Last Updated: [20/11/2025]


1. Introduction


Welcome to Villa Dilion, located in Antiparos, Greece. This Privacy Policy governs the manner in which Villa Dilion (referred to as "we," "us," or "our") collects, uses, maintains, and discloses information collected from users (each, a "User") of the website https://villaantiparosdilion.com/ ("Site") and in connection with our accommodation and booking services.

As a business operating in the European Union (Greece), we are committed to protecting your personal data and upholding your rights under the General Data Protection Regulation (GDPR).


2. Information We Collect


We may collect and process the following personal data about you:


A. Information You Provide to Us (Directly)

This information is collected when you make a booking, use our contact form, send us an email, or sign up for a newsletter.

Type of Data Purpose/Use
Personal Identifiers Full name, email address, phone number, home address.
Booking & Stay Details Check-in/check-out dates, number of guests (adults and children), nationality.
Payment Information Credit card details, bank details, or other payment information. (Note: This is usually processed securely by a third-party payment provider, and we do not store full card details.)
Special Requests Any notes regarding dietary requirements, mobility needs, or other preferences related to your stay.
Communication Data Records of correspondence, including emails and messages sent to us.

 

B. Information Collected Automatically (Usage Data)

When you visit our Site, we may automatically collect certain information about your device and usage patterns.

  • Usage Data: Information about how you interact with our Site (e.g., pages viewed, time spent on pages, referral source).

  • Technical Data: Internet Protocol (IP) address, browser type and version, device type, time zone setting, and operating system.

  • Cookie Data: Data collected via cookies and similar tracking technologies. (Please see Section 7 - Cookies Policy for details).

 

3. Legal Basis and How We Use Your Information (GDPR)


We rely on different legal bases to process your personal data under the GDPR:

Legal Basis Purpose of Processing
Performance of a Contract To process and manage your reservation, confirm your booking, and provide you with the accommodation services you have requested.
Legitimate Interests To manage our business, improve our services, administer and protect our Site, conduct internal operations (data analysis, testing, and research), and to maintain the safety and security of our guests and property.
Legal Obligation To comply with our legal and regulatory obligations, such as tax and accounting requirements, or responding to lawful requests from public authorities.
Consent To send you marketing communications, newsletters, or promotional offers if you have explicitly opted-in to receive them. You can withdraw your consent at any time.

 

4. Sharing and Disclosure of Your Personal Data


We only share your personal data with third parties as necessary to provide our services or as required by law:

  1. Service Providers: We may share data with third-party companies that perform services on our behalf, such as:

    • Online booking engines (e.g., [Name of Booking Platform if used]).

    • Payment processors (e.g., [Name of Payment Gateway]).

    • IT and system administration service providers.

  2. Compliance with Law: We may disclose your data if required to do so by law or in the good faith belief that such action is necessary to comply with legal processes or government requests.

  3. Business Transfer: In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new owner.

 

5. Data Security and Retention


Security: We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, or accessed in an unauthorized way, altered, or disclosed. Access is limited to employees, agents, and contractors who have a business need to know and are subject to a duty of confidentiality.

Retention: We will only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. Typically, booking records are retained for [5] years to comply with local tax and commercial laws.

 

6. Your Data Protection Rights (GDPR Rights)


As a data subject under the GDPR, you have the following rights concerning your personal data:

  • The Right to Access: You have the right to request copies of your personal data.

  • The Right to Rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

  • The Right to Erasure ("Right to be Forgotten"): You have the right to request that we erase your personal data, under certain conditions.12

  • The Right to Restrict Processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.34

  • The Right to Object to Processing: You have the right to object to our processing of your personal data, under 5certain conditions (e.g., for direct marketing).

  • The Right to Data Portability: You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

To exercise any of these rights, please contact us using the details provided in Section 8.

 

7. Cookies Policy


Our Site uses cookies to enhance the user experience. Cookies are small files placed on your device. We use them for technical functionality, website analytics, and, with your consent, for marketing purposes.

By using the Site, you consent to the use of cookies in accordance with our Cookie Consent banner and this policy. You can manage your cookie preferences at any time via the cookie settings located on our Site.

 

8. Contact Information


If you have any questions about this Privacy Policy, the practices of this Site, or your dealings with this Site, please contact us at:

Data Controller: Villa Dilion

Website: https://villaantiparosdilion.com/

Email: This email address is being protected from spambots. You need JavaScript enabled to view it.

 

Complaint to a Supervisory Authority

Should you be unsatisfied with our handling of your data or our response to your requests, you have the right to lodge a complaint with the Hellenic Data Protection Authority (the supervisory body in Greece).

 

9. Changes to this Privacy Policy


We reserve the right to update or change this Privacy Policy at any time. When we do, we will revise the "Last Updated" date at the top of this page. We encourage Users to frequently check this page for any changes. Your continued use of the Site after any modification will constitute your acknowledgment of the modifications and your consent to abide and be bound by the modified Privacy Policy.