Privacy Notice

Last Updated: May 24th, 2018

At XENODOCHIAKES EPIXEIRISIS ELECTRA A.E, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to XENODOCHIAKES EPIXEIRISIS ELECTRA A.E.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://electrapalacethessaloniki.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to XENODOCHIAKES EPIXEIRISIS ELECTRA A.E.

Data Controller

XENODOCHIAKES EPIXEIRISIS ELECTRA A.E operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Electra Palace Thessaloniki “XENODOCHIAKES EPIXEIRISIS ELECTRA A.E”
9 Aristotelous Sq.
546 24, Thessaloniki
GR

The User may contact our Data Protection Officer:

Data Protection Officer
dpo@electrahotels.gr

Data Processor

WebHotelier operates this booking system on behalf of XENODOCHIAKES EPIXEIRISIS ELECTRA A.E and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of XENODOCHIAKES EPIXEIRISIS ELECTRA A.E, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at XENODOCHIAKES EPIXEIRISIS ELECTRA A.E;
  • to pass on your financial details to XENODOCHIAKES EPIXEIRISIS ELECTRA A.E and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

This privacy policy governs your use of websites and services of ELECTRA HOTELS & RESORTS GROUP , members of which are XENODOCHIAKES EPIHIRISIS ELECTRA S.A., 5, ERMOU STREET,105 63 ATHENS – GREECE, XENODOCHIAKI KAI TOURISTIKI ETERIA ELECTRA S.A., 18-20, N. NIKODIMOU STREET, 105 57 ATHENS – GREECE, XENODOCHIA ELECTRA S.A., BRANCH, 5 ERMOU STREET, 105 63 ATHENS – GREECE and XENODOCHIAKES EPIHIRISIS AGIA DINAMIS S.A., 15 MITROPOLEOS STREET, 10557, ATHENS – GREECE, companies incorporated under the laws of Greece ("société anonyme") with their registered seats located as above, hereinafter the "E.H & R", "we", "our", "us", for its own benefit and the benefit of the Group’s members and their affiliates and hotels (each "a Hotel" and collectively "the Hotels") and resort properties owned by ELECTRA HOTELS & RESORTS GROUP.

By accepting our privacy policy and terms and conditions, you acknowledge that you have read and agree to be bound by this Privacy Policy. These terms may be amended, updated or otherwise modified, whether in whole or in part, at any time.The personal data, optional and compulsory, that you need to provide when you enter the web site or register for various applications related with services and products provided by ELECTRA HOTELS & RESORTS GROUP and any additional personal data that will be requested in later stages are collected, processed, transferred, stored and used by ELECTRA HOTELS & RESORTS GROUP , under its capacity as data controller, for the benefit of the members of the Group and their hotels and affiliates as well as by service providers, including the data processors and service providers as they are described below.

1. Information we collect about you and how we collect it.

1.1 User Provided Information

ELECTRA HOTELS & RESORTS GROUP obtains the information you provide when you proceed in general with actions for accommodations in our hotels, stay in an Electra Hotel or Resort, conduct business, opted in to receive news and offers from Electra Hotels & Resorts and use Applications related to our services, through our web sites, reservation and call centers, social media, when you otherwise voluntarily provide it to us, including in connection with our loyalty program and from Electra Hotels & Resorts Group subsidiaries, Hotels, or other third parties. When you download and register to such an Application which is optional, please keep in mind that you may not be able to use some of the features offered by the Applications unless you register. When you register or use our web sites and / or an Application, you are required to provide certain personal data (such as your first and last name, email address, password etc.) by filling in the fields identified as mandatory in the registration form on the login page or document.

You will also be asked to provide personal information for special purposes as when making a reservation through our Call Center or Hotels, during your stay at a Hotel or Resort etc. among others

contact information, such as your name, mailing address, e-mail address, and telephone number;

credit card number or other payment account number, billing address, and other payment and billing information (“Payment Information”);

Electra Rewardsloyalty program member information, online user account details, profile or password details and any frequent flyer or travel partner program affiliation;

records and copies of your correspondence if you contact us;

information necessary to fulfil special requests (e.g., health conditions that require specific accommodation);

guest stay information, including date of arrival and departure, and goods and services purchased;

information collected through the use of closed circuit television systems, card key and other security systems; and

in limited cases, information relating to the credit of customers.

We may collect Personal Information from a variety of sources including:

through the Site;

through reservation and call centers;

through social media and brand channels (e.g. Facebook, Twitter);

from ELECTRA HOTELS & RESORTS Subsidiaries and from Licensed Hotels, Affiliates, or other third parties; or

when you otherwise voluntarily provide it to us, including in connection with our loyalty program (i.e. Electra Rewards).

Providing your sensitive personal data is optional and you may still be able to use the web sites and / or the Applications and all of its features. We may also use the information you provided us to contact you from time to time to provide you with important information, required notices and marketing promotions, under the condition that you give us your consent with a direct opt in a relevant specific request of our, noting to you that you can opt out at any time of by sending us an email at privacy@electrahotels.gr 

Accepting our services and products and the use of our web sites and / or our related with ELECTRA HOTELS & RESORTS Applications you give us the explicit consent to collect, process, use and store your personal data according to the applicable laws and this contract.

1.2 Minors.

The use of the web site and / or our Applications is not intended for use by minors under the legal age requirement. No one under the legal age requirement may provide any personal information to or through our web site and / or our Applications. We do not knowingly collect personal information from minors. If you are under the legal age requirement, please do not visit our web sites, don't register to our Applications, don't make any use of the above or send any information about yourself to us, including your name, address, telephone number or email address. In the event that we find out that we have collected personal information from a minor without verification of parental consent, this information will be deleted, upon the minor’s parent or guardian notification. If you believe that we might have any information from or about a minor, please contact us at privacy@electrahotels.gr .

To the maximum extent permitted by applicable law and without limiting any other provision of this Policy, ELECTRA HOTELS & RESORTS GROUP disclaims any liability for any personal data submitted in contravention of this clause.

2.Purposes of processing

We collect, process, use and store your personal data:

            To authenticate you when log in to our web sites, our Application and wi-fi;

            To fulfill of reservation or information requests and to remember your preferences and registration information;

            For membership programs as Electra Rewards program   

            To provide our services to you

            To measure and obtain data for administrative and other communication purposes and in order to operate and improve the effectiveness of our services, our web sites and the Programs and Applications related the operations of ELECTRA HOTELS & RESORTS GROUP;

            To comply with applicable law;

            To support IT purposes;

            To support operational procedures;

3. Data sharing and transfers

3.1. Privacy Policy & Data Processing: Your personal data are gathered, filed and processed by ELECTRA HOTELS & RESORTS GROUP exclusively for the purposes of providing our services to you according to the applicable laws. By accepting the terms here of you give your explicit consent to ELECTRA HOTELS & RESORTS GROUP to transfer your personal data to ELECTRA HOTELS & RESORTS GROUP's Partners, that is to third natural or legal entities who provide you with services in combination or in addition to its services (specifically for transport services, internal or external activities, visits to places) and for reasons connected with the better provision of services of ELECTRA HOTELS & RESORTS GROUP to you.

3.1.1. We will share your information with third parties only as described in this Privacy Policy. We might share personal information about you outside ELECTRA HOTELS & RESORTS GROUP where a) it is required or authorized by law; b) it is required to provide you with services that you have requested, in which case you will be considered to have given your consent (i.e. car rental, restaurant reservation, reward programs, tours or visits arrangements, ticket purchases); c) if your stay has been paid for by a third party we will provide billing information to the paying party; d) if you have failed to pay owed amounts.

3.1.2. We may disclose User Provided and Automatically Collected Information:

            With government or law enforcement authorities, where required by applicable law in order to comply with any court order or other legal obligation, or respond to a government request;

            When we consider in good faith that disclosure is necessary to protect our rights or property, protect your safety or the safety of others or to investigate theft or fraud;

            With Service Providers and data processors which we use in order to execute and improve our services and support our business;

            For the purposes of special programs, according to the more specific terms and conditions if/when you choose to participate.

            With our suppliers and third partiesfor delivering our goods and services to you, storing and processing data or sending emails. From these third parties we require to protect your personal information with reasonable security measures and to limit their use only to the purposes for which we have disclosed it to them. This Privacy Policy does not describe the collection, use or disclosure of information by third parties that you contact for services related to ours, for which you have to inform about their Privacy Policies.

3.1.3. The Site may contain links to third-party websites operated by parties other than ELECTRA HOTELS & RESORTS GROUP. These linked sites are not under ELECTRA HOTELS & RESORTS GROUP's control, and ELECTRA HOTELS & RESORTS GROUP is not responsible for the operation, content, privacy practices or the security of any such linked site (or any link contained in any linked site). You are responsible for reading and complying with the privacy statements and terms of use posted on these linked sites. We provide such links only as a convenience, and the inclusion of a link on the Site does not imply endorsement of the linked site by ELECTRA HOTELS & RESORTS GROUP or ELECTRA HOTELS & RESORTS GROUP affiliates. If you decide to access any of the third-party websites linked to this Site, you do so entirely at your own risk and subject to the terms and conditions of use and privacy policies for such websites. If you provide any Personal Information through any such third-party website, your Personal Information will be treated in accordance with the privacy policy of that third party. ELECTRA HOTELS & RESORTS GROUP may also partner with a limited number of Internet providers to offer Internet access to our guests. Your use of on-property Internet service is subject to the third-party Internet provider’s terms of use and privacy policy. You can access those terms and policies using the links on the service sign-in page, or by visiting the Internet provider’s website.

