Legal
Updated: 16 September 2026
1.1Day 8 AB, trading as Day 8, Yacht Week, YW and Ski Week, a company registered in Sweden with organisation number 556765-8769 and registered address at Beckholmsvägen 4, 115 21 Stockholm, Sweden, is committed to protecting and respecting your privacy.
1.2This Privacy Policy explains how Day 8 AB, together with relevant group companies where applicable, collects, uses, stores, shares and otherwise processes personal data when you access or use our websites, mobile applications, forms, communications channels, booking flows, recruitment flows, social media interactions, video interview processes, and related services.
1.3It applies to your use of:
1.4By accessing or using the Services, or by otherwise submitting personal data to us, you acknowledge that your personal data will be processed in accordance with this Privacy Policy.
1.5If you have any questions about this Privacy Policy or about how we process your personal data, contact us at info@day8.com.
2.1For the purposes of applicable data protection law, Day 8 AB is the controller responsible for your personal data, unless this Privacy Policy states otherwise.
2.2This means we decide how and why your personal data is processed in connection with the Services.
2.3We are established in Sweden, so the General Data Protection Regulation (EU) 2016/679 and Swedish data protection law apply to our processing. Where we offer services to individuals in the United Kingdom, the UK GDPR and the Data Protection Act 2018 also apply to that processing.
3.1This Privacy Policy explains:
3.2We may update this Privacy Policy from time to time. Where we do so, we will update the "Updated" date shown at the top of this page.
4.1Personal data means information relating to an identified or identifiable individual.
4.2Processing means any operation carried out on personal data, including collecting, recording, organising, storing, adapting, retrieving, consulting, using, sharing, restricting, deleting, or destroying it.
4.3Legitimate interests means the legitimate interests of our business in conducting, managing, improving, protecting and developing our business and Services, provided those interests are not overridden by your rights and interests.
5.1We may process personal data relating to:
6.1The personal data we collect depends on how you interact with us and with the Services.
6.2Identity Data. First and last name; company name and VAT number where you book as a business; username or account identifier; date of birth; place and country of birth; nationality; sex; passport details, national identity number or other proof of identity where relevant; social media or creator identity; and other identifying information you provide.
6.3Contact Data. Billing address; home address; city, postcode and country; email address; phone and mobile number; WhatsApp or messaging contact details; social media contact details; and the name, relationship and phone number of your next of kin or emergency contact.
6.4Account and Profile Data. Account information; passwords, which are stored in hashed form; login identifiers from Facebook or Google where you sign in that way; profile picture; interests and preferences; survey responses; and identifiers used by the systems we operate with, including our CRM, our support platform and our email platform.
6.5Booking and Transaction Data. Details of products and services purchased or requested; crew and cabin details; destination and week; prices, tourist tax and currency; payment status; deposit, refund and invoice records; referral source, affiliate code and attribution data; and related administrative records.
6.6We do not store full payment card numbers. Where we hold card information it is limited to the last four digits, the issuing range, and a token or hash used to identify the card. Full card details are processed by our payment service providers.
6.7Online Check-in Data. Before your trip we ask for information needed to run it safely and to allocate cabins and crew. This includes swimming ability, languages spoken, expected arrival time, cabin and sleeping preferences, sleep schedule, whether you snore, food and drink preferences, special occasions, and where required for travel, entry documentation such as vaccination or test records and destination-specific entry cards. It also includes health information, which is covered by section 7.
6.8Communications Data. Emails; phone call records and notes; SMS and WhatsApp messages; chat and in-app messages; guest support interactions; responses to forms; video interview invitations and status; feedback and complaints; and any other communications between you and us.
6.9Recruitment Data. If you apply for a role and are invited to complete a video interview through a third-party provider such as Hireflix, we may process your name, email address, phone number, role applied for and application identifier; invitation and completion status; video, audio, image and written responses; timestamps and interview metadata; assessment notes and recruitment decisions; and related technical information. We may also process availability, role preferences, work history, qualifications, licences and certifications, and screening information.
6.10Technical and Usage Data. IP address; device identifiers; browser type and version; operating system and platform; referral source; time zone and location data; cookie identifiers; page views; session information; interaction behaviour; page response times; errors; and similar technical information.
6.11Marketing Preference Data. Your preferences for receiving updates, promotions, newsletters and other communications; your channel preferences, including email and SMS; and records of your opt-in or opt-out choices and when they were made.
7.1Some of the information we ask for is special category data under data protection law. In particular, our online check-in asks about medical conditions, allergies, dietary requirements, accessibility needs, and in some destinations vaccination or test status.
7.2We ask for this information so that we can run your trip safely: so that your skipper and host know about a condition that may matter at sea, so that food can be provided safely, so that we can make reasonable arrangements for accessibility, and so that we can meet entry requirements at your destination.
7.3Our lawful basis. We process this information on the basis of your explicit consent, given when you provide it at check-in or at the time of booking. You do not have to provide it. If you choose not to, we may be unable to accommodate a requirement, and in some cases that may affect whether you can participate in part of the trip. Where it is necessary to protect your vital interests or those of another person, for example in a medical emergency, we may also rely on that basis. Where we need to establish, exercise or defend a legal claim, we may rely on that basis.
7.4You may withdraw your consent at any time by contacting us at info@day8.com. Withdrawing consent does not affect processing carried out before you withdrew it, and we may still need to retain a record where that is necessary for a legal claim or a legal obligation.
7.5Access to this information is restricted to those who need it to run your trip, including the relevant members of our Event Team and, where necessary for your safety, your skipper and host. We do not use it for marketing.
7.6We do not intentionally collect information about criminal convictions or offences unless this is necessary and lawful in connection with recruitment, safeguarding, compliance, insurance, or service delivery requirements.
