PRIVACY POLICY

1. OBJECTIVE OF THIS PRIVACY POLICY

This privacy notice is intended to inform you about how Sunvista.ky handles your Personal Data when you use this Website, including any information you may submit through the sign-up forms on this Website. Please note that this Website is not designed for children, and we do not knowingly collect data from individuals under the age of 18.

We recommend that you review this privacy notice in conjunction with any other privacy or fair processing notices provided on specific occasions when we process your Personal Data. This ensures that you fully understand how and why we use your data. This privacy notice complements those other notices and does not supersede them. It is crafted to align with applicable privacy laws, including the EU and the UK General Data Protection Regulation.

2. MODIFICATIONS TO THE PRIVACY NOTICE AND OUR RESPONSIBILITY TO NOTIFY YOU OF CHANGES

Kindly note the last update date of the privacy notice mentioned above. If significant modifications are made to this privacy notice in the future, we will notify you beforehand through the Website.

3. OUR IDENTITY (CONTROLLER) AND HOW TO REACH US

a. Who we are

Sunvista is a premier destination management company which specializes in offering discerning clients the opportunity to experience the Cayman Islands at its best. With intimate knowledge of the Island’s finest accommodations, most luxurious transportation solutions, exquisite restaurants, places to go, and things to do, we are able to create our clients wishes into a delightful stay in paradise. Name the size of your dream and let’s make it a reality in Cayman. (collectively referred to as “Sunvista’’, “we”, “us” or “our” in this privacy notice) in context of this Website.

Sunvista is a private entity which performs business in the Cayman Islands. As such, Sunvista does not formally have to appoint a local EU or UK representative.

b. Our Data Protection Compliance Manager

We have appointed a Data Protection Compliance Manager (DPCM) who is responsible for overseeing questions in relation to this privacy notice. If you have any questions about this privacy policy / notice, including any requests to exercise your legal rights, please contact the DPCM using the details set out below or at enquiries@Sunvista.ky

4. THE DATA / INFORMATION WE COLLECT & PROCESS ABOUT YOU

a. Personal Data

Personal Data, or personal information, refers to any details that can identify an individual. It excludes data where the identity has been removed (anonymous data). We may process various types of Personal Data about you, categorized as follows:

Identity Data: This includes first name, last name, gender, or similar identifiers.

Contact Data: This encompasses postal address, email address, and telephone numbers.

Technical Data: This involves the internet protocol (IP) address, login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, and other technological information from the devices you use to access this Website.

Usage Data: This comprises information about how you use our Website.

Marketing and Communications Data: This includes your choices and preferences regarding marketing communications from us and our third parties, your communication preferences, data from social media profiles and usernames, and all information provided to us via email, the Website, or other means.

Under specific circumstances, such as when you register for a webinar, training, sponsorship, or a similar event, or when you request specific assets, we may also process additional categories of your Personal Data based on the information requested in the respective sign-up form. These may include:

Financial Data: Bank account details, tax information, pay slips, credit card details, and other financial information.

Company Data: Corporate name, account statements, tax information, type of business, job roles.

Research Data: Visitor spend, demographic data, and characteristics of visits.

Employment Data: Company name, company address, company email address, company phone and fax numbers, company website, references, job history, business travel arrangements, and safety data.

Daily Work Data: Information collected and created in the context of your working relationship with SUNVISTA, including emails, work products/services, bookings, rewards, and evaluation data.

Educational Data: Education and vocational training records, including qualifications, grades, and training received.

b. Aggregated Data

Additionally, we collect, use, and share Aggregated Data, such as statistical or demographic data, for specific purposes. Aggregated Data may be derived from your Personal Data but is not considered Personal Data in law, as it does not directly or indirectly reveal your identity. For example, we might aggregate Usage Data to calculate the percentage of users accessing a particular website feature.

5. HOW WE COLLECT YOUR PERSONAL DATA?

a. Direct Interactions:

Through direct interactions, you provide us with Personal Data by filling in forms on the Website or corresponding with us via post, phone, email, or other means. This includes Personal Data you furnish when you:

Subscribe to our publications/newsletters

Complete a form

Engage in our activities (e.g., webinars and trainings)

Request marketing materials

Apply for a program or visitor status

b. Automated Technologies or Interactions:

While visiting the Website, we may automatically collect Technical Data about your equipment, browsing actions, and patterns. This Personal Data, along with Marketing and Communications Data, is gathered using cookies and similar technologies. Refer to "COOKIES" below for more details

c. Third Parties:

We typically do not obtain data from third parties unless we are engaged in joint marketing activities or training programs with another brand or organization (e.g., a tour operator). In such cases, the use of your data by each party will be explicitly communicated.

