Privacy policy
Version 2026-09-28. The Polish version of this policy prevails.
This policy explains what personal data DiveTheory processes, why, and what rights you have. DiveTheory is an online service that helps diving instructors teach the theory part of their courses. It does not certify divers.
1. Who we are
DiveTheory is run by Bartlomiej Zubrzycki IT Services, Warszawa, NIP 9512298102 ("we", "the operator").
For anything about your data, write to divetheory@nopressurediving.com.
2. Two roles: instructors and students
- Instructors. For an instructor's own account (email, password, school name) we are the controller: we decide why and how that data is processed.
- Students. Student accounts are created by an instructor or school, who is the controller of the students' data: the school decides whom to enrol and what to do with the results. We process that data on the school's behalf as its processor, under the data processing agreement that every instructor accepts when registering. If you are a student, your instructor is your first point of contact for questions about your data; you can also write to us and we will pass your request on and help the instructor answer it.
3. What data we process
Instructors:
- email address and password (stored only as a salted hash that cannot be turned back into the password);
- the name of the school or organisation;
- when you accepted the terms, and which version;
- what you do in the service: students you add, courses you assign, remediation tasks, assessments, and training records.
Students (on behalf of their school):
- first name, last name, and email address, entered by the instructor;
- the courses assigned and the language chosen for each;
- progress through lessons, answers to quizzes and exams, scores, and the topics the results show as weak;
- remediation tasks, the instructor's assessments and notes, and training records;
- when you accepted the terms, and which version.
Everyone:
- technical data needed to run the service safely: IP address, browser type, the time and address of requests, and failed sign-in attempts. The app uses the IP address only in memory to limit repeated form submissions; the server and Cloudflare (see section 6) keep it in their logs for a short time.
- error reports (see section 6, Sentry): the page where an error happened and technical details. They do not contain IP addresses, cookies, or account details.
We do not ask for health data. Instructors must not enter it (for example medical questionnaire answers) in the service.
4. Why we process it, and on what legal basis
For instructors' data, where we are the controller:
- to create and run your account and provide the service under the terms: Article 6(1)(b) GDPR (performance of a contract);
- to keep the service secure, prevent abuse, and find and fix errors: Article 6(1)(f) GDPR (our legitimate interest in a safe, working service);
- to answer your messages and requests, and to establish or defend legal claims: Article 6(1)(f) GDPR;
- to meet legal obligations, for example keeping records of how we handled a data request: Article 6(1)(c) GDPR.
For students' data we act on the school's instructions. The school's legal basis is usually the contract for the diving course (Article 6(1)(b) GDPR) or its legitimate interest in teaching and documenting the training (Article 6(1)(f) GDPR).
5. Automatic analysis of results
The service scores quizzes and exams automatically and shows the instructor which topics a student found hard. This supports the instructor's teaching. Decisions about a student's readiness and any certification are made by the instructor, not by the service.
6. Who receives the data
We use these providers, each bound by a data processing agreement:
- Hetzner Online GmbH, Germany: the server that runs the service and stores the database, in the European Union.
- Cloudflare, Inc., USA: the domain's DNS, the secure connection, protection against attacks, and storage of database backups. All traffic to the service passes through Cloudflare.
- Sendinblue SAS (Brevo), France: sending the service's emails (invitations, account confirmation, password reset). It receives the recipient's address and the email's content.
- Functional Software, Inc. (Sentry), USA: error reports, stored in its European Union data region.
Where a provider is based in the USA, data is transferred on the basis of the EU–US Data Privacy Framework or the European Commission's standard contractual clauses (Articles 45–46 GDPR).
A student's data is visible to the instructors of the student's school. We do not sell data and do not use it for advertising. We disclose it to public authorities only when the law requires.
7. How long we keep it
- Account data: while the account exists. After a request to delete it, within one month. Database backups that still contain it are overwritten within a further 30 days.
- Students' data: as long as the school keeps it in the service, and deleted when the school asks or when the school's account is closed (see the data processing agreement).
- Server and Cloudflare logs: at most 30 days.
- Error reports in Sentry: at most 90 days.
- Emails: Brevo keeps delivery logs for a limited time set by Brevo.
- Records of data requests and how we handled them: up to 3 years, to be able to show we handled them correctly.
8. Your rights
You have the right to:
- access your data and get a copy of it (Article 15 GDPR);
- have it corrected (Article 16);
- have it deleted (Article 17);
- restrict its processing (Article 18);
- receive it in a machine-readable format (Article 20);
- object to processing based on our legitimate interest (Article 21).
On the account page you can download your account details at any time. For a full copy that includes courses and results, for deletion, or for any other request, write to divetheory@nopressurediving.com from the address you sign in with. Students can also ask their instructor. We answer within one month.
You can also lodge a complaint with the Polish data protection authority: Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa (uodo.gov.pl), or with the authority in the EU country where you live or work.
Giving your data is voluntary, but without an email address and a password we cannot create an account, and without the details the instructor enters the school cannot use the service for your course.
9. Minors
Diving courses are open to children and teenagers. When a student is under 18, the school makes sure that a parent or legal guardian has agreed to the student using DiveTheory. The parent or guardian can exercise the student's rights described above.
10. Cookies
The service uses only cookies it needs to work, so it does not ask for consent to them:
.AspNetCore.Identity.Application: keeps you signed in; deleted when you sign out or close the browser, or after 14 days if you choose "Remember me";.AspNetCore.Antiforgery.*: protects forms against being submitted from other websites; for the browser session;Identity.StatusMessage: shows a one-time message after an action, such as "Your account is ready"; deleted once shown;.AspNetCore.Culture: remembers the interface language (Polish or English) when you choose one with the PL/EN switch; set only then, for one year;- Cloudflare may set technical cookies such as
__cf_bmto tell people from automated attacks.
We use no analytics, advertising, or tracking cookies, and pages load no third-party scripts or fonts.
11. Security
Connections are encrypted (HTTPS). Passwords are stored only as hashes. The database cannot be reached from the internet. Each school sees only its own students. Repeated failed sign-ins lock the account for a short time. Backups are made daily and a restore is tested.
12. Changes to this policy
When this policy changes in substance, we will tell users by email or in the service before the change takes effect. The version date is at the top.