SerenaVillage.NET is a Secure website and has been online since 2017. You can verify the reliability of SerenaVillage.NET through the Google Safe Browsing system. Google is a Global Leader company on the Internet. Click to verify security on Google. SerenaVillage.NET commits to observing the necessary precautions to guarantee the safety of all customers. Maximum level of security for all SerenaVillage.NET customers Book in complete safety on the SerenaVillage.NET website.
SerenaVillage.NET adopts a high-tech system and secure connections with the new TLS 1.3, HSTS, DNSSEC, HTTP 3.0, and SSL Full (Strict) system. For issues related to the security of the SerenaVillage.NET site, you can read our Privacy Policy page. We also adopt all the latest extreme security techniques to protect customer data in forms, using the newest and most secure CSP nonce system, applying the following extreme security CSP in all server security headers: default-src 'none'; style-src 'self' 'nonce-'; style-src-attr 'none'; script-src 'self' 'nonce-'; and also require-trusted-types-for 'script'. As shown in the image below, you can see the Security Certification Grade A+ for our SerenaVillage.NET server headers.
Absolute Default Blocking:
This is the fundamental directive of extreme security through CSP default-src 'none'. It establishes that no resource (images, scripts, styles, fonts, etc.) can be loaded unless explicitly permitted by another more specific directive. Security Purpose: It forces the developer to strictly whitelist absolutely everything. If an attacker manages to inject a tag like img src= or script src=, these requests will automatically fail because they are not allowed.
Secure Loading of Styles and Scripts:
These directives allow the loading of: Resources that come from the same origin as the page ('self'). Inline styles and scripts (inside style or script tags) or files that contain a nonce attribute that matches a randomly generated, single-use value that the server includes in the HTTP header and in the HTML tags.
Extreme Security Purpose (Noncing): The use of the newest and most secure CSP nonce system prevents almost all XSS. An attacker injecting malicious code does not know the secret nonce value for the current request, so their injected script will simply be blocked by the browser. This is much safer than using hashes or simply allowing inline scripts ('unsafe-inline').
Blocking of Styles in Attributes:
Description (style-src-attr 'none'): This directive prohibits the use of CSS in HTML attributes, such as style="...CSS styles. Security Purpose: It prevents a common and subtle form of XSS code injection or CSP bypass where an attacker could manipulate the appearance of the page or attempt to execute code via vulnerable CSS properties.
Required Trusted Types:
Description (require-trusted-types-for 'script'): This is a cutting-edge security feature (Trusted Types). It demands that DOM functions that handle text strings as code (e.g., innerHTML, document.write) only accept a special object called a "Trusted Type" and not a simple text string. Extreme Security Purpose: It completely blocks the last line of defense against XSS attacks. Even if the attacker manages to inject a text string into one of these DOM functions, the browser will reject it because it is not a Trusted Type object. It is the highest security standard for preventing client-side code injection.
🔑 What It's For - Final CSP Goal:
The main goal of this extreme security CSP is to protect customer data in forms by: - Preventing the execution of malicious code (XSS): An attacker cannot inject scripts into the page to steal session cookies, authentication tokens, or form credentials. - Guaranteeing content integrity: It ensures that only resources (scripts, styles) authorized and verified by the server are executed, preventing the page from loading code from external or untrusted sources. - Reinforcing XSS mitigation (Defense in Depth): By using nonce and require-trusted-types-for 'script', multiple layers of protection are created, ensuring that even minor input validation failures do not result in a critical vulnerability.
In summary, this CSP configuration is an advanced shield that ensures the web application only loads the resources the developer intended, neutralizing code injection attempts and raising security to a level much higher than the average.
Maximum Security Cookie Policy:
Our default Cookie Policy on the SerenaVillage.NET server is: path=/;max-age=1440;SameSite=Strict;Secure. This serves to limit the duration of cookies and use only secure, first-party cookies that are deleted after booking, and it is a highly recommended practice to reinforce user privacy and security.
In summary, the cookie policy implemented by SerenaVillage.NETdemonstrates a strong commitment to user privacy and security through the following recommended practices: - Appropriate cookie scope (path=/). - Protection against CSRF (SameSite=Strict). - Protection against "Man-in-the-Middle" attack (Cookie Secure). - Limited cookie lifespan of 24 minutes (max-age=1440). - Minimization of third-party cookie usage. - Proactive deletion of cookies after booking and their necessary use.
Cookie Policy Goal:
path=/: This ensures the cookie is valid for all paths within the SerenaVillage.NET domain.
