← Back to Sailing Router

Privacy Policy

Last updated: 2026-05-12

This Privacy Policy explains what personal data Sailing Router (operated by Nitrox Consulting) collects when you use sailingrouter.tech, why we collect it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR). If anything here is unclear, write to privacy@nitroxconsulting.com.

1. Data Controller

Nitrox Consulting ("we", "us") is the data controller for personal data processed via sailingrouter.tech. Contact: privacy@nitroxconsulting.com.

2. What We Collect

We collect the minimum data needed to run the routing service:

3. Why We Collect It

We use your data for the following purposes only:

4. Legal Basis (GDPR Article 6)

We rely on contract performance (Art. 6(1)(b)) for account creation, route computation, and credit deduction — without processing these, we cannot deliver the service. We rely on legitimate interests (Art. 6(1)(f)) for security logging and error tracking, balanced against your rights. We rely on consent (Art. 6(1)(a)) for Google Analytics — see §5; you can decline by blocking analytics cookies in your browser.

5. Third-Party Processors

We share data with the following sub-processors, each acting on our behalf under a data-processing agreement (DPA) or equivalent contractual safeguards:

6. International Data Transfers

Some sub-processors are based outside the European Economic Area (EEA), primarily in the United States (Resend, Sentry, parts of Google Analytics infrastructure). Transfers rely on the European Commission's Standard Contractual Clauses (SCCs) or, where applicable, the EU-U.S. Data Privacy Framework. Our primary hosting (Google Cloud Run and AWS Lightsail) is inside the EEA.

7. Your Rights

Under GDPR, you have the right to:

To exercise any of these rights, email privacy@nitroxconsulting.com. We aim to respond within 30 days.

8. Retention

Account data and route history are retained for as long as your account exists. If you delete your account, all personal data is purged within 30 days, except where we are required by law to retain it (e.g. invoicing records for tax purposes — currently none, as the service is free-tier). Request logs are kept 30 days. Error reports in Sentry are retained 90 days.

9. Updates to This Policy

We may update this policy as the service evolves. The "Last updated" date at the top reflects the most recent change. Material changes affecting how we use your data will be announced by email to registered users.