Ocean Ops helps dive and marine tour operators handle guest enquiries and bookings over WhatsApp. This page explains how we handle information, which companies help us run the service, and the terms we provide it under.
Privacy notice
Who we are
Ocean Ops is provided by Quolo OÜ, registered in Estonia under registry code 16530266, at Sepapaja tn 6, Lasnamäe linnaosa, Tallinn, Harju maakond 15551, Estonia.
Ocean Ops is the name of the service. Quolo OÜ is the company that provides it and the company you contract with.
Who this notice is for
This covers people who visit this website and operators who use the Ocean Ops app.
If you messaged a dive shop on WhatsApp and want to know about your own information, ask the dive shop. They decide what your messages are used for — we handle them on their instructions only — so they are the right people to give you a copy of your data or delete it. Their own privacy notice covers your conversation. Not sure who to contact? Email privacy@oceanops.co and we will point you to the right operator.
What we collect, and why
When a business uses Ocean Ops we hold the names, email addresses and roles of the people who log in, so we can run their account, and a scrambled version of their password so we can sign them in. We keep that for as long as the account is active.
We also record which features are used and when, so we can understand what works and fix what does not, and we record software faults so they can be diagnosed.
Most of this we need in order to provide the service a customer has asked for. The rest — understanding how the product is used, keeping it secure — rests on our legitimate interest in running and improving it. You can object to that; see your choices below.
Analytics and cookies
We use PostHog to understand how operators use the product. It is hosted in the European Union and records which features are used rather than who is using them: accounts appear as numbers rather than names, and where a session is recorded to diagnose a fault, all text and everything typed is hidden before it is saved. Guest names, phone numbers and message content are never sent to it.
This applies only to people signed into the operator console. Dive shop guests never load this app. PostHog sets cookies in the operator's browser to recognise a returning session, and you can block or delete these in your browser settings at any time without affecting how the product works.
This website itself sets no cookies and runs no analytics. Nothing is stored on your device by visiting these pages, and we do not track visitors here.
We do not use advertising cookies, and we do not sell or share information with advertisers.
Guest conversations
Everything about guest conversations — what we do with them, how long we keep them, and the AI that drafts replies — is in the data processing terms below.
Your choices
You can ask us for a copy of the information we hold about you, ask us to correct it, ask us to delete it, ask us to stop or limit how we use it, or ask for it in a portable format. Email privacy@oceanops.co and we will respond within 30 days.
If you are a dive shop's guest, your request goes to the dive shop — see the note above — and we will help them answer it.
If something does not seem right
Tell us first — email privacy@oceanops.co and we will do our best to put it right quickly. You also have the right to raise it with a data protection regulator at any time: ours is the Estonian Data Protection Inspectorate (aki.ee), or you can go to the authority where you live.
Who processes data for us
We use a small number of other companies to run Ocean Ops. Each one is listed below with what it receives, where it is, and how long it keeps anything. This is the same list that forms part of the agreement each operator has with us.
Companies that handle guest information
OpenAI, L.L.C.
Drafts replies and sorts enquiries
- Receives
- The text of guest messages and the conversation so far
- Where
- United States
- Legal safeguard
- EU–US Data Privacy Framework, with Standard Contractual Clauses in their agreement as an additional safeguard
- Retention
- Up to 30 days to monitor for misuse, then deleted. Never used to train their models
WADA BV, trading as Dualhook
Delivers our outgoing WhatsApp messages
- Receives
- Outgoing message content and media, while in transit only — not stored, cached or written to logs. Guest messages coming in do not pass through Dualhook at all; WhatsApp delivers those straight to us
- Where
- No single committed region. Their delivery network is global and they do not undertake to keep data in one country. The company is registered in Antwerp, Belgium, which is where the business is rather than where the processing happens
- Legal safeguard
- Their published agreement, which forms part of their terms and includes the Standard Contractual Clauses for processor-to-processor transfers
- Retention
- Message content is not kept. Delivery records and phone status history are kept for 30 days
DigitalOcean, LLC
Hosts the application, the database and file storage
- Receives
- Everything the service stores, including message content and the fault records described in the data processing terms below
- Where
- Database in New York, United States. Guest photos, voice notes and documents in Amsterdam, Netherlands
- Legal safeguard
- Their agreement, accepted with their terms of service, which includes the Standard Contractual Clauses and the UK Addendum
- Retention
- For as long as the account is open. Daily backups, with recovery covering the previous 7 days
Companies that handle operator information only
PostHog
Shows us how operators use the product
- Receives
- Which features are used, under a number rather than a name. Session recordings have all text and inputs hidden. No guest names, phone numbers or message content
- Where
- European Union
What is not on this list
WhatsApp and Meta. Meta runs WhatsApp itself, and every operator has their own direct relationship with Meta for their business number — so Meta does not act for us.
