Privacy Policy
Last updated: May 2026
1. Data Controller
PANDEMI G.P.
Trading name: PANDEMI Luxury Living
28is Oktovriou 70, Rhodes 85100, Greece
Tax Reg. No (ΑΦΜ): 801011930
GEMI No.: 146925520000
Email: info@pandemi.gr
Tel: +30 6978871000
2. Data We Collect
Our website has no contact form and no booking system of our own, so we do not collect or store personal data in any database of ours. You reach out to us directly, on your own initiative, via:
- Phone call or SMS (from your own device)
- Email (from your own email account)
- WhatsApp (via a link that opens your own WhatsApp app)
Whatever you send us through these channels (e.g. name, contact details, desired dates, questions) is received and handled by us directly, on our own phone/email — not through the website's infrastructure.
Bookings are made via the external BookOnlineNow booking platform (linked from our website). Data you enter there is subject to its own privacy policy — see book-onlinenow.net.
We do not automatically collect browsing data or third-party data unless you have consented to cookies.
3. Guest Registration Details (Before Check-in)
Before check-in, Greek law requires us to separately collect the following, via your booking platform's chat (e.g. Booking.com, Airbnb) or email — for security reasons, not via WhatsApp, Messenger, or Instagram:
- Greek residents: Tax ID (ΑΦΜ) and the lead guest's full name
- International guests: Passport or EU ID number and the lead guest's full name
We only ask for the number and full name as plain text — never a photo or scan of the document. This information is used solely to file the mandatory declaration with the Greek tax authority (AADE) and is deleted from our systems immediately after filing — it is not subject to the 5-year retention in section 5.
4. Purpose & Legal Basis
Responding to enquiries / pre-contractual booking communication
Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR)
Filing the guest declaration with AADE
Legal basis: Legal obligation (Art. 6(1)(c) GDPR)
Accounting and tax obligations
Legal basis: Legal obligation (Art. 6(1)(c) GDPR)
5. Data Retention
We keep our correspondence (email/WhatsApp/phone) relating to a completed booking for 5 years from the check-in date, in accordance with Greek tax/accounting obligations. If no booking results, we delete the correspondence within 12 months. Guest registration details (Tax ID/passport) are deleted immediately after filing with AADE, as described in section 3.
6. Data Sharing
We do not sell, rent or share your personal data with third parties for commercial purposes. Data may be disclosed:
- To regulatory authorities (Greek tax authority, statistics) if legally required
- BookOnlineNow — external booking platform, if you choose to book through it. See its own privacy policy at book-onlinenow.net.
- Viva.com (Viva Payments S.A., Greece) — our payment services provider, for secure payment processing. Privacy policy: viva.com
7. Cookies & Tracking
🔧 Functional Cookies (no consent required)
Stored locally in your browser (localStorage) for theme (dark/light) and language preferences. Never transmitted to external servers.
🗺️ Google Maps (requires consent)
If you accept cookies, a Google Maps embed loads from Google's servers. Google may collect usage data. Google Privacy Policy: policies.google.com/privacy
📊 Google Analytics (requires consent)
If you accept cookies, we use Google Analytics 4 (GA4) to analyse traffic. It collects anonymous statistics (pages visited, session duration, country-level location). It is not linked to personal details. IP addresses are automatically anonymised. Google Privacy Policy: policies.google.com/privacy | Opt out of Google Analytics
8. Your Rights (GDPR)
Under GDPR (EU Regulation 2016/679) you have the right to:
Access
Obtain a copy of your personal data
Rectification
Correct inaccurate data
Erasure
Request deletion ('right to be forgotten')
Restriction
Restrict processing of your data
Portability
Receive your data in a structured format
Objection
Object to data processing
Withdrawal
Withdraw your consent at any time
Complaint
Lodge a complaint with the supervisory authority
To exercise your rights: info@pandemi.gr
9. Supervisory Authority
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
www.dpa.gr | Tel: +30 210 6475600
10. Data Security
We implement appropriate technical and organisational security measures, including SSL/TLS encryption for all data transmissions.
Data Protection Contact
Email: info@pandemi.gr
Tel: +30 6978871000
We respond within 30 days of receiving your request.