SameSite=Strict: This attribute is the MAXIMUM SECURITY OPTION available and guarantees the best protection against Cross-Site Request Forgery (CSRF) attacks. A cookie with Strict is NEVER sent if the user accesses our site from a link or request originating from an external site. It is only sent in requests that originate from the same website.
Secure: The Secure attribute is a critical security measure. When present, it instructs the browser that the cookie should only be sent over secure connections encrypted with (HTTPS). What does it do?: It prevents the cookie from being accidentally sent over an unencrypted HTTP connection (in plain text). Why is it important?: If an attacker is intercepting traffic on a public Wi-Fi network, for example, and the site attempts to load a resource via HTTP, with Secure the browser will not deliver the cookie, protecting it from being stolen through a "Man-in-the-Middle" attack.
🛡️ UNBREAKABLE SECURITY 🛡️: By implementing Strict, we eliminate any window of opportunity for a session to be potentially hijacked or used by a third party, even if an attacker tricks the user into clicking a malicious link.
max-age=1440: Setting the maximum cookie lifespan to 1440 seconds (24 minutes) is an excellent security and privacy practice. This limits the time during which a cookie can be used, reducing the window of opportunity for its exploitation in case of a security breach or unauthorized access.
Exclusive use of first-party cookies: By using only cookies generated and managed directly by the SerenaVillage.NET domain, the risk associated with third-party cookies, which are often used for cross-site tracking and can raise privacy concerns, is significantly reduced.
Cookie cancellation after booking: This is a proactive privacy measure. Once the booking is complete and the information is no longer needed in a cookie, deleting it minimizes the unnecessary retention of personal data, which is fundamental for user privacy.
These measures complement HTTP header security policies and contribute to creating a safer and more privacy-respecting online environment for users of SerenaVillage.NET. It is an excellent strategy for generating trust among website visitors.
SerenaVillage.NET is the owner of the personal data provided by the customer at the time of booking and therefore commits to treating said data with the utmost confidentiality and not to disclose, copy, or transfer said documentation to third parties. SerenaVillage.NET only sends communications related to the current order to the email address provided by the customer. The customer will have the possibility to modify their personal data at any time, only after accessing their personal area, and only for customers with a confirmed booking. All information will be processed in accordance with legal terms and in compliance with the Privacy Law. SerenaVillage.NET does not sell or transfer customers' personal data to third parties. When making a booking, the customer only needs to provide 5 essential pieces of data: 1 - Entry Date (Check-in Date). 2 - Guest Quantity (Number of people). 3 - Full Name (Name and Surname of the booking holder). 4 - E-Mail (Email address where the server automatically sends the booking confirmation). 5 - Phone (Phone Number where our staff can contact the booking holder). The SerenaVillage.NET site server only collects these 5 essential pieces of data to process bookings, and does not collect any more customer data. In compliance with applicable laws regarding the processing of personal data privacy, personal data will be managed exclusively by SerenaVillage.NET with the exception of payments. All payments will be made through PayPal. Only PayPal knows the customers' card details. SerenaVillage.NET does not know customers' Credit and Debit card details. Our secure online booking system sends all bookings to the PayPal site for validation. All payments will be processed by PayPal, a global leader company in secure Credit and Debit card payments.
An automatic booking confirmation is sent to the customer by E-Mail only after making the payment. The booking confirmation contains the Apartment Number and the exact location. Note: The SerenaVillage.NET site does not belong to the Serena Village office staff. Serena Village office staff do not manage bookings from the SerenaVillage.NET site and do not offer the promotional discount price. Book Now Click here. You can only get the promotional discount price by booking online at SerenaVillage.NET. To check the Check-in and Check-out times, you can read our Serena Village Punta Cana Times page.
Security Measure:
Strict telephone security measure in respect of customers' personal data. To prevent identity theft and another person from accessing customers' confidential data, Our Telephone Exchange 829-341-4713 only accepts calls from the Phone Numbers provided when booking, and only for customers with a confirmed booking. If you do not have a confirmed booking number, our telephone exchange does not allow calls to be transferred to our telephone Customer Service operators. Customers' Phone Numbers will be automatically authorized on our Telephone Exchange through the Payment Validation system. This way, only the Booking Holder can access their confidential booking data, and only by calling from their Phone Number provided when booking. If the customer does not have a Confirmed Booking, they can only receive assistance through Live Chat Support and WhatsApp or alternatively by visiting the Serena Village Frequently Asked Questions page and the SerenaVillage.NET Assistance page.
