SPIRIDAKOS RENT A CAR (we), as a company operating in the field of car rental we have to operate under the General Data Protection Regulation (GDPR), as established by the new Regulation (EU) 2016/679 of the European Parliament , the greek law No 4624/2019 and their obligations on us and our customers. This privacy policy explains how we may collect and use information (personal data) that you provide us and for what reasons. Furthermore, we would like to inform you about your rights in relation to that information (personal data).
This website is not intended for children and we do not knowingly collect data relating to children.

A. Data information we collect and for what reasons :

Personal data, or personal information, means any information about an individual, which can be used to identify that person. It does not include data where the identity has been removed (anonymous data).
We only collect these categories of personal data that are necessary for the purposes of our services. Specifically:
Full name, full address, driving license, Internet Protocol address (IP address), email address, phone number, payment details (bank account number, IBAN, card details etc), document to prove personal ID for security reasons (ID, passport and visa information), tax details, company tax details. We also collect information about you from cookies and similar tracking technologies, such as web beacons, pixels, and mobile identifiers. We do not collect “sensitive information”. If you interact with us through social media, this may include your social media user name.

B. Legal grounds for processing your personal data

We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
● Where we need to perform the contract we are about to enter into or have entered into with you.
The provision of the services you appoint us for and you wish to receive from us,
Complying with a statutory obligation, such us returning prepayment, managing your claims etc,
Safeguarding and protecting the legitimate interests of yours as well as ours.
The consent you provide us with under the specific conditions set out in the legal framework in order to receive updates on services and offers.
We may use personal data :
for complying with our legal obligations
for safeguarding our legitimate interests and for the protection of persons and goods,
for communicating with you in order to process your reservation.

When you make a reservation with us we may need to collect some of your personal data by law, or under the terms of a contract we have with you. This means that if you decide not to give us your data, we might not be able to provide the service, and may have to cancel your booking. We will let you know if this is the case at the time, so you can decide what you’d like to do.

C. Share information – Transfer to third – party associates:

We share your personal data with the following categories of recipients :
Governmental authorities, law enforcement agencies etc
Ours associates (accountants and insurers). We declare that we do not sell the information you provide us.

D. Cookies

Our website uses “cookies”. Cookies are small pieces of information which are sent by a website to your web browser and remain on your computer until they are deleted. Cookies are sent by our website to ensure that it does not unnecessarily show you information that you have already seen or have indicated as not being of interest to you. Cookies therefore enable our website to offer you a more personalized service. You agree to our use of cookies and/or any other data tracking or gathering technologies we employ in the future.
Cookies help us to provide you with a good experience when you use our website and also allow us to improve our website and services. We use the following categories of cookies:
● Strictly necessary cookies. These are cookies which are needed to make the website work properly. For example, cookies enable you to log in, make a booking
● Functionality cookies. These are used to recognize you when you return to our website. This helps us to personalize our content for you and remember your preferences.
● Analytical/performance cookies. These allow us to recognize and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
● Targeting cookies. These cookies record your visit to our website, the pages you have visited and the links you have followed. This forms part of Tacking Data.
The data received from our website cookies is anonymized data, therefore individuals cannot be identified.
Please note that third parties (including, for example, advertising networks and providers of external services like web traffic analysis services) may also use cookies, and we have no control over this. These cookies are likely to be analytical/performance cookies or targeting cookies.
We can use strictly necessary and functional cookies without consent. We gain your consent for other cookies via the banner that you see the first time you visit our website. You can choose not to consent. You can also block cookies by activating the setting on your browser that allows you to refuse the setting of all or some cookies.
However, if you do not consent, or use your browser settings to block all cookies (including essential cookies), you may not be able to access all or parts of our site.
Adjusting your browser’s cookie settings
If you are using Internet Explorer 11, 10, 9, 8, 7, 6
Choose Tools then
Internet Options
Select the Privacy tab,
Under settings, select Advanced
Check Override automatic cookie handling
Check and choose if you want to allow, block or be prompted for first and third-party cookies.
If you are using Internet Explorer 5.0 or 5.5:
Choose Tools, then
Internet Options
Click the Security tab
Click on Custom Level
Scroll down to the sixth option to see how cookies are handled by IE5 and change to Accept, Disable, or Prompt for action as appropriate.
If you are using Internet Explorer 4.0
Choose View, then
Internet Options
Click the Advanced tab
Scroll down to the yellow exclamation icon under Security and choose one of the three options to regulate your use of cookies.
In Internet Explorer 3.0: You can View, Options, Advanced, then click on the button that says Warn before Accepting Cookies.
If you are using Chrome
At the top right, click More and then Settings
At the bottom, click Advanced
Under “Privacy and security,” click Content settings
Click Cookies
From here, you can,
Turn on cookies: Next to “Blocked,” turn on the switch
Turn off cookies: Turn off Allow sites to save and read cookie data
If you are using Safari
Choose Preferences
Click Privacy, then do any of the following:
Always block cookies: Select ‘Block all cookies’
If you are using Firefox
Select Options from the right side of the drop-down menu.
Click Privacy & Security tab
In History, select the use custom settings for history option in the drop-down menu of the panel’s History section.
There you will have the option to tick or untick, always use private browsing mode, remember my browsing and download history, remember search and from history, accept cookies from web sites or clear history when Firefox closes.

