Privacy policy

Personal Data Protection Policy

One of our company’s main priorities is the protection of your personal data, which it processes in strict compliance with applicable legislation on the Protection of Personal Data.

We urge you to read carefully this personal data protection policy to be adequately informed on the type of personal data we process.


1. General information and controller

The company “Gelasakis Tourism, Hotel SA”, with head offices at 6 Aristidou Street, PC 18531 Piraeus, TIN 997570880 (Tax Office: FAE of PIRAEUS), as legally represented (hereinafter referred to as the “Company”), is the controller responsible for the collection, retention and general processing of the personal data of users, as such data are collected and retained through this website as well as the social media sites linked to our website.


2. Which personal data are collected and how

We collect and process your personal data as follows:

- Information about your reservations

When you make a reservation on our website you will be asked to provide your name, email address, phone number and payment details. We may also ask you for your residential address, your date of birth and the names of any additional drivers. Upon receipt of the car, we will ask you for an identification document (e.g. ID / passport), your driver’s license and your bank card. The relevant information will be kept for 10 years. The provision of the above information is voluntary. However, we may not be able to serve you if you do not provide us with the information necessary to complete your reservation.

If you make a reservation on behalf of someone else or add someone as an additional driver, please make sure that these people know that you are giving us their personal data and that they have been informed about this policy.

- Information about your registration as a user on our website

You can create a user account. To do this you will be asked to provide your name, e-mail address and password. Your registration allows you to manage your reservations, take advantage of our offers and manage your personal settings and preferences.
It also makes the process of future reservations and personalized offers easier.

- Information when contacting us.

If you visit our website and have a question or comment, you can submit it to our Company by completing the contact form available on our website. You will be asked to provide your name, e-mail address as well as information about your request, question or comment. We will only use this information to reply to your question or comment. We will record your requests, questions and comments and our respective responses and any other actions for the management of your request / communication. All information shall be kept for 36 months after your question or complaint has been settled or the case has been closed.

- Information when you have provided your e-mail so we can send you our newsletter.

We will use your e-mail address to inform you on the products, offers and services that we provide. You have the option to revoke the relevant consent at any time.

- Information about your visit and use of our website

We collect certain information when you visit our website such as your IP address, device category, browser, and web browser type. The information about your use of our website and our services allows us to make categorizations, i.e. to form groups of visitors to the website or customers with certain common characteristics, such as age group, sex or region. We may add you to one of our categories. We use the categories to personalize the website (e.g. to be displayed in your preferred language). We use these personal data as required in the context of our legitimate interests, in order to be able to promote our products and services to the consumers and visitors of our website, to be able to attract more consumers, and to improve the sales of our products and services. We retain personal data for a maximum period of five (5) years.

- Information on the maintenance and optimization of our website

Your personal data shall also be used for the maintenance and analysis of our website, in order to resolve performance issues, improve availability and user’s experience. We record every use of our website. Using your personal data for these purposes is necessary in the context of our legitimate interests and information is retained for a maximum period of 24 months. Records of the use of the website shall be deleted within 24 months.

- Information when you participate in campaigns, prize draws and contests.

If you take part in contests, prize draws or other events or campaigns, you will be asked for your name, e-mail address, telephone number and the answers to any open questions of the contests. We need this information to process your participation and to be able to contact you about your prize. You may be asked for your residential address or other information that may be required to send you the prizes, tickets or products by post. All information related to your participation in our campaigns, prize draws and contests are kept by us for a maximum period of 12 months after the end of the contest. The information will not be used for other purposes unless you have been explicitly informed of such purposes and / or your consent has not been previously requested. We would to inform you that we also collect information from the Company’s social media (e.g. Instagram, Facebook, Twitter), (e.g. for participation in the Company’s contests) which are necessary for the registration or connection, for which you have given to the social media provider permission to share with us, such as your name and your e-mail address. The collection of other information may depend on the privacy settings you have set with the social media provider, so you are asked to please read the privacy statement or the privacy policy of the relevant service. Your personal data, collected in the context of social media contests shall be kept for 12 months.


3. Processing purposes

a. Car reservations: We use your personal data in order to complete your reservation and ensure the provision of the services you have requested.

Legal basis of processing: Performance of contract.

b. User registration: We use your registration data so that you are able to manage your reservations, your personal settings and preferences.

Legal basis of processing: Your consent. You have the right to withdraw your consent at any time by sending an email to dataprotection@gelasakis.com, without affecting the lawfulness of our processing of such data prior to the withdrawal of your consent.

c. Support of information systems / improvement of services provided: We use your personal data in order to detect problems in the server and ensure the proper functioning of our website. The Company uses the personal data of users, collected by it through the website, in order to offer new services through the website or improve the services already provided.

Legal basis of processing: The legitimate interest of the Company to ensure the smooth operation of its website and to improve the services provided by it.

c. Compliance with our legal obligations: When we receive respective orders from courts or public authorities, we may process your personal data in order to respond to such requests.

Legal basis of processing: Compliance with our legal obligations.

d. Conducting company contests: We process the personal data that you submit through the website and social networking sites for your participation in contests of the company.

Legal basis of processing: Performance of contract (by participating in the contest you accept the contest terms and you conclude a contract with the Company).

e. Legal protection of the company: Ensure application of the terms of use of our website and protection of our legal rights.

Legal basis of processing: Legitimate interests of the Company.

f. Responding to your request, question or comment: We make every effort to respond to your request, question or comment, submitted on your own initiative via the contact form.

