Privacy Policy

PERSONAL DATA
Intro
We would like to assure you that for Kalderimi Country House, a company based in Mouresi village P.C. 37012,
email: [email protected], tel:(+30) 24260 49453, website: www.kalderimihotel.gr (henceforth Company),
the protection of our customers' personal data is of paramount importance. For this reason, we take appropriate
measures to protect the personal data of our customers, which we process and to ensure that the processing of
these data is always carried out in accordance with the obligations set by the applicable legislative framework,
both by the company itself and by third parties who cooperate with us.
Controller – Data Protection Officer (DPO)
The Company informs you that, for the purposes of carrying out its business activities, it is processing the personal
data of its customers in accordance with the current national law and European Regulation 2016/679 concerning
the protection of individuals with regard to the processing of personal data and on the free movement of such
data (General Data Protection Regulation, henceforth referred to as the "Regulation") as applicable. For any
information regarding the processing of personal data, please contact the personal data department by email in
the following email address: [email protected] , with the Data Protection Officer (DPO).
What is the purpose of processing and how we use your personal data
Your data is used in a variety of ways that vary depending on the processing purpose. There are cases in which the
Company will not be able to take action unless it has collected your specific personal data, such as:
In particular, we need:
 the name and surname (for natural persons) and the name, ΤΙΝ number, Local Tax Office Number, activity
and name of the consignee (for businesses).
 The full billing address (street, number, P.C., city).
 The phone number so we can contact you.
 Your mobile phone number for your electronic information via e-mail and/or telephone communication.
 your e-mail address so that you are able to receive updates.
It is necessary for you to provide us with all the above information, both in order to prevent and to detect fraud
against you and against the Company.
Following your consent and in case you have notified us, either when you create a membership account on this
website or when you subscribe to our newsletters and personalized communication your necessary personal
information where appropriate, the following possibilities are provided:
Subscription to newsletters and receiving updates and offers:
In order to subscribe to the Company's newsletters and send updates and/or offers and/or promotions, you must
provide us with your email address in our online store. By registering, sending newsletters and personalized
updates, you give us your express consent to receive all our updates and/or offers and/or promotions that we send
via emails and text messages or Instant messaging through the relevant services (e.g. by SMS, Viber, Push
Notifications etc).
Creation of a member account:
To create a membership account in our online store, you must provide us with your email address and set your
own personal passwords. By subscribing to the https://www.kalderimihotel.grwebsite, you give us your express
consent, to receive all our updates and/or offers and/or promotions that we send via e-mails and textmessages.
Customer Satisfaction Survey

Your personal data collected from our website is used to participate in a Customer Satisfaction Survey, subject to
the specific conditions set by the applicable legislative framework. The Customer Satisfaction Survey today is
conducted through electronic communication with you.
Personalized communication ("Profiling")
In order to offer you the best possible browsing experience on our website, your personal data we collect may be
used to send personalized updates, provided you have given your consent, subject to the specific conditions set by
the applicable legislative framework.
Creation of a member account using social media:
To create a membership account using social media you must give your prior consent to each social media. An
essential item we receive from social media is your email address. The additional information we receive depends
on the social media. Examples may be your gender or date of birth or both if and when you have declared them as
public information. By creating a membership account, in accordance with the above, you give us your consent to
place your next orders without having to re-enter your details. You'll now be able to enjoy an optimal experience
with access to your account information, your history, and the status of your preferences ("favorites") and all the
settings offered on the My Account page. This will give you access to all your information so that you can fill it out
or modify it, as appropriate. You will be able to enter in your account all the information necessary to execute your
orders so that you do not have to fill them out every time you place a new order. You will also be able, if you wish,
to add additional information such as your gender and date of birth, which will allow us to offer you an even closer
to your needs and more personalized information.
Credit/Debit Card Details
Your credit/debit card details will be requested upon completion of your order, if you choose the relevant payment
method and will be used exclusively for their electronic transmission through the secure environment of the
partner bank to complete your payment alone. The Company does not store any credit/debit card information in
its electronic systems or in a physical file. Certification of the cardholder may require the transfer of your card
details to a third party provider, working with the bank that implements the completion of the card payment
process.
What are the legal reasons for processing your personal data?
The personal data you provide with your express consent to the Company, can only be processed by us when there
is a legitimate reason.
Legal reasons for processing your personal data are:
 the execution of the sale of the goods you have purchased from our online store
https://www.kalderimihotel.gr and consequently the fulfilment of our contractual obligations in this
context, proof of submission of your orders, after-sales support, the possibility of contacting you about
your orders and generally where it is reasonably necessary or required to use them to comply with legal
or regulatory requirements, resolve disputes, prevent fraud and abuse
 the safeguarding and protection of the legal interests of both yours and ours, for this reason we use
special security software to detect and prevent malicious acts. In particular, in our online store, we collect
information, such as your IP address, location information, users' devices, and so on, in order to detect or
prevent fraud or abuse of our website.
 compliance with various obligations imposed by law, such as regulatory compliance for tax purposes, e-
commerce legislation.
 the consent you give to the Company, under the specific conditions set by the applicable legislative
framework, to subscribe to newsletters, receive updates on products, offers and/or promotions,
participate in customer satisfaction surveys, receive personalized updates, etc.
Are minors and children allowed to use our online store?

