PRIVACY POLICY (EN) — KYMMABOATS LLC (OPT-OUT) — READY TO PUBLISH
Version 1.0
Last updated: February 20, 2026
See also: Terms of Use — /terms | Do Not Sell or Share — /do-not-sell-or-share
1) Who We Are — Contact Details
Controller: KymmaBoats LLC (California, USA)
Support email: support@kymmaboats.com
Privacy email: privacy@kymmaboats.com
Legal notices / address: Registered Agents Inc, 1401 21st Street Suite R, Sacramento, CA 95811, USA
EU Representative (if applicable)
If we do not have an establishment in the EU/EEA and we offer services to individuals in the EU/EEA or monitor their behavior (e.g., via analytics/retargeting), we may appoint an EU Representative under Article 27 GDPR. If appointed, details will be published in this Policy.
2) Personal Data We Collect
2.1 Data you provide
Account/contact details: name, email, phone number
Request/booking details: destination, dates, boat preferences, number of guests, messages/notes
Billing details (if needed): invoicing information where applicable
Communications: messages via forms, email, chat, and calls (where permitted)
2.2 Data collected automatically
Technical data: IP address, device type, browser, operating system, language
Usage data: pages viewed, clicks, time on page, referrers
Cookies/trackers data: see Section 7
2.3 Data from third parties
From payment providers: payment confirmation/failure status (we do not receive or store full card details)
From analytics/advertising platforms: aggregated metrics, audiences, conversion events, where permitted
2.4 Sensitive data
We do not knowingly collect sensitive personal data (e.g., health, race, religion) or children’s data, except where strictly necessary to provide a service you request and only to the minimum extent required. Where required by law, we provide appropriate limitation/opt-out choices for certain uses.
3) How We Use Personal Data (Purposes)
We use personal data to:
Provide the Platform services (requests/bookings, communication, support)
Manage accounts and security (fraud prevention, logs, checks)
Improve Platform performance and user experience (analytics, debugging, UX)
Marketing and retargeting (where applicable and subject to your opt-out choices)
Legal compliance (tax/accounting, rights requests, legal claims)
Where required, we perform impact assessments (e.g., DPIA) and apply additional safeguards.
4) Legal Bases (GDPR)
Where GDPR applies, we rely on:
Contract / pre-contractual steps
Legitimate interests (security, fraud prevention, service improvement, baseline analytics where permitted, with appropriate balancing)
Legal obligation
Where required/used: your right to object/opt-out from certain technologies/uses.
5) Sharing Personal Data (Recipients)
We may share personal data with:
Providers/Partners (charter companies) to fulfill your request/booking
Payment providers and fraud-prevention tools (for payment processing and security)
Hosting and infrastructure providers (website hosting, storage, security)
Customer support tools (communications/ticketing)
Analytics/UX tools (e.g., Google tools, Microsoft tools, and Platform-related analytics/services), depending on configuration and your Privacy/Cookie Settings
Professional advisors (legal/accounting) where necessary
Authorities where required by law
We provide information about recipients or categories of recipients as part of our transparency obligations.
Payment note: We do not receive or store full card details. Payments are handled by payment providers and we receive only status information (e.g., confirmed/failed).
6) International Transfers (If Applicable)
If you are located in the EU/EEA/UK, your data may be transferred to the United States and/or other countries where our vendors operate. Where required, we use appropriate safeguards (such as the EU-US Data Privacy Framework where applicable and/or Standard Contractual Clauses (SCCs), plus supplementary technical/organizational measures).
7) Cookies, Analytics, Session Replay & Retargeting (OPT-OUT)
We use cookies and similar technologies for:
Platform operation and security
Performance measurement (analytics)
UX improvements (e.g., heatmaps/session replay)
(Where applicable) targeted advertising/retargeting
Your choices (OPT-OUT):
You can manage analytics, session replay, and (where applicable) targeted advertising via:
Privacy/Cookie Settings on our site, and/or
/do-not-sell-or-share (for “sale/share” opt-out where applicable)
Cookie consent banner (where required):
Where required by law, we provide controls that allow you to accept or reject non-essential cookies with clear options (including an equally prominent “Reject all” option where applicable).
Examples of tools we may use (non-exhaustive):
Google tools (analytics/ads measurement where enabled)
Microsoft tools (UX analytics/session replay where enabled)
Session replay masking
Where session replay tools are used, we apply masking to prevent recording of sensitive fields (e.g., payments/passwords).
8) “Do Not Sell or Share” (California — CCPA/CPRA)
Under CCPA/CPRA, certain disclosures—especially for targeted advertising/retargeting—may be considered a “sale” or “share” of personal information. We provide a clear opt-out mechanism:
Do Not Sell or Share My Personal Information: /do-not-sell-or-share
Limit the Use of My Sensitive Personal Information (if/where applicable): /limit-sensitive
Global Privacy Control (GPC)
Where we detect GPC signals, we treat them as an opt-out request for sale/share where applicable.
9) Data Retention
We retain personal data only as long as necessary for the purposes above and/or as required by law. Examples:
Bookings/accounting records: up to 7 years
Support communications (tickets/emails/chat): up to 24 months after last interaction
Security/fraud logs: up to 12 months
Analytics/cookies: up to 26 months or per the relevant tool settings
After applicable retention periods, we delete or anonymize data unless legal retention is required (e.g., disputes).
10) Security
We apply technical and organizational security measures (e.g., access controls, logging, encryption where appropriate, vendor management). No system is 100% secure, but we continuously improve protections and reduce risk.
11) Your Rights
GDPR (EU/EEA/UK) may include rights of access, rectification, erasure, restriction, objection, portability, and withdrawal where applicable.
CCPA/CPRA (California) may include rights to know/access, delete, correct, opt-out of sale/share, limit sensitive PI (where applicable), and non-discrimination.
Response timelines
GDPR requests: we respond within 30 days of receipt (unless a lawful extension applies).
CCPA/CPRA requests: we respond within 45 days of receipt (with extensions where permitted).
Submit requests: privacy@kymmaboats.com
We may request identity verification to prevent fraud and unauthorized disclosures.
12) Children
The Platform is intended for individuals 18 and older. We do not knowingly collect personal data from minors. If you believe a minor has provided us data, contact privacy@kymmaboats.com so we can delete it.
13) Changes to This Policy
We may update this Policy. The version and date at the top indicate the latest update. If changes are material, we will provide notice as appropriate (e.g., banner and/or email where required).
14) Contact
Privacy: privacy@kymmaboats.com
Support: support@kymmaboats.com
