Privacy Policy
Last Updated: February 2026
1. Introduction
Sky Universe Ltd (“we”, “us”, “our”) is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard personal information when you use our website and services, in compliance with the EU General Data Protection Regulation (GDPR) and Cyprus law (Law 125(I)/2018). Sky Universe Ltd is the “data controller” for your personal data (i.e. the company responsible for determining how and why your data are processed). We adhere to all applicable data protection laws in Cyprus and the EU, and we maintain required records of our data processing activities. If any changes are made to this policy, we will post the updated date above.
2. Information We Collect
We collect personal information that you provide directly through our website forms, booking system, and live chat, as well as data gathered automatically through cookies (see our Cookie Policy). The types of data we may collect include:
- Contact Information: Name, email address, telephone number, and mailing address (e.g. when you fill out our contact or inquiry form).
- Identity and Booking Information: Passport or ID details (if required for booking), dates of booking, property selected, number of guests, and any preferences or special requests related to your stay.
- Payment Information: If you make a booking, we may collect payment details such as credit card information or bank transfer details to process the transaction. However, we do not store full credit card numbers or sensitive payment data on our servers – online payments are handled securely by accredited third-party payment processors, and we only retain necessary information like payment confirmation and transaction references. If you choose to pay via wire/bank transfer, we will record the fact of payment (date, amount, account name) but we do not keep your bank account details beyond what is needed for the transaction.
- Communication Records: Copies of your communications with us, such as emails, contact form submissions, and live chat transcripts. This may include any personal data you choose to provide during those communications (for example, your inquiries, feedback, or any issues you report).
- Usage Data and Cookies: When you navigate our site, we automatically collect technical data including IP address, browser type, device identifiers, and browsing behavior through cookies or similar tracking technologies. Our Cookie Policy (below) explains this in detail, including how you can manage cookie preferences.
We do not intentionally collect any “special categories” of sensitive personal data about you (such as health information, racial or ethnic origin, political opinions, religious beliefs, etc.), nor do we collect information about criminal convictions. Please refrain from providing such sensitive data to us.
If you provide us personal data about others (for example, the names of additional guests on a booking), you must ensure you have their permission or other lawful basis to share that information with us.
3. How We Use Your Data
We only use your personal data for specific purposes and legal reasons. The main purposes for which we process personal information include:
- Providing Services and Fulfilling Bookings: We use your information to process and confirm your property bookings, take payment, and provide the rental services you’ve requested (performance of a contract with you). For example, we use your name and contact details to issue booking confirmations and your payment details to charge for the booking. We may also share necessary details (e.g. your name, arrival time) with property managers or owners to facilitate check-in and accommodation arrangements (see Data Sharing below).
- Communicating with You: We use contact information (email, phone) to respond to your inquiries, send booking confirmations, receipts, and important updates about your reservation (such as check-in instructions). We may also use the live chat or email to assist you in real time with any questions.
- Customer Support and Service Quality: If you contact us with questions, feedback, or complaints, we will process those communications to address your concerns and improve our services. We may send post-stay surveys or follow-ups to gauge your satisfaction and enhance our offerings.
- Marketing (with Consent): With your consent, we may send you promotional communications such as newsletters, special offers, or information about new properties. You can opt out of marketing at any time. We will not spam you – we only send marketing emails if you have agreed to receive them, and you can easily unsubscribe via the link in each message.
- Website Functionality and Analytics: We process certain data (like cookies and usage data) to personalize your experience (e.g. remembering your language or currency preferences) and to analyze how our website is used. This helps us debug issues, secure our site, and optimize the content and layout for a better user experience. Any analytics or tracking is done in accordance with our Cookie Policy and, where required, based on your consent.
- Legal Compliance and Protection: We may process personal data as necessary to comply with legal obligations (such as retaining records for tax/audit purposes or responding to lawful requests by authorities). For instance, Cyprus law may require us to keep invoicing records including customer names and payment amounts for a certain number of years. We may also process data to establish or defend legal claims or to investigate fraud. Additionally, basic personal details might be required if we must register guests with local authorities (for example, for tourism tax or safety regulations, if applicable).
