Back to home

Privacy Policy

Last updated: 10 July 2026

1. Data Controller

The controller responsible for your personal data under the EU General Data Protection Regulation (GDPR) is:

  • Company: APOPLOU P.C.
  • Address: Stadiou, Patra 26504, Greece
  • Contact: privacy@appoploo.com
  • Data Protection Officer / representative: APOPLOU P.C. is established in the EU, so an Art. 27 EU representative is not required. Privacy enquiries are handled at privacy@appoploo.com.

2. Categories of Personal Data We Process

Appoploo is a yacht-fleet management platform used by charter operators. We process the following categories of personal data:

  • Account data — name, email address, password (hashed), company details, phone number, and business address of the operator and any team members they invite.
  • Client & crew personal data — where the operator records it: names and contact details of their charter clients, and names, contact details and role information of their crew. The operator is the controller of this data; we act as a processor on their behalf.
  • Booking & operational data — charter bookings, quotes, invoices, expenses, vessel and maintenance records, and any free-text notes entered by the operator.
  • Technical data — IP address, device/browser information and log data generated when you use the service.

3. Purposes & Lawful Basis

Purpose Lawful basis (Art. 6 GDPR)
Providing and operating the platform Performance of a contract (Art. 6(1)(b))
Billing & subscription management Performance of a contract (Art. 6(1)(b))
Security, fraud prevention, service integrity Legitimate interests (Art. 6(1)(f))
Legal & tax record-keeping Legal obligation (Art. 6(1)(c))
Product/marketing communications (only if you opt in) Consent (Art. 6(1)(a))

4. Data Retention

We retain account and operational data for as long as your account is active. When you delete your account, associated tenant data is erased (see Section 7). Records we are legally required to keep — such as invoices for tax purposes — are retained for five (5) years from the end of the fiscal year to which they relate, as required by Greek tax law. Backups are rotated on a rolling basis, so deleted data may persist in backup storage for a short period after erasure before being overwritten.

5. Sub-processors & International Transfers

We rely on the following sub-processors to deliver the service. Your database and file storage are hosted within the EEA (Germany). Where a sub-processor is established outside the EEA, transfers are safeguarded by appropriate mechanisms, principally the EU Standard Contractual Clauses (SCCs).

Sub-processor Purpose
Cloudflare, Inc. Application hosting, edge network, DDoS/security
Hetzner Online GmbH (Germany, EEA) Primary database & file storage backend (PocketBase)
Stripe, Inc. Subscription billing & payment processing
Resend, Inc. (USA) Transactional email (account, booking notifications)

6. Your Rights

Under the GDPR you have the right to access, rectify, erase, restrict, and port your personal data, and to object to processing. You may also withdraw consent at any time and lodge a complaint with your local supervisory authority. Our lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece — www.dpa.gr.

7. Account Deletion & Data Subject Requests

You can delete your account and its associated tenant data at any time from Settings → Delete my account. To exercise any other data subject right, contact us at privacy@appoploo.com. We will respond within the timeframe required by law (generally one month).

8. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated by email to your account address and via an in-app notice. The "last updated" date at the top reflects the current version.