Modify personal data:
The customer will have the possibility to modify their personal data at any time, only after accessing their personal area, and only for customers with a confirmed booking. If the customer does not have a confirmed booking number, they will not be able to access their personal area, as the server will not create any account for unvalidated bookings, since the access data to the customer's personal area will be created automatically on our server when the booking is made, through the Payment Validation system. This way, only the Booking Holder can access their confidential data.
The SerenaVillage.NET Site does not know customers' Credit and Debit card details. Our secure online booking system sends all bookings to the PayPal site for validation. All payments will be processed by PayPal, a global leader company in secure Credit and Debit card payments. Only PayPal knows the customers' card details. Through PayPal, you can pay with all Visa, MasterCard, American Express, Diners Credit and Debit Cards, without needing to have a PayPal account. The SerenaVillage.NET Site Does Not require customers' card details. If you wish to pay with your card, you can only pay through PayPal, where you can pay with all Visa, MasterCard, American Express, Diners Credit and Debit Cards, only through PayPal without needing to have a PayPal account, thanks to our Express payment agreements with PayPal. You can pay with your card through PayPal from all over the World. SerenaVillage.NET does not know customers' card details.
Privacy Policy Goal:
The Privacy Policy sets out the essential information regarding personal data and the relationship with the SerenaVillage.NET site. The Policy applies to all SerenaVillage.NET site services and any associated services (hereinafter, the Service). The conditions governing your use of the Service offered on the SerenaVillage.NET website are contained in our Booking Terms (hereinafter, the Terms). We may periodically develop new or complementary services. If the launch of these new or complementary services causes significant changes in the way we collect or process your personal data, we will provide you with more information or additional policies or conditions. These new or complementary services will be subject to this Policy, unless we indicate otherwise upon their launch.
The objective of this Policy is to: Ensure you understand what personal data we collect about you, the reasons why we collect and use it, and who we share that data with. Explain how we use the personal data you provide us so that you can enjoy an excellent experience when using the SerenaVillage.NET site Service, and explain your rights and choices regarding the personal data we collect about you and process, as well as how we will protect your privacy. In this way, we hope to help you understand the privacy commitments we undertake to you. For information on how to contact us to ask questions or raise concerns, please consult the Customer Service Contacts page. Conversely, if you do not agree with the content of this Policy, remember that it is you who decides whether you wish to use the SerenaVillage.NET site Services and you may choose not to book and not to continue browsing the website. By accessing, browsing, using the SerenaVillage.NET website, and making a booking, you agree to have read, understood, and agreed with the site's Booking Terms, and the Privacy Policy, and you cannot plead ignorance in case of not reading or not complying with the Booking Terms.
Your rights and preferences:
We offer you choices and control. The General Data Protection Regulation (GDPR) grants certain rights to individuals regarding their personal data. Consequently, we are pleased to offer access and transparency controls to help users benefit from these rights. The rights conferred to individuals, without prejudice to the limitations provided for in the applicable legislation, are as follows: Right of access: the right to be informed and request access to the personal data we process about you. Right to rectification: the right to request the correction or update of your personal data when they are inaccurate or incomplete. Right to erasure: the right to request the deletion of your personal data. Right to restriction of processing: the right to request the temporary or definitive suspension of the processing of all or part of your personal data. Right to object: the right to object, at any time, to our processing of your personal data for reasons related to your particular situation and the right to object to the processing of your personal data for direct marketing purposes. Right to data portability: the right to request a copy of your personal data in an electronic format and the right to transfer that personal data for use in another third-party service. Right not to be subject to decisions based on automated processing: the right not to be subject to decisions based solely on automated processing, including profiling, when those decisions produce legal effects concerning you or similarly significantly affect you.
Customer Support Resources:
On our website, several pages offer more information on data protection issues. A fundamental source of information is the FAQ page, which contains answers to Frequently Asked Questions about the SerenaVillage.NET website Service. If you are a customer with a confirmed booking, and you have any questions about privacy, your rights, or how to exercise them, you can contact our Data Protection Officer using Our Telephone Exchange +1 829-341-4713. If you have concerns about our processing of your personal data, we hope to continue collaborating together to resolve them. If the customer does not have a Confirmed Booking, they can only receive assistance through WhatsApp or alternatively by visiting the Serena Village Frequently Asked Questions page and the SerenaVillage.NET Assistance page.
It is mandatory to carefully read the Reservation Terms before reserving. By accessing, browsing, using the site and making a reservation, all customers agree to have read, understood and be agree with our Terms.