← oceanops.co

Privacy and legal

Ocean Ops · a service provided by Quolo OÜ

Last updated 17 August 2026

Ocean Ops helps dive and marine tour operators handle guest enquiries and bookings over WhatsApp. This page explains how we handle information, which companies help us run the service, and the terms we provide it under.

Privacy notice

Who we are

Ocean Ops is provided by Quolo OÜ, registered in Estonia under registry code 16530266, at Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond 15551, Estonia.

Ocean Ops is the name of the service. Quolo OÜ is the company that provides it and the company you contract with.

Who this notice is for

This covers people who visit this website and operators who use the Ocean Ops app.

If you messaged a dive shop on WhatsApp and want to know about your own information, ask the dive shop. They decide what your messages are used for — we handle them on their instructions only — so they are the right people to give you a copy of your data or delete it. Their own privacy notice covers your conversation. Not sure who to contact? Email privacy@oceanops.co and we will point you to the right operator.

What we collect, and why

When a business uses Ocean Ops we hold the names, email addresses and roles of the people who log in, so we can run their account, and a scrambled version of their password so we can sign them in. We keep that for as long as the account is active.

We also record which features are used and when, so we can understand what works and fix what does not, and we record software faults so they can be diagnosed.

Most of this we need in order to provide the service a customer has asked for. The rest — understanding how the product is used, keeping it secure — rests on our legitimate interest in running and improving it. You can object to that; see your choices below.

Analytics and cookies

We use PostHog to understand how operators use the product. It is hosted in the European Union and records which features are used rather than who is using them: accounts appear as numbers rather than names, and where a session is recorded to diagnose a fault, all text and everything typed is hidden before it is saved. Guest names, phone numbers and message content are never sent to it.

This applies only to people signed into the operator console. Dive shop guests never load this app. PostHog sets cookies in the operator's browser to recognise a returning session, and you can block or delete these in your browser settings at any time without affecting how the product works.

This website itself sets no cookies and runs no analytics. Nothing is stored on your device by visiting these pages, and we do not track visitors here.

We do not use advertising cookies, and we do not sell or share information with advertisers.

Guest conversations

Everything about guest conversations — what we do with them, how long we keep them, and the AI that drafts replies — is in the data processing terms below.

Your choices

You can ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it, ask us to stop or limit how we use it, or ask for it in a portable format. Email privacy@oceanops.co and we will respond within 30 days.

If you are a dive shop's guest, your request goes to the dive shop — see the note above — and we will help them answer it.

If something does not seem right

Tell us first — email privacy@oceanops.co and we will do our best to put it right quickly. You also have the right to raise it with a data protection regulator at any time: ours is the Estonian Data Protection Inspectorate (aki.ee), or you can go to the authority where you live.


Who processes data for us

We use a small number of other companies to run Ocean Ops. Each one is listed below with what it receives, where it is, and how long it keeps anything. This is the same list that forms part of the agreement each operator has with us.

Companies that handle guest information

OpenAI, L.L.C.

Drafts replies and sorts enquiries

Receives
The text of guest messages and the conversation so far
Where
United States
Legal safeguard
EU–US Data Privacy Framework, with Standard Contractual Clauses in their agreement as an additional safeguard
Retention
Up to 30 days to monitor for misuse, then deleted. Never used to train their models

WADA BV, trading as Dualhook

Delivers our outgoing WhatsApp messages

Receives
Outgoing message content and media, while in transit only — not stored, cached or written to logs. Guest messages coming in do not pass through Dualhook at all; WhatsApp delivers those straight to us
Where
No single committed region. Their delivery network is global and they do not undertake to keep data in one country. The company is registered in Antwerp, Belgium, which is where the business is rather than where the processing happens
Legal safeguard
Their published agreement, which forms part of their terms and includes the Standard Contractual Clauses for processor-to-processor transfers
Retention
Message content is not kept. Delivery records and phone status history are kept for 30 days

DigitalOcean, LLC

Hosts the application, the database and file storage

Receives
Everything the service stores, including message content and the fault records described in the data processing terms below
Where
Database in New York, United States. Guest photos, voice notes and documents in Amsterdam, Netherlands
Legal safeguard
Their agreement, accepted with their terms of service, which includes the Standard Contractual Clauses and the UK Addendum
Retention
For as long as the account is open. Daily backups, with recovery covering the previous 7 days

Companies that handle operator information only

PostHog

Shows us how operators use the product

Receives
Which features are used, under a number rather than a name. Session recordings have all text and inputs hidden. No guest names, phone numbers or message content
Where
European Union

What is not on this list

WhatsApp and Meta. Meta runs WhatsApp itself, and every operator has their own direct relationship with Meta for their business number — so Meta does not act for us.

Other AI providers. OpenAI is the only AI provider that receives anything. No other AI company holds credentials in the service.

When this list changes

We give every operator at least 30 days' written notice by email before a new company starts handling guest information, or before one of the above materially changes what it does. An operator who objects on reasonable data-protection grounds can raise it with us, and if we cannot resolve it they can stop using the affected part of the service without penalty.

The only exception is where a supplier's own terms, or an urgent security or availability problem, force shorter notice. In that case we tell operators as soon as we reasonably can.

Version history

DateWhat changed
17 August 2026First published.

Terms of service

These terms apply to businesses using Ocean Ops. By using the service you agree to them.

What Ocean Ops does

An inbox for your guest conversations, an assistant that can draft or send replies outside your working hours, booking capture, weather and rescheduling messages, and a dashboard showing your enquiries and bookings.

An early-stage service

Ocean Ops is a young product, developed closely with the operators who use it. Features will change, sometimes without notice. Things will occasionally break and we will fix them. We do not yet offer an availability guarantee or a guaranteed support response time. If you need a service with formal availability commitments, Ocean Ops is not the right choice yet, and we would rather say so now.

Your account

You are responsible for keeping your login details secure and for what the people you give access to do with the account. Tell us promptly if you think someone has gained access who should not have. You need your own WhatsApp Business account to use Ocean Ops; Meta's terms apply to that separately and we cannot accept them on your behalf.

The assistant

You remain responsible for what your business tells its guests. You can switch the assistant off, pause it for a single conversation, or take over at any time.

Guests are told when a reply is automated — the data processing terms below cover that notice and why it stays in place.

The assistant provides information and takes bookings. It does not decide whether a guest is medically fit to dive. Those decisions are yours.

Fees

Your fees, and any free period, are agreed with you in writing before any charge applies — nothing is ever owed that we have not agreed first. There is no automatic renewal and no card on file: if an agreed period ends and we have not agreed what comes next, the service simply stops rather than starting to charge you.

Your data and your guests' data

You remain in control of your guests' information. We handle it on your instructions only, and the detail is in the data processing terms below, which form part of these terms. We do not use guest conversations to train AI models, and we do not sell anyone's data.

What we ask of you

Do not use Ocean Ops to send unsolicited marketing, to break Meta's WhatsApp terms, or to do anything unlawful, and do not attempt to access other operators' data. If you do, we may suspend the account — we will tell you why and give you a chance to put it right where that is reasonable.

Stopping

During any free period, either of us can stop at any time by saying so in writing, and nothing is owed. On paid terms, either of us can end the service on 30 days' written notice.

Whenever it ends you can ask us for a copy of your data, and we will provide it within 14 days.

Limits on our liability

We provide Ocean Ops with reasonable care and skill, but we cannot promise it will be uninterrupted or error-free. We are not liable for lost profits, lost bookings, or losses caused by circumstances outside our reasonable control, including Meta suspending or restricting your WhatsApp account for reasons unconnected with our service. Our total liability to you is limited to the fees you have paid us in the twelve months before the claim, or €1,000 where no fees have been paid.

Nothing here limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.

If you have a separate written agreement with us

Some operators have their own written agreement with us setting their commercial terms. Where it differs from these terms, that agreement governs. These terms fill in anything it does not cover — except the handling of personal data, where the data processing terms below always apply.

Changes to these terms

We may update these terms. If a change materially affects you we will give you at least 30 days' notice by email. Continuing to use Ocean Ops after that means you accept the change.

Law

These terms are governed by the laws of Estonia, and the courts of Estonia have jurisdiction. If your business is established elsewhere, this does not affect rights you have under your own local law that cannot be excluded by agreement.


Data processing terms

These terms apply when we handle information about your guests on your behalf. They form part of your agreement with us, and they are what data protection law calls a processor agreement. Nothing needs signing — using the service means these apply.

Who is responsible for what

You decide how your guests' information is used. We act only on your documented instructions — these terms, together with the settings you keep in the service, are those instructions. In data protection language you are the controller and we are the processor. You are responsible for the lawfulness of what you ask us to handle, and for telling your guests what happens to their information. If an instruction would, in our view, break data protection law, we will tell you before acting on it.

We do not use your guests' conversations for our own purposes. We do not use them to train AI models. We do not sell anyone's data.

What we do with it

We receive, store, display and transmit guest messages and booking details, draft replies using the AI service listed above, store media guests send, and send scheduled messages such as weather updates, reminders and rescheduling notices. Where you switch it on, we also send post-trip review requests.

The people whose information is involved are your guests and prospective guests, and your own staff who use the app. It covers names, phone numbers, message content, media, booking details, and information the software records about faults.

Health information

Guests sometimes mention a medical condition while messaging you, unprompted. You are responsible for the lawful basis on which you handle that, through the medical or fitness declaration you already use as a dive business.

We do not use health information for any purpose of our own, and we never include it in case studies or marketing. The assistant is not built to ask guests about medical conditions, and it refers medical and fitness questions to a person rather than answering them. Decisions about whether a guest can dive are always yours.

Security

Connections use TLS. The database encrypts data at rest, and third-party credentials and access tokens are separately encrypted on top of that. Guest media sits in a private bucket, not publicly listable, reachable only through links that expire after an hour. Access to live systems is limited to named people who need it, each under a written confidentiality obligation. Deleting a guest conversation is restricted to our platform administrators.

Suppliers

The companies that help us run the service are listed in the section above, with what each receives and where it is. We give you at least 30 days' written notice by email before a new one starts handling guest information, unless a supplier's own terms or an urgent security problem force shorter notice — in which case we tell you as soon as we reasonably can. If you object on reasonable data-protection grounds and we cannot resolve it, you can stop using the affected part of the service without penalty.

How long we keep things, and deleting on request

Guest conversations are kept while your account is active and deleted within 90 days if you stop. If you ask us to erase an individual guest, we do it within 14 days and confirm it — deliberately quicker than the month you have to answer the guest, so you have time to reply to them.

Fault records — kept in our own database, with no outside error-tracking company — can contain part of a message, and are held for 30 days, or 180 days where the fault is still being worked on. Deleted information may remain in encrypted backups for up to 7 days before being overwritten.

If a guest asks about their information

If a guest contacts us directly we will tell you and point them to you, rather than answering ourselves. We will help you respond within 7 days of you asking.

If something goes wrong

If information is lost or exposed, we will tell you within 48 hours of becoming aware, with what we know: what happened, roughly how many people and records are affected, what the likely consequences are, and what we are doing about it. We will not notify a regulator or your guests about it without talking to you first, unless the law requires us to.

Existing message history

When you first connect your WhatsApp number, WhatsApp may transfer up to six months of your existing conversations into the service so your team can see them in one place. That is your own record of communications you already held. We keep that history out of the AI entirely — there for you to read and search, never used to draft a reply. You can tell us not to import it at all.

WhatsApp and AI

Meta's WhatsApp Business terms forbid using WhatsApp message data to train or improve AI models, and a breach can cost you your WhatsApp number. We only use AI providers whose terms prohibit training on what we send, and we do not enable any option that would allow it. That commitment is given with that consequence in mind.

Guests are told when a reply is automated. That notice is required of us by law and must not be removed or reworded to look as though a person wrote it. As the business using the assistant, you are responsible for making sure guests see it.

Using conversations in our own material

We may publish aggregate figures about how the service performs, and quote you with your consent. We will not reproduce any guest's message in a case study or marketing without anonymising it, removing anything about health, and getting your written approval first.

Checking we do what we say

We will give you the information you reasonably need to satisfy yourself that we are keeping to these terms, including our current security measures and the supplier list above. You can also audit our compliance — once in any twelve-month period, on 30 days' written notice, at your own cost and under reasonable confidentiality. Where an audit would need access to a supplier's systems, we will provide that supplier's own audit reports or certifications instead.

Ending

When you stop using the service you can ask for a full copy of your data and we will provide it within 14 days, then delete it as set out above.

Where you stand if you also have a separate agreement with us

A separate written agreement with us governs the commercial side. Where it differs from these terms on the handling of personal data, these terms apply. Where it differs on anything else, your agreement applies. Nothing here reduces your rights under it, including your ownership of your guest data and conversation history.

Law

These terms are governed by the laws of Estonia. Quolo OÜ's supervisory authority is the Estonian Data Protection Inspectorate. Because we are established inside the European Economic Area, no separate EU representative is required.

Where your business is established in South Africa, references to data protection law include the Protection of Personal Information Act 4 of 2013 (POPIA), and health information is treated as special personal information under it.


Contact

For anything on this page, including data requests and questions about our suppliers:

privacy@oceanops.co