Bluewater Training Privacy Policy

Version: v1.0-26

Last updated: 5 August 2026

1. About this Training Privacy Policy

This Privacy Policy explains how Bluewater Training processes personal data relating to:

This Policy supplements Bluewater’s general Privacy Policy. Where there is a conflict concerning training-related processing, this Training Privacy Policy takes priority.

2. Who is responsible for your personal data?

The controller is the legal entity identified as the training provider on your booking confirmation, contract or invoice.

For courses contracted through the Antibes training centre and for Bluewater e-learning services, the controller is:

Blue Water France SARL
14 Avenue Mirabeau
06600 Antibes
France

The operational Antibes training office is located at:

7 Boulevard d’Aguillon
06600 Antibes
France

For courses contracted through the Palma training centre, the controller is:

Bluewater International Yachting Services Palma S.L.
Calle San Juan 4
07012 Palma de Mallorca
Spain
CIF ES B16555203

Data protection contact

Training-related privacy questions and requests may be submitted:

Bluewater has appointed a Data Protection Officer. The Data Protection Officer may be contacted directly on any matter relating to the processing of your personal data or the exercise of your rights:

Lucia Chastel, Data Protection Officer

dpo@bluewateryachting.com

3. Personal data we collect

Depending on the course and certification requirements, we may collect the following information.

Identity and contact information

This may include your name, title, address, email address, telephone number, date and place of birth, nationality, gender where required by a relevant certification body, photograph and signature.

Photographs and images. Where a photograph is required for a certificate or student card, we process it to issue that document. We may also ask, on the registration form, whether you consent to your image being used in Bluewater course materials, publicity or social media. That use is based on your consent under Article 6(1)(a) GDPR, it is entirely optional, and you may withdraw it at any time by contacting us.

Identification documents

This may include a passport, national identity document, Seaman’s Discharge Book, visa or other document needed to verify identity, age, nationality or eligibility.

Where possible, we record only the information necessary rather than retaining a complete copy of the document.

Professional and maritime information

This may include:

Booking and account information

This may include course selections, dates, location, online-account information, booking history, attendance, correspondence, cancellations, transfers and information about an employer or yacht paying for a course.

Assessment and certification information

This may include attendance records, instructor records, examination scripts, assessment results, certificates, candidate numbers, appeals, reasonable adjustments and records of suspected malpractice or certificate fraud.

Payment information

This may include billing details, payment status, transaction references, invoices, refunds and information needed for accounting purposes.

Health, accessibility and emergency information

For courses involving practical activity or particular safety risks, we may request:

We do not require broader medical information that is not relevant to course safety, participation, accessibility or an applicable legal requirement.

Technical information

For online bookings and e-learning, we may collect IP addresses, device and browser information, login and course-progress records, assessment activity, security logs and cookie identifiers.

Communications and marketing preferences

This includes emails, enquiries, feedback, complaints, survey responses, communication choices and records of marketing consent or objections.

4. Where we obtain information

We normally obtain information directly from you.

We may also receive it from:

Where another person makes a booking for you, that person must be authorised to provide your information and should direct you to this Policy.

5. How and why we use training data

Answering enquiries and arranging bookings

We use contact, course and eligibility information to answer questions, recommend appropriate courses, check availability and take requested steps before a booking.

Legal basis: steps taken at your request before entering into a contract and our legitimate interests in responding to enquiries.

Administering your account and booking

We use identity, contact, account, booking and payment information to create an account, confirm a booking, process payment, provide materials, communicate course information and administer cancellations or transfers.

Legal basis: performance of a contract or steps taken before entering into a contract.

Where an employer or yacht contracts and pays for the course, we may rely on our legitimate interests and those of the employer in administering the booking.

Confirming identity, age and prerequisites

We use identification, qualification, sea-service and training information to confirm that you meet course, examination or certification requirements.

Legal basis: performance of a contract, compliance with applicable legal or accreditation requirements and our legitimate interests in maintaining the validity, safety and integrity of our courses.

Delivering courses and monitoring attendance

We use booking, attendance, progress and participation records to provide classroom, practical and online training.

Legal basis: performance of a contract and compliance with applicable training or accreditation requirements.

