Privacy Notice

Last Updated: May 24th, 2018

At Greek Pride Hotels, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Greek Pride Hotels.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://greekpridehotels.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Greek Pride Hotels.

Data Controller

Greek Pride Hotels operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Greek Pride Hotels

, 
GR

Data Processor

WebHotelier operates this booking system on behalf of Greek Pride Hotels and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Greek Pride Hotels, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Greek Pride Hotels;
  • to pass on your financial details to Greek Pride Hotels and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Aithrion IKE takes the issue of safeguarding your privacy very seriously. We have created this Privacy Policy in order to better familiarize you with the information we collect from our hotels guests and web site visitors, and the way in which Aithrion IKE uses this information to better serve the needs of our guests

What is Personal Information?

The term “Personal Information” refers to any information that can be used to identify you as an individual. It can include, among other things, your name, address, age, gender, etc.

How is Personal Information Collected?

1. Reviewing Our Website

A. Initially Upon Contact With Our Website

When you visit our web site, you are initially given a “cookie”, and your computer is assigned an ID number. A cookie is a commonly used device that tracks an individual user’s preferences, and is capable of enhancing your visit to the site. Cookies allow us to provide a customized experience without the visitor having to remind us of his or her preferences each time she or he visits our site. Our cookies do not contain any personally identifying information. Aithrion IKE cookies also do not follow visitors when travelling on the Internet after leaving the Aithrion IKE website.
Our website also uses Google Analytics Advertising Features (including Remarketing & Demographics and Interest based reporting) which is one of the most widespread and trusted analytics solutions on the web for helping us to understand how you use the site and ways that we can improve your experience. These cookies may track things such as how long you spend on the site and the pages that you visit, which helps us see which areas are popular with our users and which are not. Among other things, this helps us improve and update the site, based on such data as total number of visitors and pages viewed. For more information on Google Analytics cookies, see the official Google Analytics page.
Finally, we use 3rd party vendor re-marketing tracking cookies in our websites and / or their subdomains, including the Google Adwords Tracking Cookie and the Facebook Remarketing Pixel.

Disabling cookies – Opt-out from 3rd party vendors

If you do not want to accept cookies, you can block them by adjusting the settings on your Internet browser. Visitors should understand, however, that rejecting cookies will affect your ability to benefit from the conveniences afforded by the use of cookies, and you will not be able to use certain customisation features associated with creating a user profile. You may also wish to opt of Google Analytics by visiting the Google Analytics opt-out page.
Once you have visited our web site and accepted our cookie, your ID number is automatically assigned to your computer whenever you visit our web site. Despite the fact that you remain anonymous until you enter personal information in the web site, the ID number allows us to log your session, so that we may better assist you should you need some individualized service or support. Once you enter personal information on the web site, we associate your ID number with your contact information so we can recognize you on a future visit. We also use it to keep track of information that appears to be of particular interest to you.

B. While Browsing Our Web Site

While you explore our web site for the information that interests you, you may wish to put in a specific “Request” about our resort, or you may wish to chat online. To respond to this request, we may ask you for Personal Information, such as your name, zip/postal code, e-mail address, and phone number.
In the event you choose to provide us with this information, we will only use it for the purpose we have specified to you. We will only e-mail you if you want us to, and you can choose a number of alternate methods by which to receive a reply to a request. Your transmittal of your personal data shall constitute your acknowledgment and agreement to the terms and conditions contained in this Privacy Policy. If you are uncomfortable providing this information over the Internet, you can always call us for more details.
If you wish, you may also submit your e-mail address in order to be placed on a subscription list or to receive other information. You will be placed on this list only when you indicate your desire to be included. In the event you choose to join our mailing list, you may ask to be removed from the list at any time. Visitors will always have the ability to accept or decline any form of communication from Kappa Resort.

2. Reviewing Our Application

Downloading our Application you are able to check-in online, reserve a table in our restaurant, reserve a daily sailing cruise. Some of your Personal Information are needed in order to finalize all the above. Your transmittal of your personal data shall constitute your acknowledgment and agreement to the terms and conditions contained in this Privacy Policy. If you are uncomfortable providing this information over the Internet, you can always call us for more details.

3. When Making a Reservation through telephone.

Reservations can be made by calling us directly. When you make a reservation we may ask you for Personal Information such as your name, address, telephone number and method of payment. We may also obtain from you any room preferences or special requests. Confirmation of your reservation will be provided to you, by e-mail, directly from the resort.

4. During your stay at Aithrion IKE

During your stay, we record your itemized spending to properly assemble your folio, which sets out your accommodation rate and other expenses billed to your accommodation. We also record this information to comply with financial reporting requirements, including those imposed by our auditors and government regulators. We may also collect certain information as required by local laws (e.g. passport number).

