Click to view the Privacy Policy
Privacy Notice
Last Updated: March 2026
ATTIKOS OURANOS A.E. is committed to protecting and respecting your privacy. Please read this Privacy Notice (the “Notice”) which describes how we collect, use, and disclose your personal data in conjunction with the access to and use of our booking system by you (hereinafter also “User”). You must carefully read this Notice, which has been written clearly and simply, to help you decide freely and voluntarily whether you wish to provide your personal data, or those of third parties, to ATTIKOS OURANOS A.E. When this Notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://zafolia.reserve-online.net/, unless specified otherwise. We may change this Notice from time to time. You should check this Notice frequently to ensure you are aware of its most recent version.
1. Controller’s and Processor’s Identity
When this Notice mentions “we,” “us,” or “our”, “Company” or “Controller”, it refers to ATTIKOS OURANOS
A.E. ATTIKOS OURANOS A.E operates this booking system through a Processor, as explained below. For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) we are the Controller. There is a strict contractual framework between the Controller and the Processor for the protection of your personal information. We are:
Athens Zafolia Hotel “ATTIKOS OURANOS A.E” 87-89 Alexandras Avenue
114 74, Athens, GR
WebHotelier operates this booking system on behalf of ATTIKOS OURANOS A.E as Processor and is committed to protecting the privacy of the Users of this system.
When this Notice mentions “Processor” or “WebHotelier,” it refers to WebHotelier Technologies Ltd., Mnasiadou 9 (Demokritos Building, Office 16), 1065 Nicosia, Cyprus
WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.
Obligatory nature of providing the data
The data requested in the forms accessible from the booking engine are mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or not provided correctly, we will be unable to process your request.
Personal data we collect and process, purposes of processing and legal bases
Purpose of processing Types of data Legal bases
1. To manage User’s bookings, including the
processing of payments, the management of the user’s requests and preferences in relation to -Identification and
communication data (e.g. your name, Performance of the
contract (Art. 6 (1) (b) GDPR)
bookings and provision of the contracted accommodation service and/or additional services. address, and email address)
-financial and transaction details
-User’s booking preferences
-In cases of Social Login: information of the User’s profile from the corresponding social network
2. To manage registration in loyalty or membership programs, as well as obtaining and redeeming points. -Identification and communication data Performance of the contract (Art. 6 (1) (b) GDPR)
3. To manage the User’s contact requests with us through the channels provided to this end. -Identification and communication data Consent (Art. 6 (1) (a) GDPR
4. To send marketing communications -Identification and communication data Legitimate interest (Art. 6 (1) (f) GDPR for current customers) and consent (Art. 6 (1) (a) GDPR (for
prospective customers)
5. To manage surveys and/or evaluations regarding the quality of the services provided by us and our company -Identification and evaluation data Legitimate interest (Art. 6 (1) (f) GDPR)
6. Compliance with legal obligations -Identification and communication data
-financial and
transaction details Compliance with legal obligations (Art. 6 (1) (c) GDPR)
Our Processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions for the aforementioned purposes. WebHotelier cannot process it in any other way or for any other purpose.
Third-party data (e.g., book for a friend)
In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested with the information contained in this Notice, duly exonerating us and our Processor from any liability in this regard.
Special Categories of Data
Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Special Categories of data (e.g., data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).
Data Retention
We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice, according to the following criteria:
• The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
• Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
• Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)
Recipients
We will use and disclose your personal data to third parties (recipients) where necessary or appropriate:
• to comply with applicable law, including laws outside your country of residence;
• to comply with legal processes;
• to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
• to enforce our terms and conditions;
• to protect our operations;
• to protect the rights, privacy, safety or property of our own, you or others; and
• to allow us to pursue available remedies or limit the damages that we may sustain. The categories of recipients of your data are:
• Authorised personnel and service providers, e.g., cloud service providers, IT systems support service provider, Webhotelier;
• Financial institutions (where required for the execution of the transaction);
• Lawyers (where required for the exercise of the Company's rights and the defence of its legal interests);
• Tax authorities (where required for the exercise of the Company's rights and the defence of its legal interests);
• Bailiffs, notaries, judicial, prosecutorial and police authorities, as well as auditing authorities, if required by law or court decisions or at their legitimate request in the exercise of their duties.
International transfers of personal data
We may transfer your personal information outside of the European Economic Area for the purposes described in this Notice, as follows:
Recipient Country Transfer Mechanism
Amazon Web Services N. Virginia, USA Standard Contractual Clauses. You may receive a copy by contacting the Controller at the contact
details indicated below.
User's Responsibility
The User:
Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.
Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this Notice. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.
Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.
Exercise of Rights
You may contact us at any time free of charge, to:
• To obtain confirmation about whether or not personal data concerning you is being processed by us and to access/receive a copy of your data
• To rectify any inaccurate or incomplete data.
• To request the deletion of your personal data when, among other reasons, the data are no longer necessary for the purposes for which it was collected.
• To revoke your consent at any time.
• To request from us the restriction of the data processing
• To request the portability of your data.
• To object to the processing of your data.
You may exercise these rights by sending a written request to the following e-mail address: info@zafoliahotel.gr. We will reply to you in writing within the statutory deadlines.
In case you believe that we have violated your rights in relation to your personal data, you also have the right to lodge a complaint with the Hellenic Data Protection Authority, through its website www.dpa.gr, as well as the right to appeal to the courts.
Security Measures
We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organizational nature required to guarantee the security of their data and prevent it from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.
