Privacy Policy
Last Updated: December 8, 2024
Introduction
Welcome to Halkidiki Rentals (“we,” “us,” “our,” or “the Company”). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website halkidiki-rentals.gr and use our services.
Please read this Privacy Policy carefully. By accessing or using our website and services, you acknowledge that you have read, understood, and agree to be bound by the terms of this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use our services.
1. Information We Collect
1.1 Personal Information You Provide to Us
We collect personal information that you voluntarily provide to us when you:
- Register for an account
- Make a booking or reservation
- Subscribe to our newsletter
- Contact us via email, phone, or contact forms
- Participate in surveys or promotions
- Leave reviews or feedback
Personal information we collect may include:
- Identity Information: Full name, username, date of birth, gender
- Contact Information: Email address, phone number, mailing address
- Account Information: Username, password (encrypted)
- Booking Information: Check-in/check-out dates, number of guests, special requests, property preferences
- Payment Information: Credit/debit card details (processed securely through our payment providers), billing address
- Communication Data: Content of messages you send us, customer service interactions
- Travel Documents: Passport number, ID number (as required by Greek law for accommodation providers)
- Profile Information: Preferences, favorites, saved properties
1.2 Information Automatically Collected
When you visit our website, we automatically collect certain information about your device and browsing behavior:
- Device Information: IP address, browser type and version, device type, operating system
- Usage Data: Pages visited, time spent on pages, links clicked, referring website
- Location Data: Approximate geographic location based on IP address
- Cookies and Tracking Technologies: See our Cookie Policy section below
1.3 Information from Third Parties
We may receive information about you from third-party sources, including:
- Payment processors (for transaction verification)
- Social media platforms (if you connect your social media account)
- Property owners (information related to your stay)
- Analytics providers
- Marketing partners
2. How We Use Your Information
We use your personal information for the following purposes:
2.1 To Provide and Manage Services
- Process and manage your bookings and reservations
- Facilitate communication between you and property owners
- Send booking confirmations, check-in instructions, and trip details
- Process payments and issue invoices
- Provide customer support and respond to inquiries
- Send service-related notifications and updates
2.2 To Comply with Legal Obligations
Under Greek and European Union law, we are required to:
- Collect and maintain guest registration data as required by Greek tourism authorities
- Report accommodation bookings to local authorities (as per Greek Law 4070/2012)
- Maintain records for tax purposes
- Comply with General Data Protection Regulation (GDPR) requirements
- Respond to lawful requests from authorities
2.3 For Marketing and Communications
With your consent, we may:
- Send promotional emails about special offers, new properties, and travel tips
- Send newsletters and updates
- Personalize marketing content based on your preferences
- Conduct surveys and request feedback
You can opt-out of marketing communications at any time by clicking the “unsubscribe” link in our emails or contacting us directly.
2.4 To Improve Our Services
- Analyze website usage and user behavior
- Conduct research and analytics
- Improve website functionality and user experience
- Develop new features and services
- Prevent fraud and enhance security
2.5 For Business Operations
- Manage our relationship with property owners
- Process insurance claims (if applicable)
- Resolve disputes and enforce our Terms of Service
- Protect our legal rights and interests
3. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:
3.1 Contractual Necessity
Processing is necessary to fulfill our contract with you (providing accommodation booking services).
3.2 Legal Obligation
Processing is required to comply with Greek and EU laws, including:
- Greek Law 4070/2012 (Tourism Development)
- Tax and accounting regulations
- Anti-money laundering regulations
- Greek Police registration requirements for guests
3.3 Legitimate Interests
Processing is necessary for our legitimate business interests, such as:
- Fraud prevention and security
- Improving our services
- Direct marketing (where permitted)
- Business analytics
3.4 Consent
For certain processing activities (such as marketing emails or optional cookies), we rely on your explicit consent, which you can withdraw at any time.
4. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We may share your information in the following circumstances:
4.1 With Property Owners
We share necessary booking information with property owners to facilitate your reservation, including:
- Your name and contact information
- Booking dates and guest numbers
- Special requests or requirements
- Payment status
4.2 With Service Providers
We share information with trusted third-party service providers who assist us in operating our business:
- Payment Processors: Stripe, PayPal, banks (for secure payment processing)
- Email Service Providers: For sending booking confirmations and communications
- Hosting Providers: For website hosting and data storage
- Analytics Providers: Google Analytics, for website usage analysis
- Customer Support Tools: For managing customer inquiries
- Marketing Platforms: For email marketing campaigns (with your consent)
All service providers are contractually obligated to protect your data and use it only for specified purposes.
