Updated: 12.09.2026

1. Introduction

Welcome to the privacy policy for Div’In users (hereinafter: “you”, “your”), a platform developed and operated by Div’In Solutions Sàrl (hereinafter: “Div’In”, “we”, “our”, “us”), a company registered in Switzerland. This document explains how we collect, use, share, and protect your personal information when you use our platform, either via the mobile application or our website (collectively referred to as the “Services”).

We are committed to protecting your privacy in accordance with Swiss data protection legislation and the European Union’s General Data Protection Regulation (GDPR).

2. Data Controllers

Div’In Solutions Sàrl is the data controller for all personal data processing mentioned below.

However, if you use the Services as a diver and personal data is processed for the purpose of booking dives with a diving center, the diving center is a joint controller with Div’In Solutions Sàrl for this personal data processing. The diving center is an independent data controller for the processing of personal data to conduct the dive.

3. Information We Collect

3.1. Information Collected Through Your Account

3.1.1. If you use the Services as a diver

If you use the Services as a diver, we may collect the following information:

3.1.2. If you use the Services as a diving center

If you use the Services as a diving center, we may collect the following information:

3.2. Automatically Collected Information

When you use the Services, we may automatically collect the following personal data, including through cookies and similar technologies:

3.3. Information from Third Parties

When you authorize a third-party social network (such as Facebook, YouTube, LinkedIn, TikTok, Instagram, etc.) to share information with Div’In, we may receive any data that you publicly share on that social network and data that is part of your profile. This may include basic data related to your account (e.g., first name, last name, email address, gender, birthday, city of residence, profile picture, user ID, etc.) and any other data or activity that you authorize the third-party social network to share. These social networks are governed by their own terms of use and privacy policies, which we encourage you to read.

4. Purposes and Legal Bases for Processing

We use your personal data for the following purposes:

4.1. Provision of Services

We use your personal data to provide our services, including allowing you to create and use an account, manage reservations, process payments, personalize your experience, interact with other users, send you notifications, inform you of Service updates, and ensure the security of the Services. In this case, the legal basis for processing is the necessity to perform a contract and, if you have freely decided to provide us with health data or additional data or have freely selected settings, your consent.

Health data. Health data (medical certificate of no contraindication to diving, allergies or medical conditions relevant to diving) is sensitive data. We process it solely on the basis of your explicit consent (Art. 9(2)(a) GDPR; Art. 6(7) FADP). This consent is collected separately in the application, before any such data is recorded. You may withdraw it at any time in the application; the health data concerned is then deleted.

4.2. Pursuit of Our Legitimate Interests

We may use your personal data to pursue our legitimate interests, which includes detecting fraud, debt collection, as well as investigating any complaints we may receive from you or third parties. This also includes analyzing our Services with the aim of improving them. In this case, the legal basis for processing is the pursuit of our legitimate interests as described above.

4.3. Compliance with Our Legal Obligations

We use your personal data to fulfill our legal obligations, such as maintaining accounting records or responding to requests from authorities. In this case, the legal basis for processing is compliance with a legal or regulatory obligation to which we are subject.

5. Information Sharing

5.1. With Our Processors

We may use external service providers acting as processors, particularly providers to host your personal data, keep the application up-to-date, and fix bugs. Personal data is only shared with them to the extent necessary to perform the tasks assigned to them.

5.2. With Third Parties

We may share your personal data with third parties (i) if necessary for the purposes for which you freely provided it to us, (ii) if you have previously consented to it, or (iii) if the law permits or requires us to do so (e.g., at the request of a judicial authority, to assert our rights in court, or to proceed with debt collection with the help of a collection service).

In addition, certain personal data is shared with other users of the Application, including:

5.3. Google Calendar (optional feature)

If you enable “Calendar Sync” in the Div’In mobile application, you authorise Div’In to create events in the calendars you own within your Google Account. We use this authorisation for one purpose only: to add an event for each dive booking you make, so that the booking appears in your own calendar. The event contains the name of the dive centre, your booking reference, the dates and times of the dive, and, where the dive centre has provided one, the description of the dive package you booked.

We do not read, modify or delete your existing calendar entries, and we do not use data from your Google Account for any other purpose. We store only the access credentials issued to us by Google, so that we are able to add your next booking; we keep no copy of your calendar. You may withdraw this authorisation at any time by switching Calendar Sync off in the application; we then delete the credentials we hold. You may also revoke our access directly from your Google Account at https://myaccount.google.com/permissions, which immediately makes unusable any credentials we may still hold.

Div’In’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

6. Transfer Abroad

Personal data processed by Div'In is processed and stored in Switzerland.

In case of booking dives at a diving center located outside Switzerland, your personal data may also be transferred to the country where the diving center is located and/or to the country where the diving activity will take place. In this case, the transfer is authorized because it is necessary for the execution and conclusion of a contract.

If personal data is transferred abroad in other cases, we ensure that appropriate safeguards are in place to protect your data.

We use certain providers located in the United States for limited processing: payment processing (Stripe, PayPal), sending transactional emails such as booking confirmations (Amazon SES) and push notifications (Google / Firebase). Where personal data is transferred to these providers, the transfer is governed by appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses and equivalent measures recognised under the Swiss FADP.

By contrast, your health data (medical certificate, allergies or medical conditions), your insurance information and your emergency contacts are not transferred to these providers: they are stored in Switzerland, in our database and our private storage.

If you enable Calendar Sync (section 5.3), the booking details listed there are sent to Google LLC in the United States so that the event can be created in your own Google Account. This transfer is not covered by the safeguards described above: it takes place because you asked for it, and its legal basis is your explicit consent (Art. 49(1)(a) GDPR; Art. 17(1)(a) FADP). Switching Calendar Sync off in the application stops it.

7. Data Security

We take the security of your data very seriously and implement appropriate security measures to protect your personal information.

However, no method of transmission over the Internet or electronic storage is completely secure. Although we strive to protect your personal information, we cannot guarantee its absolute security.

8. Your Rights

You have the following rights regarding your personal data:

To exercise these rights, contact us at info@div-in.net.

In addition, you have the right to lodge a complaint with the competent authority for personal data protection, particularly the Federal Data Protection and Information Commissioner (Préposé fédéral à la protection des données et à la transparence, PFPDT) in Switzerland or the supervisory authority in your country of establishment in the EU.

9. Data Retention

We retain your personal data as long as necessary to provide our services and comply with our legal obligations. The criteria used to determine our retention periods include:

10. Changes to This Policy

We may modify this privacy policy from time to time. If we make significant changes, we will inform you by email or by notification in the application before the changes take effect.

11. Contact

If you have any questions regarding this policy or our data practices, please contact us at:

Div’In Solutions Sàrl
E-mail: info@div-in.net