Privacy Policy

This Privacy Policy describes how Zeas Yacht Academy (“we,” “our,” or “the Academy”) collects, uses, and protects the personal data of its clients, students, staff, and other stakeholders in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR).

  1. Data Protection Principles

We adhere to the following principles as outlined in the GDPR to ensure your privacy is protected:

  • Lawfulness, Fairness, and Transparency: Personal data will be processed lawfully, fairly, and in a transparent manner.
  • Purpose Limitation: Personal data will be collected for specified, explicit, and legitimate purposes and will not be further processed in an incompatible manner.
  • Data Minimization: Personal data will be adequate, relevant, and limited to what is necessary for the purposes for which they are processed.
  • Accuracy: We will take reasonable steps to ensure personal data is accurate and kept up-to-date where necessary.
  • Storage Limitation: Personal data will be kept in a form that permits identification of data subjects for no longer than is necessary for the purposes for which the data is processed.
  • Integrity and Confidentiality: Personal data will be processed in a manner that ensures appropriate security, including protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.
  1. Data We Collect

We may collect the following categories of personal data:

  • Identification data (e.g., name, contact details)
  • Educational and professional information (e.g., qualifications, certifications, CVs)
  • Financial data (e.g., payment information)
  • Health information (when necessary for activities such as practical training)
  • Communications and correspondence (e.g., emails or feedback)
  1. Purposes for Processing Personal Data

We collect and process your personal data for the following purposes:

  • Enrolling students in courses and managing their academic progress.
  • Communicating with clients and stakeholders about our services.
  • Complying with legal and regulatory obligations.
  • Processing payments and managing financial records.
  • Ensuring safety and health during training programs and events.
  • Conducting marketing activities, provided that consent has been obtained where necessary.
  1. Legal Basis for Processing

We rely on one or more of the following lawful grounds for processing personal data:

  • Your consent for marketing communications and any optional data processing.
  • Compliance with legal obligations, such as health and safety regulations.
  • Legitimate interests, such as improving our services or ensuring the security of our operations, provided that such interests do not override your fundamental rights.
  1. Data Sharing and Transfers

We do not sell or rent your personal data. However, we may share your personal data with trusted third parties, including:

  • Service providers who support our operations (e.g., IT, payment processors)
  • Government bodies or regulators where required by law
  • Accreditation bodies as part of certification processes

If personal data is transferred outside the European Economic Area (EEA), we will ensure adequate safeguards, such as Standard Contractual Clauses, are in place to protect your data.

  1. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, comply with legal obligations, or resolve disputes. Specific retention periods are set based on our business needs and legal requirements.

  1. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the data we hold about you.
  • Right to rectification: You can request that inaccurate or incomplete data be corrected.
  • Right to erasure: You can request that we delete your personal data under certain circumstances.
  • Right to restrict processing: You can request that we limit the processing of your data.
  • Right to data portability: You can request a copy of your personal data in a commonly used format.
  • Right to object: You can object to the processing of your data where we are relying on legitimate interests or for direct marketing purposes.
  • Right to withdraw consent: If we are processing your data based on your consent, you may withdraw that consent at any time.

To exercise these rights, don’t hesitate to get in touch with us using the details provided below.

  1. Security Measures

We implement appropriate technical and organisational measures to protect personal data from unauthorised access, disclosure, alteration, or destruction. These measures include encryption, access controls of our data protection practices.

  1. Changes to this Privacy Policy

We reserve the right to update this Privacy Policy from time to time. Any changes will be communicated on our website or by email where appropriate. Please review this policy periodically to stay informed of any updates

  1. Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data, please contact:

director@zya.com

For complaints related to data protection, you may also contact our Academy.

This policy is designed to comply with GDPR and should be reviewed periodically to ensure continued compliance.