This Privacy Policy explains how Reserva Sete Quedas (“the reserve,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you visit our website, contact us, or stay with us. We are a small organisation and we take this seriously: we ask for as little as we can, we explain why, and we give you real control over your data. This policy is written in plain language on purpose. It also sets out, in full, your rights under the European Union's General Data Protection Regulation (GDPR), Brazil's Lei Geral de Proteção de Dados (LGPD), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
Last updated: 8 August 2026.
The short version
Here is the whole policy in a paragraph, before the detail. We collect the information you give us when you contact us or book a stay, plus a small amount of technical information that any website receives, plus one privacy-friendly analytics cookie that only runs if you agree to it. We use that information to reply to you, to host your stay, to keep the site working and secure, and to understand which pages are useful. We do not sell your personal information. We share it only with the service providers we need to run the reserve, and only so they can do that job. You can ask us at any time to show you your data, correct it, delete it, or stop using it, and we will. If you only read one section, read “Your rights” below.
Who is responsible for your data
Reserva Sete Quedas is the controller of your personal information — the organisation that decides why and how it is processed. We are based in the mountains above Paraty, in the state of Rio de Janeiro, Brazil. If you have any question about this policy, or you want to exercise any of your rights, you can reach us at privacy@reservasetequedas.com, or through the details at the end of this page. We will always reply from our own domain, and we will never ask you to send a password, a full payment-card number, or a government identity document by email.
What personal information we collect
We collect three kinds of information: what you give us, what we receive automatically, and what we set with cookies. We describe each below.
Information you give us
When you use our contact form, email us, or make and manage a booking, you may give us:
- Identity and contact details — your name, email address, and, if you provide it, a phone number or postal address.
- Enquiry and booking details — the dates you are interested in, the number and ages of guests, the reason for your visit, dietary requirements, accessibility or mobility needs, and anything else you choose to tell us in your message.
- Correspondence — the content of the messages you send us and our replies, so we have a record of what was agreed.
- Payment-related information — if you book a stay, payment is handled by a specialist payment provider or by bank transfer; we receive confirmation that a payment was made and the information needed for our records, but we do not collect or store full card numbers on this website.
Some of what you might tell us — for example a health condition behind an accessibility request, or a dietary requirement that reveals a religious belief — can be “special category” or “sensitive” data. You do not have to share it, but if you do, we use it only to make your visit safe and comfortable, and we treat it with extra care.
Information we receive automatically
Like almost every website, our servers and security systems receive certain technical information when you visit, which is necessary to deliver the site and keep it safe:
- Device and connection data — your IP address, browser type and version, operating system, and the referring page.
- Usage data — the pages you view, the date and time, and how you move through the site.
- Security data — information our hosting and security provider uses to detect and block malicious traffic, spam, and abuse.
Cookies and similar technologies
A cookie is a small text file a website stores on your device. We keep our use of them to a minimum. We use two categories:
- Strictly necessary storage — a small amount of local storage that remembers your cookie choice so we do not ask you again on every page. This does not track you and is always on, because the site cannot honour your preference without it.
- Analytics (optional, off by default) — if, and only if, you click “Accept analytics” on our cookie banner, we load Google Analytics 4 with IP anonymisation to understand which pages help visitors. If you decline, or ignore the banner, no analytics cookie is set and no analytics data is collected. You can change your mind at any time by clearing your browser storage for this site, which brings the banner back.
We do not use advertising cookies, we do not run third-party ad networks, and we do not build advertising profiles about you.
Why we use your information, and our legal basis
Under the GDPR and the LGPD we must have a lawful basis for each use of your personal data. Here is what we do and why.
- To answer your enquiry. When you contact us, we use your details to reply and to help you plan. Legal basis: your consent, and our legitimate interest in responding to people who contact us; where you are asking about a booking, the steps taken at your request before a contract.
- To provide and manage a stay. If you book, we use your information to hold the reservation, prepare for your arrival, meet your requirements, and keep records. Legal basis: performance of a contract with you.
- To run and secure the website. We use technical and security data to deliver the site, prevent fraud and abuse, and keep it available. Legal basis: our legitimate interest in a working, secure website, and compliance with our legal obligations.
- To understand and improve the site. If you consent, we use analytics to see which pages are useful. Legal basis: your consent.
- To meet legal and accounting obligations. We keep certain records to comply with tax, accounting, and other laws. Legal basis: compliance with a legal obligation.
- To send you occasional updates, only if you have asked to receive them. Legal basis: your consent, which you can withdraw at any time.
Where our basis is legitimate interest, we have weighed that interest against your rights and freedoms, and we use the information only in ways you would reasonably expect. Where our basis is consent, you are free to refuse or withdraw it without any detriment to the service you receive.
Who we share your information with
We do not sell your personal information, and we do not share it for anyone else's marketing. We share it only with the service providers (“processors”) we rely on to run the reserve, and only so they can perform their service for us under a contract that requires them to protect your data. These currently include:
- Website hosting and security — our site and its security are provided by Cloudflare, which serves the pages and protects against attacks and abuse.
- Email delivery — when you use the contact form, a transactional email provider (such as Resend) delivers your message to our inbox. Your message content and contact details pass through this service for that purpose.
- Analytics — if you consent, Google Analytics 4 processes anonymised usage data on our behalf.
- Payment and booking services — if you book and pay, a payment provider and, where used, a reservation system process the information needed to take payment and manage the booking.
- Professional advisers and authorities — we may disclose information to our accountants or lawyers, or to a public authority, where we are legally required to do so, or to establish, exercise, or defend legal claims.
If the reserve is ever reorganised, or its business transferred, personal information may be shared with the parties involved, always subject to this policy and applicable law.
International transfers
We are in Brazil, and some of our service providers store or process data in other countries, including the United States and the European Union. This means your information may be transferred across borders. When it is, we rely on appropriate safeguards recognised under the GDPR and the LGPD — such as the European Commission's Standard Contractual Clauses, adequacy decisions where they apply, and equivalent protections — so that your data keeps a comparable level of protection wherever it is handled. You can ask us for more detail on the safeguards that apply to a particular transfer.
How long we keep your information
We keep personal information only for as long as we need it for the purposes described above, and then we delete or anonymise it. In practice:
- Enquiries that do not lead to a booking are kept for up to two years, in case you come back to us, and then deleted.
- Booking and guest records are kept for the length of your stay and for as long afterwards as we are required to keep them for tax, accounting, and legal reasons, which is typically several years.
- Financial records are kept for the period required by law.
- Analytics data is retained for a limited period in line with our analytics settings, in aggregated and anonymised form.
When a retention period ends, we securely delete the information or remove anything that could identify you.
How we protect your information
We use appropriate technical and organisational measures to protect your personal data against loss, misuse, and unauthorised access. These include encryption of the website in transit (HTTPS), a strict content-security policy and other security headers, access controls that limit who on our team can see your information, reputable service providers with their own strong security, and keeping our systems up to date. No method of transmission or storage is perfectly secure, but we work hard to reduce the risk, and if a data breach ever occurs that is likely to affect your rights, we will notify you and the relevant authority as the law requires.
Your rights
You have strong rights over your personal information. Depending on where you live, they come from the GDPR, the LGPD, or the CCPA/CPRA, but we extend the core of them to everyone who contacts us, because it is simpler and fairer. To exercise any right, write to privacy@reservasetequedas.com. We will respond within the time the law allows — generally one month under the GDPR, fifteen days under the LGPD, and forty-five days under the CCPA, each extendable where permitted — and we will not charge you or treat you differently for asking.
If you are in the European Union, the United Kingdom, or the European Economic Area (GDPR)
You have the right to:
- Be informed about how we use your data — which is the purpose of this policy.
- Access the personal data we hold about you and receive a copy.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted where there is no good reason for us to keep it (the “right to be forgotten”).
- Restrict processing — ask us to pause using your data in certain circumstances.
- Data portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller.
- Object — object to processing based on legitimate interests, and to any direct marketing at any time.
- Withdraw consent at any time, where we rely on consent, without affecting processing already carried out.
- Not be subject to automated decision-making that produces legal or similarly significant effects — which we do not carry out.
- Complain to a supervisory authority. If you believe we have mishandled your data, you may lodge a complaint with your local data protection authority. We would appreciate the chance to put things right first.
If you are in Brazil (LGPD)
Under the LGPD you have the right to confirm that we process your data; to access it; to correct incomplete, inaccurate, or out-of-date data; to anonymise, block, or delete data that is unnecessary, excessive, or processed unlawfully; to portability; to delete data processed with your consent; to information about who we share your data with; to information about the consequences of refusing consent; and to withdraw consent. The national data protection authority in Brazil is the Autoridade Nacional de Proteção de Dados (ANPD), and you have the right to petition it regarding your data. You can exercise any of these rights by writing to us at the address above.
If you are in California (CCPA/CPRA)
If you are a California resident, you have the right to know what personal information we collect, use, and disclose; to access a copy of it; to have it corrected; to delete it, subject to legal exceptions; and to be free from discrimination for exercising your rights. You also have the right to opt out of the “sale” or “sharing” of your personal information and to limit the use of sensitive personal information. We do not sell or share your personal information as those terms are defined under the CCPA/CPRA, and we do not use sensitive information for anything beyond providing the service you asked for. You may exercise your rights yourself or through an authorised agent by contacting us; we will verify your request using the information we already hold, to protect your account.
Children's privacy
Our website is intended for adults planning travel, and it is not directed at children. We do not knowingly collect personal information directly from children. Families are very welcome at the reserve, and when you book as a family you may give us the ages of children so we can prepare properly; that information is provided by the booking adult and used only to host your stay. If you believe a child has provided us with personal information without a parent's involvement, please contact us and we will delete it.
Marketing communications
We do not run a large marketing operation. We will only send you updates if you have asked us to, and every such message includes a clear way to unsubscribe. Replying to your enquiry, confirming your booking, and sending you the practical information you need for your stay are not marketing — they are part of providing the service you asked for — but you can still tell us to stop at any time.
Links to other websites
Our site and journal sometimes link to other organisations — a national park, a boat cooperative, a town's tourism page. Those websites have their own privacy practices, which we do not control and are not responsible for. We encourage you to read the privacy policy of any site you visit through a link from ours.
Automated decision-making
We do not make decisions about you based solely on automated processing that would produce legal or similarly significant effects. A person reviews and answers your enquiries and bookings.
Changes to this policy
We may update this policy from time to time, for example if we add a service provider or the law changes. When we do, we will change the “last updated” date at the top of this page, and if the change is significant we will make it prominent. We encourage you to review this page when you contact us or book, so you always know how your information is handled.
Cookies and storage, in detail
To be concrete about what sits on your device: when you first visit, nothing is stored until you interact with the cookie banner. When you make a choice, we save a single small preference in your browser's local storage so we do not ask you again on every page; this preference contains only your choice and cannot identify you. If — and only if — you accept analytics, Google Analytics 4 then sets its own measurement cookies to count visits and understand which pages are read, always with IP anonymisation enabled. If you decline, none of those analytics cookies are set. Our hosting and security provider may also process standard technical request data to deliver pages and protect the site from attack; this is necessary to run any website and is not used to profile you. You can clear all of this at any time from your browser, and doing so simply resets the banner on your next visit.
Log data and its retention
Server and security logs — which record technical details such as IP addresses, timestamps, and requested pages — are generated automatically and kept only for a short period, long enough to diagnose problems, investigate security incidents, and keep the site reliable, after which they are rotated out and deleted. We do not mine these logs to build profiles of individual visitors; they exist to keep the service working and safe.
If there is ever a data breach
We work hard to prevent it, but if a security incident ever occurred that was likely to put your rights or your information at risk, we would act quickly: we would contain and investigate the incident, notify the relevant supervisory authority within the timeframe the law requires (for example, without undue delay and, under the GDPR, generally within seventy-two hours of becoming aware of it), and tell affected individuals in clear language what happened, what information was involved, what we were doing about it, and what steps they could take to protect themselves. We would not stay silent to save face.
The principles we hold ourselves to
Beyond the specific rules of any one law, we try to follow the same handful of principles that sit underneath all of them, because they are simply the right way to treat someone's information:
- Lawfulness, fairness, and transparency. We process data only where we have a lawful basis, we do not do so in ways you would find surprising or hidden, and we explain what we do in plain language.
- Purpose limitation. We collect data for the specific reasons set out in this policy, and we do not later use it for unrelated purposes without telling you.
- Data minimisation. We ask for as little as we can. A short enquiry needs only a name, an email, and a message.
- Accuracy. We keep information current where we can, and we correct it promptly when you tell us it is wrong.
- Storage limitation. We keep data only as long as we need it, then delete or anonymise it.
- Integrity and confidentiality. We protect data with appropriate security, and we limit who can see it.
- Accountability. We take responsibility for all of the above, and we are ready to demonstrate it.
Categories of information, in CCPA terms
For the sake of California residents, the categories of personal information we may collect, in the language the CCPA uses, are: identifiers (such as your name, email address, and IP address); customer records (such as a phone number or booking details you provide); internet or network activity (such as pages viewed and interactions with the site); geolocation data only at the coarse, city-level accuracy that an IP address implies, never precise location; commercial information (such as a record that you made a booking); and, only where you choose to share it, limited sensitive personal information such as a health or dietary detail behind a special request. We collect these from you directly, and automatically from your device when you use the site. We use them for the business purposes described in “Why we use your information.” We disclose them only to the service providers listed above, for those same purposes. We have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months, and we have no plans to.
What we deliberately do not do
It is sometimes clearest to say what we avoid. We do not sell your personal information. We do not share it with advertisers or data brokers. We do not run advertising cookies or build advertising profiles. We do not track you across other websites. We do not collect precise geolocation. We do not require you to create an account to browse. And we do not use your information to make automated decisions that significantly affect you. If any of that ever changed, we would update this policy first, make the change obvious, and, where the law requires, ask for your consent.
Your choices and controls
You are in control of most of what we collect, through everyday tools as well as the formal rights above:
- The cookie banner. Analytics are off until you choose “Accept analytics.” You can decline, and you can reverse an earlier choice by clearing this site's storage in your browser, which brings the banner back.
- Your browser. You can block or delete cookies and local storage at any time in your browser settings. The site will still work; it simply will not remember your cookie choice between visits.
- Global Privacy Control. Where your browser sends a recognised opt-out preference signal, we honour it as an opt-out of any sale or sharing — which, as noted, we do not carry out in any case.
- What you tell us. The most direct control of all: you decide how much to put in your message. You never have to give us more than a name, an email, and what you want to ask.
- Unsubscribing. If you ever opt in to updates, every message carries a one-click way out.
Making a request, and how we verify it
To exercise any right, email privacy@reservasetequedas.com and tell us what you would like us to do. To protect you, we will verify your request against the information we already hold — usually by confirming you control the email address associated with your enquiry or booking — before we act on it, because we do not want to hand your data to someone pretending to be you. If you use an authorised agent to make a request on your behalf, we will ask for proof of that authorisation. We will not charge you for a reasonable request, and we will never penalise you, refuse service, or give you a worse experience for exercising a privacy right.
Definitions
A few terms, briefly, so the rest of this policy is unambiguous. Personal information (or personal data) means information that identifies, relates to, or could reasonably be linked with you. Processing means anything we do with that information — collecting, storing, using, sharing, or deleting it. A controller decides why and how data is processed; that is us. A processor handles data on a controller's instructions; those are our service providers. Consent means a clear, affirmative choice you make, which you can withdraw at any time. Where this policy names a specific law — the GDPR, the LGPD, the CCPA/CPRA — the rights under it apply to the people that law protects, though as noted we extend the core of them to everyone who writes to us.
Third-party content and embeds
We keep third-party content to a minimum. Our fonts are served from a well-known font provider so the site loads quickly, and, only with your consent, our analytics are provided by Google. From time to time an article may link out to another organisation's site or embed a map or a video; when it does, that third party may receive technical information about your device as part of loading its content, under its own privacy policy. We choose such embeds sparingly and prefer plain links where we can, precisely to keep your visit private by default.
A quick recap of your rights
To summarise the detail above: wherever you live, if you have contacted us or stayed with us, you can ask us what personal information we hold about you, ask us to correct it, ask us to delete it, ask us to stop or limit how we use it, ask for a copy to take elsewhere, object to particular uses, and withdraw any consent you have given — and you can do all of it by a single email to privacy@reservasetequedas.com, at no cost and with no penalty. Residents of the EU, the UK, and Brazil also have the right to complain to a data protection authority. We would simply ask for the chance to put things right ourselves first.
How to contact us or make a complaint
If you have any question about this policy, want to exercise any of your rights, or wish to make a complaint about how we have handled your data, please write to us at privacy@reservasetequedas.com, or by post to Reserva Sete Quedas, Sete Quedas, Paraty — RJ, Brazil. We will take your concern seriously and do our best to resolve it. If you are in the EU/EEA, the UK, or Brazil and you are not satisfied with our response, you retain the right to complain to your local data protection authority or, in Brazil, to the ANPD. We would be grateful for the opportunity to address your concern directly first, and we will always try to make it right.