Privacy notice
Document version: 1.0 · Effective: 18-07-2026 · Last modified: 18-07-2026
At Divebuddyping we take your privacy seriously. We work according to data minimization and only store data that is necessary for operation, contact, security and legal obligations. We do not sell personal data. Data is only shared with necessary service providers or when required by law. This statement explains what data we process, why and what rights you have.
1. What data do we process?
Email address for verification, recovery, system email and set notifications; name or display name; Joomla user ID, account status, language and registration date; the diving certificate without a copy or license number; custom country, province, avatar and notification preferences; Calls, responses, times, locations and history; push endpoint, public cryptographic keys and subscription information; IP address, logs and browser/device information where server or security processes it. Passwords are stored hashed by Joomla.
2. Why do we process data?
For account management, communications, Calls and responses, filtering by country, state and radius, set push and email notifications, personal history, security, fraud and spam prevention, technical operation, error diagnosis, security logging and legal obligations.
3. Legal grounds
Execution of the user agreement for account and services; legitimate interest for security, abuse prevention and technical logs; consent for optional push notifications and where consent is required; legal obligation when processing or provision is required by law.
4. What do other Users see?
Depending on the page, registered Users see name or display name, avatar, Calls, responses, role, date, time and chosen location. The full profile is not public. Email address, password, push endpoint and technical logs are not publicly displayed.
5. Push notifications and email
Push is optional and requires browser or device permission. Push can report new Calls, responses, withdrawals and important system notifications. The subscription includes endpoint and public cryptographic keys and can be disabled via profile and browser; delivery is not guaranteed. Email is used for activation, recovery, necessary system and security messages and set notifications. Non-essential emails can be adjusted where settings exist; necessary account emails not always.
6. Country, provinces and location use
Country and provinces/regions are saved for filtering. The map radius preference can be saved. Use My Location requires browser permission; the current coordinates are temporarily used in the browser for map and distance filtering and are not stored as GPS history on the server. Selected dive locations for Calls are saved as Call data.
7. Cookies, browser storage and cache
Joomla uses session, authentication and security cookies. Functional preferences can be saved by Joomla or the browser. sessionStorage temporarily stores map returnstate and closing quickstart; no native localStorage usage was found in the component. The PWA/service worker can cache app files. At the time of drawing up this Privacy Statement, Divebuddyping does not use analytics within the component. If analytics are used in the future, this Privacy Statement will be adjusted accordingly. No ad network or tracking component code was found.
8. Sharing with service providers and third parties
Personal data will not be sold or provided for commercial marketing purposes. Personal data can only be processed by service providers that are necessary for hosting, e-mail, backups, push notifications and the technical operation of Divebuddyping. These parties only process data to the extent necessary for their services and in accordance with applicable privacy legislation. Data can also be provided when Divebuddyping is legally obliged to do so.
9. Retention periods and account deletion
Personal data is not kept longer than necessary for the functioning of Divebuddyping, personal history, the security of the services, handling disputes and complying with legal obligations. Account and profile information is retained for as long as the account is active. When deleting an account, personal data will be deleted or anonymized from the active environment, unless further storage is necessary or legally required. Data may still be temporarily present in backups, server logs or security logs. As soon as data is no longer necessary, it is deleted or anonymized.
10. Your rights
Where applicable, you have the right to inspect, correct, delete, limit, object, portability and withdraw consent. You can request a data copy or portable export via the email address provided. You can file a complaint with the Dutch Data Protection Authority.
11. Security
Divebuddyping takes appropriate technical and organizational measures, including HTTPS, access restriction, password hashing via Joomla, CSRF protection, security logging and timely updating of software. No internet service can guarantee complete security.
12. International transfer
Divebuddyping processes personal data in principle within the European Economic Area (EEA). To the extent that necessary service providers are used for the technical operation of the service, personal data will only be processed in accordance with the applicable privacy legislation and appropriate security measures. There is currently no structural transfer of personal data outside the EEA.
13. Contact
Controller: Divebuddyping Email address: info@divebuddyping.com Website: https://www.divebuddyping.com You have the right to file a complaint with the Dutch Data Protection Authority.




