A. Data information we collect and for what reasons :
Full name, gender, full address, phone number, email address, payment details (bank account number, IBAN, card details etc), business title, document to prove personal ID for security reasons (ID, passport and visa information, driving license) nationality, tax details, dates of your stay and purchase or delivery products or services. We do not collect “sensitive information”, unless it is volunteered by you.
We also may collect:
• Data about family members and companions, who stay with you,
• Images and videos and audio data via: security cameras,
• Wi-fi data,
• Automated information: When you visit our website, we may also collect certain information through the use of “cookies” and other automated means. Cookies are small pieces of information that are stored by your browser on your computer's hard drive. Such information may comprise the following information:
• date and time,
• originating IP address,
• domain name,
• type of browser and operating system used (if provided by the browser),
• URL of the referring page (if provided by the browser),
• object requested,
• completion status of the request,
• geographic location, or
• language preferences.
How we collect these information:
• filing in a form on our website,
• filling in a physical registration form,
• contacting us by telephone or face to face,
• sending us a letter, e-mail or social media message,
• subscribing to receive a service from us (e.g. a newsletter or by following us on social media),
• requesting promotional information from us (e.g. information about any of our services),
• participating in a survey or competition.
We collect personal data either directly from you, when you visit our hotel or through online services (the website we operate www.laroka.gr , and our social media pages – facebook etc.).
La Roka adopts and implements the following principles:
• Purpose specification and purpose limitation: the purposes for which we collect and use personal data shall be specified and legitimate. The data shall not be used for anything other than the specified purposes,
• Transparency: clear information shall be provided to individuals about the purposes for which personal data are collected and used, at the time the data is collected,
• Data minimization: we shall only collect personal data that is strictly necessary for the specific purposes i.e. the minimum personal data required shall be collected and used,
• Accuracy: personal data shall be accurate and where necessary kept up to date,
• Retention: personal data shall not be kept for longer than is necessary,
• Security: appropriate measures to protect personal data shall be implemented maintained,
• Accountability: our hotel will be able to demonstrate that it has implemented measures to comply with the above mentioned principles.
Legal grounds for processing your personal data:
• The provision of the services you appoint us for and you want to receive from us,
• Complying with a statutory obligation, such us returning prepayment, managing your claims etc,
• Safeguarding and protecting the legitimate interests of yours as well as ours. So we are entitled to use closed circuit television system (CCTV) and security cameras to be able to protect the security of individuals, materials and facilities,
• The consent you provide us with under the specific conditions set out in the legal framework in order to receive updates on services and offers.
B. Share information - Transfer to third - party associates:
We may share information with service providers who perform functions and services on our behalf. Such third parties will be appointed as data processors and will be provided only with information necessary to perform the services on our behalf but are not authorized to use such information for any other purposes. We may disclose information about you if we are required to do so by law or pursuant to legal process, or in response to a request from law enforcement authorities or other government officials.
Our Hotel shares your personal data with the following categories of recipients :
• Governmental authorities, law enforcement agencies etc
• Associates of our Hotel.
We declare that we do not sell information we collect and hold about you.
C. Data Controller:
NOULIS IKE., trading under the name La Roka registered with the VAT NUMBER 801497335 having its registered office in Santorini (Fira 84700), email: firstname.lastname@example.org , tel: +30 6933330028, website: www.laroka.gr , informs that, for the purposes of its business, it processes personal data of its customers in accordance with applicable national law and the European Regulation 2016/679 on the protection of individuals with regard to the processing of personal data.
We take all necessary technical and organizational measures to ensure the secure processing of your personal data and to prevent any accidental loss or destruction and any unauthorized and/or illegal access, use, alteration or disclosure of your data. Any personal data in hard copy format will be kept in a locked filing cabinet, drawer or safe, with restricted access in our premises, and only the Data Controller and authorized members of our staff, have access to the data. These premises are protected by CCTV camera systems. Confidential paper records will not be left unattended or in clear view anywhere with general access. All electronic devices are password-protected to protect the information on the device in case of theft. Digital data is coded, encrypted or password-protected, on a network drive that is regularly backed up on and off-site. All members of our staff are provided with their own secure login and password, and every computer regularly prompts users to change their password. Emails containing sensitive or confidential information are password-protected if there are unsecure servers between the sender and the recipient. The security of our computer and storage systems, and access to them, is continuously monitored.
