🔒 Privacy Policy

Last updated: 31 July 2026

Green Boat Engines ("we", "us", "our") respects your privacy and is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and Dutch data protection law (Uitvoeringswet Algemene verordening gegevensbescherming). This Privacy Policy explains in detail what information we collect, how we use it, who we share it with, and the rights you have over your data.

1. Who We Are

Green Boat Engines is the data controller responsible for the personal data collected through this website (greenboatengines.nl) and related services.

Company Name: Green Boat Engines
Registered Address: 3631 NP Nieuwersluis, Netherlands
VAT / BTW Number: NL001565913B83
KvK (Chamber of Commerce) Number: 12345678 (Amsterdam)
Email: help@greenboatengines.nl
Phone: +31 97005030370
Website: https://boatdistributiongmbh.com

We specialise in the sale, service, repair, and shipping of new and reconditioned marine engines, generators, and parts across the European Union. Because our business involves cross-border shipping, warranty administration, and technical service, we collect and process certain categories of personal data necessary to fulfil contracts, comply with legal obligations, and provide customer support.

If you have any questions about this Privacy Policy or how we handle your personal data, please contact our Data Protection contact using the details in Section 16.

2. What Data We Collect

We collect personal data that you provide directly to us, data we collect automatically when you use our website, and data we receive from third parties (such as payment processors and shipping partners). The categories of personal data we may collect include:

2.1 Identity and Contact Data

  • Full name (first name and surname)
  • Company name (if applicable, for B2B orders and fleet contracts)
  • Email address (primary and secondary, if provided)
  • Phone number (including country code for international customers)
  • Billing address (street, city, postal code, country)
  • Shipping/delivery address (if different from billing address, including marina or boatyard addresses)

2.2 Order and Transaction Data

  • Order history — products purchased, dates, quantities, prices, and order numbers
  • Payment confirmation data — transaction IDs, payment method type (card, bank transfer, iDEAL, PayPal), and payment status. We do not store full credit or debit card numbers on our servers.
  • Invoice and VAT records — required for Dutch tax law compliance
  • Customer account credentials — username and encrypted password (if you create an account)

2.3 Tax and Customs Data (for Cross-Border Orders)

Because we ship engines, parts, and equipment across the European Union and beyond, we may collect additional data required for customs clearance and tax compliance:

  • VAT identification number (BTW-nummer) — for business customers within the EU
  • EORI number (Economic Operators Registration and Identification) — required for delivery to customers outside the Netherlands, particularly for shipments to non-EU countries or customs-controlled territories
  • Country of residence / registered business — for determining applicable VAT rate and customs treatment

This data is collected solely for the purpose of fulfilling your order and complying with EU customs and tax regulations. It is not used for marketing or shared with unauthorised parties.

2.4 Service, Repair, and Warranty Data

  • Engine details — make, model, serial number, horsepower, year of manufacture, and hour meter reading
  • Service history — dates of service, work performed, parts fitted, technician notes, and test results
  • Fault descriptions and diagnostic reports — including compression readings, fault codes, and photographs taken during service
  • Warranty claims — claim dates, descriptions, supporting documentation, and resolution records
  • Appointment and scheduling data — preferred dates, service type, and technician assignments

2.5 Communication Data

  • Email correspondence — including enquiries, quotes, complaints, and support tickets
  • Contact form submissions — including the subject, message content, and any attachments
  • Phone call records — date, time, and notes taken by our customer service team (calls are not recorded without explicit consent)
  • Live chat transcripts — if you use our website chat function

2.6 Marketing and Preference Data

  • Marketing opt-in status — whether you have consented to receive newsletters, special offers, and product updates
  • Communication preferences — preferred language, preferred channel (email, SMS, phone)
  • Interest categories — engine type preferences (outboard, inboard, generator, electric) based on your browsing and purchase history, used only where you have opted in to personalised marketing

2.7 Technical and Usage Data (Collected Automatically)

When you visit our website, we automatically collect certain technical data through cookies, server logs, and analytics tools:

  • IP address (anonymised where possible for analytics)
  • Browser type and version (e.g., Chrome, Safari, Firefox)
  • Device type and operating system (desktop, mobile, tablet; Windows, macOS, iOS, Android)
  • Referring website (the site you came from before visiting ours)
  • Pages visited, time spent, and click paths — used to improve website usability and product offerings
  • Shopping cart contents and abandoned cart data — to help you complete your purchase
  • Cookie identifiers and session IDs — see Section 8 for full details

2.8 Data We Do NOT Collect

We do not collect or process:

  • Special categories of personal data (racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation), unless explicitly required by law for a specific and limited purpose.
  • Full payment card numbers or CVV codes — these are handled exclusively by our PCI-DSS compliant payment providers.
  • Social media passwords or third-party account credentials.

3. How and Why We Use Your Data

We use your personal data only for specific, lawful purposes. We do not use your data for purposes that are incompatible with the reasons you provided it, unless we have a separate legal basis to do so.

Purpose Data Categories Used Legal Basis
Processing and delivering your orders — including order confirmation, invoicing, payment processing, shipping coordination, and delivery tracking. Identity, contact, order, transaction, tax/customs data Performance of a contract (Art. 6(1)(b) GDPR)
Managing your customer account — account creation, login authentication, order history, saved addresses, and preferences. Identity, contact, account credentials, order history Performance of a contract (Art. 6(1)(b) GDPR)
Providing service, repair, and warranty support — scheduling appointments, performing diagnostics, maintaining service records, and processing warranty claims. Identity, contact, engine details, service history, communication data Performance of a contract / Legitimate interest (Art. 6(1)(b) & (f) GDPR)
Customer support and answering enquiries — responding to questions via email, phone, contact forms, and live chat. Identity, contact, communication data Legitimate interest (Art. 6(1)(f) GDPR)
Sending transactional communications — order confirmations, shipping updates, appointment reminders, service completion notices, and warranty status updates. Identity, contact, order/service data Performance of a contract / Legitimate interest (Art. 6(1)(b) & (f) GDPR)
Sending marketing communications — newsletters, special offers, new product announcements, and seasonal promotions (only with your explicit consent). Identity, contact, marketing preferences, interest categories Consent (Art. 6(1)(a) GDPR)
Improving our website and services — analysing usage patterns, identifying technical issues, A/B testing, and enhancing user experience. Technical and usage data (anonymised where possible) Legitimate interest (Art. 6(1)(f) GDPR)
Preventing fraud, abuse, and security incidents — detecting suspicious transactions, protecting against cyberattacks, and verifying identity for high-value orders. Identity, contact, transaction data, technical data Legitimate interest (Art. 6(1)(f) GDPR)
Complying with legal and tax obligations — maintaining accounting records, filing VAT returns, responding to legal requests, and cooperating with regulatory authorities. Identity, contact, order, transaction, tax/customs data Legal obligation (Art. 6(1)(c) GDPR)
Enforcing our terms and conditions — resolving disputes, pursuing legal claims, and protecting our rights and property. Identity, contact, order, communication data Legitimate interest (Art. 6(1)(f) GDPR)

5. How Long We Keep Your Data

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Our retention periods are as follows:

Data Category Retention Period Reason
Order and invoice records 7 years from the date of the transaction Dutch tax law (Wet op de omzetbelasting) requires retention of accounting records for 7 years.
Customer account data Until you request deletion, or 2 years of inactivity To allow you to view order history and reorder easily. After 2 years of inactivity, we will contact you before deletion.
Service and repair records 10 years from the date of service Marine engines have long lifespans; service history supports warranty claims, resale value, and safety recalls.
Warranty claim records 7 years from claim resolution To defend against future claims and support product liability requirements.
Marketing data and consent records Until you unsubscribe, or 3 years from last interaction To demonstrate compliance with consent requirements and respect your preferences.
Communication records (enquiries, support) 3 years from last contact To resolve disputes, provide continuity of support, and improve service quality.
Technical and usage data (analytics) 26 months (Google Analytics) or until cookie expiry Aggregated and anonymised after 26 months. Individual IP addresses are anonymised immediately.
Payment transaction data 7 years from transaction date Legal requirement for financial record-keeping and fraud investigation.
Cookie consent records 12 months from consent date To demonstrate compliance with cookie consent requirements under the ePrivacy Directive.

When the retention period expires, we securely delete or anonymise your data. If data is anonymised (stripped of identifiers), it may be retained indefinitely for statistical and research purposes, as it no longer constitutes personal data under GDPR.

6. Who We Share Your Data With

We do not sell, rent, or trade your personal data to third parties for marketing purposes. We share data only with trusted service providers who assist us in operating our business, and only to the extent necessary for them to perform their specific functions.

