Privacy Policy
How Sorvantia collects, uses, shares, and protects the information readers give us.
Last revised: 2 September 2026
1. What this notice covers
Sorvantia operates as an editorial directory and enquiry service covering resort hotels and hospitality destinations. Protecting the personal information readers entrust to us, and being transparent about how it is handled, is a standing obligation across every part of the service.
What follows describes how Sorvantia collects, structures, uses, shares, and secures your details as you navigate the catalogue, review destination ratings, set up a guest profile, or complete an accommodation request.
2. Categories of information gathered
To return accurate availability, verified assessments, and reliable enquiry confirmations, we handle several categories of record:
- Who you are and how to reach you
- Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
- Reservation preferences
- Check-in and check-out dates, room type and bedding choice, suite tier, dietary requirements, accessibility needs, and hotel loyalty references.
- Billing and payment confirmation records
- The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Sorvantia systems.
- Technical metadata
- Your IP address, browser build, operating system, the page that referred you, time zone setting, device identifiers, and timestamps for page interactions.
3. Lawful bases and purposes
Processing takes place only under an established lawful ground — contractual necessity, legitimate interest, legal obligation, or consent you have given. Those grounds support the following purposes:
- Passing on your request
- Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
- Content customisation
- Shaping featured rankings and travel guidance around your preferred destinations and resort types.
- Security and verification
- Keeping the infrastructure secure, verifying that requests are legitimate, and preventing unauthorised access to reader profiles.
- Operational communication
- Delivering enquiry acknowledgements, booking references, travel reminders, and critical service messages.
- Statutory adherence
- Satisfying accounting disclosure, tax reporting, and other duties imposed by the jurisdictions in which we operate.
4. Who receives your information
There is no sale, rental, or leasing of personal identifiers to unrelated commercial entities. Disclosures occur strictly under contractual protection to the parties below:
- Partner properties
- Listed hotels receive the minimum needed — name, travel dates, and room requirements — to process your request.
- Certified payment gateways
- Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
- Hosting and cloud services
- Enterprise-grade data centres and delivery networks store encrypted backups to maintain uptime and disaster resilience.
- Courts and regulators
- We disclose where compelled by subpoena, court order, or statutory mandate, or where vital individual interests are at stake.
5. Digital identifiers and measurement
Cookies and browser storage let us recognise repeat visitors, remember currency and layout preferences, evaluate site performance, and preserve session integrity. You retain complete control through your browser, but switching off essential cookies degrades enquiry functionality.
6. Storage protection and retention
Protection is layered across administrative, technical, and physical measures: encrypted transport under TLS 1.3, AES-256 encryption at rest, isolated database clusters, and credentials restricted by role.
We retain data only for the time required to fulfil the request, handle follow-up questions, meet audit standards, or comply with a retention schedule set in law. After that, records are deleted or anonymised beyond recovery.
7. Individual rights
Subject to verification of your identity and the law in your jurisdiction, you may exercise the following:
- Right of access
- Obtain a portable copy of the personal records we hold and confirm how they are being handled.
- Right to correction
- Request prompt correction of profile information that is wrong, partial, or out of date.
- Erasure
- Ask for records to be deleted where no statutory or contractual basis for keeping them remains.
- Right to restrict processing
- Restrict our use of your data during any dispute over accuracy or over our grounds for processing.
Opt-out and your choices
Control over the collection and use of your personal information rests with you. Where local law provides for it, the following choices apply:
- Data sharing and sale
- Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
- Cookies and tracking
- Cookies and similar tracking tools can be managed or declined via your browser configuration or the consent controls published on this website.
- Marketing communications
- Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
- Withdrawal of consent
- Consent given earlier can be withdrawn whenever you choose, without affecting the lawfulness of any processing that took place while the consent was in force.
Requests to exercise these rights, or to opt out, can be sent to [email protected] or submitted through our contact form.
8. Revisions
This notice may be refined periodically in line with legal or architectural change. Any material modification is reflected on this page with an updated date, and further use of the service constitutes acknowledgement.