Skip to main content

Legal

Privacy Policy

Last updated: 8 March 2026

1. Introduction

Experience North Santorini ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website at experience-northsantorini.com (the "Site") and related services.

We are the data controller for purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Our contact details are provided in the Contact Us section below.

2. Data We Collect

CategorySpecific DataPurposeLawful Basis
Account InformationEmail, name, phone numberCreate and manage your accountContract performance
Booking DataDates, guest count, preferences, special requestsProcess and fulfil your reservationsContract performance
Contact FormName, email, phone, messageRespond to your enquiriesLegitimate interest
Payment DataCard details (processed by Viva, never stored by us)Process payments securelyContract performance
Technical DataIP address, browser type, device info, pages visitedSecurity, performance monitoring, abuse preventionLegitimate interest
Error MonitoringJavaScript errors, stack traces, anonymised session replaysIdentify and fix technical issuesLegitimate interest
AnalyticsPage views, referrer, anonymous visitor metrics, anonymised IP (Google Analytics)Understand site usage and improve our servicesConsent

3. How We Use Your Data

We process your personal data for the following purposes:

  • Fulfilling bookingsprocessing your experience, dining, spa, cruise, and transfer reservations.
  • Processing paymentssecurely handling transactions through Viva. We never store your card details on our servers.
  • Transactional emailssending booking confirmations, reminders, and cancellation notices via Resend.
  • Site securityprotecting against abuse, bot attacks, and fraudulent activity using Cloudflare and Cloudflare Turnstile.
  • Error monitoringidentifying and fixing bugs through Sentry (with all text masked and no PII collected).
  • Analyticsunderstanding how visitors use our site through Google Analytics 4 (with IP anonymisation) and Vercel Analytics (only with your consent).
  • Media deliveryserving optimised images and videos through Cloudflare R2 and Mux.

4. Cookies & Tracking

We use cookies and similar technologies to operate our site. You can manage your preferences at any time by clicking "Cookie Settings" in the footer or .

Strictly Necessary Cookies

These cookies are essential for the site to function and cannot be disabled. They include authentication tokens (Supabase), cart and trip planner storage (localStorage), and your cookie consent preference.

Analytics Cookies

With your consent, we use Google Analytics 4 and Vercel Analytics to understand how visitors use our site. Google Analytics collects anonymised data (IP addresses are anonymised) and sets cookies such as _ga and _ga_* to distinguish unique visitors. Vercel Analytics collects anonymous page-view data without cookies. No personal information is shared with third parties. You can opt out at any time through your cookie preferences.

Functional Cookies

With your consent, Sentry may record anonymised session replays to help us diagnose technical issues. All text content and media are masked before any data is captured.

5. Third-Party Services

We share data with the following third-party service providers, each acting as a data processor under GDPR:

ServiceData SharedPurposeLocation
SupabaseAccount data, bookings, profilesDatabase and authenticationEU (Frankfurt)
VivaPayment card details, billing infoPayment processingEU / US
VercelAnonymous page views (with consent)Hosting and analyticsGlobal edge network
Google AnalyticsAnonymised IP, page views, referrer, device info (with consent)Website analyticsUS (EU DPF certified)
SentryError logs, masked session replays (with consent)Error monitoringUS (EU DPF certified)
ResendEmail address, nameTransactional emailsUS (EU DPF certified)
CloudflareIP address, request metadataCDN, DDoS protection, bot managementGlobal edge network
Cloudflare R2Uploaded files (admin only)Image storage and deliveryGlobal edge network
UpstashIP-based identifiers (hashed)Rate limiting to prevent abuseEU (Frankfurt)
MuxIP address, playback metricsVideo streaming and deliveryUS (EU DPF certified)

6. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Data TypeRetention Period
Account dataWhile your account is active, plus 30 days after deletion request
Booking records7 years (Greek tax and accounting requirements)
Contact form submissions12 months
IP addresses (rate limiting)24 hours (auto-expire in Upstash)
Error logs (Sentry)90 days
Analytics data12 months (aggregated and anonymised)
Payment recordsAs required by Viva; we do not store card details

7. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of accessrequest a copy of the personal data we hold about you.
  • Right to rectificationrequest correction of inaccurate or incomplete data.
  • Right to erasurerequest deletion of your personal data (subject to legal retention obligations).
  • Right to restrictionrequest that we limit how we process your data.
  • Right to data portabilityreceive your data in a structured, machine-readable format.
  • Right to objectobject to processing based on legitimate interest.
  • Right to withdraw consentwithdraw consent at any time for consent-based processing (e.g. analytics cookies) without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint you may file a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr or your local EU supervisory authority.

To exercise any of these rights, please contact us at infonorthsantorini.com. We will respond within 30 days.

8. International Data Transfers

Some of our service providers process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework — Google, Sentry, Resend, Mux, and Vercel are certified under the EU-US Data Privacy Framework.
  • Standard Contractual Clauses (SCCs) — where the DPF does not apply, we rely on EU-approved Standard Contractual Clauses.
  • EU-based processing — our primary database (Supabase) and rate limiting infrastructure (Upstash) are hosted in the EU (Frankfurt).

9. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Encryption in transit — all connections use HTTPS/TLS, enforced by Cloudflare.
  • Password security — passwords are hashed using bcrypt via Supabase Auth.
  • Row Level Security — database access is restricted so users can only access their own data.
  • Rate limiting — API endpoints are rate-limited to prevent brute-force and abuse attacks.
  • Bot protection — Cloudflare Turnstile verifies human users on sensitive forms.
  • Error monitoring — Sentry provides real-time alerting with all PII masked.

10. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we may also notify you via email or a prominent notice on our website.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Experience North Santorini
Pyrgos, Santorini 847 00
Cyclades, Greece

Email: infonorthsantorini.com
Phone: +30 22860 71234