Compare Car Classes

Cheapest option in each category

Loading prices...
No Deposit No Credit Card Free Cancellation
Welcome Discover Paphos Our Rides Hot Offers How to Rent
Explore Paphos Petra tou Romiou House of Dionysus Paphos Mosaics Archaeological Site of Paphos Castle

Data Privacy Policy

How we collect, use, and protect your personal information at carpaphos.com

1. Introduction and Scope

This Data Privacy Policy explains how Car Rental Paphos, operating at carpaphos.com and based in Paphos, Cyprus, collects, processes, stores, and protects personal data provided by visitors and customers. It applies to all individuals who browse our website, make a booking inquiry, or rent a vehicle through our service.

We operate in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the Cyprus Personal Data Protection Law (Law 125(I)/2018), and any applicable guidance issued by the Office of the Commissioner for Personal Data Protection in Cyprus. By using our website or services, you acknowledge the practices described in this policy.

2. Data Controller

The data controller responsible for your personal information is Car Rental Paphos, Paphos, Cyprus. For all privacy-related inquiries, you may contact us at [email protected].

3. Information We Collect

We collect the following categories of personal data depending on how you interact with our services:

3.1 Identity and Contact Details

Full name, email address, telephone number, and home or billing address. These are collected when you submit a booking request, contact our support team, or register for promotional communications.

3.2 Driver and License Information

Driver license number, issuing country, license expiry date, and date of birth. We collect this to verify driver eligibility and comply with car rental insurance requirements under Cypriot law.

3.3 Booking and Transaction Data

Rental dates, vehicle category selected, pickup location (such as Paphos International Airport, Coral Bay, or Kato Paphos), drop-off location, optional extras (child seats, GPS, insurance upgrades), and booking reference numbers.

3.4 Payment Information

We do not store full card details on our servers. Payment transactions are processed securely through third-party payment processors compliant with PCI-DSS standards. We may retain partial transaction references (last four digits, transaction ID) for reconciliation and dispute resolution.

3.5 Browsing and Technical Data

IP address, browser type and version, operating system, referring URLs, pages visited, session duration, and device identifiers. This data is collected automatically via server logs and analytics tools when you access carpaphos.com.

3.6 Location Data

Approximate geolocation derived from your IP address may be used to pre-fill pickup locations or display relevant rental offers for the Paphos region. We do not collect precise GPS-level device location without explicit consent.

4. How We Use Your Data

We process your personal data for the following purposes, each supported by a lawful basis under GDPR Article 6:

  • Processing bookings and rental agreements - contractual necessity. We use your name, contact details, license information, and booking data to confirm and fulfill your car rental reservation in Paphos.
  • Customer support and communication - contractual necessity and legitimate interest. We use your contact details to respond to inquiries, send booking confirmations, and provide assistance during your rental period.
  • Service improvement and analytics - legitimate interest. Aggregated and anonymized browsing data helps us improve website performance, optimize booking flows, and refine our vehicle fleet offering.
  • Marketing and promotional communications - consent. With your explicit opt-in, we may send you news about seasonal offers, Paphos travel tips, and new vehicle categories. You may withdraw consent at any time by emailing [email protected].
  • Legal and regulatory compliance - legal obligation. We may need to share or retain certain data to comply with Cypriot traffic laws, insurance obligations, tax regulations, or valid law enforcement requests.
  • Fraud prevention and security - legitimate interest. We analyze technical data to detect suspicious activity, prevent unauthorized bookings, and protect the integrity of our platform.

5. Data Sharing with Third Parties

We do not sell or rent your personal data to third parties. We may share your data only with the following categories of trusted partners, under strict data processing agreements:

  • Payment processors - to securely handle debit and credit card transactions. These providers are PCI-DSS certified and process data solely for payment authorization.
  • Insurance providers - we share relevant booking and driver data with our insurance partners to activate collision damage waivers and third-party liability coverage required under Cyprus road traffic law.
  • Booking platform integrators - our online reservation system may be powered by a third-party booking engine that processes your name, contact details, and rental preferences on our behalf.
  • Analytics and performance tools - anonymized usage data may be shared with web analytics providers to help us understand traffic patterns and improve our service.
  • Legal and regulatory authorities - we will disclose personal data when required by Cypriot law, court order, or regulatory authority, including the Cyprus Police or tax authorities.

All third-party processors are contractually bound to process your data only for specified purposes and in line with GDPR requirements.

6. Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected, or as required by law:

  • Booking and rental records - retained for 7 years from the date of rental to comply with Cypriot tax and accounting obligations.
  • Driver license copies - retained for 12 months after the rental end date, then securely deleted.
  • Customer support correspondence - retained for 3 years from the date of last contact.
  • Marketing consent records - retained until consent is withdrawn, plus 12 months thereafter for audit purposes.
  • Technical and browsing logs - retained for 90 days in rolling server logs, then automatically purged.
  • Payment transaction references - retained for 7 years for financial record-keeping.

7. Your Rights as a Data Subject

Under the GDPR and Cyprus personal data protection law, you have the following rights regarding your personal data:

  • Right of access - you may request a copy of the personal data we hold about you at any time.
  • Right to rectification - if any of your personal data is inaccurate or incomplete, you may ask us to correct it.
  • Right to erasure - you may request deletion of your personal data where there is no compelling legal reason for continued processing, subject to our legal retention obligations.
  • Right to data portability - you may request that we provide your data in a structured, machine-readable format, or transfer it directly to another controller where technically feasible.
  • Right to object - you may object to processing based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds.
  • Right to restrict processing - in certain circumstances, you may ask us to limit how we use your data while a dispute is resolved.
  • Right to withdraw consent - where processing is based on consent (e.g., marketing emails), you may withdraw at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus (www.dataprotection.gov.cy).

8. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, accidental loss, alteration, or disclosure. These include:

  • SSL/TLS encryption for all data transmitted between your browser and carpaphos.com.
  • Restricted staff access to personal data on a need-to-know basis, with access logging.
  • Regular security assessments of our booking platform and third-party integrations.
  • Secure deletion protocols for data that has exceeded its retention period.
  • Staff training on data protection obligations under GDPR and Cyprus law.

While we take all reasonable precautions, no method of transmission over the internet is entirely secure. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and affected individuals without undue delay, as required by GDPR Article 33-34.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to improve functionality, measure performance, and support marketing activities. Cookies are small text files stored on your device. For full details on the types of cookies we use, how long they persist, and how to manage your preferences, please refer to our Cookie Policy.

You may withdraw cookie consent at any time through your browser settings or via the cookie preference tool on this site. Note that disabling certain cookies may affect the functionality of the booking system.

10. International Data Transfers

Where any of our third-party service providers process data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or an adequacy decision. We do not transfer personal data to countries that do not offer an adequate level of data protection without appropriate safeguards.

11. Policy Updates

We may update this Data Privacy Policy from time to time to reflect changes in our practices, legal obligations, or applicable regulations. When we make material changes, we will update the "Last Revised" date at the bottom of this page and, where appropriate, notify you by email or a prominent notice on our website. We encourage you to review this policy periodically.

Continued use of our website or services after any changes constitutes acceptance of the updated policy.

12. Contact for Privacy Inquiries

For any questions, concerns, or requests relating to this Data Privacy Policy or our handling of your personal data, please contact us:

Last Revised: June 2025