Privacy Policy
Version 1.0, effective 3 September 2026
This policy explains what personal data DiveLogic collects, why we collect it, and what rights you have over it.
We collect what we need to run your account and the Software. We do not sell your personal data, and we do not use it to train artificial intelligence models.
Some features handle information about your health, such as the post-dive review. We treat that information with the extra care the law requires.
1. About us and this policy
1.1. This Privacy Policy (the "Policy") explains how DiveLogic Limited, a private limited company incorporated and registered in England and Wales with company number 16512942, whose registered office is at 86-90 Paul Street, London, England, EC2A 4NE ("DiveLogic", "we", "us", "our"), collects and uses personal data about you.
1.2. Under the UK General Data Protection Regulation (the "UK GDPR") and the Data Protection Act 2018, DiveLogic is the controller of the personal data described in this Policy.
1.3. "Software" has the meaning given in our Terms of Use, and includes the DiveLogic desktop, mobile and web applications, API, web services, documentation and user handbook. Read this Policy alongside those Terms of Use.
1.4. "Personal data" means information about an identified or identifiable living person. "Special category data" means the sensitive categories listed in Article 9 of the UK GDPR, which include information about health.
1.5. Words defined in the Terms of Use have the same meaning here unless we say otherwise.
2. What we collect
2.1. Your account. Your email address, your first and last name, and your password in a securely hashed form. We also record whether your email address has been verified and which version of the Terms of Use you accepted.
2.2. Sign-in and security. Session tokens in hashed form. If you turn on two-factor authentication, we store an authenticator secret or the fact that email codes are enabled, plus your recovery codes in hashed form. We never store your password or recovery codes as plain text.
2.3. Preferences. Your language, units and other application settings, and any profile details you add.
2.4. Dive plans. The plans you create, including depths, times, gases, decompression settings, gradient factors, setpoints and notes, together with any plans, courses or invitations you share with other users or that others share with you.
2.5. Dive logs. Dives you record or download from a dive computer, including the computer's make, model, serial number and firmware version, and each dive's date, duration, depth samples, gas switches and related values.
2.6. Post-dive reviews. If you use the post-dive review, we collect what you tell us about how you feel after a dive, including whether you have symptoms that may relate to decompression illness, and the score and triage level that follow. This is information about your health. See clause 4.
2.7. Instructor and course information. If you use the instructor features, we process your courses, your students and members, invitations and roles, and the invoices, customers, price lists and payout details you enter.
2.8. Billing. Card payments are processed through a secure, regulated payment system. We never receive or store your full card number. We store a customer and subscription reference, your tier and status, and a record of payments and invoices.
2.9. AI features. If you use the AI assistants, we process the messages and context you send and the replies produced, and a count of the tokens used. See clause 5.
2.10. Technical and usage information. Your IP address, device and browser details, and our own analytics about how the Software is used, such as page views and sessions. We do not use third party advertising or cross-site tracking.
2.11. Messages. Records of your correspondence with support, and of the service messages we send you.
3. Why we use it, and our lawful basis
3.1. We use your personal data for these purposes:
- To run your account and the Software. Creating and verifying your account, storing and syncing your plans, logs, courses and reviews across your devices, and operating the features you use. Basis: performing our contract with you.
- To keep your account secure. Sign-in, two-factor checks, preventing fraud and abuse, rate limiting and logging. Basis: our legitimate interest in keeping the service secure.
- To take payment. Billing, invoicing, trials, refunds and tax. Basis: performing our contract with you, and our legal obligations.
- To provide AI features. Producing replies to what you send. Basis: performing our contract with you.
- To send service messages. Email verification, security codes, invitations, and service or billing notices. Basis: performing our contract with you, and our legitimate interests.
- To support and improve the Software. Fixing faults, understanding usage through our own analytics, and answering your questions. Basis: our legitimate interest in maintaining and improving the service.
- To send optional product updates. Only where you have agreed, and you can withdraw that agreement at any time. Basis: your consent.
- To meet legal duties and defend legal claims. Basis: our legal obligations and legitimate interests.
3.2. Service messages are not marketing. Verification emails, security codes, invitations and billing notices are part of running your account, so we send them whatever your marketing preference.
4. Information about your health
4.1. The post-dive review described in clause 2.6 handles information about your health. We only handle it:
- because you have given your explicit consent by choosing to enter it (Article 9(2)(a) of the UK GDPR); and
- to provide the review to you and keep your own dive safety records.
4.2. You never have to use the post-dive review. You can leave symptom questions unanswered, withdraw your consent at any time, and delete your reviews. See clause 11. Withdrawing consent does not affect anything we did lawfully beforehand.
