Personal Data Protection Policy
Increased economic and scientific partnerships as well as mutual provision for data processing services result in the exchange of personal data, a trend boosted by the ever-increasing use of modern telecoms. For these reasons, it is necessary to process the data with caution.
“Data Subject”: any natural person whose personal data is processed by or on behalf of the Company
“Personal Data”: Any information in relation to an identified or identifiable natural person that relates to its physical, physiological, psychological, mental or economic situation, its cultural or social identity.
“Processing”: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, such as the collection, recording, blocking, erasure or destruction.
1. Data Controller: Data Controller of your personal data collected by us is the company under the name «BLUEBIRD VILLAS», tel. no. 210 8085520, email address info@BLUEBIRDVILLAS.COM, having its registered seat in Athens, Kifissias Ave. No. 238-240.
2. Type of Personal Data collected
- personal information about you which we ask you for (e.g. your name, address, email address) when you express interest in our services (and third parties’ Personal Data you provide us e.g. for “book for a friend” program; in that case you declare that you have their consent), or sign up for our newsletter or when you make a booking from our booking engine;
- financial details in order to process your booking when we require pre-payment;
- details of transactions you carry out through our booking engine and details of the fulfilment of your orders;
- we try to minimize the risk to your rights and freedoms by not collecting or storing sensitive information about you, unless specifically requested.
2. Sources from which we collect your Personal Data
We obtain your Personal Data when you express your interest in our services and products, when you contact us, when we conclude a contract for the provision of our products and services, when you use our website, or if you register to receive one of our newsletters. We do not sell your information to anyone and only share it with third parties who are facilitating the delivery of our services to you.
3. Lawfulness of processing
Personal data may be processed if at least one of the following applies:
- the subject has given his / her consent;
- processing is necessary for the performance of a contract in which the subject is a party;
- processing is necessary in favor of our legitimate interests or to ensure our compliance with Greek and/or European law.
4. Principles applied during processing
The principle of proportionality applies to the processing of Personal Data. Among other things, it creates the obligation not to collect Personal Data unnecessarily.
Personal Data used should be accurate and up-to-date. Personal Data used and which is no longer accurate and complete should be corrected or deleted. Except where there is an obligation under law to maintain it for a longer period of time, Personal Data should not be kept for a longer period of time than is necessary for the purposes for which it was collected or processed.
The processing of Personal Data should be in accordance with the principles of good faith. This means that data subjects can rely on the processors to show proper care in all data processing issues.
Individuals whose Personal Data has been processed should be updated accordingly if they so request. In particular, they have the right to be informed of the purposes for which their data is processed, the type of data it concerns, and the identity of the recipients of the data. Where necessary, data subjects are also entitled to request the correction, non-transmission or deletion of their data. The above rights may be limited only if such limitation is provided for by law. This applies, in particular, to scientific research.
In particular, Personal Data is protected against unauthorized disclosure and any unauthorized processing. The measures put in place should ensure a level of security commensurate with the nature of the data to be protected and the risks that may arise from its processing. The Company is responsible for implementing and complying with EU Regulation 2016/679 and the applicable National Law.
5. How long we keep your Personal Data
- We keep your Personal Data for as long as it is required for the completion of the above mentioned scopes, as well as for as long as such storage is required by a contract or the applicable legislation.
- We keep the Personal Data of the people who signed up for our newsletters until they state to us that they no longer wish to receive.
6. Access to Personal Data and Rights
If you wish, you may request at any time to be informed about your Personal Data held by the Company, its recipients, the purpose of keeping and processing, and modifying, correcting or deleting it, by sending an e-mail to address email@example.com from the email address you have declared, enclosing a copy of your identity card.
You also have the right to review your Personal Data and, in general, to exercise any right under the law to protect Personal Data. The Personal Data that you communicate to the Company through firstname.lastname@example.org or through your personal presence in our stores, either during your registration or at a later stage, is collected and is used and processed in accordance with the applicable data protection provisions character, also according to the provisions of Law 2472/1997 and Law 3471/2006, as well as the new European General Data Protection Regulation (EU) 2016/679 .
You retain the following rights in detail:
- Right to know about your Personal Data: Upon your request, we will provide you with information about the Personal Data we hold for you.
- Right to correct and complete your personal information: If you notify us in this regard, we will correct any inaccurate Personal Data you may have. We will fill in incomplete data provided you notify us, provided that such data is necessary for the purpose of processing your data.
- Right to delete your Personal Data: Upon your request, we will delete the Personal Data we hold for you. However, some data will only be deleted after a specified hold period, for example because in some cases we are legally required to retain the data, or because the data is required to fulfill our contractual obligations vis-à-vis you.
- Right to bind your Personal Data: In some cases provided by law, we will block your data if you request it. Further processing of blocked data occurs only to a very limited extent.
- Right to withdraw your consent: You may at any time withdraw your consent to the processing of your Personal Data in the future. The lawfulness of your data processing remains unaffected by this action, to the point where your consent is withdrawn.
- Right to the restriction of processing of your Personal Data: Under certain conditions, you have the right, to request the restriction of your Personal Data. In this case, these data will be flagged and be processed only for specific purposes.
- Right to data portability: Under certain conditions, you have the right to receive your Personal Data in a structured, commonly used and machine-readable format and transmit those data to a third party without hindrance.
- Right to object to the processing of your Personal data: You can always object to the processing of Personal Data in the future, if we process your data in the base of one of the legal justifications provided for in Article 6 (1e or 1f) of Regulation (EU) 2016/679. If you object to the processing, we will stop processing your data, provided that there are no legal grounds for further processing. Processing your data for advertising purposes is not a legitimate reason.
- Right to lodge a complaint with the competent supervisory authority: In the case you think that the processing of your Personal Data infringes the legislation on Personal Data, you have the right to lodge a complaint with the competent supervisory authority (www.dpa.gr).
7. Security of Personal Data
The Company applies specific technical and organizational security procedures to protect Personal Data and information from loss, misuse, alteration or destruction. Our partners who support us in the operation of this website also comply with these provisions. The Company makes every reasonable effort to keep Personal Data collected only for the time it takes for the purpose for which it was collected or until its removal is requested (if this occurs earlier) unless it continues to keep them as provided in the applicable legislation.
8. Transferring of information outside the EU
Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.
This is a Declaration of Compliance with the provisions of EU Regulation 2016/679 and the applicable Greek Law.