Privacy Notice

Last Updated: May 24th, 2018

At Α.Ξ.Ε.Π.Τ. ΑΕ, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Α.Ξ.Ε.Π.Τ. ΑΕ.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://thechatzigakimanor.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Α.Ξ.Ε.Π.Τ. ΑΕ.

Data Controller

Α.Ξ.Ε.Π.Τ. ΑΕ operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

The Chatzigaki Manor “Α.Ξ.Ε.Π.Τ. ΑΕ”
Pertouli
420 32, Pertouli, Trikala
GR

Data Processor

WebHotelier operates this booking system on behalf of Α.Ξ.Ε.Π.Τ. ΑΕ and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Α.Ξ.Ε.Π.Τ. ΑΕ, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Α.Ξ.Ε.Π.Τ. ΑΕ;
  • to pass on your financial details to Α.Ξ.Ε.Π.Τ. ΑΕ and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

This privacy policy governs your use of websites and services of Chatzigaki Manor Hotel, (Anaptyxiaki Xenodoxeiakh Epixeirhsh Pertouliou Trikalon – A.X.E.P.T. S.A.) company incorporated under the laws of Greece ("société anonyme") with its registered seat located at Pertouli, Trikala, Greece, hereinafter the "Chatzigaki Manor Hotel", “Hotel”, "we", "our", "us", for its own benefit.

The Hotel collects and processes data according to the principles included in the General Data Protection Regulation, EU 2016/679 (“GDPR”) and according to the applicable national and European legislation on personal data protection and for the purposes of processing which are described in the present Personal Data Protection Policy. It also takes all the necessary technical and organizational measures required for the protection of the personal data it collects and processes within the framework of its commercial activities.

We urge you to read carefully the present personal data protection policy of our Hotel,

By accepting our privacy policy and terms and conditions, you acknowledge that you have read and agree to be bound by this Privacy Policy. These terms may be amended, updated or otherwise modified, whether in whole or in part, at any time. The personal data, optional and compulsory, that you need to provide when you enter the web site or register for various services and products provided by the Chatzigaki Manor hotel and any additional personal data that will be requested in later stages are collected, processed, transferred, stored and used by the Chatzigaki Manor hotel, under its capacity as data controller, for its own benefit and affiliates as well as by service providers, including the data processors and service providers as they are described below.

1) Purposes of Processing

In accordance with the above legal framework, personal data collected by the Hotel are used for the following processing purposes:

a) To manage the booking of rooms, the organization of conferences or events as well as any other hosting, catering or food services

b) To manage the relationship with you before, during and after your stay at the hotel

c) For the Company's compliance with Greek and European Law

d) For marketing purposes

e) For the establishment, recognition, exercise, or defense of a right and legal claims

f) To support business processes

g) To improve our hotel services

h) For the security of our information technology systems

2) Legal basis for the Processing of Personal Data

The Hotel processes your personal data transparently, in accordance with the principles of legality, proportionality, confidentiality and integrity, limitation of purpose and accuracy, specific time of data retention and data minimization.

The legal basis for processing your personal data may be:

a) your consent

b) the need to process your data in the context of our contractual obligation or at the pre-contractual stage

c) the need to process your data in accordance with our legal obligation

d) the need to process your data in the context of safeguarding our legitimate interests

e) the need to process data to protect the vital interests of you or the person you accompany

f) the need to export statistics

3) Data the Hotel processes

For the above purposes, the Hotel collects and processes personal data. The Hotel is fully committed to the safeguarding of your private life and the personal information you entrust us.

Your personal data are collected by the Hotel when you personally book on-line or by telephone or through a third party or through our website or through a third party’s platform (type Booking, Expedia), or when information is passed on by third parties (for example travel agencies, on-line booking systems), or when you make a payment to the Hotel for the purchase of services in any way, or when you check in (online or physically) or during your stay in the Hotel.

We, usually, collect and process the following personal data:

  • records and copies of your correspondence when you contact us
  • Full name, nationality, identity card/passport number, date of birth, profession, address, signature sample, vehicle license plate number, telephone number and e-mail
  • Stay data (arrival-departure, number of persons, total number of overnight stays)
  • Information necessary to fulfil special requests (e.g., health conditions that require specific accommodation, dietary restrictions)
  • Room rate
  • Information on your payment, credit or debit card information, remittance number and bank account number
  • Invoice details
  • Record of previous visits
  • Contact information (i.e. e-mail) where the visitor agrees to receive information and advertising material by the Hotel

Purposes / Legal basis for data processing are:

- Performance of a contract to which the subject is a party

- Consent of the subject

- Compliance with the legal obligation of the Hotel.

The Hotel processes your personal data exclusively and only after you have given your written consent to this end, which you offer when you make a booking or when you check in at our Hotel.

The Hotel processes your personal data in a legal and legitimate way. In no case it collects or processes a greater number of information or data than the one required for fulfilling the purpose of the processing. Your data is safely stored. Their collection and processing are carried out exclusively for the above-mentioned purposes of processing and use. Your data are not used for the creation of a profile.

Minors

For persons under fifteen years of age (15), consent is offered by his legal representative.

The use of the web site and the booking engine is not intended for use by minors under the legal age requirement. No one under the legal age requirement may provide any personal information to or through our web site. We do not knowingly collect personal information from minors. If you are under the legal age requirement, please do not visit our web sites, don't make any use of the above or send any information about yourself to us, including your name, address, telephone number or email address. In the event that we find out that we have collected personal information from a minor without verification of parental consent, this information will be deleted, upon the minor’s parent or guardian notification. If you believe that we might have any information from or about a minor, please contact us.

To the maximum extent permitted by applicable law and without limiting any other provision of this Policy, the Chatzigaki Manor hotel disclaims any liability for any personal data submitted in contravention of this clause.

