Effective Date: 8th of July, 2026
At FlowState Divers ("FlowState Divers," "our," "us," or "we"), we value your privacy and are committed to being fair, accountable, and transparent in how we handle your personal information/personal data. This Privacy Policy explains how we collect, use, and disclose personal information when you use our website, book or participate in our diving courses, trips, or services, and otherwise interact with us (collectively, the "Service"), and describes your privacy rights and choices — including the rights available to you under the EU/UK General Data Protection Regulation ("GDPR") if you are located in the European Economic Area ("EEA"), United Kingdom, or Switzerland (collectively, "Europe").
1. Who We Are - Data Controller
Controller: FlowState Divers Contact: info@flowstatedivers.com Mailing Address: Av. Agua Dulce, 2, Edif Angocor, Bajo D, 38618 Los Abrigos, Santa Cruz de Tenerife
EU/UK Representative: If FlowState Divers does not have an establishment in the EEA or UK but offers services to, or monitors the behavior of, individuals located there, we will appoint an EU and/or UK representative under Article 27 GDPR / UK GDPR and publish their contact details here: [Insert EU representative name and contact, if applicable].
Data Protection Officer: [If FlowState Divers is required to appoint a DPO under Article 37 GDPR based on the scale or nature of processing (e.g., large-scale processing of health data), insert DPO name and contact here. If not required: "FlowState Divers has assessed that a Data Protection Officer is not currently required under Article 37 GDPR; all privacy inquiries may be directed to info@flowstatedivers.com."]
2. Personal Information We Collect and Our Lawful Basis for Processing
We ask that you not provide us with more personal information than is necessary for the purpose at hand; however, we cannot control everything you may choose to submit to us. For each category below, we identify our lawful basis for processing under Article 6 GDPR (and Article 9 GDPR where special category data is involved).
Account Information. Name, email address, phone number, mailing address, date of birth, emergency contact information, and account credentials.
- Collected: Directly from you, or from a third-party login service (e.g., Google or Facebook) if you register that way.
- Used for: Providing and administering the Service; verifying eligibility and certification requirements; communicating with you; safety and security; legal compliance.
- Disclosed to: Contracted service providers (e.g., booking and payment platforms); certifying dive agencies where required; parties involved in a business transfer; recipients required by law.
- Lawful basis (GDPR): Performance of a contract (Art. 6(1)(b)) — to register you and provide the course, trip, or rental you request; legitimate interests (Art. 6(1)(f)) — to secure and administer our Service; legal obligation (Art. 6(1)(c)) where recordkeeping is legally required.
Health and Medical Screening Information. Diving activities require health disclosures (e.g., medical questionnaires required by certifying agencies) to assess fitness to dive. This is special category data under Article 9 GDPR.
- Collected: Directly from you (or, for minors, from a parent/guardian), typically via required medical/liability forms prior to participation.
- Used for: Assessing eligibility to safely participate in diving activities; complying with certifying agency and legal requirements; protecting your vital interests and those of others in an emergency. We do not use this information for marketing or profiling.
- Disclosed to: Certifying dive agencies and instructors/staff directly involved in your activity where necessary; emergency medical personnel; recipients required by law. Access is limited to personnel with a legitimate need to know.
- Lawful basis (GDPR): Your explicit consent (Art. 9(2)(a)) — obtained via signed medical/liability forms prior to your participation — and, where relevant, protection of vital interests (Art. 9(2)(c)) in a medical emergency. You may withdraw consent at any time, but doing so may mean we are unable to permit your participation in diving activities.
Payment Data. Payment card information and transaction details, collected via a third-party processor (e.g., Stripe, Square, PayPal).
- Used for: Processing payments and bookings; preventing fraud; legal compliance.
- Disclosed to: Payment processors; contracted service providers; recipients required by law.
- Lawful basis (GDPR): Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for financial recordkeeping.
- Used for: Responding to inquiries; customer support; service improvement; legal compliance.
- Lawful basis (GDPR): Legitimate interests (Art. 6(1)(f)) in responding to and managing communications; performance of a contract where the inquiry relates to an existing booking.
Usage and Device Data. IP address, browser type/version, operating system, device identifiers, pages visited, time on page, referring URLs, and approximate location derived from IP address.
- Used for: Maintaining, securing, and improving our website; understanding usage trends; legal compliance.
- Lawful basis (GDPR): Legitimate interests (Art. 6(1)(f)) in operating and securing our website; consent (Art. 6(1)(a)) where required under applicable ePrivacy laws for non-essential cookies/analytics (see Section 3).
- Strictly necessary cookies are used on the basis of legitimate interests/necessity to operate the site and do not require consent.
- Analytics and marketing cookies are used only with your prior consent, obtained through a cookie consent banner presented to users in Europe, in accordance with the ePrivacy Directive and GDPR. You may withdraw consent at any time via your cookie preferences or browser settings.
- Lawful basis (GDPR): Legitimate interests (Art. 6(1)(f)) in enhancing and tailoring your experience with our Service.
We do not collect special category data beyond what is described above (health/medical screening), and we ask that you not provide us with additional sensitive information (e.g., relating to racial or ethnic origin, religion, political opinions, or criminal history) unless specifically and lawfully requested as part of a required form.
3. Cookies
4. How We Use Personal Information
We use personal information to:
- Provide, maintain, and improve our Service, including courses, trips, rentals, and bookings;
- Assess eligibility and safety requirements for diving activities;
- Process payments and manage transactions;
- Communicate with you, including confirmations, safety information, and (with your consent, where required) promotional communications;
- Personalize your experience and provide relevant recommendations;
- Ensure the security and integrity of our Service and prevent fraud or misuse;
- Comply with legal, regulatory, and certifying-agency obligations, and to establish, exercise, or defend legal claims.
