Privacy Notice

Last Updated: May 24th, 2018

At Luxury Resorts Ltd, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Luxury Resorts Ltd.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://mmvilla.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Luxury Resorts Ltd.

Data Controller

Luxury Resorts Ltd operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Manu Mykonos Luxury Villa “Luxury Resorts Ltd”
Agia Anna
846 00, Mykonos
GR

Data Processor

WebHotelier operates this booking system on behalf of Luxury Resorts Ltd and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Luxury Resorts Ltd, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Luxury Resorts Ltd;
  • to pass on your financial details to Luxury Resorts Ltd and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

PRIVACY POLICY

This Website is owned by the company Luxury Resorts Ltd.

Information about our company and websites

This Privacy Policy provides notice to you of the privacy practices, the choices you can make about the way your information is collected online, how that information is used and the rights that you have if your use of this website falls under the jurisdiction of the General Data Protection Regulation 2016/679 (“GDPR”).

Please read this Privacy Policy carefully and revisit this page from time to time to review any changes that may have been made.

We may amend this Privacy Policy at any time by posting the amended terms on this site. All amended terms automatically take effect on the date set out in the posted Privacy Policy, unless otherwise specified.

Sites covered by this Privacy Policy

This Privacy Policy applies to all our company’s websites and domains including all regional or country-specific sites (collectively the “Websites”).

The Websites may provide links to third-party websites for your convenience and information. If you access those links, you will leave the Websites.

We do not control those sites or their privacy practices, which may differ from our privacy practices. This Privacy Policy does not cover any personal data that you choose to give to unrelated third parties.

We do not monitor or control the information collected by such sites or the privacy practices of any third parties, and we are not responsible for their practices or the content of their sites.

Types of information we collect and use in this policy, “personal information” or “personal data” means information about an identifiable individual that is subject jurisdiction in which you reside.

In some jurisdictions, “personal information” or “personal data” will not include business to protection under the law in the contact information.

The Websites collect information through a variety of different ways and for different purposes as follows.

If you choose to register with any of the Websites to receive updates from us, to manage your account and/or use our self-service portal, then you will be requested to provide contact information (name, address, telephone number, email address, a unique login name, and password).

We use this information under our legitimate business interests to provide our services and/or to contact you about the services on our site in which you have expressed interest.

We may also use your contact information to send you information about other company’s products and services, having obtained your consent following applicable law.

If you do not want to receive these promotional announcements on an on-going basis, you can notify us to update your preferences. You also have the option to provide demographic information (such as the type of business, size of the company, locations, etc.).

We use this demographic information to understand your needs and interests and to provide you with a more personalized experience on our site. The information is used by the company to process your orders, enable participation in promotions (subject to your marketing preferences), and so that we can provide our services to you.

Through the Websites, you can order products or services, request information, or subscribe to marketing or support materials.

In order to purchase a product or service from us, we will request specific information from you which will be used for contract performance purposes.

You will need to provide contact information (such as name, email, and address) and financial information (such as credit card number, billing address, and expiration date).

Financial information collected from you is used only to bill you for the products and services that you have purchased. If we collect credit card information from you, we only use this information for payment processing and fraud prevention. Credit card information and other similar sensitive personal data are not used for any other purpose by the company without your express consent.

We do not retain your credit card information after processing a payment unless you permit us to maintain your credit card information for future purchases.

The Websites may automatically collect technical information about your visit (such as browser type, Internet service provider, platform type, internet protocol (IP) addresses, referring/exit pages, operating system, date/time stamp).

We aggregate this information for reporting about the Websites to analyse trends, diagnose problems with our server and administer the Websites, to track user movement and use, and to gather broad demographic information.

We may be required to share information with third parties as a result of applicable law.

For example, we may be required to disclose information as a result of a court order, subpoena or warrant. Also, we may, subject to applicable law, voluntarily provide information in order to assist in a law enforcement investigation or where the disclosure is necessary to protect our systems, our business or the rights of others.

Communications

Once you register, we will send you a welcoming email. We will also respond to your inquiries, provide services you request and manage your account. We will communicate with you by email or telephone and will make every effort to honor your preference.

Subject to the marketing preferences which you give us, we will also send you information on new products, services, special savings, promotions, and general information.

