Privacy Policy & Personal Data Governance (GDPR)
Full Compliance with Regulation (EU) 2016/679 • Effective Date: September 2026
1. Data Controller Identification & Legal Seat
This privacy declaration details the processing policies applicable to all electronic services and visitors accessing amazingluxuryresort.com. The legal Data Controller under Article 4(7) of the General Data Protection Regulation (EU) 2016/679 is:
Commercial Registration: LV40203658043
Official Address: Lielā iela 6, Jelgava, LV-3001, Republic of Latvia
Data Protection Contact: [email protected]
2. Principles of Data Collection & Scope
Amazing Luxury Resort operates strictly as an autonomous editorial publication, architectural archive, and hospitality guide. We do not operate e-commerce shopping carts, process credit cards, or manage direct consumer hotel booking checkouts. Consequently, our data collection is strictly minimal:
- Voluntary Liaison Records: Full name, corporate or personal email address, and contextual message bodies transmitted when initiating contact via our web forms. (Lawful Basis: Art. 6(1)(f) GDPR — Legitimate interest in resolving user correspondence).
- Server Security & Telemetry Data: Truncated/pseudonymized Internet Protocol (IP) addresses, user-agent strings, HTTP request headers, and access timestamps captured by edge firewalls. (Lawful Basis: Art. 6(1)(f) GDPR — Legitimate interest in maintaining server uptime, blocking abusive botnets, and defending against DDoS attacks).
3. Absence of Sensitive Financial or Profile Processing
Under no circumstances does Amazing Luxury Resort collect, store, or process payment cards (PCI-DSS data), bank account numbers, social security records, biometric information, or special category data under Article 9 of the GDPR. When a user navigates to an official hotel portal via external hyperlinks, transactions are governed solely by that third-party provider's checkout systems.
4. Third-Party Linkage & Partner Autonomy
Our website contains external hyperlinks pointing exclusively to official domains of evaluated hotels and regulatory bodies. Once an external link is clicked, this Privacy Policy ceases to govern. We do not pass personal profile data or tracking identifiers to external hotel operators.
5. Data Retention & Erasure Timelines
Correspondence records submitted via our liaison form are archived for an administrative duration not exceeding 12 months from the date of final resolution, after which they are permanently deleted from secure digital archives. Technical server log entries are automatically overwritten on a rolling 30-day cycle.
6. Enforceable Data Subject Rights Under GDPR
Pursuant to Chapter III (Articles 15 through 22) of Regulation (EU) 2016/679, European Union data subjects maintain statutory rights regarding their personal records:
- Right of Access (Art. 15): Obtain confirmation regarding whether your personal data is processed and request a digital copy.
- Right to Rectification (Art. 16): Correct inaccurate or incomplete contact records without undue delay.
- Right to Erasure / 'Right to be Forgotten' (Art. 17): Request deletion of correspondence records when no longer necessary.
- Right to Restriction of Processing (Art. 18): Restrict active use of data during disputes regarding accuracy.
- Right to Object (Art. 21): Object to processing based on legitimate interest at any time.
To exercise any of these statutory rights, submit an electronic request to [email protected]. If you consider that our processing breaches GDPR, you have the legal right to lodge a formal complaint with the Data State Inspectorate of Latvia (Datu valsts inspekcija — dvi.gov.lv).