Sailfloat

Privacy

Privacy Policy

Last updated 15 September 2026

This policy explains how Sailfloat collects and processes personal data, the legal basis we rely on, and the rights you have under the GDPR and the Norwegian Personal Data Act.

What we actually process today

Sailfloat has not launched. You can create an account and register your boat, but there is no payment and no BankID verification, and no boat is published. We therefore process your account and what you enter into the forms yourself: the contact form, the waiting list and the boat registration. Section 2 separates what we process now from what only arrives at launch.

1. Data Controller

The controller is the service provider identified in section 10. The controller determines the purpose of the processing and the means used. As long as no business is registered, the private individual behind the website is the controller.

We use processors who handle data on our behalf and on our instructions, governed by data processing agreements. Today that means the provider of the database that receives the forms, and the provider that hosts the website and our email. See section 4.

2. Data we process

The table shows the main categories we process today, and the primary legal basis. Further detail follows in section 3.

CategoryExamplesLegal basis
Contact formName, email, subject, message text, language, browser stringPre-contractual steps / legitimate interest (b and f)
Waiting listEmail address and the place you asked to be notified aboutConsent (Art. 6(1)(a))
Boat submissionName, email, phone and details about the boatPre-contractual steps (Art. 6(1)(b))
Technical logsIP address, timestamp and requested page — held by our providersLegitimate interest (Art. 6(1)(f))
LocationApproximate position, to sort places by distanceBrowser consent (Art. 6(1)(a))
Boat owner accountEmail address, name, phone number and the photos you upload of the boatSteps prior to a contract (Art. 6(1)(b))

We process no special categories of personal data (sensitive data), and we accept no payments — so there are no card details held by us or by a payment partner today.

This only arrives at launch

When booking, payment and BankID open, we will additionally process verified identity (name and year of birth from BankID), transaction data from the payment partner, and booking and rental history. None of this is processed today, and this policy will be updated before any of it is put into use.

3. Purposes and legal basis

3.1 Enquiries and boat submissions (Art. 6(1)(b) and (f))

If you send the contact form or submit a boat, we process the data to reply to you and to assess the boat as a possible listing at launch. The basis is steps taken at your request prior to entering into a contract, and our legitimate interest in being able to answer enquiries. If you have registered a boat that is not complete, we send you up to three reminders about it during the first three weeks. Each one has a link that unsubscribes you with one click.

3.2 Waiting list (Art. 6(1)(a))

If you join the waiting list for a place, we process your email address to notify you when boats are available there. The basis is the consent you give when signing up. We use the address for nothing else, and every email contains an unsubscribe link.

3.3 Other consent (Art. 6(1)(a))

Browser location is used only if you allow it in your browser, and only to sort places by distance. Consent can be withdrawn at any time, without affecting the lawfulness of processing before withdrawal.

3.4 Legitimate interest (Art. 6(1)(f))

The providers that run the website keep technical logs in order to serve the pages, handle errors and stop abuse. We also count visits ourselves, without cookies: for each page view we store which page was opened, which language, which site you came from (the hostname only, never the search term), and whether the device is a mobile. Instead of your IP address we store a one-way hash that includes today's date — it is replaced at midnight, so we can count unique visitors within a single day but cannot follow anyone over time. Form submissions also pass through a checking function that counts submissions per sender to prevent spam; it uses a similar hash, deleted after 48 hours. We have assessed that this interest outweighs the impact on you. You may object to it, see section 6.

4. Sharing with others

We share personal data, to the extent necessary, with:

  • Supabase – the database that receives the forms. Data is stored in the EU (Stockholm), and the table is configured so that no one can read submitted forms from the website.
  • Webhuset – the Norwegian provider that hosts the website and our email address, and keeps technical logs for operations.
  • Visitor statistics – we count them ourselves, in our own database at Supabase in the EU. No third party, no cookies, no cross-site tracking.
  • Public authorities – when we are legally required to.
  • At launch: payment, insurance and BankID – payment partner, insurer and identity verification provider, plus the other party to a rental. None of them receive any data today.
  • OpenStreetMap and CARTO – when you use the map or search for an address, the query and the map viewport are sent to these services to fetch results and map tiles.
  • Google (Gmail) – delivers the email the service sends on its own: the sign-in link to your page, the receipt when you have registered a boat, and the reminders about a boat that is not complete. Google processes the sender, recipient and contents of each message in order to deliver it.
  • We sell nothing – personal data is never shared with ad networks, data brokers or anyone else for marketing purposes.

If data is transferred outside the EU/EEA, the transfer is secured by a valid transfer mechanism, such as the European Commission's Standard Contractual Clauses (SCC). Form data is currently stored within the EU.

5. Retention periods

We store personal data for as long as it is necessary for the purpose it was collected for:

  • Contact form enquiries – deleted no later than 24 months after the last contact.
  • Submitted boats – kept until launch and for up to 12 months after, so we can come back to you about the listing. If you ask for deletion, they are deleted immediately.
  • Waiting list – kept until you unsubscribe, or at most 12 months after we open in the area.
  • Visitor statistics, technical logs and abuse counters – visitor counts are kept for up to 12 months and contain neither IP address nor full browser string. Abuse counters are deleted after 48 hours. The providers' own operational logs are kept for a shorter period.
  • At launch: accounting and payment data – for as long as the Norwegian Bookkeeping Act requires, normally 5 years.

6. Your rights

Under the GDPR you have the following rights in relation to us:

  • Access – to know what data we process about you and to receive a copy.
  • Rectification – to have inaccurate or incomplete data corrected.
  • Erasure – to have data deleted when it is no longer necessary (the ‘right to be forgotten’).
  • Restriction – to request that processing be restricted in certain circumstances.
  • Data portability – to receive data you have provided to us in a machine-readable format and to have it transferred to another controller.
  • Objection – to object to processing based on legitimate interest and to direct marketing.
  • Withdrawal of consent – where processing is based on consent.

You may exercise your rights by contacting us; see section 10. If you believe we are processing data in breach of applicable law, you may lodge a complaint with the Norwegian Data Protection Authority (datatilsynet.no). We appreciate you contacting us first.

7. Cookies

We use cookies and similar technologies to make the platform work, to remember preferences, and for analytics. Which cookies we use, how long they are stored, and how to change your consent are described in our cookie policy.

8. Security

The website is served only over HTTPS with HSTS, and form data travels encrypted to a database whose table only accepts submissions — it cannot be read from the website. Access to submitted forms requires a personal login with the provider. We store no passwords, national identity numbers or card details.

In the event of a personal data breach that poses a risk to your rights, we will notify the Norwegian Data Protection Authority, and you, in accordance with applicable law.

9. Changes

We may update this statement when the service or the regulatory framework changes. In the event of material changes we will notify you in an appropriate manner. The date at the top shows when the statement was last amended.

10. Contacting the controller

If you have questions about privacy or want to exercise your rights, you can contact the controller:

Zagros Nyseth

Dalsbergstien 22, 0170 Oslo, Norge

post@sailfloat.com

We are not required to appoint a data protection officer under GDPR Art. 37, and have not appointed one. Privacy enquiries therefore go directly to the address above.