6. HOW WE PROCESS AND USE YOUR PERSONAL DATA/INFORMATIION

We only use your Personal Data when the law allows us to as described below. Most commonly, we will use your Personal Data in the following circumstances:

a. Purposes for which we process your Personal Data

Following is a description of all the ways we may process your Personal Data in connection with your visit of the Website, and which of the legal bases we rely on to do so. Please be informed that not all processing activities may be applicable to your Personal Data and that this depends on how you use the Website and interact with us. Wherever the legal basis is consent, we will ask you explicitly to consent on our Website or otherwise.

# Purpose/Activity

Type of Personal Data

Lawful basis for processing including basis of legitimate interest

1 To manage our relationship with you which will include:
(a) Respond to inquiries.
(b) Notifying you about changes to our terms or privacy policy
(c) Asking you to leave a review or take a survey
(d) Payment of government services or programmes
(e) Daily working relationship inclusive of meetings

1 (i) Identity
(ii) Contact
(iii) Profile
(iv) Marketing and Communications
(iv) Financial
(v) Company
(vi) Employment
(vii) Daily work

1 (a) Necessary to comply with a request from you (contract performance).
(b) Necessary to comply with legal obligations.
(c) Necessary for our legitimate interests (to keep our records updated and to study how customers use our products/services)
(d) Your consent

2 To administer and protect our business and this Website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data).

2 (i) Identity
(ii) Technical

2 (a) Necessary for our legitimate interests (for running our business, provision of administration and IT services, network security).
(b) Necessary to comply with a legal obligation

3 We send you marketing communications if you have requested information from us based on your interests.

3 (i) Identity
(ii) Contact
(iii) Profile
(iv) Usage
(v) Marketing and Communications
(vi) Technical

3 Your consent

4 To deliver relevant website content, including marketing information, to you and measure or understand the effectiveness of the communication (including in emails) that we serve to you.

4 (i) Identity
(ii) Profile
(iii) Usage
(iv) Marketing and Communications
(iv) Technical

4 Your consent

5 To use data analytics to improve our Website, products/services, marketing, customer relationships and experiences.

5 (i) Technical
(ii) Usage

5 Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Website updated and relevant, to develop our business and to inform our marketing strategy)

6 To deliver relevant Marketing materials to individuals subscribed to our mailing lists. Materials including news articles, newsletters and event invitations.
We use an email cleaning software and mailing list software in conjunction with our CRM to deliver the communication by email.

6 (i) Identity
(ii) Contact
(iii) Profile
(iv) Usage
(v) Marketing and Communications
(vi) Technical
(vii) Company

6 Your consent

7 To feature your images or videos (“User Assets”) shared with us via our Website, email, digital asset management tool, or by other available means on our Website or on the official SUNVISTA social media channels

7 (i) Identity
(ii) Marketing and Communications Data

7 (a) Your consent
(b) Necessary to prepare and perform the license agreement with you (contract performance)

8 Research data collection (inclusive of online surveys) to measure stayover and cruise visitors. This information is used to develop policies and marketing strategies.

8 (i) Identity
(ii) Contact
(iii) Research Data

8 (a) Legitimate interest (policy development, marketing strategy development)

9 Research data collection (inclusive of online surveys) to measure stayover and cruise visitors. This information is used to develop policies and marketing strategies.

9 (i) Identity
(ii) Contact
(iii) Research Data

9 (a) Legitimate interest (policy development, marketing strategy development)

10 (a) Your consent
(b) Necessary for contract fulfilment (employment contract)
(c) Necessary to comply with legal obligations

10 (i) Identity
(ii) Contact
(iii) Marketing and Communications
(iv) Financial
(v) Company
(vi) Employment
(vii) Daily work
(viii) Educational

10 (a) Your consent
(b) Necessary for contract fulfilment (employment contract)
(c) Necessary to comply with legal obligations

b. Your choices

We strive to provide you with choices regarding certain Personal Data uses, particularly around marketing and advertising. For example, when subscribing for our newsletter, we offer a variety of information options you can choose from.

