Privacy Charter and Data Governance
Effective Date: 27/08/2026
1. Scope of Data Governance
Clostavia operates as an editorial and digital reservation directory dedicated to showcasing premier accommodations and luxury hospitality destinations. We maintain a firm obligation toward safeguarding individual personal records and upholding strict standards of transparency across all customer touchpoints.
This document outlines how Clostavia collects, organizes, uses, transfers, and safeguards your individual details when you navigate our catalog, review destination ratings, create guest profiles, or complete accommodation bookings.
2. Information Gathered Through Our Services
To deliver accurate lodging availability, verified reviews, and seamless booking confirmations, we collect several categories of user records:
Personal Identity and Contact Details
Full name, professional title, preferred language, residential region, authorized electronic communication address, and telephone contact channels provided during account registration or inquiry submissions.
Reservation Preferences & Stay Requirements
Dates of arrival and departure, room configurations, suite categories, bed selections, dietary preferences, special accessibility requests, and hotel loyalty membership references.
Billing and Payment Verification Records
Cardholder identity, truncated account indicators, billing location, and transaction confirmation tokens processed through accredited and certified payment processing intermediaries. Full card numbers are never stored on Clostavia core servers.
Technical Metadata and Device Telemetry
Internet Protocol address, browser version, operating system environment, referring URLs, regional time zone settings, device identifiers, and page interaction timestamps.
3. Lawful Grounds and Operational Purposes
Clostavia processes guest records strictly within established legal justifications, including contractual execution, legitimate business interests, statutory compliance, and explicit customer consent. The primary operational objectives include:
- Booking Execution: Transmitting itinerary details directly to partner resort destinations to finalize room holds and arrival preparations.
- Editorial Customization: Personalizing featured hospitality rankings and travel reviews aligned with preferred destinations and resort styles.
- Security & Verification: Safeguarding digital infrastructure, verifying transaction legitimacy, and shielding users against unauthorized profile access.
- Service Communication: Providing reservation updates, booking vouchers, itinerary reminders, and critical customer service notifications.
- Regulatory Adherence: Fulfilling accounting disclosures, tax reporting rules, and legal mandates established by administrative jurisdictions.
4. Authorized Data Disclosures and Partner Integrations
We do not sell, rent, or lease personal identifiers to unaffiliated commercial entities. Data transfers occur strictly under contractual safeguards with designated third parties:
Partner Hospitality Properties
Selected resort destinations and luxury hotels receive guest names, arrival dates, and accommodation specifics strictly necessary to honor room reservations.
Accredited Payment Processors
Encrypted billing data is routed to certified financial gateways operating under modern PCI-DSS validation standards to complete checkout actions.
Infrastructure and Cloud Providers
Tier-1 data center facilities and content distribution networks host encrypted database backups to ensure platform uptime and disaster resilience.
Legal and Regulatory Authorities
Information may be disclosed where required by lawful subpoena, court order, or official mandate to safeguard vital individual interests.
5. Digital Identifiers and Analytics Preferences
Our portal utilizes digital cookies and local storage tokens to recognize returning visitors, preserve currency display preferences, evaluate website performance, and maintain active session integrity. Users retain total autonomy over cookie management through standard web browser configurations. Disabling essential cookies may impact certain reservation functionality.
6. Storage Safeguards and Retention Principles
We apply rigorous multi-layered administrative, technological, and physical defenses to insulate guest records against unauthorized access, loss, alteration, or unlawful extraction. Protective mechanisms encompass TLS 1.3 transport encryption, AES-256 data storage encryption, segregated database clusters, and role-restricted credential access.
Data is preserved only for the duration necessary to satisfy the booking itinerary, resolve customer inquiries, satisfy audit standards, or fulfill statutory retention schedules. Once the designated holding period expires, records are permanently erased or irrevocably anonymized.
7. Individual Rights and Choices
Guests maintain comprehensive control over their personal records under modern consumer data standards. Subject to jurisdictional verifications, you may exercise the following prerogatives:
Right of Access & Inspection
Obtain a portable copy of stored personal records and verify handling procedures.
Right to Rectification
Request prompt corrections for outdated, partial, or inaccurate profile information.
Right to Erasure
Request deletion of guest records when processing is no longer required by law.
Right to Restrict Processing
Limit processing activities while record accuracy or legitimate interests are audited.
Opt-Out and Your Choices
You have the right to control how your personal information is collected and used. Depending on your location and applicable laws, you may exercise the following opt-out choices:
- Data Sharing and Sale: You may opt out of the sale or sharing of your personal information with third parties, where applicable under laws such as the CCPA/CPRA in California or similar legislation in other jurisdictions. While we do not sell personal information in the traditional sense, some data may be shared with trusted partners to provide or improve our services.
- Cookies and Tracking: You can manage or refuse cookies and tracking technologies through your browser settings or by using the cookie consent tools provided on our website.
- Marketing Communications: You can opt out of receiving promotional emails or newsletters by following the unsubscribe link in any communication or by contacting us directly.
- Withdrawal of Consent: If you have previously provided consent to data processing, you may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights or make an opt-out request, please contact us at [email protected] or via our contact form.
8. Updates to this Document
Clostavia reserves the right to refine and update this charter periodically in accordance with regulatory updates or architectural revisions. Any material modifications will be reflected directly on this page with an updated effective date. Continued interaction with our portal following publication signifies acknowledgment of the amended provisions.