BlueBird Villas Mykonos

Privacy Notice

Last Updated: May 24th, 2018

At CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://bluebirdvillas.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ.

Data Controller

CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

BlueBird Villas “CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ”
Pouli,Mykonos
846 00, Mykonos
GR

Data Processor

WebHotelier operates this booking system on behalf of CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ;
  • to pass on your financial details to CAPITAL ADVISORS RELATIVITY ΕΤΑΙΡΕΙΑ ΣΥΜΒΟΥΛΩΝ ΧΡΗΜΑΤΟΟΙΚΟΝΟΜΙΚΗΣ & ΔΙΟΙΚΗΤΙΚΗΣ ΥΠΟΣΤΗΡΙΞΗΣ ΕΠΙΧΕΙΡΗΣΕΩΝ - ΤΟΥΡΙΣΤΙΚΗ ΞΕΝΟΔΟΧΕΙΑΚΗ ΑΝΩΝΥΜΗ ΕΤΑΙΡΕΙΑ and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Privacy Policy

Personal Data Protection Policy

(Privacy Policy)

 

To access the service, it is necessary to state that you have read the Privacy Policy by clicking on the link at the bottom of this page.

Increased economic and scientific partnerships as well as mutual provision for data processing services result in the exchange of personal data, a trend boosted by the ever-increasing use of modern telecoms. For these reasons, it is necessary to process the data with caution.

The Company "Bluebird Villas" (hereinafter referred to as "the Company"; when this Privacy Policy mentions “we”, “us” or “our”, it refers to the Company) declares that compliance with the principles of data protection for the processing thereof is an objective of the Company as it is committed to respecting the individual rights and privacy of individuals. The online store of the Company handles personal data with special care and always in accordance with EU Regulation 2016/679, the applicable Greek Law and the applicable law.

For the purposes of this Privacy Policy, the following definitions shall apply:

“Data Subject”: any natural person whose personal data is processed by or on behalf of the Company

“Personal Data”: Any information in relation to an identified or identifiable natural person that relates to its physical, physiological, psychological, mental or economic situation, its cultural or social identity.

“Processing”: any operation or set of operations which is performed on Personal Data or on sets of Personal Data, such as the collection, recording, blocking, erasure or destruction.

1. Data Controller: Data Controller of your personal data collected by us is the company under the name «BLUEBIRD VILLAS», tel. no. 210 8085520, email address info@BLUEBIRDVILLAS.COM, having its registered seat in Athens, Kifissias   Ave. No. 238-240.

 

2. Type of Personal Data collected

personal information about you which we ask you for (e.g. your name, address, email address) when you express interest in our services (and third parties’ Personal Data you provide us e.g. for “book for a friend” program; in that case you declare that you have their consent), or sign up for our newsletter or when you make a booking from our booking engine;

financial details in order to process your booking when we require pre-payment;

details of transactions you carry out through our booking engine and details of the fulfilment of your orders;

we try to minimize the risk to your rights and freedoms by not collecting or storing sensitive information about you, unless specifically requested.

 

2. Sources from which we collect your Personal Data

We obtain your Personal Data when you express your interest in our services and products, when you contact us, when we conclude a contract for the provision of our products and services, when you use our website, or if you register to receive one of our newsletters. We do not sell your information to anyone and only share it with third parties who are facilitating the delivery of our services to you.

3. Lawfulness of processing

 Personal data may be processed if at least one of the following applies:

the subject has given his / her consent;

processing is necessary for the performance of a contract in which the subject is a party;

processing is necessary in favor of our legitimate interests or to ensure our compliance with Greek and/or European law.

4. Principles applied during processing

We may process your Personal Data in order to provide personalized services under the law (Article 6 (1b) of Regulation (EU) 2016/679) and the relevant Greek Law. Your Personal data is not used for purposes other than those described in the Privacy Policy unless we obtain your prior permission or unless this is required or permitted by law. Personal Data should be processed in a way that is compatible with the purpose for which it was collected.

The principle of proportionality applies to the processing of Personal Data. Among other things, it creates the obligation not to collect Personal Data unnecessarily.

Personal Data used should be accurate and up-to-date. Personal Data used and which is no longer accurate and complete should be corrected or deleted. Except where there is an obligation under law to maintain it for a longer period of time, Personal Data should not be kept for a longer period of time than is necessary for the purposes for which it was collected or processed.

The processing of Personal Data should be in accordance with the principles of good faith. This means that data subjects can rely on the processors to show proper care in all data processing issues.

Individuals whose Personal Data has been processed should be updated accordingly if they so request. In particular, they have the right to be informed of the purposes for which their data is processed, the type of data it concerns, and the identity of the recipients of the data. Where necessary, data subjects are also entitled to request the correction, non-transmission or deletion of their data. The above rights may be limited only if such limitation is provided for by law. This applies, in particular, to scientific research.

