Privacy Policy
Last updated: August 19, 2026
Effective date: January 1, 2026
1. Who we are
This privacy policy is published by:
D-ICE Engineering SAS ("D-ICE", "we", "us")
1 rue de la Noë, 44321 Nantes, France
SIREN 809 273 329 — Share capital €6,000,000 — Publication Director: Sofien Kerkeni
Phone: +33 2 40 37 53 25
Data protection contact / DPO: privacy@dice-engineering.com
General contact: contact@dice-engineering.com
D-ICE acts as data controller within the meaning of the General Data Protection Regulation 2016/679 (GDPR) and the French Loi Informatique et Libertés no. 78-17.
This policy describes how we collect, use, share, retain and protect personal data when you:
- visit dice-engineering.com, squid-sailing.com or any of their pages;
- use the institutional website, including contact forms, job applications and newsletters;
- create or manage a D-ICE or Squid account;
- purchase or manage a subscription;
- use our applications (web, iOS, Android or desktop), such as Squid, including when you choose "Sign in with Google".
This policy is the default reference framework applicable in the absence of any other agreement. It does not prevail over commercial contracts, framework agreements or specific terms negotiated between D-ICE Engineering and its professional clients. Under such contracts, the data protection provisions agreed contractually take priority.
This policy applies in full to users of our products, such as Squid, who are not bound to D-ICE by a specific contract.
2. Personal data we collect
2.1 Data you provide to us
| Category | When | Examples |
|---|---|---|
| Identity and contact | Registration, contact form, account creation | First name, last name, email address, phone, company, job title |
| Authentication | Account creation, login | Username, hashed password where applicable, MFA information |
| Payment and subscription | Subscribing to or managing a paid plan | Billing name and address, VAT number where applicable, subscription information, payment status and payment-related identifiers. Full payment-card details are processed by Stripe and are not stored by D-ICE |
| User content | Use of the applications | Routes, GPX tracks, polars, vessel data, waypoints, support messages and screenshots |
| Communication preferences | Account settings | Language, display preferences and notification preferences |
2.2 Automatically collected data
| Category | Where | Purpose / examples |
|---|---|---|
| Technical and request logs | Websites, web applications, APIs, application servers and hosting infrastructure | Operation, security, fraud prevention and diagnosis of the services. These logs may include IP address, date and time, requested URL or API endpoint, HTTP method, response status, user agent, request or technical identifiers, error information and, where necessary, an authenticated account or user identifier |
| Infrastructure and operational metrics | Amazon CloudWatch | Monitoring the availability, performance and operation of our infrastructure. Metrics may include request counts, response times, error rates, resource utilisation and other technical performance measurements. These metrics are not intended to contain user content |
| Device and software information | Websites and applications | Browser, operating system, device type, screen or viewport information and application version, used for compatibility, diagnostics and support |
| Approximate geographic information derived from IP address | Web infrastructure and product analytics | Product analytics, aggregated statistics, security and fraud detection |
| Precise device or browser geolocation | Web, mobile and desktop applications, after browser or operating-system permission | Map positioning, navigation, weather routing, race tracking and other location-dependent features. Location may be processed locally on the device and may be transmitted to D-ICE servers where necessary to provide the feature requested by the user |
| Product Analytics | PostHog Cloud EU, after analytics consent | Pages or screens viewed, navigation paths, features used, clicks and other interface interactions, sessions and frequency of use, browser and operating system, device type, screen and viewport dimensions, language, referring website or acquisition source, approximate geographic information derived from IP address, technical/session identifiers and, where applicable, an internal account identifier |
| Session Replay | PostHog Cloud EU, after analytics consent | Reconstruction of interactions with the Squid Web interface, including pages viewed, clicks, mouse movements, scrolling, navigation and other interface interactions, for usability analysis and diagnosis of technical or navigation issues |
| Diagnostic data | Sentry and internal diagnostic systems | Crash reports, application errors, technical metrics and information required to investigate incidents |
Technical and request logs are generated as part of the normal operation, maintenance and security of our websites, applications, APIs and infrastructure. Their exact content may vary according to the service concerned and the nature of the request.
Infrastructure and operational metrics collected through Amazon CloudWatch are used to monitor the availability, stability, capacity and technical performance of our services.
Product Analytics collected through PostHog are used to understand how our products are used, measure the use of features, identify usability or technical issues and improve our applications.
PostHog Session Replay allows us to reconstruct certain user sessions in order to understand navigation problems, errors and areas of friction in the interface. Session Replay may record interactions including pages viewed, clicks, mouse movements, scrolling and navigation between pages.
PostHog Product Analytics and Session Replay are activated only after the user has consented to analytics through our cookie banner or cookie preferences. If analytics are refused, PostHog does not collect Product Analytics or Session Replay data. Users may withdraw their consent at any time.
2.3 Data received from Google when you choose "Sign in with Google"
The D-ICE applications using "Sign in with Google" include in particular Squid, Tactics and Panoramics. For Tactics and Panoramics, deployed under commercial contracts, the specific data processing terms agreed contractually take priority over this policy.
When you activate "Sign in with Google" on one of our applications, Google requests your consent and then transmits to us only the data covered by the scopes below. We request no other access to your Google account.
| Google scope | Data received | Why |
|---|---|---|
| openid | Stable Google identifier (sub), opaque to a human |
To link your D-ICE account to your Google account and log you in |
| Email address of your Google account and email verification information | To create and manage your account, send operational notifications and allow support to contact you | |
| profile | First name, last name, locale and, where available, profile photo URL | To personalise the interface and identify you within relevant product features |
We do not request access to Gmail messages, Google Drive files, Google Calendar events, Google Contacts, Google Photos, YouTube data, Chrome history, Fitness data, Health Connect data or other Google APIs unless specifically stated and separately authorised.
If we add a new Google scope, we will update this policy and obtain any consent or authorisation required before using that scope.
3. Use of Google data — "Limited Use" commitment
D-ICE Engineering's use, and transfer to any other application, of information received from Google APIs is limited to the following purposes:
- Providing user features of our applications, including creating and maintaining your account, authenticating you, displaying appropriate profile information and contacting you for transactional messages.
- Improving these features in aggregated form or, where required, with your consent for usage measurement.
- Complying with the law or a legally binding request.
- Investigating security incidents, abuse or violations of our Terms of Use.
We do not:
- use Google data for targeted, personalised or retargeted advertising;
- sell or rent Google data to data brokers or information resellers;
- use Google data for credit or lending decisions;
- train, fine-tune or evaluate artificial intelligence or machine-learning models using Google data;
- transfer Google data to third parties except where necessary to provide the relevant service, comply with a legal obligation, or as part of a corporate restructuring subject to appropriate data-protection obligations.
You may revoke access granted to D-ICE from the permissions section of your Google Account. Revoking Google access does not itself delete the D-ICE account created using that login. Account deletion is described in § 7.
3a. Aggregated and anonymised data
D-ICE Engineering may use and commercialise aggregated and anonymised data generated through the use of its services and applications — for example, maritime traffic flows, environmental data and aggregated routing or port-call statistics.
Such data must no longer allow D-ICE or another party reasonably likely to receive it to identify a natural person or an individual vessel.
Personal data, navigation data relating to an identifiable individual vessel, and information taken from private user content are not included in datasets described by D-ICE as anonymised under this section.
If D-ICE intends to use less aggregated information that remains personal data, the processing will be subject to an appropriate legal basis and the information obligations applicable under data-protection law.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Creation and management of your D-ICE account | Performance of a contract — GDPR art. 6(1)(b) |
| Authentication and account security | Performance of a contract and/or legitimate interest — GDPR art. 6(1)(b) and 6(1)(f) |
| Billing and subscription management | Performance of a contract — GDPR art. 6(1)(b) |
| Provision of routing, navigation, geolocation and analysis features | Performance of a contract — GDPR art. 6(1)(b). Access to precise device or browser geolocation also requires the applicable browser or operating-system permission |
| Technical and request logging | Legitimate interest — GDPR art. 6(1)(f), in particular operation, troubleshooting, fraud prevention and security of the services |
| Infrastructure and operational monitoring | Legitimate interest — GDPR art. 6(1)(f), in particular availability, capacity, performance and security of the services |
| Transactional and service communications | Performance of a contract — GDPR art. 6(1)(b) |
| Marketing emails | Consent — GDPR art. 6(1)(a), where consent is required |
| PostHog Product Analytics | Consent — GDPR art. 6(1)(a) |
| PostHog Session Replay | Consent — GDPR art. 6(1)(a) |
| Compliance with accounting, tax and other legal requirements | Legal obligation — GDPR art. 6(1)(c) |
| Processing of genuinely anonymised information | Outside the scope of the GDPR once the information is irreversibly anonymised |
Browser or operating-system permission to access a device's location is technically separate from consent to analytics cookies and trackers.
5. Our technical service providers
We do not sell your personal data.
We use technical service providers where necessary to operate our websites, applications, subscriptions and infrastructure. Depending on the service and processing concerned, these providers act under appropriate data-protection terms and may act as processors or, for certain processing activities required by their own legal obligations, as independent controllers.
| Provider | Role | Main processing location |
|---|---|---|
| Amazon Web Services (AWS), including CloudWatch | Hosting, infrastructure, monitoring and operational telemetry | European Union, including the AWS Paris region used by D-ICE |
| Stripe | Payments, subscription management and billing | European Union and other locations in accordance with Stripe's applicable data-protection arrangements |
| Authentication and related Google services | European Union / United States, subject where applicable to lawful transfer mechanisms | |
| Sentry | Error monitoring and diagnostics | European Union where configured |
| PostHog Cloud EU | Product Analytics and Session Replay | Frankfurt, Germany |
| Webflow | Institutional website services | European Union / United States, subject where applicable to lawful transfer mechanisms |
| Apple / Google Play | Mobile application distribution and related platform services | European Union / United States, subject where applicable to lawful transfer mechanisms |
6. International transfers
Some of our service providers may process personal data outside the European Economic Area.
Where a transfer of personal data outside the European Economic Area requires safeguards under Chapter V of the GDPR, D-ICE relies on an appropriate transfer mechanism, such as an adequacy decision, the EU-US Data Privacy Framework where applicable, or Standard Contractual Clauses approved by the European Commission.
PostHog Product Analytics and Session Replay are provided through PostHog Cloud EU, with the relevant product data hosted in Frankfurt, Germany.
7. Retention and deletion
We retain personal data only for as long as necessary for the purpose for which it is processed, subject to legal retention requirements and the specific periods below.
| Category | Retention period |
|---|---|
| Account identity and profile data | Duration of the account + up to 3 years after closure where required for legitimate business or legal purposes |
| Invoices and accounting records | 10 years where required by French accounting and tax law |
| Authentication/security logs | Up to 12 months |
| HTTP/API request and access logs | 180 days |
| Amazon CloudWatch infrastructure and operational metrics | Up to 15 months |
| User content such as routes, polars and tracks | Duration of the account; deletion in accordance with the account-deletion process |
| Proof of marketing consent | Up to 3 years from the relevant contact or consent record, where applicable |
| PostHog Product Analytics data | 12 months |
| PostHog Session Replay recordings | Up to 30 days |
| Support tickets | Up to 3 years following closure of the request or relationship where necessary |
| Diagnostic and crash data | Up to 90 days, subject to the configuration of the relevant diagnostic service |
CloudWatch progressively aggregates older metric data to a lower time resolution during the retention period.
Account deletion. You may request deletion of your D-ICE account at any time by writing to privacy@dice-engineering.com or through the account-deletion functionality where available.
D-ICE will process deletion requests in accordance with applicable law. Data that must be retained to comply with a legal obligation, establish or defend legal claims, prevent fraud or satisfy another valid legal basis may be retained for the corresponding period.
Where identifiable personal data associated with the account is held by a service provider acting on behalf of D-ICE, D-ICE will take appropriate steps to delete or anonymise that data where required.
8. Your rights
Subject to the conditions provided by the GDPR, you may have the right to:
- obtain access to your personal data;
- correct inaccurate or incomplete data;
- request erasure of personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive eligible data in a structured, commonly used and machine-readable format and, where applicable, have it transmitted to another controller;
- withdraw consent at any time for processing based on consent, without affecting the lawfulness of processing carried out before withdrawal.
To exercise these rights, contact privacy@dice-engineering.com.
We will respond without undue delay and in principle within one month of receiving a valid request. Where permitted by the GDPR, this period may be extended where necessary because of the complexity or number of requests.
You may also lodge a complaint with the French data-protection authority, the CNIL.
9. Security
We implement technical and organisational measures intended to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.
Depending on the relevant system, these measures include:
- encrypted HTTPS communications;
- protection of databases and storage systems;
- identity and access management;
- role-based access controls;
- authentication and security logging;
- monitoring of infrastructure and applications;
- vulnerability and dependency management;
- confidentiality obligations applicable to authorised personnel.
Access to personal data is limited to persons and service providers who require it for their authorised functions.
Security measures are reviewed and adapted where appropriate in light of changes in our systems, risks and available technologies.
Security incidents may be reported to security@dice-engineering.com.
10. Cookies and trackers
The dice-engineering.com and squid-sailing.com websites and D-ICE web applications use cookies and similar technologies.
Certain cookies or identifiers are strictly necessary for functions such as authentication, maintaining a session, securing the service, remembering privacy choices or providing functionality expressly requested by the user. These technologies may be used without consent where permitted by applicable law.
Other trackers, including PostHog Product Analytics and Session Replay, are activated only after the user has consented to analytics through the cookie banner or cookie-preference interface.
If the user refuses analytics, PostHog Product Analytics and Session Replay do not collect data.
PostHog uses technical and session identifiers to associate analytics events with a browsing session and, where applicable, subsequent sessions. D-ICE uses this information for product analytics and user-experience analysis, not for advertising.
Session Replay allows D-ICE to reconstruct certain interactions with the Squid Web interface, such as pages viewed, clicks, mouse movements, scrolling and navigation, in order to identify technical problems and improve usability.
Users may use the essential functions of the service without accepting PostHog Product Analytics or Session Replay.
Consent may be withdrawn or changed at any time through the cookie-preference controls available on the relevant website or application. Withdrawal prevents subsequent PostHog analytics and Session Replay collection.
Analytics cookies and similar trackers used by D-ICE are subject to the duration defined in their configuration and applicable law, with a maximum tracker lifetime of 13 months unless a shorter period applies. The retention periods for the resulting PostHog data are stated separately in § 7.
11. Minors
Our products are not intended for children under 16 years of age.
We do not knowingly seek to collect personal data from children under 16 through our consumer services. If you believe that such data has been provided to us inappropriately, please contact privacy@dice-engineering.com so that we can investigate and take the appropriate action.
12. Changes to this policy
We may update this privacy policy where our services, processing activities or legal obligations change.
The "Last updated" date at the beginning of this policy indicates the date of the latest revision.
Where required by applicable law, or where a change materially affects how we process personal data, we will provide appropriate additional notice.
13. Contact
Data protection contact / DPO:
privacy@dice-engineering.com
Postal address:
D-ICE Engineering SAS — Data Protection
1 rue de la Noë
44321 Nantes, France
General contact:
contact@dice-engineering.com
Phone:
+33 2 40 37 53 25