Privacy Policy
Effective date: 6-July-2026 Last updated: 6-July-2026
This Privacy Policy explains how [DiveCC Pty Ltd] ("ISC", "we", "us") collects, uses, and protects your personal information when you use the ISC DIVER mobile and web application (the "App") and related services.
1. Who we are
ISC DIVER is a dive training and certification platform used by dive students, certified divers, dive professionals, and dive centres. Contact: privacy@iscdiver.com — [registered address].
For students enrolled through a dive centre, the dive centre is responsible for the training relationship; ISC processes your data to deliver the platform.
2. Information we collect
Information you provide
-
Account & profile — name, email address, phone number, date of birth, profile photo, emergency contact details.
-
Training records — course enrolments, theory progress, exam and quiz answers, skill sign-offs, instructor assessments, and certifications you earn.
-
Dive medical questionnaires (health information) — answers to dive-safety medical screening questions required by international training standards before in-water training. This is sensitive health information; we collect it only with your explicit consent, and only the information needed to determine fitness to dive. Where a physician's clearance is required, we store the clearance document you upload.
-
Waivers & signatures — liability documents you sign electronically.
-
Dive logs — dive details (site, date, depth, duration, conditions, buddies, equipment, marine life observed) and any photos or notes you attach. Dive-site selection may record the location of the dive.
-
Photos & videos — dive photos, profile photos, and course media. If you or your dive centre create a "Dive Wrap" course video, we process course photos and videos to produce it, including on-device face detection so you can choose to blur faces (face detection for blurring runs on your device; detected face regions are not used to identify anyone).
-
Payment information — when you purchase courses or memberships, payment is processed by Stripe; we never receive or store your full card number. We keep records of what you purchased.
-
Communications — support requests, feedback, and messages you send us.
Information collected automatically
-
Device & usage data — device model, OS version, app version, language, and how you use the App (screens viewed, features used), collected via PostHog (hosted in the EU). This may include session replays of your interactions with masking applied to sensitive screens.
-
Crash & performance data — via Sentry, to fix bugs.
-
Push tokens — so we can send you notifications you've enabled.
-
Location — only if you grant permission, and only while using the App, to suggest nearby dive sites. We do not track your location in the background.
Information from devices you connect
-
Dive computers — if you import dives over Bluetooth, we read dive profiles (depth/time/temperature) from your dive computer.
-
Nearby app devices — instructor sign-offs can transfer between two nearby devices over Bluetooth or QR code; this transfers only the sign-off record.
3. How we use your information
-
Deliver training: courses, exams, skill tracking, certification issuance and verification
-
Maintain your digital logbook and dive history
-
Assess dive-safety fitness via medical questionnaires (with your explicit consent)
-
Process payments and manage memberships
-
Send service notifications (course updates, certification and membership reminders) and, with consent, marketing emails (unsubscribe anytime)
-
Operate community features you choose to use (activity feed, follows, shared dives)
-
Improve the App through analytics and crash reporting
-
Meet legal, safety, and training-standard obligations
Legal bases (where GDPR applies): performance of contract (training, logbook, payments), explicit consent (health information, marketing, location), legitimate interests (analytics, security, fraud prevention), legal obligation (financial records, training-standard record-keeping).
4. Community features & visibility
Your profile defaults to being visible to approved followers only. You control who can follow you and what appears in the activity feed. Certifications can be verified by dive centres you share them with. You can report or block other users in the App.
5. Who we share information with
We do not sell your personal information. We share it only with:
-
Your dive centre and instructors — training records, medicals, and waivers relevant to courses you take with them (they need these to train and certify you safely)
-
Certification verification — when you share a certification, the recipient sees the certification details
-
Service providers (processors) acting on our instructions: Stripe (payments), Resend (email), PostHog EU (analytics), Sentry (crash reporting), Amazon Web Services (photo storage; automated photo checks on profile photos to confirm they show a face — no biometric identification template is retained), Cloudflare (content delivery), Hetzner (video rendering), Expo and Google Firebase (push notifications and app updates)
-
Legal & safety — where required by law, or where necessary in a diving emergency or incident investigation
6. Children and minors
The App is not directed at children under 13, and you must be at least 13 to create an account. Students under 18 may use the App as part of a dive course only with the consent and involvement of a parent or guardian, who must complete or countersign medical questionnaires and waivers where required. We collect no more information from minors than from any other student.
7. Data retention
-
Certification records are retained long-term — they are the proof of your qualifications and are required by training standards.
-
Medical questionnaires and waivers are retained for as long as required by training standards and applicable liability laws, then deleted.
-
Dive Wrap source media used for video rendering is deleted from the rendering system within 30 days.
-
Analytics data is retained per our analytics provider settings and then aggregated or deleted.
-
Account data is deleted or anonymised when you delete your account (below), except records we must keep by law (e.g. certification registry, financial records).
8. Your rights and choices
-
Access, correct, export your data from your profile or by contacting us
-
Delete your account in the App (Profile → Settings → Delete account) or at https://iscdiver.com/delete-account. Certifications already issued remain in the certification registry as required by training standards, but are unlinked from your marketing/community profile.
-
Withdraw consent for health data (note: an in-date medical is required to continue in-water training), marketing, or location at any time
-
Permissions — camera, photos, location, Bluetooth, and notifications can each be revoked in your device settings; the related feature simply stops working
-
EU/UK users have GDPR rights (access, rectification, erasure, restriction, portability, objection) and may complain to their supervisory authority. Australian users may complain to the OAIC.
Requests: privacy@iscdiver.com. We respond within 30 days.
9. International transfers
We operate globally. Your data may be processed in Australia, the EU, Singapore, and the United States by the providers listed above, protected by appropriate safeguards (standard contractual clauses or equivalent).
10. Security
Data is encrypted in transit (TLS) and at rest where supported. Access is role-restricted (your dive centre sees only its own students). Sensitive credentials are stored in your device's secure keystore. Instructor sign-off actions can require biometric confirmation — biometric data never leaves your device and is handled entirely by iOS/Android.
11. Changes
We will notify you in the App of material changes to this policy. Continued use after the effective date constitutes acceptance.
12. Contact
[International Scuba Certification Pty Ltd] [Registered address] privacy@iscdiver.com
