PERSONAL DATA PROTECTION POLICY
According to the current legislation, the company Olympion S.A, which is located in 13 Fragon Str., Thessaloniki and has a branch at Fourka Beach at Kassandra area of Chalkidhiki district with the distinctive title "Olympion sunset", is responsible for processing the personal data that you provide, in the context of trade cooperation with the company. Olympion S.A. is committed to protect the personal data of the visitors / users of the www.olympion-sunset.com website and to comply with the relevant provisions on the protection of personal data as they apply. Olympion S.A. does not collect information on visitors’/ users' personal data unless they are provided voluntarily. Data collected from Olympion SA are those required and used only for the purposes for which they are collected, excluding any other non-desired use thereof. No personal data is required to navigate at the www.olympion-sunset.com site or to access its content.
The current Policy imprints and describes the Data Protection Management System of Olympion S.A and comprises the basic data protection principles that the company must provide to all users involved (internal and external partners).
Additionally, Olympion S.A constantly provides the necessary resources for the proper implementation of the Policy, by all departments, systems, company users, services, as well as any related activities.
- How are your rights being protected?
Olympion S.A implements an information security management system to ensure the confidentiality and security of your data and protect them against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access and all other unlawful forms of processing. This information is provided in accordance to Regulation (EU) 2016/679 of the European Parliament, the European Council and the provisions of the Greek legislation on the protection of personal data adopted and applied in this context, superseding any prior information received under the Law 2472/1997 and may refer to contractual or other documents of Olympion S.A.
- Which data do we process?
Your personal data processed by Olympion S.A may be:
1. Identity or passport information such as name, surname, nationality.
2. Contact details, such as phone number, email.
3. Booking information such as date and time of arrival and departure, room number.
4. Car Details.
5. Data regarding your professional status and / or expertise.
6. Tax Registry number and competent tax office
7. Credit or debit card details
- Why do we collect Personal Data?
The above-mentioned information and personal data that Olympion S.A collects from you will be stored in the Company's databases and servers, always in accordance with the provisions of the current legislation, particularly with those concerning the protection of the privacy of communications and the protection of the person itself from the processing of personal data.
The Olympion S.A explicitly declares that this data will not be shared, in any case, with third parties unless it is ordered differently by law or court, prosecutor's order or decision / other Public Authority provision as well as written authorization from the subject of such data.
The legal basis for your data processing is your consent, as well as the necessity of their storage for the company's response to your requests of any form provided by the relevant legislation.
Specifically, we process your data in order to provide your accommodation and catering services, information regarding the products and services provided by our company (offers and other informational material of our company) and for our response to your requests in any form, such as providing information, formulating complaints, evaluating services, etc.
The processing of your personal data is done by designated and authorized employees of Olympion S.A.
Recipients of your personal data may also be third parties, external partners such as wellness and care services, customer transport services, leisure trips organizers, IT support, medical support, courier and mail services, to the extent it is necessary for your accomodation and the provision of our services. In this case, Olympion S.A is committed that its partners, acting only under its instructions, have been specifically authorized for that purpose and are fully bound by the confidentiality and obligations described by the law, regarding the collection and processing of the above data.
- Time of retention
Olympion S.A retains your data for as long as it is required to fulfill the purpose for which you have shared them with us and in compliance with the applicable laws of personal data protection.
- Your rights
Regarding the processing of your previously mentioned data, you have the right to request and receive from the Olympion S.A the following information:
i All personal data concerning you
ii. Processing purposes and any recipients
iii. Correcting your data kept on file and maintaining the right to raise any objections on data concerning you
In particular, your rights are the following:
• The Right to access - Right to receive information on whether your data is processed and accessed, as well as the right to receive information about this processing (who, for what purpose, recipients, retention period, etc.).
• The Right to rectification - Right to correct inaccurate personal data and fill in incomplete information.
• The Right to erasure (Right to be forgotten) - Right to request the deletion of any of your data under certain conditions (data that are no longer necessary, withdrawal of consent, etc.). You have the right to withdraw your consent, but the withdrawal is valid for the future data, meaning since your notification to Olympion S.A, and it cannot have a retroactive effect.