In addition, we may retain the content of any document (including comment cards, electronic documents such as e-mails and other similar forms of communication) that you send us before, during or following your stay. This information may be shared with internal departments of the resort but will not be shared with any third party.

How do we store this information?

1. At our hotels

Aithrion IKE ensures that all Personal Information is kept in a secure location, be it a database or filing cabinet. Furthermore, we take steps to ensure that only designated individuals have access to this information.

2. In Our Guest Reservation System

In order to serve you better we also store certain guest information in our Guest Reservation System. This is a secure customer database stored on a dedicated server.
The stored information includes guest name, address, phone numbers and credit card number, number of night stays, average daily rate and other statistical details.

What information is not secure?

It is important to note that any e-mail communication is not secure. This is a risk inherent in the use of e-mail. Please be aware of this when requesting information or sending forms to us by e-mail (for example, from the Contact Us section of our web site). We recommend that you do not include any confidential information (i.e. credit card information) when using e-mail. For your protection, our e-mail responses to you will not include any confidential information.

Why is Personal Information collected?

1. To Provide Superior Customer Service

Personal Information is collected to assist us in making your reservation, to ensure we meet your needs while you are staying with us and/or to allow us to contact you in relation to matters that arose from your stay with us.
Furthermore, by keeping certain Personal Information on file, such as information regarding guest history and itemized spending, former guests of Aithrion IKE have the ability to confirm prior transactions and make special accommodation requests based on this history.

2. To Keep Our Guests Informed

As mentioned to our Legal Notices, we may at times send you information about our products, services, offers, deals, wishes, news about our resort or invite you to events via e-mail (e-newsletters).
You can choose at any time to stop receiving this e-newsletter by “unsubscribing”. In any case you will receive such newsletters only after your subscription ( online or at the registrations form )

What information may be exchanged between internal departments?

Information is shared between internal departments, where this will ameliorate the services to the guest (e.g. reservations department and front office department).
Further, if a guest does not pay the outstanding account on time, or acts in an unlawful manner in regards to payment obligations, this information may be shared among accounting personnel at Aithrion IKE.

What Personal Information may be provided to third parties?

Agents, contractors or third party service providers of Aithrion IKE may receive your Personal Information in the course of providing services to Aithrion IKE to better serve the needs of our guests. Using contractual or other arrangements, Aithrion IKE ensures these parties protect your Personal Information in a manner consistent with the principles articulated in this Privacy Policy.
We will only share Personal Information about you outside Aithrion IKE without your consent, where: (a) it is required or authorized by law (for example, in response to a legal subpoena); (b) it is required to provide you with services you have requested in which case you will be considered to have implied your consent (i.e. car rental, massage); (c) if your stay has been paid for by a third party we will provide billing information to the paying party; (d) if you have failed to pay balance.

If Aithrion IKE suspects any unlawful activity is taking place, it may investigate and/or report its findings or suspicions to the police or other relevant law enforcement agency.

How do I access my Personal Information?

We understand that you may like to know what Personal Information we hold about you. We are happy to assist you with your request. To protect your Personal Information, however, we require that you prove your identity to us at the time your request is made.
When you make a request in person, we will require you to produce some form of photo identification such as a passport or a driver’s license and you will be asked to sign a request form.
Where you make a request by other means, we require the request be made in writing via fax or letter including a copy of a government issued identification and signature. We also require home and business addresses and phone numbers so we can check them with our files and satisfy ourselves as to your identity.
The above information is required to create an audit trail of how the request has been handled. Where a request is made, any correspondence or application may be kept and added to your Personal Information.

How do I revise my Personal Information?

If at any time you wish to update your Personal Information, you can do so by contacting our Corporate Offices:
– via e-mail at: info@greekpridehotel.com
– via phone at +30 23730 41332
Or you may visit our web site at www.greekpridehotel.com

For How long is my Personal Information retained?

Your Personal Information in our Guest Reservation System will be stored indefinitely by Aithrion IKE as long as there is a business purpose for doing so. Registration forms are destroyed after one year.

How will I know if there are changes to this Policy?

If we decide to change our Privacy Policy, we will post those changes on our web site (www.kapparesort.com) so you are always aware of how we treat Personal Information. If you do not agree with the different way we intend to use Personal Information, you may ask in writing that we not use it in that different way. If you do not object, you will be deemed to have consented to the use of your Personal Information in the changed manner.

What laws apply to this policy?

Aithrion IKE is in Greece. As such, we apply the requirements of Greek law. We ensure the privacy and protection of your Personal Information according to the new European General Data Protection Regulation (GDPR).