Health, safety and accessibility

We process relevant health and accessibility information to:

The applicable Article 6 legal basis may be performance of a contract, compliance with a legal obligation, protection of vital interests or our legitimate interests in delivering training safely.

Because health information is special-category data, we also require an Article 9 condition. This may be:

Where medical fitness must be verified before training, we rely on Article 9(2)(g) GDPR, substantial public interest in maritime safety, on the basis of applicable national law. In France this includes articles R. 5521-1 and following of the code des transports and the arrêté of 3 August 2017 on medical fitness standards for seafarers, which require a medical fitness examination before entry into maritime training. In Spain this includes Real Decreto 505/2024 on medical fitness examinations and health protection for embarked maritime workers, and Real Decreto 1696/2007.

The medical examination itself is carried out by an authorised doctor, who issues a fitness certificate and retains the underlying clinical record. Where we verify medical fitness, we record only that a valid certificate has been produced, the issuing doctor or authority, its reference and expiry date, and the fitness status shown on it, together with any restriction that affects how a course may be delivered to you safely. We do not require you to disclose the underlying medical condition.

Where we ask for information beyond this, for example to accommodate a dietary or accessibility requirement, we rely on your explicit consent under Article 9(2)(a) GDPR, and you may decline, subject to the paragraph below.

You may be unable to take part in a practical course where relevant safety information is not provided and we cannot safely accommodate participation.

Examinations, assessments and certification

We process identity, attendance, prerequisite, assessment and result information to conduct examinations, determine results, issue certificates, register achievements and arrange replacements.

Legal basis: performance of a contract, compliance with applicable legal or accreditation requirements and our legitimate interests in maintaining accurate and verifiable certification records.

Sharing information with awarding and maritime bodies

Where relevant to your course or examination, we may submit information to organisations such as:

The information and recipient depend on the course.

Legal basis: performance of a contract, compliance with legal or accreditation requirements and legitimate interests in obtaining and maintaining valid qualifications.

The receiving organisation may act as an independent controller and will provide or publish its own privacy information.

Verifying certificates

We may respond to a request from a maritime authority, employer, yacht, crew-placement agency or other person seeking to verify a certificate issued by Bluewater.

We will limit the response to information reasonably necessary to confirm authenticity, validity, issue details or status. Additional information will not be disclosed without an appropriate legal basis.

Legal basis: our legitimate interests, the legitimate interests of employers and maritime organisations in preventing certificate fraud, performance of a contract and compliance with legal or accreditation requirements.

Preventing malpractice and fraud

We may investigate suspected impersonation, cheating, falsified prerequisites, altered certificates or other malpractice and may report relevant information to an awarding body, maritime administration or law-enforcement authority.

Legal basis: compliance with legal obligations and our legitimate interests in protecting students, maritime safety and the integrity of qualifications.

Information concerning suspected criminal activity is processed only where authorised by applicable law.

Accounting and business administration

We use booking, payment and transaction information for accounting, taxation, auditing, insurance and business administration.

Legal basis: performance of a contract, compliance with legal obligations and our legitimate interests in administering the training business.

Course communications and marketing

We send essential course communications because they are necessary to administer your booking.

We may separately send information about other courses, events, services or offers where:

You may unsubscribe or object to marketing at any time without affecting essential course communications.

Consent to the use of tracking pixels in our emails is a separate matter from consent to receive the emails themselves. Both are explained in the Cookies and e-learning technologies section of this Policy.

Complaints, appeals and legal claims

We use relevant information to investigate complaints, administer appeals, respond to regulatory enquiries and establish, exercise or defend legal claims.

Legal basis: performance of a contract, compliance with legal or accreditation requirements and our legitimate interests in resolving disputes and protecting legal rights.

6. When information is required

Certain information may be mandatory because it is needed to:

Mandatory fields and documents will be identified during booking or registration.

If required information is not provided, we may be unable to confirm the booking, admit you to the course, register you for an examination or issue a certificate.

7. Third-party service providers and training recipients

We may disclose training-related personal data to selected third-party service providers, agents, instructors, assessors, subcontractors and associated organisations where necessary to administer a booking, deliver a course, conduct an examination, issue or verify a certificate, process a payment or provide another requested service.