If you do not want to receive this information, you can opt-out of receiving future mailings.

If you ask to subscribe to our newsletters, we will use your name and email address to send the newsletter to you. You can sign up for these newsletters from us on our registration page. You may unsubscribe at any time. When necessary, we will send you service-related announcements, which are not promotional in nature. If you do not wish to receive them, you may deactivate your account with the Website.

Please note that we do not provide your email address to our business partners. However, we may send you an offer on behalf of our business partners. You may ask to unsubscribe at any time.

Sharing information and Cross-border Transfers

We contract with third-party service providers and suppliers to deliver complete products, services and customer solutions described above. These service providers may change, or we may contract with additional service providers to better accommodate our customers. Our affiliates may provide services to you or your local member and may receive personal data about you.

If we transfer your data to affiliates or third parties, we require the recipients of your data to safeguard your personal data using administrative, technical and security procedures; however, your data will also be subject to the laws of the jurisdiction governing our affiliate or the third party.

Your personal data may be transferred across country borders to our affiliated companies to provide our services to you.

Residents of the EEA and Canada should understand that your personal data may be transferred outside of the EEA and Canada to the United States and other countries for the purposes of data consolidation, storage, simplified customer information management, reporting, and other internal uses.

Cookies and other digital markers

We automatically gather information through the use of cookies and other digital markers.

Cookies and digital markers are small computer files that may be stored on your computer’s hard drive or embedded in our website pages that enable us to identify you and track your visit on the Website.

We may use the services of third-parties to collect and process personal information through the use of cookies and other digital markers on our behalf. You may disable cookies on your computer by changing the settings in the preferences or options menu in your browser. If you choose to disable cookies, you may not be able to access certain areas of the Website.

Children’s privacy

The company is committed to protecting the privacy needs of children and we encourage parents and guardians to take an active role in their

Children’s online activities and interests

The company does not knowingly collect information from children under the age of 13 and we do not target its websites to children under 13.

Your choices and opting-out

We give you the choice of receiving a variety of information that complements our products and services. You can subscribe to receive certain product-and service-specific information and company-wide marketing communications.

Such communications may include new product information, special offers, or an invitation to participate in market research.

If you no longer wish to receive our newsletters and/or promotional communications, you may opt-out of receiving them by following the instructions included in each newsletter or communications including by contacting us.

Access to and accuracy of your information and your other rights

In certain jurisdictions, notably the EU and the UK, you have a right: to ask us for a copy of your personal information; to ask us to correct, delete or restrict (stop any active) processing of your personal data and to obtain the personal data you provide to us for a contract or with your consent and to ask us to share (port) this data to another data controller; to object to the processing of your personal information by us in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirements, or where we are using the data for direct marketing).

These rights may be limited, for example, if fulfilling your request would reveal personal data about another person or breach the privacy rights of others, or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.

If you have unresolved concerns, you have the right to make a complaint to the data protection supervisory authority where you live, work or where you believe a breach may have occurred.

Keeping your information secure

We do not guarantee or warrant the security of our servers nor can we ensure that the information you supply through the Website will not be intercepted while being transmitted over the Internet. We follow generally accepted industry technical standards to protect the personal data submitted to us, both during transmission and once we receive it. When you enter sensitive information (such as credit card information) on our registration or order forms, we encrypt that information using secured socket layer technology.

Where we process personal information for marketing purposes or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data indefinitely so that we can respect your request in the future. Where we handle personal information in connection with performing a contract or Service, or for a competition, we keep the data for six years (except for financial information which we hold for ten years) from your last interaction with us.

Business transitions

If we go through a business transition, such as a merger, acquisition by another company or sale of all or a portion of its assets, your personal information will likely be among the assets transferred.

Terms and Conditions

If you choose to visit our Websites, your visit and any dispute over privacy are subject to this Privacy Policy and our Terms and Conditions, including, but not limited to, disclaimers of warranty, limitations of liability, and arbitration of disputes. If you have any questions regarding our use of your data, please email us.

CONTACT INFORMATION

You may contact us at the following:

Luxury Resorts Ltd

16 Gr. Lampraki 16674 Glyfada Greece

Tel: +30 2108986000

contact@luxuryresortsltd.com