your device's geolocation, and only then your boat's berth. Except for the berth case these are your actual whereabouts, and therefore personal data.

3.7 AIS Data

When the Anchor Watch or trip view shows nearby vessels, AIS data is received via the aisstream.io WebSocket API. To do so, the app transmits a rectangular area (bounding box) around your own current position to aisstream.io so that the service can deliver the vessels around you; the area is transmitted again whenever you have moved more than roughly 0.5 nautical miles. That area is derived from your position and is therefore location data and personal data — it is not anonymous. The AIS data received in return is public maritime safety information broadcast by vessels.

Trip-encounter storage (third-party MMSIs): When you record a trip, the MMSI numbers, vessel names and positions of other passing vessels broadcast on AIS may be persisted in the ais_encounters database table. This is required to power the trip-replay feature, which lets you review which vessels were nearby during your voyage. These records are retained for a maximum of 90 days and then automatically purged by a scheduled pg_cron cleanup job.

MMSI numbers identify a vessel, not a natural person, but where a vessel is uniquely associated with an individual the data may qualify as personal data under GDPR Art. 4(1). Lawful basis: legitimate interest (Art. 6(1)(f) GDPR) — preserving an accurate maritime traffic picture for your voyage record. You can opt out of this storage at any time by disabling AIS in Settings → AIS; with AIS disabled, no ais_encounters rows are written.

3.8 Technical Data

Automatically collected on errors: IP address, browser type, device type, and access time. The IP address is pseudonymised before storage — it is run through a salted one-way (SHA-256) hash and the plain IP is never written to our database. This is not the same as anonymous data: a pseudonymised value is still indirectly identifiable (e.g. by re-hashing a candidate IP with the same salt) and remains personal data under GDPR Art. 4(1)/4(5). These technical error-log entries are retained for 14 days and then automatically purged by a scheduled job; see Section 7.

3.9 Emergency & Health Data (Crew)

If you, a skipper, or a boat owner fills in the crew emergency questionnaire (“Emergency Information”), the following may be recorded for each person on board: emergency contact (name, phone, relationship), blood type, allergies, medications, pre-existing conditions, swimming ability, languages spoken, and health-insurance provider/policy number.

Blood type, allergies, medications and pre-existing conditions are health data — a special category of personal data under GDPR Art. 9(1). They are stored only with your explicit, separately given consent (Art. 9(2)(a) GDPR), recorded together with the wording you consented to; no such field is written without it, and each field can be deleted individually at any time.

Who can see it: day-to-day, only the boat's owner and the skipper of the voyage. In a declared emergency, any person recorded as crew on that voyage can also retrieve this data — because if the skipper is the person affected, restricting access to the skipper helps no one. Every such emergency retrieval is logged (who accessed it, when, which boat/voyage, the stated reason, and how many records were shown) in a separate, append-only log that is visible to everyone on board, so the wider access is accountable rather than an open door.

All entries are voluntary and every field may be left blank. The retention rule is 24 months from whichever is later — the date it was entered or the date it was last actually used (e.g. shown on an emergency sheet); a database function implements exactly this rule. As of the date of this policy, that function is not yet scheduled to run automatically, so entries are not currently purged on their own after 24 months — this is being corrected. You can delete any field yourself at any time regardless; see Section 7.

4. Legal Basis / Rechtsgrundlagen

4.1 EU/EEA (GDPR)

4.2 California (CCPA/CPRA)

Yachtlantis does not sell or share your personal information with third parties for advertising. We do not use personal data for profiling or automated decision-making. California residents have the right to know, delete, and opt-out (see Section 8).

4.3 Brazil (LGPD)

Processing is based on: consent (Art. 7, I), contract execution (Art. 7, V), and legitimate interest (Art. 7, IX). Brazilian users have rights under Art. 18 LGPD (see Section 8).

4.4 Thailand (PDPA)

Processing is based on consent and contractual necessity under Sections 24-26 PDPA. Thai users have rights under Section 30 PDPA (see Section 8).

