Definitions
For the purposes of this Privacy Policy:
“Personal Data” means any information relating to an identified or identifiable natural person.
“Data Subject” means any individual whose personal data is processed by SAMARITIS S.A.
“Processing” means any operation performed on personal data, including collection, recording, storage, use, disclosure, or deletion.
“Controller” means SAMARITIS S.A., which determines the purposes and means of processing personal data.
“Processor” means any third party that processes personal data on behalf of the Controller.
“Website” means www.alsusboutiquehotel.com.
“GDPR” refers to Regulation (EU) 2016/679.
Sekretesspolicy
I. Company’s Details
At Alsus Boutique Hotel, operated by SAMARITIS S.A., we value trust as much as we value hospitality.
SAMARITIS S.A., with registered seat at Leof. Andrea Papandreou 50, 71414 Heraklion, Greece, VAT number 094209409, Tax Office of Heraklion, tel. +30 2810 372700, email: [email protected], is the Data Controller of the personal data collected through www.alsusboutiquehotel.com.
We process your personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable Greek legislation.
II. Collected Data
Depending on your interaction with our services, we may collect:
Reservation Data:
- Full name
- Email address
- Telephone number
- Address / country of residence
- Stay details
- Special requests or preferences
- Payment Data
Online payments are processed securely through Eurobank’s e-commerce gateway. We do not store full credit card details on our servers.
Communication Data: Information you provide via contact forms, email correspondence, or telephone communication.
Newsletter Data: Email address and communication preferences (only with your explicit consent).
Technical & Usage Data:
- IP address
- Browser type and device information
- Website interaction data
- Cookies
- Google Analytics statistics
III. Processing Purposes
We process your personal data in order to:
- Manage and confirm reservations
- Provide accommodation services
- Communicate with you before, during, and after your stay
- Comply with tax and accounting obligations
- Improve our website and guest experience
- Send newsletters and promotional communication (with consent)
- Ensure transaction and website security
IV. Legal Basis for Processing (Article 6 GDPR)
We process personal data based on:
- Performance of a contract (reservation and accommodation services)
- Compliance with legal obligations
- Legitimate interest (service improvement, system security)
- Your explicit consent (newsletter and optional cookies)
V. Data Recipients / Processors
Your data may be shared with trusted service providers acting on our behalf, including:
- Webhotelier (online booking engine)
- Eurobank (payment gateway provider)
- HOTELIZER (Property Management System – PMS)
- Newsletter service provider
- Hosting and IT support providers
- Accounting and tax advisors
All partners are contractually bound to comply with GDPR.
VI. International Data Transfers
If certain service providers (e.g., analytics or newsletter platforms) are located outside the European Union, data transfers are safeguarded through Standard Contractual Clauses approved by the European Commission.
VII. Data Retention
We retain personal data only for as long as necessary:
Reservation and invoicing data: up to 10 years (as required by Greek tax law)
Contact form data: up to 24 months
Newsletter data: until you withdraw your consent
Analytics data: according to Google Analytics retention settings
VIII. About Your Rights
Under the GDPR, you have the right to:
- Access your personal data
- Request correction of inaccurate data
- Request deletion (where legally applicable)
- Restrict processing
- Object to processing
- Data portability
- Withdraw consent at any time
- Lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr)
Requests may be submitted to: [email protected]
We respond within one (1) month as required by law.
IX. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- SSL encryption
- Secure servers
- Restricted access to authorized personnel
- Confidentiality agreements
- Secure payment processing systems
X. Cookies
Our website uses:
- Strictly necessary cookies for essential functionality
- Analytics cookies (Google Analytics)
- Consent cookies to remember your preferences
You may manage your cookie preferences through the cookie banner displayed on our website.
XI. Updates to This Policy
This Privacy Policy may be updated from time to time. Any changes will be published on this page with a revised date.
Last updated: 21/02/2026
