Privacy Policy

If you are using or just visiting www.themediterraneansuites.com this Privacy Policy applies to you.

This policy contains information about the types of personal data we may collect, why we might collect them and how we might use them, in accordance with the relevant Greek and EU law (ΕΕ 2016/679).

Our Role

We act as the “data controller” of personal data. This means we determine why and how your data are processed.

If you provide us with personal information about other people, or if others give us your information, we will only use that information for the specific reason for which it was provided to us. By submitting any information, you confirm that you have the right to authorize us to process it on your behalf in accordance with this Privacy Policy.

Types of Data We Collect

1. Data we require when you use our contact form

When you contact us for any matter, such as inquiries with regards to our services we collect your name (first name and/or last name), your email address and any other data you include in your message that is relevant to your queries (eg Address, Telephone number -landline and mobile-Passport details). We need this data in order to address your inquiries.

2. Your email and telephone number

When you contact us for any matter via email reservations@lavish-hospitality.com, we collect your email in order to address your inquiry. Similarly, when you subscribe to our newsletter, we collect your email in order to send you our newsletter. In addition, if you contact us for any matter via telephone, we will collect your telephone number in order to address your inquiry.

3. Data relevant to your identity online and your location

Your IP address, browser type and version, browser plug-in types, time zone setting, geolocation information about where you might be and your operating system type and version.

4. Data relevant to your use of our website

Your URL clickstreams (the path you take through our site), locations and/or services viewed, page response times, cookie preferences, download errors, how long you stay on our pages, what you do on those pages, how often, any messages you send through a feedback window in relation to the goal of your visit, and other actions.

5. Special categories of data and children's data

We don’t collect any data about you revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning sex life or sexual orientation. We offer services directed to and intended for use only by those who are 18 years of age or over. We do not knowingly collect any personal data from any person under 16 years of age.

Our Legal Bases for Processing Your Personal Data

In order to collect and/or use your personal data we have at least one of the following legal bases:

  • Consent. You have given us clear and explicit consent to process your personal data for one or more specific purposes. If you have previously given consent to processing your data, you can withdraw such consent at any time. You can do this by emailing us at reservations@lavish-hospitality.com If you do withdraw your consent, and if we do not have another legal basis for processing your information, then we will stop processing your personal data. If we do have another legal basis for processing your information, then we may continue to do so, subject to your legal rights.

  • Contract. Processing your data is necessary for a contract you have with us (for the provision of our services or otherwise), or because providing such data is necessary to take specific steps before entering into that contract (e.g. when you make an inquiry through our contact form with regards to our services).

  • Legitimate interests. Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your legal rights and interests. These legitimate interests are:

    • providing, developing and improving our services

    • determining whether marketing campaigns are effective

    • improving data security

    • gaining insights from your behavior on our website in order to improve the function/usability of the website and your overall experience.

In each case, these legitimate interests are only valid if they are not outweighed by your legal rights and interests.

  • Legal obligation. Processing of your data is necessary for compliance with a legal obligation to which we are subject (e.g. providing you with an invoice).

Why do we collect your personal data and how do we use them?

We use your personal data for the following reasons:

  1. Answering your inquiries or requests (legal bases: contract, consent and the legitimate interest of providing our services). Managing your inquiries or requests with regards to our services especially when you give us information such as your website, company name, needs, budget, special request, etc through our contact form.

  2. Marketing purposes, promotional emails and newsletter (legal bases: legitimate interest and consent). The Company may send you promotional emails and newsletters containing information about our services and news and information about our company. We will never send you spam or annoying messages. We will only send you such informational and promotional emails if one of two conditions applies:

    • You are an existing customer and we believe you might be interested in receiving information about our services

    • You have subscribed to our newsletter and/or you have given us your consent to use your email for promotional purposes by other means.

You can always withdraw your consent and elect not to receive such promotional content or unsubscribe from our newsletter by following the dedicated link at the end of each promotional email or newsletter and the procedure described therein or by emailing us your request at reservations@lavish-hospitality.com

· Customer support (legal basis: contract and the legitimate interest of providing, developing and improving our services). Notifying you of any changes to or any problems with our services, workshops, webinars or training, solving issues via email or phone support including any bug fixing.

