Privacy Policy

The Noverian Bios Caldera, Sunset Suites — Santorini, Greece

Last updated: April 2026

1. Introduction

The Noverian Bios Caldera, Sunset Suites ("we", "us", or "our") is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 (GDPR) and applicable Greek data protection law. This Privacy Policy explains how we collect, use, store, and protect your personal information.

2. Data Controller

The Noverian Bios Caldera, Sunset Suites

Santorini, Greece

Email: info@noveriancaldera.com

Website: https://noveriancaldera.com

3. What Data We Collect

We collect the following personal data:

  • Identity data: full name, nationality, passport/ID number (required by Greek law for hotel registration)
  • Contact data: email address, phone number, postal address
  • Booking data: check-in/out dates, room preferences, special requests, number of guests
  • Payment data: billing information (processed securely via third-party payment processor — we do not store card details)
  • Communication data: messages and emails you send us
  • Technical data: IP address, browser type, cookies (see Section 8)

4. Legal Basis for Processing (GDPR Article 6)

We process your data on the following legal bases:

  • Contractual necessity (Art. 6(1)(b)): to fulfill your reservation and provide hotel services
  • Legal obligation (Art. 6(1)(c)): Greek Law 4172/2013 and hotel registration regulations require we record guest identity
  • Legitimate interest (Art. 6(1)(f)): property security (CCTV), fraud prevention, and improving our services
  • Consent (Art. 6(1)(a)): for marketing communications — you may withdraw consent at any time

5. How We Use Your Information

  • Processing and managing your reservation
  • Check-in procedures and Greek hotel registration compliance
  • Payment processing
  • Communicating with you about your stay
  • Sending promotional offers (only with your explicit consent)
  • Improving our services and website

6. Data Sharing

We do not sell your personal data. We share data only with:

  • Payment processors: to complete transactions securely
  • Online Travel Agencies (OTAs): when bookings are made through platforms such as Booking.com or Expedia
  • Greek authorities: as required by law (e.g., tourist police registration)
  • IT/software service providers: operating under Data Processing Agreements (DPAs)

All third-party processors are contractually bound to handle your data in compliance with GDPR.

7. Data Retention

Data TypeRetention Period
Booking & reservation records5 years (tax and legal compliance)
Guest identity recordsAs required by Greek hotel law
Marketing consent recordsUntil consent is withdrawn
CCTV footage30 days, then deleted
General correspondence2 years

8. Cookies

Our website uses cookies to ensure functionality and analyse traffic. For full details, see our Cookie Policy. You may manage cookie preferences via your browser settings.

9. Your Rights under GDPR

You have the right to:

  • Access your personal data (Art. 15)
  • Rectify inaccurate data (Art. 16)
  • Eraseyour data ("right to be forgotten") (Art. 17)
  • Restrict processing (Art. 18)
  • Data portability (Art. 20)
  • Object to processing based on legitimate interest (Art. 21)
  • Withdraw consent at any time, without affecting prior processing

To exercise any of these rights, contact us at: info@noveriancaldera.com We will respond within 30 days.

10. Right to Lodge a Complaint

If you believe your data rights have been violated, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

  • Website: https://www.dpa.gr
  • Email: complaints@dpa.gr
  • Phone: +30 210 647 5600
  • Address: Kifissias 1–3, 115 23 Athens, Greece

11. Data Security

We implement appropriate technical and organisational measures to protect your data, including encrypted systems, restricted staff access, and secure network infrastructure.

12. Changes to This Policy

We may update this policy periodically. The latest version is always published on this page with the "Last updated" date above.

13. Contact Us

For any privacy-related questions: Contact Us