Who we are (Data Controller)
Pinakoti Lodge (“we”, “us”) operates this website and is responsible for processing your personal data.
Email: info@pinakotilodge.gr | Tel: +30 693 270 1977
Location: Pinakates, Pelion, Greece
MHTE / License No
What personal data we collect
We may collect and process the following categories of personal data:
- Booking and stay details: name, email, phone number, dates of stay, number of guests, and information you provide during the booking/enquiry process.
- Messages and enquiries: information you submit via contact forms, email, or phone.
- Payment information: where applicable, we record payment status and details needed for invoicing/receipts (payment card details are processed by the payment provider if card payments are used).
- Technical data: IP address, browser/device information, and basic logs for security and troubleshooting.
- Cookies and similar technologies: see our Cookie Policy for details.
Why we use your data (purposes & legal bases)
We process your data only when we have a lawful basis under the GDPR, including:
- To manage bookings and provide our services (performance of a contract / pre-contract steps).
- To comply with legal and tax obligations (e.g., invoicing and record-keeping).
- To reply to enquiries and provide customer support (legitimate interests).
- To keep the website secure and prevent abuse/spam (legitimate interests).
- For analytics/marketing cookies (if used) only when you consent via our cookie banner/settings.
Who we share data with
We may share personal data with trusted service providers who help us operate the website and provide services, such as:
- Website hosting and technical support providers
- Booking system and website service providers (e.g., plugins running on our website)
- Email and communication providers
- Payment providers (only if you choose card payment)
We share only what is necessary and require appropriate safeguards.
International transfers
If any of our service providers process data outside the European Economic Area, we use appropriate safeguards such as Standard Contractual Clauses where required.
How long we keep data
- Booking and invoicing records: retained as required by applicable legal/tax obligations.
- Enquiries: retained for a reasonable period to handle your request and for reference if it becomes a booking.
- Security logs: retained for a limited period as needed for security.
Your rights
Subject to conditions and exceptions under the GDPR, you have the right to:
- request access to your personal data
- request correction of inaccurate data
- request deletion (where applicable)
- request restriction of processing
- object to processing based on legitimate interests
- request data portability (where applicable)
- withdraw consent at any time for consent-based processing (e.g., analytics/marketing cookies)
We aim to respond within one month.
How to exercise your rights
Contact us at info@pinakotilodge.gr. We may request reasonable information to verify your identity.
Complaints
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA).
Children’s privacy
Our website and services are not directed to children. Please do not submit personal data for minors without appropriate consent.
Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be posted on this page.