1. Data Controller Information
The “Data Controller” for your personal information is [Official Corporate Name as registered with GEMI], located at [Full Physical Address in Skiathos].
- Tax Registration Number (AFM):
- GEMI Number:
- Contact Email:
2. Categories of Data Collected
We collect and process the following categories of data to provide our services:
- Core Identity: Full name, nationality, date of birth, and passport or ID number. The collection of identification documents is a legal requirement under Greek police and tourism regulations.
- Contact Information: Email address, phone number, and home address.
- Financial Data: Credit/debit card details and transaction history for payment processing via secure, PCI-DSS compliant gateways.
- Stay Details: Room preferences, arrival/departure dates, and data related to the Climate Crisis Resilience Fee.
- Sensitive Information: Health data (e.g., allergies or disabilities) is only processed if voluntarily disclosed for your safety or to protect your vital interests.
- Digital Data: IP addresses, cookies, and device identifiers collected through our website.
3. Lawful Bases for Processing
We process your data based on the following legal grounds:
- Contractual Necessity: To manage your reservation and provide accommodation services.
- Legal Obligation: To comply with Greek tax laws (AADE), police reporting, and the mandatory collection of the Climate Crisis Resilience Fee under Law 5073/2023.
- Legitimate Interests: For the security of our premises and the protection of guests and staff.
- Consent: For marketing activities, such as newsletters. In Greece, the age of digital consent is 15 years; users below this threshold require parental authorization.
4. Digital Transparency and Cookies
Our website utilizes a cookie management system that requires your active consent for all non-essential cookies (e.g., Google Analytics). You have the right to “Reject All” non-essential cookies with the same ease as accepting them.
5. Data Sharing and Transfers
Your data is shared only when necessary with:
- Public Authorities: The Greek Police and the Tax Authority (AADE) as required by law.
- Service Providers: Third-party processors (e.g., Booking Engines, PMS) who have signed Data Processing Agreements (DPAs) ensuring GDPR compliance.
- International Transfers: If data is transferred outside the EEA (e.g., via cloud services), we utilize Standard Contractual Clauses (SCCs) to ensure protection.
6. Data Retention Strategy
- Guest Registration & Invoices: Retained for 10 years to meet statutory tax and police requirements.
- Marketing Data: Retained until you withdraw your consent.
7. Your Rights and Recourse
Under the GDPR, you have the right to access, rectify, or erase your data, as well as the right to object to or restrict processing.
To exercise these rights, please contact us at ninaretiskiathos@gmail.com. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
- Address: 1-3 Kifissias Avenue, PC 115 23, Athens, Greece.
- Website: www.dpa.gr.