8.1Directly from you. When you browse or use the Services; create an account; make an enquiry; submit a booking; make a payment or deposit; complete online check-in; join a mailing list; enter a competition; create or maintain a profile; apply for a role; complete a video interview; or contact us by any channel.
8.2Automatically. Through cookies and similar technologies, analytics tools, server logs, scripts and pixels, as described in our Cookie Policy.
8.3From third parties. Analytics providers; payment providers; technical, hosting and support providers; recruitment and video interview providers; marketing and communications providers; social media platforms; advertising networks; business partners; agents or lead bookers booking on your behalf; and publicly available sources where lawful.
9.1If you provide personal data about another person, including a fellow crew member or an emergency contact, you confirm that you have the right to provide it and that you have made that person aware of this Privacy Policy where appropriate.
10.1Where we need personal data by law, or under a contract or proposed contract with you, and you do not provide it, we may be unable to provide the relevant Services, process your booking, complete your application, or confirm your reservation, and we may have to cancel or decline the relevant service, request, booking or application.
11.1We will only use your personal data where permitted by law. Depending on the circumstances we may rely on:
12.1We may use your personal data to:
13.1We may send you marketing communications where permitted by law and in line with your preferences.
13.2You may receive marketing from us if you have requested information; made a booking; entered a competition; signed up for updates; created an account; or otherwise opted in.
13.3Where required by law, we will obtain your consent before sending marketing communications or before sharing your personal data with third parties for their own marketing purposes.
13.4You can opt out at any time using the unsubscribe link in the relevant message, in your account settings, or by contacting info@day8.com.
13.5Opting out of marketing does not stop service or application communications, including messages from your skipper or host about your trip.
14.1We use cookies and similar technologies. Non-essential cookies are set only with your consent. Details of the cookies we use, and how to change your choice, are in our Cookie Policy.
15.1We may monitor and record communications with you, including calls, chats, emails, SMS and messages, for quality assurance, training, dispute resolution, fraud prevention, service improvement, compliance, and to safeguard our legal rights.
15.2Where calls are recorded, payment card details and other highly sensitive information should not be intentionally captured.
16.1We use the following service providers, who process personal data on our behalf:
16.2We may also share personal data where reasonably necessary with: companies within our group; professional advisers, including legal, insurance, audit and accounting advisers; suppliers, subcontractors and partners involved in delivering your trip, including yacht charter companies, marinas, venues, transfer operators and ground handlers; the skippers, hosts and crew working on your trip, to the extent they need it to run it safely; insurers and claims handlers; regulators, public authorities, courts, tribunals and law enforcement where required or permitted by law; and actual or potential purchasers, investors, funders or advisers in connection with a merger, acquisition, restructuring, financing or asset sale.
16.3Where service providers process personal data on our behalf, we require them to process it only on documented instructions, to keep it secure, and to use it only for appropriate purposes.
16.4In some cases a third party receives your personal data as an independent controller in its own right, in which case its own privacy policy applies.
16.5This list changes as our systems change. The version published here is kept current, and you can ask us for the position at any time.
17.1Some of our service providers, systems, partners or group companies may process personal data outside the European Economic Area.
17.2Where we transfer personal data outside the EEA we take appropriate steps to ensure it remains protected, which may include relying on an adequacy decision of the European Commission, entering into Standard Contractual Clauses approved by the European Commission, or relying on another lawful transfer mechanism.
17.3Where personal data relating to individuals in the United Kingdom is transferred out of the United Kingdom, we rely on the corresponding UK mechanisms, including UK adequacy regulations or the International Data Transfer Agreement or Addendum.
17.4You can contact us for more information about these safeguards and to request a copy of them.
18.1We take appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
18.2These may include restricted access controls, system security and monitoring, secure hosting, encryption where appropriate, internal policies and access management, contractual protections with service providers, and procedures for handling incidents and breaches.
18.3No method of transmission over the internet or electronic storage is completely secure. You are responsible for taking reasonable steps to protect your own devices, passwords and communications.
19.1We maintain procedures for identifying, investigating and responding to personal data breaches.
19.2Where a breach is likely to result in a risk to your rights and freedoms, we will report it to the relevant supervisory authority within the time required by law. Where it is likely to result in a high risk to you, we will also tell you directly, without undue delay, and explain what happened, what we are doing about it, and what you can do to protect yourself.
20.1We keep personal data only for as long as reasonably necessary for the purposes in this Privacy Policy, including to meet legal, accounting, regulatory, tax, insurance and reporting requirements.
20.2As a general principle:
20.3We operate automated processes to delete or anonymise personal data once its retention period has passed.
20.4Where we anonymise personal data so that it can no longer be associated with you, we may use that information without further notice to you.
21.1Depending on your location and applicable law, you may have the right to:
21.2You can exercise some of these rights directly in your account, which offers a data export and an account deletion option. You can also contact us at info@day8.com and we will deal with any request.
21.3We may need to verify your identity before responding. We will respond within the time required by applicable law.
22.1If you have concerns about how we process your personal data, please contact us first at info@day8.com.
22.2You may also lodge a complaint with a supervisory authority. Our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, Sweden, imy@imy.se, imy.se.
22.3You may also complain to the supervisory authority where you live or work, or where you believe an infringement took place. In the United Kingdom that is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk.
23.1The Services may link to third-party websites, applications, social platforms, booking tools, payment tools or other external services. We do not control them and are not responsible for their privacy practices.
23.2When you leave our Services or use a third-party service, review that third party's own privacy information and terms.
24.1If you have any questions about this Privacy Policy, contact:
Day 8 AB
Beckholmsvägen 4
115 21 Stockholm
Sweden
Organisation number: 556765-8769
Email: info@day8.com