Category of Recipient Purpose Data Shared Location
Payment processors
Mollie B.V., Stripe, PayPal, iDEAL
To process payments securely and prevent fraud Name, billing address, order total, transaction ID, payment method type EU (Mollie, iDEAL); US (Stripe, PayPal — with Standard Contractual Clauses)
Shipping and logistics partners
DHL, DPD, FedEx, TNT, specialised marine freight carriers
To deliver engines, parts, and equipment to your specified address Name, shipping address, phone number, email (for delivery notifications), order contents, weight/dimensions EU and international (with appropriate safeguards)
Website hosting and IT providers
Cloud hosting, CDN, and backup services
To host our website, store data, and ensure security and availability All website data (stored on encrypted servers) EU (primary); US (backup — with Standard Contractual Clauses)
Email and communication platforms
Mailchimp, SendGrid, or similar
To send transactional emails (order confirmations, shipping updates) and marketing emails (with consent) Name, email address, order data, marketing preferences EU or US (with Standard Contractual Clauses)
Analytics and performance tools
Google Analytics, Hotjar, or similar
To analyse website traffic, user behaviour, and improve our services Anonymised IP address, browser data, page views, session duration (aggregated and non-identifiable) US (with Standard Contractual Clauses and IP anonymisation)
Accountants and tax advisors To comply with tax, accounting, and audit obligations Invoice data, transaction records, VAT numbers (aggregated and limited to necessary data) Netherlands
Legal advisors and insurers To defend legal claims, process insurance claims, and comply with legal obligations Relevant order, service, or communication data (limited to what is necessary for the specific matter) Netherlands / EU
Customs and tax authorities To comply with customs declarations, VAT obligations, and regulatory requirements EORI number, VAT number, invoice data, country of destination, product descriptions and values Relevant EU member states or non-EU countries (as required by law)

All third-party service providers are contractually bound by Data Processing Agreements (DPAs) under Article 28 GDPR. These agreements require them to process your data only on our instructions, maintain confidentiality, and implement appropriate security measures.

7. International Data Transfers

Our primary data storage and processing takes place within the European Economic Area (EEA). However, some of our service providers (such as payment processors, email platforms, and analytics tools) may process data in countries outside the EEA, including the United States.

Whenever we transfer personal data outside the EEA, we ensure that appropriate safeguards are in place to protect your data, in accordance with Chapter V of the GDPR:

  • Standard Contractual Clauses (SCCs): We use the EU Commission's Standard Contractual Clauses for transfers to countries without an adequacy decision, such as the United States. These clauses impose contractual obligations on the recipient to protect your data to EU standards.
  • Adequacy decisions: For transfers to countries that the European Commission has recognised as providing an adequate level of data protection (e.g., the United Kingdom, under the UK GDPR adequacy decision), no additional safeguards are required.
  • Technical measures: We require all international service providers to encrypt data in transit (TLS 1.2 or higher) and at rest (AES-256).

If you would like a copy of the Standard Contractual Clauses we use with any specific provider, please contact us (see Section 16).

8. Cookies and Tracking Technologies

We use cookies and similar technologies (such as web beacons, pixels, and local storage) to make our website work, remember your preferences, analyse traffic, and (where you consent) support marketing activities.

8.1 What Are Cookies?

Cookies are small text files placed on your device when you visit a website. They allow the website to recognise your device and store information about your preferences or past actions. Cookies can be "session cookies" (deleted when you close your browser) or "persistent cookies" (remain on your device for a set period or until you delete them).

8.2 Types of Cookies We Use

Category Purpose Examples Lifespan
Strictly Necessary Required for the website to function. Cannot be disabled. Shopping cart cookies, session authentication, security tokens, CSRF protection Session to 1 year
Functional / Preference Remember your choices and improve your experience. Language selection, currency preference, saved login details, recently viewed products 1 month to 1 year
Analytics / Performance Help us understand how visitors use our website so we can improve it. Google Analytics (_ga, _gid), Hotjar, page speed monitoring 24 hours to 26 months
Marketing / Advertising Track your browsing to show relevant ads and measure campaign effectiveness. Facebook Pixel, Google Ads conversion tracking, retargeting cookies 30 days to 1 year

8.3 Managing Your Cookie Preferences

When you first visit our website, you will see a cookie banner that allows you to:

  • Accept all cookies — enables all categories above
  • Reject non-essential cookies — enables only Strictly Necessary cookies
  • Customise preferences — choose which categories you accept

You can change your cookie preferences at any time by clicking the "Cookie Settings" link in the footer of our website. You can also manage cookies through your browser settings:

  • Chrome: Settings → Privacy and security → Cookies and other site data
  • Firefox: Settings → Privacy & Security → Cookies and Site Data
  • Safari: Preferences → Privacy → Cookies and website data
  • Edge: Settings → Cookies and site permissions → Manage and delete cookies

Please note that disabling certain cookies may affect the functionality of our website, such as remembering your cart contents or keeping you logged in.

