Privacy Policy
How Nirvoleta collects, uses, shares, and protects the information readers give us.
Revised: 2 September 2026
1. Scope of this notice
Nirvoleta operates as an editorial directory and enquiry service covering resort hotels and hospitality destinations. Protecting the personal information readers entrust to us, and being transparent about how it is handled, is a standing obligation across every part of the service.
What follows describes how Nirvoleta collects, structures, uses, shares, and secures your details as you navigate the catalogue, review destination ratings, set up a guest profile, or complete an accommodation request.
2. Information we collect
The following categories are collected so that we can provide accurate availability, verified editorial assessments, and reliable confirmations:
- Identity and contact details
- Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
- Stay preferences and requirements
- Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
- Billing verification records
- The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Nirvoleta systems.
- Device telemetry and technical metadata
- Your IP address, browser build, operating system, the page that referred you, time zone setting, device identifiers, and timestamps for page interactions.
3. Why we process, and on what basis
Nirvoleta processes records only where a recognised legal basis applies: performance of a contract, legitimate business interest, compliance with a statutory duty, or your explicit consent. The operational purposes are:
- Enquiry fulfilment
- Transmitting itinerary details to the partner resort so a room hold and arrival preparations can be arranged.
- Editorial personalisation
- Presenting hospitality rankings and reviews aligned with the regions and property categories you browse.
- Protecting the service
- Defending the platform's infrastructure, checking that submissions are genuine, and protecting profiles from unauthorised access.
- Service messages
- Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
- Statutory adherence
- Fulfilling financial disclosure rules, tax obligations, and other legal mandates that apply to our operations.
4. Who receives your information
Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:
- The hotels themselves
- Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
- Accredited payment intermediaries
- Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
- Hosting and cloud services
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Authorities where the law requires
- Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.
5. Cookies and analytics
We use cookies and local storage to recognise returning readers, retain display preferences, measure performance, and keep sessions intact. Browser settings give you full control over these, though disabling essential cookies will limit parts of the enquiry process.
6. Security and retention
We apply multi-layered administrative, technological, and physical defences — TLS 1.3 transport encryption, AES-256 storage encryption, separated database clusters, and access limited by role — to guard against unauthorised access, loss, or alteration.
Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.
7. Your rights
Depending on where you live, and after identity verification, you can exercise these rights:
- Right of access
- Receive a copy of the data we hold about you, in a portable form, along with an explanation of its use.
- Correction
- Request prompt correction of profile information that is wrong, partial, or out of date.
- Erasure
- Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
- Restriction
- Pause processing activity while a record's accuracy or our legitimate interest is under review.
Opt-out and your choices
You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:
- Data sharing and sale
- Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
- Tracking technologies
- Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
- Marketing communications
- Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
- Withdrawal of consent
- Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.
8. Revisions
We may update this notice as regulations or our systems change. Significant revisions are published here with a fresh effective date; continuing to use the site afterwards signifies acceptance.