Privacy Policy

This policy describes the processing of personal data on www.haliblu.com , during signup and when using HALIBLU. Section 9 additionally explains the roles for guest data processed by a dive centre in its own HALIBLU.

1. Controller

HALIBLU GmbH
Goetenkamp 30
22927 Grosshansdorf
Germany
Phone: +49 40 734491430
Email: info@haliblu.com

2. Hosting and server logs

The website and HALIBLU systems are hosted by Hetzner Online GmbH, Industriestrasse 25, 91710 Gunzenhausen, Germany.

When the website is accessed, technically necessary data is processed, in particular the IP address, timestamp, requested address, amount of data transferred, referrer, browser and operating-system information. We use this data to deliver the website securely and reliably and to detect errors and abuse. The legal basis is Article 6(1)(f) GDPR. Our legitimate interest is the secure operation of the website. Our application logs are generally deleted after no more than 30 days. The hosting provider may additionally maintain its own access and security logs to the extent necessary.

3. Contact and demo requests

When you submit a contact or demo form, we process your name, telephone number, email address, company, country or location, message and selected language. If you have consented to analytics, we also store the campaign parameters that brought you to us. Without consent, no campaign or referrer information is attached to the request.

We use this information to handle your request and discuss HALIBLU with you. The legal basis is Article 6(1)(b) GDPR for pre-contractual measures and, additionally, Article 6(1)(f) GDPR for the orderly handling of business enquiries. Requests are stored in our protected backend before the email notification is sent so that they are not lost during a temporary email-provider outage. Successfully delivered enquiries are deleted no later than 24 months after the last relevant contact unless they lead to a contract or statutory obligations require longer retention.

4. Self-service signup and email verification

During signup we process the company name, requested HALIBLU name, first and last name of the administrator, email address, country and accounting configuration. A verification code confirms that the email address is reachable. Open codes remain valid for ten minutes and a successful verification for 30 minutes. Expired entries are removed daily. Locally stored data from an unfinished order is deleted after no more than 24 hours.

Entries may be kept as a draft in your browser’s local storage while you complete signup. The draft is deleted when payment starts and is not transmitted to us without your action. The legal basis is Article 6(1)(b) GDPR.

5. Payments through Stripe

Payments and the monthly subscription are processed by Stripe Payments Europe, Limited. The embedded Stripe form is loaded only when you proceed to payment. Stripe processes billing and payment details, address, company information, VAT ID where applicable, and technical data. HALIBLU does not receive full card details.

Processing is necessary to enter into and perform the contract under Article 6(1)(b) GDPR. Stripe may act as an independent controller for parts of its processing. Further information: Stripe Privacy Policy .

6. Email through Twilio SendGrid

We use Twilio SendGrid for verification codes, setup-status messages and internal notifications about contact requests. This involves the processing of email address, name, message content and technical delivery data. Depending on the message, the legal basis is Article 6(1)(b) or (f) GDPR. Twilio may process data in third countries and provides, among other safeguards, a Data Processing Addendum and the EU Standard Contractual Clauses.

With your consent, we use Google Analytics 4. For users in the European Economic Area, the provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. We measure page views and the following business steps: pricing-page view, click on a main CTA, start and submission of a contact form, start of signup, email verification, start of Stripe Checkout and payment confirmed by our backend.

We send no form content, names, email addresses, company names, requested HALIBLU names, lead IDs or Stripe session IDs to Google. A random conversion reference is sent with a purchase so the same conversion is not counted twice. Google Signals and advertising personalisation are disabled. Before you consent, the Google Analytics script is not loaded and no data is sent to Google. After consent, cookies such as _ga and _ga_<identifier> and campaign information may be processed.

The legal basis is your consent under Article 6(1)(a) GDPR and the applicable rules on access to information on your device. You can withdraw consent at any time through “Cookie Settings” in the footer. Withdrawal applies to future processing. User- and event-level data is retained in the GA4 property for two months; aggregated reports may remain available for longer. Google may process data outside the EEA and uses the applicable transfer mechanisms, in particular adequacy decisions and Standard Contractual Clauses. Further information: Google Privacy Policy .

8. Local storage and cookies

Without analytics consent, we use only technically necessary browser storage for your language preference, cookie choice and a signup draft you have actively started. Stripe uses technically necessary storage according to its requirements when you enter the payment step. After consent, we additionally store first- and last-touch campaign attribution in your browser and Google Analytics may set analytics cookies.

9. Data in our customers’ HALIBLU systems

Dive centres use HALIBLU to process data about their guests, staff and business partners. This can include identity and contact data, certifications, equipment details, bookings, payments, diving activities and — where configured by the dive centre — health information. The respective dive centre is generally the controller for this processing; HALIBLU acts as processor under Article 28 GDPR. Questions or data-subject requests concerning a particular guest account should therefore first be directed to the relevant dive centre.

Before guest data is processed in production, HALIBLU and the dive centre enter into a data processing agreement. The dive centre remains responsible in particular for the legal basis, privacy information, permissions and retention periods for its data.

10. Recipients and international transfers

We disclose data only where necessary to provide the services described above, perform a contract or comply with a legal obligation. Recipients include Hetzner, Stripe and Twilio SendGrid. Google Analytics is added only after consent. Where data is processed outside the EEA, we rely on the safeguards made available by the provider and applicable to the transfer.

11. Retention

Where no specific period is stated above, we retain personal data only for as long as it is needed for the relevant purpose. Contract, payment and invoice records may be retained longer in accordance with statutory commercial and tax requirements. Data may also be kept where necessary to establish, exercise or defend legal claims.

12. Your rights

Subject to the statutory conditions, you have rights of access, rectification, erasure, restriction, data portability and objection. You may withdraw consent at any time with effect for the future. To exercise your rights, contact info@haliblu.com .

You may also lodge a complaint with a data protection authority. Our competent authority is the Independent State Centre for Data Protection Schleswig-Holstein, Holstenstrasse 98, 24103 Kiel, Germany, www.datenschutzzentrum.de .

13. Security and changes

We use technical and organisational measures to protect personal data against loss, alteration and unauthorised access. These include encrypted transmission, access controls and protected backend storage. We update this policy when our processing, providers or legal requirements change.

Last updated: 4 August 2026