E. Data Controller: SPIRIDAKOS RENT A CAR, having its registered office in Fira Santorini, email: rentacar@spiridakos.gr, tel: +30 22860 23755, +30 22860 24240 fax: +30 22860 24790, website : www.rentacar-santorini.com, informs that, for the purposes of its business, it processes personal data of its customers in accordance with applicable national law (No 4624/2019) and the European Regulation 2016/679 on the protection of individuals with regard to the processing of personal data.

F. Your rights
Access, update, withdraw amend or correct : You may have the right to access and receive a copy of the personal information we hold about you, update, withdraw, amend or correct any information.
Change, restrict and delete : You may have the right to change, restrict or delete your personal data stored by us. This enables you to ask us to delete or remove personal data where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing, where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
Data portability : You may have the right to receive your personal data free of charge in a format that allows you to access, use and edit them. You also have the right to ask us, if it is technically feasible, to pass the data directly to another processor.
Object and complaint: You may have the right to object to the use of data by us, in case we use the information for illegal or unauthorized purposes. To exercise these rights or to make a complaint about our privacy practices, please contact us, by using the contact information stated above. Finally, if you are a resident in EU, or a citizen of EU, and wish to raise a concern about our use of your information you have the right to do so with your local data protection authority.

G. SECURITY
We take all necessary technical and organizational measures to ensure the secure processing of your personal data and to prevent any accidental loss or destruction and any unauthorized and/or illegal access, use, alteration or disclosure of your data. Any personal data in hard copy format will be kept in a locked filing cabinet, drawer or safe, with restricted access in our premises, and only the Data Controller and ours Data Processors have access to the data. These premises are protected by CCTV camera systems. Confidential paper records will not be left unattended or in clear view anywhere with general access. All electronic devices are password-protected to protect the information on the device in case of theft. Digital data is coded, encrypted or password-protected, on a network drive that is regularly backed up on and off-site. All members of staff are provided with their own secure login and password, and every computer regularly prompts users to change their password. Emails containing sensitive or confidential information are password-protected if there are unsecure servers between the sender and the recipient. The security of our computer and storage systems, and access to them, is continuously monitored.
However, given the way that Internet works and the fact that is freely accessible to anyone, we are unable to guarantee that no unauthorized third parties will ever be able to circumvent such measures and gain access, or even make use of your personal information for unauthorized and/or unlawful purposes. Furthermore, we bear no responsibility for payments that take place in other bank accounts, as a result of hacking. For your safety, we recommend you before paying, contact with us to verify the correct bank accounts.

H. DATA RETENTION
We will only keep your personal data for as long as we need to fulfill the purposes we collected it for, including for satisfying any legal, accounting, or reporting requirements. The length of time we keep your information will vary depending on the obligations of European and national legal framework.
To decide how long we should keep your personal data for, we consider the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorized use or sharing of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements.
By law we have to keep basic information about our customers (including contact, identity, payment details and transaction data) after they cease being customers for tax purposes.

I. HOW TO CONTACT US FOR GDPR ISSUES
For the purposes of EU law, if you have any questions, requests or concerns you may contact us, Manager for GDPR issues Prokopia Agioreitou, via email at rentacar@spiridakos.gr, tel: +30 22860 23755, +30 22860 24240 fax: +30 22860 24790, via mail address Fira (25is Martiou) Santorini 84 700, Greece.

Santorini Yacht Cruises by Spiridakos Sailing Cruises