Privacy policy
Last updated: 10 September 2026 · Version 2.0
Sønder Bjergevej 138, 4261 Dalmose, Denmark
Responsible for data protection: Sebastian Krogh Melgaard
kontakt@beyondvision.dk · +45 93 87 02 76
This is a translation. The Danish version is the legally binding text. If the two differ, the Danish wording prevails.
01. In short
We collect only what it takes to make the systems work. We do not sell data, we do not trade it, and we do not use it to build a profile of you.
The short version: beyondvision.dk sets no cookies. OSIS processes participant data on behalf of the school, club or organiser you are registered with — they are the ones in charge. Sailing Log stores your account, your voyages and your position, and you can delete all of it yourself inside the app.
Your profile and your logbook in Sailing Log cannot be read without logging in. Until 10 September 2026 they could be. How that happened, and what we did about it, is in section 08.
02. Who is responsible
It depends which part of us you are dealing with.
- We are the data controller for beyondvision.dk, for enquiries sent to us, for our customer records, for applications through the careers page — and for user accounts in Sailing Log, where we determine the purpose.
- We are a data processor when a boarding school, club or organiser uses OSIS to process information about their students, members or participants. There they are the data controller, and we act only on their instructions. So if you are a competitor at an event, the organiser is who you should approach — but do write to us and we will point you to the right place.
A data processing agreement is in place with every customer using OSIS commercially. The framework is set out in Legal, section 05.
03. The website & cookies
beyondvision.dk sets no cookies. No analytics cookies, no marketing pixels, no Meta Pixel, no Google Analytics. We have checked: there are no cookies in your browser after a visit, and no measurement data about you is passed on.
We do not use information from your visit for advertising either, and we do not resell it.
Google Tag Manager
We should be precise about one thing, though: the site loads Google Tag Manager. That is a container for managing measurement scripts — not an analytics tool in itself. There are currently no active analytics or marketing tags in the container, and as noted, no cookies are set.
But when the script is fetched, your browser contacts Google's servers, and your IP address is technically visible to Google at that moment. We think you should know that, even though nothing is being measured.
If we ever do switch measurement on, a consent solution will go on the site first, and this policy will be updated before it happens. We will not start measuring you quietly.
Technical logging on the server
Our web server keeps — as essentially every web server does — a log of requests: IP address, time, which page was fetched, status code and browser type. It is used for operations, debugging and blocking attacks. The logs are not used to follow individuals, and they are deleted on a rolling basis.
Local storage in your browser
We store one thing locally in your browser: your choice of light or dark theme. It is not a cookie, it is never sent to us, and it cannot be used to recognise you.
Content from others
- Google Fonts — the typefaces are fetched from Google's servers, which makes your IP address visible to Google.
- Google Calendar — the "book a meeting" button leads to Google's own booking page, where Google's terms and cookies apply.
- Google Maps — maps on individual pages are loaded from Google.
- The App Store and Google Play — links to the app lead off our site.
If you click through to LinkedIn, Instagram, Facebook or elsewhere, their policies apply, not ours.
04. When you write to us
If you write through the contact form, send an email or call, we process your name, email, phone number, any club name, and whatever you write in the message.
- We use it to answer you and to follow up.
- If it becomes a customer relationship, the correspondence is kept as part of the file.
- If it does not come to anything, we delete the enquiry after 12 months.
- Do not put civil registration numbers, health information or passwords in an ordinary email to us. If you need to send something confidential, call us and we will find a secure route.
If you book a meeting through the calendar link, the booking itself takes place at Google, on their terms.
05. Project OSIS
Here we process information on behalf of the customer you are registered with. What is actually collected is the customer's decision — below is what the system is capable of handling.
| Module | Typical data |
|---|---|
| Camp Suite | Name, date of birth, contact details, next of kin, group and room allocation, registrations, activity choices, presence at the lights-out round — and, at the customer's choice, allergies, medication and special needs. |
| Competition Suite | Competitor name, club, category, start number, marks, points, times and placings. Judges' entries with a timestamp. |
| LiveSync | The names and results shown on the big screen and in the stream. No collection of its own. |
| Digital Signage | No personal data as a rule — but the customer's own content may contain names, photos and schedules. |
| NFC DMS | A card or wristband id linked to a participant, the time of check-in and check-out, and which zones or equipment access was granted to. |
| Payment Suite | Time, amount, line items and payment reference. Never full card details — those are handled exclusively by SumUp. |
The data is used to run the event: registration, group allocation, access, safety, results and settlement. It is not used for anything else, it is not combined with data from other customers, and it is not sold.
06. Sensitive data & children
Health, allergies and medication
Camp Suite may hold information about allergies, medication and health. That is sensitive personal data under article 9 of the GDPR, and it is treated accordingly:
- It is only visible to the authorised instructor and management team the customer has given access.
- It is never shown to other participants, never on information screens and never in exports to third parties.
- It is deleted no later than 30 days after the event ends.
- The basis for processing — typically parental consent, or the vital interests of the participant — is obtained by the customer, not by us.
