Legal information

Privacy Policy

In accordance with Regulation (EU) 2016/679 (GDPR)

Effective Date: 12 May 2025Last Updated: 21 July 2026

This Privacy Policy describes how Clariva LTD collects, uses, stores, and protects personal data of individuals interacting with its digital channels, in full compliance with Regulation (EU) 2016/679 (GDPR) and applicable Cypriot data protection law.

1. Data Controller Information

Clariva LTD acts as the Data Controller in respect of all personal data collected and processed as described in this Privacy Policy.

Company Name
Clariva LTD
Registered Address
Alyos Street, Germasogeia 4046, Limassol, Cyprus
Industry / Services
Spa and wellness services
Email
booking@clarivaspa.com
Company Registration Number
Registered in the Republic of Cyprus

Clariva LTD is registered and operates in the Republic of Cyprus and is subject to the supervisory authority of the Commissioner for Personal Data Protection of Cyprus, as well as the requirements of the GDPR.

Clariva LTD is in the process of appointing a Data Protection Officer (DPO) in accordance with applicable requirements. Until such appointment is confirmed, data protection enquiries should be directed to the contact details set out in Section 9 of this Policy.

2. Personal Data Collected

Clariva LTD collects only the personal data specified below. No additional categories of data are collected or inferred beyond what is expressly listed. Should the scope of data collection change in the future, this Policy will be updated accordingly.

2.1 Categories of Data Collected

  • Electronic mail address (email address) — collected when an individual interacts with the Company's website landing pages, digital advertising forms, or automated chatbot interfaces.
  • Name (full or preferred) — collected when an individual books a treatment online or submits an enquiry through website contact forms; required to identify the client when confirming and providing the service.
  • Telephone number — collected when an individual books a treatment online or submits an enquiry; used to confirm the booking, communicate scheduling changes, and provide operational contact in relation to the service.
  • Booking comment (optional, provided by the client) — free-text notes or preferences relating to the treatment; stored together with the booking record.

2.2 Data Not Currently Collected

The following categories of data are not currently collected by Clariva LTD:

  • Postal address or location data
  • Payment or financial information (payment is taken on-site at the point of service)
  • Special categories of personal data (Article 9 GDPR) — not applicable

No data is collected from individuals under the age of 16. If Clariva LTD becomes aware that personal data has been collected from a minor, it will be deleted without undue delay.

3. Purpose of Processing

Personal data is processed exclusively for the purposes set out below. Data shall not be processed in a manner incompatible with the stated purposes (Article 5(1)(b) GDPR).

  • Processing bookings and delivering spa and wellness services: booking confirmation, schedule change notifications, client identification at the appointment.
  • Responding to enquiries submitted through the Company's digital channels, including chatbot interactions and contact forms.
  • Direct marketing and promotional communications relating to Clariva LTD spa and wellness services.
  • Lead generation and customer acquisition in connection with advertising campaigns.
  • Improving the quality and relevance of communications, advertising content, and client experience.
  • Compliance with legal obligations applicable to the Company.

5. Data Sharing and Third-Party Disclosure

Clariva LTD does not sell personal data to third parties. Personal data may be shared in the following limited circumstances:

5.1 Service Providers and Data Processors

Clariva LTD engages third-party processors to process personal data on its behalf. The main categories of processors include: a CRM system used for booking management and client records, email marketing platforms, chatbot software vendors, advertising and analytics platforms, and cloud infrastructure providers.

Such processors are bound by data processing agreements in accordance with Article 28 GDPR and are permitted to process data only on documented instructions from Clariva LTD. A current list of sub-processors engaged by Clariva LTD is available upon request. Clariva LTD will notify data subjects of any material changes to its processor arrangements.

5.2 Legal Disclosure

Personal data may be disclosed to competent authorities or regulators where required to do so by applicable law, court order, or regulatory requirement. Such disclosures will be limited to what is strictly necessary.

5.3 International Transfers

Clariva LTD primarily stores and processes personal data within the European Economic Area (EEA). In the event that personal data is transferred to a third country outside the EEA, Clariva LTD ensures that an appropriate safeguard under Chapter V GDPR is in place, which may include the use of Standard Contractual Clauses (SCCs) approved by the European Commission, or transfers to countries benefiting from an adequacy decision. Further information regarding international transfer mechanisms may be obtained by contacting the Company at the details set out in Section 9.

6. Data Storage and Retention

6.1 Storage Location

Personal data collected by Clariva LTD is stored on secure cloud-based infrastructure hosted within the European Economic Area (EEA). All storage providers engaged by the Company are required to implement appropriate technical and organisational security measures in accordance with Article 32 GDPR.

6.2 Retention Period

Personal data shall be retained only for as long as necessary to fulfil the purposes for which it was collected, in accordance with the principle of storage limitation under Article 5(1)(e) GDPR. As a general rule:

  • Email addresses collected for marketing purposes are retained for a period of two (2) years from the date of last interaction, unless the data subject withdraws consent or requests erasure at an earlier date.
  • Booking data (name, telephone number, booking comment) is retained in the Company's CRM system for the duration of the active client relationship and for up to five (5) years from the date of the last visit, after which it is anonymised or deleted.
  • Data retained for compliance with legal obligations (including tax records of completed bookings) is held for the period required by applicable law, typically up to seven (7) years.

