Privacy Policy
1. Introduction
This Privacy Policy explains how personal data are processed in connection with the Olive Suites website, direct bookings, guest communications, property access, security and accommodation operations at Akteou 32, Athens 11851, Greece. Olive Suites is currently a trading/website name and not a separate legal entity.
2. Data Controllers for Bookings
For information relating specifically to a reservation, the principal controller is the owner of the suite booked.
Guest-facing areas of the website may refer to Avraham Shafran as Avi Shaf and Hanoch Shafran as Han Shaf. These are display names only and do not change the identity of the relevant data controller.
| Controller | Suites |
|---|---|
| Avraham Shafran Akteou 32, Athens, Greece info@olivesuites.gr | KALAMATA Apartment — AMA 00003033042 HALKIDIKI Studio — AMA 00003033037 |
| Hanoch Shafran Akteou 32, Athens, Greece info@olivesuites.gr | ASPROLIA Suite — AMA 00003032975 KOLOVI Studio — AMA 00003032954 |
3. CCTV Controller
For CCTV operated at the property, the controller is Avraham Shafran, Akteou 32, Athens, Greece, info@olivesuites.gr.
4. Personal Data We Process
Booking information
- full name, email address and telephone number;
- check-in and check-out dates;
- selected suite and number of guests;
- booking reference, booking status and amount payable;
- coupon or promotional code where applicable;
- cancellation/refund information and reservation correspondence.
Payment information
Payments are processed through Stripe-hosted Checkout. We may receive payment status, payment reference, amount, refund status and limited payment metadata made available to merchants. We do not intend to store full payment-card numbers in the Olive Suites booking database.
Website and technical information
Depending on enabled technologies, we may process IP address, browser/device information, server/security logs, cookie identifiers, consent preferences, booking-session information and technical diagnostic data.
Communications
When you contact us, we may process your name, email, telephone number, message content, booking details and correspondence.
Access control
The property uses code-based electronic locks managed with the Lockin Home application. Technical door-activity records such as opening times may exist. The lock is not intended to store Guest names, email addresses or telephone numbers.
CCTV
CCTV may record persons at entrances and designated common areas. CCTV does not operate inside Guest suites.
5. Purposes and Legal Bases
Reservation and stay: checking availability, creating the booking, taking payment, confirmation, check-in, providing accommodation, communications, cancellations and refunds. Legal basis: performance of a contract or requested pre-contractual steps.
Legal, accounting and tax obligations: short-term rental declarations, tax records and legally required records. Legal basis: compliance with a legal obligation.
Security, fraud prevention and legal rights: IT security, fraud prevention, disputes, protection of property and legal claims. Legal basis: legitimate interests and/or legal obligations where applicable.
CCTV: protection of people and property and investigation of security incidents. Legal basis: legitimate interests, subject to Greek and EU data-protection rules.
Optional future newsletter: marketing email will be sent only to persons who specifically opt in, unless another lawful electronic-marketing basis applies. Consent may be withdrawn at any time.
6. Privacy Policy Is a Notice, Not a Required Consent
You are not required to “agree” to this Privacy Policy as a condition of booking. Processing necessary to create and perform a booking is primarily based on the contract. Where we rely on consent, such as optional future marketing or optional cookies, consent is requested separately.
7. Recipients and Service Providers
- [PROPERTY MANAGEMENT COMPANY LEGAL NAME] — guest support, check-in, access assistance, maintenance coordination and stay management.
- Authorised technical administrator — operates and maintains the website and booking system.
- MongoDB cloud infrastructure — booking database, currently in AWS Frankfurt (eu-central-1), EU.
- Google Cloud — website/backend infrastructure.
- Resend — transactional email delivery.
- Stripe — online payments and refunds.
- [EMAIL HOSTING PROVIDER — TO BE CONFIRMED; DOMAIN REGISTERED THROUGH DNHOST.GR] — mailbox hosting.
- Accountant/tax adviser — information reasonably required for tax, accounting and statutory short-term rental reporting.
- Authorities — Greek tax authorities, courts, law enforcement and competent public bodies where legally required or permitted.
8. Cleaning Personnel
Cleaning personnel normally receive only operational information, such as which suite requires cleaning and when. They are not intended to receive Guest names, email addresses or telephone numbers unless a specific operational need arises.
9. International Transfers
Some providers may process or access data outside the EEA. Where GDPR applies and such transfers occur, we will rely on an appropriate lawful transfer mechanism such as an adequacy decision, Standard Contractual Clauses or another valid mechanism.
10. Data Retention
- Unsuccessful general enquiries: normally up to 12 months after the last substantive contact.
- Booking and Guest records: normally up to 5 years after the end of the stay, unless longer retention is required for tax, accounting, claims or statutory purposes.
- Accounting and tax records: for the period required by Greek law.
- Cancelled bookings: for the period reasonably necessary for payment, refund, dispute, tax and legal issues.
- Failed/abandoned booking records: deleted or anonymised earlier where no longer reasonably required.
- Newsletter data: while subscribed, with evidence of consent/unsubscribe retained for an additional reasonable compliance period.
- Electronic access logs: for a limited security/operational period unless connected to an incident or legal claim.
11. CCTV Retention
CCTV recordings are retained for the shortest period reasonably necessary. As a general operational ceiling, recordings should not normally be retained for more than 15 days, unless a shorter period is required for the legal classification of the monitored common area or a specific incident justifies longer retention. Relevant incident footage may be retained longer where necessary as evidence or for legal claims. Appropriate CCTV signage will be displayed before monitored areas.
12. Cookies and Similar Technologies
The website uses cookies and may use similar technologies. The separate Cookie Policy explains them and how to manage preferences. Optional cookies or trackers requiring consent will not be activated before consent is obtained.
13. Your Rights
Subject to applicable conditions and limitations, you may have rights to access, correction, deletion, restriction, objection, data portability, withdrawal of consent and complaint to a competent supervisory authority.
14. Exercising Your Rights
Send requests to info@olivesuites.gr. We may request reasonable identity verification where necessary to prevent unauthorised disclosure.
15. Supervisory Authority
You may lodge a complaint with the Hellenic Data Protection Authority or another competent supervisory authority where GDPR permits.
16. Security
Reasonable technical and organisational measures are used, including restricted access, account security, encrypted communications where available, cloud/database security, backups, access control and data minimisation. No internet-connected system can be guaranteed completely secure.
17. Changes
This Privacy Policy may be updated where services, providers, technology or legal obligations change. The current version will be published on the Olive Suites website with its effective date.