Privacy Policy

Strovilla Gaia Luxury Private Beachfront Villas — strovilla-gaia.gr
Website: https://strovilla-gaia.gr
Data Controller: Strovilla Gaia Luxury Private Beachfront Villas
Location / Address: Psakoudia, Halkidiki, PC 63071, Greece
Contact Email: info@strovilla-gaia.gr
Effective Date: August 2026

1. Introduction & General Information

At Strovilla Gaia Luxury Private Beachfront Villas ("we", "us", "our"), operating through the website https://strovilla-gaia.gr, we are committed to respecting and protecting the personal data and privacy of our guests, website visitors, and customers.

This Privacy Policy explains how we collect, process, store, and safeguard your personal information in full compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation - GDPR), Greek Law 4624/2019, and the applicable national and European legal framework regarding data protection and electronic communications.

2. Data Controller Information

The Data Controller responsible for the processing of your personal data on this website is:

Strovilla Gaia Luxury Private Beachfront Villas
Address: Psakoudia, Halkidiki, PC 63071, Greece
Website: https://strovilla-gaia.gr
Email: info@strovilla-gaia.gr
Property Registration No (MHTE / AMA): 0938K13000499200

3. Categories of Personal Data We Collect

We process personal data necessary for providing hospitality services, processing online room bookings, handling inquiries, and completing transactions:

  • Identification & Contact Data: Full name, passport or national ID number, email address, telephone/mobile number, country of residence, and postal address.
  • Booking Details: Dates of check-in/check-out, number of guests, special preferences or requests, cancellation history, and communication history.
  • Financial & Payment Data: Transaction ID, billing address, payment confirmation status, and payment method details.
  • Technical & Electronic Browsing Data: IP address, device type, browser type, operating system, referring URL, pages visited, date and time of visit, and technical cookies.

4. Secure Online Card Payments (National Bank of Greece / NBG Pay)

PCI-DSS & Payment Gateway Security Compliance

All electronic credit and debit card payments conducted through strovilla-gaia.gr are processed through the secure electronic payment platform "NBG Pay / i-Bank E-Commerce" provided by the National Bank of Greece (NBG).

When you choose to pay via credit or debit card, you are automatically redirected to the secure, encrypted payment page of National Bank of Greece. All payment data (including card number, CVV/CVC, expiration date, and cardholder name) are encrypted using 128-bit / 256-bit SSL/TLS protocol and transmitted directly to NBG's banking infrastructure.

Important Notice: Strovilla Gaia does NOT collect, store, view, or process full credit/debit card numbers or security codes on its servers. Cardholder authentication is enforced through 3D-Secure protocols (Verified by Visa, Mastercard Identity Check) ensured entirely by the bank.

5. Purpose and Legal Basis for Processing

Purpose of Processing Categories of Personal Data Legal Basis (GDPR Art. 6)
Reservation management, guest accommodation, and service delivery Name, contact info, booking dates, special requests Performance of Contract — Art. 6(1)(b)
Payment processing, billing, tax invoicing, and accounting compliance Name, billing address, transaction record, VAT number (if applicable) Legal Obligation — Art. 6(1)(c) & Contract — Art. 6(1)(b)
Responding to guest inquiries and customer support communications Name, email, phone, message details Legitimate Interest — Art. 6(1)(f) / Consent — Art. 6(1)(a)
Website operational security, fraud prevention, and system maintenance IP address, access logs, technical device parameters Legitimate Interest — Art. 6(1)(f)

6. Recipients & Transfer of Personal Data

Your personal data is handled strictly on a need-to-know basis and is not sold, rented, or commercialized. Access to your data is strictly granted to:

  • Authorized Internal Personnel: Management and guest support staff obligated by strict confidentiality agreements.
  • Payment Processors & Financial Institutions: National Bank of Greece (NBG) for secure processing and settlement of card transactions.
  • Technical Service Providers: Website hosting providers, IT support, and reservation engine software suppliers acting as Data Processors bound by GDPR Article 28 data processing agreements.
  • Public & Regulatory Authorities: Tax authorities, police, or judicial bodies when strictly mandated by applicable Greek or EU legislation.

7. Data Retention Period

Personal data is retained only for as long as necessary to fulfill the purposes for which it was collected:

  • Booking and Stay Information: Retained for 5 years after the end of your stay or transaction for customer service and dispute handling.
  • Financial & Tax Data: Retained for a minimum of 10 years (or as specified by Greek tax legislation) following statutory invoice retention laws.
  • Contact Inquiries: Retained for up to 12 months after the resolution of the request unless converted into a reservation record.

8. Your Rights Under the GDPR

Under Chapter III of the GDPR, you have the following rights regarding your personal data:

  • Right of Access (Art. 15): Right to request details and a copy of the personal data we hold about you.
  • Right to Rectification (Art. 16): Right to request correction of inaccurate or incomplete personal data.
  • Right to Erasure / "Right to be Forgotten" (Art. 17): Right to request deletion of your personal data when no longer legally required.
  • Right to Restriction of Processing (Art. 18): Right to request limitation of data processing under certain conditions.
  • Right to Data Portability (Art. 20): Right to receive your personal data in a structured, commonly used, machine-readable format.
  • Right to Object (Art. 21): Right to object to processing based on legitimate interest or direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

To exercise any of your rights, please email us at info@strovilla-gaia.gr. We will respond within 30 days. You also have the right to lodge a complaint with the supervisory authority:

Hellenic Data Protection Authority (HDPA)
1-3 Kifissias Ave., 115 23 Athens, Greece | Web: www.dpa.gr | Email: contact@dpa.gr

9. Cookies & Tracking Technologies

Our website strovilla-gaia.gr uses technical and essential cookies required for the proper functioning and security of the site and reservation workflow. Non-essential cookies (such as analytical or marketing cookies) are loaded only with your prior explicit consent via our Cookie Banner. You can manage or modify your cookie preferences through your web browser settings at any time.

10. Technical and Organizational Security Measures

We implement appropriate technical and organizational measures (TOMs) to safeguard personal data against unauthorized access, loss, misuse, alteration, or destruction. These measures include SSL/TLS encryption for all website communications, firewall protection, secure access controls, regular data backups, and PCI-DSS compliance integrated through National Bank of Greece payment processing.

11. Updates to this Privacy Policy

We reserve the right to update or amend this Privacy Policy periodically to reflect changes in legal, operational, or technical requirements. The "Effective Date" at the top of this document indicates when the latest revision took effect.