Privacy Statement

 

This Privacy Policy was last updated on June 25, 2021.

At Astra Village Hotel & Spa, we consider the privacy and confidentiality of user information very important.

The personal information security and privacy policy of “ASTRA VILLAGE Hotel” is in force and effective for any personal information provided or collected by the hotel, either via this website or via the hotel’s digital application (app) for smart phones and tablets either directly or by telephone or in any other way (e.g. making on-line reservations, sending and receiving e-mail messages in order to communicate and check the availability of a reservation or in order to receive information relating to the hotel or the reservation, etc.). Returning your trust, we assure you that the safety and confidentiality of the personal information you disclose to us constitutes our highest priority.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Astra Village Hotel & Spa

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://astravillage.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Astra Village Hotel & Spa

Data Controller

Astra Village Hotel operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Astra Village Hotel (Kouvielos Panagiotis AXTE)

Ammes, Svoronata

281 00, Kefalonia

GR

The User may contact our Data Protection Officer:

Data Protection Officer

akouvielou@astra-village.com

Data Processor

WebHotelier operates this booking system on behalf of Astra Village Hotel & Spa and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited

Mnasiadou 9 (Demokritos Building, Office 16)

1065 Nicosia

Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Astra Village Hotel & Spa, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier’s Data Protection Officer:

Data Protection Officer

dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment or deposit;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose

In General: We receive and store all information you enter on our website or which you provide in any other way (e.g. by e-mail) or via a reservation you make using a tour operator or travel agency or the Internet platform by an independent provider facilitating hotel reservations (it is obvious that we are the recipients of the reservation information you have provided the platforms or tour operators/travel agencies to make a reservation at our hotel). This includes information by which we can identify you, such as your first name and surname, your telephone number, your postal and digital addresses, as well as billing information (such as your credit/debit card number, the name of the card holder and its expiry date). You may also enter/we may request information on your room preferences. You may choose not to provide information to us, but most information we request from you is generally required to complete a reservation.

Travel companion information: When you make a reservation that includes some other (travel companion) via our website, we shall request personal and or traveling information for said individual. You must obtain this other individual’s consent before you give us their personal information and travel preferences, since access for the display of said information or possible changes to them shall be available only via your account (or your reservation code).

Social Media. Should you use any of our hotel’s social media, either on our website or via a social networking provider, we may gain access to your personal information via this social networking provider and in accordance with said provider’s policies. For example, our website offers the option to register using the function “Facebook Login”, allowing you to register on our website using your Facebook account information, without entering on your own the information required on our website. When you use a social networking function, we may potential gain access to the information you provide by means of it, such as your name, profile avatar, sex, birthday, your e-mail address, your city, town or region, as well as any other information you have chosen to render available via the social networking medium.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Astra Village Hotel & Spa
  • to pass on your financial details to Astra Village Hotel & Spa  and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

This term refers to data which reveal an individual’s racial or ethnic origin, their political beliefs, religious or philosophical convictions or participation in a trade union, as well as biometric data aimed to the indisputable identification of an individual, data relating to the health or information regarding the sexual life and preferences of a natural person or their gender orientation. In general terms, we do not collect sensitive data unless you voluntarily provide them. We may potentially utilize data on the state of your health, provided exclusively by you, in order to better serve you and satisfy your needs (for example, catering to offer access to the facilities for the disabled).

Use of Services by Minors

We do not knowingly collect personal information from individuals under 18 years. As the parent or legal guardian, you should not let children submit personal information without your permission.

Share Data

If you have given us your consent, we may share your information with the following entities:

– Car rental companies and activity providers. All services rendered by third party suppliers are classified this way. Consequently, we encourage you to review the privacy policies of all travel suppliers, whose products you may purchase through this website or through any other of our applications. Do take into account that said suppliers may also contact you, if needed, to obtain additional information about you, to assist you with your travel booking or to respond to a review you may have submitted.

– Third party service vendors who render services or functions on our behalf, including the processing of credit cards, business analytics, customer service, booking, marketing, survey distribution/raffle programs and fraud prevention. We may also authorize third party vendors to collect information on our behalf, as well as to assist, as necessary, with the operation of features of our website or applications (Apps) or to facilitate the distribution of on-line advertisements, tailored to your interests. Third party service providers have access to and may collect information, only when needed, in order to perform their functions, whereas they are not permitted to share or use said information for any other purpose. They are also obliged to follow and observe the same or of equal level data security practices that we adhere to. Take account of the fact that said third party service vendors may be established in countries where the level of protection afforded for personal information may not be equivalent to that offered in your country of residence. However, we will try and protect all personal information collected from you pursuant to strict data protection standards.

