Last updated: 1 June 2026
Data we collect
When you make a booking we collect your name, email address, phone number, guest numbers, chosen date and time, pickup location and any notes you add, such as dietary or accessibility requirements.
We also collect basic technical data — pages viewed, device type and approximate region — to keep the site working and to understand which experiences people look for.
Why we use it
To confirm and deliver your booking, to share the details the operator needs to collect and guide you, to contact you about changes or cancellations, and to meet our legal and accounting obligations.
We do not sell your data, and we do not share it with anyone beyond the operator running your experience and the service providers that host our systems.
- • Contract performance: processing and delivering your booking
- • Legitimate interest: service messages, fraud prevention and site security
- • Legal obligation: tax and accounting records
- • Consent: marketing email, only if you opt in
How long we keep it
Booking records are retained for seven years to satisfy Cypriot accounting requirements. Marketing consent is kept until you withdraw it. Technical logs are kept for a short period only.
Your rights
Under the GDPR you can request access to your data, correction of inaccurate data, deletion where we have no overriding obligation to retain it, restriction of processing, portability, and you can object to processing based on legitimate interest.
To exercise any of these rights, email info@bluepaphos.com. We respond within 30 days. You also have the right to complain to the Office of the Commissioner for Personal Data Protection in Cyprus.
Cookies
We use essential cookies and local storage to remember your language choice and to keep a booking in progress. We do not use advertising cookies.
Security
Data is stored on managed, access-controlled infrastructure with encryption in transit. Access is limited to staff who need it to deliver your booking.