Privacy Notice

Last Updated: May 24th, 2018

At LAZAROS GATSIOS & SIA OE, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to LAZAROS GATSIOS & SIA OE.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://akrogialihotel.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to LAZAROS GATSIOS & SIA OE.

Data Controller

LAZAROS GATSIOS & SIA OE operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Akrogiali Exclusive Hotel Halkidiki *** | Adults Only “LAZAROS GATSIOS & SIA OE”
Polichrono, Kassandra
630 85, Chalkidiki
GR

The User may contact our Data Protection Officer:

Data Protection Officer
akrogiali@otenet.gr

Data Processor

WebHotelier operates this booking system on behalf of LAZAROS GATSIOS & SIA OE and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of LAZAROS GATSIOS & SIA OE, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at LAZAROS GATSIOS & SIA OE;
  • to pass on your financial details to LAZAROS GATSIOS & SIA OE and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

PRIVACY POLICY

PROCESSING AND PROTECTION OF PERSONAL DATA

The Privacy Policy will apply to the facilities of the Akrogiali Exclusive Hotel and the digital environment regarding the activities carried out by LAZAROS GATSIOS AND CO OMORRYTHMI COMPANY which manages the Akrogiali Exclusive Hotel.

At Akrogiali Exclusive Hotel we respect and protect your privacy, as well as protect your personal data.

LAZAROS GATSIOS AND CO OMORRYTHMI COMPANY informs you that it will process and keep a record of your personal data for the purpose of your service during your stay at Hotel Akrogiali Exclusive Hotel as well as for the pricing and evaluation of our services by you .

Your personal data is kept and processed exclusively for the purposes stated or for which you have agreed and to the extent necessary for their fulfillment will be kept for the absolutely necessary period of time to serve the above purposes.

According to the General Data Protection Regulation 679/2016 / EU, you have the right of information, the right of access, the right of correction, the right of deletion, the right to restrict processing, the right to data portability, the right to object to the processing of your personal data, including automated decision-making and profiling, as well as the right to lodge a complaint at the Personal Data Protection Authority.

We want to provide you through this Privacy Policy with information regarding the collection and processing of the following data.

 

Data collection and processing.

Identity data, name, nationality, date, place of birth

Data related to accommodation, room number, length of stay, information on consumption of goods or services.

Data related to food cravings, allergies and other health data.

Image data, photos, video downloads

Contact details, home address, email address, mobile phone number.

Payment method data, credit cards and debit cards.

This Privacy Policy is intended to inform you transparently about the processing of your personal data, however it may not include all of our processing activities as they are constantly evolving.

 

Electronic booking engine through our website or via mobile.

If you decide to book through our website, we will collect your first and last name, address, city, country, phone, email, any special requests you may have, your credit card details (type card number, card number, secure code, expiration date, cardholder), arrival date and departure date as well as flight details in case of transfer request.

Booking confirmation form

If you contact us directly to make a reservation, we will send you the booking confirmation form to provide us with the necessary information, such as name, address, telephone, email, your credit card details (eg card type) , card number, expiration date, cardholder).

Electronic third party booking machines or travel agents

In this case, we receive an email confirming your booking, including information such as your first and last name, country, date of arrival and departure, flight details in case of transfer, any (family) members that will accompany you, any special requests (transport requirement, statement of special preferences or allergies that we need to know).

Purposes of processing - legal basis

We collect booking data for:

Room reservation and provision of corresponding services.

Provision of additional services.

Mediation and support regarding the use of means of transport, car rental and information for the processing of transport.

Sending useful updates (informative messages via e-mail, sms) during the stay at the hotel.

Charging for services and consumption and processing payment.

Check-in process

Upon arrival at Akrogiali Exclusive Hotel, you will be provided with the necessary information for the check-in process. More specifically, we collect your title, your first and last name, your language, your address (street, postal code, city, country), your nationality, your telephone number, your email address, the names of any accompanying you and their date of birth, date of birth, passport / ID number, car license plate, credit card details, date of arrival and departure date and room number.

Declaration of allergies / special preferences

Allergies and special preferences may in some cases be sensitive personal data. We may collect such data only if you provide it to us voluntarily or when we ask you to do so and provide your express consent.

Purposes of processing - legal basis

Akrogiali Exclusive Hotel collects your registration information and personal data for the following purposes:

• Complete the registration process. Identification data is required to comply with our legal obligations.

• Service of your stay. Our legal basis is our legitimate interest. In case you want to record the information about your allergies, preferences, we will proceed with the relevant processing, if you give us your consent.

• Facilitation of management. Our legal basis is our legitimate interest.

• Service of your stay.

• Facilitate the payment process. Payment information is required to issue your invoice and comply with tax obligations

• Improving our services to offer you unforgettable stays. Our legal basis is our legitimate interest.

• Offering personalized services (on preferences, etc.). Our legal basis is your prior consent, if any.

• For communication and marketing purposes, including the analysis of your travel and accommodation preferences, in order to offer you personalized services. Our legal basis is your prior consent, if any.

• Promotion of special offers and goods, services or upcoming events or offers that may interest you. Our legal basis is your prior consent, if any.