Children and young people
A large share of our users are under 18. In Denmark the age at which someone can consent to an online service on their own is 13; for younger children the holder of parental responsibility must give or approve the consent.
If the account was created centrally by a school or club, the institution is responsible for the basis of processing and for informing parents. So if you are a parent and want to know what is held about your child, ask the school or the club — they have access to all of it, and we are happy to help them answer.
07. Photos & video
Our systems can show photos and video on information screens, the big screen and in a livestream — and recordings may afterwards appear on the customer's social media.
- It is the organiser or the school who obtains consent and is responsible for having it in place. For minors, the parents must agree.
- Consent can always be withdrawn. The material must then be taken down at the first opportunity. A livestream that has already gone out cannot be unseen, but the recording can be removed.
- Situational photographs from a public event may in some cases be shown without consent — but that judgement rests with the organiser, and we always recommend asking.
- If you do not want to be filmed, tell the organiser before things start. They can flag it in the system.
08. Sailing Log
For Sailing Log to work as a logbook and planning tool, the app processes:
- Precise location (GPS): Your position and your routes are recorded, so voyages can be saved in the logbook and shown on the map.
- Account details: Your email address is used to create your account and to log in.
- Profile and boat details: Skipper name, boat name, boat model, length and chosen home port.
- Social connections: Your friend relationships in the app, and who you have chosen to share your logbook with.
- Technical: device type and app version, so we can debug.
Data is stored so you can reach your voyage history across devices.
Sharing with other users: Sailing Log is a social fleet app. Your live position, your boat name and your skipper name can be shown to other users on the fleet map. By default your boat is publicly visible to all users, but you can change the visibility to friends only at any time in the app's settings, or turn position sharing off entirely.
Live positions can currently be read by any user who is logged in to the app. The choice between everyone and friends only is enforced in the app itself — it determines what other users are shown. If you want to be certain your position is not available at all, turn position sharing off completely.
About your logbook and your boat profile — fixed on 10 September 2026. Up to that date, your boat profile and your saved voyages could be read through the app's database without being logged in. The reason was that the leaderboard and the statistics on beyondvision.dk worked their numbers out by fetching every user and every voyage directly — and for that to be possible without a login, the database was left open for reading.
That is now closed. Profiles, logbooks, positions and boat lists require a login, and logbooks can only be read by you and by those you have explicitly shared them with. The website instead fetches a small public extract containing only the boat name, the number of voyages and a total nautical mileage — no email, no phone number, no positions and no individual voyages.
We are leaving this description in place even though the fault is fixed, because it was here, and because we would rather say so than pretend otherwise. There is nothing to suggest the data was fetched by outsiders — but we cannot rule it out for the period up to 10 September 2026. If you wrote something in your logbook notes during that period that you would not have wanted to share, do write to us and we will look at it together.
We use Google Firebase (Authentication, Firestore and Realtime Database) for login and storage, and Google Maps to display maps. They act as our data processors. Weather data is fetched from an external provider based on the area you are looking at — not on your identity. We never sell your data to advertisers or other third parties.
Delete it all yourself
You can permanently delete your account and all associated data at any time from within the app's settings — in line with the guidelines for both the App Store and Google Play. The deletion covers your profile, voyages, positions and friend relationships.
09. Legal basis
We only process data where there is a legal basis for it. Here is which:
| Purpose | Basis |
|---|---|
| Providing Sailing Log to you as a user | Performance of a contract — article 6(1)(b) |
| Showing your position to other users | Consent, which you control in the app — article 6(1)(a) |
| Answering your enquiry | Legitimate interest in being able to reply — article 6(1)(f) |
| Running and securing our systems, debugging, blocking attacks | Legitimate interest — article 6(1)(f) |
| Processing participant data in OSIS | The customer's basis. We act on instructions — article 28 |
| Health data in Camp Suite | The customer's consent or vital interests — article 9(2)(a) or (c) |
| Bookkeeping of sales and invoices | Legal obligation, the Danish Bookkeeping Act — article 6(1)(c) |
| Processing an application from the careers page | Your consent — article 6(1)(a) |
| Newsletter to business customers | Consent under the Danish Marketing Practices Act — article 6(1)(a) |
Where the basis is consent, you can always withdraw it. That does not affect the lawfulness of what happened before you did.
10. Who receives the data
We do not sell, rent or trade personal data. It is shared only with those necessary to run the service:
| Recipient | What they do | Where |
|---|---|---|
| Google Ireland Ltd. (Firebase) | Login, database and file storage for Sailing Log and parts of OSIS | EU (europe-west1) |
| Google Ireland Ltd. (Maps, Fonts, Tag Manager) | Maps, typefaces and the tag container on the website | EU/global CDN |
| SumUp | Payment acquiring in Payment Suite. Receives card data directly — we never see it | EU |
| Our hosting provider | Operation of beyondvision.dk and its APIs | EU |
| Our email provider | Sending and receiving email on @beyondvision.dk | EU |
| Apple / Google Play | Distribution of the app plus purchases and subscriptions | Their own terms |
Data may also be disclosed if an authority or a court requires it. If that happens, we tell the person affected, unless we are prohibited from doing so.