We will only use your personal data for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason compatible with the original purpose and permitted by law. If we need to use your data for an unrelated purpose, we will notify you and explain the legal basis.
4. Legal Bases for Processing
Under GDPR, we must have a valid “lawful basis” to process your personal data. Depending on the specific processing activity, one or more of the following bases apply:
- Performance of a Contract: Many data uses are to fulfill our contract with you. For example, when you book a rental, we must use your personal details and payment information to process that booking and provide the accommodation service. This is necessary for the performance of our agreement with you or to take steps at your request before entering into an agreement.
- Consent: We rely on your consent in certain cases, such as sending marketing emails or using non-essential cookies on our site. Where we ask for consent, you have the right to withdraw it at any time. For instance, we will only place analytics or advertising cookies on your device if you have given consent via our cookie banner (see Cookie Policy). If you initiate a conversation via our live chat, we treat that as consent to process the data you provide in order to assist you.
- Legitimate Interests: We may process data as necessary for our legitimate business interests, provided those are not overridden by your data protection rights. Examples include: improving website functionality, preventing fraud, securing our IT systems, understanding how customers use our services (analytics), or sending you offers about similar services you’ve previously used (within applicable legal limits). When relying on legitimate interests, we assess that our processing is reasonable, proportionate, and has minimal privacy impact. You have the right to object to processing based on our legitimate interests.
- Legal Obligation: In some cases, we need to process data to comply with a legal obligation. For example, retaining transaction records for financial reporting and compliance with Cyprus tax law, or providing information to law enforcement if required by court order. When processing is necessary for us to meet our legal obligations, this is done on that basis.
We do not typically process any sensitive (“special category”) data about you. If we ever had to (for example, if you voluntarily disclosed health information such as accessibility needs), we would only do so with your explicit consent or if otherwise lawfully permitted.
5. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to ensure it functions properly, to remember your preferences, and to analyze traffic. Cookies are small text files stored on your browser when you visit a website. They serve various purposes, from keeping you logged in to understanding how you navigate between pages. For detailed information on the cookies we use and your choices, please see our Cookie Policy below. In summary:
- We only use non-essential cookies (like analytics or marketing cookies) with your consent, per Cyprus’s implementation of the EU ePrivacy rules. On your first visit, you will see a cookie consent banner allowing you to accept or customize your cookie settings. You can change your preferences at any time.
- Essential cookies (needed for the site to work, such as to remember items in your booking cart or provide our live chat service) are used based on our legitimate interest in providing a functional website and do not require consent. These are limited to what is strictly necessary.
- We may use analytics tools (like Google Analytics) which set cookies to collect anonymized statistics (e.g., number of visitors, pages viewed). These analytics cookies and any advertising cookies (if used in the future) will only be activated if you opt-in.
- You can also manage cookies through your browser settings at any time. However, blocking all cookies may affect your experience on our site.
For more, please read the Cookie Policy section of this document, which is an integral part of our privacy practices.
6. Data Sharing and Disclosure
We treat your personal data with care and confidentiality. We do not sell your personal information to third parties. However, we may need to share your data with certain trusted parties, in accordance with the purposes outlined above:
- Affiliates and Personnel: Within Sky Universe Ltd, only authorized personnel (staff or contractors) who need access to information to perform their duties (e.g., our reservations team, customer support agents, IT administrators) will process your data. All such personnel are bound by confidentiality obligations.
- Property Owners/Managers: Sky Universe Ltd may manage properties on behalf of owners or collaborate with local property managers. If you book a stay, we will share necessary details with those parties managing the specific property (such as your name, contact details, and stay dates) so they can facilitate check-in, maintenance, or support during your stay. These parties are also bound to protect your data and use it only for the purposes of your rental.
