1. Introduction and Data Controller Overview
Curiovaultradr Hospitality Media B.V. (referred to herein as "Curiovaultradr", "we", "us", or "our"), operating the domain curiovaultradr.mom, is dedicated to upholding the highest standards of confidentiality, transparency, and data integrity. This Privacy Policy sets forth our operational practices regarding the collection, processing, transfer, storage, and erasure of personal data obtained from visitors, subscribers, property submitters, and commercial partners interacting with our digital hospitality platforms.
The designated Data Controller responsible for all processing activities is:
Curiovaultradr Hospitality Media B.V.
44 Keizersgracht, 1015 CR Amsterdam, Netherlands
Company Registry No.: NL-84920412
Data Protection Officer Contact: [email protected]
2. Categories of Personal Data Collected
We process personal information under distinct legal grounds specified under Article 6 of the General Data Protection Regulation (GDPR):
- Directly Provided Identifiers: Name, contact telephone number, professional email address, postal address, company association, and architectural portfolios transmitted via our property audit submission and contact modules.
- Technical and Telemetry Data: Internet Protocol (IP) addresses, browser specification strings, hardware device identifiers, operating system version, time zone settings, referral Uniform Resource Locators (URLs), and interaction logs across our design index.
- Subscription and Preference Data: Email dispatch subscription records, preference tokens, consent timestamps, and communication logs.
- Analytical Metrics: Anonymized dwell time, scroll depth, click-through rates on hostel blueprints, and interactive slider usage without attaching persistent user identities.
3. Legal Grounds for Data Processing
We process personal data strictly in adherence to defined legal frameworks:
- Performance of a Contract (Art. 6(1)(b) GDPR): Fulfilling editorial submissions, property audit reviews, and responding to direct inquiries initiated by the user.
- Legitimate Interests (Art. 6(1)(f) GDPR): Enhancing website security, preventing fraudulent activity, optimizing architectural asset loading speeds, and conducting aggregated statistical research.
- Explicit Consent (Art. 6(1)(a) GDPR): Sending the European Spatial Dossier newsletter and setting non-essential telemetry/cookie modules. Users reserve the unconditioned right to withdraw consent at any time.
- Legal Compliance (Art. 6(1)(c) GDPR): Fulfilling statutory financial accounting obligations, tax authority requests, and lawful regulatory directives within the European Economic Area (EEA).
4. Third-Party Data Processors & Cross-Border Transfers
Curiovaultradr does not sell, lease, or monetize personal records. Data may be shared with trusted data processors strictly under Data Processing Agreements (DPAs) that enforce compliance with European Commission Standard Contractual Clauses (SCCs). These processors encompass:
- Cloud hosting and Content Delivery Network (CDN) infrastructure providers situated within the EU and North America.
- Transactional email dispatch services utilizing encrypted TLS 1.3 channels.
- Independent architectural jury assessors engaged under formal non-disclosure and privacy protocols.
5. Data Retention Schedules
We retain personal information only for the minimum duration requisite to satisfy the specified processing purpose:
- Contact and Audit Submissions: Retained for 24 months following the conclusion of review, unless statutory commercial recordkeeping requires extended storage.
- Newsletter Subscriptions: Retained until the recipient unsubscribes via the one-click unsubscribe mechanism.
- Server Telemetry Logs: Automatically rotated and permanently purged every 90 days.
6. Your Statutory Rights under GDPR & CCPA
Under European and California legislation, you hold extensive rights concerning your personal data:
- Right of Access (Art. 15 GDPR): Request a copy of all personal records maintained concerning your identity.
- Right to Rectification (Art. 16 GDPR): Rectify inaccurate or incomplete spatial or personal records.
- Right to Erasure / Right to be Forgotten (Art. 17 GDPR): Request deletion of your personal records where no overriding legal basis exists.
- Right to Restriction of Processing (Art. 18 GDPR): Restrict active processing pending verification of data accuracy.
- Right to Data Portability (Art. 20 GDPR): Obtain your data in a structured, commonly used, and machine-readable format (JSON/CSV).
- Right to Object (Art. 21 GDPR): Object to processing based upon legitimate interests.
To exercise any statutory right, contact our Data Protection Officer at [email protected] with verifiable identification credentials. We respond within 30 calendar days.
7. Security Measures and SSL Encryption
We implement stringent technical and organizational security measures (TOMs), including 256-bit Advanced Encryption Standard (AES) at rest, continuous TLS 1.3 in transit, strict access control matrices, and regular vulnerability scanning.
8. Updates to this Policy
We may revise this privacy documentation periodically to mirror operational or regulatory developments. Material alterations will be published with an updated revision date.