Privacy Notice

Our Company fully shares your concern regarding your personal data. Recently, we have introduced several changes that reflect the enhanced requirements of the EU’s General Data Protection Regulation (a.k.a. GDPR). Our aim is to be as honest and transparent as possible regarding the personal data we collect and the way we process it.

Ι. Types of personal data collected – Purposes

Through this website, personal data are being collected and processed for the following purposes:

Contact

The phone number and the e-mail addresses through which you can contact us can be found on our website. During the process of communication, any personal data you have provided shall be collected.

Booking Inquiry

When you make an inquiry on our website using our booking inquiry form, we collect the data that you submit in the form, as listed below: name, e-mail, and any other information you choose to include in the relevant message field.

ΙI. Legal basis for the data processing we conduct

Our Company collects and processes personal data when at least one of the following conditions are present:

• Execution of a contract: processing is essential for the performance of the contract or for action to be taken on the request of a natural person prior to the conclusion of a contract. For example, we collect and process your personal data to complete and manage your reservation so that we can respond adequately to any queries you have submitted through our communication channels (contact form, phone, fax, e-mail).

• Legal Obligation: processing is necessary so that we can comply with obligations established by the law.

• Legitimate interests of the Controller or third parties, provided that they are not overridden by the interests of the employee: Collection and processing are essential for the protection of our legitimate interests in order to ensure the smooth operation of our hotel, the achievement of our corporate goals and the defense of any legal claims.

• Vital interests: Processing is necessary to protect the life or any other vital interests of the data subject.

• Consent: In cases where required by law or when none of the above legal bases is applied, our company shall collect and process data after being given explicit, freely given, and informed consent by a natural person (the data subject) under the specific conditions provided by the GDPR. For example, we are given your consent for data collection through cookies.

III. How long your personal data is retained for

Personal data shall be retained for as long as necessary for data collection purposes, unless otherwise specified by law.

If retaining your data is not needed for an explicitly described and legal purpose, we safely delete and/or destroy them in accordance to our “Policy for Keeping and Deleting Personal Data”.

ΙV. Who your personal data are disclosed and/or transmitted to

Your personal data shall be disclosed to:

(a) Authorized employees of our Company.

(b) Entities entrusted with the execution of specific tasks such as, but not limited to, lawyers, product suppliers and/or IT service providers and/or support service providers of all kinds of computer-based information systems or electronic systems and networks, logistics companies, marketing companies, business consulting firms.

(c) Third parties cooperating with or rendering services to our Company, including, but not limited to, cleaning and catering personnel.

(d) Supervisory, independent, judicial, prosecuting, public and/or other authorities, bodies or parties assigned to control/monitor the Company’s activities within the scope of their responsibilities.

(e) Companies under a franchise agreement, for example to “Marriott International”.

(f) To «KANAVA S.A.»

V. Rights of the data subject

The General Data Protection Regulation provides you with rights and options that we are committed to satisfying. Thus, you may:

You may send your requests to the email address: dpo-cust@revivalsa.gr .

Our Company shall fulfill all your requests within one (1) month. In the extremely rare cases that such a fulfillment is proven unfeasible, we shall immediately inform you explaining the reasons in detail.

If you believe that the provisions for personal data are being violated, you may file a complaint to the Hellenic Data Protection Authority (www.dpa.gr).

VI. Contact Info

We shall remain at your disposal for any further query or clarification. Contact us.

Email: dpo-cust@revivalsa.gr

DATA CONTROLLER
NAFSIKA ESTATE
reservations@vedema.gr
Megalohori, Santorini
+30 22860 81796
DPO
Revival Consulting Services Α.Ε
dpo-cust@revivalsa.gr
Lenorman 194-196
+30 210 5156800

VII. Effective date – Amendments Version 1.0, Posted on 22/05/2019