Privacy Policy
Last updated: May 2026
At Kipos Hotel, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek data protection legislation, including Law 4624/2019.
1. Data Controller
The data controller responsible for the processing of your personal data is:
Tourist Enterprises E. Tsakatara SA
Limenas, Thassos 64 004, Greece
Email: info@kipos.gr
VAT ID: EL094245814
GEMI Registration Number: 121585130000
Authorized Representative: Constantinos G. Tsakataras
For any privacy-related request, you may contact us at info@kipos.gr.
2. Personal Data We Collect
We may collect and process personal data when you visit our website, contact us, make an inquiry, request a reservation, subscribe to our newsletter, or stay at our hotel.
Depending on the situation, the personal data we collect may include:
- Contact and identification details, such as your first name, last name, email address, telephone number, country, home address, ID card or passport details, and date of birth where required by law or for hotel registration purposes.
- Reservation and stay details, such as arrival and departure dates, number of guests, room type, special requests, communication history, and information necessary to manage your booking or stay.
- Payment and invoicing details, such as payment method, transaction information, billing details, and information required for issuing invoices or receipts. We do not intentionally store full payment card details on our website.
- Communication data, such as messages sent through our contact forms, email, telephone, social media, WhatsApp, Viber, or other communication channels.
- Newsletter and marketing data, such as your email address and your preferences when you choose to receive offers or updates from us.
- Technical and website usage data, such as IP address, browser type, device information, pages visited, approximate location, referral source, and interaction with our website. This may be collected through cookies or similar technologies, depending on your consent choices.
3. Special Categories of Personal Data
We do not intentionally request or collect special categories of personal data, such as health information, biometric data, religious beliefs, or similar sensitive information.
However, you may voluntarily provide information connected to your stay, for example allergies, mobility needs, or other accessibility requirements. In such cases, we process this information only where necessary to respond to your request and provide appropriate hospitality services.
4. How We Collect Personal Data
We may collect personal data directly from you when you:
- use our website contact or inquiry forms;
- send us an email;
- contact us by phone, WhatsApp, Viber, social media, or other communication channels;
- make or request a reservation;
- check in or stay at the hotel;
- subscribe to our newsletter or marketing communications;
- accept cookies or interact with third-party tools on our website.
We may also receive limited personal data from third parties involved in your reservation or travel arrangements, such as travel agencies, online booking platforms, tour operators, or payment providers.
5. Why We Use Your Personal Data
We process your personal data for the following purposes:
- to respond to your inquiries and messages;
- to manage reservation requests and bookings;
- to provide accommodation and hospitality services;
- to complete check-in and guest registration procedures;
- to issue receipts, invoices, and other legally required documents;
- to process payments and manage financial records;
- to communicate with you before, during, and after your stay;
- to handle special requests related to your accommodation;
- to send newsletters, offers, or updates when you have agreed to receive them;
- to improve our website, services, and guest experience;
- to protect the security of our website, systems, guests, and business;
- to comply with legal, tax, accounting, tourism, and public authority obligations.
6. Legal Basis for Processing
We process your personal data only when there is a valid legal basis under GDPR.
- Contractual necessity, when processing is necessary to respond to a reservation request, manage a booking, or provide accommodation services.
- Legal obligation, when processing is required by applicable law, including tax, accounting, tourism, public authority, or guest registration obligations.
- Consent, when you agree to receive marketing communications or when you accept non-essential cookies and similar technologies.
- Legitimate interest, when processing is necessary for the normal operation of our business, communication with guests, fraud prevention, website security, service improvement, or handling legal claims, provided that your rights and interests do not override our legitimate interests.
7. Newsletter and Marketing Communication
If you choose to subscribe to our newsletter or receive offers from us, we may use your email address to send you updates, offers, and news about Kipos Hotel.
We use Brevo, formerly Sendinblue, for email marketing and newsletter management.
You may unsubscribe at any time by using the unsubscribe link included in our emails or by contacting us at info@kipos.gr.
We do not sell or rent your personal data to third parties.
8. Cookies, Analytics, and Advertising Tools
Our website uses cookies and similar technologies. Some cookies are necessary for the website to function properly, while others are used for analytics, advertising, embedded content, or communication tools.