If you are taking part in an event, the organiser naturally has access too — it is their system, and they are the data controller.
If we change or add a sub-processor, customers are given at least 30 days' notice. See Legal, section 05.
11. Server location
All data processed by Beyond Vision and our systems sits on servers physically located within the EU/EEA. Sailing Log's data is hosted with Google Firebase in the EU (europe-west1).
Should a transfer to a third country exceptionally become necessary — for example support from a provider outside the EU — it takes place only on the basis of the European Commission's standard contractual clauses (SCCs), supplemented by a specific risk assessment.
All communication between app, screen and server is encrypted in transit with HTTPS/TLS.
12. How long we keep it
We do not keep data longer than the purpose requires. The periods here are the same as in Legal, section 05:
| Type | Deleted |
|---|---|
| Event data in OSIS (registrations, groups, results) | No later than 12 months after the event |
| Health data in Camp Suite | No later than 30 days after the event |
| Access and check-in logs (NFC) | No later than 90 days after the event |
| Sailing Log account, voyages and positions | When you delete the account yourself in the app |
| Enquiries that do not come to anything | After 12 months |
| Applications through the careers page | After 12 months, or whenever you ask |
| Customer and contract documents | 5 years after the end of the relationship |
| Bookkeeping and transaction data | 5 years plus the current financial year (the Danish Bookkeeping Act) |
| Server logs | On a rolling basis, no later than 90 days |
| Backups | Rotate and are overwritten no later than 90 days |
That also means a deletion may sit in a backup a little longer, until that backup expires. We never restore deleted data from a backup without good reason.
13. Security
- All traffic is encrypted with HTTPS/TLS, and data is encrypted at rest with our infrastructure providers.
- Access is granted on a least-privilege basis and is personal. Administrator access is protected with two-factor authentication.
- Access to production data is logged and reviewed if misuse is suspected.
- Backups are taken continuously, and restoration is tested.
- Everyone with access — including helpers and volunteers at events — is bound by confidentiality and signs a confidentiality agreement.
- Devices used for development and operations are disk-encrypted and passcode-locked.
If something does go wrong: If we identify a personal data breach, we notify the controlling customer without undue delay and no later than 24 hours after we become aware of it. If we are the controller ourselves and there is a high risk to you, you are told directly — and we report to the Danish Data Protection Agency within 72 hours.
If you have found a security hole, we would very much like to hear about it. The procedure is under Responsible Disclosure.
14. Applications
If you apply to join through the careers page, we process what you write yourself: name, email, any phone number, age and where you live, what you would like to do, how much time you have, any links you send, and your two free-text answers.
- The basis is your consent, which you give by ticking the box in the form.
- The application is read by the owner. It is not shared with anyone else and is not used for anything other than assessing your enquiry.
- We keep it for up to 12 months, so we can come back to you if something turns up that fits. If you want it deleted sooner, just write to sebastian@beyondvision.dk and it is gone.
- Do not put a civil registration number, health information or anything else sensitive in the application. We do not need it.
- If you are under 18, your parents need to agree before we take it further.
15. Your rights
Under the GDPR you have the right to:
- Access — to be told what data we hold about you, and get a copy.
- Rectification — to have anything incorrect put right.
- Erasure — to be forgotten, where we are not obliged to keep the data.
- Restriction — to have processing paused while a disagreement is resolved.
- Data portability — to receive your data in a machine-readable format.
- Objection — to object to processing based on legitimate interest.
- Withdrawal of consent — at any time, at no cost.
How to do it
- Sailing Log: most of it you can handle yourself inside the app — edit your profile, or delete the account and everything with it.
- OSIS: contact your school, club or organiser. They are the data controller and hold the access. We will help them answer.
- Everything else: write to kontakt@beyondvision.dk or through the contact page.
We reply within one month. If the matter is complicated, we can extend that by two months — and we will tell you along the way. We may ask you to identify yourself if we are unsure who you are; that is for your own protection.
16. Complaints & changes
Complaints
If you are unhappy with how we handle your data, please write to us first — we will put it right if we can. You always have the right to complain to:
Datatilsynet (the Danish Data Protection Agency)
Carl Jacobsens Vej 35, 2500 Valby, Denmark
Phone +45 33 19 32 00 · datatilsynet.dk
Changes to this policy
We update the policy when the systems or the law change. The date at the top shows when it was last amended. Material changes are notified to active customers by email at least 30 days in advance, and to Sailing Log users through a message in the app.
Version 2.0 — 10 September 2026. Expanded from 6 to 16 sections: clarification about Google Tag Manager and server logs, an overview per OSIS module, legal bases, recipients and sub-processors, retention periods, data breaches, applications through the careers page, plus rights and how to complain.
Version 1.0 — August 2026. First edition.
See also Legal, Terms of use and Sales and refunds.