Evaluate your experience, improve our services, and further communicate with you to discuss your experiences.

• Assess and investigate an accident / incident in accordance with relevant internal procedures, for the proper handling of any legal issues that arise after

• Data transfer to our insurance company. Our legal basis is your explicit consent, if any.

Inform your company about our business news in the context of our cooperation with travel agencies and agents. Our legal basis is our legitimate interest.

Room service

If you wish to submit a "Breakfast in the Room" request, your order (including food preferences and allergies, if any) will be dropped along with your name and room number. This information will be properly deleted upon your departure.

Book breakfast through the QR MENU application

In case you wish to make a reservation through our application, we collect your name, surname, room number and relevant order details.

Personal data collected through visitor questionnaires

For us, your feedback is valuable, as they help us improve our services for you. You can give us your feedback at any time by completing the guest questionnaire. If you want to fill them in, providing personal information (ie your name, surname, room number email, address, country, occupation, arrival data, length of stay, birth data) is optional. .

Pictures / videos

We collect, process and store images through the video surveillance systems where they are installed, for security reasons, in accordance with the requirements and standards set by national and union legislation for the preservation of data, audio and video.

Security reports

Reports, including personal data, are prepared by our security department for security reasons (ie incident reports, item loss reports, open safe list, etc.). Such reports may include personal information, such as name, room number, and will only be recorded for security reasons.

Accident form

In the event of an accident on our premises, you will be asked to provide information such as your name, surname, date of birth, room number, length of stay, and some additional information about the accident, such as location of the event, the date and time of the event, is the nature and any other relevant details.

Data collected through our website or online platforms

Personal data collected through your subscription to our Newsletter

When you register to receive our newsletter, we collect and store your email address and if you wish you can submit your first name, last name and country.

Registration system of travel agents and tourist offices.

Akrogiali Exclusive Hotel will be notified of your request and you will receive a notification message. The data selected through this form is the data of the Company and the contact person of the Company and are not considered personal data or information. We will use the email address you provide to us through this form to inform your company of our business news as part of our partnership.

Internet technologies

On the website and the mobile application of LAZAROS GATSIOS AND CO OE , we may use cookies, invisible pixels, to obtain information about you when you visit our sites.

Personal data of our partners

If you cooperate with us, we may process only the data necessary to fulfill our contractual agreement and serve our business relationship. We may use the email address you provide to us voluntarily to keep your company informed of our business news as part of our partnership. However, you can always choose to unsubscribe from this business communication by clicking the unsubscribe button available on our communications.

Transfer of personal data

The personal information you provide to us is kept secure and protected. We may disclose your information to public services in, Third parties providing related services (eg hosting services, software, financing, legal or technical support, payroll, etc.). In any case, all these companies are contractually committed to us to ensure confidentiality, as well as commitment to data protection legislation.

Public authorities (police, prosecutors, tax authorities, etc.) in the context of the issuance of fines or upon request.

When data transmission concerns a country outside the European Union (EU) or the European Economic Area (EEA), we always check whether:

• The Commission has issued a decision of adequacy for the third country to which the transfer is addressed.

• There are appropriate safeguards in accordance with the Regulation for the transmission of such data.

In any other case, the transfer to a third country is not allowed and we may not transfer personal data, unless one of the special derogations provided for in the Regulation applies (eg explicit consent of the data subject, when informing transport), the transfer is necessary for the performance of a contract at the request of the subject, there are reasons of public interest, it is necessary to support legal claims and vital interests.

Disclaimer of third party websites

We can provide hyperlinks to third party websites as a convenience to our users. LAZAROS GATSIOS AND CO OE is not responsible for the content of any third party linked sites or for hyperlinking to a site linked to a site. We are not responsible for the privacy practices or the content of third party websites.

Your rights

If you wish to revoke your consent, exercise your rights or if you generally have any questions regarding the protection of your personal data, you can address your request by contacting the Hotel Manager at Email: akrogiali@otenet.gr

Your right to request correction of their inaccurate personal data;

Your right to request the deletion of personal information provided, unless prohibited by law;

Your right to request a processing restriction;

Data protection officer

In order to ensure that your personal data is effectively protected, LAZAROS GATSIOS AND CO. OE. appoint a data protection officer to whom data subjects may address their requests and questions in relation to this privacy policy, as follows:

Akrogiali Exclusive Hotel

Polychrono, Halkidiki, Greece,

63085 Kassandra,

Tel: 0030 6944503920

email: akrogiali@otenet.gr

In case you consider that we did not respond correctly to your request, you can always contact the competent Greek Data Protection Authority (www.dpa.gr).

Information security

We have taken precautions to maintain the accuracy of your data and to ensure the security of the information we collect. We take all measures to protect your personal information from unauthorized access,

Period of retention of personal data

Your personal data is retained for a predetermined and limited period depending on the purpose of the processing, after which, this personal data is deleted from our files, unless another retention period is required or permitted by applicable law.

Updates

The Privacy Policy may be modified to respond to changes in the regulatory environment and the Privacy Policy will be updated with a new date.

Date January 2020