1. GENERAL TERMS
This privacy policy sets out how the company under the name «Gargaretta Suites Wildflower», with registered —————————————————, collects, uses and process the personal data of visitors/users of its website “https://wildflowersuites.gr/”. Having the highest principle of protection of privacy and personal data, the Company is compliant with the requirements of General Data Protection Regulation EU/2016/679 and current national legislation, Law 4624/2019. With this text, the Company, as the Controller of the personal data, which extracted from its website, informs the visitors/users, with all the necessary information regarding the processing of their data and the practice of their rights. The use of the website “https://wildflowersuites.gr/”, means that you have read and accept this Privacy Policy of your personal data.
2. CATEGORIES OF DATA WE COLLECT
The personal data we collect depends on the nature of our relationship with you, as set out below:
When you book with us
When you make a reservation or a booking with us, or check-in at one of our accommodations, the processing of your personal data concerns information such as:
- full name
- address
- telephone number
- nationality
- identification documents (e.g. passport information)
- bank/payment details (when you make a payment)
- dates of arrival and departure
It may be the case that we collect more sensitive personal data about you, such as information about disabilities or medical conditions, if you need us to make special arrangements.
When you use guest wi-fi at one of our accommodations
If you sign up to use the guest wi-fi, we will collect your name and email address.
If you are a supplier or other business contact
The personal data we collect typically includes your name, your company name, your work contact details and any other information you may provide during our relationship.
Visitors to our website and persons making contact
When you sign up to receive newsletters through our website, the personal data we usually collect includes your name and email address. When you visit our website, we will automatically collect information through the use of cookies, web beacons, and website analytic tools, and the data collected will include the user’s Internet Protocol (IP) address and the user’s type of browser.
Please note that we do not address minors and do not collect their personal information. However, since it is impossible to crosscheck and verify the age of the users of our website, the Company asks the parents/guardians of minors, in case they become aware of any unauthorized data disclosure on behalf of minors, to immediately notify the Company, in order to take the necessary protective measures, such as the immediate deletion of this data.
3. PURPOSE OF DATA PROCESSING
We process your personal data for one or more of the following professional or commercial reasons:
- For identification purposes in order to communicate with you,
- For the management of your online submitted comment inquiry, booking request or expression of interest in relation to our provided services,
- For your information regarding our services, for which you have previously expressed an interest,
- For receiving payment for your booking by collecting, processing and storing payment and payment card information,
- For making accessibility or other arrangements for your stay,
- For guest registrations upon arrival,
- For providing customer services, including communicating with you about your stay, managing complaints or other issues during your stay, and requesting feedback,
- For the accurate and more efficient operation and management of our website,
- In order to investigate and resolve technical issues in the context of the provision of our services (e.g. coding errors),
- For sharing data with other group entities, including guest information required for the purposes of bookings,
- For security purposes or to investigate possible fraud or other violations of the Terms of Use of our website or this Privacy Policy,
- To conduct studies and research in order to evaluate and improve our services or to develop new services,
- To investigate the degree of satisfaction from the service offered and the services of the Company and/or your further needs or wishes,
- To understand how you use and interact with the content of our website, through the use of cookies (Performance, analysis and research Cookies),
- To improve our services offered through our website, in order to meet your personal needs and choices also using location data (Functionality Cookies),
- To improve and measure the effectiveness and deliverability of our advertisements appearing in third party websites, to display advertisements related to our offers and services as well as to send updates via newsletters (Advertising and Marketing Cookies).
In any case, the Company may process your data for purposes of compliance with the obligations imposed by the currently applicable legal and regulatory framework and the supervising authorities, as well as with the decisions of competent Authorities or Courts.
4. LEGALITY OF DATA PROCESSING
The legitimation of data processing is based on the following relevant provisions of the General Data Protection Regulation (GDPR) ΕU 679/2016 and the processing takes place only in case:
- the data subject has given his/her complicit consent to the processing of his or her personal data and/or
- the processing is necessary for the performance of a contract and/or
- the processing is necessary for the compliance of the Company with one of its legal obligations and/or
- the processing is necessary for the purposes of the legitimate interests of the Company.
5. DISCLOSURE OF DATA
Your personal data is not disclosed or transferred in any case to third parties except with your written permission or in case of law enforcement. Exceptions are cases in which, in order to fulfil our contractual and legal obligations, your personal data may be provided to our external partners (e.g. cloud service providers, information systems, property management service providers, accounting services) or other entities within our group. The above external partners are bound by contractual confidentiality clauses and compliance with processing standards, in order to ensure sufficient assurances for the implementation of appropriate technical and organizational measures to protect your personal data.