You can ask to stop sending you messages, particularly marketing messages, at any time by contacting us at enquiries@sunvista.ky . Each communication we send will also have an unsubscribe option in the footer. Please note, however, that you will not be able to opt out of certain messages that we are required to send by law or in order to fulfil contractual obligations towards you.

c. Cookies

i. What are cookies, and how do we utilize them?

"Cookies" refer to pieces of information that may be placed on your computer either by us or a service we use. The purpose is to facilitate and enhance your communication and interaction with that service. Similar technologies with comparable purposes, such as beacons or pixels, are also referred to as "cookies" in this policy. Beacons and pixels, included in the Website and emails, collect Technical Data about your equipment, Usage Data, and Marketing and Communications Data when you engage with the Website and emails.

ii. Types of cookies we use

We employ the following types of cookies on the Website:

Essential Site Functions Cookies: Necessary for browsing the Website and utilizing its functions. Without these cookies, the Website would not function correctly. The data processed by these cookies is more technical than personal and includes information about your device type and settings.

Analytical Cookies: Used to identify highly frequented content on the Website and analyze whether content needs updating or improvement. These cookies also personalize content based on your interests. Information processed and stored includes browser type, referrer URLs, operating system, date/time stamp, views and clicks on the Website, and your (truncated) IP address. We use these cookies only if you have given consent via our cookie settings page.

Advertising Cookies: Aid in displaying relevant ads on our website and partner websites. They also help control ad frequency and measure the effectiveness of marketing campaigns. Data processed and stored includes your user agent (browser software name and version), clicks, views, referrers, and URL calls. We use these cookies only if you have given consent via our cookie settings page.

Social Media Cookies: Similar to Advertising Cookies, these assist in providing relevant ads based on your interests on social platforms. They also help measure the effectiveness of marketing campaigns on social platforms. Information processed and stored includes your user agent (browser software name and version), clicks, views, referrers, and URL calls. We use these cookies only if you have given consent via our cookie settings page.

iii. Specific cookies we use

Find a list of the cookies we use at [Link to Cookie Settings], where you can also adjust your cookie preferences.

iv. How can you control cookies?

Manage cookie usage on our Website through our cookie settings page. Generally, you can configure your browser to reject some or all browser cookies or receive alerts when websites attempt to set or access cookies. Disabling or refusing cookies may result in some parts of the website becoming inaccessible or malfunctioning.

d. Social Plug-ins

i. Social Plugins

Our Website incorporates social plugins from Facebook, Twitter, LinkedIn, Pinterest, WhatsApp, Tumblr, and Reddit. These services are provided by Facebook Inc., Twitter Inc., LinkedIn Corporation, Pinterest Inc., WhatsApp Inc., Tumblr Inc., and Reddit Inc. ("Providers").

You can employ these plugins to express appreciation, share content, or engage directly on the relevant social network.

Identification of the social plugins on our Website is facilitated by their corresponding company logos.

We utilize a privacy-conscious tool known as the "Shariff button" to ensure that, before clicking on the social plugin buttons, only the server address is transmitted to the respective social network, rather than your IP address (which would typically occur immediately upon visiting our Website). By refraining from clicking on the social plugin, you remain concealed from the operators of the respective social network.

The Shariff button serves to prevent social networks from monitoring and storing internet behavior without the active participation of users.

Upon utilizing the social plugin, you implicitly consent to the collection of your personal data by the relevant network. The responsibility for data collection and processing, including the use of cookies and similar technologies, lies with the respective social network. Notably, information about the specific pages you have visited on our website and your IP address is then transmitted to the social network, even if you lack a profile with that network or are not currently logged in. If you are logged in as a member of the social networks, the network associates the information with your personal user account.

We therefore recommend that you read the privacy policy of the respective network before using the social plugin:

Facebook: https://www.facebook.com/policy.php

Twitter: https://twitter.com/en/privacy

Linkedin: https://www.linkedin.com/legal/privacy-policy

Pinterest: https://policy.pinterest.com/en/privacy-policy-2016

Whatsapp: https://www.whatsapp.com/legal/?lang=en

Tumblr: https://www.tumblr.com/privacy

Reddit: https://www.redditinc.com/policies/privacy-policy

7. SHARING / DISCLOSURES OF YOUR PERSONAL DATA

We may have to share your Personal Data with third parties set out below for the purposes set out in the table in paragraph 6 (a) above:

We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes and only permit them to process your Personal Data for specified purposes and in accordance with our instructions.

