Spa & Wellness Design
Last updated: 8 July 2026.
Spa & Wellness Design (“we”, “us”, “our”) operates the website spawellnessdesign.com from the Republic of Cyprus and is the data controller responsible for your personal data.
Contact for data matters:
Email: hello@spawellnessdesign.com
| Data | When / why | Legal basis (GDPR Art. 6) |
|---|---|---|
| Name, email, phone, message | When you submit an inquiry through our contact form, so we can respond and advise you | Consent, and our legitimate interest in responding to inquiries |
| Live-chat messages (and any name/email you provide) | If you start a chat with us, so we can answer you in real time and follow up | Consent (you choose to start the chat) and legitimate interest |
| Approximate location & device | When you contact us or use the site or chat, your IP is used momentarily to derive an approximate country and device type — to help confirm where enquiries originate (fraud and abuse prevention), for security and routing, and for anonymous usage statistics. This lookup is performed on our own servers — your IP is not shared with any third party and is not stored alongside this data. See sections 4 and 8. | Legitimate interest (fraud prevention & security) |
| Usage statistics (cookieless) | Pages viewed, referring site, approximate country and device — collected without cookies and without storing your IP address, so they cannot identify you | Legitimate interest |
| IP address & technical data | Recorded briefly in standard server logs to keep the site running and secure | Legitimate interest (security, fraud prevention) |
We collect only what we need. We do not sell your data, and we do not use it for automated decision-making or profiling.
Your data is stored on our own server infrastructure. We do not sell it or share it for advertising. We share it only with:
We use privacy-first, first-party usage statistics (no cookies, no advertising networks, no Google Analytics), and our approximate-location lookup runs on our own servers, so your IP address is not shared with any third-party analytics or geolocation service.
Our website infrastructure is located in the Netherlands (European Union), so your data is stored within the European Economic Area (EEA). Where a service provider (such as our email provider) processes data outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
Under the GDPR you have the right to: access your data; correct it; request its deletion; restrict or object to its processing; data portability; and to withdraw consent at any time. To exercise any of these, email hello@spawellnessdesign.com. You also have the right to lodge a complaint with your local data-protection authority.
The site is served exclusively over encrypted HTTPS. Our database is not exposed to the public internet, administrative access is restricted and protected, and secrets are stored securely. We apply appropriate technical and organisational measures to protect your data.
Cookies are small files stored on your device. Our approach is deliberately minimal:
Our web fonts are self-hosted, so loading the site does not send your data to Google or any third-party font provider. You can control or delete cookies and local storage through your browser settings at any time.
We may update this policy from time to time. The “last updated” date at the top reflects the latest version.
Questions about this policy or your data: hello@spawellnessdesign.com.