Depending on your consent choices, our website may use services such as:
- Google Analytics;
- Google Ads;
- Meta/Facebook Pixel;
- YouTube embeds;
- Click to Chat or similar communication widgets.
These tools may collect technical and usage information, such as your device, browser, IP address, visited pages, and interactions with the website.
You can find more detailed information in our separate Cookie Policy. You can also manage or withdraw your cookie consent through the cookie settings available on our website.
9. Contact Forms and Email Communication
When you contact us through a website form or email link, we use the information you provide to respond to your message and handle your request.
Your message may include personal data such as your name, email address, phone number, arrival and departure dates, number of guests, and any information you include in the message.
Our website uses HTTPS encryption to protect communication between your browser and our website. However, no method of online transmission or storage is completely secure.
10. Social Media and External Communication Channels
If you contact us through social media platforms or messaging services, such as Facebook, Instagram, WhatsApp, or Viber, your personal data may also be processed by the provider of that platform or service according to its own privacy policy.
We use such communication only to respond to your messages, manage inquiries, or assist with your reservation or stay.
11. Sharing Personal Data with Third Parties
We may share personal data only where necessary and only to the extent required for the relevant purpose.
Recipients may include:
- booking platforms, travel agencies, or tour operators involved in your reservation;
- payment service providers and banks;
- accountants, tax advisors, legal advisors, or professional consultants;
- IT, website hosting, email, newsletter, analytics, advertising, and technical service providers;
- public authorities, tax authorities, police, courts, or other competent bodies where required by law;
- service providers requested by you or necessary for your stay, such as taxi transfer or car rental providers.
We require service providers processing personal data on our behalf to protect your data and process it only according to our instructions and applicable law.
12. International Transfers
Some third-party service providers we use may process personal data outside the European Economic Area.
Where this happens, we rely on appropriate safeguards required by GDPR, such as adequacy decisions, Standard Contractual Clauses, or other lawful transfer mechanisms.
13. How Long We Keep Your Personal Data
We keep personal data only for as long as necessary for the purpose for which it was collected, unless a longer retention period is required by law.
- Reservation, accounting, invoicing, and tax-related data may be kept for as long as required by Greek tax, accounting, and business legislation.
- General inquiry messages may be kept for a reasonable period in order to respond to your request, manage future communication, or protect our legitimate interests.
- Newsletter data is kept until you unsubscribe or request deletion.
- Cookie and analytics data is kept according to the retention settings of the relevant tools and your cookie consent choices.
Where possible, we delete, anonymize, or securely archive personal data that is no longer required.
14. How We Protect Your Personal Data
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.
These measures may include secure systems, access restrictions, HTTPS encryption, backups, password protection, staff access limitations, and regular review of our data handling practices.
Only authorized persons who need access for business, legal, or service-related purposes may access personal data.
15. Your Rights
Under GDPR, you have rights regarding your personal data. These may include the right to:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion of your personal data, where legally possible;
- request restriction of processing;
- object to processing based on legitimate interests;
- withdraw consent where processing is based on consent;
- request data portability, where applicable;
- lodge a complaint with the competent data protection authority.
To exercise your rights, you may contact us at info@kipos.gr.
The competent supervisory authority in Greece is the Hellenic Data Protection Authority.
16. Children’s Personal Data
Our services are not directed to children using the website independently.
Where personal data of children is necessary for reservations, accommodation, legal registration, or guest service purposes, it should be provided by a parent, guardian, or responsible adult.
If you believe that a child has provided us with personal data without appropriate consent or authorization, please contact us at info@kipos.gr.
17. Data Breaches
In the event of a personal data breach, we will take appropriate steps to assess and limit the breach.
Where required by law, we will notify the competent supervisory authority and/or affected individuals within the time limits required by GDPR.
18. Links to External Websites
Our website may contain links to third-party websites or services. We are not responsible for the privacy practices, content, or security of external websites.
We recommend that you read the privacy policies of any external websites you visit.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, or business changes.
The updated version will be published on this page with a new “Last updated” date.
For privacy-related questions or requests, please contact us at info@kipos.gr.
