Privacy Notice

Last Updated: May 24th, 2018

At KASSANDRA BAY SA, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to KASSANDRA BAY SA.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://kbammoshotel.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to KASSANDRA BAY SA.

Data Controller

KASSANDRA BAY SA operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

KB Ammos “KASSANDRA BAY SA”
Megali Ammos
370 02, Skiathos
GR

The User may contact our Data Protection Officer:

Data Protection Officer
konstantina@kassandrabay.com

Data Processor

WebHotelier operates this booking system on behalf of KASSANDRA BAY SA and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of KASSANDRA BAY SA, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at KASSANDRA BAY SA;
  • to pass on your financial details to KASSANDRA BAY SA and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Privacy Policy

Privacy Policy and Information Notice on Processing of Personal Data Our Privacy Policy was last updated and posted on May 2018. It governs the privacy terms of our Website, sub-domains, and any associated web-based and mobile applications (collectively, “Website”). We wish to hereby inform you that we comply with the protection framework for natural persons with regard to the processing of personal data, as established by the new Regulation (EU) 2016/679 of the European Parliament. We respect the privacy of every individual who visits our Properties and/or uses of our website, subdomain, mobile apps. This Privacy Policy explains how we may collect and use information that you provide us, and your rights in relation to that information. Please read this policy carefully. Your use of our online services or your provision of information to us constitutes your acknowledgment of the terms of this Privacy Policy. Please do not send us any of your information if you do not want it to be used in the ways described in this Privacy Policy.  
                                             
1. Information we collect

a) Voluntary information

We will collect and process information about you if you voluntarily provide us with such information in connection with the following:  
 
• filling in a form on our website;    
• filling in a physical registration card;    
• contacting us by telephone or face to face;    
• sending us a letter, e-mail or social media message;    
• subscribing to receive a service from us (e.g., a newsletter, blog or by following us on social media);    
• requesting promotional information from us (e.g., information about any of our good or services including gift cards);    
• participating in a survey, competition or prize draw; or    
• contributing content to us

The types of information we may obtain include:    
• your name, gender, home and work contact details, business title, e-mail address, telephone number, date and place of birth, nationality;    
• details of food allergies/dietary requirements and special requests made (for example, relating to a disability) you provide to us;    
• passport and visa information, payment information, travel history and details of joint travellers;    
• dates of your stay and associated charges;    
• purchase or delivery of products or services;    
• reviews and opinions about our brand, products and services;    
• or information we receive about you from any third parties through whom you have booked your arrangements;

We do not collect “sensitive information” (e.g., information on racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership) unless it is volunteered by you.
We may use medical or other sensitive data provided by you to better serve and meet your needs (but under no circumstances will we process any sensitive data for marketing and/or profiling purposes). Such sensitive information is only shared with our third party service providers (acting as data processors) for the purpose of providing the services you request. By making such special requests or notifying us of such preferences, you agree to us sharing your information in this way.

b) Automated information.

When you visit our website, we may also collect certain information through the use of “cookies” and other automated means. Cookies are small pieces of information that are stored by your browser on your computer's hard drive. Such information may comprise the following information:    


• Date and time;    
• Originating IP address;    
• Domain name;    
• Type of browser and operating system used (if provided by the browser);    
• URL of the referring page (if provided by the browser);    
• Object requested;    
• Completion status of the request;    
• Geographic location; or    
• Language preferences.  

2. Use of information
Typically, we will use and process your information to:  
 
• help us create content that is relevant to our visitors;    
• make improvements to our websites and social media pages and ensure that content on these is presented in the most effective manner for you;    
• provide you with information, products or services that you request from us or which we feel may interest you;    
• assess and help us understand general trends and patterns relating to our business;    
• provide for the safety and security of our guests and visitors;    
• manage general record keeping;    
• enable us to compile anonymous, aggregated statistics that allow us to understand how users use our websites and to help us improve the structure of our websites;    
• enable you to make reservations, buy gift cards and make payments;    
• meet any legal and/or regulatory requirements;    
• provide the products or services you request from us; and    
• improve our products and services and to ensure our products and services are of interest to you.

We may process your personal information by both automated and manual means. We may use your information in other ways for which we provide specific notice at the time of collection.  

3. Sharing information
We do not sell, otherwise disclose, or share information we collect and hold about you, except as described in this Privacy Policy. We may share information with service providers who perform functions and services on our behalf. Such third parties will be appointed as data processors and will be provided only with information necessary to perform the services on our behalf but are not authorised to use such information for any other purposes. We may disclose information about you if we are required to do so by law or pursuant to legal process, or in response to a request from law enforcement authorities or other government officials. We reserve the right to transfer information about you in the event that we sell or transfer all or a portion of our business or assets, in accordance with applicable law. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use information you have provided to us in a manner that is consistent with our Privacy Policy. Following such a sale or transfer, you may contact the entity to which we transferred your information with any inquiries concerning the processing of that information.  

4. Your rights
You have certain rights to the information we process about you as expressly provided for by applicable law. You may request access to a copy of the information we hold about you, update, withdraw, amend or correct the information, and in some circumstances you may object to our use of your information. You also have the right to request that we cease sending marketing communications, whether by email or otherwise, to you. To exercise these rights or to make a complaint or submit an inquiry about our privacy practices, please contact us. You will find our contact details at the end of this policy. To help protect your privacy and maintain security, we may take steps to verify your identity before do any act. Please note that if you opt out as described above, we will not be able to remove your information from the databases of third parties with whom we have already shared your information, with your consent. You should contact such third parties to opt out directly.

