CAERION App Terms of Use
This document is designed as standalone, app-specific terms of use. It does not replace the membership agreement or the terms governing concierge services and individual bookings. (version 20260917.1 | effective date: 20.09.26)
1 Scope and relationship with other agreements
These Terms of Use govern only access to and use of the CAERION mobile application by invited members. The App is provided by Atrium Lifestyle Services Ltd., an Irish company registered under number 789871 with its registered office in Waterford, Ireland, trading as CAERION (“CAERION”, “we”, “us” or “our”).
The App supports communication and administration under an existing CAERION membership. The membership agreement, general terms and conditions, and any terms applicable to a specific request or third party also apply to membership, membership fees, concierge services and individual bookings. If terms conflict, the terms specific to the membership or individual transaction prevail.
2 Access and user account
The App is generally intended only for adult invited members. There is no entitlement to activation. Login credentials are personal and must not be shared.
Users must keep registration and contact details accurate and current, adequately protect their device and notify CAERION without undue delay of suspected misuse or loss of credentials. Actions through a properly authenticated account may be attributed to the account holder to the extent that the holder is responsible for the misuse.
3 App functions
Depending on the functionality enabled, the App may allow users to communicate with the concierge team, submit requests and preferences, receive proposals and information, approve instructions, provide documents and view status and booking information.
The available functionality may vary by operating system, country, membership and development status. App store descriptions and marketing material do not guarantee that a particular function will always be available.
4 Requests instructions and bookings
A request submitted through the App initially invites CAERION to identify options or assess an instruction. A contract for a particular service is formed only by an unequivocal confirmation or in accordance with the terms notified for that instruction.
Unless expressly confirmed otherwise, CAERION arranges or facilitates third party services in the member’s name and for the member’s account. The relevant supplier is the contracting party for the third party service. Its prices, cancellation rules, house rules, conditions of carriage and other terms may also apply.
Before approval, the user must check proposals, names, dates, travel details, prices, taxes, fees and cancellation terms. CAERION does not guarantee a particular booking result or third party availability.
5 Payments
The App does not create a general balance, wallet or payment account. Payments should generally be made directly to the relevant supplier or through an authorised payment service provider used for that purpose.
If CAERION requests a purpose specific advance for an individual instruction or uses a card authorisation, the separately notified terms apply. Deleting the App or the user account does not extinguish accrued payment or reimbursement obligations.
6 User obligations and prohibited use
- do not submit unlawful, fraudulent, discriminatory or dangerous requests, or requests that infringe third party rights;
- do not use a false identity, payment details or other material information;
- do not introduce malware, use automated access or scraping, reverse engineer the App or circumvent security measures, except where mandatory law permits this;
- do not upload content without the necessary rights or consents;
- do not use the App in a way that impairs its operation, security or other users.
7 Communications and approvals
Communications in the App may have legal effect, particularly approvals and requests to amend or cancel an instruction. Before approval, the user must verify that the scope and content of the instruction are accurately stated.
Push notifications are a convenience feature and may be delayed or fail. For time critical matters, users must use the contact channels shown in the App and obtain confirmation of receipt.
8 Content and intellectual property
The App, its software, design, trade marks and content supplied by CAERION are protected by law. For the duration of authorised access, CAERION grants a personal, revocable, non exclusive and non transferable right to use the App in accordance with these Terms.
Users retain their rights in their own content. They grant CAERION the rights necessary to process a request, perform the relevant agreement and communicate with appointed third parties.
9 Third party services
The App may integrate third party content, mapping, communication, identity, analytics or payment services, or link to external services. The relevant third party terms and privacy notices apply to those independent services. CAERION does not adopt third party content as its own.
10 Availability changes and updates
CAERION aims to operate the App securely and effectively but does not promise uninterrupted or error free availability. Maintenance, security measures, network or third party outages and compelling operational reasons may temporarily restrict functions.
