Privacy Policy of “The Boats Hub”
This Privacy Policy describes how this website manages the processing of personal data of users who consult it and use its services. This information is provided in accordance with Article 13 of the EU Regulation 2016/679 (GDPR).
1. Data Controller
The Data Controller is The Boats Hub, Contact Email: [Insert Your Email Address].
2. Types of Data Collected
This website may collect, independently or through third parties, the following personal data:
- Navigation data: IP addresses, connection times, domain names of computers used by users, and anonymous statistical data on site usage.
- Account and Registration data: username, password, name, surname, email address, and any additional profile information provided by the user during the registration process.
- Billing and Transaction data: billing address, company name (if applicable), VAT number or tax ID, and history of purchases/subscriptions. Note: Complete payment card details or bank account details are processed directly by our secure third-party payment gateways (Stripe and PayPal) and are never stored on our servers.
- Data provided voluntarily by the user: data entered into contact forms or support channels.
- Cookies: for details, please refer to the dedicated Cookie Policy.
3. Purpose and Legal Basis for Processing
The user’s personal data is collected and processed for the following purposes:
- User Registration and Service Provision: to allow users to create an account, authenticate themselves, and access the restricted areas and paid services offered by the website. (Legal basis: performance of a contract to which the user is party).
- Payment Processing and Billing: to process transactions, issue invoices, manage subscriptions, and fulfill legal tax and accounting obligations. (Legal basis: performance of a contract and compliance with legal obligations).
- To respond to user requests: managing and processing messages sent via contact forms or customer support channels. (Legal basis: performance of pre-contractual or contractual measures).
- To send commercial communications (Newsletter): sending informative or promotional emails, strictly subject to the user’s explicit consent. (Legal basis: consent of the data subject).
- Statistical analysis and maintenance: optimizing website performance based on aggregated and anonymous data. (Legal basis: legitimate interest of the Data Controller).
4. Methods of Processing and Data Retention
Processing is carried out using IT and telemediatic tools, with logics strictly related to the purposes indicated and in a manner that ensures data security and confidentiality.
Data will be kept for the period strictly necessary to fulfill the purposes for which it was collected, specifically:
- Account and registration data will be retained for as long as the user’s account remains active.
- Billing and financial data will be stored for the period required by applicable tax and commercial laws (typically 10 years in accordance with local regulations).
- Data from contact forms will be stored for as long as necessary to process the request.
- Newsletter data will be stored until the user requests to unsubscribe.
5. Disclosure of Data to Third Parties
Personal data will not be publicly disseminated but may be communicated to third parties performing services on behalf of the Data Controller, appointed as Data Processors if required by law. These include:
- Payment Gateways: Stripe and PayPal, used to handle transactions securely. These platform providers act as independent data controllers for the data necessary to complete the payment transaction (for details, please refer to Stripe’s and PayPal’s respective privacy policies).
- Technical Providers: hosting services, database management services, and IT maintenance.
- Professional Advisors: accountants and legal consultants for tax compliance and bookkeeping.
6. International Data Transfers (Extra-EU)
Some third-party services used by this website (e.g., Stripe, PayPal, Google, cloud hosting providers) may involve the transfer of data outside the European Economic Area (EEA), including to the United States. These transfers take place exclusively to countries ensuring an adequate level of protection, or on the basis of Standard Contractual Clauses (SCC) approved by the European Commission, and in compliance with the EU-U.S. Data Privacy Framework where applicable.
7. User Rights (Data Subject Rights)
At any time, users may exercise their rights under Articles 15-22 of the GDPR by sending a written request to the Data Controller’s email. Users have the right to:
- Access their data and receive a copy.
- Request rectification, updating, or deletion of their data (including account deletion).
- Object to processing or request restriction of processing.
- Withdraw consent at any time (without affecting the lawfulness of processing based on consent before its withdrawal).
- Lodge a complaint with a supervisory authority (such as the Italian Garante Privacy or your local data protection authority).
8. Changes to this Privacy Policy
The Data Controller reserves the right to modify this Privacy Policy at any time to adapt it to new legal requirements. The latest update date is indicated at the bottom of the document.
Last updated: 23/09/2026