This policy explains what personal data we collect through aesistinos.com, why, and what your rights are under the EU General Data Protection Regulation (GDPR). We collect as little as we can.
Who is responsible
AĒSIS is a holiday rental in Krokos, Tinos, Greece, run by Antonis, who is the data controller. TODO (host): full name or business name, postal address, and tax number if the rental is run as a business.
You can reach us by phone on +30 694 425 9160, or by sending a message through the reservation form.
What we collect
When you send a reservation request: your name, email address, phone number (optional), number of guests, the dates you choose and your message.
When you visit the site: our hosting provider records technical data such as your IP address, browser type and the pages requested, to keep the site running and secure. The spam check on the reservation form (Cloudflare Turnstile) looks at similar technical data to tell people from bots.
We do not use advertising or analytics cookies, we do not track you across other sites, and we never sell your data. Fonts are served from our own site, not from third parties.
Why we use it, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Answering your request and arranging your stay | Steps before entering a contract, and the contract itself (Art. 6(1)(b)) |
| Sending you a confirmation that we received your request | Same as above (Art. 6(1)(b)) |
| Keeping records required by Greek tax law for confirmed stays | Legal obligation (Art. 6(1)(c)) |
| Protecting the site and the form from spam and abuse | Legitimate interest (Art. 6(1)(f)) |
Who receives it
Only the host and the service providers that run the site on our behalf, under data processing agreements:
- Cloudflare, Inc.: website hosting, the database that stores reservation requests, and Turnstile spam protection
- Resend: sending the emails about your request
Some of these providers may process data outside the European Economic Area. When they do, the transfer is covered by an adequacy decision of the European Commission or by the Commission’s Standard Contractual Clauses.
We do not share your details with Booking.com, Airbnb or other platforms. To prevent double bookings, they only receive the dates that are taken, with no personal details.
How long we keep it
- Requests that do not lead to a stay: deleted after TODO: 12 months?
- Confirmed stays: kept for as long as Greek tax and accounting law requires TODO: confirm the period with your accountant, then deleted.
- Server logs: kept by the hosting provider for a short period for security.
Your rights
You can ask us to:
- give you a copy of your data (access)
- correct it (rectification)
- delete it (erasure)
- limit how we use it (restriction)
- give it to you in a portable format (portability)
- stop using it where we rely on legitimate interest (objection)
To use any of these rights, contact us as described above. We will answer within one month.
If you think we have mishandled your data, you can complain to the Hellenic Data Protection Authority (www.dpa.gr) or to the data protection authority in your own EU country.
Changes
If we change this policy, we will update it on this page and change the date above.