4) Communication Data

Persons who have expressed their wish through explicit consent to receive news and updates from the Hotel.

Purposes / Legal basis for data processing are:

Consent of persons wishing to receive updates and offers from the Hotel

5) Transfer of personal data to third parties

The entire workforce of the Hotel that processes your personal data is contractually bound by the terms of confidentiality and privacy of your data. We shall not disclose your information to third parties for their own independent business or marketing purposes without your consent.

In order to offer you the best possible services, we provide access to your personal data or to special categories of them, to specific and expressly authorized personnel of our Hotel. For example:

To the Reservations Department

To the IT Department

To the Marketing Department

To our Accounting Office

To the Legal Department if necessary

The Hotel will disclose your personal data if this is required by the law, by a judicial or regulatory decision or in order to exercise its legal rights.

These third parties may be found in Greece or in countries within the European Union or anywhere in the world. When personal data are stored by us we demand from the service providers to utilize suitable measures for the protection of the confidentiality and security of personal data. If the case of transfer of personal data to a third country outside the EU or to an international organization, you will be notified in advance according to the provisions of article 13 par. 1 (f) GDPR.

However, we may share your information with the following:

Business partners. We may also share your information with trusted business partners to provide you with services you have requested, in which case you will be deemed to have given your consent (especially for services of internal or external activities, excursions, visiting procedures, restaurant reservations, etc.) and for reasons related to the best service of the Chatzigaki Manor Hotel to you. These partners may use your information to provide the services you requested and to provide you with other material, in the event you have given your consent. Also, if your stay has been paid for by a third party, we will provide billing information to the party paying.

Service providers and / or any third party who may undertake the processing on our behalf. We may also disclose your information to companies that provide services on our behalf, such as IT subcontractors, email service companies, print service companies, etc.

Other third parties with your consent or by your order. In addition to the disclosures described in this Privacy Policy, we may share information about you with third parties if you give your consent or request it.

Exceptionally, the following are allowed to have access to your personal data:

a) the judicial and prosecutorial authorities in the exercise of their functions on their own motion or at the request of a third party claiming a legitimate interest and in accordance with legal procedures.

b) other bodies of the Greek State, which by virtue of their statutes have such a right and competence.

c) when we consider in good faith that disclosure is necessary to protect our rights or property, to protect your safety or the safety of others, or to investigate theft or fraud.

6) International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Hotel PMS data is stored in the cloud, using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. Mail service data is stored in the cloud and in servers based in the USA. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

7) Personal data retention period

We take reasonable steps to ensure that your personal information is retained only for as long as it is necessary and for the purpose for which it was collected or for as long as it is required under contract or applicable law.

Your personal data are kept exclusively and only for a reasonable period of time required for fulfilling the above-mentioned purposes for which they were collected, in compliance with the legislation in force.

Tax information is maintained in accordance with tax law.

8) Your rights concerning your personal data

The Hotel ensures that data subjects are able at any time to exercise their rights under the law regarding the collection and processing of personal data. These rights are: The right to be updated and have access, the right to correction, the right to erasure, the right to the limitation of processing, the right to oppose to the processing, the right to portability, the right to the withdrawal of consent.

In order to exercise any of your rights, you can send a message to the following e-mail address: info[at]chatzigaki.gr

Or you can contact us at the following address:

Chatzigaki Manor Hotel

Pertouli, Trikala, Greece,

PC 42032

Telephone: +30 24340 91146

The Hotel will respond to your request free of charge, without delay and in any event within one month upon receipt of the request, except in exceptional cases, so that the above deadline may be extended by a further two months if necessary, taking into account the complexity of the request and/or the number of requests. The Hotel will inform you of any extension within one month upon receipt of the request, as well as of the reasons for the delay. In the event that the satisfaction of your request is impossible, the Hotel will inform you within one month upon receipt of the request, of the relevant reasons and of the possibility to file a complaint with the Data Protection Authority, as well as about your right to appeal to the competent judicial authorities.

If your claim is deemed by the Hotel to be manifestly unfounded or excessive, it may give rise to the charge of a reasonable and proportionate fee, taking into account administrative costs to satisfy it or refusing to process your claim.

The right to complain to the APPD: You have the right to submit a complaint to the Authority for the Protection of Personal Data (www.dpa.gr), 1-3 Kifissias Avenue, 115 23, Athens, Greece: Switchboard: +30 210 6475600, Fax: +30 210 6475628, e mail: complaints@dpa.gr.

9) Security of personal data

The Hotel takes and applies all suitable technical and organizational measures, as possible, aiming at the safe processing of your personal data and the prevention of their accidental or unfair loss or destruction or distortion and the unauthorized and/or illegal access to them, their use, alteration or revelation and sees to the legality of the collection, processing and safe storage of personal data, according to the provisions of national, European and International Law on the protection of an individual from the processing of personal data and especially having regard to the provisions of the General Regulation on the Protection of Data (EU 2016/679)

10) Changes to the Privacy Policy

We reserve the right to change, update or supplement this Privacy Policy at any time. You are also advised to consult this Privacy Policy regularly for any changes. If you continue to accept the use of our website and our services after we have posted modified Terms, you are indicating to us that you agree to be bound by the modified Terms. If you don’t agree to be bound by the modified Terms, then you may not use our web site after such modifications have been made.

11) Jurisdiction

It is explicitly agreed that the Courts of Trikala, Greece applying the laws of Greece shall be exclusively competent for the resolution of any dispute, claim, interpretation or controversy arising out of or relating to the Terms of this privacy Policy.

12) Your Consents

By accepting this Privacy Policy you grant your explicit consent and you accept the processing and use of your personal data, as set forth and for the purposes described in this Privacy Policy.