Privacy Notice

Last Updated: May 24th, 2018

At S BOURBOS AE ODYSSEUS, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to S BOURBOS AE ODYSSEUS.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://odysseushotel.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to S BOURBOS AE ODYSSEUS.

Data Controller

S BOURBOS AE ODYSSEUS operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Odysseus Hotel Corfu “S BOURBOS AE ODYSSEUS”
Palaiokastritsa
490 83, Corfu
GR

Data Processor

WebHotelier operates this booking system on behalf of S BOURBOS AE ODYSSEUS and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of S BOURBOS AE ODYSSEUS, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at S BOURBOS AE ODYSSEUS;
  • to pass on your financial details to S BOURBOS AE ODYSSEUS and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

PRIVACY POLICY

1.1 ODYSSEUS HOTEL SA, a company incorporated in Greece with registered number MHTE: 1048494 whose address is Paleokstritsa – Corfu 49083 – Greece, (hereinafter “We” or “the Company”) are committed to protecting and respecting your privacy. This policy (together with our Terms of Use , the Cookies Policy and any other documents referred to on it) sets out the basis on which any personal data we collect from you, or that you provide to us, will be processed by us. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it. The Company is committed to preserving the privacy of all visitors to www.odysseushotel.gr  and to protecting any personal information that you may provide to us. We provide this Privacy to help you understand what we may do with any personal information that we obtain from you. By providing your personal information to us, you signify your acceptance of our Privacy Policy and agree that we may collect, use, and disclose your personal information as described in this Privacy Policy. If you do not agree to this Notice, please do not provide your personal details to us. What is personal information? Personal information is information about an identifiable individual, as defined by applicable law, such as name, e-mail address and telephone number etc. The data controller is ODYSSEUS HOTEL SA.

INFORMATION WE MAY COLLECT

2.1 We may collect personal information about you when you use our website, and otherwise interact with us. The information we collect falls into three categories:

(a) Information you provide us; and

(b) Information we collect through automated methods, and

(c) Information we collect from other sources.

2.2 We may combine the information you provide us, with information that is collected through automated methods, and with information we receive from other sources.

2.3 We collect information you provide us. You may provide the following information to us:

(a) Personal details, such as your name, postal and email addresses, phone number, date of birth and other contact information, when you register with our Website, log-in to Wi-Fi, or contact us by phone or through our online services;

(b) Profile information, including products and services you like, or times you prefer to visit us; and

(c) Other personal information you choose to give us when you interact with us.

2.4 We collect information through automated methods

(a) We may use automated technology to collect information from your computer system or mobile device when you visit our restaurants, use our online services, or in-restaurant technology. Automated technology may include cookies, local shared objects, and web beacons. There is more information below about cookies and other technologies.

2.5 We may collect information about your:

(a) Internet protocol (IP) address;

(b) Computer or mobile-device operating system and browser type;

(c) Advertising identifiers (for example, IDFAs and IFAs) or similar identifiers;

(d) Referring website (a site that has led you to ours) or application;

(e) Online activity on other websites, applications, or social media;

(f) Communications to us or regarding us on social media; and

(g) Activity related to how you use our online services, such as the pages you visit on our sites or in our mobile apps.

2.6 We collect information from other sources we may collect information about you from other companies and organizations. We may also collect information that is publicly available. For example, we may collect information about you when you interact with us through social media.

TYPES OF CLIENTS’ PERSONAL DATA

3.1 We will ask you to fill the registration form during registration/check-in at our properties and provide us with certain information about yourself. We will also collect your Personal Data on various other occasions during your interaction with us and your stay at our hotels, including:

(a) Booking a room with us;

(b) Checking – in and paying;

(c) Using the facilities of our hotels during your stay;

(d) Lodging a request/complaint during your stay;

(e) Participation in customer surveys;

(f) Subscription to newsletters and other types of direct marketing communication;

3.2 In order to administer your accommodation at our hotel and to meet our obligations towards you, as a customer/guest of ours, we will collect the following information about you, including:

(a) Contact details (for example, last name, first name, father’s name, telephone number, email, nationality, gender, place and date of birth, postal address, national identification number, tax identification number);

(b) Information relating to your children (for example, first name, date of birth, age);

(c) Information related to your reservation, stay or visit to a property;

(d) Information related to the purchase and receipt of products or services;

(e) Transaction and billing information, such as your payment card number and other card information;

(f) Guest preferences;

(g) Marketing and communication preferences;

(h) And other types of information that you choose to provide to us or that we may obtain about you.

3.3 The information collected in relation to children and minors is limited to which can only be provided to us by their legal guardian and/or any person legally authorized to do so.

COOKIES

4.1 We may obtain information about your general internet usage by using a cookie file which is stored on your browser or the hard drive of your computer. Cookies contain information that is transferred to your computer’s hard drive. They help us to improve our site and to deliver a better and more personalized service. Some of the cookies we use are essential for the site to operate. Please note that our advertisers may also use cookies, over which we have no control. For more information on the way, we use cookies, please refer to our Cookies Policy.

