Privacy Policy

Effective date: May 2026 — Version 1.1

At Naora, discretion is not just a principle — it is part of the experience. This Privacy Policy explains how Redwind BV (“Naora”, “we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you interact with our website, apply for membership, participate in journeys, or use any of our services.

This policy applies to all current and prospective members, visitors to naora.world, and anyone who contacts us directly. It should be read alongside our Terms & Conditions.

Naora operates in full compliance with applicable data protection legislation, including the General Data Protection Regulation (GDPR) as applicable in the Netherlands and the European Union.

1. Who We Are

The data controller responsible for your personal data is:

Redwind BV — operating as Naora

Email: [email protected]

Website: naora.world

Registered in the Netherlands under Dutch company law.

If you have any questions about how we handle your data, you can contact us at any time at [email protected].

2. What Data We Collect

2.1 Information You Provide Directly

We collect personal data that you voluntarily provide when you:

— Apply for membership or respond to an invitation

— Complete onboarding or health documentation

— Book a journey segment or communicate scheduling preferences

— Contact us via email, WhatsApp, or any other channel

— Create or use a member account on our platform

This may include:

— Full name, date of birth, nationality

— Email address, phone number, postal address

— Passport details and visa information (for travel logistics)

— Health and physical readiness information (where relevant to participation)

— Emergency contact details

— Payment and billing information (processed via secure third-party providers)

2.2 Information Collected Automatically

When you visit naora.world, we may automatically collect certain technical data, including:

— IP address and browser type

— Device and operating system information

— Pages visited, time spent on pages, and referring URLs

— Cookie and tracking data (see Section 7)

2.3 Information from Third Parties

In some cases, we may receive information about you from third parties — for example, from an existing member who refers or recommends you, or from payment processors in connection with a transaction. We handle all such data in accordance with this policy.

3. How We Use Your Data

3.1 Legal Bases for Processing

Under the GDPR, we process your personal data on the following legal bases:

— Contract performance: To administer your membership, process bookings, and deliver the services you have signed up for.

— Legal obligation: To comply with applicable laws, including immigration requirements, financial regulations, and tax obligations.

— Legitimate interests: To operate and improve our services, ensure the safety of persons aboard, and communicate relevant updates — provided these interests are not overridden by your rights.

— Consent: For optional communications such as newsletter updates or marketing content, where we have obtained your explicit consent.

3.2 Specific Uses

We use your personal data to:

— Process and manage your membership application and account

— Confirm and coordinate journey segment bookings

— Arrange travel logistics, including visa and port documentation

— Communicate with you regarding your participation, schedule changes, and relevant updates

— Process payments and manage escrow arrangements

— Ensure the health, safety, and wellbeing of all persons aboard

— Comply with legal and regulatory requirements

— Improve our platform, services, and member experience

— Send you communications you have consented to receive

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.

4. How We Share Your Data

4.1 We Do Not Sell Your Data

Naora does not sell, rent, or trade your personal data to third parties for commercial or marketing purposes. Your information is not shared with advertisers or data brokers.

4.2 Operational Sharing

We may share your data with trusted third parties strictly where necessary to operate our services, including:

— Payment processors and escrow providers — to handle membership fees and journey payments securely.

— Port authorities, immigration services, and customs agencies — where required by law for vessel arrivals and departures.

— Visa and travel documentation services — to assist with entry requirements for specific destinations.

— Medical or emergency services — in the event of a health emergency aboard, where disclosure is necessary to protect your vital interests.

— IT and platform service providers — who assist in operating and maintaining the Naora member platform, under strict data processing agreements.

4.3 Legal Disclosure

We may disclose personal data where required to do so by law, court order, or at the request of a competent regulatory authority. We will notify you of such requests where legally permitted to do so.

4.4 Business Transfers

In the event of a merger, acquisition, or transfer of Naora’s business or assets, your personal data may be transferred as part of that transaction. You will be notified in advance if such a transfer affects the way your data is processed.

5. Data Retention

We retain your personal data only for as long as is necessary to fulfil the purposes outlined in this policy, or as required by law. The specific retention periods we apply are:

— Active membership data: Retained for the duration of your membership and for a period of 5 years thereafter, to comply with contractual, financial, and legal obligations.

— Health and safety records: Retained for the duration of your participation and up to 3 years after your last journey segment.

— Payment and financial records: Retained for 7 years in accordance with Belgian accounting and tax law.