3.2.1. Business Partners: We may partner with other persons or companies jointly or separately to provide you with products, services, or offers based upon your experiences at our properties and may share your information with our business partners accordingly. For example, we may help, after having been asked from you and informed you about, to arrange among others rental cars or other means of transport, external activities, visits to places or other services from our business partners, and share personal information with our business partners in order to provide those services.

These Suppliers independently provide their services, it will be clearly stated that their services do not concern us and may include other hotels, airlines, car rental companies, service providers, companies that organize package tours or bookings. All services provided by third parties are characterized in this way and are not related to our own services. Therefore, we encourage you to read the privacy policies and rules of providing the things and services of all third part service providers whose products or services you acquire through this website or through any or our employees. Keep in mind that these third parties may also contact you if they need to ask for additional information about you providing their services or responding to a request you have submitted. We are not responsible for any communication will be directly with them and you. ELECTRA HOTELS & RESORTS GROUP and its affiliates expressly disclaim any liability and the under- accepting guest hereby waives any claims which may be brought against the same for any kind of loss, injury or any kind of damages resulting from the services provided by the as above independent providers of services or goods.

3.2.2. Service Providers: We rely on third parties to provide services and products on our behalf and potentially share your personal information with them, as the case may be. In general, our service providers are required by law to protect your personal information and may not use or share your personal information unless required by law. We may also share your information with service providers and third partners so that you can create visiting programs by selecting sights visits and other activities from the lists we have configured for you according to your preferences and third party information.

3.2.3.Social Networking Providers: When using certain social media features through our website or apps, you share information with your social media provider (such as Facebook) and the information you share will be governed by their own policies privacy (including the possibility of having access to such information through the social media provider). You may be able to change your privacy settings for these social media providers. Please consult the relevant social media provider's privacy policy for further information.

Third-party social networks that provide interactive activities, plug-ins or social networking features (e.g., to allow you to connect to Facebook or Google to find friends to add as connections or to "Like" a page) may use cookies or other methods (e.g., web beacons) to gather information regarding your use of our website and apps. The use of such information by a third party depends on the privacy policy available on that social network’s website, which we encourage you to carefully review. Such third parties may use these cookies or other tracking methods for their own purposes by relating information about your use of our site with any of your Personal Information that they may have. We may also obtain analytics information from social networks that help us measure the effectiveness of our content and advertisements on social networks (e.g., impressions and clicks).

4. Data Retention Period

We will retain User Provided data for as long as you use our web sites and / or our Application and for a reasonable time thereafter so as to fulfill the afore mentioned purposes or to respect any applicable laws or statutes of limitation or terms of this Policy. We will retain Automatically Collected information for up to 12 months and thereafter may store it in a non identifiable aggregate form.

5. Security

We implement appropriate technical and organizational measures to reasonably protect your personal data against unauthorized and unlawful access and processing or accidental loss, destruction, damage, theft, use or disclosure.

The safety and security of your information also depends on you. Where we have given you or where you have chosen a password for access to services through our web sites and/ or our Applications, you are responsible for keeping this password confidential. We request you not to share your password with anyone else.

We make every effort to ensure as fully as possibly the secure use of our web sites or our Applications. (It is important to note that any e-mail communication is not secure. This is a risk inherent in the use of e-mail. Please be aware of this when requesting information or sending forms to us by e-mail. We recommend that you do not include any confidential information (i.e. credit card information) when using e-mail. For your protection our e-mail responses to you will not include any any confidential information).

6. Changes to the Privacy Policy

To improve our services we may require amendments to this Privacy Policy – e.g. by the implementation of new technologies or the introduction of new features and services. We reserve the right to change, update or supplement this Privacy Policy at any time. . You are also advised to consult this Privacy Policy regularly for any changes. If you continue to accept our services and / or use the related applications after we have posted modified Terms, you are indicating to us that you agree to be bound by the modified Terms. If you don’t agree to be bound by the modified Terms, then you may not use our web site or Applications after such modifications have been made.

7. Jurisdiction

It is explicitly agreed that the Courts of Athens, Greece applying the laws of Greece shall be exclusively competent for the resolution of any dispute, claim, interpretation or controversy arising out of or relating to the Terms of this privacy Policy.

8.Your Rights

According to applicable laws, you have the right to information, access, rectification, blocking, and/or requesting deletion and objection to processing, to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal, to lodge a complaint with the supervisory authority (Hellenic Personal Data Protection Authority) and to data portability, in relation to the processing of your personal data.

If you have any questions regarding your privacy while using our websites and / or services and / or Applications, or in case you want to exercise your rights, please contact us via email at privacy@electrahotels.gr.

9. Your Consents

By accepting this Privacy Policy you grant your explicit consent and you accept the processing and use of your personal data, as set forth and for the purposes described in this Privacy Policy.

 

For the Terms of Use please click here