1. Introduction
Experience North Santorini ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your information when you use our website at experience-northsantorini.com (the "Site") and related services.
We are the data controller for purposes of the General Data Protection Regulation (EU) 2016/679 ("GDPR"). Our contact details are provided in the Contact Us section below.
2. Data We Collect
| Category | Specific Data | Purpose | Lawful Basis |
|---|---|---|---|
| Account Information | Email, name, phone number | Create and manage your account | Contract performance |
| Booking Data | Dates, guest count, preferences, special requests | Process and fulfil your reservations | Contract performance |
| Contact Form | Name, email, phone, message | Respond to your enquiries | Legitimate interest |
| Payment Data | Card details (processed by Viva, never stored by us) | Process payments securely | Contract performance |
| Technical Data | IP address, browser type, device info, pages visited | Security, performance monitoring, abuse prevention | Legitimate interest |
| Error Monitoring | JavaScript errors, stack traces, anonymised session replays | Identify and fix technical issues | Legitimate interest |
| Analytics | Page views, referrer, anonymous visitor metrics, anonymised IP (Google Analytics) | Understand site usage and improve our services | Consent |
| Marketing Preferences | Email address, name, language, and the record of your consent: the wording you agreed to, the date and time, how you gave it, and the IP address it came from | Send the marketing emails you asked for, and prove and honour your choice | Consent (ePrivacy) |
3. How We Use Your Data
We process your personal data for the following purposes:
- Fulfilling bookings — processing your experience, dining, spa, cruise, and transfer reservations.
- Processing payments — securely handling transactions through Viva, including refundable reservation deposits (such as for larger restaurant parties), which are charged and refunded through the same provider. We never store your card details on our servers.
- Transactional emails — sending booking confirmations, reminders, and cancellation notices via Resend.
- Marketing emails — sending offers and reminders via Resend, only to guests who have asked for them, and only until they unsubscribe.
- Site security — protecting against abuse, bot attacks, and fraudulent activity using Cloudflare and Cloudflare Turnstile.
- Error monitoring — identifying and fixing bugs through Sentry (with all text masked and no PII collected).
- Analytics — understanding how visitors use our site through Google Analytics 4 (with IP anonymisation) and Vercel Analytics (only with your consent).
- Media delivery — serving optimised images and videos through Cloudflare R2 and Mux.
4. Marketing Emails
We send marketing email only to people who have asked for it. This section sets out what we send, on what basis, and how to stop it.
What we send
If you have ticked the marketing box at checkout or on a waitlist form, we may send you:
- A reminder about an unfinished booking — if you start a booking and do not complete payment, we may email you about it — at most twice, and only within 30 days of the attempt.
- An alternative when your date stays full — if you joined a waitlist and the date does not open up, we may suggest something comparable, such as a private dinner in the Cave Spa, sometimes with a discount code issued to you personally.
- Occasional news and offers — about our rooms, Akau Restaurant, the Natura Spa and our experiences.
We cap this deliberately. A reminder about an unfinished booking is at most two emails, roughly two days apart. Beyond that we do not start anything new within seven days, and we never send more than four marketing emails in any 90 days.
Booking confirmations, reminders, cancellation and refund notices, waitlist alerts and account emails are not marketing. We send those because you have made a booking or asked us to, and they continue whether or not you accept marketing.
Our lawful basis
We send marketing email on one of two bases under Article 13 of the ePrivacy Directive (2002/58/EC) as implemented in Greece by article 11 of Law 3471/2006: your consent (Article 13(1)), given by ticking an unticked box or clicking a confirmation link; or, for guests who have paid for a booking with us, the existing-customer rule (Article 13(2) / article 11(3)), which lets us email you about our own similar services provided you were given a clear chance to object at checkout and are given it again in every message — that basis lapses twelve months after your last booking. We do not rely on legitimate interests to send you marketing, and we never treat acceptance of our Terms of Service as consent to it.
Working out who to contact — checking whether a booking was left unpaid, whether you have since booked with us, and whether a waitlisted date is still full — is done on the basis of our legitimate interest in running our business efficiently (Article 6(1)(f) GDPR). That basis covers the internal selection only. Nothing is sent to you unless you have given consent.
Consent is optional, and you can withdraw it
The marketing box is never pre-ticked and is never bundled with anything else you agree to. Ticking it is not a condition of booking or of joining a waitlist, and it does not change any price you are quoted — your booking goes through either way.
You can withdraw your consent at any time, free of charge, and it is as easy as giving it was. Every marketing email carries an unsubscribe link that works in one click, with no sign-in and no reason required, and it stops every kind of marketing email at once. You can also write to us at infonorthsantorini.com, or reply to any marketing message asking us to stop. Withdrawing does not affect the lawfulness of anything we sent before you withdrew.