We may aggregate or anonymize information so that it no longer identifies you, and use it for analytics and service improvement. Once information is truly anonymized, it is no longer personal data and GDPR does not apply to it. Where we pseudonymize data, we treat it as personal data and protect it accordingly.
Automated Decision-Making. We do not make decisions about you based solely on automated processing (including profiling) that produce legal or similarly significant effects, without human involvement. If this changes, we will update this Policy and provide the information required under Article 22 GDPR, including the logic involved and your right to obtain human intervention.
5. How We Disclose Personal Information
We do not sell your personal information. We may disclose personal information as follows:
- Service Providers: Vendors supporting our operations (hosting, booking, payment processing, analytics, marketing), bound by data processing agreements consistent with Article 28 GDPR.
- Certifying Agencies: Relevant dive certification bodies where necessary to process certifications or verify prerequisites.
- Legal Compliance: Where required by law, to respond to subpoenas, court orders, or other lawful requests, or to protect rights, safety, or property.
- Emergency Situations: To emergency responders or medical personnel to protect health or safety during diving activities.
- Business Transfers: In connection with a merger, acquisition, financing, or sale of assets, subject to reasonable efforts to notify you where required by law.
- With Your Direction: Where you choose to share information with a third party through our Service.
6. International Data Transfers
FlowState Divers is based in Spain. If we transfer personal data of individuals in Europe to a country that the European Commission (or, for the UK, the UK government) has not recognized as providing an adequate level of data protection, we will implement appropriate safeguards as required by Chapter V GDPR, such as:
- The European Commission's Standard Contractual Clauses (SCCs), or the UK International Data Transfer Addendum, with recipients; and/or
- Reliance on an applicable derogation under Article 49 GDPR (e.g., your explicit consent, or necessity for performance of a contract with you) where appropriate.
You may request a copy of the relevant safeguard by contacting us at info@flowstatedivers.com.
7. Retention of Personal Information
We retain personal information only for as long as necessary for the purposes described in this Policy, including:
- To comply with legal, tax, insurance, or certifying-agency recordkeeping requirements (medical and liability waiver records, in particular, are often subject to extended statutory retention periods given the physical risks associated with diving);
- To resolve disputes or complaints;
- To protect the safety, security, and integrity of our Service and our customers;
- For litigation, regulatory, or other legal matters.
Where feasible, we apply defined retention periods to each category of data (e.g., [insert specific periods once determined, such as "account data: duration of account plus X years"; "medical screening forms: X years post-activity in line with liability limitation periods"]). If you request deletion of your account or information, we will delete or anonymize it within a reasonable time (generally 30 days), except where we are required or permitted to retain it for the reasons above, in which case we will inform you of the specific basis and expected retention period.
8. Security of Personal Information
9. Children's Privacy
Our website and general account registration are not directed at children under the age of 13 (or, for users in Europe, under the applicable local age of digital consent, which ranges from 13 to 16 depending on the EU member state), and we do not knowingly collect personal information from children below the applicable age without verifiable parental or guardian consent.
Because diving courses and certifications are, in some cases, available to minors under applicable certifying-agency rules, we may collect personal information (including health screening information) about minors directly from a parent or legal guardian, who must review, consent to, and accept responsibility for the accuracy of that information on the minor's behalf. If you are a parent or guardian and believe your child has provided us with personal information without appropriate consent, please contact us using the details below.
10. Your Privacy Rights and Choices
If you are located in Europe, subject to certain exceptions and conditions under GDPR, you have the right to:
- Access — obtain confirmation of whether we process your personal data and a copy of it (Art. 15);
- Rectification — request correction of inaccurate or incomplete personal data (Art. 16);
- Erasure ("right to be forgotten") — request deletion of your personal data in certain circumstances (Art. 17);
- Restriction of processing — request that we limit how we use your data in certain circumstances (Art. 18);
- Data portability — receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20);
- Object — object to processing based on our legitimate interests, including profiling, and to processing for direct marketing purposes at any time (Art. 21);
- Withdraw consent — where processing is based on consent (including for special category health data or non-essential cookies), withdraw it at any time without affecting the lawfulness of prior processing (Art. 7(3));
- Not be subject to solely automated decision-making, including profiling, that produces legal or similarly significant effects (Art. 22);
- Lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at https://edpb.europa.eu/about-edpb/board/members_en, and UK residents may contact the Information Commissioner's Office (ICO) at https://ico.org.uk.
All users, regardless of location, may also generally:
- Opt Out of promotional communications by following the unsubscribe instructions in any marketing email;
- Manage Cookies through your browser or our cookie consent tool;
- Access, Correct, or Update your personal information through your account settings, where applicable;
- Appeal a decision we make regarding a rights request;
- Designate an Authorized Agent to submit a request on your behalf, subject to our ability to verify the agent's authorization.
Exercising Your Rights. To submit a request, contact us at info@flowstatedivers.com or write to us at the address in Section 1. Please include your full name, contact information, and a description of your request. We will verify your identity before acting on a request and will respond within one month, as required under Article 12 GDPR (extendable by two further months for complex requests, with notice to you).
Do Not Track. Because there is no consistent industry standard for responding to "Do Not Track" browser signals, we do not currently alter our data practices in response to such signals; however, users in Europe retain full rights described above regardless of browser signals.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated version and revise the effective date above. Where changes are material — particularly changes affecting the lawful basis or purpose of processing your data — we will provide additional notice or seek renewed consent where required by GDPR. Your continued use of the Service after changes are posted constitutes acceptance of the updated Policy, to the extent permitted by applicable law.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
FlowState Divers Email: info@flowstatedivers.com Av. Agua Dulce, 2, Edif Angocor, Bajo D, 38618 Los Abrigos, Santa Cruz de Tenerife