Privacy Policy
The Noverian Bios Caldera, Sunset Suites — Santorini, Greece
Last updated: April 2026
1. Introduction
The Noverian Bios Caldera, Sunset Suites ("we", "us", or "our") is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Greek data protection law. This Privacy Policy explains how we collect, use, store, and protect your personal information.
2. Data Controller
The Noverian Bios Caldera, Sunset Suites
Santorini, Greece
Email: info@noveriancaldera.com
Website: https://noveriancaldera.com
3. What Data We Collect
We collect the following personal data:
- Identity data: full name, nationality, passport/ID number (required by Greek law for hotel registration)
- Contact data: email address, phone number, postal address
- Booking data: check-in/out dates, room preferences, special requests, number of guests
- Payment data: billing information (processed securely via third-party payment processor — we do not store card details)
- Communication data: messages and emails you send us
- Technical data: IP address, browser type, cookies (see Section 8)
4. Legal Basis for Processing (GDPR Article 6)
We process your data on the following legal bases:
- Contractual necessity (Art. 6(1)(b)): to fulfill your reservation and provide hotel services
- Legal obligation (Art. 6(1)(c)): Greek Law 4172/2013 and hotel registration regulations require we record guest identity
- Legitimate interest (Art. 6(1)(f)): property security (CCTV), fraud prevention, and improving our services
- Consent (Art. 6(1)(a)): for marketing communications — you may withdraw consent at any time
5. How We Use Your Information
- Processing and managing your reservation
- Check-in procedures and Greek hotel registration compliance
- Payment processing
- Communicating with you about your stay
- Sending promotional offers (only with your explicit consent)
- Improving our services and website
6. Data Sharing
We do not sell your personal data. We share data only with:
- Payment processors: to complete transactions securely
- Online Travel Agencies (OTAs): when bookings are made through platforms such as Booking.com or Expedia
- Greek authorities: as required by law (e.g., tourist police registration)
- IT/software service providers: operating under Data Processing Agreements (DPAs)
All third-party processors are contractually bound to handle your data in compliance with GDPR.
7. Data Retention
| Data Type | Retention Period |
|---|---|
| Booking & reservation records | 5 years (tax and legal compliance) |
| Guest identity records | As required by Greek hotel law |
| Marketing consent records | Until consent is withdrawn |
| CCTV footage | 30 days, then deleted |
| General correspondence | 2 years |
8. Cookies
Our website uses cookies to ensure functionality and analyse traffic. For full details, see our Cookie Policy. You may manage cookie preferences via your browser settings.
9. Your Rights under GDPR
You have the right to:
- Access your personal data (Art. 15)
- Rectify inaccurate data (Art. 16)
- Eraseyour data ("right to be forgotten") (Art. 17)
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior processing
To exercise any of these rights, contact us at: info@noveriancaldera.com We will respond within 30 days.
10. Right to Lodge a Complaint
If you believe your data rights have been violated, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
- Website: https://www.dpa.gr
- Email: complaints@dpa.gr
- Phone: +30 210 647 5600
- Address: Kifissias 1–3, 115 23 Athens, Greece
11. Data Security
We implement appropriate technical and organisational measures to protect your data, including encrypted systems, restricted staff access, and secure network infrastructure.
12. Changes to This Policy
We may update this policy periodically. The latest version is always published on this page with the "Last updated" date above.
13. Contact Us
For any privacy-related questions: Contact Us
