Legal information
Privacy policy
This policy explains how the business operating Ktima Tsaknaki processes the personal data of website visitors, people who contact us and accommodation guests. It covers the website https://ktima-tsaknaki.gr/ and the communication and service connected with our accommodation services.
1. Controller
The controller for the activities described in this policy is the business operating the accommodation trading as “Ktima Tsaknaki”. Contact address: Ilioupoleos – Agia Zoni, Palioura Epanomi, Thessaloniki, 57500, Greece. Email: ktimatsaknaki@gmail.com. Phone: +30 2392044362.
For data protection matters and to exercise your rights you can contact us at ktimatsaknaki@gmail.com or +30 2392044362, stating your request and the details necessary to handle it.
2. Data and sources
For communication and bookings we process your name, email, phone number, requested dates, number of guests, stay details and the content of related messages. Information about children’s ages is requested only where needed for capacity, pricing or a legal obligation.
For confirmation, payment and invoicing, identification or tax details may be required to the extent imposed by law, together with the amount, date, method and transaction reference. We do not ask for photographs or copies of identity cards, passports or bank cards for ordinary check-in and payment procedures. Please do not send such copies or card security codes by email.
When you access the website, the server and security tools may log the IP address, date and time, the requested page, technical browser details and error or security events. Technologies stored on your device are described separately in the Cookie Policy.
Data comes mainly from you. If the booking is made by another person on your behalf or through a partner platform, we receive the necessary details from the booking organiser or that platform. You may ask for the exact source of your data. Where required, information is provided within the deadlines of Article 14 GDPR.
Please do not include sensitive data in general messages. If you request a specific service that requires health data, separate information is provided beforehand along with the legal condition of Article 9 GDPR, such as explicit consent where appropriate. General acceptance of this policy is not sufficient.
3. Purposes and legal bases
| Purpose | Legal basis and necessity |
|---|---|
| Availability request and offer | Pre-contractual steps at your request, Article 6(1)(b) GDPR. |
| Booking and accommodation service | Performance of a contract, Article 6(1)(b), including operational communication about the booking. |
| Invoices and statutory records | Legal obligation, Article 6(1)(c), only for the data required by applicable law. |
| General communication and complaints | Legitimate interest in effective service, Article 6(1)(f), or performance of the contract where the request concerns a booking. |
| Security and legal claims | Legitimate interest in protecting systems, preventing abuse and establishing or defending legal claims, Article 6(1)(f), balanced against your rights. |
| Optional third-party technologies | Consent, where required, Articles 6(1)(a) and 7 GDPR and Article 4(5) of Greek Law 3471/2006. The choice is made through the cookie settings. |
Providing data that is necessary to conclude or perform the booking, or that is required by law, is a condition for providing that service. Without it we may be unable to reply or complete the booking. Optional items are marked separately and refusing them does not prevent the basic service.
Contacting us does not sign you up to a marketing list. Any future newsletter service would come with separate information and the required opt-in and unsubscribe mechanism.
4. Recipients
Only authorised people who need the data to serve you have access. The categories of partners that may have access, to the extent their service requires, are website hosting, technical support and communication infrastructure providers. Google’s Gmail service is used for email communication.
Data is disclosed, to the extent necessary, to accounting services, banks or payment providers when you use the relevant method, and to competent authorities where there is a legal obligation. Any booking platform also processes data according to its own role and notice.
Where a partner acts on our behalf, processing terms are set in accordance with Article 28 GDPR. Other recipients, such as certain payment providers or platforms, may act as independent controllers. You may request information about the specific recipients of your data using our contact details.
5. Transfers outside the European Economic Area
The use of international technology providers, such as Google’s Gmail and, when enabled, Google Maps, may involve processing of or access to data from countries outside the European Economic Area, including the United States. Google publishes information about the relevant mechanisms in its data transfer frameworks and its privacy policy, referring to Google LLC’s participation in the EU-US Data Privacy Framework and the use of contractual safeguards where applicable.
Every transfer requires an applicable mechanism under Chapter V GDPR, such as a valid adequacy decision covering the specific recipient or appropriate safeguards, potentially standard contractual clauses and supplementary measures. You may request information and a copy of the relevant safeguards at our email address.
6. Retention periods
| Category | Duration or deletion criterion |
|---|---|
| Requests that do not lead to a booking | For as long as needed to answer and close the request, based on its subject and the last substantive communication. Further retention only where there is a specific legal need. |
| Bookings and related correspondence | Until the stay is completed and related obligations are settled. Afterwards only data required by law or for specific claims is kept, until the applicable limitation period ends or a pending dispute is finally resolved. |
| Invoices and mandatory records | For the period imposed by applicable tax and accounting law, including any statutory extension. In an audit or pending dispute only what remains necessary is kept. |
| Technical security logs | For the period needed to detect and investigate errors or security incidents, based on the purpose of each log and the severity of the event. Retention is reviewed and is not unlimited. |
| Cookie choices and consent records | Storage on the device follows the durations of the active cookie list. Any separate record is kept as long as needed to evidence the specific consent and meet a related legal obligation or claim. |
After the necessary period the data is deleted or anonymised. Backups are kept with restricted access, are retired in their renewal cycle and are not used for other purposes. The existence of backups does not justify unlimited retention.
7. Your rights
Under the conditions of the GDPR you may request access, rectification, erasure, restriction of processing and data portability. You may object to processing based on legitimate interest on grounds relating to your particular situation. For direct marketing your objection is respected without any need to justify it.
Where consent is used, you may withdraw it at any time without affecting the lawfulness of prior processing. Erasure does not override a legal obligation to retain specific data.
Submit your request to ktimatsaknaki@gmail.com. We reply without undue delay and, as a rule, within one month. If an extension of up to two further months is permitted due to complexity or the number of requests, you are informed within the first month of the extension and its reasons.
Where there is reasonable doubt about the identity of the requester, only the additional details necessary to confirm it are requested. A copy of an identity document is not systematically required for every request.
You have the right to lodge a complaint with the Hellenic Data Protection Authority at www.dpa.gr, or with the competent supervisory authority under the GDPR.
8. Security
We apply appropriate organisational and technical measures proportionate to the risks of the processing, with controlled access and confidentiality obligations for authorised people. No system guarantees absolute security.
9. Policy updates
The policy is updated when purposes, services or the applicable framework change. The date of the new version is shown at the top. Where new information or consent is required, it is provided before the relevant processing.