4.3 For Legal Compliance
We may disclose your information when required by law:
- Greek Tourism Authorities: Guest registration data as required by Greek law
- Tax Authorities: For tax compliance purposes
- Law Enforcement: In response to lawful requests, court orders, or legal processes
- Greek Police: For guest registration requirements under Greek legislation
4.4 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred to the acquiring entity.
4.5 With Your Consent
We may share your information with other third parties when you provide explicit consent.
5. International Data Transfers
Halkidiki Rentals is based in Greece, a member of the European Union. Your personal data is primarily stored and processed within the EU/EEA region, which provides a high level of data protection.
However, some of our service providers may be located outside the EU/EEA (such as cloud hosting providers in the United States). When we transfer data internationally, we ensure appropriate safeguards are in place:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions by the European Commission
- Privacy Shield certification (where applicable)
- Your explicit consent
6. Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.
Retention Periods:
- Account Information: Retained while your account is active, plus 3 years after account closure
- Booking Information: Retained for 10 years as required by Greek tax and accounting laws
- Guest Registration Data: Retained as required by Greek tourism authorities (typically 3-5 years)
- Marketing Data: Retained until you withdraw consent or request deletion
- Website Usage Data: Typically 2-3 years
- Payment Data: Transaction records retained for 7-10 years for accounting and legal compliance
After the retention period expires, we securely delete or anonymize your personal information.
7. Your Data Protection Rights (GDPR)
Under the General Data Protection Regulation (GDPR) and Greek data protection law, you have the following rights:
7.1 Right to Access
You have the right to request copies of your personal data. We may charge a reasonable fee for multiple copies.
7.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data.
7.3 Right to Erasure (“Right to be Forgotten”)
You have the right to request deletion of your personal data in certain circumstances, such as:
- The data is no longer necessary for the purposes collected
- You withdraw consent (where processing was based on consent)
- You object to processing and there are no overriding legitimate grounds
- The data was unlawfully processed
Note: We may not be able to delete data if retention is required by Greek or EU law (e.g., tax records, guest registration data).
7.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain situations.
7.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, machine-readable format and transfer it to another controller.
7.6 Right to Object
You have the right to object to processing based on legitimate interests or for direct marketing purposes.
7.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw consent at any time.
7.8 Right to Lodge a Complaint
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) if you believe your data protection rights have been violated.
Hellenic Data Protection Authority (HDPA)
Address: Kifissias Ave. 1-3, 11523 Athens, Greece
Phone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
How to Exercise Your Rights
To exercise any of these rights, please contact us at:
- Email: privacy@halkidiki-rentals.gr or info@halkidiki-rentals.gr
- Phone: +30 237 123 4567
We will respond to your request within one month as required by GDPR. In complex cases, we may extend this period by two additional months.
8. Data Security
We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.
Security Measures Include:
- Encryption: SSL/TLS encryption for data transmission
- Secure Servers: Data stored on secure servers with restricted access
- Password Protection: Encrypted password storage
- Access Controls: Limited access to personal data on a need-to-know basis
- Regular Security Audits: Ongoing monitoring and security assessments
- Secure Payment Processing: PCI-DSS compliant payment processors
- Employee Training: Staff trained on data protection and privacy practices
However, please note: No method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.
9. Cookies and Tracking Technologies
9.1 What Are Cookies?
Cookies are small text files placed on your device when you visit our website. They help us improve your browsing experience and provide personalized content.
9.2 Types of Cookies We Use
Essential Cookies (Required)
- Enable core website functionality
- Remember your login status
- Maintain security
- Cannot be disabled
Performance Cookies
- Analyze website usage and performance
- Help us improve user experience
- Example: Google Analytics
Functional Cookies
- Remember your preferences (language, currency)
- Enable enhanced features
- Personalize content
Marketing Cookies
- Track your browsing across websites
- Deliver targeted advertising
- Measure marketing campaign effectiveness
- Example: Facebook Pixel, Google Ads
9.3 Managing Cookies
You can control and manage cookies through your browser settings. However, disabling cookies may affect website functionality.
