STAVELLO← Back

Privacy Policy

Effective: 19 July 2026 · Stavello (stavello.com)

This Privacy Policy explains how Stavello ("we", "us", "our"), an independent business, handles personal data in connection with our booking, operations, CRM and AI-concierge platform available at stavello.com. It applies to visitors to our website, to the businesses that subscribe to our platform, and to the guests, clients and staff whose data those businesses process using it. Our privacy contact and designated privacy lead is privacy@stavello.com. Effective date: 19 July 2026.

At a glance

The short version. We provide software that businesses (for example, a resort or a salon) use to run bookings, billing, staff operations and guest services. For most of the data about a business's own guests, clients and employees, the business decides what is collected and why — we only process it on their behalf. We are directly responsible for your data when you hold an account with us, when we bill you, and for keeping the platform secure. We do not sell your data, we do not run advertising or tracking SDKs, and card numbers never touch our servers. Health information you provide for diving activities is treated as our single highest-risk category and is protected accordingly.

If you are a guest of a resort or a client of a business that uses our platform: your primary privacy relationship is with that business — they are the data controller and decide how your information is used. This policy explains our role as their technology provider. For questions about why your information was collected, or to exercise your rights, you can contact the business first; we will support them in responding, and you can always reach us directly at privacy@stavello.com.

1. Who we are & our two roles

Stavello is operated as an independent, unincorporated business, based in Malaysia. Data-protection law distinguishes between a controller (who decides why and how personal data is used) and a processor (who acts only on the controller's documented instructions). We act in both roles depending on whose data is involved.

Where we are the controller

We decide how data is handled — and are directly accountable to you — for:

  • The account-holder's own data (the person who signs up for and administers a business account);
  • Billing and subscription data;
  • Platform security logs (for example, login and access records used to protect the service);
  • Platform-level operational data we use to keep the service reliable.

Where we are the processor

For personal data about a business customer's end-guests, clients and employees — for example, a resort's guests or a salon's staff and clients — the business is the controller and we are the processor. We hold and handle that data only to provide the platform and only on the business's instructions. We do not use it for our own purposes, and we do not sell or share it beyond the sub-processors listed in Section 5. Our obligations to each business are set out in a Data Processing Agreement (DPA) that imposes obligations equivalent to Article 28 of the GDPR — confidentiality, security, assistance with data-subject requests, breach support, and export or deletion of data on termination (subject to records we are required to retain) — and flows those obligations down to our sub-processors.

What this means for a guest, client or employee. If you are, for example, a guest or an employee of a business that uses our platform, that business chose to collect your information and decides how it is used. We store and process it on their behalf. When you ask us to change or delete something, we act in coordination with — and on the authority of — that business.

Our privacy lead, DPO and representatives

Questions about this policy and all privacy requests are handled by our designated privacy lead, reachable at privacy@stavello.com. Where a Data Protection Officer is required under GDPR Article 37 or the appointment thresholds of Malaysia's amended PDPA, this is the accountable role for that function; we are formalising this appointment and will name a formally appointed DPO here once confirmed. Where we are required to designate an EU and/or UK representative under Article 27 of the GDPR/UK GDPR, we are putting that appointment in place and it will be reachable through the same contact channel.

2. The personal data we collect

The categories below reflect what the platform actually collects. Not every field applies to every business or every person — a salon client record is far lighter than a dive-guest record. Where we act as processor, the specific fields are determined by the business.

Guests & clients

  • Identity & contact: name, email, phone, nationality, date of birth, home address, emergency contact.
  • Government / identity documents: national identity number (for example, a Malaysian NRIC/IC), passport number, and uploaded photos or scans of passports, ID cards and diving certification cards (stored as images).
  • Stay & booking: villa/room number, departure date and time, co-guest names, loyalty tier and tags, free-text staff notes, and booking & payment history.
  • Handwritten signature images captured as an e-signature on liability waivers.
  • Payment tokens — see Section 5. We never store raw card numbers.

Notice at the point of capture. For the most sensitive capture points — the dive medical questionnaire, the upload of a passport/ID/certification image, and the e-signature on a liability waiver — a short, plain-language notice is shown at the moment of collection explaining what is being collected and why, and (for health data) requesting separate explicit consent before you submit.

Special-category health data (dive medical questionnaire)

This is the most sensitive data we handle and we protect it accordingly. Where a guest registers for a diving activity, the business collects a diver medical questionnaire (based on the RSTC/DMSC standard). This includes health information such as heart disease, high blood pressure, lung and respiratory disease, epilepsy and seizures, diabetes, recent surgery, prescription medications, pregnancy, and mental-health items (including major depression, suicidal ideation, panic attacks, bipolar disorder, and drug or alcohol dependency), as well as allergies, medical conditions, medications and blood type.

This is special-category data under the GDPR (Article 9) and sensitive personal data under Malaysia's PDPA. It is collected only with separate, explicit, opt-in consent captured at the questionnaire itself, is used solely to assess fitness to dive and to protect diver safety, and is subject to the heightened safeguards described in Sections 3 and 9. As explained in Section 4, the raw structured answers stay in our database and are not sent to our AI provider; only a minimised binary fitness outcome, tied to a named diver, is.

Staff (a business's employees)

Where a business uses our HR and payroll features, we process its employees' data on its behalf: name and contact details, date of birth, NRIC/passport, address, emergency contact, salary and commission, bank account details, statutory numbers (such as EPF/KWSP, SOCSO/PERKESO and tax/LHDN references), attendance, leave, and certifications.

For employees. Your employer — the business that subscribes to the platform — is the controller of your employment data and is responsible for informing you about how it uses that data through its own staff/employee privacy notice. We process this data only as a processor on your employer's instructions. Requests about your employment data are normally directed to your employer; we will assist them in responding.

Website visitors & account-holders

  • Account and login details for people who administer a business account;
  • Essential/session cookies and authentication cookies (see Section 10);
  • A referral value (the `?ref=` parameter) captured when you arrive via a referral link, used only to attribute where a sign-up came from — not for advertising, profiling or cross-site tracking (see Section 10).

3. How we use data & our legal bases

Where we are a controller, the table below sets out our purposes and the GDPR Article 6 legal bases we rely on. Where a business is the controller (guest/client and staff data), the business is responsible for the legal basis; we process on their documented instructions under the DPA. Under the PDPA, these purposes rest on consent and on processing necessary for the relevant transaction or legal obligation.

PurposeLegal basis (GDPR Art 6)
Provide the platform and deliver the services you or your business have requested (bookings, billing, guest services)Contract — Art 6(1)(b)
Bill and collect subscription fees; maintain financial recordsContract — Art 6(1)(b); Legal obligation — Art 6(1)(c)
Keep the platform secure, prevent abuse, and maintain security logsLegitimate interests — Art 6(1)(f) (securing the service)
Send transactional messages (e.g. booking confirmations)Contract — Art 6(1)(b)
Send marketing communicationsConsent — Art 6(1)(a); prior opt-in only (see below)
Protect the vital interests of a diver in a medical emergencyVital interests — Art 6(1)(d) (with Art 9(2)(c) for health data)
Comply with legal, tax, safety and duty-of-care obligationsLegal obligation — Art 6(1)(c); Legitimate interests — Art 6(1)(f)

Marketing — opt-in only

We send marketing communications only on the basis of prior opt-in consent. Marketing preferences default to off, so no one receives marketing unless they have actively opted in, and we do not send marketing to any data subject who has not opted in. You can withdraw marketing consent at any time (see Section 8).

Legal basis for health data

The dive medical questionnaire is processed on the basis of the guest's explicit consent under GDPR Article 9(2)(a). This consent is obtained through a separate, affirmative opt-in presented at the questionnaire itself — distinct from acceptance of any general terms — and names diving fitness assessment and diver safety as the purpose. Where processing is necessary to protect the vital interests of the guest or another person — for example, in a diving emergency where the guest cannot give consent — we and the business may also rely on Article 9(2)(c). Under Malaysia's PDPA, this is sensitive personal data requiring the data subject's explicit consent. Consent to health processing can be withdrawn at any time (see Section 8), subject to the safety and legal-retention limits described in Section 7.

4. The AI concierge & automated decisions

The platform includes an AI guest "butler"/concierge that answers guest questions, assists with bookings, translates, and helps parse documents. It is powered by Anthropic (Claude). We are deliberate about what the AI does and does not receive.

What is sent to the AI provider

  • Guest name, villa number, and departure date/time;
  • The names of divers whose medical screening is complete;
  • The binary fitness outcome of a medical screen only — i.e. "one or more items answered yes" or "no conditions flagged";
  • Any free-text a guest types into the chat.

A note on the medical outcome. Because the binary pass/flag outcome is linked to a named diver, we treat it as health-related data even though it contains none of the underlying conditions. It is transferred to the AI provider under the same explicit-consent basis and GDPR Article 9 safeguards as the questionnaire itself, and is deliberately minimised to a single yes/no flag — the AI is not sent the individual health conditions, medications, mental-health responses or any other structured questionnaire answer, which remain solely in our own database.

What is NOT sent to the AI provider

The raw, structured medical answers are never sent to the AI provider. They remain in our own database. The AI receives only the yes/no summary outcome, never the individual health conditions, medications or mental-health responses.

Please don't type sensitive details into the chat. Free-text you type into the concierge chat is sent to the AI provider to answer you. If you choose to volunteer health or other sensitive information in that free-text, it will be processed as part of your message. We ask that you use the structured questionnaire — not the chat — for medical information, so that it stays within our database and out of the AI pipeline.

No solely-automated decisions

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing (GDPR Article 22). The AI concierge only assists — it drafts, suggests and answers. Any decision about your fitness to dive is reviewed and made by a qualified human dive instructor, and the medical screen flags a case for human review rather than deciding it.

Your inputs are not used to train AI models. Data sent to Anthropic's API is processed under terms that do not train models on it and that apply zero or limited retention. Anthropic is based in the United States (see Section 6 on international transfers).

5. Sub-processors

We use a small set of vetted service providers to run the platform. Each is bound by a data-processing agreement carrying obligations equivalent to GDPR Article 28. Data flows only to the providers listed below; the list reflects where data actually goes.

ProviderPurposeData it receives
SupabasePrimary database, file storage & authenticationAll stored platform data, including guest/staff records, health questionnaire answers, and ID/passport/certification scans
Anthropic (Claude)AI guest concierge, translation & document parsing (US-based)Guest name, villa number, departure date/time, names of divers screened, the binary (health-related) medical outcome only, and chat free-text. Not used for model training; zero/limited retention
StripePayment processing & subscription billing (US-based)Card data entered on Stripe's own hosted checkout; billing details. We store only Stripe tokens/customer IDs
ResendTransactional email delivery (US-based)Recipient email and booking details (e.g. booking confirmations)
WhatsApp providers (Fonnte / Wassenger) — where enabledOutbound messaging, only where a business enables itGuest phone number and message body
Web Push (Apple / Google / Mozilla push services)Push notifications, mostly to staffNotification payloads and device push tokens
VercelApplication hosting / global edge runtime (US-based / global edge)Application traffic processed to serve the platform
CloudflareDNS & email routingNetwork/DNS and email-routing metadata
Meta, LinkedIn, X, TikTokBusiness marketing content onlyMarketing content — no guest personal data

Sub-processor changes — notice and objection. For business customers, the DPA gives you the right to advance notice of any new or replacement sub-processor and a reasonable opportunity to object on legitimate data-protection grounds before their data is entrusted to that sub-processor. We maintain the current list above and notify affected customers through the DPA's notification channel. Contact privacy@stavello.com to subscribe to change notices.

No advertising or analytics trackers. We do not integrate third-party analytics or tracking SDKs (no Google Analytics, PostHog or Plausible). We do not sell personal data or share it with data brokers.

6. International data transfers

The platform operates across borders. Our database region, our global edge hosting, and several providers (including Anthropic, Stripe, Resend and Vercel) process data in the United States and other locations. This means personal data — including data about guests located in the EU/UK — is transferred outside the European Economic Area and the United Kingdom.

Where such transfers occur, we rely on appropriate safeguards for each recipient, layered as needed:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, and the UK International Data Transfer Addendum / IDTA for UK transfers, as incorporated into each provider's data-processing agreement;
  • the EU-US Data Privacy Framework (DPF), where the relevant US provider is certified under it;
  • a transfer risk assessment for US and other third-country recipients, considering the recipient's laws and our supplementary measures;
  • supplementary technical measures — encryption in transit (TLS) and at rest, private storage with short-lived signed URLs for identity documents, and strict data minimisation to the AI provider (a binary outcome rather than the underlying health answers) — applied as an additional layer for special-category health data crossing borders.

For transfers involving guests processed in the Maldives — where there is not yet a comprehensive data-protection statute in force — we apply GDPR-grade standards as a matter of policy. You may request a copy of the relevant transfer safeguard for a specific provider by emailing privacy@stavello.com.

7. Data retention

We keep personal data for as long as needed to provide the service, and thereafter as required for legal, safety, financial and duty-of-care reasons. Because we are a young platform, we want to be straightforward about how retention works today rather than promise something we do not yet do. Indicative periods per category are set out below; where we act as processor, the business's own retention instructions also apply.

CategoryIndicative retention
Account & administrator dataFor the life of the business account, then a short wind-down period after closure
Guest / client operational records (bookings, notes)For the duration of the business's relationship with the individual, as directed by the business (controller)
Dive medical & safety records tied to an activityRetained as a safety record on duty-of-care / legal grounds (see below) — not deleted on request while that ground applies
Financial & billing recordsAs required by tax and accounting law (typically ~7 years)
Security & access logsA limited period to protect the service (typically up to ~24 months)
  • No automated auto-purge yet. We do not currently run an automated deletion schedule, and we do not claim a fixed deletion window we do not enforce. When a business "deletes" a guest record today, it is generally archived (hidden from everyday use) rather than permanently erased; the underlying record may be retained until a deletion request is actioned manually.
  • Safety & medical records tied to an activity. Where a diver medical questionnaire is connected to an actual dive activity or a liability event (for example, a signed waiver for a dive that took place), we retain it as a safety record. There is a legitimate-interest, legal-obligation and duty-of-care basis — aligned with recognised diving-safety standards and insurance/liability requirements — for keeping that specific record, which can outweigh an erasure request.
  • A current technical limitation, disclosed honestly. The dive medical questionnaire is presently held under a technical control that prevents editing or deletion, including by administrators. This means we currently cannot delete a completed medical questionnaire even where an erasure request would otherwise succeed. We are prioritising a change to permit lawful, logged erasure so that valid requests can be completed. Until that change is live, we will tell you honestly and without delay if a specific erasure cannot yet be completed, and we will complete it as soon as the control is updated and no overriding safety or legal ground applies.
  • Financial & billing records. Retained for the periods required by tax and accounting law.
  • Security logs. Retained for a limited period to protect the service.

If you need data removed, contact us (Section 8) and we will action it manually, within statutory timeframes, except where law or a documented safety/legitimate-interest ground requires us to retain a specific record — and except where the technical limitation above currently prevents deletion of a completed dive medical questionnaire, in which case we will tell you plainly and complete it once we can.

8. Your rights

Subject to applicable law (GDPR/UK GDPR and Malaysia's PDPA), you have the following rights over your personal data:

  • Access — obtain a copy of the personal data we hold about you;
  • Rectification — correct inaccurate or incomplete data;
  • Erasure — request deletion, subject to the safety, legal-retention and technical limits in Section 7 (in particular, dive medical/safety records and financial records may be retained, and completed dive medical questionnaires currently cannot be deleted even by an administrator);
  • Restriction — ask us to limit how we use your data;
  • Portability — receive certain data in a portable format;
  • Objection — object to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent — where we rely on consent (including for health data and marketing), withdraw it at any time, without affecting prior lawful processing;
  • Complain to a supervisory authority (see below).

How to exercise your rights — and an honest note on how requests are handled. Email privacy@stavello.com. We handle requests manually today — we do not yet offer a self-service download-or-delete tool — and we respond within the statutory timeframe (generally one month under the GDPR). If you are a guest, client or employee of a business that uses our platform, that business is the controller; we will route your request to them and act on their authority. We will honour valid erasure requests except where a safety, legal or technical limitation described in Section 7 applies, and we will tell you plainly which applies.

Marketing: we send marketing only to people who have actively opted in, and you can opt out at any time by emailing privacy@stavello.com or using the unsubscribe link in any marketing message.

Complaints: you may lodge a complaint with your local supervisory authority. These include the Personal Data Protection Commissioner (JPDP) in Malaysia, the Information Commissioner's Office (ICO) in the United Kingdom, and — for individuals in the EU — your national data-protection authority or the relevant EU lead supervisory authority. We ask that you contact us first at privacy@stavello.com so we can try to resolve the matter directly.

