Privacy Policy
This policy explains what personal data iDive collects, why we collect it, the legal basis on which we process it, how long we keep it, who we share it with, and the rights you have as a Data Principal under India's Digital Personal Data Protection Act, 2023 and the rules made under it.
1. Who we are (the Data Fiduciary)
iDive (the "Platform") is an online scuba aggregator operated from Goa, India. For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), iDive is the Data Fiduciary that decides why and how your personal data is processed.
The registered legal entity that operates iDive is [REGISTERED LEGAL ENTITY NAME, to be confirmed], with its base of operations at Novotel Resort and Spa, Candolim, Goa 403515, India. You can reach us at hello@idive.in or on WhatsApp at +91 87677 60334.
2. The data we collect and why
We collect only what we need to run the services you ask for. Here is what we collect, grouped by purpose:
Account and login
When you create an account or sign in, we collect your name, phone number or email, and a one-time password or a Google sign-in identifier. We use these to verify it is you, keep you signed in, and contact you about your account. We do not store your password; sign-in is by one-time password or Google.
Bookings and reservations
When you reserve a course, dive or trip, we collect the details needed to fulfil it, such as your certification level, the destination and dates, and the people in your party. We use this to coordinate your booking with dive centres and trip suppliers.
Community content you post
If you join the iDive community, we store the posts, replies, reactions, photos, dive logs and buddy-finder profile you choose to share. This content is shown to other community members. You decide what to post, and you can edit or remove it.
Dive logbook
If you use the dive logbook, we store the dives you record, including the site, date, depth, duration and any notes or buddy names you add. This is your personal record and is processed to provide the logbook feature to you.
AI chat (Laila)
When you chat with our assistant Laila, your messages are processed to answer your questions and help you plan dives. These chats are handled through our AI sub-processor (see section 8).
Analytics
With your consent, we collect basic, aggregated usage data (such as which pages are visited and how the site performs) to understand and improve the Platform. Analytics only runs after you accept it in the consent banner.
Payments
When you pay, our payment processor handles your card or payment details directly. We do not store your full card number. We keep a record of the transaction (amount, status, reference) for accounting and legal compliance.
3. The legal basis: your consent
We process your personal data on the basis of the consent you give us at the point of collection, in line with the DPDP Act. The consent we ask for is specific, informed and unambiguous, and it is limited to the purposes described in this policy. We do not pre-tick consent boxes, and giving consent for one purpose (such as your account) does not bundle in others (such as analytics, which you choose separately in the cookie banner). For some processing we also rely on the lawful "legitimate uses" allowed by the DPDP Act, for example responding to a request you make to us, or meeting a legal obligation.
4. Your rights as a Data Principal
Under the DPDP Act you have the following rights, and we give you easy ways to use each of them:
- Right to access and a summary of your data. You can download a copy of the personal data we hold about you.
- Right to correction. You can correct or update your name, email or phone and your community profile.
- Right to erasure. You can ask us to delete your account and personal data, subject to records we must keep for legal or financial reasons.
- Right to withdraw consent. You can withdraw any consent at any time. Withdrawing is as easy as giving consent, and stopping further processing does not affect anything already done lawfully before you withdrew.
- Right to grievance redressal. You can raise a complaint with us and have it addressed within the timeline below.
- Right to nominate. You can nominate another person to exercise your rights on your behalf in the event of your death or incapacity. Contact us at hello@idive.in to record a nominee.
You can use most of these rights yourself from the "Privacy and your data" tools in your dashboard (download a copy of your data, correct your details, withdraw consent, or delete your account). For anything else, or to raise a complaint, use our Grievance Redressal form or email hello@idive.in.
5. Grievance Officer
We have appointed a Grievance Officer to answer your questions and resolve any complaint about how we handle your personal data.
We commit to acknowledging and resolving grievances within 90 days of receiving them. The fastest way to raise one is the Grievance Redressal form, which gives you a reference number you can quote in any follow-up.
6. How long we keep your data (retention)
We keep personal data only for as long as it is needed for the purpose it was collected, or for as long as the law requires. Our standard schedule is:
| Data | Retention |
|---|---|
| Login sessions | 30 days, then expired and removed |
| One-time passwords (OTP) | 5 minutes, then deleted |
| Analytics and click data | 365 days, then removed |
| Hidden or removed community posts | 90 days, then permanently deleted with their media |
| Resolved moderation reports | kept for a limited period as a moderation audit trail |
| Resolved grievances | kept for several years as a legal and compliance record |
| Consent records | kept as a ledger for the life of the account plus a legal tail, so we can prove what you agreed to and when |
| AI chat (Laila) conversations | 180 days, then purged |
| Financial and transaction records | retained as required by tax and accounting law |
When you delete your account, we remove your personal content and revoke your sessions. We anonymise records we must keep for legal, financial or aggregate reasons so that they no longer identify you.
7. Cookies and analytics consent
We use a small number of essential cookies to run the site and keep you signed in; these are always on because the Platform cannot work without them. We use analytics and load our assistant Laila only after you accept them in the consent banner shown on your first visit. You can choose "Essential only" to keep analytics and Laila off, and you can change your mind at any time by clearing the consent cookie or using the privacy tools in your dashboard.
8. Who we share data with (sub-processors)
We use a small set of trusted service providers to deliver parts of the Platform. Each processes data only for the purpose below and under our instructions:
| Provider | Purpose |
|---|---|
| OpenAI | Powers our assistant Laila, which answers your questions in chat |
| Meta (WhatsApp Cloud API) | Sends login one-time passwords and trip and crew messages over WhatsApp |
| Google sign-in (OAuth) and, with your consent, website analytics | |
| Razorpay | Processes your payments securely |
Some of these providers process or store data on servers outside India. Where that happens, the transfer is carried out in line with the cross-border provisions of the DPDP Act and the rules made under it. We monitor any government list of restricted countries and will adjust our processing if required.
9. Children's data: iDive is an 18+ platform
The iDive community and account features are strictly for adults aged 18 or older. You confirm you are 18 or older when you sign up. Under-18s must not register for the community or create an account. Because we do not knowingly collect personal data from anyone under 18, the verifiable-parental-consent process does not apply. If we learn that an under-18 has registered, we will remove the account.
10. Security and breach notification
We take reasonable technical and organisational measures to protect your personal data, including access controls, encryption in transit, rate-limiting and same-origin protections on our forms, and limited data retention. No system is perfectly secure, but if a personal data breach occurs that is likely to affect you, we commit to notifying the Data Protection Board of India and the affected users within 72 hours of becoming aware of it, with details of what happened and what you can do.
11. Changes to this policy
We may update this policy as the Platform and the law evolve. When we make a material change, we update the "Last updated" date and the policy version above. If the change affects what you consented to, we will ask you to review and re-confirm your consent the next time you sign in.
12. Contact us
Questions about your privacy or this policy? Email hello@idive.in, message us on WhatsApp at +91 87677 60334, or use the Grievance Redressal form.