Legal basis of processing: Your consent. You have the right to withdraw your consent at any time without affecting the lawfulness of our processing of such data prior to the withdrawal of your consent.

g. Sending newsletters: We send you a newsletter when there is a pre-existing contractual relationship between us or when you have given us your information for this purpose.

Legal basis of processing: legitimate interests of the company or your consent (for the revocation thereof applies what is mentioned above in b).  


4. Cookies

Cookies are small text files that contain small amounts of information, which are downloaded and can be stored on your user device, e.g. your computer, smartphone or tablet.  To see more information about the cookies we use and how we use them, please refer to the separate Cookies Policy.


5. Right of access, right to rectification, right to erasure, right to restriction of processing and right to data portability

You have the right to request access to your personal data processed by us or on our behalf. You have the right to rectify, erase or restrict the processing (as appropriate) of your personal data. You can exercise these rights by contacting us via email at dataprotection@gelasakis.com and submitting a respective request.

Please note that requests that do not meet the requirements set by the applicable legislation or the Company’s guidelines may be required to be re-drafted or may be rejected and that certain personal data may be exempted from such requests for access, rectification and erasure, in accordance with the applicable institutional framework. You have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and, in certain cases, we shall transmit your data to another controller, if this is technically feasible.

If you request to exercise your right, we will ask for more information to confirm your identity. In any case you can update or delete your user account at any time.


6. Right to object

You also have the right, in certain cases, to request from us to stop processing your personal data, but if there are compelling legal reasons, we shall continue to process your personal data. In any case, you have the right to object to the use of your personal data by us for the purposes of direct marketing, including profiling, and if you do so, we shall satisfy your request.

In case you have given to us your consent to use your personal data, you have the right to withdraw your consent, without this affecting the lawfulness of processing such data prior to the withdrawal of your consent.

Requests regarding the exercise of the above rights can be sent to the Data Protection Officer ("DPO") of the Company at dataprotection@gelasakis.com. You can also lodge complaints with the Hellenic Data Protection Authority regarding the exercise of your rights (www.dpa.gr).


7. Data retention

Personal data of users are retained only for the period necessary to fulfill the purposes for which such data were collected, in full compliance with applicable legislation. When the purpose of processing your personal data is completed, they shall be deleted. The specific data retention periods for each relevant processing purpose are given above.


8. How and with whom we share your personal data (recipients of personal data)

We may need to share your personal data with third parties to help us provide you with services and products and to manage our website. Such third parties are:

• Shared information systems within the group.

• The company / companies providing the rental car and / or related products and services (e.g. insurance). In order to achieve the purpose of your reservation, we must send your details to the company providing the car and the other related products you have requested (e.g. insurance).

• Payment service providers / financial institutions that we work with to settle your payment or payment guarantees. 

 

• Public / investigative authorities: we may share your personal data with public / investigative authorities if required by law (e.g. audit by tax authorities), by a court decision / order or if this is absolutely necessary for prevention, detection or prosecution for fraud and other criminal offenses or for defending our legal rights.

 

• Service providers, when required, to provide us with a service and to provide data analysis services (e.g. website hosting, website technical support).

• Service providers that help us organize campaigns and promotions: e.g. we may share your email address with third party advertising partners.

 

• In case Gelasakis SA sells to third parties all or part of the assets or shares of a group company to which personal data have been sent, your personal data may be provided to those third parties.

In those cases where the Company, as the controller, transfers your data to third party processors, on the one hand the Company itself determines the individual elements of the processing (manner, means, retention period, etc.) and on the other hand it signs a special contract with the processors in order to ensure that the processing is carried out in accordance with the applicable legal framework; that appropriate measures are taken to protect the confidentiality and security of personal data and that any natural person can freely and unrestrictedly exercise his rights.  

Such third parties may have their registered office in the European Union or in other countries of the European Economic Area or in other parts of the world. When we store personal data outside the EEA, we ensure an adequate level of protection of the transferred data. If we are going to transfer your personal data to a third country, i.e. to a country outside the EEA or to an international organization, you will be informed before their transfer, in accordance with the provisions of Article 13 par. 1(f) of the GDPR.

Finally, we may need to provide personal data to law enforcement agencies in order to comply with a legal obligation or court order.


9. Data security

The Company assures the users that it takes all appropriate technical and organizational measures for the security of their personal data, for ensuring confidentiality of their processing and protection against accidental or unlawful destruction/loss/alteration, prohibited dissemination or access and any other form of unlawful processing.

Although every effort is made to protect personal data, the Company cannot guarantee the security of the data transmitted through its website, as the transmission of information via the Internet can never be completely secure.

Our website may contain links to other websites. We are not responsible for the personal data protection practices, content and security of other websites that are not governed by this Personal Data Protection Policy and we therefore advise you to always carefully study the personal data protection policies in such websites. In addition, if you choose to share information from the website via social media, we advise you to read carefully the personal data protection policies of social media.


10. Applicable Law

Any dispute arising from the use of this website shall be subject to the exclusive jurisdiction of the Greek Courts.


11. Amendments

This Personal Data Protection Policy has been drafted pursuant to the provisions of the General Data Protection Regulation No. 2016/679/EU. In case of an update, all changes shall be posted on this website and shall bear a revision date.


12. Data Protection Officer

You can contact the Company’s Data Protection Officer for any issues relating to the processing of your personal data at: dataprotection@gelasakis.com