Legal N°04 / 04

Guest Privacy Notice

Last updated 8 June 2026 · Villa Prima, Paleros, Greece

1. Who is responsible for your data

The data controller is JMN van Eekeren, operating Villa Prima, Paleros (Palairos), Aktio-Vonitsa, Greece. Contact: Info@villaprima.gr. This notice explains how we handle your personal data under the EU General Data Protection Regulation (GDPR) and Greek data-protection law.

2. What we collect

  • Identification and contact details: name, address, email, phone, and (where legally required) ID/ passport details of the lead guest and the names/number of guests in the party.
  • Booking and payment details: dates, price, and payment confirmation (card payments are processed by our payment provider; we do not store full card numbers).
  • Correspondence with us, and any special requests.
  • Limited security data: external/entrance CCTV, if installed, for safety only.
  • To take and manage your booking and provide the stay — performance of a contract.
  • To comply with legal obligations (e.g. tax, the property registry/AMA, the climate fee, any guest- reporting duty) — legal obligation.
  • To handle the security deposit, damage, complaints or disputes, and for the security of the property and guests — our legitimate interests.
  • To send you optional updates/offers only if you have asked us to — consent (you can withdraw it any time).

4. Who we share it with

Only as needed: our payment provider, our accountant and (where required) the Greek tax authority (AADE), the booking platform you used, and professional advisers or authorities where legally required. We do not sell your data.

When you submit an enquiry through our website, your enquiry details are delivered to us by email (via our email provider, Resend) and a copy is stored securely on our website hosting infrastructure (Netlify, EU/US — covered by appropriate safeguards) so your enquiry is not lost if email delivery fails. Enquiry records are kept only as long as needed to handle your enquiry and any resulting booking, and are then deleted.

5. International transfers

Your data is processed in the EU/EEA. If any provider processes data outside the EEA, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses).

6. How long we keep it

We keep booking and financial records as long as required by Greek tax and accounting law (generally several years) and other data only as long as needed for the purposes above; CCTV footage is kept for a short period and then deleted unless needed for an incident.

7. Your rights

You have the right to access, rectify, erase or restrict your data, to object to certain processing, to data portability, and to withdraw consent. To exercise these, email Info@villaprima.gr. You can also complain to the Greek Data Protection Authority (Hellenic DPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr).

8. Children

We do not knowingly collect data about children beyond the names/number of minors in the party, provided by the lead guest.