Legal
Data Processing Agreement
Last updated: 1 September 2026
This page summarises how Cove & More handles personal data as a data controller and, where relevant, engages processors — in line with the EU General Data Protection Regulation (GDPR) and Cyprus's Law 125(I)/2018 implementing it.
Our role
For enquiry and client data (name, contact details, weekend preferences), Cove & More acts as the data controller — we decide why and how this data is used, as set out in our Privacy Policy .
Sub-processors we use
We use a small number of trusted service providers to run our enquiry and communication systems (for example, spreadsheet-based record keeping and email delivery). Each acts as a data processor on our behalf, bound by their own data processing terms, and does not use your data for their own purposes.
Sharing with suppliers
We do not share your personal data with villas, yacht operators, restaurants or other third-party suppliers unless and until you confirm you want to proceed with a specific booking — at which point only the details needed to complete that booking are shared, and that supplier becomes an independent controller of the data you provide them directly.
International transfers
Where a service provider we use stores data outside the EU/EEA, we rely on appropriate safeguards (such as Standard Contractual Clauses) as required by GDPR.
Requesting a formal DPA
If you represent a corporate group and require a signed Data Processing Agreement or Data Protection Impact Assessment information for your own compliance records, contact us at support@coveandmore.com and we will provide one.
Supervisory authority
If you believe your data protection rights have not been respected, you may lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus.