Privacy Policy

Privacy policy

“Lyrids Apartments” is a company operating in the field of tourism and hospitality and must apply the General Data Protection Regulation (GDPR) of the European Parliament with number 2016/679 and Greek Law 4624/2019, regarding the personal data of our staff and our customers. This privacy policy explains in a simple and understandable way: (a) how we collect and use the personal data you provide to us, (b) the reasons for the collection and processing and (c) your legal rights in relation to your personal data.

Personal data we collect and why

Your name, gender, full address, telephone number, email address, payment details (bank account number, IBAN, card details etc.), place of work, proof of identity documents (ID card, passport, driving licence or health number) nationality, personal tax details, dates of residence and products or services ordered or purchased. We do not collect sensitive personal data unless the customer wishes to forward it to us to facilitate their stay. We also collect:

  • images and video and audio data via security cameras,
  • wi-fi connection data,
  • automated information: When you visit our website, we also collect certain information through the use of “cookies” or other automated means. Cookies are small files of information stored by your browser on your computer’s hard drive. Such information may include the following information: date and time, web protocol address, domain name, browser type and operating system you are using, website address, geographic location and language selection.

How we collect the above information

By filling out a relevant online form on our website, by filling out the printed reservation form, by contacting us by phone or in person, by sending us a letter, email or social media message, by registering as a subscriber to receive our services (e.g. newsletter, or when you follow us on social media), by participating in a survey or contest. If you submit personal data about other people to us (e.g. if you make a booking for another person), you represent that you have the authority to do so and you allow us to use the data in accordance with this Privacy Policy. We collect personal data either directly from you when you visit our hotel or through online services (the website we operate: www.lyridsapartments.gr, social media pages facebook, instagram etc.)

Data protection principles

Our company complies with all legal requirements (principles) imposed by EU and Greek legislation. The purposes for which our Hotel collects and uses personal data must be specified and legal. The data will not be used for any other purpose than the specified ones.

Transparency: clear information is provided to individuals about the purposes for which personal data is collected and used, at the time the data is collected.

Data minimization: our Hotel collects only personal data that is absolutely necessary for the specific purpose(s), i.e. the minimum required personal data is collected and used.

Accuracy: personal data must be accurate and, where required, updated.

Retention: personal data shall not be kept for longer than necessary.

Security: appropriate measures are in place to protect personal data.

Responsibility: our Hotel will be able to demonstrate compliance with all of the above principles.

Legitimate grounds for processing your personal data include:

  • the provision of services that you have commissioned and wish to receive from us,
  • to comply with an obligation imposed by law, e.g. refunding an advance payment, managing your claims for compensation, etc,
  • safeguarding and protecting your legitimate interests, both yours and ours, with potential use of closed circuit television (CCTV) and security cameras to enable us to be able to protect the safety, security of persons, property and premises,
  • consent, which you provide under the specific conditions set out in the legislative framework, in order to receive updates on services and offers.

Data sharing – Third parties

Our Hotel shares your personal data with the following categories of recipients:

  • government authorities, law enforcement agencies, tax authorities etc.
  • our Hotel’s partners (accountants, lawyers etc).

We declare that we do not sell your personal data that we collect and store.

Data Controller

“Papapostolou Bros. Ltd” with the distinctive title “Lyrids Apartments”, Greek Company No 15465705000, Tax No 801336411, located in Episkopi, Municipality of Rethymnon on the provincial road of Loutra – Episkopi (p.c. 74055), email: info@lyridsapartments.gr, tel: +30 697 6786337, website: www.lyridsapartments.gr, we inform you that for the purposes of our business we collect and process the personal data of our customers, always in accordance with the requirements of European legislation and in particular Regulation 2016/679 of the European Parliament for the protection of personal data and national legislation.

Data Security

Our Hotel takes all appropriate technical and organizational measures to ensure the secure processing of personal data and to prevent accidental loss or destruction and any unauthorized and/or unlawful access, use, modification or disclosure. Any personal data in hard copy will be kept in a locked filing cabinet, drawer or other secure place, with strictly limited access on our Hotel premises, and only our Data Controller and our authorized staff will have access to it. Our facilities are protected by closed circuit television security cameras. Confidential document files will not be left unattended or exposed to public view anywhere there is general access. All electronic devices are protected by security codes to protect personal data in the event of theft or loss. Digital files are encrypted, encoded or protected by security codes on a network drive, which is regularly backed up. All our staff members are provided with personal security passwords, and each computer regularly reminds them to change these passwords for security reasons. Email messages we receive from you containing sensitive or confidential information are protected by security codes in the event of insecure servers being proxies between the sender and recipient of the message. The above security of, and access to, our computer and storage systems is monitored and controlled on an ongoing basis. However, our Hotel is not responsible for payments that you have made and that take place in bank accounts other than our own as a result of interception. For the security of your transactions, we recommend that before you transfer funds to a bank account, you contact us to verify the correctness and accuracy of our Hotel’s bank accounts.

Data Retention

We retain our customers’ personal data only for as long as necessary to fulfill the purposes for which we collect it, including any existing legal obligation. The period of time for which we retain your personal data will be adjusted in accordance with the requirements of European and national legislation. In order to determine the retention period for your personal data, the quantity, nature (if it falls into a special category of data), exposure to potential risk from unlawful use, the purposes of collection and processing and whether these purposes can be achieved by other means, as well as any existing legal obligations, will be taken into account. We are required by law to retain basic information about our customers (including contact details, payment information and transaction data) for a certain period of time after they have ceased to be our customers for tax purposes.

Closed Circuit Television (CCTV) data

The hotel uses (or shall) CCTV. We use a surveillance system for the purpose of protecting persons and property. The processing is necessary for legitimate interests that we pursue as a data controller. The security cameras are positioned to cover the entrance of the Hotel, the reception area, the surrounding area of the building, parking areas, cashiers, mechanical installations and areas of increased risk. Areas where CCTV closed circuit television is installed shall be specially marked. Our legitimate interest consists of the following: enhancing the protection of the personal safety of our staff and guests; facilitating the identification, apprehension and prosecution of offenders; protecting our hotel premises; preventing theft, vandalism, damage and burglary; pursuing and/or defending legal claims. We assure you that access to your data is granted to the Data Controller and only to our authorized personnel. The data, which is stored digitally, is protected by security codes. The retention period for images and videos is 15 days.

Your rights:

  • Access, information, revocation, amendment or rectification: you have the right to access your personal data, and if you wish you can request a copy of the information we have collected and stored. You also have the right to update, withdraw, amend or correct your personal data.
  • Restriction of processing and erasure: You have the right to restrict the processing of your personal data or even delete it.
  • Portability: You have the right to receive, free of charge, your personal data in a format that allows you to access, use and process it. You also have the right to ask us, where technically feasible, to transfer your data directly to another controller.
  • Objection or Complaint: You have the right to object or terminate if you find that we are using your personal data for unlawful purposes or without your consent.

Exercise of rights

To exercise the above rights, please contact us at the contact information below. Finally, if you reside in or you are citizen of a Member State of the European Union or are a citizen of a Member State of the European Union and you wish to lodge a complaint regarding our use of your personal data, you may contact your local authority responsible for the protection of personal data.

Changes, Amendments to Privacy Policy Terms

The Company reserves the right, at its sole discretion, to modify or replace these terms. Posting on the Company’s website shall be deemed to be notice of such changes, which shall be effective ten (10) calendar days after posting. The updated Privacy Policy is available on the Company’s website at https://lyridsapartments.gr.

Contact

For any question, query or clarification regarding the protection of personal data, you can contact us via email: info@lyridsapartments.gr, tel: +30 697 6786337, postal address: Provitional road of Loutra-Episkopi, Rethymno p.c.74055.

Last update: 14/2/2025

ESPA