Legal
Privacy policy
What we do with personal data — for visitors to this website, for Vivestay customers, and for guests whose registration data passes through the platform. These are three different situations and this policy keeps them apart.
Provisional pre-launch legal draft. It will be reviewed and replaced before paid commercial activation. Version 1.0 (provisional draft), effective 5 August 2026.
1. Who is responsible
The controller for the processing described in sections 3 to 6 is Cloudsource LTD, a private limited liability company registered in the Republic of Cyprus under registration number HE 478194, registered office Strovolou 77, Strovolos Center, Office 401, 2018 Strovolos, Cyprus, VAT identification CY60185107T (“Cloudsource”, “we”, “us”). Vivestay is a product of Cloudsource LTD.
Contact for any privacy question or request: hello@vivestay.com. Postal contact is the registered office above.
Data protection officer. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — whether a DPO is required for Cloudsource LTD and, if so, who it is. Until this is settled, privacy requests are handled at the contact address above.
2. Three different relationships — please read the right one
Vivestay touches personal data in three distinct ways, and our role differs in each:
- You visit this website. We are the controller. Sections 3–4 apply.
- You are (or work for) a Vivestay customer — a host, property manager or accommodation operator with an account at app.vivestay.com. We are the controller for your account, billing and support data. Sections 5–6 apply.
- You are a guest whose registration data an accommodation operator collects through Vivestay in order to meet a legal reporting obligation. There, the operator is the controller and we are the processor, acting on their instructions. Section 7 applies.
The distinction is not cosmetic. If you are a guest and want your registration data corrected or erased, the operator you booked with decides — we act on their instruction. We will always help you reach them.
3. When you simply browse this website
What is stored on your device
This website sets no cookies at all. It loads no analytics, no advertising or tracking pixel, no third-party font, no embedded video or map, no CAPTCHA and no third-party script of any kind. The only things it can store in your browser are the three items listed in the cookie policy, and everything beyond the strictly necessary one requires your consent first.
We do not fingerprint visitors, and we do not store anything to remember that you refused.
Server logs
Our web server records technical access logs: the requesting IP address, the date and time, the page requested, the response code and the browser user-agent string. We use them to operate and secure the site — detecting abuse, diagnosing faults, and understanding load. They are not used to build a profile of you, are not combined with anything else, and are not shared for any other purpose.
Legal basis: our legitimate interest in operating the website securely and reliably (Art. 6(1)(f) GDPR).
Retention: logs are kept short-term and then discarded. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — the exact log retention period in days
4. When you contact us through this website
If you submit the Talk to us or contact form, what you typed is sent over an encrypted connection to a service we run ourselves on EU infrastructure — no third-party form, marketing or CRM service is involved. The data is written to durable storage before we confirm receipt, so a request cannot be silently lost, and it is then forwarded to our team mailbox.
Categories of data: your name; your email address; your company (optional); an indication of portfolio size; your message; and the technical context of the submission — the language of the page, an optional country selection, the page the form was on, and the time it was sent. We also record whether our automated abuse checks flagged the submission.
Purposes and legal bases: to answer you and to follow up on your enquiry — steps taken at your request prior to entering into a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to business enquiries and in protecting the form against abuse (Art. 6(1)(f) GDPR).
Providing it is voluntary, but a name and an email address are necessary for us to reply at all; without them the form cannot be submitted.
Retention: we keep an enquiry for as long as the conversation and any resulting business relationship require, and then delete it. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — a defined maximum retention period for unconverted enquiries
No marketing lists. We do not add enquiries to a mailing list, do not sell or share them, and do not use them for advertising.
5. When you have a Vivestay account
The Vivestay application runs at app.vivestay.com. Some of what follows is also presented inside the application itself and in the agreement concluded with each customer; where the two differ, the agreement governs.
Account and organization data: the name and email address of each operator user, the password (stored only as a cryptographic hash, never in readable form), organization and property details, the roles and permissions held, and the record of invitations and membership changes.
Business-contact data: the contact details you give us for commercial, support and administrative correspondence.
Security and audit data: sign-in events, session records, and an audit trail of significant actions taken in the account. A compliance product has to be able to show who did what; that audit trail is deliberate and is part of the service.
Billing data: where a paid subscription exists, the subscription state, the plan and cycle, and the records needed for invoicing. Paid activation is not live today — see the terms and conditions. Card details are never received or stored by us; a payment provider handles them directly.
Purposes and legal bases: performing the contract with your organization (Art. 6(1)(b) GDPR); complying with our own legal obligations, in particular accounting and tax (Art. 6(1)(c) GDPR); and our legitimate interest in securing the service, preventing abuse and supporting customers (Art. 6(1)(f) GDPR).
