Privacy Policy

1. Introduction

This Privacy Policy describes how the company under the name “THE ATHENIAN CALLIRHOE EXCLUSIVE HOTEL S.A.” (hereinafter the “Hotel”, the “Company”, “we”, “us” or “our”) collects, uses, processes, stores and protects the Personal Data of visitors and users of its website.

The Company processes Personal Data in accordance with Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”), Greek Law 4624/2019 and the applicable Greek and European data protection legislation.

This Privacy Policy applies to any processing of Personal Data carried out through the Hotel’s website, as well as to any communication or electronic interaction taking place through it.

2. Data Controller

The Data Controller of the Personal Data collected through this website is:

THE ATHENIAN CALLIRHOE EXCLUSIVE HOTEL S.A.

15 Petmeza Street & Kallirrois Avenue, 11743 Athens, Greece

Telephone: (+30) 210 9215353

Email: hotel@tac.gr

As Data Controller, the Company determines the purposes and means of the processing of Personal Data collected through this website and ensures that such processing is carried out lawfully, fairly and securely.

3. What Personal Data We Collect and for What Purposes

While browsing our website and using the services available through it, we may collect and process the following categories of Personal Data:

Activity

Personal Data

Purpose of Processing

Legal Basis

Browsing the website

IP address, date and time of access, device and browser information, technical log files

Ensuring the secure operation of the website, technical support, prevention of malicious activities and improvement of our services

Legitimate interest (Article 6(1)(f) GDPR)

Submitting a contact form or sending a message

Full name, email address, telephone number (if provided), message content

Managing requests, providing information and communicating with users

Pre-contractual measures and legitimate interest (Article 6(1)(b) and (f) GDPR)

Online room reservation

Identification and contact details, reservation details, invoicing and payment information, special preferences relating to the stay

Completing and managing reservations, providing accommodation services and complying with tax and other legal obligations

Performance of a contract and compliance with a legal obligation (Article 6(1)(b) and (c) GDPR)

Modification or cancellation of a reservation

Reservation number, email address or other identification details

Managing requests for reservation modifications or cancellations

Performance of a contract (Article 6(1)(b) GDPR)

Participation in or organisation of conferences, corporate events or social events

Contact details of participants or organisers, reservation details for meeting rooms or event services

Organisation, management and implementation of conferences, corporate meetings and social events

Performance of a contract and legitimate interest (Article 6(1)(b) and (f) GDPR)

In each case, we only collect Personal Data that is necessary and proportionate for the relevant processing purpose.

Failure to provide certain mandatory information may prevent us from providing the requested services or responding to your request.

4. Special Categories of Personal Data

The Company does not collect, and does not seek to collect, Special Categories of Personal Data, such as data concerning health, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, biometric data or other sensitive information.

However, in the context of a specific request, accommodation requirement or service provided by the Hotel, you may voluntarily provide information relating to your health or other Special Categories of Personal Data. In such cases, such data will be processed only to the extent strictly necessary for the provision of the requested services and in accordance with Article 9 of the GDPR and any applicable legal requirements.

We recommend that you do not submit sensitive Personal Data through the general contact forms available on the website unless this is strictly necessary for the fulfilment of your request.

5. Minors' Data

The Hotel's website is not specifically directed at minors, and the Company does not knowingly seek to collect or receive Personal Data directly from individuals under the age of fifteen (15) without the consent of their parent or legal guardian.

However, the Company is not always able to verify the age of individuals accessing and using the website. For this reason, if a minor provides Personal Data through the website without the required parental consent, the Company will take appropriate steps to delete such data as soon as it becomes aware of the relevant circumstances. Until we receive written notification that the Personal Data relates to a minor, such data will be processed in the same manner as Personal Data relating to adults.

Where the processing of a minor's Personal Data is based on consent, such consent shall be valid only where it is provided by the minor who has reached the age of fifteen (15) or, in the case of a younger minor, by the person exercising parental responsibility, in accordance with Article 8 GDPR and Article 21 of Law 4624/2019.

6. Recipients of Your Personal Data

The Company takes appropriate measures to ensure that access to your Personal Data is restricted only to those persons who need such access in order to perform their duties and provide our services.

In this context, your Personal Data may be disclosed to or become accessible by the following categories of recipients:

  • authorised employees of the Hotel who are bound by confidentiality obligations;

  • service providers and business partners acting on behalf of the Company as processors pursuant to Article 28 GDPR. The Company ensures that such processors provide sufficient guarantees for the protection of Personal Data and are contractually bound to implement appropriate technical and organisational measures in accordance with Articles 28 and 32 GDPR;

  • in particular, when making an online reservation through the website, you are redirected to the reservation environment of WebHotelier Technologies Ltd, which processes the Personal Data included in your reservation on behalf of the Company as a Data Processor, providing appropriate safeguards for the security and protection of Personal Data, including measures relating to the secure processing of payment information;

  • external professional advisers, such as accountants, auditors, legal advisers and providers of business support services;

  • organisers of conferences, corporate events or social events, where this is necessary for the management of your participation or the provision of the relevant services;

  • public authorities, courts, regulatory authorities and other competent bodies, where disclosure is required by applicable law or pursuant to a lawful request.