Who else sees your email address
Only Resend, the service that delivers our email, listed in the Third-Party Services section below. We do not sell your address, share it with other companies for their own marketing, or upload it to advertising platforms.
What we keep, and for how long
So that we can show your consent was properly obtained, we record the exact wording you agreed to, the date and time, the language you read it in, how you gave it, and the IP address it came from. If you unsubscribe or object, we keep your email address on a do-not-email record indefinitely: that record is the only reliable way to be sure we never email you again, and deleting it would undo your own decision. The exact periods are in the Data Retention section below.
Who to contact
For anything to do with marketing email — withdrawing consent, objecting, or asking what we hold about you — write to infonorthsantorini.com. If you are not satisfied with our response, you can complain to the Hellenic Data Protection Authority at www.dpa.gr.
6. Third-Party Services
We share data with the following third-party service providers, each acting as a data processor under GDPR:
| Service | Data Shared | Purpose | Location |
|---|---|---|---|
| Supabase | Account data, bookings, profiles | Database and authentication | EU (Frankfurt) |
| Viva | Payment card details, billing info | Payment processing | EU / US |
| Vercel | Anonymous page views (with consent) | Hosting and analytics | Global edge network |
| Google Analytics | Anonymised IP, page views, referrer, device info (with consent) | Website analytics | US (EU DPF certified) |
| Sentry | Error logs, masked session replays (with consent) | Error monitoring | US (EU DPF certified) |
| Resend | Email address, name | Transactional and marketing emails | US (EU DPF certified) |
| Cloudflare | IP address, request metadata | CDN, DDoS protection, bot management | Global edge network |
| Cloudflare R2 | Uploaded files (admin only) | Image storage and delivery | Global edge network |
| Upstash | IP-based identifiers (hashed) | Rate limiting to prevent abuse | EU (Frankfurt) |
| Mux | IP address, playback metrics | Video streaming and delivery | US (EU DPF certified) |
7. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected:
| Data Type | Retention Period |
|---|---|
| Account data | While your account is active, plus 30 days after deletion request |
| Booking records | 7 years (Greek tax and accounting requirements) |
| Contact form submissions | 12 months |
| IP addresses (rate limiting) | 24 hours (auto-expire in Upstash) |
| Error logs (Sentry) | 90 days |
| Analytics data | 12 months (aggregated and anonymised) |
| Payment records | As required by Viva; we do not store card details |
| Marketing consent record | While we rely on your consent, then 3 years; the IP address recorded at the time is deleted after 12 months |
| Unsubscribe and objection record | Kept indefinitely, so that we never email you again |
| Marketing email log | Your address is removed after 12 months; the record is deleted after 3 years |
8. Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data. Some records have to be kept: bookings, for Greek tax and accounting purposes, and — if you have unsubscribed or objected — your email address on our do-not-email record, so that your decision keeps being honoured.
- Right to restriction — request that we limit how we process your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on our legitimate interests. You can object to direct marketing at any time, without giving a reason — see Marketing Emails.
- Right to withdraw consent — withdraw consent at any time for consent-based processing (for example analytics cookies or marketing emails) without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint — you may file a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr or your local EU supervisory authority.
To exercise any of these rights, please contact us at infonorthsantorini.com. We will respond within 30 days.
9. International Data Transfers
Some of our service providers process data outside the European Economic Area (EEA). Where this occurs, we ensure appropriate safeguards are in place:
- EU-US Data Privacy Framework — Google, Sentry, Resend, Mux, and Vercel are certified under the EU-US Data Privacy Framework.
- Standard Contractual Clauses (SCCs) — where the DPF does not apply, we rely on EU-approved Standard Contractual Clauses.
- EU-based processing — our primary database (Supabase) and rate limiting infrastructure (Upstash) are hosted in the EU (Frankfurt).
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data:
- Encryption in transit — all connections use HTTPS/TLS, enforced by Cloudflare.
- Password security — passwords are hashed using bcrypt via Supabase Auth.
- Row Level Security — database access is restricted so users can only access their own data.
- Rate limiting — API endpoints are rate-limited to prevent brute-force and abuse attacks.
- Bot protection — Cloudflare Turnstile verifies human users on sensitive forms.
- Error monitoring — Sentry provides real-time alerting with all PII masked.
11. Children's Privacy
Our services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will promptly delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the "Last updated" date at the top of this page. For significant changes, we may also notify you via email or a prominent notice on our website.
13. Contact Us
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us:
Experience North SantoriniPyrgos, Santorini 847 00
Cyclades, Greece
Email: infonorthsantorini.com
Phone: +30 2286034246