Iliano Villas
enitfr
Back to Iliano Villas

Privacy & GDPR

Last updated 21 September 2026

This notice explains how Iliano Villas collects and uses your personal data when you visit our website, contact us or stay with us. It is written to meet the EU General Data Protection Regulation (GDPR), the UK GDPR and Kenya’s Data Protection Act, 2019.

1. Who is responsible for your data

Iliano Villas, Watamu, Kilifi County, Kenya, is the data controller. For any question about your data or to exercise your rights, write to stay@ilianovillas.com.

2. What we collect

3. Why we use it and our legal basis

4. Cookies and similar technologies

We use only what is strictly necessary for the site to work:

We do not use analytics, advertising or social media tracking cookies, so we do not ask for cookie consent. Our fonts are hosted on our own server, so loading the site does not send your data to font providers.

5. Who we share it with

We never sell your data. We share it only where needed, with:

Our Google reviews are loaded by our server, so viewing them does not share your data with Google.

6. International transfers

We are based in Kenya and some of our providers operate in other countries, including the EU and the United States. Where your data is transferred outside the EU/EEA, the UK or Kenya, we rely on adequacy decisions or appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

7. How long we keep it

8. Your rights

Depending on where you live, you have the right to:

To use any of these rights, email stay@ilianovillas.com. We will reply within one month and will not charge a fee in most cases.

9. Complaints

If you are unhappy with how we handle your data, please tell us first so we can try to put it right. You also have the right to complain to a supervisory authority: in Kenya, the Office of the Data Protection Commissioner (odpc.go.ke); in the EU, the authority in your country, such as the Garante per la protezione dei dati personali in Italy or the CNIL in France; in the UK, the Information Commissioner’s Office.

10. Security

We use appropriate technical and organisational measures to protect your data, including encrypted connections (HTTPS), restricted access and trusted providers. No system is completely secure, but we work to keep risks low and will act promptly if something goes wrong.

11. Children

Bookings must be made by adults. We only hold data about children when a parent or guardian gives it to us as part of a booking.

12. Changes to this notice

We may update this notice from time to time. The date at the top shows when it last changed.