Privacy Policy

Last updated: August 2026

1. Data Controller

Club d'Exploration Profonde (CEP) a.s.b.l., registered in Luxembourg.
Contact: clubcep@clubcep.eu

2. Data We Collect

  • Account data: name, email address, phone number (optional), diving certification level, medical certificate expiry date.
  • Authentication data: when you sign in via Google or another OAuth provider, we receive your name, email, and profile picture from that provider. We do not receive or store your password.
  • Event participation: registration for club events, attendance records, dive logs.
  • Financial data: membership fee payment status, trip cost-sharing records. We do not store credit card or bank account numbers.
  • Technical data: IP address, browser type, and session cookies for security and functionality.

3. Purpose & Legal Basis

We process your data to:

  • manage your club membership (contractual necessity);
  • organise diving events and ensure safety compliance (legitimate interest);
  • communicate club news and event updates (legitimate interest);
  • comply with Luxembourg a.s.b.l. legal obligations.

4. Data Sharing

We do not sell your data. We share data only with:

  • diving federations (FLASSA/CMAS) for certification and insurance purposes;
  • email service providers (Resend) for transactional emails;
  • translation services (DeepL, Cloudflare) for article translations (no personal data is sent).

5. Data Retention

Account data is retained while your membership is active and for 2 years after, unless you request earlier deletion. Event and financial records are retained for 10 years per Luxembourg accounting obligations.

6. Your Rights

Under the GDPR, you have the right to access, rectify, erase, restrict processing, and port your data. You may also object to processing or withdraw consent at any time.

To exercise these rights, contact us at clubcep@clubcep.eu.

You may also lodge a complaint with the Luxembourg data protection authority (CNPD).

7. Cookies

We use only essential session cookies required for authentication and security. We do not use advertising or tracking cookies. Analytics are provided by a self-hosted, privacy-respecting tool (Umami) that does not use cookies.

8. Security

All data is transmitted over encrypted connections (TLS). The application is hosted on a dedicated server in the EU. Database backups are encrypted.