Privacy Policy of Message at Sea
pursuant to Articles 12, 13 and 14 of Regulation (EU) 2016/679 – GDPR
Version: 14 August 2026
This is an unofficial English translation provided for convenience. The Italian version is the legally binding text and prevails in case of any discrepancy.
1. Data Controller
The Data Controller is:
LAB421 SRL
Via Monte Magno, 1
84020 Palomonte (SA) – Italy
VAT No. 06050190658
REA SA-493447
Share capital € 10.000,00
General email: wow@lab421.com
Privacy: privacy@messageatsea.com
Support: support@messageatsea.com
Reports: abuse@messageatsea.com
PEC: lab@pec.lab421.com
2. Fundamental principle: anonymous to other users, not to Message at Sea
Message at Sea allows two people who do not know each other to meet online without the Platform automatically communicating their respective personal data.
Only the alias is shown to other users.
First name, last name, email address, telephone number, date of birth, place of residence and other account data are not shown to the other participants.
In order to provide the service and protect users from abuse, LAB421 must nevertheless know and process certain information relating to registered persons.
The anonymity offered by Message at Sea must therefore be understood as reciprocal anonymity between users, not as anonymity with respect to the operator of the Platform.
3. Data collected during registration
At the time of registration, the following may be collected:
- first name;
- last name;
- alias;
- date of birth;
- declared sex/gender, if provided;
- Municipality/Province or Region/State of habitual residence;
- email address;
- telephone number;
- password stored exclusively in cryptographically protected/hashed form;
- date and time of acceptance of the Terms;
- declaration of being of legal age (18+);
- email address verification;
- telephone number verification;
- any consent to the newsletter.
We do not ask, in the current registration process, to upload an identity document.
The sex/gender field is used exclusively for internal statistical analysis and is not shown to other users.
4. Legal age (18+)
Message at Sea is reserved for users who have reached the age of 18.
The date of birth and the declaration of being of legal age (18+) are used to prevent the registration of users who declare an age below 18.
Email and telephone number are verified respectively via a confirmation link and an OTP code.
These systems verify the availability of the respective contact details, but do not certify the declared personal identity.
5. Data relating to invites
When a user creates or manages an invite, we may process:
- QR Code identifier;
- title;
- message text;
- category;
- any place noted by the user;
- creation date;
- date or indication relating to the moment it was left;
- QR Code status;
- deactivation;
- scans;
- acceptance;
- link with the user who created it and, after acceptance, with the resulting contact.
The texts of the invites may be retained to enable the operation of the service, reconstruct the user's history and manage any reports or abuse.
6. Contacts, appointments and activities on the Platform
We may process data relating to:
- contacts created through an invite;
- appointment proposals;
- appointment confirmations;
- accesses to the video call page;
- technical initiation of the call;
- conclusion of the contact;
- use of End contact;
- blocks;
- reports;
- reason and notes associated with a report.
Message at Sea does not currently have a text chat between users.
7. Video calls
Video calls are end-to-end encrypted: audio and video travel directly between the participants' browsers or, when a direct connection is not technically possible, through a LAB421 relay server that receives only encrypted traffic and cannot decrypt it. In no case does Message at Sea record, listen to or view the content of conversations.
To establish the connection, technical data (for example IP addresses and ports) is temporarily processed, automatically deleted within 2 hours. Video calls rely exclusively on LAB421 infrastructure: no technical data, including IP addresses, is sent to external providers.
The technical events of the start and end of calls may be recorded in the security logs described in the following section, for security and abuse-management purposes.
8. Technical and security data
During use of the Platform, the following may be processed:
- IP address;
- date and time;
- user-agent;
- browser;
- operating system;
- device type;
- URL or function used;
- events relating to login, verifications, appointments, calls and sensitive operations;
- information necessary to prevent spam, fraud, abusive access and violations.
The full IP addresses present in the security logs are not used to be shown to other users.
Anti-bot protection
Registration is protected by an anti-bot check performed entirely on our servers, without external CAPTCHA services and without sending data to third parties.
9. Approximate geolocation
Message at Sea does not use the device's GPS position for the statistics described in this Privacy Policy.
The IP address may be used temporarily to derive an approximate location, for example:
- Country;
- Region;
- Province/equivalent area;
- approximate city.
Geolocation is performed on the server using a local copy of the MaxMind GeoLite2 database.
The IP address is not sent to MaxMind to perform the lookup.
Analytics events store the derived geographical data and not the full IP address.
IP geolocation is approximate and may prove inaccurate.
10. Statistics on the use of Message at Sea
LAB421 analyses the use of the Platform to understand its functioning and development.
Statistics may concern, for example:
- QR Codes generated;
- QR Codes scanned;
- people who read an invite without registering;
- registrations originating from the scan;
- accepted and non-accepted invites;
- appointments;
- video calls;
- invite category;
- approximate geographical distribution;
- declared sex/gender;
- age ranges;
- combinations between age ranges and sex/gender of users who create a contact.
