TERMS AND PRIVACY POLICY

Data privacy is of high importance for Kymata Hotel and rezDirect and we want to be open and transparent with our processing of your personal data.
Please read this policy as it contains important information about how we use personal data that we collect from you or that you provide to us.

INFORMATION AND CONSENT

By reading this Privacy Policy, the user is hereby informed on how rezDirect collects, processes and protects personal data furnished through the website rezdirect.com (hereinafter, the “website”, “booking system”, “booking engine”, “online booking”, "online booking engine", “system”, “platform”, “webapp”, “service”), via the rezDirect booking engine,
as well as through their connection and browsing of the website and those other data that may be provided in the future to rezDirect through the accommodation agreement or any other enabled means.

The User must carefully read this Privacy Policy, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Kymata Hotel.

By accessing this online booking engine or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this policy from time to time. You should check this policy frequently to ensure you are aware of the most recent version.

IDENTITY

When this policy mentions “data controller”, “controller”, it refers to Kymata Hotel

DATA CONTROLLER

Kymata Hotel operates this booking system through a data processor, as it will be explained below.
For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, rezDirect is the Data Controller.
There is a strict contractual framework between the data controller and the data processor for the protection of your personal information.

Hotel Kymata
Saint George Beach, Naxos Town
Naxos Island, Cyclades
Greece

DATA PROCESSOR

rezDirect.com operates this booking system on behalf of Kymata Hotel and is committed to protecting the privacy of the users of this system.
rezDirect is a division of WebDirect, registered at Cyclades Commercial Chamber

WebDirect
Court Sq., Naxos Town, Cyclades
Greece

For the purposes of the GDPR, where rezDirect processes your personal data on behalf of Kymata Hotel, rezDirect is the the Data Processor.
When this policy mentions “data processor”, “processor” it refers to rezDirect.

The User may contact rezDirect Data Protection Officer at dpo[at]rezdirect.com

OBLIGATORY NATURE OF PROVIDING THE DATA

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless otherwise stated in the required field) to meet the stated purposes.
Accordingly, if they are not provided or are not provided correctly, rezDirect and thereafter Kymata Hotel will be unable to process the request.

PERSONAL DATA COLLECTED AND PROCESSED

Personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
Financial details in order to process your reservation when we require pre-payment;
Details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
Our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. rezDirect cannot process it in any other way or for any other purpose.

Kymata Hotel grants permission to the data processor:

To use your personal information for reserving accommodation and/or other services for you at Kymata Hotel.
To pass on your financial details to Kymata Hotel and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a reservation;
To use your information for inviting you to write a review
To complete forms and other details on the booking engine to view your reservation or to cancel you reservation, whenever it is applicable.

THIRD-PARTY DATA

In the event that the User provides third-party data (e.g. book for a friend), they declare that they have the third party's consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Policy, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

SENSITIVE DATA

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data
(e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions,
religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background,
trade union membership, or administrative or criminal proceedings and sanctions).

INFORMATION WE AUTOMATICALLY COLLECT AND INTERACTIONS

Analytical usage data. We collect anonymous analytical information about your use of our booking engine and your interactions with our booking engine, your session durations and the web pages you accessed.
This may also include basic information about the device you use to access our booking engine, including its type, screen resolution, operating system, language settings, the Internet Protocol (IP) address, through which your device accessed our website and/or the booking engine.

PURPOSE OF PROCESSING PERSONAL DATA

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
To manage the User’s contact requests with us through the channels provided to this end.
To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
To manage the provision of the contracted accommodation service, as well as additional services.
To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

PROMOTIONAL OFFERS FROM US

We may use your Identity, Contact, Technical, Usage and Profile Data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).

You will receive marketing communications from us if you have requested information from us or purchased services from us or if you provided us with your details when you entered a competition or registered for a promotion and, in each case, you have not opted out of receiving that marketing.

DATA RETENTION

Data will be retained for the period necessary to fulfill the purposes outlined in this Privacy Policy unless a longer retention period is required
or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

In some circumstances we may anonymise your personal data (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

The criteria used to determine our retention periods include:

The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have a booking that has not yet been fulfilled)
Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)


LEGITIMATE INTEREST FOR PROCESSING YOUR DATA

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.


DATA DISCLOSURE

We will use and disclose Personal Data as we believe to be necessary or appropriate:

To comply with applicable law and legal process, including laws outside your country of residence;
To respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
To enforce our terms and conditions;
To protect our operations;
To protect the rights, privacy, safety or property of our own, you or others; and
To allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law.
In some instances, we may combine Other Data with Personal Data (such as combining your name with your location).
If we do, we will treat the combined data as Personal Data as long as it is combined.

INTERNATIONAL TRANSFERS OF PERSONAL DATA

We may transfer your personal information to servers based outside of the EEA for the purposes described in this policy.
If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law.
These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

COOKIES

We and third-party website analytics provider (such as Google) use. Cookies are packets of information sent by our servers to your web browser and then sent back by the browser each time it accesses our servers. The cookies may contain a variety of information, such as the web pages you have accessed, session durations and IP addresses. Cookies are used for various purposes, such as to collect statistical information about your use of our website and save you the need to re-login with your username and password in case it is required.

This information is used to make websites work more efficiently, as well as to provide business and marketing information, and to gather such data as browser type and operating system, referring page, path through site, domain of ISP, etc. for the purposes of understanding how visitors use a website. Cookies and similar technologies help us tailor our website to your personal needs, as well as to detect and prevent security threats and abuse.

If you wish to block cookies, you may do so through your browser’s settings. You can delete cookies that are already on your computer and you can set your browser to prevent

USER’S RESPONSIBILITY

The User guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information submitted is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

The User will be responsible for false or inaccurate information provided through the website and for damages, whether direct or indirect, that this may cause to Kymata Hotel or third parties.

Our service is not directed to individuals under the age of sixteen (16), and we request that they do not provide Personal Data through the Services.

YOUR RIGHTS TO YOUR PERSONAL DATA

You have the following rights with respect to your personal data:

The right to request a copy of your personal data that we hold about you.
The right to request to correct your personal data if inaccurate or out of date.
The right to request that your personal data be deleted when it is no longer necessary for us to retain such data.
The right to withdraw any consent to personal data processing at any time
The right to request to provide you with your personal data and, if possible, to pass on this information directly (in a portable format) to another data controller when the processing is based on consent or contract.
The right to request a restriction on further data processing, in case there is a dispute in relation to the accuracy or processing of your personal data.
The right to object to the processing of personal data, in case data processing has been based on legitimate interest and/or direct marketing.
If you want to withdraw your consent, please send us an email. Please note that you may still receive system messages and administrative communications from us, such as order confirmations, system messages and notifications about your account activities.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

DATA SECURITY MEASURES

We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed.
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
They will only process your personal data on our instructions and they are subject to a duty of confidentiality.

Last Updated: May 24th, 2018