Privacy Policy

Effective Date: 2025/03/20

1. Introduction

Izzy’s Boat Charter (“we”, “our”, or “us”) values your privacy and is committed to protecting your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Portuguese data protection laws.

This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit our website https://izzysboatcharter.com, make a booking, or otherwise interact with us.


2. Data We Collect

We collect personal information necessary to provide our services, manage bookings, and communicate effectively with our customers.

a. Information You Provide Voluntarily

When you contact us or book a charter, we may collect:

  • Full name

  • Email address

  • Phone number

  • Booking details (date, time, passengers, preferences)

  • Payment information (where applicable)

  • Any additional information you choose to provide

b. Information Collected Automatically

When you browse our website, we may automatically collect:

  • IP address

  • Browser type and version

  • Device information

  • Pages visited, time spent, and referring URLs

  • Cookie and usage data (see Section 6)


3. How and Why We Use Your Data

We process your personal data only when there is a lawful basis under the GDPR, including:

PurposeLegal Basis (GDPR Article 6)
To process bookings, payments, and provide charter servicesContract performance (Art. 6(1)(b))
To communicate with you (confirmations, inquiries, support)Legitimate interest / Pre-contractual steps (Art. 6(1)(f)/(b))
To send marketing communications (only with consent)Consent (Art. 6(1)(a))
To improve our website and servicesLegitimate interest (Art. 6(1)(f))
To comply with tax, legal, or regulatory obligationsLegal obligation (Art. 6(1)(c))

You can withdraw your consent to marketing communications at any time by contacting us.


4. Data Sharing and Disclosure

We do not sell or rent personal data.
We may share limited information only when necessary to:

  • Process payments (with secure payment processors)

  • Manage bookings (with trusted partners, if applicable)

  • Comply with legal obligations or respond to lawful requests

  • Provide hosting, email, or analytics services under GDPR-compliant contracts

All third-party processors are required to safeguard your data and act only on our instructions.


5. Data Retention

We retain personal data only as long as necessary to fulfill the purposes outlined above or to comply with legal obligations.
For example:

  • Booking and billing data: 7 years (for accounting/tax compliance)

  • General inquiries: 12 months after resolution

  • Marketing data: until you withdraw consent

After these periods, data will be securely deleted or anonymized.


6. Cookies and Tracking Technologies

Our website uses cookies and similar technologies to enhance your browsing experience, analyze site traffic, and improve performance.

You can manage or disable cookies through your browser settings at any time.
For detailed information, please review our cookie policy.


7. Your Rights (GDPR Articles 12–23)

As a data subject under the GDPR, you have the following rights:

  • Access: Obtain a copy of your personal data.

  • Rectification: Correct inaccurate or incomplete data.

  • Erasure: Request deletion of your personal data (“right to be forgotten”).

  • Restriction: Limit the processing of your data in certain situations.

  • Portability: Request a copy of your data in a structured, machine-readable format.

  • Objection: Object to processing based on legitimate interest or direct marketing.

  • Withdraw Consent: Withdraw consent at any time (without affecting past lawful processing).

To exercise any of these rights, please contact us at the details below.
We will respond within 30 days as required by law.


8. Data Security

We implement appropriate technical and organizational measures to protect your data against unauthorized access, alteration, loss, or disclosure.
This includes:

  • Encrypted connections (SSL/HTTPS)

  • Secure hosting within the EU

  • Restricted access and password protection

  • Regular security audits


9. International Data Transfers

We store and process personal data within the European Economic Area (EEA).
If we must transfer data outside the EEA (e.g., via cloud services), we ensure adequate safeguards in accordance with GDPR Articles 44–49, such as Standard Contractual Clauses.


10. Contact Information

For any questions, concerns, or to exercise your data protection rights, please contact:

Izzy’s Boat Charter
📍 Vilamoura Marina, Algarve, Portugal
📞 +351 926 558 274
✉️ [email protected]

You may also lodge a complaint with the Comissão Nacional de Proteção de Dados (CNPD):
📍 Av. D. Carlos I, 134 – 1º, 1200-651 Lisboa, Portugal
🌐 www.cnpd.pt