Privacy Policy
Privacy Policy
Last updated: August 2026
At Caviro Apartments & Residence, we respect your privacy and are committed to protecting your personal data. This Privacy Policy explains what personal data we collect, why we collect it, how we use it, and what rights you have under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and Greek data protection legislation, including Law 4624/2019.
1. Data Controller
The data controller responsible for the processing of your personal data is:
Caviro Apartments & Residence
Sole proprietorship
VAT ID (ΑΦΜ): 045472430
GEMI No.: 137706942000
Moudros, Limnos 81401, Greece
Email: info@caviro.gr
For any privacy-related request, you may contact us at info@caviro.gr.
2. Personal Data We Collect
We may collect and process personal data when you visit our website, contact us, make a reservation request, or stay at our property. Depending on the situation, this may include:
- Contact and identification details: name, email, phone number, country, address, ID/passport details where required by law or for guest registration.
- Reservation and stay details: arrival and departure dates, number of guests, room type, special requests, communication history.
- Payment and invoicing details: payment method, transaction information, billing details. We do not intentionally store full payment card details on our website — bookings and payments are handled through the BookOnCloud platform.
- Communication data: messages sent through our contact form, email, or phone.
- Technical and website usage data: IP address, browser type, device information, pages visited — collected through cookies or similar technologies, depending on your consent choices.
3. Special Categories of Personal Data
We do not intentionally request or collect special categories of personal data (e.g. health information). You may, however, voluntarily provide related information (e.g. allergies, accessibility needs) — we process this only to the extent necessary to respond to your request.
4. How We Collect Personal Data
We collect personal data directly from you when you: use our contact form; send us an email; call us; make a reservation request; check in or stay at the property; interact with our social media profiles. We may also receive limited personal data from third parties involved in your reservation (e.g. booking platforms).
5. Why We Use Your Personal Data
We process your personal data to: respond to your inquiries and messages; manage reservation requests and bookings; provide accommodation services; complete check-in and guest registration; issue receipts and invoices; communicate with you before, during, and after your stay; handle special requests; improve our website and guest experience; protect the security of our website and business; comply with legal, tax, and tourism obligations.
6. Legal Basis for Processing
We process your personal data only when there is a valid legal basis under GDPR:
- Contractual necessity, when processing is necessary to manage a booking or provide accommodation services.
- Legal obligation, when required by applicable law (tax, accounting, tourism, guest registration).
- Consent, when you accept non-essential cookies or similar technologies.
- Legitimate interest, when processing is necessary for the normal operation of our business, communication with guests, website security, or service improvement.
7. Cookies, Analytics, and Third-Party Tools
Our website uses cookies and similar technologies. Depending on your consent choices, we may use:
- Google Analytics (via Google Site Kit) — for website traffic statistics.
- Other website security and optimization tools.
You can manage or withdraw your consent at any time using the “Manage consent” button on our website. These tools may collect technical information such as your device, browser, IP address, and pages visited. You can find more details in our separate Cookie Policy.
8. Contact Forms and Email
When you contact us through a form or email, we use the information you provide to respond to your message. Our website uses HTTPS encryption to protect communication between your browser and our website.
9. Sharing Personal Data with Third Parties
We may share personal data only where necessary, with:
- The booking/payment platform BookOnCloud;
- Accountants, tax advisors, or legal advisors;
- Website hosting, email, and technical service providers;
- Public authorities or tax authorities, where required by law.
We require any service providers processing data on our behalf to protect it in line with applicable law.
10. International Transfers
Some third-party providers we use may process data outside the European Economic Area. Where this happens, we rely on appropriate safeguards required by GDPR.
11. How Long We Keep Your Personal Data
We keep personal data only for as long as necessary for the purpose it was collected, unless a longer period is required by law. Reservation, accounting, and invoicing data is kept as required by Greek tax and accounting legislation (generally up to 5 years). General inquiry messages are kept for a reasonable period, and in any case no longer than necessary for the purpose of the communication.
12. How We Protect Your Personal Data
We take appropriate technical and organizational measures to protect personal data against unauthorized access, loss, or misuse — including HTTPS encryption, access restrictions, and regular review of our data practices.
13. Your Rights
Under GDPR, you have the right to: request access to your data; request correction of inaccurate data; request deletion, where legally possible; object to processing based on legitimate interest; withdraw consent; lodge a complaint with the competent authority. To exercise your rights, contact us at info@caviro.gr. The competent supervisory authority in Greece is the Hellenic Data Protection Authority (www.dpa.gr).
14. Children’s Personal Data
Our services are not directed to children using the website independently. Where a child’s data is necessary for a reservation or registration, it should be provided by a parent or guardian.
15. Data Breaches
In the event of a personal data breach, we will take appropriate steps to assess and limit it, and, where required by law, notify the competent authority and/or affected individuals within the time limits set by GDPR.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be published on this page with a new “Last updated” date.
For privacy-related questions, please contact us at info@caviro.gr.