· Improving and securing our services (legal basis: legitimate interests -see above). Testing features, managing landing pages, heat mapping our site, traffic optimization and data analysis and research.

Any personal data collected by us is intended to be used exclusively for the above purposes and always in accordance with the relevant Greek and EU law.

How We Protect Your Data

The website www.themediterraneansuites.com is operated according to applicable EU and Greek legislation and it stores your personal data with safety. We have physical electronic and administrative procedures (technical and organizational measures) to secure and protect the information we collect and process.

However, please keep in mind that no data transmission is guaranteed to be 100% secure. We do not control the privacy of emails until they reach us. We recommend that you do not include confidential, private or sensitive information in emails.

If you believe your privacy has been breached, please contact us without delay by sending us an email at reservations@lavish-hospitality.com

Your Rights

1. You have the right to access the information we hold about you (Right of access to data). You can contact us and we shall inform you about:

  • the categories of data we’re processing

  • the purposes of data processing

  • the categories of third parties to whom the data may be disclosed

  • how long the data will be stored (or the criteria used to determine that period)

  • other rights you have regarding our use of your data

We can also send you a copy of this information if you wish.

2. You have the right to ask us to correct personal data about you if they are inaccurate or incomplete (Right of rectification)

3. You can restrict the processing of your personal data or object to us using your data for profiling you or making automated decisions about you (Right to restrict and object to processing).

4. You have the right to ask us to directly transfer your data to another service (Right to data portability) , as long as it is technically feasible or to provide you with a copy in a common machine-readable format. Please note that if such data also contain personal data about another person, we may not choose to include such data in our deliverables.

5. You have the right to be ‘forgotten’.

All you have to do is ask and we will erase and delete your data, unless we have another legal reason to hold your personal data (such as a legal claim or a regulatory requirement, specific legitimate and stated purpose) (Right of data erasure)

6. You can ask us not to use your data for direct marketing purposes.

7. You can file a complaint regarding our use of your data to the Hellenic Data Protection Authority.

Please tell us first and we would be happy to address your concerns. If you insist on contacting the Hellenic Data Protection Authority, you can find out how to reach them and exercise your rights at their website (www.dpa.gr).

You can exercise all the aforementioned rights (with the exception of 7) by emailing us at reservations@lavish-hospitality.com We shall address your request within thirty (30) days of its receipt unless it is too complicated or we are dealing simultaneously with too many such requests. In the latter case, it may take us up to two additional months to address your request, but we will let you know so within thirty (30) days of reception of your initial request.

Location of Processing and Storage of Data

The personal data we collect are processed at our offices in Greece and in any data processing facilities operated by the third parties identified below.

You agree to the transfer, storing or processing of your data by us, by submitting your personal data to us. If your information is transferred or stored outside of the EU or the EEA in this way, we will take steps to ensure that your privacy rights continue to be protected as outlined in this Privacy Policy.

Any personal data stored by us will be deleted within five (5) years of its collection. We may however keep your personal data longer in order to exercise or defend a legal claim or in case we are obliged by a legal provision to do so (e.g. tax legislation or other legislation). With regard to the email addresses kept for promotional purposes, we may keep them for longer periods but you can unsubscribe anytime, in which case we will continue to hold such information only for the purpose of not sending you undesired communications.

Transfer of personal data to third parties

We do not transmit your personal data to third parties, except where necessary to carry out your order or in the context of the performance of our services. The third parties to whom your personal data is transferred in this way are not entitled to use it for other purposes.

Links - References to other websites

This Website may contain links or references to other websites which are outside our control. The placement of these links has been done for the sole purpose of facilitating visitors/users while browsing the internet.

Please note that we do not control these websites and that the Privacy Notice does not apply to them. We advise you to read the privacy statements and terms and conditions of the linked or referenced websites you visit.

Access by using the links provided to the website in question is at the sole risk of the user.

Will we update this privacy policy?

We may update this Policy from time to time in order to reflect changes in law, third-party vendors, technologies we use etc. The Company reserves the right to amend, update, revise, or otherwise change this Notice from time to time as it deems necessary, without prior notice in accordance with the law.

Therefore, please re-visit this Policy regularly to stay informed.

April 2025