1. Scope
This policy explains how PlanetHike OÜ, operating Regreenity, handles personal data on this website and in controlled product pilots. Customer deployments may include customer-specific privacy information reflecting the cruise line, hotel or resort systems and legal responsibilities.
2. Controller and processor roles
PlanetHike OÜ is controller for website and direct business enquiries, including pilot requests. In a typical white-label customer deployment, the cruise line, hotel or resort determines the purposes of guest and staff processing and acts as controller; PlanetHike OÜ generally processes that data on documented instructions as processor. Contractual documents define the exact allocation.
3. Website and pilot-request data
When you request a pilot, we may process name, work email, company, role, business segment, operating footprint, message, source page, basic technical information and a one-way hash of the submitting network address for abuse-rate limiting. We use these data to respond to the request, qualify the use case, administer the enterprise relationship and protect the form from abuse.
4. Platform data
Depending on customer configuration, Regreenity may process verified guest/stay or sailing context, selected guest profile information, participation actions, recognition signals, experience scores, service recovery status, campaign entries, relevant commerce handoff events and technical data required to operate the service. Production deployments should minimize data to the enabled workflows.
5. Legal bases
Relevant GDPR legal bases may include steps requested before entering a business relationship, legitimate interests in enterprise communications and service security, contractual necessity, legal obligations and consent where an optional guest feature requires it.
6. Recipients and transfers
We do not sell personal data. Data may be available to authorized PlanetHike OÜ personnel, the relevant customer and approved infrastructure or professional service providers where necessary. International transfers use an applicable lawful transfer mechanism where required.
7. Retention
Business enquiries are retained only as long as needed for the commercial relationship, legal obligations and reasonable follow-up. Customer deployment retention is defined with the customer. Regreenity’s design principle is to keep proximity identifiers and offline queues short-lived and avoid collecting payment-card data.
8. Your rights
Where GDPR applies, you may have rights of access, correction, erasure, restriction, portability and objection, and may withdraw consent where processing relies on consent. For PlanetHike OÜ-controlled data contact hello@planethike.org with the subject “Privacy request – Regreenity”.
9. Security and changes
We use data minimization, role-based access, secure transport, restricted database permissions and bounded interaction patterns. We may update this policy as the product and customer integrations evolve.