To manage cookies:
- Chrome: Settings > Privacy and Security > Cookies
- Firefox: Options > Privacy & Security > Cookies
- Safari: Preferences > Privacy > Cookies
- Edge: Settings > Privacy > Cookies
Third-Party Cookie Opt-Out:
- Google Analytics: tools.google.com/dlpage/gaoptout
- Facebook: www.facebook.com/ads/preferences
9.4 Do Not Track
Some browsers include a “Do Not Track” (DNT) feature. Our website does not currently respond to DNT signals, as there is no industry standard for compliance.
10. Children’s Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect personal information from children under 16.
If you are under 16, please do not:
- Register for an account
- Make bookings
- Provide personal information
If we discover that we have collected personal information from a child under 16 without parental consent, we will delete that information immediately.
If you believe we have collected information from a child under 16, please contact us immediately at privacy@halkidiki-rentals.gr.
11. Third-Party Links
Our website may contain links to third-party websites, including:
- Social media platforms (Facebook, Instagram, Twitter)
- Payment processors
- Partner websites
- Travel blogs and resources
We are not responsible for the privacy practices of third-party websites. We encourage you to review the privacy policies of any third-party sites you visit.
12. Your California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to know if personal information is sold or disclosed
- Right to opt-out of the sale of personal information
- Right to deletion
- Right to non-discrimination
Note: We do not sell personal information to third parties.
To exercise your CCPA rights, contact us at privacy@halkidiki-rentals.gr.
13. Data Controller
For the purposes of GDPR and Greek data protection law, the data controller is:
Halkidiki Rentals
Location: Halkidiki, Northern Greece
Email: info@halkidiki-rentals.gr
Phone: +30 237 123 4567
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- Changes in our practices
- Changes in applicable laws
- New features or services
- Feedback from users
When we update this policy:
- We will update the “Last Updated” date at the top
- Significant changes will be communicated via email or prominent website notice
- Continued use of our services after changes constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
General Inquiries:
Email: info@halkidiki-rentals.gr
Phone: +30 237 123 4567
Address: Halkidiki, Northern Greece
Data Protection Officer (DPO):
Email: privacy@halkidiki-rentals.gr
Complaints:
If you are not satisfied with our response, you have the right to lodge a complaint with:
Hellenic Data Protection Authority (HDPA)
Address: Kifissias Ave. 1-3, 11523 Athens, Greece
Phone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
16. Language
This Privacy Policy is provided in English. In case of any discrepancy between the English version and translations in other languages, the English version shall prevail. However, for your convenience, we may provide translations in Greek and other languages.
17. Specific Greek Law Compliance
17.1 Greek Tourism Registration
In accordance with Greek Law 4070/2012 and subsequent amendments, accommodation providers in Greece are required to:
- Collect guest identification information
- Report guest stays to local police authorities
- Maintain guest registration records
- Provide accommodation data to tourism authorities
We collect and process this information as a legal obligation and share it with Greek authorities as required.
17.2 Greek Tax Compliance
We maintain booking and payment records for 10 years as required by Greek tax law for accounting and audit purposes.
17.3 Greek Consumer Protection
Your rights under Greek consumer protection laws are not affected by this Privacy Policy. For consumer protection inquiries, contact the Hellenic Consumer Ombudsman at www.synigoroskatanaloti.gr.
18. Consent
By using our website and services, you consent to:
- The collection and use of information as described in this Privacy Policy
- The transfer of data as described in Section 5 (International Data Transfers)
- Our use of cookies as described in Section 9
You can withdraw your consent at any time by contacting us or adjusting your account settings.
Acknowledgment
By using Halkidiki Rentals’ website and services, you acknowledge that you have read and understood this Privacy Policy and agree to its terms.
Effective Date: December 8, 2024
Halkidiki Rentals – Your Privacy is Our Priority
This Privacy Policy complies with:
- General Data Protection Regulation (GDPR) – EU Regulation 2016/679
- Greek Data Protection Law 4624/2019
- Greek Law 4070/2012 (Tourism Development)
- ePrivacy Directive 2002/58/EC
- California Consumer Privacy Act (CCPA) – where applicable