— Enquiry and contact data: Retained for up to 2 years from the date of last contact if membership does not proceed.

— Website analytics data: Retained in anonymised or aggregated form.

When data is no longer required, it is securely deleted or anonymised.

6. Data Security

We take the security of your personal data seriously. Naora implements appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, destruction, or disclosure. These measures include:

— Encrypted storage and transmission of personal data

— Access controls limiting data access to authorised personnel only

— Secure third-party payment processing (Naora does not store full credit card numbers or sensitive financial credentials)

— Regular review of our security practices and service providers

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority as required by the GDPR.

7. Cookies & Tracking

7.1 What Are Cookies

Cookies are small text files placed on your device when you visit a website. They help us understand how visitors use our site and enable certain functionality to work correctly.

7.2 Cookies We Use

Naora’s website may use the following types of cookies:

— Essential cookies: Required for the website to function correctly, including member login sessions and security features. These cannot be disabled.

— Analytics cookies: Used to understand how visitors interact with our site (e.g. pages visited, time on site). We use this data in aggregated, anonymised form to improve our website.

— Preference cookies: Used to remember your settings and preferences for a better experience on return visits.

7.3 Managing Cookies

You can control and manage cookies through your browser settings at any time. Please note that disabling certain cookies may affect the functionality of our website. For more information on managing cookies, visit aboutcookies.org.

8. International Data Transfers

Naora is a global expedition operating across multiple continents. In the course of administering your membership and journey segments, your personal data may be transferred to or processed in countries outside the European Economic Area (EEA) — for example, to facilitate port clearances or visa applications in destinations along our route.

Where such transfers occur, we ensure that appropriate safeguards are in place in accordance with GDPR requirements, including the use of standard contractual clauses approved by the European Commission or reliance on adequacy decisions where applicable.

We will not transfer your data to countries or organisations that cannot provide an adequate level of protection for your rights.

9. Your Rights

Under the GDPR, you have the following rights in relation to your personal data:

— Right of access: You have the right to request a copy of the personal data we hold about you.

— Right to rectification: You have the right to request correction of any inaccurate or incomplete data we hold.

— Right to erasure: You have the right to request deletion of your personal data, subject to any legal obligations that require us to retain it.

— Right to restriction: You have the right to request that we limit the processing of your data in certain circumstances.

— Right to data portability: You have the right to receive your data in a structured, commonly used, machine-readable format and to transfer it to another controller.

— Right to object: You have the right to object to processing based on our legitimate interests, or to processing for direct marketing purposes.

— Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please contact us at [email protected]. We will respond to your request within 30 days. In complex cases, we may extend this by a further two months and will inform you accordingly.

If you believe that we have not handled your personal data in accordance with applicable law, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de Protection des Données) at dataprotectionauthority.be.

10. Children’s Privacy

Naora’s services are intended exclusively for adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have inadvertently collected data from a minor, we will delete it promptly. If you believe a minor has provided us with personal data, please contact us at [email protected].

11. Photography, Video & Member Discretion

Naora places the highest value on member privacy and discretion. No identifiable images, video, or personal information relating to a member will be used in any Naora marketing, social media, press material, or public communication without that member’s explicit written consent.

Naora’s crew may create editorial photography and video content aboard for brand and archival purposes. Members will be informed prior to any such content creation and may opt out at any time.

Members are reminded that sharing identifiable images or personal information about fellow members on any public platform — without the explicit consent of the individuals depicted — is prohibited under Naora’s Terms & Conditions and may also give rise to liability under applicable data protection law.

12. Third-Party Links & Services

Our website and platform may contain links to third-party websites or integrate with third-party services (such as payment processors, mapping tools, or social media platforms). Naora is not responsible for the privacy practices of these third parties.

We encourage you to review the privacy policies of any third-party services you use in connection with your Naora membership. This Privacy Policy applies solely to data collected and processed by Naora.

13. Updates to this Policy

Naora reserves the right to update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. When we make material changes, we will notify you by email to the address registered on your account, with a minimum of 30 days’ notice before the changes take effect.

The current version of this policy is always available at naora.world/privacy-policy. The date at the top of this page indicates when it was last updated.

14. Contact

For any questions, requests, or concerns regarding this Privacy Policy or the way we handle your personal data, please contact us:

Redwind BV — operating as Naora

Email: [email protected]

Website: naora.world

WhatsApp: via naora.world/contact

Member Login