AI Boat Buddy

  • Buy a Boat Valuation Report
  • Articles
  • About AI Boat Buddy
  • Tools
    • Free Boat Valuation Tool
    • Marine Spare Parts & Engine Components
  • API Pricing
  • Sign Up for AI Boat Buddy
  • Buy a Boat Valuation Report
  • Articles
  • About AI Boat Buddy
  • Tools
    • Free Boat Valuation Tool
    • Marine Spare Parts & Engine Components
  • API Pricing
  • Sign Up for AI Boat Buddy
Contact us

Privacy Policy (v2 — udkast 2026-06-09)

AI Boat Buddy is operated by Kim Scheel (Ved Bækken 12, 4660 Store Heddinge, Denmark) and complies with the EU General Data Protection Regulation (GDPR).

We are the data controller for personal data processed through this site. Contact: kim@aiboatbuddy.com.

1. What We Collect

1.1 Boat Reports (B2C)

  • Your email address
  • Boat details and photos you upload
  • Report preferences
  • Payment metadata (Stripe handles card data — we never see your card number)

1.2 API Subscription (B2B)

  • Account holder name and business email
  • Billing address and VAT-ID (where applicable)
  • Subscription tier and billing history
  • API key (we store only a one-way hash — the plaintext key is shown to you once at issuance)
  • Monthly usage counters (call counts, PDF report counts)
  • Session cookies for the broker dashboard (30-day expiry, HTTP-only, secure)

1.3 Automatically Collected

  • IP address and basic request logs (retained 30 days for security and abuse monitoring)
  • Standard web analytics (page views, no third-party trackers)

2. How We Use Your Data

  • To deliver the boat report or API service you have purchased.
  • To process payments via Stripe.
  • To send service-related emails (welcome message with API key, billing receipts, security alerts, scheduled maintenance notice).
  • To improve our valuation models — but only aggregated, anonymised data, never your boat data or client data attached to identifiers.
  • To meet legal and tax obligations.

We do not sell, rent, or share personal data with third parties for marketing.

3. Data Processors We Use

We rely on the following sub-processors to deliver the service. Each is bound by a Data Processing Agreement (DPA) or equivalent under GDPR:

Processor Purpose Location
Stripe Payments Europe Ltd. Payment processing, card storage, billing portal Ireland (EU)
Google Workspace (Gmail SMTP) Transactional email delivery EU regions
Cloudflare DNS, email routing for kim@aiboatbuddy.com Global edge
Hetzner Online GmbH Server hosting (some legacy services) Germany (EU)

Our primary infrastructure runs on-premises in Denmark (the AI Boat Buddy database, valuation engine, and API are hosted at the data controller’s address above).

4. Data Retention

  • Boat report data: uploaded images deleted automatically after report delivery (within 24 hours). Report metadata kept for 30 days for re-download.
  • API customer data: retained for the active life of your subscription and for 7 years after cancellation (statutory bookkeeping requirement under Danish law).
  • API usage logs: 90 days.
  • Stripe billing records: governed by Stripe’s retention policy (typically 7 years).

5. Your Rights Under GDPR

You have the right to:
– Access the personal data we hold about you
– Rectify inaccurate data
– Erasure (“right to be forgotten”) — subject to statutory bookkeeping
– Restrict or object to processing
– Portability — receive your data in a machine-readable format
– Withdraw consent at any time

To exercise any of these rights, email kim@aiboatbuddy.com. We respond within 30 days (typically within 7 business days). You may also lodge a complaint with Datatilsynet (the Danish Data Protection Authority) at datatilsynet.dk.

6. Security

All data is transmitted over TLS (HTTPS). API keys are stored as one-way SHA-256 hashes. Payment cards are stored only by Stripe (PCI-DSS Level 1). Server access is restricted to the data controller via SSH on a non-default port with key-based authentication.

If we discover a personal-data breach, we will notify affected users and Datatilsynet within 72 hours as required by GDPR Article 33-34.

7. International Transfers

Some sub-processors (notably Cloudflare and Stripe’s parent in the US) may transfer data outside the EEA. These transfers are protected under the EU’s Standard Contractual Clauses and (for US-based entities) the EU-U.S. Data Privacy Framework where applicable.

8. Cookies

We use the following cookies:
– Strictly necessary: session cookies for the broker dashboard (aibb_session)
– WordPress functional: cart, checkout, and login (for the B2C report shop)
– No third-party marketing or analytics cookies.

See our Cookie Policy for details.

9. Changes to This Policy

Material changes will be announced by email to all active API subscribers at least 30 days before they take effect. Routine clarifications may be published without notice.

Last updated: 9 June 2026

AI Boat Buddy

Facebook Instagram Youtube

Information

  • Privacy Policy
  • Terms & Conditions
  • Cookie Policy

Quick links

  • Buy report
  • About us

discover

  • Articles
  • Newsletter

email

  • info@aiboatbuddy.com

Call Us

  • +45 7060 5155

location

Denmark, Zealand

Copyright © 2026 AI Boat Buddy | Powered by AI Boat Buddy