CAERION may update the App and change functions where reasonably necessary for security, error correction, legal compliance or appropriate development and where this is reasonable for the user. Required security updates must be installed promptly.
11 Privacy and permissions
Personal data is processed as described in the privacy notice linked in the App and the relevant app store. The App should request only device permissions required for the relevant function. Where available, users may manage or withdraw permissions in their device settings.
12 Account deletion
Users may request deletion of their App account through the function provided in account settings. CAERION must also provide an easily discoverable web page for deletion requests. Statutory retention duties and records required for ongoing or completed instructions remain unaffected.
Deletion of the App account does not automatically terminate the CAERION membership or cancel pending instructions or bookings. The applicable termination and cancellation procedures must be used.
13 Suspension and termination of App access
CAERION may temporarily suspend or terminate access in the event of a material security risk, misuse, payment default, serious contractual breach or termination of membership. Where reasonably possible, the user will be informed in advance and given an opportunity to remedy the issue.
Mandatory statutory rights and claims under previously confirmed instructions remain unaffected.
14 Liability
CAERION has unlimited liability for wilful misconduct and gross negligence, death or personal injury, mandatory product liability and any expressly assumed guarantee.
For a slightly negligent breach of an essential contractual obligation, liability is limited to loss that was foreseeable and typical for the contract. Otherwise, liability for slight negligence is excluded to the extent permitted by law. CAERION is liable for an independent third party service only where CAERION has breached its own duty.
15 Governing law and jurisdiction
Irish law applies, excluding its conflict of laws rules and the United Nations Convention on Contracts for the International Sale of Goods. For consumers, this choice does not deprive them of the protection of mandatory provisions of the law of their habitual residence.
Statutory rules on jurisdiction apply to consumers. For business users, Waterford, Ireland, is the exclusive place of jurisdiction to the extent permitted by law.
16 Changes to these Terms
CAERION may amend these Terms for an objective reason, including new functionality, security requirements or legal developments. Users will receive appropriate notice of material changes. Where consent is required by law, continued use will not be treated as deemed consent.
17 Contact and provider information
Atrium Lifestyle Services Ltd., trading as CAERION, 8 Shanagarry, Collins Avenue, X91A5R5 Waterford, Ireland, registered in Ireland under No. 789871.
Email: concierge@caerion.com
Website: www.caerion.com
Privacy Policy
1. Overview
This Privacy Policy explains how Atrium Lifestyle Services Ltd. collects, uses, stores, and protects personal data when you visit or use this website.
Personal data means any information that can directly or indirectly identify you, such as your name, email address, IP address, browser information, or communication data.
We process personal data in accordance with the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and other applicable data protection laws.
2. Controller
The controller responsible for data processing on this website is:
Atrium Lifestyle Services Ltd.
8 Shanagarry, Collins Avenue
Waterford, X91 A5R5
Ireland
Phone: +353 89 484 4355
Email: info@caerion.com
3. Data We Process
Depending on how you use this website, we may process the following categories of data:
- technical access data, such as IP address, browser type, operating system, referrer URL, date and time of access, and requested pages;
- contact data, such as your name, email address, phone number, and message content if you contact us;
- usage data relating to how the website is accessed and displayed;
- communication data if you send us an enquiry by email or through a contact form.
4. Purposes of Processing
We process personal data for the following purposes:
- to provide and operate this website securely;
- to display the website correctly on your device;
- to respond to enquiries and communication;
- to protect the website against misuse, technical errors, and security risks;
- to comply with legal obligations;
- to improve the performance, structure, and usability of the website.
5. Legal Bases for Processing
We process personal data on the following legal bases:
- Art. 6(1)(b) GDPR where processing is necessary to take steps prior to entering into a contract or to perform a contract;
- Art. 6(1)(f) GDPR where processing is necessary for our legitimate interests, such as secure website operation, technical stability, and responding to enquiries;
- Art. 6(1)(a) GDPR where you have given consent, for example for optional cookies or optional communication features;
- Art. 6(1)(c) GDPR where processing is necessary to comply with legal obligations.