8.4 Third-Party Cookies

Some cookies are set by third-party services integrated into our website (e.g., Google Analytics, Facebook Pixel, payment provider widgets). These third parties may collect data about your online activities over time and across different websites. We do not control these third-party cookies. Please refer to the privacy policies of the respective providers for more information:

9. Your Rights Under GDPR

Under the GDPR, you have the following rights regarding your personal data. These rights are free of charge, and we will respond to your request within one month (extendable to two months for complex requests). We may ask you to verify your identity before processing your request to prevent unauthorised access.

9.1 Right to Access (Art. 15 GDPR)

You have the right to request a copy of the personal data we hold about you, along with information about how we process it. This includes:

  • The categories of data we hold
  • The purposes of processing
  • The recipients or categories of recipients to whom the data has been disclosed
  • The retention period or criteria used to determine it
  • Your other rights (rectification, erasure, restriction, objection)
  • The source of the data (if not collected from you directly)
  • Whether automated decision-making is used

To request access, email help@greenboatengines.nl with the subject line "Data Access Request" and include proof of identity (a copy of your passport or ID card, with sensitive details such as your photo and ID number redacted if you prefer).

9.2 Right to Rectification (Art. 16 GDPR)

If the personal data we hold about you is inaccurate or incomplete, you have the right to request that we correct or complete it. You can update most information yourself through your customer account. For changes that require verification (such as billing address or VAT number), please contact us directly.

9.3 Right to Erasure ("Right to Be Forgotten") (Art. 17 GDPR)

You have the right to request that we delete your personal data in the following circumstances:

  • The data is no longer necessary for the purposes for which it was collected
  • You withdraw consent and there is no other legal basis for processing
  • You object to processing based on legitimate interests, and there are no overriding legitimate grounds
  • The data has been unlawfully processed
  • The data must be erased to comply with a legal obligation

However, this right is not absolute. We may be required to retain certain data to comply with legal obligations (e.g., tax records for 7 years), to establish or defend legal claims, or for reasons of important public interest. If we cannot fully erase your data, we will explain why and restrict processing instead.

9.4 Right to Restriction of Processing (Art. 18 GDPR)

You have the right to request that we restrict processing of your data in the following situations:

  • You contest the accuracy of the data (restriction lasts until we verify accuracy)
  • The processing is unlawful, but you oppose erasure and request restriction instead
  • We no longer need the data, but you require it to establish, exercise, or defend legal claims
  • You have objected to processing based on legitimate interests, pending verification of whether our interests override yours

When processing is restricted, we will only store the data and not use it for any other purpose, except with your consent or for legal claims.

9.5 Right to Data Portability (Art. 20 GDPR)

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format (such as CSV or JSON), and to transmit that data to another controller without hindrance. This right applies only to data processed based on consent or contract, and only where processing is carried out by automated means.

To request a portable copy of your data, email us with the subject line "Data Portability Request" and specify your preferred format.

9.6 Right to Object (Art. 21 GDPR)

You have the right to object to processing based on legitimate interests (including profiling) or for direct marketing purposes:

  • Direct marketing: You have an absolute right to object to processing for direct marketing purposes at any time. We will stop processing your data for marketing immediately upon receiving your objection.
  • Legitimate interests: You may object to processing based on our legitimate interests if you believe your fundamental rights and freedoms override those interests. We will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for legal claims.

To object, email us at help@greenboatengines.nl or use the unsubscribe link in any marketing email.

9.7 Right to Withdraw Consent (Art. 7(3) GDPR)

Where we process your data based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew consent. You can withdraw consent by:

  • Clicking the "unsubscribe" link in any marketing email
  • Adjusting your cookie preferences via our cookie banner
  • Contacting us directly at help@greenboatengines.nl

9.8 Right to Lodge a Complaint (Art. 77 GDPR)

If you believe we have violated your data protection rights, you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement. For the Netherlands, the supervisory authority is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Bezuidenhoutseweg 30
2594 AV Den Haag
Netherlands
Website: autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500

10. Automated Decision-Making and Profiling

We do not make decisions that produce legal effects or similarly significant effects concerning you based solely on automated processing (including profiling). All decisions that affect your rights, order status, or service outcomes are made by human beings.

We do use automated tools for the following non-decision-making purposes:

  • Fraud detection: Our payment providers use automated algorithms to detect potentially fraudulent transactions. If a transaction is flagged, a human reviews it before any action is taken.
  • Marketing segmentation: We may use automated tools to segment our email lists based on purchase history or browsing behaviour (e.g., customers who have viewed outboard engines may receive outboard-related offers). This is not profiling that produces legal or significant effects — it is simply targeted marketing, and you can opt out at any time.
  • Website personalisation: We may show you product recommendations based on your browsing history. These are suggestions, not decisions.

