Back

Privacy Policy

Effective Date: September 30, 2025
Last Updated: September 30, 2025

Introduction

Maya Villas (“we,” “our,” or “us”) operates the website https://www.maya-villas.com (the “Site”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data.

By using our Site and submitting information through our contact form, you agree to the collection and use of information in accordance with this Privacy Policy.

Information We Collect

Personal Information You Provide

When you submit a consultation request through our contact form, we collect the following personal information:

  • Name: Your first and last name
  • Email Address: Your email address for communication purposes
  • Phone Number: Your contact number (if provided)
  • Message Content: Any information you include in your consultation request
  • Inquiry Details: Information about your villa rental needs or questions

Automatically Collected Information

When you visit our Site, we may automatically collect certain technical information, including:

  • IP Address: Your device’s Internet Protocol address
  • Browser Type: The type and version of your web browser
  • Device Information: Information about your device and operating system
  • Usage Data: Pages visited, time spent on pages, and general navigation patterns
  • Cookies: Small data files stored on your device (see Cookies section below)

How We Use Your Information

We use the personal information we collect for the following purposes:

Primary Purposes

  • Respond to Inquiries: To respond to your consultation requests and provide information about our villa rental services
  • Communication: To contact you regarding your inquiry and follow up on your consultation request
  • Customer Service: To provide customer support and address your questions or concerns

Secondary Purposes

  • Service Improvement: To understand how visitors use our Site and improve our services
  • Legal Compliance: To comply with applicable laws, regulations, and legal processes
  • Business Operations: To maintain the security and integrity of our Site
  • Marketing: With your consent, to send you information about our services, special offers, and updates (you may opt out at any time)

Legal Basis for Processing (GDPR)

If you are located in the European Economic Area (EEA), our legal basis for collecting and using your personal information depends on the data concerned and the context in which we collect it:

  • Consent: You have given us explicit consent to process your personal information for a specific purpose
  • Legitimate Interests: Processing is necessary for our legitimate business interests (such as responding to your inquiry) and does not override your rights
  • Legal Obligation: Processing is necessary to comply with applicable laws

How We Share Your Information

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

Service Providers

We may share your information with trusted third-party service providers who assist us in operating our website and conducting our business, including:

  • Email service providers
  • Web hosting services
  • Analytics services
  • Customer relationship management (CRM) systems

These service providers are contractually obligated to protect your information and use it only for the purposes we specify.

Legal Requirements

We may disclose your information if required by law or in response to:

  • Legal processes (subpoenas, court orders)
  • Government or regulatory requests
  • Protection of our rights, property, or safety
  • Investigation of fraud or security issues

Business Transfers

If we are involved in a merger, acquisition, or sale of assets, your personal information may be transferred as part of that transaction. We will notify you of any such change.

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Specifically:

  • Consultation Requests: We retain your contact form submissions for up to 3 years or until you request deletion
  • Communication Records: Email correspondence is retained for up to 5 years for business record purposes
  • Technical Data: Most automatically collected data is retained for up to 2 years

After the retention period expires, we will securely delete or anonymize your personal information.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • Encryption of data in transit using SSL/TLS protocols
  • Secure server infrastructure with access controls
  • Regular security assessments and updates
  • Employee training on data protection practices
  • Restricted access to personal information on a need-to-know basis

However, please note that no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

Cookies and Tracking Technologies

Our Site may use cookies and similar tracking technologies to enhance your browsing experience and collect usage information.

Types of Cookies We Use

  • Essential Cookies: Required for the Site to function properly (e.g., form submission)
  • Analytics Cookies: Help us understand how visitors interact with our Site
  • Functional Cookies: Remember your preferences and settings

Managing Cookies

You can control and manage cookies through your browser settings. Please note that disabling cookies may affect the functionality of our Site. For more information about cookies, visit www.allaboutcookies.org.

Your Privacy Rights

Depending on your location, you may have the following rights regarding your personal information:

Rights for All Users

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete information
  • Deletion: Request deletion of your personal information
  • Objection: Object to the processing of your personal information
  • Withdraw Consent: Withdraw your consent at any time (where processing is based on consent)

Additional Rights (GDPR – EEA Residents)

  • Data Portability: Receive your personal information in a structured, machine-readable format
  • Restriction: Request restriction of processing in certain circumstances
  • Automated Decision-Making: Not be subject to automated decision-making (we do not use automated decision-making)

Additional Rights (CCPA – California Residents)

California residents have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know what personal information is collected, used, shared, or sold
  • Right to delete personal information
  • Right to opt-out of the sale of personal information (we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

How to Exercise Your Rights

To exercise any of these rights, please contact us using the contact information provided below. We will respond to your request within the timeframe required by applicable law (typically within 30 days).

International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country.

When we transfer personal information internationally, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions by relevant data protection authorities
  • Other legally approved transfer mechanisms

Children’s Privacy

Our Site and services are not directed to children under the age of 16. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us, and we will delete such information from our systems.

Third-Party Links

Our Site may contain links to third-party websites or services that are not operated by us. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

Do Not Track Signals

Some browsers include a “Do Not Track” (DNT) feature that signals to websites that you do not want your online activities tracked. Our Site does not currently respond to DNT signals or similar mechanisms.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by:

  • Posting the updated Privacy Policy on this page
  • Updating the “Last Updated” date at the top of this policy
  • Sending you an email notification (if we have your email address)

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Maya Villas

For GDPR-Related Inquiries

If you are located in the EEA and have concerns about our data practices, you have the right to lodge a complaint with your local data protection authority.

Response Time

We aim to respond to all legitimate requests within 30 days. Occasionally, it may take us longer if your request is particularly complex or you have made multiple requests. In this case, we will notify you and keep you updated.


Consent

By using our Site and submitting information through our contact form, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.


This Privacy Policy is designed to comply with major international privacy regulations including GDPR (EU), CCPA (California, USA), PIPEDA (Canada), and other applicable data protection laws. However, it is recommended to consult with a legal professional to ensure full compliance with all applicable laws in your specific jurisdiction.