Legal

Privacy policy

Last updated: 17 July 2026

Who we are

Sofia K Diving Safari runs diving and boat trips from Sithonia, Halkidiki, in Greece. This policy explains what happens to your personal data when you visit this website or send us an enquiry. We decide why and how that data is used, which makes us the data controller for it. [Add the registered legal entity name, legal form, registration number, and registered address here.] You can reach us about anything in this policy at contact@sofiakdivingsafari.com.

When you just read the site

Reading this site involves a few things, and we store none of them ourselves. Your browser asks our host, Cloudflare, for each page. Cloudflare therefore receives your IP address and keeps it in its own records - that is simply how the web works, and it is also how the site stays online and defended. To pick your language, we look at the cookie described below if you have one, and otherwise at the languages your browser says it prefers. We keep no copy of any of it: no account, no analytics, no tracking, no profile.

What the enquiry form collects

If you send us an enquiry, we collect what you type into the form, plus two details you do not type:

  • Your name - required, so we know who we are replying to.
  • Your email address - required. This is how we reply to you.
  • Your message - required. Whatever you want to ask us.
  • Your phone number - optional, if you would rather we called or messaged you.
  • The number of guests - optional, so we can check the boat fits your group.
  • The trip you are interested in - optional, and "not sure yet" is a perfectly good answer.
  • Your rough dates - optional, so we can check availability.
  • Your IP address - used only to count how many times your connection has posted the form in the last minute. We never put it in the email, and we hold it only for those 60 seconds.
  • The time you sent it - our server's clock, shown in the email so we know when you wrote.

No law or contract requires you to give us any of this. The three required fields are simply what we need in order to answer you - without them we cannot reply. The optional ones help us quote accurately, and the form works without them. The form also carries one hidden field that only spam bots fill in; if it arrives filled, we discard the message.

Why we use it, and our legal basis

We use your data for four purposes. Each needs a legal basis under the GDPR, and for all four it is the same one: our legitimate interest. That means you can object to any of them.

  • Reading and answering your enquiry. We use what you typed to understand what you are asking for, work out a price, and write back. Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in answering people who contact us about our trips. You can object to this - see Your rights below.
  • Recognising you if you come back. Diving seasons repeat, and people who asked last year often ask again. Keeping your past enquiry means we can pick up where we left off instead of starting from nothing. Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in keeping a workable record of the people who have asked about our trips. This is the purpose that our 24-month retention period serves.
  • Keeping the form working. We use your IP address to limit how often one connection can post the form - five times a minute - which holds automated spam down. Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in protecting the form from misuse.
  • Serving and protecting the website. Cloudflare receives your IP address on every page you open, delivers the page, and blocks attacks on the site. We also read your language cookie, or your browser's preferred languages, to open the site in your own language. Our legal basis is our legitimate interest (Article 6(1)(f) GDPR) in keeping this site online, defended, and readable in your language.

We make no automated decision about you that has a legal or similarly significant effect, and we build no profile of you. The spam limit above is automatic, but all it can do is ask you to try again in a minute.

Who we share it with

We do not sell your data and we do not share it for advertising. Today, three parties handle it:

  • Resend (Plus Five Five, Inc.) delivers the enquiry email to our inbox. It sees everything the email contains - your name, your message, and the rest of what you typed. It acts on our instructions and may use your data for nothing but delivering that email. It does not receive your IP address.
  • Cloudflare, Inc. hosts this website and defends it from attack, on our instructions. Every request to the site passes through it, so it receives your IP address whenever you open a page. Cloudflare also uses what it sees across its whole network to detect attacks, which is its own decision rather than ours.
  • Your enquiry then arrives in our own email inbox, where a person reads it and answers you. [Name the email provider that hosts our inbox here.]

Where your data goes

Resend and Cloudflare are US companies. So your data travels to the United States, outside the European Economic Area. Resend stores it there. Two safeguards cover that journey. First, both companies are certified under the EU-US Data Privacy Framework. The European Commission has decided that this framework protects personal data properly. Second, both have agreed to the European Commission's standard contractual clauses with us, which are a separate protection that does not depend on that decision. [State where our email provider keeps the inbox, and, if that is outside the European Economic Area, the safeguard covering it.] Email us at contact@sofiakdivingsafari.com and we will send you a copy of any of these.

How long we keep it

This website has no database. Your enquiry is never written down here - it exists as an email, and in the systems that carry it:

  • Our inbox: we keep enquiry emails for up to 24 months after your last contact with us, then delete them. That leaves us time to answer you, quote you, and recognise you if you come back next season.
  • Resend: keeps a copy in its sending logs, then deletes it - 30 days at the time of writing. Resend sets that period, not us.
  • The spam limit: counts your IP address for 60 seconds, then forgets it. Nothing is kept beyond that minute, and there is nothing there for us to look up.
  • Cloudflare: records requests to the site, including your IP address, both in its own network logs and in the server log our site writes as it runs. Neither holds anything you typed. Cloudflare sets how long these are kept, and its own privacy policy covers them.

Cookies

This website sets one cookie, and only if you use the language picker. It is called "locale". It stores one thing: the language code you chose - en, bg, or ro. That way the site opens in your language next time. It is set by this website, read only by this website, and it lasts one year. If you never touch the language picker, we set no cookie at all.

We ask for no consent for this cookie because none is required: it only remembers a choice you made yourself, which the ePrivacy rules treat as strictly necessary. That is why you see no cookie banner here. We use no analytics, no advertising, and no tracking cookies of any kind. Fonts and images are served from this domain rather than from a third party, so reading this site sends nothing to any company other than Cloudflare, our host.

Your rights

The GDPR gives you these rights over the personal data we hold about you:

  • Access - ask us what we hold about you, and get a copy of it.
  • Rectification - have anything wrong or incomplete corrected.
  • Erasure - ask us to delete it.
  • Restriction - ask us to pause what we do with it while something is sorted out.
  • Objection - object to our using it at all. Every one of our purposes rests on legitimate interest, so this right covers everything we do with your data.

To use any of these, email us at contact@sofiakdivingsafari.com. It normally costs you nothing, and we answer within one month. If your request is complicated, we can take up to two months more, and we will tell you within that first month if we do. If we have real doubt about who you are, we will ask you for proof first, so that we do not hand your data to someone else. You can also complain to a data protection authority. Use the one where you live, the one where you work, or the one where you think the problem happened.

How we protect it

We serve the site over an encrypted HTTPS connection, so nobody can read what you type into the form on its way to us. The form also limits how often you can send it, which holds automated abuse down. The site keeps no database of its own, so there is no store of enquiries here to lose. No website or email system is ever completely secure. We cannot promise you absolute safety. If a breach ever did put people at risk, we would tell the supervisory authority, and we would tell you too if it put you at high risk.

Changes to this policy

If we change what we do with your data, we change this page and the date at the top with it. When a change actually matters to you - a new purpose, or a new company handling your data - we will say so plainly here rather than leave you to spot the difference. The date above always tells you which version you are reading.

Contact

Questions about this policy, or about what we hold on you? Email Sofia K Diving Safari at contact@sofiakdivingsafari.com and a person will answer.