If we ever introduce fully automated decision-making that produces legal or significant effects, we will notify you in advance, explain the logic involved, and provide you with the right to contest the decision and request human intervention.

11. How We Protect Your Data

We take the security of your personal data seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. These measures include:

11.1 Technical Measures

  • Encryption in transit: All data transmitted between your browser and our website is encrypted using TLS 1.2 or higher (HTTPS). Look for the padlock icon in your browser address bar.
  • Encryption at rest: Sensitive data stored on our servers (including account credentials and order data) is encrypted using AES-256 encryption.
  • Secure hosting: Our website is hosted on ISO 27001-certified servers with redundant backups, firewalls, and intrusion detection systems.
  • Access controls: Personal data is accessible only to authorised personnel who need it to perform their job functions. Access is granted on a least-privilege basis and protected by multi-factor authentication (MFA).
  • Regular security updates: Our systems, software, and plugins are kept up to date with the latest security patches.
  • Password hashing: Account passwords are hashed using bcrypt or equivalent strong hashing algorithms. We cannot see or retrieve your password.
  • Payment security: We do not store full payment card details. All payment processing is handled by PCI-DSS Level 1 compliant providers (Mollie, Stripe, PayPal).
  • Penetration testing: We conduct annual penetration tests and vulnerability assessments by independent security firms.

11.2 Organisational Measures

  • Staff training: All employees who handle personal data receive GDPR and data security training upon joining and annually thereafter.
  • Confidentiality agreements: All staff and contractors sign confidentiality agreements that include data protection obligations.
  • Incident response plan: We have a documented data breach response plan. In the event of a breach that poses a risk to your rights and freedoms, we will notify the Dutch Data Protection Authority within 72 hours and inform you without undue delay.
  • Data minimisation: We collect only the data we need and review our data holdings regularly to delete unnecessary information.
  • Physical security: Our offices and workshop have controlled access, alarm systems, and secure storage for paper records.

While we take all reasonable steps to protect your data, no internet-based service can be guaranteed 100% secure. You are responsible for maintaining the confidentiality of your account password and for any activity that occurs under your account. If you suspect unauthorised access, please contact us immediately.

12. Children's Privacy

Our website and services are not directed at children under the age of 16, and we do not knowingly collect personal data from children. The sale and service of marine engines are activities intended for adults and boat owners who are legally capable of entering into contracts.

If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us immediately at help@greenboatengines.nl. We will delete the data as soon as we verify that it was provided by a child.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or technology. When we make significant changes, we will:

  • Update the "Last updated" date at the top of this page
  • Post a notice on our website homepage or send an email to registered customers (for material changes)
  • Update the cookie banner if changes affect cookie usage

We encourage you to review this Privacy Policy periodically. Your continued use of our website and services after any changes constitutes your acceptance of the updated policy. If you do not agree with the changes, you should stop using our services and contact us to close your account.

15. Complaints and Supervisory Authority

If you have a complaint about how we handle your personal data, we encourage you to contact us first so we can try to resolve the issue. You can reach our Data Protection contact at:

Data Protection Contact
Green Boat Engines
Email: help@greenboatengines.nl
Address: 3631 NP Nieuwersluis, Netherlands
Phone: +31 97005030370
Please mark your email with the subject line "Data Protection Complaint" for priority handling.

We will acknowledge your complaint within 5 business days and provide a full response within 30 days. If we cannot resolve your complaint to your satisfaction, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
Bezuidenhoutseweg 30, 2594 AV Den Haag, Netherlands
Website: autoriteitpersoonsgegevens.nl
Phone: +31 70 888 8500

16. Contact Us

If you have any questions about this Privacy Policy, how we handle your personal data, or if you wish to exercise any of your GDPR rights, please contact us using the details below:

Green Boat Engines — Data Protection

Address: 3631 NP Nieuwersluis, Netherlands
Email: help@greenboatengines.nl
Phone: +31 97005030370 (Mon–Fri 09:00–17:00 CET, Sat 09:00–13:00 CET)
VAT / BTW: NL001565913B83
Website: https://boatdistributiongmbh.com

For data protection enquiries, please include "Data Protection" or "GDPR" in your subject line for priority routing.

🔗 Related Policies

  • Cookie Policy — Detailed information about the cookies and tracking technologies we use.
  • Terms & Conditions — The legal terms governing your use of our website and services.
  • Disclaimer — Limitations of liability and important legal notices.
  • Copyright Notice — Intellectual property rights and permitted use of our content.
  • Contact Us — General enquiries, support, and service bookings.