Privacy Policy — Blue Ocean Network LLC

Last updated: July 2026

1. Who we are

Data controller: Blue Ocean Network LLC
Registered address: 1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, USA
EIN: 98-1922043
Phone: +34 672 220 731
Email: hello@blueoceannetwork.us
Website: [insert website]

Blue Ocean Network LLC (“we,” “us,” “our”) provides boat trip and related tourism services. Because we offer and market these services to residents of the European Union and Spain, in addition to customers in the United States and elsewhere, this policy is written to satisfy both the EU/UK General Data Protection Regulation (GDPR) and applicable United States privacy laws. Where obligations differ by jurisdiction, this is noted below.

2. What data we collect

Depending on how you interact with us (booking a trip, contacting us, browsing our website), we may collect:

  • Identification data: name, ID/passport number (where required for boat manifests or port authority rules), date of birth
  • Contact data: email, phone number, postal address
  • Booking and payment data: reservation details, payment card data (processed by our payment provider — we do not store full card numbers)
  • Communications: messages, emails, or forms you send us
  • Technical data: IP address, browser type, device identifiers, cookies (see Section 8)
  • Special categories: dietary requirements or health/mobility information you voluntarily provide for safety on board (treated as sensitive data under GDPR, processed only with your explicit consent or where necessary to protect vital interests)

We do not collect more data than is necessary for the purposes below (data minimization).

3. Why we process your data and our legal basis (GDPR Article 6)

Purpose Legal basis
Managing your booking and providing the service Performance of a contract
Complying with maritime/port safety or tax obligations Legal obligation
Responding to inquiries Legitimate interest / consent
Sending marketing communications Consent (opt-in)
Improving our website and services Legitimate interest
Processing health/dietary data for onboard safety Explicit consent / vital interests

You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.

4. Who receives your data

We only share personal data with:

  • Staff and crew who need it to deliver the service
  • Payment processors and banks
  • Port authorities or maritime safety bodies, where legally required
  • IT and hosting providers acting as our processors, bound by data processing agreements
  • Tax authorities, where required by law

We do not sell your personal data.

5. International data transfers

Because Blue Ocean Network LLC is based in the United States, personal data collected from individuals in the EU/Spain is transferred to and processed in the US. This is a transfer of personal data outside the European Economic Area and requires a valid legal transfer mechanism. We use one or more of the following safeguards for such transfers:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, incorporated into our contracts with EU-based customers and processors; and/or
  • Reliance on service providers certified under the EU-US Data Privacy Framework (DPF), where applicable.

You can request a copy of the relevant safeguard by contacting us using the details in Section 1.

(This section describes the legal mechanism — you still need the underlying contracts/certifications in place with each vendor that touches EU data.)

6. How long we keep your data

We retain personal data only as long as necessary for the purpose it was collected, and to meet legal, accounting, or tax retention obligations (generally up to 5–6 years for invoicing/tax records under Spanish and US requirements, unless a longer period is legally required). After that, data is securely deleted or anonymized.

7. Your rights

If you are in the EU/UK (GDPR):

  • Access — know what data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — request deletion, where applicable
  • Restriction — limit how we use your data
  • Portability — receive your data in a portable format
  • Objection — object to processing based on legitimate interest or direct marketing
  • Withdraw consent at any time
  • Lodge a complaint with your national supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), www.aepd.es

If you are a US resident (e.g., California):
Depending on where you live, state privacy laws may give you rights to know, delete, correct, or opt out of the sale/sharing of personal information. We currently do not meet the revenue or data-volume thresholds that trigger comprehensive state laws like the CCPA/CPRA, but we honor good-faith requests to access or delete your data regardless of where you live. New Mexico does not currently have a comprehensive consumer privacy law; our obligations there are primarily under the New Mexico Data Breach Notification Act (notification of security breaches affecting NM residents’ personal identifying information).

To exercise any of these rights, contact us at the details in Section 1. We will respond within the timeframe required by applicable law (generally one month under GDPR).

8. Cookies

Our website does not use Google Analytics, Meta/Instagram pixels, or any other analytics or advertising cookies. We only use strictly necessary cookies required for the website and booking system to function (e.g., session management, security, and, where applicable, cookies set by our payment processor to complete a transaction). Because these cookies are strictly necessary, EU law (ePrivacy Directive) does not require a consent banner for them, but we still disclose them here for transparency.

If this changes in the future — for example, if we add analytics, advertising, or embedded third-party widgets (booking engine, live chat, video, social media plugins) — we will update this section and, where required, implement a consent banner before those cookies are set.

9. Security

We apply technical and organizational measures appropriate to the risk, including access controls, encryption in transit, and staff training, to protect your personal data against unauthorized access, loss, or misuse.

10. Data breach notification

In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours where required under GDPR, and affected individuals without undue delay where the breach poses a high risk to their rights. Where New Mexico residents are affected, we will comply with the notification timelines of the New Mexico Data Breach Notification Act.

11. Automated decision-making and profiling

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

12. Changes to this policy

We may update this policy from time to time. The “Last updated” date at the top reflects the most recent revision. Material changes will be communicated to you where required by law.

13. Contact us

For any question about this policy or your personal data:
Blue Ocean Network LLC
1209 Mountain Road PL NE, STE N, Albuquerque, NM 87110, USA
Phone: +34 672 220 731
Email: hello@blueoceannetwork.us

For GDPR matters, you may also contact the AEPD (www.aepd.es).

© Copyright 2026 Blue Ocean Network