• The Right to Restrict Processing - e.g. when the accuracy of the data is in dispute, the data are no longer needed by the controller etc.
•The Right to data portability - The Right to request the transfer of personal data to another Processing Manager in a structured, widely used and mechanically readable form. In case of exercising the right of correction, deleting and restricting the data, the applications will be transmitted to third party recipients to whom the data were disclosed.
The above services are provided free of charge. However, if the claims are manifestly unfounded, excessive or repetitive, Olympion S.A may refuse to respond to these requests, by informing the applicant accordingly.
Olympion S.A has taken all technical measures to protect your personal data. It provides restricted access only to those employees / collaborators who need to have access to these data. The company will take all necessary measures to prevent any unauthorized access and use or modification of such data. The company complies with current legislation and has set up procedures for data protection.
- Collection of personal data from website
The policy of personal data protection includes and refers to the conditions of collecting and managing your personal information by Olympion S.A during the use of its services and visit of web sites. The Olympion S.A is the owner and holder of all rights of the page and Controller of data that may be declared by you.
This current policy does not cover, in any way, the legal relationship between visitors / users of the web pages and any other services that are not subject to control over the management and ownership of Olympion S.A even when it includes links to other sites controlled by third parties (individuals or entities).
The current policy of personal data protection applies only to the selection and processing operations carried out by Olympion S.A through its website and does not apply to information selected via any other collection and processing activity initiated by the company.
Most of our services do not require registration to visit and browse our site without having to disclose your identity. However, in some cases, it may be necessary to sign up to access some services. In case you hide your identity, you may not be allowed to access certain parts and services of our website.
The cookies used by this website only serve the purposes of navigation, the website functionality, to facilitate navigation and therefore does not collect personal data.
- Personal data and children
The current website is not directed to children under 13 years old. It is our policy not to collect or keep data of people under 13 years of age. In any case, most of the information provided by Olympion S.A websites is addressed to people aged 18 years or over.
Olympion S.A will not collect, use, or disclose on purpose personal data from minors under the age of 18 without having obtained first the consent of the parent or guardian through direct communication, offline, over a network.
The Olympion S.A does not deliberately collect personal information from minors under 18 years old. If it finds out that it has collected any personal data from a minor under 18 without a verifiable parental consent, it will delete the data from its database as soon as possible.
- The purpose of the protection of personal data policy.
The policy aims to ensure the following:
• Continuous data protection from unauthorized access.
• Continuous ensuring of the Confidentiality of OLYMPION S.A customers and associates data.
• Continuous maintenance of the integrity of Olympion S.A, customers and associates data.
• Continuous Ensuring of the Availability of Data and Business Processes.
• Continuous monitoring and compliance with Legislative and Regulatory Requirements.
• The Business Continuity Plan is maintained and controlled for its effectiveness.
• Continuous Data Protection training for all employees of Olympion S.A.
• Confirmed or suspected violations of personal data are reported to the Data Protection Officer, are thoroughly investigated and addressed promptly and effectively.
• Appropriate procedures and individual data protection policies have been developed and implemented in support of this policy, including technical and organizational protection measures.
• Olympion S.A ensures constant compliance with the legislation and requirements of GDPR through extended monitoring of the implementation of the Data Protection Management System.
• The Data Protection Officer is responsible for maintaining the Policy, as well as for providing support and advice in its implementation.
• All holders of managerial positions of Olympion S.A are directly responsible for implementing the Policy as well as for ensuring the compliance of the supervising personnel.
• The compliance with the Policy is mandatory for all those who work or cooperate with Olympion S.A.
• Any violations of the Policy are subject to disciplinary sanctions depending on the nature and impact of the infringement.
- Change of policy
The Olympion S.A preserves the right to change this policy by updating the current text in order to comply with the applicable legislation on data protection as well as for any other reason deemed necessary.
- Contact Information
If you believe that your privacy is affected in any way, you can appeal to the Data Protection Authority.
Competent courts for any disputes related to your data are Thessaloniki’s’ Courts.