WhatsApp

ΠΟΛΙΤΙΚΗ ΑΠΟΡΡΗΤΟΥ

The protection of your personal data is important to us. This privacy notice (the “Privacy Notice”) intends to inform you about the kind of personal data MEX PC (as defined here below) collects, how it is processed, how it is protected and your rights to such processing, in relation to the services we provide or when you visit our website(s) or when you interact with us.

Definitions

• The terms "we", “us” and “Company” refer to MEX Private Company (TIN 801139034) and/or any other affiliated companies, as legally represented.

• The terms "you" and "user" refer to each person who visits or uses our website(s) and/or to each person we interact with, including customers, visitors of our premises and users of our services (e.g. online reservations, contact forms, newsletter subscriptions).

• The terms "site" and "website" refer to www.kantounibeach.gr, www.kymatarestaurant.gr and/or any related sites, communication channels, including, but not limited to, our social media pages and/or channels (the “Pages”), which, along with their entire content, are owned by the Company.

• The term "GDPR" refers to the General Data Protection Regulation, namely the Regulation (EU) 2016/679 of the European Parliament and the Council in respect of the protection of natural persons, with regards to the process of personal data, the free movement of this data and the repeal of Directive 95/46/EC.

• The term "Law" refers to any national law, including but not limited to the Greek Law 4624/2019, which implemented the measures of GDPR, as in force.

Introduction

The Company appreciates the interest you have shown in our company, services and premises, including “Kantouri Beach Hotel” and “Kymata Restaurant”, by contacting us or by visiting the Pages. We strive to protect and safeguard the privacy and personal data of the users/visitors of the Pages, our customers and guests, and therefore have so far implemented a series of actions, rules and procedures, to ensure our full compliance with current European and national legislation. This Privacy Notice aims to inform you about the processing of your data in accordance with articles 12-14 of the GDPR and the respective articles of the Law.

Please read the Privacy Notice carefully, in order to be informed about the data processed by the Company how it is protected and what your legal rights are.

This Privacy Notice applies to all the personal data that the Company processes when you directly or indirectly interact with it, such as when you, indicatively and not exclusively, visit our premises (hotel and restaurant), visit the Pages, communicate with us via our website or contact forms, subscribe to newsletters, make online reservations, use or purchase our services, interact with the Company as a job applicant, customer or business partner. This personal data is described in more detail below. This Privacy Notice applies, without limitation, to all online and offline processing of all types of personal data.

We process your personal data on the legal basis of performance of contract and/or compliance with other legal obligations and as the case may be on the basis of legitimate interest. In addition, we may process your personal data on the legal basis of consent, granted by you through our Pages or in person (e.g. in our premises) and provided you have been previously informed, under this Privacy Notice, of the type of data, the purpose(s), the extent of the processing and the recipients. Your consent may be revoked at any time by contacting us at reservations@kantounibeach.gr[EA1.1][MN1.2].

In any case, when visiting the Pages and/or using our services, you acknowledge that you have read and understood and accept this Privacy Notice and are bound by its terms.

What are "Personal Data" and "Processing of Personal Data" (Article 4 GDPR)

"Personal data" means any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is person whose identity can be identified, directly or indirectly, in particular by reference to an identifier such as name, identity number, location data, online identity card, or one or more factors specific to physical, physiological, genetic, psychological, economic, cultural or social identity of that person.

"Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

What personal data we process

You can visit our websites without providing any personal data. In this case, only access data will be stored such as the name of your internet service provider. This data will be used only to improve our services and cannot lead to your identification.

In addition, we may collect your personal data via cookies or similar techniques, upon your consent, including, but not limited to: IP address, cookie ID, web browser type, location, web pages you visit our websites, advertisements you've viewed or clicked through. For further information please read our Cookies Policy[EA2.1][MN2.2].

Your personal data, such as name and email address, will be collected when you communicate with us via our Pages (e.g. through our contact forms, reservation forms or chatbot). In this case, we will process your data in order to respond to your request and/or provide you with our services.

Furthermore, we may collect your personal data, when you apply electronically for a job position via our website. For this purpose, we may collect your name and surname, email address, phone number and CV. In case you apply for a job by submitting the application form via our website, you may optionally upload your photograph and your cover letter as well, if you wish to do so.

When you make a reservation or purchase our services (e.g. accommodation, dining, events), we collect and process personal data necessary for the fulfilment of the service, including your name and surname, email address, phone number, postal address, booking details, number of guests, special requests (e.g. dietary requirements, accessibility needs) and, where applicable, payment information. When you check in at our hotel, we collect identification data (name, surname, nationality, passport or ID number, date of birth) as required by law for the hotel guest register (Police guest registry), pursuant to applicable Greek legislation. We do not retain copies or photographs of identity documents, passports or payment cards, in compliance with the recommendations of the Hellenic Data Protection Authority.

Also, depending on the choices you have made regarding your settings on various social media sites, and your settings on our Pages, certain personal data may be shared with the Company about your online activities and social media profiles.

We may also receive your personal data from our business partners (e.g. online booking platforms, travel agencies, event organisers) in order to provide you with our services. Personal data we receive in these cases may include your name and surname, contact data, email address, booking preferences, dietary requirements and any other data necessary to provide you with our services. In case your data is received from our business partners, the Company acts as controller or processor, as applicable.

The Company may also process personal data in a form that does not, on its own, permit direct association with any specific individual. If the Company combines non-personal data with personal data, the combined information will be treated as personal data for as long as it remains combined.

When visiting our premises (hotel, restaurant and any other Company facilities), we may also have access to Wi-Fi connection data, if used, as well as to video surveillance system material (CCTV), which operates in our premises, where relevant signposting exists, for the protection of persons and goods, in accordance with the respective legislation and the guidelines of the Hellenic Data Protection Authority. CCTV cameras are limited to entrance/exit areas, reception and areas housing valuable assets; they do not cover dining areas, corridors leading to rooms, swimming pools or any areas where guests’ privacy may be disproportionately affected. The CCTV system captures image only, not sound. The relevant material is stored for two (2) days[EA3.1][MN3.2], after which it is automatically deleted. In case we find an incident during this period, we isolate part of the video and keep it for one (1) more month, in order to investigate the incident. In case legal proceedings arise, the relevant material shall be stored until a final judgement is issued. Access to CCTV footage is restricted to strictly authorised personnel bound by confidentiality obligations.

How we collect your personal data

Your data may be collected by the Company in the following ways:

• when you communicate with us via our website or by email, phone or in writing;

• through our business partners (e.g. online booking platforms, travel agencies) in order to provide you with our services;

• when you apply for a job;

• when making a reservation or using our hotel and restaurant services;

• when you voluntarily participate in promotional activities, including social media activities, competitions, surveys or events;

• when you create an account or sign in on our websites or booking platforms;

• through cookies placed on your computer or mobile device when you visit our website upon your consent.

Purposes of processing your personal data

Your personal data provided to the Company as indicated above, either by our partners or by you, are processed for the following purposes:

• communication and correspondence to your personal requests via our website, contact forms or chatbot;

• receiving information about our hotel, restaurant and related services;

• provision and delivery of our hotel accommodation, dining, event and related services;

• managing customer relationships;

• recruitment of employees;

• processing and managing reservations and bookings for our hotel and restaurant services;

•

• participating in our online communities, including our social media channels/pages;

• storing your preferences for future interactions and communications with us;

• helping us to improve our services, and allowing us to keep you informed of, or involve you in the testing of, new services;

• creating statistical reports, based on anonymised data, and improving our services;

• internal purposes such as auditing, data analysis, and research to improve our services and customer communications;

• resolving customer and/or service-related issues;

• sending important notices, such as communications about purchases and changes to our terms, conditions, and policies;

• sending newsletters or emails regarding our services, offers and/or events upon your consent;

• compliance with obligations imposed by laws, regulations or Community legislation (including anti-money laundering laws) and to establish or defend a legal claim.

Disclosure of your personal data

The Company strives to protect the privacy and security of your personal data. For this reason, we shall only disclose your personal data to third parties, if you have provided your written consent or if it is required by law, legal process, litigation, enforceable agreements and/or requests from public and governmental authorities. We do not share or transmit your personal data to third parties unless this is required by law or is a necessary action to fulfill our contractual obligation to you. Our personnel is properly trained regarding the need to protect your privacy and personal data and we continuously improve the protection of your personal data against unauthorized use, accidental loss, dissemination or destruction.