- Service Providers (Processors): We use third-party service providers to support our business operations, for example:
- Payment Processors: to securely handle credit card transactions or bank payment confirmations (e.g., banks or payment gateways). Your payment details are transmitted directly to them over encrypted connections. (As noted, we do not store your full card details.)
- IT and Hosting Providers: that host our website and databases or provide email and data storage services. Our website hosting may be with a reputable company that stores data on servers within the EU (or in a country deemed adequate under EU law, or otherwise under proper safeguards).
- Live Chat/Communication Tools: If our live chat functionality is provided by a third-party platform, that provider may process the data you enter into chat on our behalf to enable the conversation. Similarly, we may use third-party email or CRM systems to organize communications.
- Analytics and Ad Partners: We may use analytics services (like Google Analytics) to collect usage data (with your consent as required). These providers process data such as IP addresses and cookie identifiers to give us insights into site traffic. We ensure any such partners only use personal data for the intended analytics purpose and not for their own marketing unless you separately consent to them.
In all cases where we engage service providers, they act under our instructions and are “data processors” under GDPR. We sign appropriate data processing agreements with them to ensure they protect your data and only use it for our specified purposes.
- Legal and Safety Reasons: We may disclose personal information to third parties (such as advisors, law enforcement, courts, or regulators) when we believe in good faith that such disclosure is necessary to: comply with a legal obligation or request, enforce our booking terms or website terms of use, address fraud or security issues, or protect the rights, property, or safety of Sky Universe, our customers, or others. For example, if required by law we might provide guest registry information to public authorities, or share transaction details with our accountants for financial audits.
- Business Transfers: In the unlikely event that we undergo a major business transaction such as a merger, acquisition, or sale of assets, your personal data may be transferred to the new owner or successor entity as part of that transaction. If this happens, we will ensure the confidentiality of your personal data is maintained and give affected users notice before their data becomes subject to a different privacy policy.
Except for the situations above, we will not share your personal data with third parties without your consent. Where personal data is shared, we only share the minimum information necessary for the purpose and in accordance with data protection law.
7. International Data Transfers
Sky Universe Ltd is based in Cyprus (an EU member state). Generally, your data is stored and processed within the European Economic Area (EEA). However, some of our third-party service providers may be located or have servers outside the EEA. For example, if we use a cloud hosting, marketing, or chat service based in the United States or another country, your personal data might be transferred to that jurisdiction.
Whenever we transfer personal data outside the EEA, we take steps to ensure it remains protected in line with EU standards. This includes:
- Transferring data only to countries that the European Commission has formally deemed to have an “adequate” level of data protection; or
- Using standard contractual clauses (SCCs) approved by the European Commission, which legally bind the foreign recipient to protect your data; or
- Relying on another valid transfer mechanism under GDPR (such as an approved certification or binding corporate rules, where applicable).
We will also assess on a case-by-case basis whether additional technical and organizational measures are needed to ensure your data’s security when it’s transferred internationally.
You can contact us (see Contact Us below) if you would like more information about international data transfers or specific safeguards in place.
8. Data Retention
We keep your personal data only for as long as necessary to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. Retention periods will vary depending on the type of data and purpose of processing. For example:
- Booking and Transaction Data: Information related to confirmed bookings (e.g. your name, contact, booking details, payment records) will be retained for a number of years after your stay is completed. This is to fulfill our contract, handle any post-stay issues, and comply with financial record-keeping laws. In Cyprus, we may need to retain invoice data for 7 years for tax purposes (or as required by law).
- Inquiries and Contact Form Data: If you contact us with a question but do not make a booking, we will retain those communications and your contact details for a reasonable period (typically up to 1 year) in case you have follow-up queries or decide to book later, and to improve our customer service. After that, we will delete or anonymize inquiry data.
- Live Chat Transcripts: Chat histories are generally stored for a short period (e.g. 90 days) for quality assurance and to reference if you have subsequent interactions. We periodically purge older chat logs.