5. Data Processors & Third-Party Services

ProviderRoleLocationDPA
Supabase Inc.Database, authentication, file storageFrankfurt, Germany (EU)Yes
Vercel Inc.Web hosting, content delivery, serverless/cron functions and the payment flowEU Edge Network / USA (EU-US Data Privacy Framework certified)Yes
Cloudflare, Inc.Application delivery and server functions (global CDN, edge routing)USA / worldwide CDN (EU-US Data Privacy Framework certified)Open — to be reviewed / concluded
Resend (Resend, Inc.)Transactional e-mail delivery to usersUSA (EU-US Data Privacy Framework certified)Open — to be reviewed / concluded
Open-MeteoWeather and marine dataIP address and the requested coordinates are transmitted — this is location dataNo
Windy.com (Windyty SE)Embedded weather mapsIP address and the requested coordinates are transmitted — this is location dataNo
Victron Energy BVVRM Portal — energy/battery data (optional); the VRM access token is stored server-side (Supabase, Frankfurt), associated with your boat — not in your browserToken at rest: Frankfurt (EU) via Supabase; requests relayed to Victron (Netherlands/EU)No
aisstream.ioAIS vessel tracking (Anchor Watch) — an area around your own position is transmitted so the service can deliver the vessels nearbyLocation data around your own position is transmitted (personal data)No
OpenStreetMap / OpenSeaMapMap tiles for Anchor Watch, the derived land mask (see 5.1), and reverse geocoding of your current position to a place name via nominatim.openstreetmap.org (used for the dashboard weather label)IP address and the requested coordinates are transmitted — this is location dataNo
Esri (server.arcgisonline.com)Satellite-imagery map tiles (optional map layer)USAOpen — to be reviewed / concluded
CARTO (basemaps.cartocdn.com)Dark-theme map tiles (optional map layer)USA / worldwide CDNOpen — to be reviewed / concluded
Apple / GooglePayment processing via App Store (planned)Apple: Ireland (EU), Google: EU/USYes
RevenueCat Inc.Subscription receipt validation (App Store / Play Store)USA (EU-US Data Privacy Framework certified)Yes
Sentry (Functional Software, Inc.)Client-side error monitoring and performance tracing; only active when an access key is configured for the running build — not confirmed active in every deployment at the time of writingNot confirmed at time of writing — to be verified with Sentry before relying on this rowOpen — to be reviewed / concluded

Every map tile request (from any of the map-tile providers above) transmits the requesting device's IP address to that provider, along with the coordinates of the map area currently shown — this is location data. Map tiles are not cached beyond normal browser caching.

Data Processing Agreements (DPA/AVV) per Art. 28 GDPR are in place with Supabase and Vercel. For Cloudflare, Resend, Esri, CARTO, and Sentry no concluded DPA is on record — reviewing it and, where required, concluding it is an open item. All providers maintain EU Standard Contractual Clauses (SCCs) for any third-country transfers.

5.1 Data sources & licences / Datenquellen und Lizenzen

Beyond map tiles, Yachtlantis stores a land mask — a derived dataset used to tell land from water. Its sources and licences:

5.2 Newsletter

Yachtlantis operates an optional newsletter. It is not part of the service and you can use the app in full without it.

AspectDetail
Data processedE-mail address, name, the point in time at which consent was given, and a delivery log recording which newsletter was sent to which address and when.
PurposeInformation about new features and changes to the app.
Legal basisArt. 6(1)(a) GDPR — consent. Not Art. 6(1)(b): the newsletter is not required to perform the contract, and consent to advertising may not be a condition of using the service (Art. 7(4) GDPR).
How consent is givenThrough a separate, non-pre-ticked checkbox in the app, shown apart from the two mandatory items. Ticking nothing is a valid outcome and does not restrict use of the app.
WithdrawalAt any time, with one click, via the unsubscribe link in every newsletter — no login, no form, no reason required. Withdrawal has no effect on the lawfulness of processing carried out before it.
RecipientsResend (Resend, Inc.) as processor, as listed in the table above.
RetentionConsent and the delivery log are retained as evidence that the mailing was lawful, and are erased when they are no longer needed for that purpose.

No newsletter is sent to anyone who has not actively consented. Existing accounts were not added retroactively; every address starts at „no“ and only changes when a person ticks the box.

6. International Data Transfers

Your data is primarily stored in Frankfurt, Germany (EU) on Supabase servers. Some processing may occur on Vercel's EU edge network. For transfers outside the EU/EEA:

For UK users: transfers are governed by the UK International Data Transfer Agreement (IDTA). For Swiss users: transfers comply with the Swiss-US Data Privacy Framework.