We may also disclose your personal data to our afiliates and subsidiares or other companies, such as IT and communications service providers, auditing companies, data management support partners, online booking platforms and other parties bearing a necessary relationship for the Company to provide its services. We shall not transfer your personal data in countries outside of the EEA without your prior notice and/or written consent and ensuring appropriate safeguards are in place, as provided under applicable legislation.

Data subject’s rights

Once you have provided us with your personal data, you may exercise your rights (Article 15 and subsequent of Regulation (EU) 2016/679 - GDPR), including the right of access, the right to rectification, the right to restriction of processing, the right to erasure (“right to be forgotten”), the right to object to processing and the right to data portability, where technically feasible, by contacting us by email at reservations@kantounibeach.gr. Where the processing is based on your consent, you can at any time withdraw your consent without affecting the lawfulness of processing based on consent before its withdrawal. You also have the right to file a complaint with the Hellenic Data Protection Authority by using the following link.

In case you exercise one of the above rights, the Company shall use its best efforts to respond to your request in writing within one (1) month, otherwise the Company will explain the reasons why a right cannot be exercised or a request cannot be satisfied in accordance with the GDPR.

We encourage you to keep your personal settings and personal data complete and current. Where applicable laws require so, we will ask you to “opt-in” or affirmatively consent to the processing of your personal data.

Retention period

Your personal data will be kept for as long as necessary to achieve the purposes for which they were collected and will be stored in compliance with the time limits provided by the Hellenic Data Protection Authority or applicable laws. When the data storage time is expired or in case there is no contractual or legal obligation regarding the retention, that said data will be erased or made anonymous. CVs of job applicants not chosen will be deleted within six (6) months after their submission.

Children

Our website is general audience site and we do not intentionally collect personal data from children under the age of 16, unless provided by our customers through the services we provide to them. In this case, we take all necessary measures to ensure confidentiality and security of such data. Children should always get their parents’ permission before disclosing any personal data about themselves (such as their names, email addresses etc.).

Cookies

The Company takes privacy and security very seriously, and strives to put our website users first in all aspects of our business. We utilise cookies to help you get the most out of the Pages. For more information please read our Cookies Policy.

Third-party websites

During your online use of our websites, you may encounter links to other websites for your convenience and information. These websites may operate independently from the Company, and may have their own privacy notices, statements or policies. We strongly suggest that you review them to understand how your personal data may be processed in connection with those sites, as we are not responsible for the content of websites not owned or managed by the Company, or the use or privacy practices of those sites.

Service providers

The Company implements appropriate technical and organisational measures to protect your personal data and has ensured that similar measures are implemented by all our service providers and data processors.

Notwithstanding the above, for the purposes of providing our services, we may use third-party service providers (including email marketing platforms, online booking systems such as WebHotelier, and analytics providers), who process personal data on our behalf as data processors pursuant to Article 28 GDPR. Such providers are carefully selected and are required to implement appropriate technical and organisational measures to protect your personal data. Where such providers are located outside the EEA, transfers are subject to appropriate safeguards as provided under applicable legislation. For any further details you may contact reservations@kantounibeach.gr.

Security

The Company implements the appropriate technical and organizational measures to protect your personal data. The information you disclose to us is processed exclusively by specially authorized personnel of the Company that is under our control and only upon our order. For the prosecution of the processing, we choose persons with respective professional qualifications, that provide sufficient guarantees, in terms of technical knowledge and personal integrity to maintain confidentiality. The Company uses a variety of security technologies and organisational procedures to protect your personal data such as access controls, firewalls, secure servers and encryption of certain types of data.

Updates to this Privacy Notice

This Privacy Notice is effective as of the date last modified. The services that the Company provides are always evolving and the form and nature of the services that the Company provides may change from time to time, without prior notice to you. For this reason, we reserve the right to amend or add to this Privacy Notice from time to time and any material revisions shall be posted on our websites.

A new privacy notice will be effective upon posting. If you do not agree to the revised notice, you should alter your preferences, or consider to stop using the Pages or services. By continuing to access or make use of our services after the changes become effective, you agree to be bound by the revised Privacy Notice.

How to contact us

For any privacy related matters you may contact us at reservations@kantounibeach.gr.

(last updated: August 2026)

Cookie SettingsCookie Settings