- Marketing Data: If you have consented to receive marketing emails, we will retain the necessary contact info until you unsubscribe or withdraw consent. If you unsubscribe, we may keep your email on a suppression list to ensure we do not accidentally send you further communications.
- Cookie Data: Cookies have varying lifespans. Some expire when you close your browser (session cookies), while others may last days or months (persistent cookies). Details are in our Cookie Policy, but for example, analytics cookies might last up to 12 months unless you clear them. We do not use cookies beyond their intended retention period, and you can delete them at any time.
- Legal Compliance: In cases where data must be kept for legal reasons, we retain it as long as required by the specific law. For instance, if a dispute arises or if we receive a legal order to preserve data, we will retain the relevant data for as long as needed to resolve the issue.
After the applicable retention period ends, we will securely erase, anonymize, or otherwise delete the personal data. We take care to ensure that data is properly disposed of so that it cannot be reconstructed or read.
9. Your Rights as a Data Subject
As an individual whose personal data we process, you have certain rights under GDPR and Cyprus data protection laws. You may exercise the following rights (subject to some conditions and exceptions set by law):
- Right to Access: You have the right to request a copy of the personal data we hold about you, and to obtain information about how we process it. This is commonly known as a “data subject access request.” We will provide you with a copy of your data, usually free of charge, within one month (unless the request is complex, in which case we may extend by a further two months and inform you).
- Right to Rectification: If any of your personal data we have is inaccurate or incomplete, you have the right to have it corrected or updated without undue delay. Please contact us if you believe we hold incorrect details (for example, a misspelled name or an outdated contact number) and we will promptly rectify it.
- Right to Erasure: You can ask us to delete or remove your personal data in certain circumstances, often referred to as the “right to be forgotten.” This applies, for instance, if the data is no longer needed for the original purpose, if you withdraw consent and we have no other legal basis, or if you object to processing and we have no overriding legitimate grounds. Note that absolute erasure may not be possible if we must keep certain data by law (e.g., transaction records) or if another lawful basis applies. We will inform you if that’s the case.
- Right to Restrict Processing: You have the right to request the suspension of processing of your personal data in certain scenarios – for example, if you contest the accuracy of the data or have objected to our processing (pending verification of our grounds). While processing is restricted, we will still store your data but not use it for the time being.
- Right to Data Portability: For data you provided to us and which we process by automated means on the basis of your consent or contract, you have the right to request a copy in a structured, commonly used, machine-readable format, and/or to have that data transmitted to another service provider where technically feasible. For example, if you provided us with certain information in the booking process, you can ask us to transfer that data to a competitor rental agency’s system if you wish.
- Right to Object: You may object to our processing of your personal data where we rely on legitimate interests as the basis, if you feel it impacts your rights and freedoms. You also have an absolute right to object to your data being used for direct marketing. If you object, we will consider whether our processing has compelling legitimate grounds that override your rights, or if we need to continue processing for legal claims; otherwise, we will cease the processing in question.
- Right to Withdraw Consent: If we are processing your personal data based on your consent, you have the right to withdraw that consent at any time. For example, you can opt out of marketing emails by clicking “unsubscribe” in any message or by contacting us. Withdrawing consent will not affect the lawfulness of any processing carried out before you withdrew.
- Right to Lodge a Complaint: If you believe we have infringed your data protection rights or not handled your personal data properly, you have the right to complain to a supervisory authority. Sky Universe Ltd is established in Cyprus, so our lead supervisory authority is the Office of the Commissioner for Personal Data Protection (Cyprus). You can find their contact details on their official website or contact them by phone or mail. We would, however, appreciate the chance to address your concerns directly before you approach the authority – please see Contact Us below to reach our team, and we will do our best to resolve any issue.
To exercise any of your rights, please contact us via the details provided in Contact Us. We may need to verify your identity (for example, by asking for information that confirms you are the account holder or the person who made the booking) to ensure we don’t disclose data to the wrong person. We will respond to all legitimate requests as soon as possible and at least within the legally required timeframes.