These analyses also serve to understand whether Message at Sea is actually used as a social platform capable of creating meetings between people differing in age and sex/gender, or whether different usage patterns emerge.
For historical analyses LAB421 may transform the data into aggregated and anonymous statistics, for example age range, sex/gender, invite category, period and geographical area.
When the anonymisation process renders persons no longer identifiable, such statistics are no longer personal data and may be retained without a predetermined time limit.
11. Cookies and identifiers
Message at Sea uses strictly necessary technical cookies, including:
sessionid
Necessary to maintain the user's session.
csrftoken
Necessary to protect the service from fraudulent requests of the CSRF type.
These tools are necessary for the functioning of the service and do not require prior consent.
mas_vid (analytics, only with consent)
Message at Sea uses a random first-party identifier (cookie mas_vid, duration 12 months) to measure the use of the Platform and reconstruct, when permitted, the path:
scan → registration → acceptance → appointment → video call.
The mas_vid cookie is set only after acceptance in the cookie preferences. In the event of refusal or no choice, no persistent identifier is set and no individual analytics events are recorded.
Without analytics consent Message at Sea may only perform aggregate measurements or technical/statistical processing that does not involve persistent individual tracking of the user, within the limits permitted by the applicable legislation.
Consent may be modified or revoked at any time through the privacy preferences.
12. Purposes and legal bases
A. Account creation and management
Purpose: registration, authentication, email and telephone verification, account management and provision of the requested functionalities.
Legal basis: performance of the contract and pre-contractual measures requested by the user, Art. 6(1)(b) GDPR.
B. Legal age (18+) verification and user protection
Purpose: application of the 18+ rule, community safety and prevention of non-permitted uses.
Legal basis: performance of the service and legitimate interest of LAB421 and of users in the security of the Platform, Art. 6(1)(b) and (f) GDPR, according to the processing concerned.
C. Management of QR, contacts, appointments and video calls
Purpose: provision of the functions requested by the user.
Legal basis: Art. 6(1)(b) GDPR.
D. Security, anti-fraud and abuse prevention
Purpose: protection of accounts and infrastructure, anti-bot checks, countering abusive behaviour, management of reports and prevention of the repetition of serious violations.
Legal basis: legitimate interest of LAB421 and of users in the security of the service, Art. 6(1)(f) GDPR; any legal obligations, Art. 6(1)(c).
E. Moderation and management of illegal content
Purpose: enforcement of the Terms, management of reports, removal of content and compliance with the obligations provided by the legislation applicable to digital services.
Legal basis: legal obligations, Art. 6(1)(c) GDPR, and legitimate interest in the secure management of the service, Art. 6(1)(f).
F. Internal statistics and service improvement
Purpose: understanding how Message at Sea is used, measuring conversions, meeting types, distribution by age range, sex/gender, category and geographical area.
Legal basis: legitimate interest of LAB421 in evaluating and improving its service, Art. 6(1)(f) GDPR, when the analyses can be performed without tracking tools subject to consent.
When cookies or persistent identifiers are used for which the legislation requires consent, the legal basis is consent, Art. 6(1)(a) GDPR and the legislation applicable to terminal devices.
G. Newsletter
Purpose: sending news and communications relating to Message at Sea.
Legal basis: optional consent, Art. 6(1)(a) GDPR.
Failure to subscribe to the newsletter does not prevent use of the service.
Consent may be revoked at any time by writing to privacy@messageatsea.com.
H. Protection of rights
Purpose: establishment, exercise or defence of a right of LAB421 or of third parties.
Legal basis: legitimate interest, legal obligations and other bases provided by the applicable legislation.
13. Provision of data
Email, telephone number, date of birth, declaration of being of legal age (18+) and the other information indicated as mandatory during registration are necessary to create the account.
Failure to provide them prevents registration.
Consent to the newsletter is always optional.
The sex/gender field also provides the option “I prefer not to say”. Failure to indicate it does not prevent use of the service.
14. Who can access the data
The data may be processed by:
- LAB421 administrators;
- expressly authorised and instructed personnel;
- technicians responsible for managing the infrastructure, within the necessary limits;
- providers acting as Data Processors under Art. 28 GDPR;
- public, judicial or police authorities in the cases provided for by law.
Access to abuse reports is limited to administrators and to persons specifically authorised to manage security and moderation.
15. Providers and recipients of the data
To provide the service LAB421 makes use of external providers for hosting and server infrastructure (Germany/EU) and email delivery (Italy), which process the data within the limits necessary to provide their respective services and are appointed as Data Processors under Art. 28 GDPR. The updated list of Data Processors may be requested by writing to privacy@messageatsea.com.
Telephone number verification via SMS, video calls, anti-bot protection and IP-based geolocation are managed on own infrastructure: the related data is not communicated to third parties.
16. Transfers outside the European Economic Area (EEA)
Users' personal data is currently not transferred outside the European Economic Area (EEA).