Once the applicable retention period expires, personal data will be securely deleted or irreversibly anonymised.

6.3 Security Measures

Clariva LTD implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, or disclosure, in accordance with Article 32 GDPR. Measures in place include:

  • Encryption of personal data in transit using industry-standard TLS protocols.
  • Access controls ensuring that personal data is accessible only to authorised personnel on a need-to-know basis.
  • Regular review of security practices and procedures.
  • Contractual requirements imposed on all third-party processors to maintain equivalent security standards.

7. Rights of Data Subjects

In accordance with Chapter III of the GDPR, individuals whose personal data is processed by Clariva LTD are entitled to exercise the following rights:

  • Right of Access (Article 15): The right to obtain confirmation as to whether personal data concerning the individual is being processed, and to receive a copy of such data.
  • Right to Rectification (Article 16): The right to request correction of inaccurate or incomplete personal data without undue delay.
  • Right to Erasure / 'Right to be Forgotten' (Article 17): The right to request deletion of personal data where it is no longer necessary for the original purpose, consent is withdrawn, or no legitimate grounds for processing remain.
  • Right to Restriction of Processing (Article 18): The right to request that processing be restricted in certain circumstances, including where accuracy is contested or the processing is unlawful.
  • Right to Data Portability (Article 20): The right to receive personal data in a structured, commonly used, machine-readable format and to transmit it to another controller, where processing is based on consent or contract and is carried out by automated means.
  • Right to Object (Article 21): The right to object at any time to processing based on legitimate interests, including for direct marketing purposes. Upon receipt of such an objection, Clariva LTD will cease processing personal data for direct marketing without delay.
  • Right to Withdraw Consent (Article 7(3)): Where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of prior processing.
  • Right not to be Subject to Automated Decision-Making (Article 22): The right not to be subject to solely automated decisions, including profiling, which produce legal or similarly significant effects.

To exercise any of the above rights, data subjects may contact Clariva LTD at the details set out in Section 9 of this Policy. Clariva LTD will respond to requests within one (1) month of receipt, unless the complexity or volume of requests necessitates an extension of up to two (2) additional months, in which case the data subject will be informed without undue delay.

Data subjects also have the right to lodge a complaint with the Commissioner for Personal Data Protection of Cyprus (the competent supervisory authority), or with any other EU supervisory authority in the Member State of their habitual residence or place of work, if they consider that the processing of their personal data infringes the GDPR.

8. Cookies Policy

Clariva LTD uses cookies and similar tracking technologies on its website(s). A cookie consent banner is displayed to users upon their first visit, enabling informed and freely given consent prior to the placement of non-essential cookies.

8.1 What Are Cookies

Cookies are small text files placed on a user's device by a website. They serve a variety of functions including session management, preference storage, and analytics.

8.2 Categories of Cookies Used

  • Strictly Necessary Cookies: Required for the operation of the website and the provision of services requested by the user. No consent is required for these cookies under applicable law. These cookies do not collect personal data for marketing purposes.
  • Analytical / Performance Cookies: Used to collect aggregated information about how visitors use the website, such as pages visited and error messages encountered. This data is used to improve website performance. Where analytics tools such as Google Analytics are employed, data is processed in anonymised or pseudonymised form.
  • Marketing / Advertising Cookies: Used to deliver advertising relevant to users and their interests, and to measure the effectiveness of advertising campaigns. These cookies may be set by third-party advertising partners.
  • Functional Cookies: Used to remember user preferences and settings to improve the browsing experience, such as language preferences.

8.3 Cookie Consent

Non-essential cookies are only placed on a user's device after explicit consent has been obtained through the cookie banner displayed on the website. Users may withdraw their cookie consent or amend their preferences at any time by accessing the cookie settings panel on the website.

8.4 Third-Party Cookies

Third-party cookies may be set by service providers including advertising networks, analytics platforms, and embedded content providers. Where such providers set cookies on the Company's website, they do so under their own privacy policies. Users are encouraged to review the privacy policies of relevant third parties.

8.5 Cookie Retention

  • Strictly Necessary Cookies: Session-based; deleted when the browser is closed.
  • Analytical / Performance Cookies: Persistent; typically retained for up to 13 months.
  • Marketing / Advertising Cookies: Persistent; typically retained for up to 12 months.
  • Functional Cookies: Persistent; typically retained for up to 12 months.

9. Contact Information

For any questions, requests, or concerns relating to this Privacy Policy or the processing of personal data by Clariva LTD, data subjects may contact the Company using the details below:

Data Controller
Clariva LTD
Registered Address
Alyos Street, Germasogeia 4046, Limassol, Cyprus
Email Address
booking@clarivaspa.com

Requests submitted by email will be acknowledged within five (5) business days. Responses to substantive requests regarding the exercise of data subject rights will be provided within one (1) month in accordance with Article 12 GDPR.

10. Changes to This Privacy Policy

Clariva LTD reserves the right to amend this Privacy Policy at any time. Material changes will be communicated to data subjects by appropriate means, which may include notification via email or a prominent notice on the Company's website. The date of the most recent revision is indicated at the top of this document.

Continued use of the Company's digital channels following notification of amendments constitutes acceptance of the revised Policy, to the extent permitted by applicable law.

Message on WhatsApp