The Company does not sell its goods, through its online store, to children and minors under the age of 18. If you
are under the age of 18, you can make purchases from our website only with the participation and approval of a
parent or guardian.
Where do we transfer the data to?
In order to fulfill the above mentioned purposes of processing your personal data, the Company may disclose or
transmit personal data that you have given to us to subsidiaries or affiliates of the Company, or to third party
service providers who in cooperation with it assist in the proper functioning of this website, such as but not limited
to , technology service providers for the protection and security of our electronic systems, advertising companies,
as well as our partner companies to run corporate and customer reward programs, companies that conduct
customer satisfaction research. In particular, for the purposes of implementing and executing each sale through
our online store, your necessary information is transmitted to cooperating companies entrusted with the
performance of part of the contract such as logistics, transport, order management, etc.
In all of the above cases the Company remains responsible for the processing of your personal data and defines the
individual elements of the processing, and signs a special contract with the third parties to whom it entrusts the
execution of processing activities, in order to ensure that the processing is carried out in accordance with the
applicable legislative framework and that any natural person can freely and unhindered exercise the rights granted
to him by the applicable legislative framework.
Storage of your personal data
The Company undertakes to keep with absolute confidentiality the record of personal data that you have stated to
us when you register on our website, as well as your transaction history in our online store
https://www.kalderimihotel.gr and only for the purposes of processing the above.
 Where processing is required as an obligation by provisions of the current legislative framework, your
personal data will be stored for as long as the relevant provisions require.
 When processing is performed on the basis of a contract, your personal data shall be stored for as long as
is necessary for the performance of the contract and for the establishment, exercise, and/or support of
legal claims under the contract.
 For various promotional/marketing activities, your personal data is kept until your consent is revoked. You
may exercise this right at any time. Withdrawal of your consent shall be without prejudice to the
lawfulness of the processing based on your consent in the period prior to its withdrawal.
 We will also keep the account data you created on our website stored for as long as you keep it and have
not requested that it be deleted. If required to comply with legal or regulatory requirements, resolve
disputes, prevent fraud and abuse, or enforce the terms and conditions of access to this website, we may
keep some of your data stored as required, even after deleting your account.
 To withdraw your consent, please contact the Company's Data Protection Officer (DPO) at the following
contact details: email: [email protected]
What are your rights in relation to your personal data?
Any natural person whose data is processed by the Company reserves the following rights:
Right of access:
You have the right to have immediate access to information on matters relating to your personal data and to verify
the time and manner of their initial storage, as well as information on the methods of processing and protection
applied.
Right of correction:
You have the right to study, correct, update or modify your personal data.
Right to erasure:

You have the right to make a written request to delete your personal data from the Company's file at any time,
provided that we have processed it with your prior consent. In all other cases (such as, but not limited to, where
there is a contract, an obligation to process personal data imposed by law, a public interest), this right is subject to
specific restrictions or does not exist, as the case may be.
Right to restrict processing:
You have the right to request a restriction on the processing of your personal data in the following cases: (a) when
you question the accuracy of your personal data and until it is verified, (b) when you do not wish to delete your
personal data and you request instead of deletion the restriction of their use, (c) when your personal data is not
used for processing purposes , however, they are necessary to establish, exercise and support legal claims, and (d)
when you object to processing and until it is verified that there are legitimate reasons that concern us and take
precedence over the reasons why you object to processing.
Right to object to processing:
You have the right to object at any time to the processing of your personal data in cases where, as described
above, it is necessary for the purposes of legal interests that we pursue as controllers, as well as to the processing
for the purposes of direct marketing and training of consumer profiles.
Right to portability:
You have the right to receive, free of charge, a copy of the "customer card" containing your personal data in
electronic or printed form, allowing you to access, verify and edit it using the commonly used processing methods.
You also have the right to ask us, if technically feasible, to transmit your data directly to another controller. This
right may be exercised for the data provided to us by you and their processing is carried out by automated means,
with your prior consent or in the performance of a contract.
Right to withdraw consent:
Finally, the Company informs you that in cases where your personal data is processed with your prior consent, you
have the right to withdraw it freely, without affecting the legality of the processing based on your consent before
revoking it. In order to exercise any of the above rights you can contact the Data Protection Officer (DPO) in writing
at the following contact details: email: [email protected]
Right to complain to the IFRS
You have the right to lodge a complaint to Data Processing Agreement ( www.dpa.gr ) at : TelephoneCentre: (+30)
210 6475600, Fax: (+30) 210 6475628, E-mail: [email protected]
Personal Data Security
The Company has taken care of and implements appropriate technical and organizational measures aimed at the
safe processing of your personal data and the prevention of accidental loss or destruction and unauthorized
and/or illegal access to them, use, modification or disclosure. In any event, the way the Internet works and the fact
that it is free to anyone does not allow guarantees to be provided that unauthorised third parties will never be
able to breach the technical and organisational measures applied by gaining access to and possibly using personal
data for unauthorised and/or unfair purposes.