Skip to main content

Legal

Privacy Policy

Last updated: 27 August 2026

1. Introduction

Experience North Santorini ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website at experience-northsantorini.com (the "Site") and related services.

We are the data controller for purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Our contact details are provided in the Contact Us section below.

2. Data We Collect

CategorySpecific DataPurposeLawful Basis
Account InformationEmail, name, phone numberCreate and manage your accountContract performance
Booking DataDates, guest count, preferences, special requestsProcess and fulfil your reservationsContract performance
Contact FormName, email, phone, messageRespond to your enquiriesLegitimate interest
Payment DataCard details (processed by Viva, never stored by us)Process payments securelyContract performance
Technical DataIP address, browser type, device info, pages visitedSecurity, performance monitoring, abuse preventionLegitimate interest
Error MonitoringJavaScript errors, stack traces, anonymised session replaysIdentify and fix technical issuesLegitimate interest
AnalyticsPage views, referrer, anonymous visitor metrics, anonymised IP (Google Analytics)Understand site usage and improve our servicesConsent
Marketing PreferencesEmail address, name, language, and the record of your consent: the wording you agreed to, the date and time, how you gave it, and the IP address it came fromSend the marketing emails you asked for, and prove and honour your choiceConsent (ePrivacy)

3. How We Use Your Data

We process your personal data for the following purposes:

  • Fulfilling bookingsprocessing your experience, dining, spa, cruise, and transfer reservations.
  • Processing paymentssecurely handling transactions through Viva, including refundable reservation deposits (such as for larger restaurant parties), which are charged and refunded through the same provider. We never store your card details on our servers.
  • Transactional emailssending booking confirmations, reminders, and cancellation notices via Resend.
  • Marketing emailssending offers and reminders via Resend, only to guests who have asked for them, and only until they unsubscribe.
  • Site securityprotecting against abuse, bot attacks, and fraudulent activity using Cloudflare and Cloudflare Turnstile.
  • Error monitoringidentifying and fixing bugs through Sentry (with all text masked and no PII collected).
  • Analyticsunderstanding how visitors use our site through Google Analytics 4 (with IP anonymisation) and Vercel Analytics (only with your consent).
  • Media deliveryserving optimised images and videos through Cloudflare R2 and Mux.

4. Marketing Emails

We send marketing email only to people who have asked for it. This section sets out what we send, on what basis, and how to stop it.

What we send

If you have ticked the marketing box at checkout or on a waitlist form, we may send you:

  • A reminder about an unfinished booking if you start a booking and do not complete payment, we may email you about it — at most twice, and only within 30 days of the attempt.
  • An alternative when your date stays full if you joined a waitlist and the date does not open up, we may suggest something comparable, such as a private dinner in the Cave Spa, sometimes with a discount code issued to you personally.
  • Occasional news and offersabout our rooms, Akau Restaurant, the Natura Spa and our experiences.

We cap this deliberately. A reminder about an unfinished booking is at most two emails, roughly two days apart. Beyond that we do not start anything new within seven days, and we never send more than four marketing emails in any 90 days.

Booking confirmations, reminders, cancellation and refund notices, waitlist alerts and account emails are not marketing. We send those because you have made a booking or asked us to, and they continue whether or not you accept marketing.

Our lawful basis

We send marketing email on one of two bases under Article 13 of the ePrivacy Directive (2002/58/EC) as implemented in Greece by article 11 of Law 3471/2006: your consent (Article 13(1)), given by ticking an unticked box or clicking a confirmation link; or, for guests who have paid for a booking with us, the existing-customer rule (Article 13(2) / article 11(3)), which lets us email you about our own similar services provided you were given a clear chance to object at checkout and are given it again in every message — that basis lapses twelve months after your last booking. We do not rely on legitimate interests to send you marketing, and we never treat acceptance of our Terms of Service as consent to it.

Working out who to contact — checking whether a booking was left unpaid, whether you have since booked with us, and whether a waitlisted date is still full — is done on the basis of our legitimate interest in running our business efficiently (Article 6(1)(f) GDPR). That basis covers the internal selection only. Nothing is sent to you unless you have given consent.

Consent is optional, and you can withdraw it

The marketing box is never pre-ticked and is never bundled with anything else you agree to. Ticking it is not a condition of booking or of joining a waitlist, and it does not change any price you are quoted — your booking goes through either way.

You can withdraw your consent at any time, free of charge, and it is as easy as giving it was. Every marketing email carries an unsubscribe link that works in one click, with no sign-in and no reason required, and it stops every kind of marketing email at once. You can also write to us at infonorthsantorini.com, or reply to any marketing message asking us to stop. Withdrawing does not affect the lawfulness of anything we sent before you withdrew.

Who else sees your email address

Only Resend, the service that delivers our email, listed in the Third-Party Services section below. We do not sell your address, share it with other companies for their own marketing, or upload it to advertising platforms.

What we keep, and for how long

So that we can show your consent was properly obtained, we record the exact wording you agreed to, the date and time, the language you read it in, how you gave it, and the IP address it came from. If you unsubscribe or object, we keep your email address on a do-not-email record indefinitely: that record is the only reliable way to be sure we never email you again, and deleting it would undo your own decision. The exact periods are in the Data Retention section below.