6. Website Hosting via Vercel
This website is hosted by Vercel.
When you access this website, technical data may be processed by Vercel to deliver the website, maintain security, prevent abuse, and ensure technical stability. This may include:
- IP address;
- date and time of access;
- requested URL or page;
- browser type and version;
- operating system;
- referrer URL;
- server response data;
- device and connection information.
The legal basis for this processing is Art. 6(1)(f) GDPR. Our legitimate interest is the secure, fast, and reliable provision of this website.
Vercel may process data on servers located outside the European Economic Area. Where such transfers take place, they are carried out on the basis of appropriate safeguards under applicable data protection law, such as data processing agreements and standard contractual clauses where required.
7. Server Log Files
For technical and security reasons, server log files may be created automatically when you visit this website. These log files may include:
- browser type and browser version;
- operating system used;
- referrer URL;
- hostname or IP address of the accessing device;
- time of the server request;
- requested files or pages.
This data is processed to ensure the proper technical operation, security, and stability of the website. The legal basis is Art. 6(1)(f) GDPR.
Server log data is not combined with other data sources unless this is necessary to investigate misuse, security incidents, or legal claims.
8. Contact by Email or Contact Form
If you contact us by email or through a contact form, we process the information you provide in order to handle your enquiry and respond to you.
This may include your name, email address, phone number, message content, and any other information you choose to provide.
The legal basis is Art. 6(1)(b) GDPR where your enquiry relates to a contract or pre-contractual communication. In all other cases, the legal basis is Art. 6(1)(f) GDPR based on our legitimate interest in responding to enquiries.
We do not share this information with third parties unless required by law or necessary to process your request.
9. Google Fonts
This website uses Google Fonts to display typography consistently and attractively.
If Google Fonts are loaded directly from Google servers, your browser may connect to Google servers when you visit this website. In this process, Google may receive technical information such as your IP address, the requested font file, browser information, operating system information, and referrer data.
According to Google, the Google Fonts API is designed to limit the collection and use of end-user data, does not set cookies, and does not use information collected through Google Fonts to create end-user profiles or for targeted advertising.
The use of Google Fonts is based on Art. 6(1)(f) GDPR. Our legitimate interest is the visually consistent, technically reliable, and efficient presentation of this website.
If Google Fonts are hosted locally on this website, no connection to Google servers is established for the loading of fonts.
10. Cookies
This website may use cookies or similar technologies that are technically necessary for the operation, security, and proper display of the website.
Cookies are small text files stored on your device by your browser. Some cookies are deleted automatically after your visit, while others may remain on your device until you delete them.
Technically necessary cookies are processed on the basis of Art. 6(1)(f) GDPR. Our legitimate interest is the secure and functional operation of the website.
If optional cookies, analytics tools, marketing tools, or third-party tracking technologies are used, they will only be activated where legally required after your consent.
11. Google Tag Manager and Google Analytics 4
This website uses Google Tag Manager and Google Analytics 4, services of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland ("Google").
Google Tag Manager is a tag management system used to load and manage website tags. It does not set cookies of its own and does not collect personal data beyond the technical data required to load the tags, such as the IP address.
Google Analytics 4 collects information about the use of this website, for example pages viewed, the duration of a visit, approximate location derived from the IP address, device type, browser and referring source. Google Analytics 4 does not store full IP addresses; they are truncated in the European Union before being processed further. The data is used to compile aggregated reports on website usage, which help us improve the content and structure of this website.
Google Analytics 4 uses cookies and similar technologies. Where consent is required by law, these tools are activated only after you have given your consent. The legal basis is Art. 6(1)(a) GDPR (consent); otherwise Art. 6(1)(f) GDPR, our legitimate interest in analysing and improving this website.
Google may process data on servers in the United States. Google LLC is certified under the EU-US Data Privacy Framework; where necessary, transfers are additionally safeguarded by the European Commission’s Standard Contractual Clauses. We have concluded a data processing agreement with Google.
