Data protection

Privacy Policy

How Ochantera collects, uses, shares, and protects the information readers give us.

Revised: 2 September 2026

1. Scope and application

As an editorial catalogue and booking-enquiry directory for premier accommodation, Ochantera takes on a firm duty to protect individual records and to maintain transparency wherever readers interact with the service.

This document sets out what Ochantera collects, how it is organised and used, when it is transferred, and how it is protected when you browse the catalogue, read ratings, register a profile, or submit an accommodation request.

2. What we collect through the service

Delivering accurate lodging information, verified reviews, and dependable enquiry handling requires us to process the following categories:

Who you are and how to reach you
Name, salutation, chosen language, residential region, the email address you authorise, and telephone contact points given at registration or enquiry.
Travel and room requirements
Arrival and departure dates, room and bed configuration, suite category, dietary notes, accessibility requests, and any loyalty membership reference.
Billing verification records
The cardholder's name, masked card identifiers, billing location, and confirmation tokens issued by certified payment intermediaries. Complete card numbers never reach Ochantera systems.
Technical metadata
Your IP address, browser build, operating system, the page that referred you, time zone setting, device identifiers, and timestamps for page interactions.

3. Legal grounds and operational purposes

We rely on contractual performance, legitimate interests, statutory compliance, or explicit consent as our lawful grounds. Within those, records serve these purposes:

Enquiry fulfilment
Relaying your dates and requirements to the property's reservations desk so it can answer with current availability.
Content customisation
Adjusting the rankings and guides we surface to match the destinations and property styles you have shown interest in.
Security and verification
Safeguarding digital infrastructure, validating the legitimacy of transactions, and shielding users from unauthorised profile access.
Operational communication
Sending enquiry updates, confirmations, itinerary reminders, and necessary customer service notices.
Statutory adherence
Meeting accounting, tax reporting, and record-keeping requirements set by the applicable administrative authorities.

4. Who receives your information

Personal identifiers are never sold, rented, or leased to unaffiliated businesses. Data moves only where a contract governs it, and only to these recipients:

The hotels themselves
Selected properties are given only the name, arrival dates, and room details required to answer an enquiry or hold a room.
Certified payment gateways
Encrypted billing data passes to certified financial gateways operating to current PCI-DSS validation standards.
Hosting and cloud services
Tier-1 data centres and content delivery networks hold encrypted backups so the service stays available and recoverable.
Courts and regulators
Information may be released where a lawful subpoena, court order, or official mandate requires it, or to protect vital interests.

5. Cookies and analytics

Digital identifiers and local storage support returning-visitor recognition, preference retention, performance measurement, and session continuity. Control rests with you via browser configuration; blocking essential cookies will impair some features.

6. Security and retention

Protection is layered across administrative, technical, and physical measures: encrypted transport under TLS 1.3, AES-256 encryption at rest, isolated database clusters, and credentials restricted by role.

We retain data only for the time required to fulfil the request, handle follow-up questions, meet audit standards, or comply with a retention schedule set in law. After that, records are deleted or anonymised beyond recovery.

7. Your rights

Depending on where you live, and after identity verification, you can exercise these rights:

Access
Request a transferable copy of your stored records and verify our handling procedures.
Rectification
Have inaccurate, incomplete, or outdated details corrected without undue delay.
Erasure
Request deletion of your records where we no longer have a legal reason to retain them.
Restriction
Restrict our use of your data during any dispute over accuracy or over our grounds for processing.

Opt-out and your choices

You have the right to control how your personal information is collected and used. Depending on your location and the laws that apply to you, the following opt-out choices are available:

Data sharing and sale
Where the CCPA/CPRA in California or similar laws in other jurisdictions apply, you can opt out of your personal information being sold or shared with third parties. We do not sell personal information in the ordinary meaning of the term, though some data is shared with trusted partners to deliver or improve the service.
Tracking technologies
Use your browser's settings, or the consent tool on this site, to manage or reject cookies and other tracking technologies.
Marketing communications
Opt out of promotional messages and newsletters using the unsubscribe link in any communication, or by writing to us.
Withdrawal of consent
Where you previously consented to processing, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before it.

Requests to exercise these rights, or to opt out, can be sent to [email protected] or submitted through our contact form.

8. Revisions

We may update this notice as regulations or our systems change. Significant revisions are published here with a fresh effective date; continuing to use the site afterwards signifies acceptance.