Who to contact

For anything to do with marketing email — withdrawing consent, objecting, or asking what we hold about you — write to infonorthsantorini.com. If you are not satisfied with our response, you can complain to the Hellenic Data Protection Authority at www.dpa.gr.

5. Cookies & Tracking

We use cookies and similar technologies to operate our site. You can manage your preferences at any time by clicking "Cookie Settings" in the footer or .

Strictly Necessary Cookies

These cookies are essential for the site to function and cannot be disabled. They include authentication tokens (Supabase), cart and trip planner storage (localStorage), and your cookie consent preference.

Analytics Cookies

With your consent, we use Google Analytics 4 and Vercel Analytics to understand how visitors use our site. Google Analytics collects anonymised data (IP addresses are anonymised) and sets cookies such as _ga and _ga_* to distinguish unique visitors. Vercel Analytics collects anonymous page-view data without cookies. No personal information is shared with third parties. You can opt out at any time through your cookie preferences.

Functional Cookies

With your consent, Sentry may record anonymised session replays to help us diagnose technical issues. All text content and media are masked before any data is captured.

6. Third-Party Services

We share data with the following third-party service providers, each acting as a data processor under GDPR:

ServiceData SharedPurposeLocation
SupabaseAccount data, bookings, profilesDatabase and authenticationEU (Frankfurt)
VivaPayment card details, billing infoPayment processingEU / US
VercelAnonymous page views (with consent)Hosting and analyticsGlobal edge network
Google AnalyticsAnonymised IP, page views, referrer, device info (with consent)Website analyticsUS (EU DPF certified)
SentryError logs, masked session replays (with consent)Error monitoringUS (EU DPF certified)
ResendEmail address, nameTransactional and marketing emailsUS (EU DPF certified)
CloudflareIP address, request metadataCDN, DDoS protection, bot managementGlobal edge network
Cloudflare R2Uploaded files (admin only)Image storage and deliveryGlobal edge network
UpstashIP-based identifiers (hashed)Rate limiting to prevent abuseEU (Frankfurt)
MuxIP address, playback metricsVideo streaming and deliveryUS (EU DPF certified)

7. Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:

Data TypeRetention Period
Account dataWhile your account is active, plus 30 days after deletion request
Booking records7 years (Greek tax and accounting requirements)
Contact form submissions12 months
IP addresses (rate limiting)24 hours (auto-expire in Upstash)
Error logs (Sentry)90 days
Analytics data12 months (aggregated and anonymised)
Payment recordsAs required by Viva; we do not store card details
Marketing consent recordWhile we rely on your consent, then 3 years; the IP address recorded at the time is deleted after 12 months
Unsubscribe and objection recordKept indefinitely, so that we never email you again
Marketing email logYour address is removed after 12 months; the record is deleted after 3 years

8. Your Rights Under GDPR

As a data subject under the GDPR, you have the following rights regarding your personal data:

  • Right of accessrequest a copy of the personal data we hold about you.
  • Right to rectificationrequest correction of inaccurate or incomplete data.
  • Right to erasurerequest deletion of your personal data. Some records have to be kept: bookings, for Greek tax and accounting purposes, and — if you have unsubscribed or objected — your email address on our do-not-email record, so that your decision keeps being honoured.
  • Right to restrictionrequest that we limit how we process your data.
  • Right to data portabilityreceive your data in a structured, machine-readable format.
  • Right to object object to processing based on our legitimate interests. You can object to direct marketing at any time, without giving a reason — see Marketing Emails.
  • Right to withdraw consentwithdraw consent at any time for consent-based processing (for example analytics cookies or marketing emails) without affecting the lawfulness of processing before withdrawal.
  • Right to lodge a complaint you may file a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr or your local EU supervisory authority.

To exercise any of these rights, please contact us at infonorthsantorini.com. We will respond within 30 days.

9. International Data Transfers

Some of our service providers process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place:

  • EU-US Data Privacy Framework — Google, Sentry, Resend, Mux, and Vercel are certified under the EU-US Data Privacy Framework.
  • Standard Contractual Clauses (SCCs) — where the DPF does not apply, we rely on EU-approved Standard Contractual Clauses.
  • EU-based processing — our primary database (Supabase) and rate limiting infrastructure (Upstash) are hosted in the EU (Frankfurt).

10. Data Security

We implement appropriate technical and organisational measures to protect your personal data:

  • Encryption in transit — all connections use HTTPS/TLS, enforced by Cloudflare.
  • Password security — passwords are hashed using bcrypt via Supabase Auth.
  • Row Level Security — database access is restricted so users can only access their own data.
  • Rate limiting — API endpoints are rate-limited to prevent brute-force and abuse attacks.
  • Bot protection — Cloudflare Turnstile verifies human users on sensitive forms.
  • Error monitoring — Sentry provides real-time alerting with all PII masked.

11. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we may also notify you via email or a prominent notice on our website.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:

Experience North Santorini
Pyrgos, Santorini 847 00
Cyclades, Greece

Email: infonorthsantorini.com
Phone: +30 2286034246