In particular, Personal Data is protected against unauthorized disclosure and any unauthorized processing. The measures put in place should ensure a level of security commensurate with the nature of the data to be protected and the risks that may arise from its processing. The Company is responsible for implementing and complying with EU Regulation 2016/679 and the applicable National Law.

Employees of the Company dealing with the processing of Personal Data should be suitably informed. Procedures for the processing of Personal Data of third parties by agreement should be set out in writing. The Company will ensure that the third party is properly processing the Personal Data and is in compliance with the principles set forth in this Privacy Policy. In the event that the third party decides that it cannot ensure an adequate level of security of Personal Data, the Company will terminate the cooperation.

5. How long we keep your Personal Data

We keep your Personal Data for as long as it is required for the completion of the above mentioned scopes, as well as for as long as such storage is required by a contract or the applicable legislation.

We keep the Personal Data of the people who signed up for our newsletters until they state to us that they no longer wish to receive.

6. Access to Personal Data and Rights

If you wish, you may request at any time to be informed about your Personal Data held by the Company, its recipients, the purpose of keeping and processing, and modifying, correcting or deleting it, by sending an e-mail to address info@bluebirdvillas.com from the email address you have declared, enclosing a copy of your identity card.

You also have the right to review your Personal Data and, in general, to exercise any right under the law to protect Personal Data.  The Personal Data that you communicate to the Company through info@bluebirdvillas.com or through your personal presence in our stores, either during your registration or at a later stage, is collected and is used and processed in accordance with the applicable data protection provisions character, also according to the provisions of Law 2472/1997 and Law 3471/2006, as well as the new European General Data Protection Regulation (EU) 2016/679 .

You retain the following rights in detail:

Right to know about your Personal Data: Upon your request, we will provide you with information about the Personal Data we hold for you.

Right to correct and complete your personal information: If you notify us in this regard, we will correct any inaccurate Personal Data you may have. We will fill in incomplete data provided you notify us, provided that such data is necessary for the purpose of processing your data.

Right to delete your Personal Data: Upon your request, we will delete the Personal Data we hold for you. However, some data will only be deleted after a specified hold period, for example because in some cases we are legally required to retain the data, or because the data is required to fulfill our contractual obligations vis-à-vis you.

Right to bind your Personal Data: In some cases provided by law, we will block your data if you request it. Further processing of blocked data occurs only to a very limited extent.

Right to withdraw your consent: You may at any time withdraw your consent to the processing of your Personal Data in the future. The lawfulness of your data processing remains unaffected by this action, to the point where your consent is withdrawn.

Right to the restriction of processing of your Personal Data: Under certain conditions, you have the right, to request the restriction of your Personal Data. In this case, these data will be flagged and be processed only for specific purposes.

Right to data portability: Under certain conditions, you have the right to receive your Personal Data in a structured, commonly used and machine-readable format and transmit those data to a third party without hindrance.

Right to object to the processing of your Personal data: You can always object to the processing of Personal Data in the future, if we process your data in the base of one of the legal justifications provided for in Article 6 (1e or 1f) of Regulation (EU) 2016/679. If you object to the processing, we will stop processing your data, provided that there are no legal grounds for further processing. Processing your data for advertising purposes is not a legitimate reason.

Right to lodge a complaint with the competent supervisory authority: In the case you think that the processing of your Personal Data infringes the legislation on Personal Data, you have the right to lodge a complaint with the competent supervisory authority (www.dpa.gr).

7. Security of Personal Data

The Company applies specific technical and organizational security procedures to protect Personal Data and information from loss, misuse, alteration or destruction. Our partners who support us in the operation of this website also comply with these provisions. The Company makes every reasonable effort to keep Personal Data collected only for the time it takes for the purpose for which it was collected or until its removal is requested (if this occurs earlier) unless it continues to keep them as provided in the applicable legislation.

8. Transferring of information outside the EU

Information we collect from you is transferred and will be processed outside the EU for the purposes described in this Privacy Policy. If we do this, your Personal Data will continue to be subject to one or more appropriate safeguards set out in the law.

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

9. Revisions of the Privacy Policy

The Company reserves the right to modify or periodically revise this Privacy Policy in its sole discretion. If any changes are made, the Company will record the date of change or revision in this Privacy Policy and the updated Privacy Policy will apply to you from that date. We encourage you to periodically review this Privacy Policy to consider whether there are any changes to the way we manage your Personal data.

This is a Declaration of Compliance with the provisions of EU Regulation 2016/679 and the applicable Greek Law.

March 2019