Data protection

Privacy Policy

How Valpurena collects, uses, shares, and protects the information readers give us.

Last updated: 2 September 2026

1. Scope and application

As an editorial catalogue and booking-enquiry directory for premier accommodation, Valpurena takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.

This document sets out what Valpurena collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.

2. What we collect through the service

Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:

Who you are and how to reach you
Full name, form of address, preferred language, region of residence, email address, and any telephone number you supply when registering or submitting an enquiry.
Reservation preferences
Arrival and departure dates, room and bed configuration, suite category, dietary notes, accessibility requests, and any loyalty membership reference.
Billing verification records
Cardholder identity, partial card indicators, billing address, and processor-issued confirmation tokens. At no point is a full card number retained on Valpurena infrastructure.
Technical and device data
IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.

3. Legal grounds and operational purposes

Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:

Handling enquiries
Forwarding your stay details to the relevant property so it can respond on availability and prepare for arrival.
Content customisation
Shaping featured rankings and travel guidance around your preferred destinations and resort types.
Protecting the service
Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
Operational communication
Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
Meeting legal obligations
Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.

4. Authorised disclosures

Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:

Hospitality partners
Selected properties are given only the name, arrival dates, and room details required to answer an enquiry or hold a room.
Payment processors
Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
Infrastructure providers
Tier-1 data centres and content delivery networks hold encrypted backups so the service stays available and recoverable.
Courts and regulators
Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.

5. Cookies, storage, and analytics

Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.

6. Storage protection and retention

We apply multi-layered administrative, technological, and physical defences — TLS 1.3 transport encryption, AES-256 storage encryption, separated database clusters, and access limited by role — to guard against unauthorised access, loss, or alteration.

Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.

7. Rights and choices available to you

Depending on where you live, and after identity verification, you can exercise these rights:

Access
Request a transferable copy of your stored records and verify our handling procedures.
Right to correction
Have inaccurate, incomplete, or outdated details corrected without undue delay.
Right to erasure
Have your data removed once processing is no longer required by law or by the purpose it served.
Restriction
Pause processing activity while a record's accuracy or our legitimate interest is under review.

Opt-out and your choices

Control over the collection and use of your personal information rests with you. Where local law provides for it, the following choices apply:

Sharing and sale of your data
You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
Cookies and tracking
Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
Promotional email
Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
Consent withdrawal
Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.

To exercise any of these rights, or to make an opt-out request, please contact us at [email protected] or use our contact form.

8. Revisions

This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.