Preamble
At THEARTEMIS PALACE RESORT hereinafter referred to as “Hotel”, we are committed to protecting and respecting your privacy. The observance of the Privacy Policy (“policy”) of Personal Data (“PD”) determines the basis on which PDs are collected for you. The Policy has been developed based on the Impact Assessment for the protection of PD (DPIA – Data Protection Impact Assessment), which is provided by the GDPR and the National law 4624/2019. PD are either provided to us by you, with your free consent directly or are provided to us through third parties, who have already secured your free consent and are always processed in accordance with GDPR. Please read the following carefully to understand the use of PD.
Information and PD that we collect on you
We collect information and PD from you, which you provide with your free consent either directly or through third party services with which you interact and have already asked for your free consent.
We may collect and process data, including the following during the provision of hosting and use of our facilities by you, which could contain PD or be considered as PD:
In addition, we inform you that
Purposes of processing
We process PD for the following purposes:
Legal basis of the processing
The legal bases of the processing are, as the case may be:
PD Security
The hotel is committed to take all measures possible to protect your PD. For this reason, we use a variety of security technologies and procedures for the protection of PD from unauthorized access and use. Please consider, however, that no physical or electronic security system is completely safe. We cannot guarantee the complete security of our databases, nor can we guarantee that the information you provide to us via the Internet may not be intercepted. However, we are committed to continuing to review and improve our security policies and implement additional technical and organizational security measures, when such new technologies become available.
The transmission of information via the Internet is not completely secure and may include the transmission of data to countries outside the European Union. This is due to the use of cloud solutions for web hosting, email hosting or exclusive software solutions which have been delivered to us via the Cloud. However, in any case we do not allow third parties to use your PD for their own purposes. While we will take all possible measures to protect your personal data, we cannot guarantee the security of your personal data which are transmitted to us. Consequently, any transfer of PD is at your own risk. Once PD are obtained, we take the necessary security measures to avoid unauthorized access.
Retention Period of PD
The period of time which PD is retained at the hotel is specified by the provisions of Greek legislation on the protection of the state’s interests and the hotel’s data maintenance policy on the protection of the legal interests of the company.
PD that are necessary for the conclusion or execution of the contract between us are kept throughout the duration of the contract and 5 years after its expiration. In case of claims, these data are kept until an irrevocable court decision is issued.
Transfer of PD
We ensure that your PD is processed legally, which is restricted within the Hotel, while ensuring their confidentiality and we are committed to non-transfer your PD to third parties other than those to whom you have already given your consent, without our intervention. However, we may disclose your information to business associates, who act as processors on our behalf, to the extent that the aforementioned processing purposes are served and provided that, under our contractual commitments, confidentiality is maintained to protect PD, the service of the legal interests of our company and with the right to control them.
Your rights
In connection with the exercise of your above rights, the following are noted
For the exercise of your above rights in accordance with European and Greek legislation and the restrictions defined in them, you can contact in writing at the address of the Company “TSOURLAKIS – BIRLIRAKIS HOTELS AND TOURISM ENTERPRISES SA” – “THEARTEMIS PALACE”, 26 Markou Portaliou str. Rethymno, 74100 Crete – Greece or electronically via e-mail: dpo@theartemis.gr
Services which are covered by this policy
E-mails
If you do not wish to receive marketing and promotional emails from the hotel, you can click on the unsubscribe link in the email to revoke your registration and cancel the email and marketing communications. You can also declare in the relevant hotel’s registration form that you do not give your consent to receive promotional emails, so you may choose not to be included in the hotel email lists. Please note that even if you opt out of receiving marketing messages from us, we may need to send you communications related to services, such as confirmations of any future reservations you may make.
WiFi service
For the WiFi service inside the hotel please see the relevant policy (WiFi disclaimer).
Data Controller
Data Controller is the company with the name “TSOURLAKIS – BIRLIRAKIS HOTELS AND TOURISM ENTERPRISES SA” – “THEARTEMIS PALACE”, as it is legally represented, with which you can contact for GDPR issues via e-mail address: info@theartemis.gr
Policy changes
We reserve the right to change this policy by applying newer provisions of European and Greek legislation and at our discretion. If we make any changes, we will record these changes here so that you can have immediate access.