Other AI providers. OpenAI is the only AI provider that receives anything. No other AI company holds credentials in the service.
When this list changes
We give every operator at least 30 days' written notice by email before a new company starts handling guest information, or before one of the above materially changes what it does. An operator who objects on reasonable data-protection grounds can raise it with us, and if we cannot resolve it they can stop using the affected part of the service without penalty.
The only exception is where a supplier's own terms, or an urgent security or availability problem, force shorter notice. In that case we tell operators as soon as we reasonably can.
Version history
| Date | What changed |
|---|---|
| 17 August 2026 | First published. |
Terms of service
These terms apply to businesses using Ocean Ops. By using the service you agree to them.
What Ocean Ops does
An inbox for your guest conversations, an assistant that can draft or send replies outside your working hours, booking capture, weather and rescheduling messages, and a dashboard showing your enquiries and bookings.
An early-stage service
Ocean Ops is a young product, developed closely with the operators who use it. Features will change, sometimes without notice. Things will occasionally break and we will fix them. We do not yet offer an availability guarantee or a guaranteed support response time. If you need a service with formal availability commitments, Ocean Ops is not the right choice yet, and we would rather say so now.
Your account
You are responsible for keeping your login details secure and for what the people you give access to do with the account. Tell us promptly if you think someone has gained access who should not have. You need your own WhatsApp Business account to use Ocean Ops; Meta's terms apply to that separately and we cannot accept them on your behalf.
The assistant
You remain responsible for what your business tells its guests. You can switch the assistant off, pause it for a single conversation, or take over at any time.
Guests are told when a reply is automated — the data processing terms below cover that notice and why it stays in place.
The assistant provides information and takes bookings. It does not decide whether a guest is medically fit to dive. Those decisions are yours.
Fees
Your fees, and any free period, are agreed with you in writing before any charge applies — nothing is ever owed that we have not agreed first. There is no automatic renewal and no card on file: if an agreed period ends and we have not agreed what comes next, the service simply stops rather than starting to charge you.
Your data and your guests' data
You remain in control of your guests' information. We handle it on your instructions only, and the detail is in the data processing terms below, which form part of these terms. We do not use guest conversations to train AI models, and we do not sell anyone's data.
What we ask of you
Do not use Ocean Ops to send unsolicited marketing, to break Meta's WhatsApp terms, or to do anything unlawful, and do not attempt to access other operators' data. If you do, we may suspend the account — we will tell you why and give you a chance to put it right where that is reasonable.
Stopping
During any free period, either of us can stop at any time by saying so in writing, and nothing is owed. On paid terms, either of us can end the service on 30 days' written notice.
Whenever it ends you can ask us for a copy of your data, and we will provide it within 14 days.
Limits on our liability
We provide Ocean Ops with reasonable care and skill, but we cannot promise it will be uninterrupted or error-free. We are not liable for lost profits, lost bookings, or losses caused by circumstances outside our reasonable control, including Meta suspending or restricting your WhatsApp account for reasons unconnected with our service. Our total liability to you is limited to the fees you have paid us in the twelve months before the claim, or €1,000 where no fees have been paid.
Nothing here limits liability that cannot lawfully be limited, including for death or personal injury caused by negligence, or for fraud.
If you have a separate written agreement with us
Some operators have their own written agreement with us setting their commercial terms. Where it differs from these terms, that agreement governs. These terms fill in anything it does not cover — except the handling of personal data, where the data processing terms below always apply.
Changes to these terms
We may update these terms. If a change materially affects you we will give you at least 30 days' notice by email. Continuing to use Ocean Ops after that means you accept the change.
Law
These terms are governed by the laws of Estonia, and the courts of Estonia have jurisdiction. If your business is established elsewhere, this does not affect rights you have under your own local law that cannot be excluded by agreement.
Data processing terms
These terms apply when we handle information about your guests on your behalf. They form part of your agreement with us, and they are what data protection law calls a processor agreement. Nothing needs signing — using the service means these apply.
Who is responsible for what
You decide how your guests' information is used. We act only on your documented instructions — these terms, together with the settings you keep in the service, are those instructions. In data protection language you are the controller and we are the processor. You are responsible for the lawfulness of what you ask us to handle, and for telling your guests what happens to their information. If an instruction would, in our view, break data protection law, we will tell you before acting on it.
