This Privacy Policy explains how Thermyès (Website: thermyes.com) ("we," "us," or "our") collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable Greek and European Union data protection laws. By using our website, booking accommodation, or using our services (collectively, the "Services"), you acknowledge and agree to the terms of this Privacy Policy.
Personal Data We Collect
We may collect and process the following categories of personal data:
• Identification data (such as full name)
• Contact data (such as email address, phone number, and postal address)
• Booking and accommodation details (such as dates of stay, preferences, and special requests)
• Payment and billing data (such as transaction references and invoices; we do not store full card details)
• Technical data (such as IP address, browser type, device information, and usage logs)
• Communication data (such as emails, messages, and inquiries)
Legal Basis for Processing
We process your personal data only when we have a lawful basis to do so, including:
• Performance of a contract (to manage your bookings and provide accommodation services)
• Legal obligation (to comply with tax, accounting, and regulatory requirements)
• Legitimate interests (to improve our Services, ensure security, and prevent fraud)
• Consent (for marketing communications or non-essential cookies, where applicable)
How We Use Your Personal Data
We use your personal data to:
• Manage reservations and provide accommodation services
• Process payments and issue invoices
• Communicate with you regarding your booking or inquiries
• Comply with legal and regulatory obligations
• Improve and secure our website and Services
• Send marketing communications, where you have provided your consent
Cookies and Similar Technologies
Our website uses cookies and similar technologies to ensure proper functionality, analyze website traffic, and improve user experience. Where required by law, we request your consent before placing non-essential cookies. You can manage or withdraw your cookie preferences at any time through your browser settings.
Data Sharing and Recipients
We may share your personal data with:
• Payment service providers and booking platforms
• IT and website hosting providers
• Professional advisors (such as accountants or legal advisors), where necessary
• Public authorities, where required by law
All third parties are required to process your personal data in accordance with GDPR and applicable data protection laws.
International Data Transfers
We do not transfer your personal data outside the European Economic Area (EEA). If such transfers become necessary, we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy and to comply with legal, tax, and regulatory obligations. Booking and billing records may be retained for the period required by Greek law.
Your Rights Under GDPR
You have the following rights regarding your personal data:
• Right of access
• Right to rectification
• Right to erasure ("right to be forgotten")
• Right to restriction of processing
• Right to data portability
• Right to object to processing
• Right to withdraw consent at any time, where processing is based on consent
To exercise your rights, please contact us using the details provided above. We will respond within the time limits required by law.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU member state of your habitual residence, place of work, or place of the alleged infringement. In Greece, this is the Hellenic Data Protection Authority (www.dpa.gr).
Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. However, no system is completely secure, and we cannot guarantee absolute security.
Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to review their privacy policies.
Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. Any changes will be posted on our website and will become effective upon publication.