7. Data Retention / Speicherdauer

Clarification on “irreversibly deleted” vs. AGB export window: When you request account deletion, your user content (logbook entries, photos, settings) is erased from active systems without undue delay (typically within 24 hours). Separately, our AGB §6(5) describes a 30-day technical archive window during which de-identified backup snapshots and legal-archive entries (e.g. invoice records mandated by Austrian Bundesabgabenordnung §132 for up to 7 years) may persist for compliance, fraud-prevention, and breach-forensics purposes. After the 30-day technical window, all non-statutory data is irreversibly purged. Statutory invoice/tax records continue to be retained for the period required by Austrian tax law and are isolated from the active service.

8. Your Rights / Ihre Rechte

8.1 EU/EEA & UK (GDPR Art. 15-22)

8.2 California (CCPA/CPRA)

8.3 Brazil (LGPD Art. 18)

8.4 Other Jurisdictions

Users in South Africa (POPIA), Thailand (PDPA), Turkey (KVKK), and all other countries enjoy equivalent rights as described above. We apply GDPR-standard rights globally as our minimum baseline.

To exercise any of these rights, contact: planung@ep-kolar.at

9. Supervisory Authorities / Aufsichtsbehörden

You have the right to lodge a complaint with a data protection authority (Art. 77 GDPR):

Austria: Österr. Datenschutzbehörde (dsb.gv.at)
Germany: Landesdatenschutzbeauftragte
Croatia: AZOP
Italy: Garante Privacy
Spain: AEPD
France: CNIL
UK: ICO (ico.org.uk)
Netherlands: Autoriteit Persoonsgegevens
Poland: UODO
Czechia: ÚÓOÚ
Hungary: NAIH
Turkey: KVKK
Greece: DPA (dpa.gr)
Brazil: ANPD
Thailand: PDPC
South Africa: Information Regulator

10. Cookies & Local Storage

Yachtlantis uses no tracking cookies, no third-party analytics (no Google Analytics, no Facebook Pixel, no advertising trackers), and no third-party font CDNs. All webfonts (Outfit, JetBrains Mono) are self-hosted and bundled with the application — your IP address is never transmitted to Google Fonts (fonts.googleapis.com / fonts.gstatic.com) or any other font provider, in compliance with LG München I, 3 O 17493/20 (Jan 2022) and Schrems II.

We store only technically necessary data in your browser's Local Storage:

This data is essential for app operation (GDPR Art. 6(1)(f), ePrivacy Directive Art. 5(3) exemption for strictly necessary storage).

11. Data Security / Datensicherheit

12. Data Breach Notification

In the event of a data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours (Art. 33 GDPR) and affected users without undue delay (Art. 34 GDPR). For CCPA: California residents will be notified per Civil Code § 1798.82.

13. Children's Privacy

Yachtlantis is not directed at persons under 16 years of age. We do not knowingly collect personal data from children under 16 (GDPR Art. 8) or under 13 (COPPA, USA). If we discover that data from a child has been collected, it will be deleted immediately.

14. Automated Decision-Making

Yachtlantis does not use automated decision-making or profiling as defined in Art. 22 GDPR. No AI or algorithms make decisions about you. All data processing serves solely the purpose of providing the app's features as described.

15. Do Not Sell My Information (CCPA)

Yachtlantis does not sell your personal information to any third party. We do not share personal data for cross-context behavioral advertising. There is no “opt-out” needed because we never sell or share data in the first place.

16. Changes to This Policy / Änderungen

We may update this privacy policy to reflect changes in legal requirements or app features. The current version is always available within the app. For material changes, you will be asked to review and accept the updated policy upon your next login. Your continued use of Yachtlantis after accepting the updated policy constitutes your agreement to the changes.

17. Limitation of Liability / Haftungsausschluss

Yachtlantis is provided “as is” and “as available” without warranties of any kind, either express or implied. To the fullest extent permitted by applicable law:

This limitation applies to the maximum extent permitted under applicable law, including but not limited to Austrian law (§§ 1295ff ABGB), German law (§§ 280ff BGB), EU consumer protection directives, and the laws of any other jurisdiction from which the app is accessed.

18. Terms of Use / Nutzungsbedingungen

By using Yachtlantis, you agree to the following terms:

19. Your Consent / Einwilligung

By creating an account and using Yachtlantis, you confirm that you have read, understood, and agree to this Privacy Policy, the Limitation of Liability, and the Terms of Use. You may withdraw your consent at any time by deleting your account (Profile → Delete Account) or by contacting planung@ep-kolar.at. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

20. Contact

ChurchHill Holding GmbH, Marktplatz 17, A-3470 Kirchberg am Wagram, Austria — planung@ep-kolar.at