YachtWyse Privacy Policy: How We Protect Your Data

Last Updated: March 1, 2026

YachtWyse (“we,” “our,” or “us”), a product of On10 Solutions, LLC, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our yacht management software platform and related services (collectively, the “Service”).

This Privacy Policy applies to all information collected through our website (https://yachtwyse.com), our web application (https://app.yachtwyse.com), mobile applications, and any related communications. By accessing or using our Service, you agree to the collection and use of your information as described in this Privacy Policy.

1. Information We Collect

1.1 Personal Information

We may collect personal information that you voluntarily provide, including:

  • Name, email address, phone number, and mailing address
  • Account credentials (username and password)
  • Payment and billing information
  • Professional information (job title, company name, role aboard vessel)
  • Communication preferences

1.2 Vessel Information

To provide our yacht management services, we collect:

  • Vessel specifications (make, model, year, length, etc.)
  • Registration and documentation numbers
  • Maintenance records and service history
  • Equipment inventory and specifications
  • Photos and documents related to your vessel
  • Crew profiles, certifications, and scheduling data
  • Charter bookings and guest information
  • Financial records (expenses, budgets, APA tracking)

1.3 Usage Information

We automatically collect certain information when you use our platform:

  • Device information (type, operating system, browser)
  • IP address and general location data
  • Usage patterns and feature interactions
  • Log data and analytics information

2. Legal Basis for Processing (GDPR Article 6)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal information only where we have a valid legal basis:

  • Contractual Necessity: Processing necessary to perform our contract with you (providing the YachtWyse platform, managing your vessel data, processing payments, and fulfilling subscription obligations).
  • Legitimate Interests: Processing necessary for our legitimate interests, such as improving our Service, fraud prevention, platform security, and marketing our services to existing customers. We balance these interests against your rights and freedoms.
  • Consent: Where you have given us specific, informed consent for a particular processing activity, such as receiving marketing communications or enabling optional AI features. You may withdraw consent at any time.
  • Legal Obligation: Processing necessary to comply with applicable laws, regulations, or legal processes (e.g., tax reporting, responding to lawful requests from public authorities).

3. How We Use Your Information

We use the collected information for the following purposes:

  • Providing and improving our yacht management services
  • Processing maintenance schedules and sending reminders
  • Generating expense reports and cost analytics
  • Powering AI diagnostic assistance and predictive maintenance features
  • Processing payments and managing subscriptions
  • Communicating with you about your account and services
  • Ensuring platform security and preventing fraud
  • Complying with legal and regulatory requirements
  • Analyzing usage to improve our products and services

4. Information Sharing

We do not sell your personal information to third parties. We may share your information in the following circumstances:

4.1 Service Providers

We work with third-party service providers who assist us in operating our platform, including cloud hosting, payment processing, email delivery, and analytics services. These providers are contractually obligated to protect your information and process it only as instructed.

4.2 Legal Requirements

We may disclose your information if required by law, court order, or government request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice on our website of any change in ownership.

4.4 With Your Consent

We may share your information with third parties when you have given us your explicit consent to do so.

5. Data Security

We implement industry-standard security measures to protect your information, including:

  • TLS 1.3 encryption for data in transit
  • AES-256 encryption for data at rest
  • Secure authentication and role-based access controls
  • Regular security audits and monitoring
  • Employee training on data protection practices

While we strive to protect your information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security.

5.1 Breach Notification

In the event of a data breach that affects your personal information, we will notify you and the appropriate regulatory authorities (including relevant EU supervisory authorities) as required by applicable law, including within 72 hours where required under GDPR.

6. Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. Our retention criteria include:

  • Account data: Retained for the duration of your active account. If you request account closure, your account is disabled immediately and permanently deleted after 30 days. You may log back in during this 30-day window to reactivate your account.
  • Vessel and maintenance records: Retained for the lifetime of your active account and deleted upon account closure, except where associated with financial records subject to the 7-year retention requirement below.
  • Financial and transaction data: Retained for 7 years as required by tax and accounting regulations. This includes expenses, charter bookings, charter payments, and management fees. These records are archived upon account closure and permanently purged after the 7-year retention window — even if your account has been deleted.
  • AI interaction data: Your AI conversation history is stored in your account. You control how long it is retained via the Chat History Retention setting in Account Settings > Preferences. Options include: don't save history (cleared in the next daily cleanup), 30 days, 90 days, 6 months, 1 year, or keep forever. Anthropic, our AI provider, may retain API interactions for up to 30 days for trust and safety review only — this data is never used for model training.
  • Usage and analytics data: Retained for the duration of your account and deleted upon account closure.

You may request deletion of your data at any time by closing your account through Account Settings. Upon closure, your account is disabled immediately and all data permanently deleted after 30 days, except financial records which are retained for 7 years as required by law. To exercise your right to erasure, contact dataprotection@on10solutions.com.

7. Your Privacy Rights

Depending on your location, you have the following rights regarding your personal information:

7.1 Access

You have the right to request information about the personal information we hold about you and to receive a copy of that information.

7.2 Correction

You have the right to request that we correct inaccurate or incomplete personal information about you.

7.3 Deletion

You have the right to request that we delete your personal information in certain circumstances.

7.4 Restriction of Processing

You have the right to request that we restrict the processing of your personal information in certain circumstances.

7.5 Data Portability

You have the right to receive your personal information in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

7.6 Objection

You have the right to object to the processing of your personal information where we rely on legitimate interests as our legal basis.

7.7 Withdraw Consent

Where we process your information based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

7.8 Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

7.9 How to Exercise Your Rights

To exercise any of these rights, please contact our Data Protection Team at dataprotection@on10solutions.com. We will respond to your request within 30 days, or within the timeframe required by applicable law.