We do not use your guests' conversations for our own purposes. We do not use them to train AI models. We do not sell anyone's data.
What we do with it
We receive, store, display and transmit guest messages and booking details, draft replies using the AI service listed above, store media guests send, and send scheduled messages such as weather updates, reminders and rescheduling notices. Where you switch it on, we also send post-trip review requests.
The people whose information is involved are your guests and prospective guests, and your own staff who use the app. It covers names, phone numbers, message content, media, booking details, and information the software records about faults.
Health information
Guests sometimes mention a medical condition while messaging you, unprompted. You are responsible for the lawful basis on which you handle that, through the medical or fitness declaration you already use as a dive business.
We do not use health information for any purpose of our own, and we never include it in case studies or marketing. The assistant is not built to ask guests about medical conditions, and it refers medical and fitness questions to a person rather than answering them. Decisions about whether a guest can dive are always yours.
Security
Connections use TLS. The database encrypts data at rest, and third-party credentials and access tokens are separately encrypted on top of that. Guest media sits in a private bucket, not publicly listable, reachable only through links that expire after an hour. Access to live systems is limited to named people who need it, each under a written confidentiality obligation. Deleting a guest conversation is restricted to our platform administrators.
Suppliers
The companies that help us run the service are listed in the section above, with what each receives and where it is. We give you at least 30 days' written notice by email before a new one starts handling guest information, unless a supplier's own terms or an urgent security problem force shorter notice — in which case we tell you as soon as we reasonably can. If you object on reasonable data-protection grounds and we cannot resolve it, you can stop using the affected part of the service without penalty.
How long we keep things, and deleting on request
Guest conversations are kept while your account is active and deleted within 90 days if you stop. If you ask us to erase an individual guest, we do it within 14 days and confirm it — deliberately quicker than the month you have to answer the guest, so you have time to reply to them.
Fault records — kept in our own database, with no outside error-tracking company — can contain part of a message, and are held for 30 days, or 180 days where the fault is still being worked on. Deleted information may remain in encrypted backups for up to 7 days before being overwritten.
If a guest asks about their information
If a guest contacts us directly we will tell you and point them to you, rather than answering ourselves. We will help you respond within 7 days of you asking.
If something goes wrong
If information is lost or exposed, we will tell you within 48 hours of becoming aware, with what we know: what happened, roughly how many people and records are affected, what the likely consequences are, and what we are doing about it. We will not notify a regulator or your guests about it without talking to you first, unless the law requires us to.
Existing message history
When you first connect your WhatsApp number, WhatsApp may transfer up to six months of your existing conversations into the service so your team can see them in one place. That is your own record of communications you already held. We keep that history out of the AI entirely — there for you to read and search, never used to draft a reply. You can tell us not to import it at all.
WhatsApp and AI
Meta's WhatsApp Business terms forbid using WhatsApp message data to train or improve AI models, and a breach can cost you your WhatsApp number. We only use AI providers whose terms prohibit training on what we send, and we do not enable any option that would allow it. That commitment is given with that consequence in mind.
Guests are told when a reply is automated. That notice is required of us by law and must not be removed or reworded to look as though a person wrote it. As the business using the assistant, you are responsible for making sure guests see it.
Using conversations in our own material
We may publish aggregate figures about how the service performs, and quote you with your consent. We will not reproduce any guest's message in a case study or marketing without anonymising it, removing anything about health, and getting your written approval first.
Checking we do what we say
We will give you the information you reasonably need to satisfy yourself that we are keeping to these terms, including our current security measures and the supplier list above. You can also audit our compliance — once in any twelve-month period, on 30 days' written notice, at your own cost and under reasonable confidentiality. Where an audit would need access to a supplier's systems, we will provide that supplier's own audit reports or certifications instead.
Ending
When you stop using the service you can ask for a full copy of your data and we will provide it within 14 days, then delete it as set out above.
Where you stand if you also have a separate agreement with us
A separate written agreement with us governs the commercial side. Where it differs from these terms on the handling of personal data, these terms apply. Where it differs on anything else, your agreement applies. Nothing here reduces your rights under it, including your ownership of your guest data and conversation history.
Law
These terms are governed by the laws of Estonia. Quolo OÜ's supervisory authority is the Estonian Data Protection Inspectorate. Because we are established inside the European Economic Area, no separate EU representative is required.
Where your business is established in South Africa, references to data protection law include the Protection of Personal Information Act 4 of 2013 (POPIA), and health information is treated as special personal information under it.
Contact
For anything on this page, including data requests and questions about our suppliers: