Legal
Privacy Policy.
At Ocean Experience, your privacy is a priority. Great expeditions shouldn't come at the cost of your personal data security. This policy explains exactly what we collect, why, and how we protect it.
Privacy Policy Statement
Ocean Experience Inc. data practices
Introduction
OverviewAt Ocean Experience, your privacy is a priority. We believe that great expeditions shouldn't come at the cost of your personal data security. This Privacy Policy details the minimum amount of information we collect to process your bookings, ensure your safety during our courses, and provide you with a seamless digital experience.
Minimal collection
We only collect what we truly need.
Never sold
Your data is never sold to third parties.
You're in control
Request deletion or export anytime.
Information We Collect
Data PointsWhen you book a course, interact with our website, or contact our team, we collect specific categories of information. Each data point serves a clear operational or safety purpose.
Personal identification
Safety and medical (voluntary)
Device and usage
How We Use Your Data
PurposeThe information we collect is used exclusively for the following purposes. We do not repurpose or resell your personal data for any reason.
Course booking & logistics
Secure your spot, confirm dates, and coordinate meetups.
Safety & emergency response
Medical info shared with instructors during expeditions only.
Important communications
Itinerary updates, weather alerts, and pre-course checklists.
Payment processing
Secure transactions via our PCI DSS compliant partners.
Group coordination
Share contact info (with consent) among group members.
Service improvement
Anonymous analytics to optimize our website and booking flow.
Legal basis for processing (GDPR)
We process data under: (a) contractual necessity for bookings, (b) legitimate interest for safety communications, and (c) your explicit consent for marketing (opt-in only, never automatic).
Security Measures
ProtectedAll data is encrypted in transit and at rest using industry-standard security protocols. We conduct quarterly security audits and penetration testing to ensure your details remain confidential.
TLS 1.3 encryption
All website traffic uses the latest TLS standard.
AES-256 at rest
Database fields encrypted with 256-bit keys.
SSO & 2FA
Employee access requires multi-factor auth.
SOC 2 Type II
Our cloud provider is SOC 2 audited quarterly.
Data minimization
Auto-purge of data when no longer needed.
Breach protocol
Notification within 72 hours per GDPR/CCPA.
Data Retention
TimeframesWe keep your data only as long as required for the purposes for which it was collected, plus any legally mandated retention periods. After that, data is securely erased or irreversibly anonymized.
| Data category | Retention | Reason |
|---|---|---|
| Booking records & payments | 7 years | Tax & accounting requirements |
| Medical & safety data | 3 years post-course | Liability & incident follow-up |
| Contact form inquiries | 12 months | Follow-up correspondence |
| Marketing consent | Until you unsubscribe | Opt-out available anytime |
Your Data Rights
GDPR / CCPAYou have comprehensive rights over your personal data. We are committed to giving you complete control, and we respond to all valid requests within 30 calendar days.
Access
Request a full copy of all data we hold about you.
Correction
Update inaccurate or incomplete personal information.
Deletion
Ask us to erase your data ("right to be forgotten").
Portability
Export your data in a machine-readable JSON/CSV format.
Restriction
Pause processing of your data for a specific period.
Objection
Object to processing based on legitimate interest.
How to exercise your rights
Email privacy@oceanexperience.org from the email associated with your booking. We may request ID verification for deletion requests to protect your privacy. No fee for your first request per year.
International Data Transfers
GlobalOur operations are global, and your data may be processed in jurisdictions outside your country of residence. We ensure all transfers comply with applicable data protection laws.
Transfer mechanisms
- •EU-US Data Privacy Framework certified hosting providers
- •Standard Contractual Clauses (SCCs) for all other transfers
- •Encryption in transit for all cross-border data flows
You may request a copy of our transfer safeguards by emailing our privacy team.
Children's Privacy
COPPAOur website and services are not directed to children under 13 years of age. We do not knowingly collect personal information from children under 13 without verifiable parental consent.
Ages 10–17 (junior programs)
Participants under 18 require written parental/guardian consent. All data for minors is collected under legal authority of parent consent forms, which are retained with the booking record.
If we inadvertently collected data
If you believe we have collected data from a child under 13 without proper consent, please contact privacy@oceanexperience.org immediately. We will delete the information within 48 hours.
Changes to This Policy
VersioningWe may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or new service offerings. When we make material changes, we will notify you via email or a prominent notice on our website.
Last updated
September 24, 2026
Notice period
30 days email for material changes
Your acceptance
Continued use = acceptance of updates
Questions about our privacy practices?
Our Data Protection Officer (DPO) personally reviews every privacy inquiry. Expect a detailed response within 24 business hours.