Privacy Policy
How Norvineta collects, uses, shares, and protects the information readers give us.
Last updated: 2 September 2026
1. What this notice covers
Norvineta operates as an editorial directory and enquiry service covering resort hotels and hospitality destinations. Protecting the personal information readers entrust to us, and being transparent about how it is handled, is a standing obligation across every part of the service.
What follows describes how Norvineta collects, structures, uses, shares, and secures your details as you navigate the catalogue, review destination ratings, set up a guest profile, or complete an accommodation request.
2. What we collect through the service
Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:
- Identity and contact details
- Your name, title, language preference, country or region, email contact, and telephone details provided during profile creation or enquiry submission.
- Stay preferences and requirements
- Dates of travel, room configuration and category, bedding selection, dietary and accessibility requests, and loyalty programme identifiers.
- Billing verification records
- Cardholder identity, partial card indicators, billing address, and processor-issued confirmation tokens. At no point is a full card number retained on Norvineta infrastructure.
- Technical and device data
- IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.
3. Lawful bases and purposes
Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:
- Enquiry fulfilment
- Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
- Content customisation
- Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
- Fraud prevention and security
- Defending the platform's infrastructure, checking that submissions are genuine, and protecting profiles from unauthorised access.
- Keeping you informed
- Sending enquiry updates, confirmations, itinerary reminders, and necessary customer service notices.
- Statutory adherence
- Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.
4. Authorised disclosures
Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:
- Hospitality partners
- Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
- Certified payment gateways
- Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
- Infrastructure providers
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Authorities where the law requires
- We disclose where compelled by subpoena, court order, or statutory mandate, or where vital individual interests are at stake.
5. Cookies and analytics
Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.
6. Storage protection and retention
Protection is layered across administrative, technical, and physical measures: encrypted transport under TLS 1.3, AES-256 encryption at rest, isolated database clusters, and credentials restricted by role.
Retention lasts no longer than the enquiry, any related correspondence, audit obligations, or a statutory holding period demand. At expiry, records are erased permanently or anonymised irrevocably.
7. Rights and choices available to you
Depending on where you live, and after identity verification, you can exercise these rights:
- Right of access
- Request a transferable copy of your stored records and verify our handling procedures.
- Rectification
- Request prompt correction of profile information that is wrong, partial, or out of date.
- Right to erasure
- Request deletion of your records where we no longer have a legal reason to retain them.
- Restriction
- Restrict our use of your data during any dispute over accuracy or over our grounds for processing.
Opt-out and your choices
You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:
- Sale or sharing of personal information
- Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
- Tracking technologies
- Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
- Marketing communications
- Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
- Consent withdrawal
- Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.
Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.
8. Revisions
We may update this notice as regulations or our systems change. Significant revisions are published here with a fresh effective date; continuing to use the site afterwards signifies acceptance.