Privacy Policy

Last Updated: August 29, 2026 

At Baystone Boutique Hotel & Spa, we are highly committed to protecting your personal data and ensuring transparency regarding how we collect, store, and utilize your information under the Mauritian Data Protection Act (DPA) and applicable international frameworks, such as the General Data Protection Regulation (GDPR: No. 2016-679).

1. Presentation & Data Collection Controller

For any Personal Data collected during your navigation, inquiry forms, or room booking processes on this website, the official Data Controller is: 

  • Operating Entity: Charlie Leisure Group Ltd (BRN C13100542) 
  • Legal Representative & Data Protection Officer: Stéphanie Lebon – baystone@baystone.mu 
  • Physical Address: X club road, Pointe aux Canonniers, 30515 Grand Baie, Mauritius

As the controller of the data we collect, we commit to fully respecting all legal frameworks in force. It is our duty to establish explicit purposes for processing data and to provide our prospects and clients with complete information regarding their data processing metrics upon collecting explicit consent.

2. Purpose and Finality of Collected Data

https://www.baystone.mu may process all or part of your data to ensure seamless luxury hospitality operations: 

  • Service Fulfillment: To allow browsing on the site and execution of ordered bookings (connection logs, transactional bookkeeping, billing, and reservation histories via our secure ResRequest engine). 
  • Cybersecurity Management: To prevent and counter computer fraud, hacking, spamming, or unauthorized system access attempts (tracking user IP addresses, browser variations, and secure hashed passwords). 
  • Quality Control: To optimize site navigation, performance layouts, and run occasional, completely voluntary guest satisfaction surveys using your email address. 
  • Direct Communications: To execute transactional email confirmations, coordinate your arrival parameters, or send authorized news updates. 

Baystone Boutique Hotel & Spa does not lease, sell, trade, or commercialize your personal data to external third-party marketing agents under any circumstances.

3. Your Rights (Access, Rectification, and Opposition)

In compliance with data protection codes, users possess complete individual control over their private files: 

  • Right of Access & Rectification: The right to verify, complete, or update your personal parameters. 
  • Right to Erasure: The right to demand absolute removal of your data records when they are found to be inaccurate, outdated, or whose collection is legally prohibited. 
  • Right to Withdraw Consent: The right to cancel your consent settings for marketing materials at any time. 
  • Right to Restriction & Objecting: The right to object to specific automated processing or file transfers. 

If you wish to enforce your legal data rights or request historical data modification, you can write directly to our officer at: 

  • Mailing Address: Charlie Leisure Group Ltd – DPO, Stéphanie Lebon, X club road, Pointe aux Canonniers, 30515 Grand Baie, Mauritius. 
  • Electronic Contact: baystone@baystone.mu 

To process your security request, you must provide precise identification parameters alongside a clear copy of a valid photo identity asset (passport or national ID card). Requests for absolute deletion remain bound by statutory Mauritian corporate bookkeeping and historical financial archive laws. Users also retain the right to lodge a formal grievance regarding data execution handling with the Mauritian Data Protection Office.

4. Non-Communication and Secure Data Transfers

https://www.baystone.mu will not host, trade, or transfer technical client data profiles to locations outside of verified adequate territories without prior notification. Our primary infrastructure is established 100% locally in secure datacenters within Mauritius via our hosting provider, HOSTED Ltd (cloud.mu), which ensures compliance with local Mauritian data privacy protection regulations. 

We remain free to pick our technical data processors (such as our core booking software engine partner, ResRequest) provided they showcase sufficient standard technical guarantees to safely process secure hospitality profiles. We execute standard industry practices to preserve the isolation of your information, ensuring it is never accessed by unauthorized staff. In the event of a technical data breach impacting guest record profiles, our team will notify affected customers as soon as possible alongside details on the specific correction protocols deployed.

5. Secure Financial Systems

  • Once you have made your hotel reservation online, you will be asked to proceed with payment. We currently accept VISA & MASTERCARD in MUR.
  • All confidential credit card details are transmitted directly in an encrypted format to our secure, 3D-secure merchant payment gateway servers managed by our licensed and authorized Mauritian financial institution, without ever passing through any physical device or server within our hotel network.
  • Once the bank details are validated, the secure payment management systems send an authorization request to the bank card network. For all transactions, payment of the booking shall constitute signature and express acceptance of the sale.
  • Refunds (when applicable) will only be made back to the original credit card used to secure the booking.
Special offer — check availability for a discount price Special offer — check availability for a discount price Special offer — check availability for a discount price Special offer — check availability for a discount price