5. Data transfers
We may transfer to and store the information we collect about you in countries other than the country in which the information was originally collected, including the United States, Canada or other destinations outside the European Economic Area (“EEA”). Those countries may not have the same data protection laws as the country in which you provided the information. When we transfer your information to other countries, we will protect the information as described in this Privacy Policy and comply with applicable legal requirements providing adequate protection for the transfer of information to countries outside the EEA. By submitting your information to us, you agree to this transfer, storing and processing.

6. Security
We take information and system security very seriously and we strive to comply with our obligations at all times. However no web or email transmission is ever totally protected or mistake free. For example, email sent out to or from the Website may not be protected. You must take unique care in deciding what info you send to us by means of email. For your own protection, we encourage you not to include sensitive personal information, credit card or similar data in any e-mails you send us or our staff.

7.  Data Retention
We only retain your information for as long as needed to fulfil the purposes for which it is collected, unless otherwise provided by law. The length of time we keep your information will vary depending on the obligations we need to meet.  

8. Links to other websites
Our websites may provide links to or include links from other websites for your convenience and information. These websites operate independently from us. You access such linked Websites at your own risk. These websites are not subject to this Privacy Policy. Linked websites may have their own privacy policies, which we strongly suggest you review. To the extent that any linked websites you visit are not owned or controlled by us, we are not responsible for the websites’ content, any use of the websites, or the privacy practices of the websites.

9. Cookies
Access to this website involves the use of cookies, even though it would work without them. We use cookies and similar tracking technologies, such as pixels and web beacons to gather information about the visitors to our websites (as they enable us to improve our websites and deliver a better and more personalised service). Please note that we do not collect any personal information using cookies nor do we install any application on your device by the use of cookies. The only way in which a user’s personal details can be included in a cookie file is if the user personally supplies this information to the server. When you access our websites you will receive a clear notice advising you that the website you are visiting intends to use cookies and that: i. by continuing to use the website you consent to their use; or ii. you must click an “I accept” box in order for cookies to be placed.
Unless you have adjusted your browser setting so that it will refuse cookies from our websites, our system will issue cookies. Most browsers will tell you how to stop accepting new cookies, how to be notified when you receive a new cookie, and how to disable existing cookies. You can find out how to do this for your particular browser by clicking "help" on your browser's menu or by visiting www.allaboutcookies.org, www.youronlinechoices.eu. Please note, however, that without cookies you may not be able to take full advantage of all our websites features.  

What is a cookie?
A cookie is a small piece of data that a website asks your browser to store on your computer or mobile device. The cookie allows the website to "remember" your actions or preferences over time and generally improve the user experience. It can also help to ensure that adverts you see online are more relevant to you and your interests.

Cookies may be used on this website
A list of all the cookies may be used on the Website by category is set out below.

- Session Cookies:  Session cookies last only for the duration of your visit and are deleted when you close your browser. These facilitate various tasks such as allowing a website to identify that a user of a particular device is navigating from page to page, supporting website security or basic functionality.
- Persistent Cookies: Persistent cookies last after you have closed your browser, and allow a website to remember your actions and preferences. Sometimes persistent cookies are used by websites to provide targeted advertising based upon the browsing history of the device. We use persistent cookies to allow us to analyse customer visits to our site. These cookies help us to understand how customers arrive at and use our site so we can improve the overall service.
- Essential Cookies: Cookies essential in order to enable you to move around the website and use its features, and ensuring the security of your experience. Without these cookies services you have asked for, such as applying for products and/or managing your accounts, cannot be provided. These cookies don’t gather information about you for the purposes of marketing.
- Performance cookies: These cookies collect information about how visitors use a web site, for instance which pages visitors go to most often, and if they get error messages from web pages. All information these cookies collect is only used to improve how a website works, the user experience and to optimise our advertising.
- Functionality cookies: These cookies allow the website to remember choices you make (such as your username). The information these cookies collect is anonymized (i.e. it does not contain your name, address etc.) and they do not track your browsing activity across other websites.
- Targeting Cookies: These cookies collect several pieces of information about your browsing habits. They are usually placed by third party advertising networks. They remember that you have visited a website and this information is shared with other organisations such as media publishers. These organisations do this in order to provide you with targeted adverts more relevant to you and your interests.
- Third Party Cookies: Please note that third parties (including, for example, advertising networks, social media networks, and providers of external services like web traffic analysis services) may also use cookies, over which we have no control. These cookies are likely to be analytical/performance cookies or targeting cookies. We recommend that you check the relevant third party's privacy policies for information about any cookies which may be used.

Using browser settings to manage cookies.
The Help menu on the menu bar of most browsers will tell you how to prevent your browser from accepting new cookies, how to delete cookies, how to have the browser notify you when you receive a new cookie and how to disable cookies altogether. You can also disable or delete similar data used by browser add-ons, such as Flash cookies, by changing the add-on's settings or visiting the website of its manufacturer. However, because cookies allow you to take advantage of some of the Website's essential features, we recommend you leave them turned on.

10.  Privacy Policy Updates
We reserve the right to modify this Privacy Policy at any time. You should review this Privacy Policy frequently. If we make material changes to this policy, we may notify you on our Website, by a blog post, by email, or by any method we determine. The method we chose is at our sole discretion. We will also change the “Last Updated” date at the beginning of this Privacy Policy. Any changes we make to our Privacy Policy are effective as of this Last Updated date and replace any prior Privacy Policies.  

11. How to contact us
If you have any questions or comments about this Privacy Policy, the use of cookies, if you would like us to update information we have about you or your preferences, or to exercise your rights of access, rectification, blocking, or deletion, please contact us by email at dpo@kassandrabay.com