Privacy Notice

Last Updated: May 24th, 2018

At VOLCANO VIEW HOTEL Α.Ε, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to VOLCANO VIEW HOTEL Α.Ε.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://volcanoview.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to VOLCANO VIEW HOTEL Α.Ε.

Data Controller

VOLCANO VIEW HOTEL Α.Ε operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Volcano View Hotel Santorini “VOLCANO VIEW HOTEL Α.Ε”
Fira
847 00, Santorini
GR

Data Processor

WebHotelier operates this booking system on behalf of VOLCANO VIEW HOTEL Α.Ε and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of VOLCANO VIEW HOTEL Α.Ε, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at VOLCANO VIEW HOTEL Α.Ε;
  • to pass on your financial details to VOLCANO VIEW HOTEL Α.Ε and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

VOLCANO VIEW HOTEL

PRIVACY POLICY

Volcano View Hotel (we), as a company operating in Hospitality Industry we have to operate under the General Data Protection Regulation (GDPR), as established by the new Regulation (EU) 2016/679 of the European Parliament and national law 4624/2019, and their obligations on us and our customers. This privacy policy explains how we may collect and use information (personal data) that you provide us and for what reasons. Furthermore, we would like to inform you about your rights in relation to that information (personal data).

Data information we collect and for what reasons :

Full name, gender, full address, phone number, email address, payment details (bank account number, IBAN, card details etc), business title, document to prove personal ID for security reasons (ID, passport and visa information, driving license) nationality, tax details, dates of your stay and purchase or delivery products or services. We do not collect “sensitive information”, unless it is volunteered by you.

We also may collect:

Data about family members and companions, who stay in VOLCANO VIEW HOTEL,

Images and videos and audio data via: security cameras,

Wi-fi data,

Automated information: When you visit our website, we may also collect certain information through the use of “cookies” and other automated means. Cookies are small pieces of information that are stored by your browser on your computer's hard drive. Such information may comprise the following information:

date and time,

originating IP address,

domain name,

type of browser and operating system used (if provided by the browser),

URL of the referring page (if provided by the browser),

object requested,

completion status of the request,

geographic location, or

language preferences.

How we collect these information:

filing in a form on our website,

filling in a physical registration form,

contacting us by telephone or face to face,

sending us a letter, e-mail or social media message,

subscribing to receive a service from us (e.g. a newsletter or by following us on social media),

requesting promotional information from us (e.g. information about any of our services),

participating in a survey or competition.

If you submit any Personal Data about other people to us (e.g. if you make a reservation for another individual), you represent that you have the authority to do so and you permit us to use data in accordance with this Privacy Policy.

We collect personal data either directly from you, when you visit our hotel or through online services (the website we operate www.volcano-view.com, and our social media pages – facebook etc.).

Volcano View Hotel adopts and implements the following principles:

Purpose specification and purpose limitation: the purposes for which we collect and use personal data shall be specified and legitimate. The data shall not be used for anything other than the specified purposes,

Transparency: clear information shall be provided to individuals about the purposes for which personal data are collected and used, at the time the data is collected,

Data minimization: we shall only collect personal data that is strictly necessary for the specific purposes i.e. the minimum personal data required shall be collected and used,

Accuracy: personal data shall be accurate and where necessary kept up to date,

Retention: personal data shall not be kept for longer than is necessary,

Security: appropriate measures to protect personal data shall be implemented maintained,

Accountability: our hotel will be able to demonstrate that it has implemented measures to comply with the abovementioned principles.

Legal grounds for processing your personal data:

The provision of the services you appoint us for and you want to receive from us,

Complying with a statutory obligation, such us returning prepayment, managing your claims etc,

Safeguarding and protecting the legitimate interests of yours as well as ours. So we are entitled to use closed circuit television system (CCTV) and security cameras to be able to protect the security of individuals, materials and facilities,

The consent you provide us with under the specific conditions set out in the legal framework in order to receive updates on services and offers.

 Share information - Transfer to third - party associates:

We may share information with service providers who perform functions and services on our behalf. Such third parties will be appointed as data processors and will be provided only with information necessary to perform the services on our behalf but are not authorized to use such information for any other purposes. We may disclose information about you if we are required to do so by law or pursuant to legal process, or in response to a request from law enforcement authorities or other government officials.