The Company reserves the right to disclose and/or transfer personal data to a third party to whom it may transfer or merge parts of its business or assets. In the event of a change in our business, the new owners will have the right to use your personal data in the same way as set out in this Privacy Policy.
Where personal data needs to be transferred outside the EU during the course of its lawful activities, the Company will select the appropriate legal transfer mechanisms in full compliance with the Regulation and Existing Legislation and will inform the data subjects accordingly.
6. DATA RETENTION PERIOD
We will keep your personal data for as long as it is required to provide you with our services. Afterward, we will maintain it for a reasonable period to meet our contractual and legal responsibilities and to manage complaints and claims. When the processing is imposed as an obligation by provisions of the applicable legal framework or a specific retention period is foreseen, your personal data will be stored for as long as the relevant provisions require. At the end of the retention period, we will securely delete or anonymise your personal data. This will be done by aggregating the data with other data to create non-identifiable information for statistical analysis and business planning.
The personal data of users that are processed upon consent are kept until the consent is revoked, without this revocation affecting the legality of the processing until then.
7. YOUR RIGHTS
According to the General Data Protection Regulation EU 679/2016, you have the following rights in terms of your personal data, which you could practice by contacting the Company, through the following contact/correspondence details and request the following:
- the right to request access to your Personal Data,
- the right to correct inaccurate data concerning you,
- the deletion of data concerning you, to the extent that these are no longer necessary in relation to the purposes for which they are collected or when there is no longer any legalization to be processed and if such action is not contrary to legal obligation, for reasons of public interest, or on the basis of legal claims,
- the limitation of the processing of your data, if it is based either on the questioning of the accuracy of the data, or on the exercise of legal claims, or on objections to the processing,
- the portability of data concerning you, i.e. the transmission of this data to another Controller. This action may be taken if the processing is based on your consent and is carried out by automated means, without prejudice that the processing is not based on the performance of a duty in the public interest or the exercise of official authority entrusted to the Data Controller,
- the exercise of the right to object to the processing of your data, which is based on the performance of a duty in the public interest or on a legitimate interest pursued by the Data Controller, unless the latter demonstrates compelling and legitimate reasons to the contrary,
- the withdrawal your consent, provided that your data is processed on the basis of your explicit consent.
In case it is necessary for your identity to be confirmed for the above requests, you may be asked to provide documentary evidence. Once the legality of the request has been verified, the Company shall respond within the period of one (1) month provided by the law, after the receipt of your request and provide you with relevant information. Finally, you reserve the right to file a complaint to the competent Supervisory Authority (Hellenic Data Protection Authority) through the website: www.dpa.gr.
Keep in mind that our response to your aforementioned request is provided free of charge. However, if your requests is obviously inadmissible, excessive or repeated, we may charge a reasonable fee, after notifying you in advance or refuse to respond to your request.
8. DATA SECURITY
To ensure that your personal data is not unintentionally lost, altered, disclosed, or accessed in an unauthorized manner, we implement appropriate technical and organizational protection measures. We are aware of the varying levels of risks to the rights and freedoms of individuals and take necessary precautions to prevent such risks. Access to your personal data is restricted to only those employees and/or associates who are required to perform their duties. The above persons process your data exclusively in accordance with the instructions of the data controller (the Company) and undertake to comply with the relevant terms of confidentiality. In addition, procedures are in place to deal with any possible breach of personal data, and in this case, the concerned individual and/or any competent authority will be notified when deemed necessary, in accordance with the applicable legal and regulatory framework.
However, it is your responsibility to ensure that the equipment (e.g. personal computer, software, telecommunication equipment) that you use is sufficiently secure and protected from malware (e.g. viruses). You should be aware that, not using sufficient security measures (e.g. secure settings in your browser, updated malware protection software, avoidance of use of software and hardware of dubious provenance, etc.), entails the risk that your data, as well as the passwords you use, may be disclosed to non-authorized third parties.
9. LINKS TO OTHER WEBSITES
Our website may contain links to enable you to visit other websites of interest easily. However, once you have used these links and left our website, you should note that we do not have any responsibility. Therefore, we cannot be responsible for the protection and confidentiality of any information you provide during your visit to other websites, where you should review their respective Privacy Policy.
10. PRIVACY POLICY UPDATES
This Privacy Policy may be updated from time to time, subject to changes in the applicable legal framework, in order to fully comply with its requirements. It is recommended that you check this Privacy Policy frequently so that you are informed in a timely manner of any changes that will take effect upon their posting on the Company’s website. The use of our Website or any of our products and services after the occurrence of any changes is considered an acceptance of the revised Privacy Policy.
11. CONTACT INFORMATION
For any clarification regarding this Privacy Policy or for the exercise of your rights you can contact us via the e-mail address:————————- or by sending a letter to the address ————————————————–