These recipients may include:

Where a provider processes personal data solely on our behalf, we disclose only the information reasonably necessary to deliver the relevant service. We require the provider, through an appropriate written contract, to keep the information confidential and secure, follow our documented instructions, assist us with applicable data-protection obligations and refrain from using the information for its own direct-marketing purposes.

Certain organisations, such as awarding bodies, maritime administrations, banks, employers or examination bodies, may act as independent controllers because they determine how information must be processed for their own legal, regulatory, employment or certification purposes. Their use of personal data is governed by their own privacy notices and legal obligations.

Awarding and certification bodies act as independent controllers for the information we send them. Their own privacy notices explain how they use it. The Maritime and Coastguard Agency publishes its written assessment privacy notice here.

We will not disclose student information to third parties for their own direct-marketing purposes unless you have expressly requested or consented to the disclosure, or another lawful basis permits it in accordance with applicable marketing law.

We may disclose information where required or permitted by law, including:

Where an employer, yacht or other organisation pays for a course, we may provide information reasonably necessary to administer the booking, such as booking confirmation, attendance, completion and payment status.

We will not ordinarily disclose detailed health information, examination scripts, confidential assessment comments or unrelated personal information to the paying organisation unless the disclosure is necessary, expected, legally required and supported by an appropriate legal basis.

Where information is transferred internationally, the safeguards described in the International Transfers section of this Policy apply.

We do not sell or rent student personal data.

8. International transfers

Some examination bodies, awarding organisations, technology providers, Bluewater offices or employers may be located outside the European Economic Area or the United Kingdom.

Restricted international transfers are protected using an applicable mechanism such as:

Additional technical, contractual or organisational safeguards are used where required.

You may contact us for information about the safeguard relevant to a particular transfer.

9. Retention of training information

We retain training information according to the type of course, certification rules, legal requirements and the need to verify qualifications.

Our intended retention periods are:

Only the minimum information needed for a long-term certification record should be retained. Information is deleted or anonymised when the applicable period ends, unless it is subject to a legal hold.

10. Cookies and e-learning technologies

A cookie is a small text file placed on your computer, mobile device or other device when you visit a website or use an online learning service. Cookies and similar technologies allow websites and applications to recognise a device, maintain a secure session, remember preferences and record information needed to provide online services.

Our booking and e-learning platforms may use cookies and similar technologies for:

Strictly necessary technologies may be used without consent where permitted by law because they are required to provide a service requested by you or to operate the platform securely.

Subject to your consent where required, we may use traffic-log and analytics cookies to identify which pages and course functions are being used. This helps us analyse general usage patterns, improve website and learning-platform performance and tailor our services to student and customer needs.

Analytics information is used for statistical and service-improvement purposes. Where possible, it is aggregated, truncated, pseudonymised or otherwise limited. It is retained only for the period stated in our Cookie Policy or consent-management tool and is then deleted or anonymised, unless a longer period is required for security, certification, legal or regulatory purposes.

When you first use the relevant website or platform, you will be given the opportunity to accept, reject or manage non-essential cookies. Non-essential cookies will not be activated before the required consent has been obtained.

You may withdraw or change your choices at any time through the Consent Preferences button displayed on our website.

Most web browsers allow you to block or delete cookies through their settings. Blocking certain cookies may prevent account, booking, assessment or e-learning functions from operating correctly.

A cookie does not, by itself, give us unrestricted access to your computer or device. It permits access only to information stored within that cookie or otherwise made available through your browser, device or interaction with the platform.

Further details about the technologies we use, their providers, purposes and retention periods are available in our Cookie Policy, published within Bluewater’s Privacy Policy.

Tracking in our emails

Our marketing and course-promotion emails contain a small, invisible image known as a tracking pixel, and links that pass through a redirect before reaching their destination. When your email software displays the message, or when you click a link, these cause your device to send information back to us or to our email provider. This is a read or write operation on your device and is treated in the same way as a cookie.

Depending on the purpose, this may tell us:

Where we ask for your consent. We use tracking pixels to know whether you open our emails, the time at which you do so and information about the device you use, so that we can measure and improve the performance of our campaigns, personalise the content of our messages and adapt how often and through which channel we contact you. We also use them to identify unusual or automated opening patterns that may indicate fraud.

Where your consent is not required. We use a limited form of open measurement to manage our mailing lists, in order to identify delivery problems and to reduce or stop sending messages to recipients who no longer open them. For this purpose we retain only the date, without the time, of the last known opening, updated on each occasion and replacing the previous record. We describe this here for transparency, although your consent is not required for it.

Consent to tracking is separate from consent to receive the message. We may need your consent for a tracking pixel even in emails that we are entitled to send you without your consent, such as a booking confirmation or information about services similar to those you have already obtained from us.

How we ask for your choice. We ask for your choice at the point where you give us your email address, for example on our sign-up form, when you create a Bluewater account, or when you make an enquiry or a booking. Where we have not been able to do so, we may send you a message containing no consent-requiring tracking that invites you to make your choice. Refusing is as straightforward as accepting. We record your choice so that you are not asked again for at least six months, and we treat a lack of response as a refusal.

How to withdraw your consent. You may withdraw your consent at any time using the link in the footer of every marketing email. The page it opens allows you to change your choice without having to enter your email address again. Withdrawal applies to all future messages, and we take appropriate measures so that tracking contained in messages already sent to you is no longer used.

Who sends our emails. Our marketing emails are sent using Mailchimp, a service provided by Intuit Inc., acting on our documented instructions. Transfers outside the European Economic Area are covered by the safeguards described in the International transfers section of this Policy.

Mailchimp acts as our processor for these operations under a data processing agreement. Transfers to the United States are covered by Intuit’s certification under the EU-U.S. Data Privacy Framework, with the European Commission’s standard contractual clauses applying as a fallback.

11. Automated decision-making

We do not normally use solely automated decision-making to determine course admission, examination results, certification or disciplinary outcomes.

Digital systems may automatically mark limited objective assessments or identify activity for review, but a qualified person will be involved where the outcome could have a legal or similarly significant effect.

We will provide additional information and safeguards before introducing any qualifying solely automated decision.

12. Students aged under 18

Some courses accept students aged 16 or 17 where the applicable course and accreditation rules permit.

We may require a parent or guardian to:

We will not rely on a child’s consent for an online service without applying the age and parental-authorisation rules of the relevant country.

13. Your rights

Subject to applicable conditions and exemptions, you may have the right to:

A request may be sent to training@bluewateryachting.com or info@bluewateryachting.com.

We may request reasonable proof of identity. We normally respond within one month after receiving a valid request and any necessary verification. This period may be extended by up to two additional months where permitted because a request is complex or numerous.

Some records cannot be deleted immediately where they are needed to maintain a valid certification record, comply with an awarding-body requirement, meet a legal obligation or establish, exercise or defend legal claims.

14. Privacy complaints

Privacy complaints may be submitted to info@bluewateryachting.com.

We will acknowledge a privacy complaint within 30 days, take appropriate steps to investigate it, keep you appropriately informed and communicate the outcome without undue delay.

You may also complain to the supervisory authority in the country where you live or work or where you believe an infringement occurred. Relevant authorities may include the Commission Nationale de l’Informatique et des Libertés in France, the Agencia Española de Protección de Datos in Spain or the Information Commissioner’s Office where UK data-protection law applies.

15. Security of training information

We are committed to protecting training-related personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, misuse or access.

We maintain physical, electronic, technical and organisational safeguards appropriate to the nature and sensitivity of the information being processed.

Training information that may require enhanced protection includes:

Depending on the relevant system and risk, our safeguards may include:

Personal data is stored on systems protected by technical and organisational safeguards. Relevant systems are backed up regularly in accordance with operational, certification and business-continuity requirements.

Our controls are designed with reference to recognised information-security and quality-assurance practices.

Access to health information, identification documents, examination material and certification records is limited to individuals who require access for an authorised training, safety, examination, legal or administrative purpose.

Where information must be provided to an instructor for health or safety reasons, we disclose only the information reasonably necessary for safe course delivery.

No method of electronic transmission or storage can be guaranteed to be completely secure. Students should keep account credentials confidential and inform us promptly of suspected unauthorised access, suspicious communications or accidental disclosure.

16. Changes to this Policy

We review this Policy regularly and update it when our training activities, accreditation requirements, technology or legal obligations change.

Material changes will be communicated through an appropriate channel. The date at the top shows when this Policy was last updated.

Click here to read the Bluewater Privacy Policy, including our Cookie Policy