Privacy Policy

Last updated: 27 May 2026

This Privacy Policy explains how Panagiotis Makris, operating as a sole-person business for Symi Aerides, collects, uses, stores, and protects personal data when visitors use the website symiaerides.com, make a booking, submit information, or contact us.

We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (EU) 2016/679, known as the GDPR, and applicable Greek data protection law.

1. Data Controller

The data controller responsible for your personal data is:

Makris G. & Ntasioudi S. O.E.
Tourist Accommodation

Registered Office:
53 Mitropoleos Street, 54623, Thessaloniki, Greece
Branch: Pitini, Symi, 85600, Dodecanese, Greece
Contact Person: Smaragda Makri

GEMI Number:

2. What Personal Data We Collect

When you use our website or make a booking, we may collect the following personal data:

  • First name and last name
  • Email address
  • Phone number
  • Country
  • Address
  • Booking details, such as selected suite, stay dates, and number of guests
  • Payment method selected
  • Dietary restrictions and allergies, where voluntarily provided
  • Comments or special requests submitted through the booking form or by email
  • Email correspondence, including cancellation, refund, or booking-related requests

We do not collect or store full card details on our website.

3. How We Use Your Personal Data

We use your personal data for the following purposes:

  • To process and manage suite bookings
  • To confirm reservations automatically by email
  • To communicate with you about your booking
  • To respond to questions, comments, cancellation requests, or refund requests
  • To arrange payment by Stripe, bank transfer, or payment on arrival
  • To prepare for your stay and accommodate reasonable guest requests
  • To comply with legal, tax, accounting, and administrative obligations
  • To protect the security and proper operation of the website and booking system

The host may contact visitors or guests using the contact details provided, but only for matters related to enquiries, bookings, payments, cancellations, refunds, or the guest’s stay.

4. Legal Basis for Processing

We process personal data only when there is a valid legal basis under the GDPR. Depending on the situation, we rely on the following legal bases:

Performance of a contract
We process booking and contact details in order to manage reservations, payments, confirmations, guest communication, and the provision of accommodation services.

Legal obligation
We may process and retain certain data where required for tax, accounting, legal, or regulatory purposes.

Legitimate interests
We may process data where necessary for the normal operation of our business, such as responding to guest enquiries, keeping booking records, managing disputes, or ensuring website security, provided that your rights and freedoms do not override these interests.

Consent
Where you voluntarily provide information about dietary restrictions, allergies, or similar special requests, we use this information only for the purpose of responding to your request and preparing for your stay. Because allergy-related information may reveal health-related details, we treat it with additional care.

5. Payments

Card payments are processed securely by Stripe, a third-party payment provider. Stripe may process personal data in order to provide payment services, and its Data Processing Agreement explains its processing roles in relation to Stripe services.

We do not store your full credit or debit card details on symiaerides.com. Payment data is handled by Stripe through its secure payment systems.

Guests may also be offered the option to pay by bank transfer or payment on arrival. Where bank transfer is used, we may process payment-related information necessary to identify and confirm the payment.

6. Booking Confirmations and Email Communication

After a booking is submitted, confirmation emails are sent automatically through the website’s hosting/email infrastructure provided by:

smart-it-solutions.gr

We may also contact you manually by email or phone regarding your booking, payment, cancellation, refund request, arrival details, or stay.

Cancellation and refund requests are handled by email.

7. Cookies, Analytics, and Tracking

Our website does not use cookies.

We do not use Google Analytics, Meta Pixel, embedded maps, YouTube videos, live chat tools, advertising trackers, or similar third-party tracking technologies.

Because no cookies or tracking technologies are used, we do not currently display a cookie banner.

8. Who We Share Personal Data With

We may share personal data only where necessary for the operation of the website, booking process, payment process, or legal obligations.

This may include:

  • Stripe, for secure card payment processing
  • smart-it-solutions.gr, for website hosting and automated booking confirmation emails
  • Professional advisers, such as accountants or legal advisers, where necessary
  • Public authorities, tax authorities, or regulators, where required by law

We do not sell personal data.

We do not use personal data for third-party advertising.

9. International Data Transfers

Some service providers, such as Stripe, may process personal data in countries outside Greece or the European Economic Area, depending on how their services are operated. Where such transfers occur, they should be protected by appropriate safeguards required under applicable data protection law.

10. How Long We Keep Personal Data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

In general:

  • Booking records are kept for as long as necessary to manage the booking and meet legal, tax, and accounting obligations.
  • Email correspondence is kept for as long as necessary to respond to the request, manage the booking, handle possible disputes, and comply with legal obligations.
  • Dietary restrictions, allergies, and special request information are kept only for as long as necessary for the relevant booking or guest service purpose, unless a longer period is legally required.

When personal data is no longer needed, it will be deleted or anonymised where appropriate.

11. How We Protect Your Personal Data

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure.

These measures may include secure website hosting, restricted access to booking information, secure payment processing through Stripe, and careful handling of email communications.

However, no website, email system, or online transmission method can be guaranteed to be completely secure.

12. Your Data Protection Rights

Under the GDPR, you may have the right to:

  • Request access to your personal data
  • Request correction of inaccurate or incomplete data
  • Request deletion of your personal data
  • Request restriction of processing
  • Object to certain types of processing
  • Request data portability, where applicable
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

To exercise your rights, you can contact us at:

moc.sedireaimys@tcatnoc

The Hellenic Data Protection Authority handles complaints about alleged violations of data protection law in Greece.

13. Children’s Privacy

Our website and accommodation booking services are intended for adults who are legally able to make a booking. We do not knowingly collect personal data directly from children.

If a booking includes children as guests, any necessary information should be provided by the parent, guardian, or adult responsible for the booking.

14. Links to Third-Party Websites

Our website contains links to third-party websites or services. We are not responsible for the privacy practices, content, or security of third-party websites. Visitors should review the privacy policies of those third parties before providing personal data.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our website, booking process, service providers, or legal obligations.

The latest version will always be available on symiaerides.com, with the “Last updated” date shown at the top.

16. Contact

For questions about this Privacy Policy or the handling of your personal data, please contact the company:

Contact Person: Smaragda Makri

Tel: +306944246447