← back to maison rêves
legal

Privacy Policy

Last updated: 25 June 2026
Applies to maison-reves.com and the Maison Rêves Client Portal.

We are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679 — and the Cyprus Law on the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).

01

Who We Are

Data Controller: Maison Rêves, Limassol, Cyprus
hello@maison-reves.com

Maison Rêves is a luxury construction consultancy providing client-side project management and construction monitoring services in Cyprus. We operate the website at maison-reves.com and a client portal at maison-reves.com/portal. As data controller we determine the purposes and means of processing your personal data.

We do not have a designated Data Protection Officer as we do not carry out large-scale systematic monitoring or process special categories of data at scale. Direct all privacy enquiries to hello@maison-reves.com.

02

Data We Collect

a) Contact form

  • First and last name
  • Email address
  • Phone number (including country code)
  • Project type and budget range
  • Location (city and area in Cyprus)
  • Free-text project description

b) Client portal

  • Email address and password (authentication)
  • Full name and phone number (profile)
  • Profile photograph (optional, uploaded by you)
  • Project communications (in-portal chat messages)
  • Access logs (sign-in timestamps)

c) Technical data (automatic)

  • IP address (Cloudflare bot protection)
  • Browser type and version
  • Device type and operating system
  • Pages visited and session duration (analytics, consent only)
  • Referring URL

We do not collect special categories of personal data (health, racial/ethnic origin, political opinions, religious beliefs, or biometric data) and we do not knowingly collect data from children under 16.

03

How We Use Your Data

PurposeData UsedLegal Basis
Responding to contact form enquiriesName, email, phone, project detailsLegitimate interest / Pre-contractual steps
Delivering portal access and weekly reportsEmail, name, project data, portal activityPerformance of a contract
Sending portal invitations and password resetsEmail addressPerformance of a contract
Sending report and message notificationsEmail addressPerformance of a contract
Bot protection via Turnstile captchaIP address, browser fingerprintLegitimate interest
Improving site performance (analytics)Anonymised usage dataConsent
Legal and regulatory complianceAs required by applicable lawLegal obligation

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.

05

Cookies & Tracking Technologies

When you first visit maison-reves.com you are shown a cookie consent banner. Strictly necessary cookies are always active; all other categories require your explicit consent. Your choice is stored in a cookie named mr_cookie_consent for 12 months — the GDPR maximum for consent cookies. You can update your preferences at any time using the "cookie preferences" link in the footer.

CookieCategoryPurposeDurationProvider
mr_cookie_consentStrictly NecessaryStores your cookie consent choices12 monthsMaison Rêves (1st party)
mr_tokenStrictly NecessaryPortal authentication token (localStorage)Session / sign-outMaison Rêves / Supabase
mr_userStrictly NecessaryPortal session user info (localStorage)Session / sign-outMaison Rêves / Supabase
cf_clearanceStrictly NecessaryCloudflare bot protection tokenSessionCloudflare
_ga, _gidAnalytics & PerformanceGoogle Analytics — anonymised statistics (consent only)Up to 2 yearsGoogle (3rd party)
06

Third-Party Services

We use the following processors. Where located outside the EEA, transfers are protected by Standard Contractual Clauses (SCCs) or the EU–US Data Privacy Framework (DPF).

ServicePurposeData SharedLocationSafeguard
FramerWebsite hostingPage visits, IPUSASCCs / DPF
SupabaseDatabase, auth, storageEmail, name, phone, project data, photosEU (Frankfurt)EU hosting — no transfer
CloudflareBot protection, CDNIP address, browser dataUSA / GlobalSCCs / DPF
EmailJSContact form deliveryName, email, phone, project detailsUSASCCs
ResendTransactional emailEmail address, message contentUSASCCs
Google FontsTypeface loadingIP address (font request)USA / GlobalSCCs / DPF

We do not sell your data to any third party and do not share it with advertisers or data brokers.

07

Data Retention

Data TypeRetention PeriodReason
Contact form enquiries3 years from last contactLegitimate interest — potential client relationship
Client portal accountsEngagement + 2 yearsContractual obligation and legal compliance
Weekly reports and project dataEngagement + 5 yearsProfessional records and potential disputes
Portal messages / chat logsEngagement + 2 yearsRecord of project communications
Authentication logs90 daysSecurity monitoring
Cookie consent record12 monthsProof of consent under GDPR Art. 7

When data is no longer required it is securely deleted or anonymised. You may request earlier deletion — see Your Rights.

08

Your Rights Under GDPR

Under GDPR Articles 15–22 you have the right to:

  • Access (Art. 15): Request a copy of your personal data and information about how we process it.
  • Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Erasure / right to be forgotten (Art. 17): Request deletion where there is no overriding reason to continue processing.
  • Restriction (Art. 18): Request we limit processing while a complaint or objection is being resolved.
  • Data portability (Art. 20): Receive your data in a machine-readable format and transfer it to another controller.
  • Object (Art. 21): Object to processing based on legitimate interests or for direct marketing — with immediate effect for marketing.
  • Withdraw consent (Art. 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.
  • No automated decisions (Art. 22): Not be subject to purely automated decisions that significantly affect you. We do not carry out such processing.

To exercise any right, email hello@maison-reves.com. We will respond within 30 days (Art. 12 GDPR). No charge unless requests are manifestly unfounded or excessive.

To lodge a complaint with the supervisory authority in Cyprus:

09

International Transfers

Some processors are located outside the EEA (primarily the USA). Transfers are protected by SCCs (Commission Decision 2021/914/EU) and/or the EU–US Data Privacy Framework adequacy decision (C(2023) 4745). Supabase stores portal data within the EU (AWS eu-central-1, Frankfurt) — no international transfer occurs for your primary project data.

10

Children's Privacy

Our services are for business and professional use only. We do not knowingly collect data from anyone under 16. Under Art. 8 GDPR and Cyprus Law 125(I)/2018, processing a child's data requires parental consent. If you believe we have inadvertently collected such data, contact us immediately at hello@maison-reves.com and we will delete it without undue delay.

11

Changes to This Policy

We may update this policy to reflect changes in our practices or legal obligations. Material changes will be indicated by an updated "Last updated" date and notified by email or portal notice where appropriate. If cookie practices change, the consent version number will increment and you will be re-asked to consent. Previous versions are available on request.

12

Contact & Data Controller

Maison Rêves

Limassol, Cyprus

hello@maison-reves.com

We will acknowledge your request within 5 working days and respond fully within 30 days (Art. 12 GDPR). Where a request is complex we may extend by a further two months — we will inform you of any extension within the first 30 days.

Prepared in accordance with Regulation (EU) 2016/679 (GDPR), Cyprus Law 125(I)/2018, and the EU ePrivacy Directive 2002/58/EC. Effective from 25 June 2026.