Third party services providers may only process your Personal Data for their own purposes if you have consented to this or as otherwise allowed to do so under our contracts in accordance with applicable privacy laws.

We do not rent, sell, or share personal information (as defined by California Civil Code §1798.83) about you that we collect on the Website with other people or unaffiliated companies for their direct marketing purposes, unless we have your permission. We allow access to your information to enable the delivery of online advertising to you and others on the Website and on other websites and online services from us and our third-party advertising partners, or to send you information we think may be useful or relevant to you.

In addition to other consent rights you may have, you may be able to opt out of receiving personalized advertisements on this browser or device from advertisers, or other advertising networks who are members of the Network Advertising Initiative or who subscribe to the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising by visiting the opt-out options of each of those organizations and/or via our cookie management tool.

When you opt out of personalized advertising, you may continue to see online advertising on the Website and/or our ads on other websites and online services.

8. INTERNATIONAL SHARING / TRANSFERS OF DATA / INFORMATIONS

When we transfer your Personal Data to a destination outside the EU/EEA/UK, we take measures to ensure a comparable level of protection. This involves the implementation of appropriate safeguards, including the following:

We exclusively transfer your Personal Data to countries that the European Commission or the UK Information Commissioner has recognized as providing an adequate level of protection for Personal Data.

In cases where we engage specific service providers, we may employ contracts endorsed by the European Commission or the UK Information Commissioner. These contracts ensure that Personal Data receives an equivalent level of protection as it does in Europe/the UK and are commonly known as Standard Contractual Clauses.

If you require further details or a copy of the specific mechanism employed by us for transferring your Personal Data beyond the jurisdiction, please reach out to us at enquiries@Sunvista.ky .

9. THIRD-PARTY LINKS

This website may contain links to third-party websites, blogs, news articles, social media platforms, and applications. Clicking on such links or enabling these connections may permit third parties to gather or share data about you. We do not oversee these third-party websites and disclaim responsibility for their privacy statements. Upon exiting our website, we recommend that you review the privacy notice of each website you visit.

10. DATA SECURITY

We have implemented suitable security measures to prevent the accidental loss, unauthorized use, or access, alteration, or disclosure of your Personal Data. Furthermore, access to your Personal Data is restricted to employees, agents, contractors, and other third parties who require such information for legitimate business purposes. They will process your Personal Data solely for the specified purpose or in accordance with our instructions, and are bound by a duty of confidentiality.

Procedures are in place to address any suspected breaches of Personal Data, and we will notify you and any relevant regulatory authority of a breach when legally obligated to do so.

11. DATA RETENTION

FOR HOW LONG WILL MY PERSONAL DATA BE PROCESSED? We will keep your Personal Data only for the duration necessary to achieve the purposes for which it was collected, including meeting legal obligations, or until you request its deletion. For instance:

12. YOUR LEGAL RIGHTS

a. Your Entitlements

Under specific circumstances, you possess rights as per data protection laws regarding your Personal Data.

Especially as a user based in the EU or UK accessing our Website, you reserve the right to:

If you wish to exercise any of the rights set out above, please contact us at enquiries@Sunvista.ky.

For more information on your rights and accordant requirements, please see the information provided by the EU Commission at https://ec.europa.eu/info/law/law-topic/data-protection/reform/rights-citizens_en and UK Information Commissioner at https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/individual-rights/ or contact a data protection authority in the EU or UK.

b. No fee usually required

You won't be charged a fee to access your Personal Data or to exercise any other rights. However, if your request is evidently unfounded, repetitive, or excessive, we may impose a reasonable fee or decline to comply with your request under these circumstances.

c. What we may need from you

To verify your identity and uphold your right to access your Personal Data (or exercise any other rights), we might need to solicit specific information from you. This is a precautionary security measure designed to prevent unauthorized disclosure of Personal Data to individuals lacking the rightful access. Additionally, we may reach out to you for additional details related to your request to expedite our response.

d. Time limit to respond

We aim to address all valid requests promptly, typically within one month. However, if your request is notably intricate or if you have submitted multiple requests, it might take us longer. Should this occur, we will promptly inform you and provide regular updates on the status of your request.