
Privacy Policy
Last updated: 18 May 2026
1. Introduction
Kopiaste ("we", "us", "our") operates the website kopiastecyprus.com and the Kopiaste mobile application. We are committed to protecting and respecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) (Regulation (EU) 2016/679) and the Cyprus Processing of Personal Data Law (Law 125(I)/2018).
This policy explains how we collect, use, store, and protect your personal data when you use our services.
2. Data Controller
Kopiaste is the data controller for all personal data processed through our services.
- Operator: Kopiaste
- Registered address: Limassol, Cyprus
- Contact: info@kopiastecyprus.com
3. What Data We Collect
We may collect and process the following categories of personal data:
3.1 Data you provide directly
- Account information: name, email address, profile photo, phone number
- Booking information: selected experiences, dates, number of guests, special requirements
- Payment information: processed by Stripe (we do not store card details)
- Communication: messages with hosts, AI Concierge conversations, support requests
- Reviews and feedback: ratings, written reviews, photos you submit
- Partner/host information: business name, address, tax identification, bank details
3.2 Data collected automatically
- Device information: browser type, operating system, screen resolution
- Usage data: pages visited, features used, click patterns, session duration
- Location data: general location based on IP address (with your consent)
- Cookies and similar technologies (see our Cookie Policy)
3.3 Data from third parties
- Google: name, email, profile photo (when you sign in with Google)
- Facebook: name, email, profile photo (when you sign in with Facebook)
- Apple: name, email (when you sign in with Apple)
4. How We Use Your Data
We process your personal data for the following lawful purposes:
- Contractual necessity: To facilitate bookings, process payments, and deliver our services
- Legitimate interest: To improve our services, prevent fraud, ensure security, and personalize your experience
- Consent: For marketing communications, location-based features, and non-essential cookies
- Legal obligation: To comply with tax, anti-money laundering, and other regulatory requirements in Cyprus and the EU
5. Data Sharing
We may share your personal data with:
- Experience hosts: Your name, booking details, and communication are shared with the host you book with
- Stripe: Payment data is processed by Stripe, Inc. (PCI DSS compliant). We do not store card numbers
- Google Firebase: Infrastructure provider for hosting, authentication, and database services
- Google AI (Gemini): Powers the AI Concierge feature. Conversations are processed to generate responses
- Analytics providers: Aggregated, anonymized usage data
- Legal authorities: When required by Cyprus or EU law
6. International Transfers
Your data may be processed outside the European Economic Area (EEA) by our service providers (Google, Stripe). We ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Participation in the EU-US Data Privacy Framework where applicable
- Compliance with PCI DSS for all payment data
7. Data Retention
- Account data: Retained for the duration of your account plus 3 years after deletion for legal compliance
- Booking data: Retained for 7 years (Cyprus tax and legal requirements)
- AI Concierge conversations: Not permanently stored; used only for the current session
- Marketing data: Retained until you withdraw consent or unsubscribe
- Cookies: As specified in our Cookie Policy
8. Your Rights under GDPR
As a data subject in the EEA, you have the right to:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion of your data ("right to be forgotten")
- Restriction: Limit how we process your data
- Data portability: Receive your data in a structured, machine-readable format
- Object: Object to processing based on legitimate interest
- Withdraw consent: Withdraw consent at any time where processing is based on consent
- Lodge a complaint: With the Cyprus Commissioner for Personal Data Protection (www.dataprotection.gov.cy)
To exercise any of these rights, contact us at info@kopiastecyprus.com. We will respond within 30 days.
For information about cancellations and refunds, please see our .
9. Data Security
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption in transit (TLS/HTTPS) and at rest
- Firebase Security Rules limiting data access to authorized users only
- Regular security reviews and access controls
- PCI DSS compliance via Stripe for all payment processing
10. Children's Privacy
Our services are not directed to individuals under 18. We do not knowingly collect personal data from children. If we become aware that a child under 18 has provided us with personal data, we will take steps to delete it. Bookings for children must be made by an adult.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on our website and updating the "Last updated" date. Your continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact
If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: info@kopiastecyprus.com
- Address: Limassol, Cyprus
- Data Protection Officer: Available upon request
13. Legal Basis for Processing (GDPR Art. 6)
We process your personal data under the following legal bases established by Article 6 of the General Data Protection Regulation:
- Consent (Art. 6(1)(a)): We rely on your consent for marketing communications, newsletter subscriptions, location-based features, and non-essential cookies. You may withdraw consent at any time.
- Contractual necessity (Art. 6(1)(b)): We process your data to facilitate bookings, process payments, deliver experiences, and manage your account — all of which are necessary for the performance of a contract between you and Kopiaste (or between you and a Host via our platform).
- Legal obligation (Art. 6(1)(c)): We retain booking and financial records for 7 years to comply with Cyprus tax law, anti-money laundering regulations, and other EU statutory requirements.
- Legitimate interest (Art. 6(1)(f)): We process data for fraud prevention, platform security, service improvement, and personalization of your experience. Our legitimate interests do not override your fundamental rights and freedoms.
14. Data Subject Rights (GDPR Art. 15–22)
Under the GDPR, you have the following rights regarding your personal data. To exercise any of these rights, contact us at info@kopiastecyprus.com. We will respond within 30 days.
14.1 Right of Access (Art. 15)
You have the right to obtain confirmation that we are processing your personal data and to receive a copy of that data, along with information about the purposes, categories of data, recipients, retention period, and your other rights.
14.2 Right to Rectification (Art. 16)
You have the right to request the correction of inaccurate or incomplete personal data. You may update your profile information directly in your account settings or contact us for assistance.