USES MADE OF THE INFORMATION

5.1 We use information held about you in the following ways:

(a) To ensure that content from our site is presented in the most effective manner for you and for your computer;

(b) Meeting our obligations to our customers;

(c) Managing the reservation of rooms and accommodation requests;

(d) Managing your stay at the hotel

(e) Improving our hotel service, especially processing your personal data in our customer marketing program in order to carry out marketing operations, understand better your wishes, adapt our products and services to better meet your requirements, customize commercial offers and the promotional messages we send to you, inform you of special offers and any new services of our hotels;

(f) Managing our relationship with you as a customer before, during and after your stay, especially: developing statistics and carrying out reporting; identifying and managing preferences of our customers; directly communicating with you for marketing purposes (newsletters, promotions, hotel offers) satisfaction surveys; managing requests to unsubscribe from receiving communication from us; managing the data subjects’ requests with regard to the processing of their personal data; analyzing your Personal Data, in order to determine your interests and your customer profile, and to allow us to send you personalized offers

(g) Conforming to local legislation (for example, storing of accounting documents).

5.2 We may also use your data, or permit selected third parties to use your data, to provide you with information about goods and services which may be of interest to you and we or they may contact you about these. We do not disclose information about identifiable individuals to our advertisers, but we may provide them with aggregate information about our users. We may make use of the personal data we have collected from you to enable us to comply with our advertisers’ wishes by displaying their advertisement to that target audience.

MARKETING COMMUNICATIONS

6.1 If you have agreed to receive marketing communications from us, you can later opt out by following the opt-out instructions in the marketing communications we send you. You can also opt out by contacting us at the address, phone number or email address below. If you do opt out of receiving marketing communications from us, we may still send communications to you about your transactions, any accounts you have with us, and any contests, competitions, prize draws or sweepstakes you have entered. Opting out of one form of communication does not mean you’ve opted out of other forms as well. For example, if you opt out of receiving marketing emails, you may still receiving marketing text messages if you’ve opted in to receiving them.

6.2 We do not share your Personal Data with third parties for their own direct marketing purposes, unless you give us permission to do so. When we give you notice, and you consent, we will share your Personal Data as you direct us to.

6.3 We keep your information for the length of time needed to carry out the purposes outlined in this privacy statement and to adhere to our policies on keeping records (unless a longer period is needed by law).

6.4 If at any time you would like to correct the personal information we have about you, please contact us at the address, phone number or email address below (see par. 14 below).

WHERE WE STORE YOUR PERSONAL DATA

7.1 The data that we collect from you shall not be transferred to, and stored at, a destination outside the European Union.

7.2 All information you provide to us is stored on our secure servers. Any payment transactions will be encrypted.

INFORMATION SECURITY

8.1 Unfortunately, the transmission of information via the internet is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.

RETENTION OF PERSONAL INFORMATION

9.1 We retain personal information for the period of time necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

 

DISCLOSURE OF YOUR INFORMATION

10.1 We will only share your information as described in this Privacy Policy.

10.2 We may share your information with vendors who provide services to us, such as fulfilling orders, providing data processing and other information technology services, managing promotions, contests, carrying out research and analysis, and personalizing individual customer experiences. We do not allow these vendors to use this information or to share it for any purpose other than to provide services on our behalf.

10.3 There may be times where we may share information when it does not directly identify you. For example, we may share anonymous, aggregated statistics about your use of our Website. Or we may combine information about you with other customers and share the information in a way that does not identify you.

10.4 We have the right to use or share information as necessary to keep to any law, regulation or legal request or requests of any embassy regarding your stay at our hotels, to protect our Website, to bring or defend legal claims, to protect the rights, interests, safety and security of our organization and our employees, or users of the Website, or in connection with investigating fraud or other crime, or violations of our policies.

YOUR RIGHTS

11.1 Under the applicable legislation you have the right to request access to the personal data we hold about you, i.e. to be informed upon your request whether your personal data are subject to processing and to receive further information on such processing, including information on eventual transfers of personal data outside the EU and the appropriate or suitable safeguards we have in place for such transfer.

11.2 As long as the requirements under the applicable legislation are met, you may also request the correction of any inaccurate information we hold about you or the deletion of the same or restriction of the processing concerning your personal data. If such a request places us or our affiliates in breach of its obligations under applicable laws, regulations or codes of practice, then we may not be able to comply with your request but you may still be able to request that we block the use of your personal information for further processing. You may also have a right to data portability to another data controller under certain circumstances.

11.3 You may withdraw your consent at any time. The withdrawal of your consent will not affect the lawfulness of processing based on consent before its withdrawal.

11.4 You may also lodge a complaint with the competent Data Protection Supervisory Authority, if you feel that the processing contravenes the law.

11.5 If you would like to exercise your rights above or if you have any questions or concerns about our Privacy Policy please contact: info@odysseushotel.gr

LINKS TO OTHER WEBSITES AND SOCIAL MEDIA

12.1 Our Website may, from time to time, contain links to and from the websites of our partner networks, and advertisers. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

12.2 We may also have providers of other apps, tools, widgets and plug-ins on our online services, such as Facebook “Like” buttons, which may also use automated methods to collect information about how you use these features. These organizations may use your information in line with their own policies.

CHANGES TO OUR PRIVACY POLICY

13.1 This Privacy Policy is in effect as of the date noted at the top of the statement. We may change this Privacy Policy from time to time. If we do, we will post the revised version here and change the “last updated date” at the top of the statement. You should check here regularly for the most up-to-date version of the statement.

13.2 Any changes we may make to our Privacy Policy in the future will be posted on this page.

HOW TO CONTACT US

14.1 If you want to contact us about this Privacy Policy as well as for the exercise of your rights, you can reach us at: ODYSSEUS HOTEL SA - info@odysseushotel.gr