Usage data held in Google Analytics is retained for a maximum of 14 months and then deleted automatically.
You can withdraw your consent at any time with future effect, delete cookies in your browser settings or prevent data collection by Google Analytics with the browser add-on available at https://tools.google.com/dlpage/gaoptout. Further information: https://policies.google.com/privacy.
12. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, unless statutory retention periods apply.
Contact enquiries are retained for as long as necessary to handle the enquiry and any follow-up communication. Data may be stored longer if required for legal, accounting, or business record-keeping obligations.
Technical server logs are retained only for the period necessary to ensure website security and stability, unless longer retention is required to investigate misuse or security incidents.
13. Recipients of Data
We only share personal data where necessary for the operation of this website, the fulfilment of contractual or legal obligations, or the handling of your enquiry.
Recipients may include:
- hosting and infrastructure providers;
- technical service providers;
- Google Ireland Limited (Google Tag Manager, Google Analytics 4);
- communication providers;
- legal, tax, or compliance advisors where required;
- public authorities where legally required.
We do not sell personal data.
14. International Data Transfers
Some service providers used for this website may process personal data outside the European Economic Area.
Where personal data is transferred to countries outside the EEA, we ensure that appropriate safeguards are in place in accordance with GDPR requirements. These may include adequacy decisions, standard contractual clauses, data processing agreements, or other legally recognized transfer mechanisms.
15. Your Rights
Under applicable data protection law, you have the following rights:
- right of access to your personal data;
- right to rectification of inaccurate data;
- right to erasure of your data;
- right to restriction of processing;
- right to data portability;
- right to object to processing based on legitimate interests;
- right to withdraw consent at any time with future effect;
- right to lodge a complaint with a supervisory authority.
To exercise your rights, you can contact us at: info@caerion.com
16. Right to Object
If we process personal data on the basis of Art. 6(1)(f) GDPR, you have the right to object to this processing at any time on grounds relating to your particular situation.
If you object, we will no longer process your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights, and freedoms, or unless the processing is necessary for the establishment, exercise, or defence of legal claims.
17. Right to Lodge a Complaint
If you believe that the processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority.
For Ireland, the competent supervisory authority is:
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
18. Security
We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction.
This website uses encrypted transmission where technically available. You can recognize an encrypted connection by the lock symbol in your browser and by the use of "https" in the address bar.
Please note that data transmission over the internet can never be fully protected against third-party access.
19. Unsolicited Promotional Emails
We object to the use of contact details published in this Legal Notice for sending unsolicited advertising, marketing materials, or spam.
We reserve the right to take legal action in the event of unsolicited promotional communication.
20. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or operational changes.
Privacy Policy for the CAERION Member Portal App
Effective: September 2026
This Privacy Policy explains how personal data is processed when you use the Caerion Member Portal app (“App”).
The App is designed specifically for members of our invitation-only lifestyle and concierge membership program to submit and manage concierge requests. Members can prepare and manage bookings, view the processing status, communicate with the concierge, and access booking-related documents and confirmations. Members can also set their preferences within the App.
1. Data Controller
The data controller responsible for the processing of personal data in connection with the App is:
Atrium Lifestyle Services Ltd., operating under the brand name “Caerion,” 8 Shanagarry, Collins Avenue, Waterford X91 A5R5, Ireland (Company Number 789871) (hereinafter “Caerion”)
Phone: +353 89 484 4355
Email: info@caerion.com
www.caerion.com
2. Registration, User Account, and Membership
Use of the app is generally reserved for members who have been approved for our Concierge membership.
In connection with registration, login, and user account management, the following data in particular may be processed:
- First and last name,
- Email address,
- phone number,
- User or member ID,
- login and authentication data,
- Membership status,
- Start and, if applicable, end of membership,
- profile information, and
- technical information regarding logins and sessions.