8. European Privacy Rights (GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation.

8.1 Data Controller

On10 Solutions, LLC is the data controller for personal information collected through the YachtWyse platform. For vessel and crew data that you enter into the platform, you are the data controller and we act as the data processor on your behalf.

8.2 EU/UK Representative

As On10 Solutions is established in the United States, we have designated a representative in the European Union in accordance with Article 27 of the GDPR. You may contact our EU representative at: eu-representative@on10solutions.com

8.3 Right to Lodge a Complaint

If you are located in the EEA, UK, or Switzerland, you have the right to lodge a complaint with your local Data Protection Authority (supervisory authority) if you believe that our processing of your personal information violates applicable data protection law. A list of EU supervisory authorities is available at https://edpb.europa.eu. For the UK, contact the Information Commissioner's Office (ICO) at https://ico.org.uk.

9. International Data Transfers

On10 Solutions is based in the United States, and we process and store information on servers located in the United States. If you are located outside the United States, your personal information may be transferred to, stored, and processed in a country different from your country of residence.

9.1 Legal Basis for Transfers

When we transfer personal information from the EEA, United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we use specific legal mechanisms including Standard Contractual Clauses (SCCs) approved by the European Commission, to ensure your data receives an adequate level of protection.

9.2 Data Storage Locations

Our data storage locations are:

  • United States (primary)
  • European Union (available for Enterprise clients located in the EEA)
  • United Kingdom (available for Enterprise clients located in the UK)

Enterprise and Superyacht clients may select their preferred data storage region during onboarding. Contact our sales team for data residency options.

10. California Privacy Rights (CCPA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information we collect, the right to delete your information, the right to opt-out of the sale of your personal information, and the right to non-discrimination. We do not sell your personal information.

11. AI Features and Automated Processing

YachtWyse includes AI-powered features including diagnostic assistance, predictive maintenance, and document analysis. These features are powered by the Claude API, provided by Anthropic, PBC. The following explains how your data is handled in connection with AI features:

  • How it works: When you use an AI feature, YachtWyse sends the minimum necessary context — such as your vessel configuration, relevant maintenance records, or a specific document — to Anthropic’s API to generate a response. Your full database is never bulk-uploaded to any AI service.
  • No model training: Your data is not used to train AI models — by YachtWyse or by Anthropic. Under Anthropic’s commercial API terms, customer data submitted via API is explicitly excluded from model training.
  • AI data retention: You control how long your AI conversation history is stored via Account Settings > Preferences. You may choose not to retain any history beyond the next daily cleanup, or set a retention window of 30 days, 90 days, 6 months, or 1 year. Anthropic may retain API interactions for up to 30 days for trust and safety review, after which they are deleted.
  • Data isolation: Each account’s AI context is fully isolated. Your vessel data is never shared with or visible to other YachtWyse users or used to inform responses for other accounts.
  • No automated decisions: AI recommendations are advisory only. No automated decisions with legal or significant effects are made without human oversight. You always retain control over maintenance decisions, scheduling, and operations.
  • Opt-out: You may disable AI features at any time through your account settings without affecting core platform functionality.

12. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience on our platform. When you first visit our website, a cookie consent banner allows you to choose which categories to enable. You can change your preferences at any time via the “Cookie Settings” link in the footer.

Cookie Categories

  • Essential (always active): Required for platform functionality including authentication, security tokens, and session management. Cannot be disabled.
  • Analytics (opt-in): Help us understand how visitors use the site. You may decline these without affecting functionality.
  • Marketing (opt-in): Used for personalized content and advertising measurement. You may decline these without affecting functionality.

Cookie Inventory

Cookie NameCategoryPurposeDuration
cookie-consentEssentialStores your cookie consent preferencesPersistent
__next*EssentialNext.js framework session and routingSession
_clck, _clskAnalyticsMicrosoft Clarity — session and click tracking for heatmaps and session recordings1 year / Session
CLIDAnalyticsMicrosoft Clarity — unique user identifier1 year
ANONCHK, MR, MUID, SMAnalyticsMicrosoft Clarity / Bing — analytics and cross-site trackingVaries (session to 1 year)

For users in the EEA and UK, we obtain your consent before placing non-essential cookies. You can manage your preferences at any time by clicking “Cookie Settings” in the website footer, or through your browser settings. Note that disabling essential cookies may affect platform functionality.

13. Children’s Privacy

Our services are not intended for individuals under 16 years of age (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will take steps to delete it.

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page, updating the “Last Updated” date, and sending an email notification to the address associated with your account. For material changes, we will provide notice at least 30 days before the changes take effect, where possible. Your continued use of our services after changes constitutes acceptance of the updated policy.

15. Summary of Your Rights by Region

RegionApplicable LawKey Rights
United States (California)CCPA/CPRAKnow, Delete, Opt-out, Non-discrimination
European UnionGDPRAccess, Rectification, Erasure, Restriction, Portability, Objection, Complaint to supervisory authority
United KingdomUK GDPRAccess, Rectification, Erasure, Restriction, Portability, Objection, Complaint to ICO
CanadaPIPEDAAccess, Correction, Withdraw consent
AustraliaPrivacy ActAccess, Correction, Complaint

16. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

YachtWyse (On10 Solutions, LLC)

5005 West Laurel, Suite 100

Tampa, FL 33607

United States

Email: info@yachtwyse.com

Phone: +1 813-252-2334

Data Protection Team

For privacy-specific inquiries or to exercise your privacy rights:

Email: dataprotection@on10solutions.com

EU/UK Representative

For users in the European Economic Area or United Kingdom:

Email: eu-representative@on10solutions.com