Skip to content
RIVIERAYacht Services

PRIVACY

Privacy, plainly.

A concierge desk runs on discretion. This page sets out, in plain language, what happens to the details you share with us, and what never happens to them.

Who is responsible

The controller for your data is UNIQUE Capital GmbH, Im Sommerhau 6, 76547 Sinzheim, Germany — the operator of Riviera Yacht Services, represented by Sinan Ercan. Reach us at [email protected]; full operator details are in the legal notice.

What we collect

What you give us: a service request, a newsletter sign-up, or — if you list as a provider — an account (email and password, or a passkey) and a business profile, including any listing photos you upload. That means your name, contact details, vessel or company, and the brief itself. Nothing is collected in the background for advertising.

Why we use it, and on what legal basis

We use a service request to answer and coordinate it (Art. 6(1)(b) GDPR — pre-contractual steps); a newsletter address only on your consent (Art. 6(1)(a)); provider accounts and featured-listing payments to perform our agreement with you (Art. 6(1)(b)); and minimal technical data to keep the site secure and working (Art. 6(1)(f) — our legitimate interest in a safe, functioning service). Your details never feed marketing lists and are never sold.

Where it is stored

Service requests, provider profiles, listings and uploaded images live in our own database and file storage on a server in Germany (Hetzner); site traffic is proxied through Cloudflare. Provider sign-in and payments are handled by the specialist processors below.

Who processes it, and international transfers

Provider authentication is handled by Clerk (Clerk, Inc., USA) and featured-listing payments by Stripe — both as processors under data-processing agreements. Where this involves a transfer to the USA, it is safeguarded by the EU Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework; you can ask us for a copy of these safeguards. Hosting is Hetzner (Germany) and the CDN is Cloudflare. No data goes to advertising platforms.

Server logs

When you visit, our server and CDN briefly record technical data such as your IP address, the time and the page requested, in order to deliver the site, prevent abuse and keep it secure (Art. 6(1)(f)). These logs rotate automatically after a short period and are never combined into a profile of you.

Cookies

No advertising or analytics cookies, and the public site needs no consent banner because it sets none. Logged-in providers get strictly-necessary cookies that keep them signed in (set by Clerk) — these are required for the account area to work and are not used to track you.

How long we keep it

Service requests and newsletter sign-ups: until handled or until you withdraw, then reviewed and removed routinely. Provider accounts and listings: while the account is active. Payment records: as long as German tax and commercial law require (generally up to ten years). Server logs: a short rotation period. After that, or on your request, we delete or anonymise the data — in our database and, where applicable, at Clerk and Stripe.

Your rights

You have the right to access, rectification, erasure, restriction, data portability, and to object to processing we base on legitimate interest. Where we rely on consent, you can withdraw it at any time with effect for the future, without affecting processing already carried out. One email is enough: [email protected]. You also have the right to lodge a complaint with a supervisory authority — for us, the State Commissioner for Data Protection of Baden-Württemberg (LfDI Baden-Württemberg).

Is providing data required?

There is no statutory obligation to give us your data. The fields marked as required are simply what we need to answer a request, run a provider account or process a payment; the newsletter is entirely optional. Without the required details we may be unable to provide that particular service.

No automated decision-making

We do not use your data for automated decision-making or profiling within the meaning of Art. 22 GDPR.

Last updated June 2026. Written plainly under Art. 12 GDPR; we keep refining it with counsel, and the commitments above will not get weaker.