Should LAB421 in the future make use of providers involving transfers to third countries, it will use the mechanisms provided for by Chapter V GDPR (adequacy decisions, EU-US Data Privacy Framework or standard contractual clauses), updating this Privacy Policy.
Further information may be requested by writing to privacy@messageatsea.com.
17. Retention periods
LAB421 applies different periods according to the purpose.
Account data
Retained for the duration of the account.
After deletion they are deleted or anonymised, except for data necessary for legal obligations, security, abuse management or protection of rights.
Messages and invites
Retained during the life of the account and according to the needs of the service.
After deletion they are deleted, unless they must be retained for a report, dispute or legal obligation.
Video call signalling
Maximum 2 hours.
Anti-bot checks
The cryptographic fingerprints (hashes) of successful anti-bot checks are automatically deleted shortly after the expiry of each check (20 minutes).
Ordinary web logs
As a rule maximum 30 days, except for security needs relating to a specific event.
Audit and security logs with full IP
Maximum 12 months, unless an event must be retained longer because it is connected to a report, investigation, dispute or proceeding.
Individual analytics events
Maximum 18 months.
Once the period has elapsed, they are deleted or transformed into anonymous aggregated data.
Analytics visitor identifiers
Deleted or anonymised when no longer necessary and in any case in accordance with the retention provided for analytics events.
Reports and abuse files
As a rule 24 months from the closure of the report.
In case of particularly serious violations, recidivism, disputes or legal-protection needs, the strictly necessary data may be retained longer according to documented criteria.
Data necessary to prevent the repetition of serious abuse
May be retained, preferably in pseudonymised or cryptographically derived form, for the duration of the suspension or ban measure and subjected to periodic review.
Newsletter
Until consent is revoked.
Proof of consent and of the subsequent revocation may be retained for the period necessary to demonstrate compliance with legal obligations.
Backups
Ordinary backups are retained for 14 days.
Anonymous statistics
Statistical results that are genuinely anonymised and from which it is not reasonably possible to identify a person may be retained without a predetermined time limit.
18. Account deletion
The user may request deletion of their account by writing to privacy@messageatsea.com.
Deletion takes place through irreversible anonymisation of the account and entails:
- deactivation of the QRs still active;
- deletion of personal data and contact details (email, telephone number);
- cessation of access to the account;
- content already exchanged remains visible to the counterparties exclusively under the alias, without references to personal data;
- the telephone number becomes usable again for a new registration, unless it is subject to anti-abuse measures.
Deletion does not necessarily entail the immediate removal of copies present in backups, which are deleted according to the normal retention cycle.
In the event of a report, abuse, dispute or legal obligation, LAB421 may retain exclusively the data necessary for that specific purpose.
19. Rights of the data subject
In the cases provided for by the GDPR the user may exercise:
- right of access;
- right to rectification;
- right to erasure;
- right to restriction of processing;
- right to data portability;
- right to object to processing based on legitimate interest;
- right to withdraw consent at any time;
- right to lodge a complaint with a supervisory authority.
Requests may be sent to:
privacy@messageatsea.com
LAB421 responds within the time limits provided by the applicable legislation.
The withdrawal of consent does not affect the lawfulness of the processing carried out before the withdrawal.
20. Objection to statistics based on legitimate interest
Where individual statistical processing is based on legitimate interest, the user may exercise the right to object in the cases provided for by Art. 21 GDPR.
Statistics already transformed into effectively anonymous data cannot be traced back to the user and no longer constitute personal data.
21. Complaint to the Garante
The user may lodge a complaint with the competent supervisory authority.
For LAB421, the relevant authority is:
Garante per la protezione dei dati personali (Italian Data Protection Authority)
The other forms of protection provided for by the GDPR remain unaffected.
22. Security
LAB421 adopts technical and organisational measures proportionate to the risks of the processing.
Among the measures currently used are, among others:
- HTTPS/TLS connections;
- passwords stored by means of a secure hashing algorithm;
- email verification;
- OTP telephone verification;
- anti-bot protection at registration;
- separation between account data and the identity shown to other users;
- encrypted peer-to-peer video calls;
- logging of security events;
- control of administrative access;
- backups;
- blocking and reporting systems.
However, no computer system can guarantee a level of risk equal to zero.
23. Automated decisions
Message at Sea does not currently use exclusively automated decision-making processes that produce legal effects on the user or affect them in a similarly significant way.
Any automated tools used to identify potentially problematic content do not, on their own, entail definitive decisions on the user, except for temporary technical measures necessary for security.
24. Changes to this Privacy Policy
This Privacy Policy may be updated as a result of regulatory, technical or organisational changes.
The most recent version is published on the Platform.
When a change significantly affects the processing of registered users' data, LAB421 will provide adequate information as required by the applicable legislation.
25. Privacy contacts
For any question relating to the processing of personal data:
privacy@messageatsea.com
PEC:
lab@pec.lab421.com