4.3. The post-dive review is an information tool. It is not a medical device, a diagnosis or medical advice. If you have any symptom that may relate to decompression illness, get emergency medical help straight away. See the Terms of Use.
5. AI features
5.1. When you use an AI assistant, the messages and context you send are processed to produce a reply.
5.2. We use that content only to produce your reply. We do not use your personal data, your prompts or your dive data to train artificial intelligence models, and our contracts prohibit anyone handling it on our behalf from doing so either.
5.3. Do not enter anything into the AI features that you would rather we did not handle. AI replies can be wrong, and you must never rely on one for a safety critical decision without checking it yourself, as set out in the Terms of Use.
6. Cookies and browser storage
6.1. The Software uses a small amount of browser storage that it needs in order to work, mainly to keep you signed in and to remember essential settings. This is not used for advertising or for tracking you across other sites, and it does not require a consent banner.
6.2. We use our own analytics to understand how the Software is used. We do not use third party advertising cookies or cross-site trackers.
7. Who sees your data
7.1. We never sell your personal data. We do not hand it to anyone to use for their own purposes, and we do not use it for advertising or for tracking you across other sites.
7.2. A small number of suppliers help us run DiveLogic. They may handle personal data only on our written instructions, only so far as they need to in order to provide their service to us, and they must keep it secure and delete it when we tell them to. They are not free to use it for anything of their own.
7.3. We may also disclose personal data to our professional advisers, who are bound by confidentiality, to a buyer if our business is sold or reorganised, and where the law, a court or a competent authority requires it, or where we need to bring or defend a legal claim.
7.4. Other users see only what you choose to share with them, such as your name on a plan, course or invitation.
8. Storing data outside the UK
8.1. Some of the data we hold may be stored or handled outside the United Kingdom. Where that happens, we make sure an approved safeguard is in place, such as the UK International Data Transfer Agreement.
8.2. You can ask us for a copy of the safeguard that applies. See clause 15.
9. How long we keep it
9.1. We keep your personal data for as long as your account is open and for as long as we need it for the purposes in this Policy.
9.2. When you delete your account we delete or anonymise your personal data within a reasonable period. We keep some records for longer where we have to, such as billing and tax records, which the law generally requires us to keep for six years, and limited records we need to bring or defend a legal claim.
9.3. Session tokens, verification codes and security codes are short lived and expire on their own.
10. Keeping it safe
10.1. We take appropriate technical and organisational measures to protect personal data. These include encrypting data in transit, hashing passwords, recovery codes and session tokens, restricting access, and using reputable infrastructure that holds recognised security certifications.
10.2. No system is completely secure. Keep your password and any two-factor credentials to yourself, and tell us promptly if you think someone else has access to your account.
11. Your rights
11.1. Under the UK GDPR you have the right to:
- be told how we use your personal data, which is what this Policy does;
- get a copy of the personal data we hold about you;
- have inaccurate or incomplete data corrected;
- have your data deleted, subject to the records we must keep;
- restrict how we use your data in certain situations;
- receive certain data in a portable, machine readable format;
- object to us using your data for our legitimate interests, and to any direct marketing; and
- withdraw your consent at any time where we rely on it.
11.2. You can do much of this in the Software itself, including editing your profile, deleting plans, logs and reviews, and deleting your account. For anything else, contact us using clause 15. We reply within one month, and we do not charge for a reasonable request.
11.3. If you are unhappy with how we have handled your personal data you can complain to the Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, or at ico.org.uk. We would rather you came to us first so we can put it right.
12. Dive computers and other services
12.1. The Software connects to dive computers over Bluetooth to read your dive data. Your use of the device itself, and of any service its manufacturer offers, is covered by that manufacturer's terms and privacy notice, not this Policy.
12.2. We sometimes link to sites we do not control. We are not responsible for how they handle personal data, so please read their notices before giving them anything.
13. Automated decisions
13.1. We do not make decisions about you by automated means alone that have a legal or similarly significant effect. The post-dive review and the Software's calculations support your decisions. The diving decisions remain yours, made with your own training and judgement.
14. Children
14.1. The Software is for trained and certified adult divers. You must be at least 18 years old to create an account. If you believe a child has given us personal data, tell us and we will delete it.
15. Changes and how to contact us
15.1. We may update this Policy. When we do, we will change the version and effective date at the top, and if the change is significant we will take reasonable steps to tell you, such as by email or a notice in the Software.
15.2. If you keep using the Software after an updated Policy takes effect, you accept the update, except where we need to ask for your consent separately.
15.3. For any question about this Policy, or to exercise your rights, contact us through the support form in the Software, or write to us at the address in clause 1.1 marked for the attention of the Data Protection contact.
15.4. DiveLogic Limited is the controller responsible for your personal data.