Privacy policy
Data controller
BOUIGUE DEVELOPPEMENT (MAURICE) LTEE, BRN: C07071435, registered office Royal Road, Baie du Cap, Mauritius, publisher of anbalaba.com (Anbalaba Côté Sud). Legal representative: Hippolyte Bouigue. Tel: +230 622 11 39.
No Data Protection Officer (DPO) has been appointed. For any question about your personal data: contact@anbalaba.com.
Data collected and purposes
- Contact form (name, first name, phone, e-mail, message, newsletter checkbox): answering your request; if the box is ticked, sending our newsletter. Messages and subscriptions are transmitted to our e-mail provider Brevo (Sendinblue SAS, France).
- Newsletter (e-mail, first name, name, country, phone): news about the Domaine and Mauritius about once a month; unsubscribe through the link in every e-mail or by writing to contact@anbalaba.com.
- Audience measurement and advertising (with your consent): Google Tag Manager, Google Analytics 4 and Google Ads (remarketing and conversion measurement). Without consent no cookie is set; cookieless signals are sent to Google ("advanced" Consent Mode, see below).
- Form protection: Google reCAPTCHA (Google Ireland Ltd), which analyses your browsing to tell humans from robots.
- Maps and third-party media: Google Maps (interactive map, contact page), photos hosted by Cloudinary for our booking provider Amenitiz; bookings are made on Amenitiz's website under its own policy.
- Technical logs: IP address and browsing data kept by the hosting provider (OVH, France) for site security.
Cookies
The banner shown on your first visit lets you accept, reject or set cookies by category (audience measurement, marketing/advertising, third-party media). Your choice is kept for 365 days ("cookie-agreed" cookie) and can be changed at any time through the "Manage cookies" link in the footer. Cookies set after acceptance: _ga and _ga_* (Google Analytics, 13 months), _gcl_au (Google Ads, 3 months) and IDE (DoubleClick, Google, 13 months).
Google consent mode (Consent Mode v2)
The site uses Google's consent mode in its so-called "advanced" version. When a page opens, before any choice in the banner, the four consent signals (ad storage, ad user data, ad personalisation, analytics storage) are set to "denied". In this state no Google cookie is set and no cookie identifier is read or sent.
Before your choice, Google Tag Manager (GTM-MTVKRHQ5) nevertheless sends cookieless requests ("pings") to Google Analytics 4 (G-0M4PCF17WB, domain region1.google-analytics.com) and Google Ads (AW-831026509, domain pagead2.googlesyndication.com). They state the page viewed and the consent state ("gcs" and "gcd" parameters: consent denied); like any Internet request, they send Google the IP address and the browser's technical information. Google uses them to model audience and conversions in aggregate.
If you accept cookies, the signals switch to "granted": Google Analytics sets the _ga and _ga_0M4PCF17WB cookies, Google Ads sets the _gcl_au cookie, DoubleClick (Google) sets the IDE cookie (or test_cookie), and measurement and remarketing requests (doubleclick.net, googleadservices.com, google.com) are linked to these cookies. If you refuse, the "denied" state is kept and only the cookieless requests described above are sent. You can change your choice at any time through the "Manage cookies" link in the footer.
Retention periods
- Contact requests: 3 years from the last exchange.
- Newsletter subscribers: until unsubscription.
- Google Analytics 4: 14 months (data retention period set in Google Analytics, reset on each new user activity).
- Technical logs: 1 year at most.
- Cookies: _ga and _ga_* 13 months, _gcl_au 3 months, consent cookie 365 days.
Your rights
Under the GDPR you have the right of access, rectification, erasure, restriction, portability and objection. Write to contact@anbalaba.com.
You may lodge a complaint with the CNIL (France, www.cnil.fr) or with the Mauritius Data Protection Office (dataprotection.govmu.org).
Transfers outside the European Union
- Google (Google LLC, United States): transfers covered by standard contractual clauses and the EU-US Data Privacy Framework.
- Cloudinary (United States): transfers covered by standard contractual clauses and the EU-US Data Privacy Framework.
- Amenitiz: bookings are made on its website, under its own privacy policy.
- Brevo and OVH: data hosted in the European Union (France).