Processing is carried out, to the extent necessary for the administration of membership and the provision of the app, on the basis of Article 6(1)(b) of the GDPR.
To the extent that certain data is processed for security reasons—in particular to prevent unauthorized access or misuse—the processing is based on Article 6(1)(f) of the GDPR. Our legitimate interest lies in ensuring the security of our app, our systems, and member accounts.
3. Concierge Inquiries
Members can use the app to submit requests to the concierge, for example regarding:
- Travel and transportation,
- hotels and accommodations,
- Events and activities,
- tickets and reservations, as well as
- other lifestyle and everyday services.
To process a request, we process the information provided by the member. This may include, in particular, names, contact information, travel dates, desired destinations, dates, preferences, booking requests, and other information required for the specific request.
The specific data required depends on the nature of the inquiry.
Processing is generally carried out to handle the inquiry and to prepare, perform, or arrange the requested service in accordance with Article 6(1)(b) of the GDPR.
We ask that you refrain from providing any personal data in free-text fields or messages that is not necessary for the specific inquiry.
4. Communication with the Concierge
Members can communicate with our concierge via the app.
In doing so, we process in particular:
- Content of the messages,
- Time of communication,
- sender and recipient,
- any files or documents transmitted, if applicable, as well as
- the respective processing and request status.
This data is processed to handle concierge requests, document the communication, and provide or arrange the requested services.
The legal basis is generally Article 6(1)(b) of the GDPR.
5. Bookings and Arrangement of Third-Party Services
To the extent that we prepare, arrange, or book a service from a third-party provider at a member’s request, we may transfer the personal data required for this purpose to the respective provider or intermediary partner.
These may include, for example, hotels, airlines, transportation providers, tour operators, ticket providers, restaurants, or other service providers.
The scope of the data transmitted depends on the specific service. Only the information necessary to process the request, prepare a quote, make a reservation, complete a booking, or perform the service in question will be transmitted.
The legal basis for a transfer necessary to fulfill the member’s request is Article 6(1)(b) of the GDPR.
The respective third-party provider may subsequently process personal data under its own responsibility under data protection law. The privacy policy of the respective provider applies in addition to this processing.
6. Booking Records and Documents
The app can be used to provide booking- and inquiry-related documents, such as reservation confirmations, booking information, tickets, invoices, or other documents.
We process and store this data to the extent necessary to fulfill the respective request or to provide the corresponding functions.
The legal basis is Article 6(1)(b) of the GDPR.
To the extent that statutory retention obligations apply, further storage is based on Article 6(1)(c) of the GDPR.
7. Payments
To the extent that the app enables payment for a specific booking-related service, we process the information necessary to assign and process the payment.
The App does not hold a balance, wallet or payment account. Where a payment is required for a specific booking-related service, it is generally made directly to the relevant supplier or through an authorised payment service provider notified for that instruction. Payment card details are not entered in the App.
Where a payment service provider is used, payment information is collected and processed directly by that provider. We may receive information on the payment status, the amount, the transaction ID and the payment method used, to the extent necessary to assign the payment.
Processing is carried out to execute the respective payment or the associated service based on Article 6(1)(b) of the GDPR and, to the extent that statutory documentation or retention obligations apply, Article 6(1)(c) of the GDPR.
8. Technical Data and App Security
When using the app, technically necessary data may be processed, for example:
- IP address,
- device type and operating system,
- app version,
- language settings,
- time of access,
- technical session information,
- error and diagnostic data, as well as
- security-related events.
This processing serves to ensure the availability, stability, and security of the app, as well as to detect and resolve technical errors.
To the extent that the processing is necessary for the provision of the app, it is based on Article 6(1)(b) of the GDPR. Security and error analyses may also be based on our legitimate interest in the secure and reliable operation of the app pursuant to Article 6(1)(f) of the GDPR.
9. Push Notifications
If the app uses push notifications, members can enable or disable this feature via their device’s settings.