Our Hotel shares your personal data with the following categories of recipients :

Governmental authorities, law enforcement agencies etc

Associates of our Hotel.

We declare that we do not sell information we collect and hold about you.

Data Controller: VOLCANO VIEW HOTEL Tourism, Construction and Trading Company S.A., trading under the name «VOLCANO VIEW HOTEL», registered with the Hellenic General Commercial Register (Γ.Ε.Μ.Η.) under number 047963038000, having its registered office in Santorini (Fira 84700), email: info@volcano-view.com, tel: +30 2286024780, website: www.volcano-view.com, informs that, for the purposes of its business, it processes personal data of its customers in accordance with applicable national law and the European Regulation 2016/679 on the protection of individuals with regard to the processing of personal data.

SECURITY

We take all necessary technical and organizational measures to ensure the secure processing of your personal data and to prevent any accidental loss or destruction and any unauthorized and/or illegal access, use, alteration or disclosure of your data. Any personal data in hard copy format will be kept in a locked filing cabinet, drawer or safe, with restricted access in our premises, and only the Data Controller and authorized members of our staff, have access to the data. These premises are protected by CCTV camera systems. Confidential paper records will not be left unattended or in clear view anywhere with general access. All electronic devices are password-protected to protect the information on the device in case of theft. Digital data is coded, encrypted or password-protected, on a network drive that is regularly backed up on and off-site. All members of our staff are provided with their own secure login and password, and every computer regularly prompts users to change their password. Emails containing sensitive or confidential information are password-protected if there are unsecure servers between the sender and the recipient. The security of our computer and storage systems, and access to them, is continuously monitored.

However, given the way that Internet works and the fact that is freely accessible to anyone, we are unable to guarantee that no unauthorized third parties will ever be able to circumvent such measures and gain access, or even make use of your personal information for unauthorized and/or unlawful purposes. Furthermore, we bear no responsibility for payments that take place in other bank accounts, as a result of hacking. For your safety, we recommend you before paying, contact us to verify the correct bank accounts.

DATA RETENTION

We will only keep your personal data for as long as we need to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. The length of time we keep your information will vary depending on the obligations of European and national legal framework.

To decide how long we should keep your personal data for, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or sharing of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.

By law we have to keep basic information about our customers (including contact, identity, payment details and transaction data) after they cease being customers for tax purposes.

CCTV Data

Our Hotel uses closed circuit television system (CCTV) and security cameras to be able to protect the security of individuals, materials and facilities. The processing is necessary for our legitimate interests. Security cameras are covering the entrance of the hotel, the reception, the surroundings, the parking area, cash registers, machinery areas and high risk areas. Special markings indicate the spaces are monitored by CCTV system. The information collected only for security purposes and safety reasons.

Our legitimate interests aim to: increase the personal safety of our staff and visitors, assist in identifying, apprehending and prosecuting any offenders, protect the Hotel’s buildings and assets and those of its staff from intrusion, theft, vandalism, damage or disruption, establish, exercise or defend against legal claims.

We ensure you that CCTV data can only be viewed by Data Controller and authorized members of our staff. The digital files are protected by passwords. All recorded CCTV footage will be kept for a maximum of fifteen (15) days (recording cycle).

Your rights:

Access, update, withdraw, amend or correct : You may have the right to access and receive a copy of the personal information we hold about you, update, withdraw, amend or correct the information.

Change, restrict and delete : You may have the right to change, restrict or delete your personal data stored by us.

Data portability : You may have the right to receive your personal data free of charge in a format that allows you to access, use and edit them. You also have the right to ask us, if technically feasible, to pass the data directly to another processor.

Object and complaint: You may have the right to object to the use of data by us, in case we use the information for illegal or unauthorized purposes.

To exercise these rights or to make a complaint about our privacy practices, please contact us, by using the contact information stated below. Finally, if you are resident in EU, or a citizen of EU, and wish to raise a concern about our use of your information you have the right to do so with your local data protection authority.

CONTACT US FOR GDPR ISSUES

For the purposes of EU and national law, if you have any questions, requests or concerns you may contact us, via email at info@volcano-view.com, via phone at +30 2286024780, via fax: +30 2286024890, via mail address Fira Santorini 84 700, Greece.