– Referring websites: If some other website referred you to this one (for example, through a link on some other website that you clicked to be “directed” to this one), we may share certain information about you with the referring website. We encourage you to review the privacy policy of all websites that referred you here, since we are not liable or to be held responsibly for the personal information processing that is carried out by them.

– Social media providers: When using certain social media functions through our website or applications (Apps), you share information with the social media provider (such as Facebook) and the information you share will be governed by said provider’s privacy policies (including the possibility of us having access to such information via the social media provider). You may be able to modify your privacy setting for those social media providers. Consult the privacy policy of the relevant social media provider for more information, since we are not liable or to be held responsible for the personal data processing performed by the social media provider.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

Processing Purpose

  •          Reservations: We use the User’s personal information to process and handle  online reservations including payment management (where applicable), as well as reservations made in person or over the phone.
  •     Customer service: During your stay with us, we utilize your personal data to offer customer service and to enhance our services.
  •     Marketing activities: We also use your data for marketing activities, as permitted by law. Where we might use your personal data for direct marketing purposes, such as commercial newsletters and marketing communications on new products and services or other offers which we think may be of interest to you, we include an unsubscribe link that you can use if you do not want us to send messages in the future
  •         Other communications: There may be other times when we get in touch by email, by post, by phone or by texting you, depending on the contact data you share with us.
  •     Analytics, improvements and research: We may enlist the help of a third party to complete this task on our behalf. We may share or reveal the results of such research in anonymized, aggregated form, including to third parties. We utilize your personal information for research, to improve our services, to improve the user experience, and to improve the functionalities of our website

Google Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses cookies (text files placed on your computer) to help the website operators analyse how users use the site. The information generated by the cookie about your use of the website (including your IP address) will be transmitted to and stored by Google on servers in the United States. Google will use this information for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing other services relating to website activity and internet usage. Google may also transfer this information to third parties where required to do so by law, or where such third parties process the information on Google’s behalf. Google will not associate your IP address with any other data held by Google. By using this website, you consent to the processing of data about you by Google in the manner and for the purposes set out above.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

User’s Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

You can access and update your contact information by contacting us at the e-mail address cited below. When you provide your personal information to us through this website, our Internet application (App) for smart phones and tablets, as well as in any other way (for example, by contacting us in person, over the telephone, via a third party website or tourist agency), this entails that you accept to allow us store and process this personal information for reasons relating to your reservation and, in general, for the reasons that have been cited above. We may continue to process information that relates to your account and reservation in order for us to fulfill our lawful business objectives and to comply with our statutory and regulatory obligations, as well as to keep historic records and for analysis. Keeping your data shall last for as long as it is imposed by legislation for reasons of our own legal assurance, for keeping a reservations archive and for tax reasons. Said keeping of data shall not last for more than five years, save if otherwise dictated by legislation or our contractual obligation (e.g. taxation, banking).

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Cookies & Other Technologies

Cookies are small text files installed on your computer or mobile device, when you visit almost all websites. Cookies cannot reveal your identity or cause any harm to your computer or mobile device. They are used by the websites you visit to improve your browsing experience, to provide web analytics information to us, that will help us to generally improve our website, and to collect information regarding travel destinations of interest to you, so that you may see travel ads that better fit your wants and needs. In any case, the collection of anonymous data using “cookies” shall take place only provided you have stated that you accept their use.

Data Protection

We want you to feel comfortable when using this website and our applications to make a reservation and we are committed to protecting the information we collect. Although no website or application can guarantee absolute safety, we have introduced the appropriate safety procedures (administrative – organizational, technical and physical) to assist us in the protection of the information you provide to us. For example, only authorized employees may access personal data and they may do so only for the permitted business functions. Additionally, we utilized encryption methods when transmitting your personal information between your system and ours, while we also utilize a firewall and Intrusion Detection Systems (IDS) in order to prevent unauthorized persons from gaining access to your information.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Representative: IRENE KOUVIELOU

Data Protection Officer: ANNA KOUVIELOU

E-mail: akouvielou@astra-village.com

Postal Code 28100

SVORONATA, KEFALONIA

Tel.: 26710 42336 – 7

 
 
 
 

Read more about our: Terms & Conditions as well as our Cookie Policy.

Book Now