9. Security

We apply technical and organisational measures appropriate to the sensitivity of the data, including:

  • Encryption in transit (TLS) and at rest;
  • No stored card data — card entry happens on the payment provider's hosted checkout; we hold only tokens;
  • Hashed passwords (salted PBKDF2);
  • Private storage for identity documents — ID/passport/certification scans sit in a private bucket accessed only via short-lived signed URLs;
  • Least-privilege keys — the privileged database key is server-only and never exposed to the browser; system-admin access is governed by a server-side allow-list held outside the database;
  • Hardened sensitive actions — signed payment webhooks, login rate-limiting against brute force, a hashed PIN gate on sensitive finance actions, and fail-closed scheduled jobs behind a shared secret;
  • Baseline security headers (HSTS, no-sniff, clickjacking protection).

As with any young platform, we have a remediation programme underway — including strengthening tenant-isolation controls, adding a content-security policy and a schema-validation layer, and extending rate-limiting to remaining public endpoints. We prioritise fixes by risk and update our safeguards on an ongoing basis. No system can be guaranteed perfectly secure, but we treat health data, identity documents and financial data as our highest-priority protection tiers, and we maintain a documented process to detect, assess and respond to security incidents (see Section 12).

10. Cookies

We use essential and session cookies only, including the authentication cookies needed to keep you signed in. We do not use advertising or cross-site tracking cookies, and we do not run third-party analytics.

A referral parameter (the `?ref=` value) may be captured from a referral link to attribute where a sign-up came from. It is used only for that attribution — it is not used for advertising, profiling or cross-site tracking, and it stores no persistent cross-site identifier. Where capturing or storing this value is non-essential and requires consent under applicable e-privacy/cookie rules, we obtain that consent before the value is stored.

For full details, see our Cookie Policy.

11. Children & minor divers

The platform is a business tool and is not directed to children, and individuals below the age of digital consent in their jurisdiction (which ranges from 13 to 16 in the EU/UK) should not create their own account. However, we recognise that resorts host families and that junior divers (for example, PADI Junior Open Water divers from age 10) may register for diving activities and complete the medical questionnaire.

Where a minor's data is processed — for example, a child included in a family's booking, or a junior diver registering for an activity — it must be provided by, and the required consent given by, the child's parent or legal guardian (or the business acting on that authority). For a minor's special-category health data in the dive medical questionnaire, the explicit consent described in Section 3 must be given by the parent/guardian, and fitness to dive is reviewed by a qualified instructor in line with junior-diver safety standards.

If you believe a child's data has been provided without proper parental or guardian authority, contact us at privacy@stavello.com and we will work with the relevant business to address it.

12. Data breaches

We maintain procedures to detect, investigate, assess and respond to personal-data breaches, and we keep an internal record of any incident and of the notification decisions we take.

  • Where we act as processor (guest/client and staff data), we notify the affected business (the controller) without undue delay, and in any event within 48 hours of becoming aware, with enough detail for them to meet their own notification duties — including the GDPR's 72-hour clock.
  • Where we act as controller (account, billing and security data), we notify affected individuals and the relevant regulator where required — within 72 hours of becoming aware under the GDPR/UK GDPR.
  • Under Malaysia's amended PDPA (2024), we notify the Personal Data Protection Commissioner of a notifiable breach, and affected individuals where the breach is likely to cause significant harm, within the timeframe and thresholds set by the PDPA and its regulations.

13. Changes to this policy

We may update this policy as the platform and the law evolve. When we make a material change, we will update the effective date and notify account-holders by email or through the platform. Where a change introduces a new purpose that requires consent — for example, a new use of health data or a change to marketing — we will obtain fresh consent rather than relying on your continued use of the service. The version published at stavello.com is always the current one.

14. Contact us

For any privacy question or to exercise your rights, contact:

  • Controller / operator: Stavello, based in Malaysia
  • Privacy contact / privacy lead (DPO function, being formally appointed): privacy@stavello.com
  • EU / UK representative (Article 27, being put in place): reachable via privacy@stavello.com
  • General contact: privacy@stavello.com
  • Website: stavello.com
  • Governing law: this policy and our processing are governed by the laws of Malaysia, with the courts of Malaysia having exclusive jurisdiction.

You always retain the right to lodge a complaint with your local data-protection supervisory authority, including the Personal Data Protection Commissioner (JPDP) in Malaysia, the Information Commissioner's Office (ICO) in the UK, or your EU national/lead supervisory authority.