Retention: account data for the life of the account and a limited period afterwards; records we are required to keep for accounting or tax purposes for the statutory period. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — the post-termination retention period for account and support data, and the statutory accounting retention period applied
6. Recipients, processors and international transfers
We do not sell personal data and we do not share it for anyone else’s marketing.
Personal data is disclosed only to: our own staff, on a need-to-know basis; service providers who process data on our behalf under a written contract (Art. 28 GDPR); and public authorities where we are legally required to respond.
The current list of processors we engage: [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — the definitive sub-processor list — the hosting provider, the email delivery provider and the payment provider must each be named, with their role and location, before paid launch. We will not publish a list we have not confirmed.
Hosting. This website and the Vivestay application run on infrastructure located in the European Union. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — the name and exact location of the hosting provider
International transfers. As at the effective date of this policy, this website makes no request to any third party and transfers nothing outside the European Economic Area. If a future service provider processes data outside the EEA, we will name it here together with the transfer safeguard relied on (an adequacy decision, or standard contractual clauses), before it goes into use. We do not claim a safeguard we have not put in place.
7. Guest registration data — where we act as processor
Vivestay exists so that accommodation operators can meet legal guest-registration and reporting obligations. When a guest completes a registration form, the accommodation operator is the controller of that data. They decide what is collected, why, and how long it is kept; they are the ones who must inform the guest and answer their requests. Cloudsource LTD acts as processor and handles the data on the operator’s documented instructions.
What that means in practice for a guest: the information notice that applies to you is the operator’s, and the registration form itself tells you why the data is required, what happens to it and what happens next. If you want access, correction or erasure, contact the accommodation you booked with. If you cannot reach them, write to us and we will help you find the right contact — but we cannot act on your data without their instruction.
It also means legal obligations may prevent erasure. Guest registration data is frequently subject to a statutory retention period set by the destination country’s law, and neither the operator nor we can shorten it.
The data-processing agreement that governs this relationship between an operator and Cloudsource LTD is part of the customer agreement. [TO BE CONFIRMED BEFORE COMMERCIAL LAUNCH] — publication of the standard Art. 28 data-processing agreement. It is not published yet, and paid onboarding must not begin without it.
8. Your rights
Where we are the controller, you have the right to: obtain confirmation of whether we process your personal data and a copy of it (access); have inaccurate data corrected; have data erased in the circumstances the GDPR provides; obtain restriction of processing; receive data you gave us in a portable form; and object to processing based on our legitimate interests, including at any time where the processing is for direct marketing.
Withdrawing consent. Where processing rests on your consent, you may withdraw it at any time, and doing so is as easy as giving it. For this website’s optional storage, use “Cookie settings” in the footer of any page. Withdrawal does not affect the lawfulness of what was done before it.
To exercise any right, write to hello@vivestay.com. We will respond within the period the GDPR allows. We may need to verify your identity first — not to obstruct you, but because handing your data to someone else would be the worse failure.
Complaints. You have the right to lodge a complaint with a data protection supervisory authority. Ours is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. You may also complain to the supervisory authority of the EU or EEA country where you live or work, or where you believe an infringement occurred.
9. Automated decision-making
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile visitors of this website.
For completeness, two automated steps do exist and neither is a decision about a person: the website form applies automated abuse checks (a hidden field and a timing check) which may cause a submission to be held rather than emailed; and Vivestay applies deterministic validation rules to registration data — it checks that a document number matches the expected format, that a required field is present, that a deadline has passed. These are format checks, not judgements about you, and a person can always correct them.
10. Security
We take the measures we consider appropriate to the risk, including: encryption in transit for all traffic; passwords stored only as cryptographic hashes; strict separation between customer organizations enforced at the database level, not merely in application code; secrets held encrypted at rest; access to production limited to named accounts; and structured logging that minimises personal data — guest registration identity and identity-document content are not written to ordinary application logs, while technical request metadata such as the network address a request came from is processed where necessary to operate and secure the service. The public website and the application are separately deployed, and the website has no access to the application’s database, network or secrets.
No system is perfectly secure, and we will not pretend otherwise. What we commit to is proportionate measures, honest disclosure, and notification where the law requires it.
11. Children
This website and the Vivestay application are business tools, not directed at children, and we do not knowingly collect data from children through them. Guest registration data handled on an operator’s behalf may relate to minors travelling with their family, because the underlying legal reporting obligation requires it; that processing is the operator’s and is governed by the law creating the obligation.
12. Changes to this policy
We will update this policy as the product and the company develop — most immediately when it has been through legal review. The version and effective date are shown at the top of the page. Where a change materially alters what we do with your data, we will say so rather than replace the text quietly. A change to the technologies this website uses also increments the consent policy version, which asks every visitor again.
Version 1.0 (provisional draft) · effective 5 August 2026 · controller: Cloudsource LTD (HE 478194)