The Company ensures through appropriate contractual arrangements that any third-party processing Personal Data on its behalf provides sufficient guarantees for the protection of such data and complies with the requirements of the GDPR.

7. Transfers of Personal Data outside the European Economic Area

In principle, the Company does not transfer Personal Data outside the European Economic Area ("EEA").

Should such a transfer become necessary, it will take place only in accordance with the requirements of Articles 44 et seq. of the GDPR and subject to the implementation of appropriate safeguards to ensure the protection of the rights and freedoms of Data Subjects.

8. Data Retention Period

The Company retains Personal Data only for as long as necessary to fulfil the purposes for which it was collected and, in any event, for no longer than five (5) years from the date of collection, unless a longer retention period is required by applicable law.

In particular:

  • Personal Data collected through the contact form are retained for as long as necessary to manage and respond to the relevant request and to address any related issues or legal claims;

  • Personal Data relating to reservations, invoicing and financial transactions are retained for the period required under applicable tax, accounting and other legal obligations;

  • Personal Data necessary for the establishment, exercise or defence of legal claims may be retained until the expiry of the applicable limitation periods.

Upon expiration of the applicable retention period, Personal Data is securely deleted or anonymised, as appropriate.

9. Your Rights

You remain in control of your Personal Data and may exercise the rights granted to you under Articles 12 to 23 of the GDPR and the applicable data protection legislation, including the following:

  1. Right to Information: You have the right to be informed about how your Personal Data is collected and used, as described in this Privacy Policy.

  2. Right of Access: You have the right to obtain confirmation as to whether or not the Company processes Personal Data concerning you and, where that is the case, to access such Personal Data.

  3. Right to Rectification: You have the right to request the correction of inaccurate Personal Data and the completion of incomplete Personal Data.

  4. Right to Erasure ("Right to be Forgotten"): You have the right to request the deletion of your Personal Data where there is no longer a lawful basis for their retention or processing, subject to any legal obligations requiring their continued retention.

  5. Right to Restriction of Processing: You have the right to request the restriction of the processing of your Personal Data in the circumstances provided for by applicable law.

  6. Right to Data Portability: You have the right to receive the Personal Data you have provided us in a structured, commonly used and machine-readable format and, where technically feasible, to request its transmission to another controller.

  7. Right to Object: You have the right to object, on grounds relating to your particular situation, to the processing of your Personal Data where such processing is based on the Company's legitimate interests.

  8. Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw such consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.

You also have the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of your habitual residence, place of work or the place of the alleged infringement, if you consider that the processing of your Personal Data infringes the GDPR (Article 77 GDPR) and that your request has not been adequately addressed by the Company.

In Greece, the competent supervisory authority is the Hellenic Data Protection Authority (HDPA) (1-3 Kifissias Avenue, 115 23 Athens, +30 210 6475600, https://www.dpa.gr/el/polites/katagelia_stin_arxi)

10. Exercising Your Rights

You may exercise any of the rights described above by contacting the Company at: hotel@tac.gr

The Company will respond to your request without undue delay and, in any event, within one (1) month of receipt of the request, unless an extension is permitted under Article 12 GDPR.

The Company may request additional information necessary to verify the identity of the applicant before responding to the request.

11. Data Security

The Company implements appropriate technical and organisational security measures, in accordance with Article 32 GDPR, to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Such measures are regularly reviewed and updated, taking into account technological developments, the nature of the Personal Data processed and the risks that may arise from its processing.

12. Social Media

The Hotel's website may contain links to the Company's social media accounts and profiles.

Any interaction with such social media platforms is governed by the privacy policies and terms of use of the respective providers. The Company is not responsible for the manner in which such third parties collect, use or otherwise process Personal Data.

13. Cookies

The website uses cookies and similar technologies to enhance functionality, improve security and optimise the user browsing experience.

For detailed information regarding the cookies used on the website, the purposes for which they are used and the available cookie management options, please refer to the separate Cookie Policy available on the website.

14. Changes to this Privacy Policy

The Company reserves the right to amend, revise or update this Privacy Policy whenever deemed necessary due to legislative, regulatory, operational or technological developments.

The most current version of this Privacy Policy will always be available on the Hotel’s website and shall become effective upon its publication. We encourage you to always review this Privacy Policy and, if you agree with its terms, continue using and browsing this website.

15. Contact Details

Data Controller

THE ATHENIAN CALLIRHOE EXCLUSIVE HOTEL S.A.
15 Petmeza Street & Kallirrois Avenue, 11743 Athens
Tel.: (+30) 210 9215353
Email: hotel@tac.gr

Competent Supervisory Authority

Hellenic Data Protection Authority (HDPA)
1-3 Kifissias Avenue, 11523 Athens
Tel.: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr