Privacy Notice

Last Updated: May 24th, 2018

At EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://whitepearlvillas.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA.

Data Controller

EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

White Pearl Villas Oia “EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA”
Oia
847 02, Santorini
GR

Data Processor

WebHotelier operates this booking system on behalf of EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA;
  • to pass on your financial details to EPENDYSEIS ANONYMI ENERGEIAKI OIKODOMIKI KTIMATIKI KAI TECHNIKI ETAIREIA and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

PERSONAL DATA PROTECTION POLICY

General

White Pearl Villas are owned by the company «ΕΠΕΝΔΥΣΕΙΣ ΑΚΙΝΗΤΩΝ ΕΝΕΡΓΕΙΑΚΗ ΑΕ», and is responsible for processing the personal data that you provide, in the context of trade cooperation with the company. White Pearl Villas, are committed to protect the personal data of the visitors / users of the www.whitepearlvillas.com  website and to comply with the relevant provision on the protection of personal data as they apply. White Pearl Villas do not collect information on visitors’/ users' personal data unless they are provided voluntarily. Data collected from White Pearl Villas are those required and used only for the purposes for which they are collected, excluding any other non-desired use thereof. No personal data is required to navigate at the www.whitepearlvillas.com site or to access its content.

Introduction

The current Policy imprints and describes the Data Protection Management System and comprises the basic data protection principles that the company must provide to all users involved (internal and external partners).

Additionally, White Pearl Villas constantly provide the necessary resources for the proper implementation of the Policy, by all departments, systems, company users, services, as well as any related activities

How are your rights being protected?

White Pearl Villas implement an information security management system to ensure the confidentiality and security of your data and protect them against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access and all other unlawful forms of processing. This information is provided in accordance to Regulation (EU) 2016/679 of the European Parliament, the European Council and the provisions of the Greek legislation on the protection of personal data adopted and applied in this context.

Which data do we process?

Your personal data processed by White Pearl Villas may be:

  • Identity or passport information such as name, surname, nationality.
  • Contact details, such as phone number, address, email.
  • Booking information such as date of arrival and departure, room number.
  • Data relating to the procession of financial transactions such as credit-debit card number, bank account number, Tax Registry number, and professional status.
  • Flight details or shipping details.
  • Dietary habits and peculiarities such as allergies, intolerances or specific diets.
  • Photos and videos for republication in social media and the blog that exists on our website www.whitepearlvillas.com.
  • Copy of identity or passport and credit – debit card for identification purposes in cases of remote payments.

Why do we collect Personal Data?

The above-mentioned information and personal data that White Pearl Villas collect from you will be stored in the Company's databases and servers, always in accordance with the provisions of the current legislation, particularly with those concerning the protection of the privacy of communications and the protection of the person itself from the processing of personal data.

The White Pearl Villas explicitly declares that this data will not be shared, in any case, with third parties unless it is ordered differently by law or court, prosecutor's order or decision / other Public Authority provision as well as written authorization from the subject of such data.

The legal basis for your data processing is your consent, as well as the necessity of their storage for the company's response to your requests of any form provided by the relevant legislation.

Specifically, we process your data in order to provide:

  • The provision of accommodation, food, transportation and leisure travel
  • Information about the products and services provided by our company, (promotion packages, membership in the Loyalty club and other information material of our company).
  • For our response to your requests of any kind, such as for providing information, formulating complaints, evaluating services, etc.
  • For accounting and tax purposes based on our legal obligation
  • For protecting public health purposes.

Since you have consented to use your data for your information on the products and services provided by our company, as well as for promotional activities of our company (newsletter, social media, etc.), we will maintain this data until notifying us of something else or withdraw your consent by sending a request to the email address: info@whitepearlvillas.com .

Recipients

The processing of your personal data is done by designated and authorized employees of White Pearl Villas.

Recipients of your personal data may also be third parties, external partners such as reservation management service, customer transport services, leisure trips organizers, IT support service, accounting support to the extent that this is necessary for your best service and the provision of our services. In this case, White Pearl Villas are committed that its partners, acting only under its instructions, have been specifically authorized for that purpose and are fully bound by the confidentiality and obligations described by the law, regarding the collection and processing of the above data.

Time of retention

White Pearl Villa retains your data for as long as it is required to fulfill the purpose for which you have shared them with us and in compliance with the applicable laws of personal data protection.

Your rights

With reference to your personal data, you may exercise the following rights by submitting a request or through a legally authorized representative in our company or by sending the request by post, with the authentication of the signature. In particular, your rights are the following:

  • The Right to access - Right to receive information on whether your data is processed and accessed, as well as the right to receive information about this processing (who, for what purpose, recipients, retention period, etc.).
  • The Right to rectification - Right to correct inaccurate personal data and fill in incomplete information.
  • The Right to erasure (Right to be forgotten) - Right to request the deletion of any of your data under certain conditions (data that are no longer necessary, withdrawal of consent, etc.). You have the right to withdraw your consent, but the withdrawal is valid for the future data, meaning since your notification to White Pearl Villas, and it cannot have a retroactive effect.
  • The Right to Restrict Processing - e.g. when the accuracy of the data is in dispute, the data are no longer needed by the controller etc.
  • The Right to data portability - The Right to request the transfer of personal data to another Processing Manager in a structured, widely used and mechanically readable form. In case of exercising the right of correction, deleting and restricting the data, the applications will be transmitted to third party recipients to whom the data were disclosed.
  • The Right to object in regard to the use of your personal data- unless there are compelling and legitimate reasons for processing that override your interests, rights and freedoms, or for the foundation, exercise or support of our company's legal claims.

The above services are provided free of charge. However, if claims are unreasonable, excessive or recurring, our company may refuse to respond to these requests by informing the applicant.

Our company has taken all the technical measures to safeguard your personal data. Also, provides limited access only to those employees / partners who need to have access to these data. It takes all necessary measures to prevent any unauthorized access, use or modification of the data.

Collection of personal data from website

The policy of personal data protection includes and refers to the conditions of collecting and managing your personal information by White Pearl Villas during the use of its services and visit of web sites. The White Pearl Villas is the owner and holder of all rights of the page and Controller of data that may be declared by you.

This current policy does not cover, in any way, the legal relationship between visitors/users of the web pages and any other services that are not subject to control over the management and ownership of White Pearl Villas even when it includes links to other sites controlled by third parties (individuals or entities).

Most of our services do not require registration to visit and browse our site without having to disclose your identity. However, in some cases, it may be necessary to sign up to access some services. In case you hide your identity, you may not be allowed to access certain parts and services of our website.

The pages may use cookies for the proper functioning of services and pages. Cookies are small pieces of information stored on a computer to identify the corresponding browser while browsing websites. Cookies can be used to store items, such as logins and user preferences.

The cookies used by this website only serve the purposes of navigation, the website functionality, to facilitate navigation and therefore does not collect personal data.

In addition, pages can also use the "Google Tag Manager" a management tool through which they manage tags. In particular, the "Google Analytics - Universal Analytics" tag is used to extract statistical reports to track the website, daily traffic, and promote the company with regard to the products and services it provides.

This webpage only serves purposes of browsing and monitoring through Google Tag Manager and does not collect personal data other than the user's browsing preferences and domains that they have visited.

In any case, the visitor/user may be informed by the website www.allaboutcookies.org.In addition, it may configure its browser in such a way to inform the user about the use of cookies on specific page services or the choice to refuse/accept the use of cookies at any time. If the visitor/user does not wish the use of cookies, they cannot have further access to these services.

Personal data and children

The current website is not directed to children under 13 years old. It is our policy not to collect or keep data of people under 13 years of age. In any case, most of the information provided by White Pearl Villas websites is addressed to people aged 18 years or over.

White Pearl Villas will not collect, use, or disclose on purpose personal data from minors under the age of 18 without having obtained first the consent of the parent or guardian through direct communication, offline, over a network.

The White Pearl Villas do not deliberately collect personal information from minors under 18 years old. If it finds out that it has collected any personal data from a minor under 18 without a verifiable parental consent, it will delete the data from its database as soon as possible.

The purpose of the protection of personal data policy

The purpose of the Privacy Policy is to protect your personal data against all internal, external, deliberate or unintentional threats.

Our company has approved the Privacy Policy and hereby endorses the full commitment to the effective implementation and provision of sufficient resources for the continuous improvement of the Data Protection Management System.

The policy aims to ensure the following:

  • Continuous data protection from unauthorized access.
  • Continuous ensuring of the Confidentiality of White Pearl Villas customers and associates data.
  • Continuous maintenance of the integrity of White Pearl Villas, customers and associates data.
  • Continuous Ensuring of the Availability of Data and Business Processes.
  • Continuous monitoring and compliance with Legislative and Regulatory Requirements.
  • The Business Continuity Plan is maintained and controlled for its effectiveness.
  • Continuous Data Protection training for all employees of White Pearl Villas.
  • Confirmed or suspected violations of personal data are reported to the Data Protection Officer, are thoroughly investigated and addressed promptly and effectively.
  • Appropriate procedures and individual data protection policies have been developed and implemented in support of this policy, including technical and organizational protection measures.
  • White Pearl Villas ensure constant compliance with the legislation and requirements of GDPR through extended monitoring of the implementation of the Data Protection Management System.
  • The Data Protection Officer is responsible for maintaining the Policy, as well as for providing support and advice in its implementation.
  • All holders of managerial positions of White Pearl Villas are directly responsible for implementing the Policy as well as for ensuring the compliance of the supervising personnel.
  • The compliance with the Policy is mandatory for all those who work or cooperate with White Pearl Villas.
  • Any violations of the Policy are subject to disciplinary sanctions depending on the nature and impact of the infringement.
  • White Pearl Villas preserves the right to change this policy by updating the current text in order to comply with the applicable legislation on data protection as well as for any other reason deemed necessary.

Contact Information

For any request related to the processing of your data by White Pearl Villas, please contact as soon as possible at the following address: info@whitepearlvillas.com

If you believe that your privacy is affected in any way, you can appeal to the Data Protection Authority. [Leoforos Kifisias 1-3, 115 23, Athens, Phone: +30 2106475600, email : contact@dpa.gr].

You also have the right to appeal to the competent judicial authorities for the protection of your personal data.