PRIVACY POLICY
Last updated: [01.2026]
This Privacy Policy explains how Skopelos Experience (“we”, “us”, “our”) collects, uses, and protects personal data when you visit https://skopelosexperience.gr/ (the “Website”), in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Greek/EU data protection laws.
1) Data Controller (Who is responsible)
Data Controller: [Skopelos Experience]
Registered address: [Skopelos]
Email: [hello@skopelosexperience.gr]
Phone: [6937068251, 6973507650]
2) What personal data we collect
Depending on how you use the Website, we may collect:
A. Data you provide voluntarily
- Contact details (e.g., name, email, phone number)
- Message content submitted via contact forms or inquiries
- Reservation/request details (if you submit a booking request)
B. Data collected automatically
- IP address (may be stored in logs)
- Device and browser information
- Pages visited, time spent, referrer URL
- Cookie identifiers and consent preferences (via our cookie consent tool)
3) How we collect data
We collect data through:
- Forms you submit on the Website (e.g., Contact page)
- Cookies and similar technologies (see Section 8)
- Server logs and security tools
- Embedded content and third-party services (only if enabled/consented)
4) Purposes of processing & legal bases
We process personal data for the following purposes:
- To respond to inquiries / requests
- Legal basis: Legitimate interest (GDPR Art. 6(1)(f)) and/or steps prior to a contract (Art. 6(1)(b))
- To provide services and manage reservations/requests (if applicable)
- Legal basis: Contract / pre-contract steps (Art. 6(1)(b))
- To improve the Website and user experience (analytics, performance)
- Legal basis: Consent (Art. 6(1)(a)) where required for analytics/marketing cookies
- To ensure security, prevent fraud and abuse
- Legal basis: Legitimate interest (Art. 6(1)(f))
- To comply with legal obligations
- Legal basis: Legal obligation (Art. 6(1)(c))
5) Who we share data with (Recipients)
We may share personal data with trusted service providers acting as processors under GDPR, only as necessary, such as:
- Website hosting provider / IT support
- Email service provider (for receiving and replying to messages)
- Cookie consent management platform (we use a consent tool on the Website)
- Analytics providers (only if enabled and/or consented)
We do not sell personal data.
6) International data transfers
Some third-party providers may process data outside the European Economic Area (EEA). Where this happens, we ensure appropriate safeguards, such as:
- EU Commission adequacy decisions, and/or
- Standard Contractual Clauses (SCCs), and/or
- other lawful transfer mechanisms under GDPR.
7) Data retention (How long we keep data)
We keep personal data only for as long as necessary:
- Contact form inquiries: typically up to [e.g., 12 months] after the last communication, unless required longer for legal claims.
- Reservation requests (if applicable): for the duration of the service and for [e.g., 5 years] where needed for legal/tax purposes (adjust based on your process).
- Analytics/cookie data: according to the settings of each tool and your consent choices.
8) Cookies & consent management
We use cookies and similar technologies to operate the Website and (optionally) to analyze traffic and improve performance.
You can manage your preferences at any time via the cookie banner and/or the cookie settings on our Website.
9) Embedded content & social media links
The Website may include links to social media pages (e.g., Facebook, Instagram) or embedded content. Third-party platforms may collect data according to their own privacy policies. We encourage you to review those policies when you leave our Website.
10) Your rights under GDPR
You have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase data (“right to be forgotten”), where applicable
- Restrict processing
- Data portability (where applicable)
- Object to processing based on legitimate interest
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with a supervisory authority
Greek supervisory authority: Hellenic Data Protection Authority (HDPA) – https://www.dpa.gr/
11) How to exercise your rights
To exercise your rights, contact us at: [hello@skopelosexperience.gr]
We may request verification of identity before fulfilling requests.
12) Security
We apply appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. However, no online system can be guaranteed 100% secure.
13) Children’s privacy
Our Website is not intended for children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, please contact us to remove it.
14) Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be posted on this page with an updated “Last updated” date.
15) Contact
For any questions about this Privacy Policy or your personal data, contact:
[Skopelos Experience]
Email: [hello@skopelosexperience.gr]
Address: [Ditropon, Skopelos]
Phone: [6937068251, 6973507650]