Legal
Privacy Policy
Last updated: 30 June 2026
1. Data Controller
Cocoon Bay is operated by HOMEQUANT, Grand Baie, Mauritius. For all privacy enquiries: bookings@cocoonbay.com
As an operator based in Mauritius with EU-based partners, we comply with both the Mauritius Data Protection Act 2017 and, where applicable, the EU General Data Protection Regulation (GDPR).
2. Data We Collect
We collect the following information when you make a booking:
- Full name
- Email address
- Phone number
- Country of residence
- Nationality
- Stay dates and booking details
Nationality is collected in accordance with Mauritius legal requirements applicable to tourist accommodation providers. We do not collect payment card data — payments are made by direct bank transfer.
3. How We Use Your Data
Your data is used solely for the following purposes:
- Contract performance — processing your booking, sending confirmations, stay communications, pre-arrival information.
- Legal obligation — compliance with Mauritius guest registration and tourism authority requirements.
- Legitimate interests — operational management of the property, guest support, and improving our service.
We do not sell your data to third parties and do not use it for marketing without your explicit consent.
4. Data Processors
Your data may be shared with the following third-party processors, strictly for the purposes stated:
- Supabase (data storage) — servers located in the EU (Ireland). GDPR-compliant infrastructure.
- Resend (transactional email delivery) — EU-based infrastructure.
- HOMEQUANT — on-site operations team in Mauritius, access limited to data required for managing your stay.
5. Retention
Booking records are retained for 7 years in accordance with Mauritius tax and legal obligations (Income Tax Act, Value Added Tax Act).
Personal data (name, email, phone) may be deleted on request after your stay is complete, subject to any overriding legal obligations.
6. Your Rights (DPA 2017 & GDPR)
Under the Mauritius Data Protection Act 2017 and, where applicable, the GDPR, you have the following rights:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to object to processing
- Right to data portability
To exercise any of these rights, contact us at bookings@cocoonbay.com. We will respond within 30 days.
You may also lodge a complaint with the Mauritius Data Protection Office: dataprotection.govmu.org. EU guests may also contact their national data protection authority.
7. International Transfers
Your data is stored on Supabase servers located in Ireland (European Union), which provides an adequate level of data protection under GDPR. No transfers to countries without adequate protection take place.
8. Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or disclosure, in accordance with Section 22 of the Mauritius Data Protection Act 2017.
9. Changes to This Policy
We may update this policy at any time. The current version is always available on this page.