However, given the way that Internet works and the fact that is freely accessible to anyone, we are unable to guarantee that no unauthorized third parties will ever be able to circumvent such measures and gain access, or even make use of your personal information for unauthorized and/or unlawful purposes. Furthermore, we bear no responsibility for payments that take place in other bank accounts, as a result of hacking. For your safety, we recommend you before paying, contact us to verify the correct bank accounts.
E. DATA RETENTION
We will only keep your personal data for as long as we need to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. The length of time we keep your information will vary depending on the obligations of European and national legal framework.
To decide how long we should keep your personal data for, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or sharing of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
By law we have to keep basic information about our customers (including contact, identity, payment details and transaction data) after they cease being customers for tax purposes.
F. CCTV Data
Our Hotel uses closed circuit television system (CCTV) and security cameras to be able to protect the security of individuals, materials and facilities. The processing is necessary for our legitimate interests. Security cameras are covering the entrance of the hotel, the reception, the surroundings, the parking area, cash registers, machinery areas and high risk areas. Special markings indicate the spaces are monitored by CCTV system. The information collected only for security purposes and safety reasons.
Our legitimate interests aim to: increase the personal safety of our staff and visitors, assist in identifying, apprehending and prosecuting any offenders, protect the Hotel’s buildings and assets and those of its staff from intrusion, theft, vandalism, damage or disruption, establish, exercise or defend against legal claims.
We ensure you that CCTV data can only be viewed by Data Controller and authorized members of our staff. The digital files are protected by passwords. All recorded CCTV footage will be kept for a maximum of fifteen (15) days (recording cycle).
G. Your rights:
Access, update, withdraw, amend or correct : You may have the right to access and receive a copy of the personal information we hold about you, update, withdraw, amend or correct the information.
Change, restrict and delete : You may have the right to change, restrict or delete your personal data stored by us.
Data portability : You may have the right to receive your personal data free of charge in a format that allows you to access, use and edit them. You also have the right to ask us, if technically feasible, to pass the data directly to another processor.
Object and complaint: You may have the right to object to the use of data by us, in case we use the information for illegal or unauthorized purposes.
To exercise these rights or to make a complaint about our privacy practices, please contact us, by using the contact information stated below. Finally, if you are resident in EU, or a citizen of EU, and wish to raise a concern about our use of your information you have the right to do so with your local data protection authority.
H. CONTACT US FOR GDPR ISSUES
For the purposes of EU and national law, if you have any questions, requests or concerns you may contact us, via email at email@example.com , via phone at +30 6933330027, via mail address Fira Santorini 84 700, Greece.
WHAT IS A COOKIE?
The term «cookie» refers to a small data file consisting solely of a set of text information that the site transmits to the web browser on your computer’s hard disk, either temporarily throughout your visit , or sometimes for longer periods, depending on the type of cookie. Cookies perform different operations (for example, you are distinguished from other site’s visitors or remember certain info for you like your preferences) and are used by most websites to improve your user experience. Each cookie is unique to your browser and contains some anonymous information. A cookie typically contains the name of the cookie field, the cookie’s lifetime, and a value (usually in the form of a randomly generated unique number).
TYPES OF COOKIES
The basic types of cookies are described below
These are temporary cookies that remain in the cookie file of your device’s browser only during your visit and are deleted when you close the browser.
These remain in the cookie file of your device’s browser even after the browser closes, sometimes for one year or more (the exact length of stay depends on the lifetime of each cookie). Permanent cookies are used when the site administrator may need to know who you are for more than one visit (e.g., to remember your username or your site configuration preferences).
These are cookies installed on your browser and/or hard drive of your device from the site you are visiting. This includes assigning a unique ID to you, in order to monitor your site navigation. Site creators often use first-party cookies to handle visits and for identification purposes.
These are cookies used by third parties, such as social networks to track your visits to the various sites they advertise. The site administrator has no control over these third-party cookies.
COOKIES ON THIS SITE AND HOW TO MANAGE THEM
GOOGLE ANALYTICS COOKIES
VIDEO PROVIDERS COOKIES
Video providers can place cookies on your device if you watch their video on our site. If you disable these cookies you may not be able to see the embedded videos on our site.
SOCIAL NETWORK COOKIES
Third-party social networks can place cookies on your device if you choose to share a web page of our site with another third-party Social Network site, by clicking on one of the «share» buttons. If you disable these cookies, you will not be able to share any of our content with third-party social networks