Privacy policy
This website works without cookies, without advertising networks and without analytics services. There is no embedded third-party content, and we even load the font from our own server. So only the data you send us yourselves is processed — plus what is technically necessary.
1. Controller
Responsible for data processing on this website is:
- Controller
- Funny Divers Diving Center, Sayed Korayem Street, 84511 Hurghada, Egypt — authorised representatives: Ahmed Mahmoud Ali, Nasser Maher Hamada
- info@funnydivers.com
- Phone
- +20 122 419 3164
Bubblemakers Hurghada is the children’s and family programme of the Funny Divers Diving Center; the controller is therefore the dive centre. We have not appointed a data protection officer; in our assessment we are not required to do so.
2. Booking request
When you fill in the booking form, we process the details you enter there: your name, your email address and/or WhatsApp number, the chosen courses and packages, the requested dates, the number of participants, for the Bubblemaker whether the accompanying person snorkels or dives along, any request for rental equipment or hotel pick-up including the pick-up location, and your comments.
How the request reaches us: until you submit it, your entries stay in your browser. With “Send request” they are transmitted encrypted (HTTPS) to our dive centre’s booking system at www.funnydivers.com. There the request is stored and appears in the internal area for our team; in addition, a notification is emailed to our office. If you have given an email address, we send a confirmation of receipt to that address. Together with the request we store the time and your IP address to slow down mass automated requests (see section 5).
The route via WhatsApp or email: if you choose “Use WhatsApp instead” — or if our booking system is temporarily unreachable — nothing is transmitted to our server. The page then puts together a ready-made message from your entries and hands it to WhatsApp or your email program. This message is only sent once you send it yourself.
Purpose and legal basis: processing your request and preparing the contract, Art. 6(1)(b) GDPR.
Recipients: your request reaches our team in Hurghada — via the booking system and the notification email, or, if you choose this route, via WhatsApp or your email program. If you choose WhatsApp, WhatsApp processes the transmitted message and your phone number under its own terms; if you want to avoid that, send the request directly through the form or write to us at info@funnydivers.com.
Storage period: we keep booking requests for as long as we need them to look after your stay and to answer follow-up questions, but no longer than the end of the statutory retention periods under commercial and tax law. Requests that don’t turn into a booking are deleted after twelve months at the latest.
Passport photo and customer file: no photo is transmitted through this form. When you come to our base, we create a customer file: name, phone number, nationality, a passport-style photo and internal notes on the dives. We need the photo to identify you safely on the jetty and on the boat; on a later visit this means the photo doesn’t need to be taken again. The images are stored outside the publicly accessible area of our server, cannot be accessed via any internet address and are only handed to our staff after login. The legal basis is Art. 6(1)(b) GDPR. We keep the photo for as long as you are listed with us as a guest and delete it at any time on request. We do not collect additional data such as ID or passport details, certifications or health declarations through this website.
Medical questionnaire: the medical questionnaire to be filled in before the course starts is completed exclusively on site in paper form or via PADI’s systems — not through this website.
Payment data: no payment is made on this website. Payment takes place on site. We therefore do not collect credit card, account or other payment data through this website.
3. Who gets to see your booking data
Your details stay within our business. Internally, only the people who actually need them for your stay can see them:
- Our office in Hurghada — requests, bookings and the customer file. Access is limited to personal accounts with graduated rights.
- Guides and instructors — name, booked course, child’s age, date and experience level, so groups can be arranged.
- Hotel transfer drivers — only if you request pick-up, and only name, hotel, pick-up time and number of people. We usually pass this daily list to the driver as a message via WhatsApp; WhatsApp processes the transmitted details under its own terms. Your email address, your comments and passport photos are never included in this list.
Beyond this we only pass on data where we are legally required to — for example for reports required for dive operators and boats. We do not sell your data or pass it on for advertising purposes.
4. Contact form
Through the contact form we process your name, your email address and/or WhatsApp number and your message. The same applies as for the booking request: with “Send message” the message is transmitted encrypted to the booking system at www.funnydivers.com, stored there together with the time and IP address, and reported to our team by email; if you have given an email address, you receive a confirmation of receipt. Via “Use WhatsApp instead”, on the other hand, nothing is transmitted to our server; instead a ready-made message is handed to WhatsApp, which you send yourself.
Purpose and legal basis: answering your message, Art. 6(1)(b) or (f) GDPR. Storage period: until your matter is fully resolved, twelve months at most — unless statutory retention obligations require otherwise.
5. Spam protection
Both forms are protected by a small reef check: you pop the bubbles containing the requested sea creatures. The task is set by our own server and checked there on submission. No external service such as reCAPTCHA is used, so no data is transmitted to third parties. In addition, our server accepts at most five requests within ten minutes from the same IP address; for this the IP address is stored together with the request. A form field invisible to humans also helps detect automatically filled-in forms. The legal basis is our legitimate interest in preventing automated mass requests, Art. 6(1)(f) GDPR.
6. Server logs
When this website is accessed, our web server automatically collects the data your browser transmits: the address accessed, date and time, amount of data transferred, referring page, browser type and operating system, and the IP address. We need these logs for the technical operation and security of the website. The legal basis is Art. 6(1)(f) GDPR. This data is not merged with other data.
7. Analytics, advertising and tracking services
We use no analytics or advertising services. In particular, we use no Google Analytics, no Google Tag Manager, no Meta Pixel and no advertising networks. There is also no embedded content from third-party servers: maps and social networks are included only as ordinary links, and we serve the Sour Gummy font from our own server — so no connection to Google Fonts is made. Your visit therefore does not create a profile and is not tracked across websites.
8. Storage on your device
This website uses no cookies. It only uses your browser’s session storage for a single item:
bm_intro— the information that the logo animation has already been shown during this page visit, so it doesn’t start again on every subpage as you click through.
This entry stays exclusively on your device, is not transmitted to us and is automatically deleted when the browser tab is closed. Since it serves solely a function you requested, no consent is required for it (§ 25(2) no. 2 TDDDG).
9. External links and social networks
We link to WhatsApp, Google Maps, Facebook, Instagram and TikTok. These are ordinary links, not embedded content — no data is transmitted unless you click the link. Once you click it, the respective provider’s privacy terms apply. We have no influence over these.
If you write to us via WhatsApp, WhatsApp processes your message and your phone number under its own terms. If you want to avoid that, you can reach us just as easily by email.
10. Hosting
This website is hosted by Hostinger International Ltd, 61 Lordou Vironos Street, 6023 Larnaca, Cyprus. Hostinger processes the data on our behalf; a data processing agreement (Data Processing Addendum) under Art. 28 GDPR is in place. The server is located in Germany (Frankfurt am Main data centre).
11. Children’s data
Our offer is aimed at families; bookings are made exclusively by parents or legal guardians. We process information about children — age, swimming experience, booked course — only to the extent that you provide it to us as their guardian in the course of booking and to the extent it is necessary for the safe running of the course. The legal basis is Art. 6(1)(b) GDPR.
We publish photos in which children are recognisable only with the express consent of the guardians, revocable at any time. Photos taken during the course are given to you; this does not automatically lead to publication.
12. Your rights
You have the right, at any time, to
- information about the data stored about you (Art. 15 GDPR),
- correction of inaccurate data (Art. 16 GDPR),
- erasure (Art. 17 GDPR),
- restriction of processing (Art. 18 GDPR),
- data portability (Art. 20 GDPR),
- objection to processing based on a legitimate interest (Art. 21 GDPR).
An email to info@funnydivers.com is enough. You may also lodge a complaint with a data protection supervisory authority, in particular in the EU member state where you are staying (Art. 77 GDPR).
13. Data transfer outside the EU
Our dive centre is based in Hurghada, Egypt. There is no adequacy decision by the European Commission for Egypt. Where your data reaches Egypt, this happens in order to fulfil the contract with you or to carry out pre-contractual measures at your request (Art. 49(1)(b) GDPR).
What this means in practice: the server this website is hosted on is located in Germany. Your request is, however, read and processed by our team in Hurghada — at that point at the latest, the data reaches Egypt. There is no adequacy decision under Art. 45 GDPR for Egypt. We therefore cannot guarantee you a level of protection that is materially equivalent to that of the Union; in particular, the same legal remedies against access by Egyptian authorities are not available to you as within the Union.
We base the transfer on Art. 49(1)(b) GDPR: it is necessary to perform the contract with you, since without your details in Hurghada there is no course place, no boat place and no pick-up. We only transmit what is needed for your stay.
Technically, the transmission is fully encrypted (HTTPS), and access to our internal systems is limited to personal accounts with graduated rights.
Last updated: September 2026 · This translation is provided for convenience; the German version is legally authoritative.