Legal

Privacy Policy

CoastLeap (“CoastLeap”, “we”, “our”, “us”) operates the online platform available at coastleap.com (the “Platform”). This Privacy Policy explains how we collect, use, process, store and protect personal data when individuals access or use the Platform.

Effective Date: March 2025

By accessing or using CoastLeap, you acknowledge that you have read and understood this Privacy Policy.

1. Data Controller

The Data Controller is:

CoastLeap Legal Team
Athens, Greece
Email: support@coastleap.com
Website: coastleap.com

2. Personal Data We Collect

We may collect the following categories of personal data:

a) Account & Profile Information

  • Name
  • Company name
  • VAT number (where applicable)
  • Email address
  • Phone number
  • Business address
  • Service categories
  • Profile description and media uploads

b) Subscription & Billing Data

  • Billing address
  • VAT status
  • Payment confirmation data (payment processing is handled by third-party providers — CoastLeap does not store full credit card details)

c) Communications

  • Messages sent through the Platform
  • Customer support requests
  • Email correspondence

d) Technical Data

  • IP address
  • Browser type
  • Device information
  • Cookies and analytics data
  • Usage behavior within the Platform

3. Purpose of Processing

We process personal data for the following purposes:

  • To create and manage user accounts
  • To provide directory and contact services
  • To verify Supplier and Agency profiles
  • To process subscriptions and payments
  • To communicate with users
  • To improve platform performance and security
  • To comply with legal obligations (e.g. tax and regulatory compliance)

5. Data Sharing

CoastLeap does not sell personal data. We may share data with:

  • Payment processors
  • Hosting and IT service providers
  • Analytics providers
  • Legal or regulatory authorities when required by law

All third-party processors operate under data processing agreements compliant with GDPR.

6. Data Retention

We retain personal data:

  • For as long as the account remains active
  • For the duration required by tax and accounting laws
  • As necessary to resolve disputes or enforce agreements

Users may request deletion of their data (see Section 9).

7. International Transfers

If data is transferred outside the European Economic Area (EEA), appropriate safeguards such as Standard Contractual Clauses (SCCs) are applied.

8. Cookies & Tracking Technologies

Strictly necessary cookies

These are required for the Platform to work and are set without consent, as permitted by Article 5(3) of the ePrivacy Directive. They keep you signed in, protect forms against cross-site request forgery, and remember your answer to the cookie banner so we do not ask again on every page.

Marketing attribution cookies

If you consent, we store the marketing campaign you arrived from so that, should you later create an account, we can tell which campaign introduced you to CoastLeap. We record the campaign parameters in the link you followed (source, medium, campaign, content and search term), any advertising click identifier, the page you landed on, the site that referred you, and the date. These cookies last 90 days.

We do not use these cookies to build advertising profiles, and we do not share them with advertising networks or any other third party.

If you decline

The Platform behaves identically, and we do not record which campaign brought you here at all — not on your device, and not on our servers. Anything we had already noted during your visit before you answered is erased the moment you decline, and if you had previously accepted, declining deletes what was stored then.

If you have not answered yet

Until you choose, no attribution cookie is placed on your device. The campaign parameters from your current visit are held on our servers as part of your session, which expires when you stop browsing. If you create an account during that same visit, they are saved to your account under our legitimate interest in understanding where our members come from (Article 6(1)(f) GDPR). You may object at any time under Section 9 below, and we will erase it.

Changing your mind

Your choice is remembered for six months, after which we will ask again. You can withdraw consent sooner — as easily as it was given — by clearing CoastLeap's cookies in your browser, which makes the banner reappear. You can also block or delete cookies entirely through your browser settings.

9. User Rights (GDPR)

Under EU data protection law, users have the right to:

  • Access their personal data
  • Rectify inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict processing
  • Object to processing
  • Data portability
  • Withdraw consent at any time

Requests may be sent to: support@coastleap.com

10. Data Security

We implement appropriate technical and organizational measures to protect personal data against:

  • Unauthorized access
  • Loss or destruction
  • Alteration
  • Disclosure

However, no internet-based system is completely secure.

11. Third-Party Links

The Platform may contain links to third-party websites. CoastLeap is not responsible for their privacy practices.

12. Children’s Privacy

CoastLeap is intended for professional users. We do not knowingly collect data from individuals under 18 years of age.

13. Updates to this Policy

We may update this Privacy Policy at any time. Updates become effective upon posting on the Platform. Continued use of CoastLeap constitutes acceptance of the updated Policy.

14. Contact

For privacy-related inquiries:

CoastLeap Legal Team
support@coastleap.com
Athens, Greece

Cookies on CoastLeap

We use cookies that are necessary to run the site. We'd also like to remember which campaign brought you here, so we know where our members come from. That one is entirely up to you. The site works the same either way. Privacy policy