14.3 Right to Erasure (Art. 17)
Also known as the "right to be forgotten," you may request deletion of your personal data when it is no longer necessary for the purpose it was collected, you withdraw consent, you object to processing, or the data was unlawfully processed. We may retain certain data where required by law (e.g., tax records).
14.4 Right to Restriction of Processing (Art. 18)
You may request that we limit the processing of your data — for example, while a rectification request is being assessed, if processing is unlawful but you prefer restriction over erasure, or if we no longer need the data but you need it for legal claims.
14.5 Right to Data Portability (Art. 20)
You have the right to receive your personal data in a structured, commonly used, and machine-readable format (such as JSON or CSV) and to transmit that data to another controller. This applies to data you provided to us based on consent or contract, processed by automated means.
14.6 Right to Object (Art. 21)
You may object to the processing of your personal data based on legitimate interests or for direct marketing. Where you object to processing for direct marketing, we will stop processing your data for that purpose.
14.7 Right to Lodge a Complaint (Art. 77)
You have the right to lodge a complaint with the Cyprus Commissioner for Personal Data Protection (www.dataprotection.gov.cy) or with another EU supervisory authority if you believe our processing of your data infringes your rights.
15. Data Retention Schedule
We retain personal data only as long as necessary for the purposes for which it was collected, and in accordance with legal requirements:
- Booking and payment records: 7 years (Cyprus tax law and accounting requirements)
- Account data: Duration of your active account, plus 3 years after deletion for legal compliance
- Reviews and ratings: Retained indefinitely as they contribute to platform trust and are not personally identifiable once account data is deleted
- Newsletter subscriptions: Until you unsubscribe or withdraw consent
- AI Concierge conversations: Not permanently stored — used only within the active session
- Marketing data: Until you withdraw consent or opt out
- Support tickets: 2 years after resolution
- Partner/host data: Duration of partnership plus 3 years for legal compliance
16. Data Sharing and Recipients
We share your personal data with the following third-party service providers, each acting as a data processor under our instructions:
- Stripe, Inc. (PCI DSS compliant) — processes all payment transactions. We do not store your card details. See Stripe's Privacy Policy.
- SendGrid (Twilio Inc.) — delivers transactional and marketing emails on our behalf. See SendGrid's Privacy Policy.
- Google Analytics — provides aggregated, anonymized usage analytics. We use GA4 with IP anonymization. See Google's Privacy Policy.
- Google Firebase — provides infrastructure services including hosting, authentication, database (Firestore), cloud functions, and crash reporting. See Firebase Privacy.
- Google AI (Gemini) — powers the AI Concierge feature. Conversations are processed to generate responses but are not permanently stored by Kopiaste.
- Experience hosts — your name, booking details, and communications are shared with the Host you book with.
- Legal authorities — when required by Cyprus or EU law, court order, or regulatory request.
17. International Data Transfers
Your personal data may be processed outside the European Economic Area (EEA) by our service providers, including Google (United States) and Stripe (United States). We ensure appropriate safeguards are in place for such transfers:
- Standard Contractual Clauses (SCCs): We use the European Commission-approved SCCs with all service providers transferring data outside the EEA.
- EU-US Data Privacy Framework: Where applicable, our service providers participate in the EU-US DPF, providing an adequate level of protection.
- PCI DSS compliance: All payment data processing by Stripe meets PCI DSS standards.
- Transfer impact assessments: We conduct assessments of third-country transfer risks as required by GDPR and ECJ guidance.
You may request a copy of the safeguards we have in place by contacting us at info@kopiastecyprus.com.
18. Cookies
We use cookies and similar technologies (localStorage, sessionStorage) to operate and improve our services. Cookies are small text files stored on your device.
- Essential cookies: Required for the website to function (authentication, session management, security). These cannot be disabled.
- Analytics cookies: Help us understand how visitors use our site (Google Analytics). Enabled only with your consent.
- Marketing cookies: Used to personalize content and ads. Enabled only with your consent.
When you first visit our site, we display a cookie consent banner allowing you to accept, reject, or customize your cookie preferences. You can change your cookie preferences at any time.
For full details on all cookies we use and how to manage them, please see our .
19. Children's Data
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children under 16.
- If a child under 16 requires access to our services, a parent or legal guardian must provide consent and manage the account on their behalf.
- Bookings for children (e.g., family experiences) must be made by an adult aged 18 or over.
- If we become aware that a child under 16 has provided us with personal data without parental consent, we will take steps to delete that data promptly.
- If you believe a child has provided us with personal data, please contact us immediately at info@kopiastecyprus.com.
20. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or service features.
- Material changes: We will notify you by email (if you have an account) and display a prominent notice on our website at least 14 days before the changes take effect.
- Minor changes: We will update the "Last updated" date at the top of this page.
- Continued use: Your continued use of our services after the effective date constitutes acceptance of the updated policy.
- Subscription notifications: If you have opted into our newsletter, we will also notify subscribers of significant privacy policy changes.
21. Contact & Data Protection Officer
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your GDPR rights, please contact us:
- Email: info@kopiastecyprus.com
- Postal address: Limassol, Cyprus
- Data Protection Officer: Available upon request at privacy@kopiastecyprus.com
You also have the right to lodge a complaint with the Cyprus data protection authority:
- Office of the Commissioner for Personal Data Protection
- Website: www.dataprotection.gov.cy
- Email: commissioner@dataprotection.gov.cy
- Address: 1 Gregori Afxentiou, 1041 Nicosia, Cyprus
For our company information, please see our page.