Diving Club logoDiving Club
Diving Club · Trincomalee

Privacy policy

We ask for what we need to run your dive safely, and nothing else. We don't sell your details to anybody.

Last updated: 7 August 2026

What we collect

When you book or message us, you give us:

  • Your name, email address and phone number
  • Your nationality or country, so we know which paperwork applies
  • The date you want, how many of you there are, and what you want to do
  • Your diving certification level, and anything you write in the notes box

Before your first dive we also take a medical questionnaire. That's health information, we treat it as the sensitive thing it is, and only the instructors taking you in the water see it.

We never see your card details. Card payments go straight to our payment gateway, who handle them under their own security standards. What comes back to us is whether the payment worked and for how much.

Why we need it

  • To confirm your booking and reach you if the boat time or the weather changes
  • To dive with you safely, and to meet PADI's standards for training records
  • To take payment and issue refunds
  • To keep the records Sri Lankan law requires us to keep

If you're taking a PADI course, some of your details go to PADI to issue your certification — that's the certification card itself, so it can't be opted out of and still get you certified.

Cookies and the tools on this site

This site uses Google Tag Manager and Google Ads to understand which pages and adverts actually lead to bookings, and Ahrefs Analytics for basic visitor numbers. Between them they set cookies and store a small record in your browser of which advert you arrived from, kept for up to 90 days.

When a booking comes in from an advert, we send Google a scrambled (hashed)version of your email and phone number so it can match the booking to the click. Google receives the scrambled values, not the readable ones. You can turn all of this off with your browser's cookie settings or an ad blocker, and the site will still work normally.

Who else sees your details

Only the people who have to:

  • Our payment gateway, to take the payment
  • PADI, for course certifications
  • Google, for the advert measurement described above
  • A hospital or the coastguard, if there's a medical emergency

That's the whole list. We don't sell your details, rent them, or hand them to marketers.

How long we keep it

Booking and payment records: seven years, because tax rules say so. Training and medical records: as long as PADI requires for your certification. Enquiries that never became a booking: two years, then deleted. Ad-click records expire on their own after 90 days.

Your say over it

Email info@divingclub.lkand you can ask us for a copy of what we hold, ask us to fix anything wrong, or ask us to delete it. We'll come back to you within 30 days. The one thing we can't delete early is a record the law or PADI requires us to keep — we'll tell you plainly if that applies.

We'll only email you about your own booking. We don't run a marketing list.

Keeping it safe

The site runs over an encrypted connection, bookings live in an access-controlled admin only our staff can reach, and paper medical forms are locked up at the centre. No system is perfect, but nothing sits where it shouldn't.

Children

Under-18s dive with us only with a parent or guardian's signature, and we take a young diver's details from that adult, not from the child.

Changes, and how to reach us

If we change this policy we'll update the date at the top. Questions about any of it: Diving Club, 74/9 Sandy Cove, Trincomalee 31000, Sri Lanka · 074 394 5010 · info@divingclub.lk. See also our terms and refund policy.

Chat with us