Privacy Policy
Last updated: 10 July 2026
1. Data Controller
The controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) is:
- Company: APOPLOU P.C.
- Address: Stadiou, Patra 26504, Greece
- Contact: privacy@appoploo.com
- Data Protection Officer / representative: APOPLOU P.C. is established in the EU, so an Art. 27 EU representative is not required. Privacy enquiries are handled at privacy@appoploo.com.
2. Categories of Personal Data We Process
Appoploo is a yacht-fleet management platform used by charter operators. We process the following categories of personal data:
- Account data — name, email address, password (hashed), company details, phone number, and business address of the operator and any team members they invite.
- Client & crew personal data — where the operator records it: names and contact details of their charter clients, and names, contact details and role information of their crew. The operator is the controller of this data; we act as a processor on their behalf.
- Booking & operational data — charter bookings, quotes, invoices, expenses, vessel and maintenance records, and any free-text notes entered by the operator.
- Technical data — IP address, device/browser information and log data generated when you use the service.
3. Purposes & Lawful Basis
| Purpose | Lawful basis (Art. 6 GDPR) |
|---|---|
| Providing and operating the platform | Performance of a contract (Art. 6(1)(b)) |
| Billing & subscription management | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud prevention, service integrity | Legitimate interests (Art. 6(1)(f)) |
| Legal & tax record-keeping | Legal obligation (Art. 6(1)(c)) |
| Product/marketing communications (only if you opt in) | Consent (Art. 6(1)(a)) |
4. Data Retention
We retain account and operational data for as long as your account is active. When you delete your account, associated tenant data is erased (see Section 7). Records we are legally required to keep — such as invoices for tax purposes — are retained for five (5) years from the end of the fiscal year to which they relate, as required by Greek tax law. Backups are rotated on a rolling basis, so deleted data may persist in backup storage for a short period after erasure before being overwritten.
5. Sub-processors & International Transfers
We rely on the following sub-processors to deliver the service. Your database and file storage are hosted within the EEA (Germany). Where a sub-processor is established outside the EEA, transfers are safeguarded by appropriate mechanisms, principally the EU Standard Contractual Clauses (SCCs).
| Sub-processor | Purpose |
|---|---|
| Cloudflare, Inc. | Application hosting, edge network, DDoS/security |
| Hetzner Online GmbH (Germany, EEA) | Primary database & file storage backend (PocketBase) |
| Stripe, Inc. | Subscription billing & payment processing |
| Resend, Inc. (USA) | Transactional email (account, booking notifications) |
6. Your Rights
Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. You may also withdraw consent at any time and lodge a complaint with your local supervisory authority. Our lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece — www.dpa.gr.
7. Account Deletion & Data Subject Requests
You can delete your account and its associated tenant data at any time from Settings → Delete my account. To exercise any other data subject right, contact us at privacy@appoploo.com. We will respond within the timeframe required by law (generally one month).
8. Changes to This Policy
We may update this policy from time to time. Material changes will be communicated by email to your account address and via an in-app notice. The "last updated" date at the top reflects the current version.