We respect your privacy. This Privacy Policy explains what personal data we collect, why we collect it, how it is used, and what rights you have. It applies to all guests, website visitors, and anyone who contacts us directly.
Depending on how you interact with us, we may collect the following categories of personal data:
- Full name, date of birth, nationality
- Passport or national identity card number (required by Greek law for all guests)
- Email address, telephone number
- Postal address (where provided)
- Booking dates, accommodation type, number of guests
- Payment method and transaction records (we do not store full card details)
We process your personal data on the following legal bases:
Your data is necessary to process and fulfil your reservation, manage your stay, coordinate check-in and check-out, and handle any related requests or issues.
Greek law requires us to collect and retain identity document data (passport/ID) for all guests and to report this to the relevant authorities. We are also required to retain financial records for tax and accounting purposes.
We process data to respond to enquiries, improve our services, maintain the security of our property, and for general business administration.
Where you have given us your consent — for example, to receive marketing communications — we process your data for that specific purpose. You may withdraw consent at any time (see Section 4).
We do not sell your personal data. We may share it with the following categories of recipients where necessary:
Booking platforms: Booking.com, Expedia, and any other platform through which your reservation was made. These platforms operate under their own privacy policies.
Payment processors: Banks and card payment providers involved in processing your transaction.
Greek authorities: As required by law (e.g. police registration, tax authorities, AADE).
Service providers: Third-party companies that assist us in operating our business (e.g. email, accounting software), bound by data processing agreements.
Email marketing provider: If you have consented to receiving our newsletter, your email address may be processed by our email marketing platform.
We do not transfer your personal data outside the European Economic Area (EEA) except where legally permitted and with appropriate safeguards in place.
Under the GDPR, you have the following rights regarding your personal data:
Access - Request a copy of the personal data we hold about you.
Rectification - Ask us to correct inaccurate or incomplete data.
Erasure - Request deletion of your data where there is no lawful reason to retain it.
Restriction - Ask us to limit how we use your data in certain circumstances.
Data Portability - Receive your data in a structured, machine-readable format.
To exercise any of these rights, contact us at eloundaeleonvillas@gmail.com. We will respond within one month of receiving your request, as required by the GDPR.
Our website may use cookies — small text files stored on your device — to help us understand how visitors use our site and to improve your experience.
You may control cookie preferences through your browser settings. Please be aware that disabling certain cookies may affect the functionality of our website.
We take reasonable technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. Our website is protected by SSL (Secure Socket Layer) encryption. However, no method of data transmission over the internet is entirely secure, and we cannot guarantee absolute security.
If you believe that your personal data has not been handled in accordance with applicable law, you have the right to lodge a complaint with the Greek data protection supervisory authority
We would, however, appreciate the opportunity to address your concerns before you contact the HDPA. Please reach out to us first at eloundaeleonvillas@gmail.com.
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated version will be posted on our website with a revised effective date. We encourage you to review this page periodically.