Luxury Padel Retreats

Legal

Privacy Policy

Last updated: September 2026

This policy applies to everyone who contacts us or books a retreat, wherever you live. It is written to satisfy both the UK GDPR and the EU GDPR (Regulation (EU) 2016/679). Where the two differ, we apply whichever gives you more protection.

This policy is published in English. Translations may be provided for convenience; the English version governs.

1. Who we are

Courtside Padel Retreats ("we", "us", "our") operates the website www.cspadel.com and organises luxury padel retreats.

Data Controller:
Crtside Events Ltd (trading as Courtside Padel Retreats)
Registered in England and Wales, Company No. 16289087
24 Hendham Road, London SW17 7DQ, United Kingdom
Email: awatelet@cspadel.com

2. What personal data we collect

We may collect the following categories of personal data:

  • Contact details: name, email address, phone number, country of residence
  • Booking information: group size, preferred dates, accommodation type, and the travel details needed to deliver your retreat
  • Special category data: dietary requirements, allergies, accessibility needs and any health information you choose to share so we can run activities safely
  • Payment details: processed by our payment provider — we do not store full card numbers
  • Communications: enquiries, emails, or messages sent to us
  • Technical data: IP address, browser type, and pages visited, collected via server logs and, with your consent, analytics cookies

Providing contact and booking data is necessary to enter into a contract with us; without it we cannot arrange your retreat. Everything else is optional, though withholding dietary or medical information may limit what we can safely provide.

Where you give us personal data about other people in your group, you confirm you may do so and that you have shared this policy with them.

3. How we use your data

Purpose Legal basis
Respond to enquiriesSteps prior to a contract (Art. 6(1)(b)) / legitimate interest (Art. 6(1)(f))
Manage bookings and deliver the retreatContract (Art. 6(1)(b))
Process payments and issue confirmationsContract (Art. 6(1)(b))
Dietary, accessibility and health requirementsYour explicit consent (Art. 9(2)(a)); vital interests in an emergency (Art. 9(2)(c))
Marketing emailsConsent (Art. 6(1)(a)), or soft opt-in to existing customers, withdrawable at any time
Analytics and advertising measurementConsent (Art. 6(1)(a)), via the cookie banner
Accounting, tax and legal complianceLegal obligation (Art. 6(1)(c))
Security and improving our websiteLegitimate interest (Art. 6(1)(f))

We do not make decisions about you by automated means alone, and we do not profile you in any way that produces legal or similarly significant effects.

4. Who we share your data with

We share your data only where necessary to deliver your retreat or to meet a legal obligation:

  • Travel service providers: hotels and villas, transfer and transport operators, coaches, restaurants and activity operators at your destination
  • Local coordinators: partners who arrange activities on the ground at some destinations
  • Payment processor: subject to their own privacy policy
  • Professional advisers: accountants, insurers and lawyers, where relevant
  • Authorities: where required by law

Providers acting on our instructions are bound by written processing terms. Providers who decide how to use your data themselves — a hotel operating its own guest records, for example — act as separate controllers under their own policies.

We do not sell your personal data, and we do not share it for third-party advertising.

5. International transfers

We are established in the United Kingdom and we run retreats in several countries, so delivering your booking necessarily involves transferring your data internationally. Where you are in the EEA, that includes transfers out of the EEA.

Destination Basis for the transfer
United KingdomEuropean Commission adequacy decision for the UK
Spain (Menorca) and other EEA countriesWithin the EEA; UK adequacy regulations for EEA transfers
Indonesia (Bali)Standard Contractual Clauses / UK International Data Transfer Agreement, plus a transfer risk assessment
United Arab Emirates (Dubai)Standard Contractual Clauses / UK International Data Transfer Agreement, plus a transfer risk assessment

For destinations with no adequacy decision, we transfer only the minimum a provider needs to deliver your booking — typically a name, arrival details and any dietary or accessibility requirement. Where a transfer is strictly necessary to perform your contract, we may also rely on Article 49(1)(b).

You can ask us for a copy of the safeguards that apply to any transfer by emailing awatelet@cspadel.com.

6. How long we keep your data

  • Booking and payment records: 7 years after the end of the tax year of the booking, to meet UK accounting and tax requirements
  • Enquiries that did not become bookings: 12 months
  • Health, dietary and accessibility information: deleted within 3 months of the retreat ending, unless needed for an ongoing claim
  • Marketing consent records: until you withdraw consent, plus 2 years as proof that consent was given
  • Records relevant to a claim: until the claim is resolved and any limitation period has expired

7. Your rights

Wherever you live in the UK or the EEA, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data, subject to legal retention requirements
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interest, and to direct marketing at any time, absolutely and free of charge
  • Data portability — receive data you gave us in a structured, machine-readable format
  • Withdraw consent at any time, without affecting processing already carried out

Write to awatelet@cspadel.com. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. Exercising these rights is free unless a request is manifestly unfounded or excessive.

Complaints. If you are in the EEA, you may complain to the supervisory authority in the member state where you live, where you work, or where the problem happened — a list is published by the European Data Protection Board. If you are in the UK, you may complain to the Information Commissioner's Office. You can always come to us first, but you do not have to.

8. Cookies

We use essential cookies to make the site work and, only with your consent, analytics and advertising cookies. You can change or withdraw your choice at any time from our Cookie Policy page, where the full list is set out.

9. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls limiting guest data to those who need it, and vetting of the providers we share data with. This site is served over HTTPS.

If a breach is likely to result in a high risk to your rights and freedoms, we will tell you without undue delay, and we will notify the competent supervisory authority within 72 hours where required.

10. Children

Our retreats are sold to adults. We do not knowingly collect data from anyone under 16 except where a guardian provides it as part of a family booking. If you believe we hold a child's data without a proper basis, contact us and we will delete it.

11. Changes to this policy

We may update this policy. The "Last updated" date above reflects the current version, and we will tell you directly about changes that materially affect your rights.

12. Contact

For any privacy question, or to exercise any right above:
awatelet@cspadel.com

Chat with Us