Push notifications can, for example, provide information about new concierge messages, changes to processing status, or booking-related information.
For technical delivery, device-specific push tokens may be processed and transmitted to the respective push service.
For iOS devices, technical delivery is handled via services provided by Apple Inc. or the relevant Apple subsidiaries (Apple Push Notification Service – APNs).
10. Analytics and Tracking Services
We do not use analytics or advertising tracking services within the App that track user behaviour for advertising purposes. Technical error and diagnostic data (section 8) is processed only to keep the App stable and secure. Should analytics tools be introduced, this Privacy Policy will be updated beforehand and, where required, consent will be requested.
11. Recipients of Personal Data
Personal data may be transferred, to the extent necessary, in particular to the following categories of recipients:
- IT, hosting, and infrastructure service providers,
- Communication and support service providers,
- payment service providers,
- Providers of the respective requested or booked services,
- booking, reservation, and brokerage partners,
- tax advisors, certified public accountants, and other professional advisors, as well as
- government agencies or other public authorities, to the extent that a legal obligation exists.
Service providers who process personal data exclusively on our behalf are contractually bound in accordance with legal requirements.
12. Data Transfer to Third Countries
When using certain service providers or arranging international services, it may be necessary to process personal data outside the European Union or the European Economic Area.
This may be the case, in particular, when a member requests or books a service in a third country and the transfer of the necessary data to the service provider there is required to perform the requested service.
To the extent that no adequacy decision by the European Commission exists for a data transfer, the transfer takes place only on a legal basis provided for this purpose and—where necessary—using appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
In the case of an international booking made at the member’s express request, a transfer may also be necessary to the extent provided by law for the performance of the contract or the implementation of precontractual measures.
13. Retention Period
We store personal data only for as long as is necessary for the respective processing purpose.
Data related to the member account and membership is generally processed for the duration of the membership. Inquiry, communication, and booking data are stored for as long as necessary to process and fulfill the respective service and to safeguard legitimate interests.
To the extent that statutory retention obligations apply—in particular those under commercial or tax law—certain data and documents may also be stored for the period required by law.
Upon expiration of the respective retention period, the data will be deleted unless there is a further legal basis for its processing.
14. Deletion of the User Account
Members may request the deletion of their user account through the account deletion function in the App’s account settings or by sending an email to info@caerion.com.
Deleting the app account does not necessarily result in the immediate deletion of all personal data. Data that we are required to continue storing due to legal retention obligations, or that we need to assert, exercise, or defend legal claims, will be retained for these purposes and subsequently deleted.
15. Your Data Protection Rights
Subject to the statutory requirements, data subjects have, in particular, the right to:
- to request information about the personal data we process (Art. 15 GDPR),
- to request the rectification of inaccurate data (Art. 16 GDPR),
- to request the erasure of personal data (Art. 17 GDPR),
- to request restriction of processing (Art. 18 GDPR),
- to receive or have data transferred in a structured, commonly used, and machine-readable format (Art. 20 GDPR), and
- to object to processing based on Article 6(1)(e) or (f) of the GDPR for reasons arising from the data subject’s particular situation (Article 21 of the GDPR).
To the extent that processing is based on consent, consent may be withdrawn at any time with future effect. The lawfulness of the processing carried out prior to the withdrawal remains unaffected.
To exercise your rights, you may contact us at the following email address: info@caerion.com.
16. Right to File a Complaint
Data subjects also have the right to lodge a complaint with the data protection supervisory authority regarding the processing of their personal data.
The competent authority is:
Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland.
17. Security
We implement appropriate technical and organizational measures to protect personal data against loss, manipulation, unauthorized access, and other risks.
Our security measures are reviewed and adjusted in line with technological developments and existing risks.
18. Changes to This Privacy Policy
We update this Privacy Policy when the app’s features, the service providers we use, or legal requirements change.
The current version is available within the app and at www.caerion.com.
Last updated: 20 September 2026