Skip to content

Legal

Privacy Policy

Last updated pending

Placeholder document. This page describes the intended structure of the policy and is not a final legal agreement. Definitive terms will be issued following legal review for each operating jurisdiction.

This policy will describe how personal data is collected and processed across the public site and the authenticated platform, and how responsibilities are divided between YachtX and the management companies that operate on it.

1. Controller and processor roles

For platform records belonging to a management company, that company is the controller and YachtX acts as processor. For the public marketing site, enquiry forms and platform accounts, YachtX acts as controller.

2. Data we process

Account and profile details, organization membership and role, enquiry and application information, ownership and financial records, booking and trip data, documents uploaded by users, messages, and technical logs.

3. Purposes and legal bases

Providing the service, administering subscriptions and payments, security and abuse prevention, statutory record keeping, and service communications.

4. Sub-processors

Cloud hosting and database, email delivery, payment processing and AI model providers. A current sub-processor list will be published alongside the final policy.

5. AI features

Assistant and matching features send relevant record excerpts to a model provider to generate responses. Records remain scoped to the requesting user's permissions and are not used to train third-party models.

6. International transfers

Transfer mechanisms and hosting regions, to be confirmed.

7. Retention

Financial, ownership, governance and audit records are retained for statutory periods; other records are retained for the life of the account plus a defined tail.

8. Your rights

Access, correction, deletion, portability, restriction and objection, and how to exercise them. Requests concerning an organization's records are routed to that organization.

9. Security

Tenant isolation enforced at the database layer, role-based access, encrypted transport and storage, audit logging of privileged actions.

10. Contact

Contact route for privacy enquiries and, where required, the appointed representative or data protection officer.

Questions about this document can be directed to the platform operator through the contact page.