10. Children’s Privacy
Our website and services are not directed to children under the age of 14. In fact, under Cyprus law, children under 14 cannot validly give consent for information society services, and we do not knowingly collect personal data from anyone under 14 without parental consent. If you are under 14, please do not use our contact forms, book accommodations, or provide any personal information to us unless your parent or guardian has given permission.
If we learn that we have inadvertently collected personal data from a child under 14 without appropriate consent, we will delete that information promptly. Parents or guardians who discover that their child may have provided us personal data should contact us, and we will remove the data and unsubscribe the minor from any of our services.
For minors aged 14 to 17: If you are at least 14 but under 18, you should only use the site and provide personal data with the consent and supervision of a parent or guardian. Rental bookings can only be made by adults (18+). We reserve the right to refuse bookings if we suspect they are made by minors without proper authority.
11. Data Security
We take the security of your personal data very seriously. We have implemented appropriate technical and organizational measures to prevent unauthorized access, alteration, disclosure, or loss of your personal information. These include:
- Encryption: Our website is protected with HTTPS encryption (TLS) to secure data in transit. Sensitive transactions (such as payment processing) are conducted via secure encrypted channels.
- Access Controls: Personal data is stored on secure servers, and access to those systems is limited to authorized personnel who require it for their job duties. Access is protected by strong passwords and, where possible, two-factor authentication. We enforce principles of least privilege and regularly review user access rights.
- Firewalls and Monitoring: We use firewalls and intrusion detection systems to guard our network. Our IT team (or external hosting provider) monitors for suspicious activities and regularly updates systems with security patches to mitigate vulnerabilities.
- Training and Policies: Our staff are trained in data protection best practices and are required to follow internal policies on confidentiality and data handling. We have procedures in place to handle any suspected data security breach swiftly and effectively.
- Vendor Due Diligence: When we use third-party processors (like those mentioned earlier), we select reputable companies and ensure they also implement adequate security measures. We review their certifications or compliance (for example, payment processors should be PCI-DSS compliant for handling card data).
Despite our efforts, please note that no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security of information, especially information transmitted via email or the web. You also play a role in security: please use strong, unique passwords if you create an account on our site (if applicable), and do not share your booking confirmation or personal details with unauthorized parties. If you suspect any unauthorized access or security incident involving your data, notify us immediately so we can investigate.
12. Regulatory Compliance and Data Protection Officer
Sky Universe Ltd complies with the GDPR’s accountability requirements. We maintain an internal Record of Processing Activities, documenting what personal data we hold and how we use it, as required by Article 30 GDPR. We also conduct Privacy Impact Assessments for any high-risk data projects, and consult with the Cyprus Commissioner’s office when required by law for certain processing (for example, if we were to engage in high-risk processing of sensitive data).
Under GDPR, we are not required to register our data processing with the Data Protection Authority, since GDPR abolished general notification requirements. However, we remain under the supervision of the Cyprus Commissioner for Personal Data Protection, and we ensure all our processing is lawful and transparent. We will also appoint a Data Protection Officer (DPO) if our operations grow to meet the criteria where a DPO is mandated (e.g., large-scale monitoring or large-scale processing of special categories of data). As of the last update, we have not been required to designate a DPO, but we handle all privacy matters with the utmost diligence and have designated a privacy team responsible for overseeing compliance.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your personal data, you may contact us using the details below:
- By Email: info@skyuniverse.com.cy
(Please include “Privacy Inquiry” in the subject line to ensure appropriate routing.) - By Mail: Data Protection Team
Sky Universe Ltd
Georgiou A’ 105, Sea Gate, Flat 4-2
Germasogeia 4048, Limassol
Cyprus - By Phone: +357 96661068
(For general enquiries. Privacy-related requests should preferably be submitted in writing to ensure proper documentation.)
We will respond to your request as soon as reasonably possible and, in any event, within one (1) month of receipt, in accordance with applicable data protection legislation.
For security and privacy purposes, we may require verification of your identity before disclosing, amending, or deleting any personal data.




