Privacy Policy
How Bervolta collects, uses, shares, and protects the information readers give us.
Current as of: 2 September 2026
1. What this notice covers
Bervolta publishes hospitality reviews and passes reservation enquiries to properties. Guarding personal data and explaining our handling of it clearly is an obligation we hold across all reader touchpoints.
Below we explain the categories Bervolta gathers, the purposes they serve, the parties they may reach, and the safeguards applied — whether you are reading rankings, creating a profile, or sending a stay enquiry.
2. Information we collect
Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:
- Personal identity and contact information
- Your name, title, language preference, country or region, email contact, and telephone details provided during profile creation or enquiry submission.
- Travel and room requirements
- Arrival and departure dates, room and bed configuration, suite category, dietary notes, accessibility requests, and any loyalty membership reference.
- Payment verification data
- Cardholder name, truncated card indicators, billing address, and transaction confirmation tokens handled by accredited payment processors. Full card numbers are never stored on Bervolta servers.
- Technical and device data
- IP address, browser version, operating system, referring pages, time zone, device identifiers, and interaction timestamps.
3. Legal grounds and operational purposes
Bervolta processes records only where a recognised legal basis applies: performance of a contract, legitimate business interest, compliance with a statutory duty, or your explicit consent. The operational purposes are:
- Passing on your request
- Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
- Content customisation
- Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
- Fraud prevention and security
- Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
- Operational communication
- Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
- Meeting legal obligations
- Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.
4. Authorised disclosures
Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:
- The hotels themselves
- Resorts receive the guest name, dates, and accommodation specifics strictly necessary to respond to a request or honour a reservation.
- Payment processors
- Billing information travels encrypted to accredited payment gateways that maintain current PCI-DSS validation.
- Hosting and cloud services
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Legal and regulatory authorities
- We disclose where compelled by subpoena, court order, or statutory mandate, or where vital individual interests are at stake.
5. Cookies, storage, and analytics
We use cookies and local storage to recognise returning readers, retain display preferences, measure performance, and keep sessions intact. Browser settings give you full control over these, though disabling essential cookies will limit parts of the enquiry process.
6. Security and retention
Layered administrative, technical, and physical controls protect records against unauthorised access, loss, alteration, or extraction. These include TLS 1.3 in transit, AES-256 at rest, segregated database clusters, and role-restricted credentials.
Records are held only as long as needed to complete an enquiry, resolve a question, satisfy audit requirements, or meet a statutory retention period. Once that period ends, records are permanently erased or irreversibly anonymised.
7. Individual rights
Depending on where you live, and after identity verification, you can exercise these rights:
- Access and inspection
- Request a transferable copy of your stored records and verify our handling procedures.
- Right to correction
- Ask us to fix any record that is inaccurate, incomplete, or no longer current.
- Right to erasure
- Have your data removed once processing is no longer required by law or by the purpose it served.
- Right to restrict processing
- Restrict our use of your data during any dispute over accuracy or over our grounds for processing.
Your opt-out options
How your personal information is gathered and used remains under your control. Subject to your location and the applicable legislation, you may exercise these opt-outs:
- Sale or sharing of personal information
- You may opt out of the sale or sharing of your personal information with third parties where laws such as the CCPA/CPRA in California, or comparable legislation elsewhere, provide for it. While we do not sell personal information in the conventional sense, some data may be shared with trusted partners in order to provide or improve the service.
- Tracking technologies
- Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
- Marketing messages
- You can stop receiving promotional email or newsletters at any time by using the unsubscribe link in any message, or by contacting us directly.
- Withdrawal of consent
- Any consent you have given may be withdrawn at any point. Doing so does not render unlawful the processing that occurred before withdrawal.
Requests to exercise these rights, or to opt out, can be sent to [email protected] or submitted through our contact form.
8. Updates to this document
This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.