Data protection

Privacy Policy

How Norvineta collects, uses, shares, and protects the information readers give us.

Last updated: 2 September 2026

1. What this notice covers

Norvineta operates as an editorial directory and enquiry service covering resort hotels and hospitality destinations. Protecting the personal information readers entrust to us, and being transparent about how it is handled, is a standing obligation across every part of the service.

What follows describes how Norvineta collects, structures, uses, shares, and secures your details as you navigate the catalogue, review destination ratings, set up a guest profile, or complete an accommodation request.

2. What we collect through the service

Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:

Identity and contact details
Your name, title, language preference, country or region, email contact, and telephone details provided during profile creation or enquiry submission.
Stay preferences and requirements
Dates of travel, room configuration and category, bedding selection, dietary and accessibility requests, and loyalty programme identifiers.
Billing verification records
Cardholder identity, partial card indicators, billing address, and processor-issued confirmation tokens. At no point is a full card number retained on Norvineta infrastructure.
Technical and device data
IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.

3. Lawful bases and purposes

Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:

Enquiry fulfilment
Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
Content customisation
Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
Fraud prevention and security
Defending the platform's infrastructure, checking that submissions are genuine, and protecting profiles from unauthorised access.
Keeping you informed
Sending enquiry updates, confirmations, itinerary reminders, and necessary customer service notices.
Statutory adherence
Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.

4. Authorised disclosures

Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:

Hospitality partners
Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
Certified payment gateways
Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
Infrastructure providers
Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
Authorities where the law requires
We disclose where compelled by subpoena, court order, or statutory mandate, or where vital individual interests are at stake.

5. Cookies and analytics

Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.

6. Storage protection and retention

Protection is layered across administrative, technical, and physical measures: encrypted transport under TLS 1.3, AES-256 encryption at rest, isolated database clusters, and credentials restricted by role.

Retention lasts no longer than the enquiry, any related correspondence, audit obligations, or a statutory holding period demand. At expiry, records are erased permanently or anonymised irrevocably.

7. Rights and choices available to you

Depending on where you live, and after identity verification, you can exercise these rights:

Right of access
Request a transferable copy of your stored records and verify our handling procedures.
Rectification
Request prompt correction of profile information that is wrong, partial, or out of date.
Right to erasure
Request deletion of your records where we no longer have a legal reason to retain them.
Restriction
Restrict our use of your data during any dispute over accuracy or over our grounds for processing.

Opt-out and your choices

You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:

Sale or sharing of personal information
Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
Tracking technologies
Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
Marketing communications
Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
Consent withdrawal
Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.

Write to [email protected], or use the contact form on this site, to exercise any right or lodge an opt-out request.

8. Revisions

We may update this notice as regulations or our systems change. Significant revisions are published here with a fresh effective date; continuing to use the site afterwards signifies acceptance.