Privacy Notice

Last Updated: May 24th, 2018

At Dioni Boutique Hotel , we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Dioni Boutique Hotel .

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://dioniboutiquehotel.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Dioni Boutique Hotel .

Data Controller

Dioni Boutique Hotel operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Dioni Boutique Hotel  “ΔΙΩΝΗ Α.Ε.”
4, I. KALOU
481 00, Preveza
GR

Data Processor

WebHotelier operates this booking system on behalf of Dioni Boutique Hotel and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Dioni Boutique Hotel , WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Dioni Boutique Hotel ;
  • to pass on your financial details to Dioni Boutique Hotel and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Privacy Policy

Dioni Boutique Hotel

PRIVACY PROTECTION POLICY

Guest Information 


At Dioni Boutique Hotel we stress the importance of privacy and are committed to adopting high standards for the protection of personal information.

Our policy outlines the type of personal information we collect and receive, the circumstances in which we collect or receive personal information, the policies and procedures we have established outlining its use and storage, and for sharing certain types of personal information in certain limited circumstances, the procedures you should follow if you have any questions or requests in respect of your personal information or our policies and procedures and the person to whom such questions or requests should be directed, and the means by which to communicate with that person.

In this policy 'Dioni Boutique Hotel' means Dioni S.A. and its affiliated companies, as they may exist from time to time, which include, without limitation, the subsidiaries which carry on business that use the following names: Dioni Boutique Hotel and Dioni Boutique Hotel. The words 'we' and 'Dioni Boutique Hotel' do not include third party hotel owners or third parties involved in the delivery of services, however we have requested such hotel owners and third party suppliers to abide by the terms of our Privacy Protection Policy.

In this policy, personal information means information about you that is personally identifiable like your name, address, e-mail address or phone number, and that is not otherwise publicly available and is not part of your work identification.

It also includes information on guest preferences and usage, when such information is supplied to or recorded by Dioni Boutique Hotel in the course of transacting business with an individual.

The Privacy Protection Policy does not apply to information regarding Dioni Boutique Hotel corporate customers. However, such information is protected by other Dioni Boutique Hotel policies and practices and through contractual arrangements.

HOW YOU MAY PROVIDE US YOUR PERSONAL INFORMATION

1.By making a reservation or by using Dioni Boutique Hotel services.

2.By providing it to us in communications regarding service delivery such as comment forms.

3.By providing the information to us by participating in a marketing initiative.

4.By visiting our website or/and booking engine.

Below we will outline the type of information normally collected in each of these circumstances, the reasons for doing so, how we will use it and store it.

MAKING A RESERVATION

When making a reservation or using Dioni Boutique Hotel services it is necessary to have information in order to identify you, contact you and to process your purchase and requests. This information usually includes your name, address, phone number, e-mail address, credit card number and expiration date, and language preference. It may also include, if you choose to share that information with us, your preferences regarding the delivery of your service such as type of room, type of bed, and the like. We also offer special discounts from time to time that may have qualifying criteria. Sometimes we offer special offers to, for example, seniors or for children. To assess your eligibility and process your reservation correctly, we need to record your date of birth at the time of booking. You may be required to provide personal identification with your date of birth upon check-in.

Dioni Boutique Hotel may use the information you provide to send you offers and information about Dioni Boutique Hotel services.

If you do not wish to receive such offers and information you may unsubscribe or opt-out by sending an email to info@dioniboutiquehotel.gr, using the subject line "Unsubscribe", so indicating your request with sufficient personal identifiers so we can appropriately act on your request. All our marketing communication of this type will also contain instructions for unsubscribing.

INFORMATION PROVIDED TO US IN COMMUNICATIONS REGARDING SERVICE DELIVERY SUCH AS CONTACT FORMS

Information provided to us in such a fashion will be used solely for the purpose of recording your comments, communicating with you in respect of them, reviewing them with the hotel management team and the hotel personnel, for the purposes of recognizing employees for excellence of service delivery and for developing improvements in service delivery.

Contact forms are stored for a reasonable period of time in our system, one (1) year maximum, for security reasons yet for improved service quality.

DIONI BOUTIQUE HOTEL OFFERS YOU THE ABILITY TO RECEIVE TARGETED, TIMELY NOTIFICATION OF TIME SENSITIVE OFFERS

To sign up for this service we require you to provide us with your e-mail address, first name, last name, language preference, and country of residence. You may unsubscribe at any time using the link provided on every e-mail message and you will no longer receive e-mail offers and promotions for the specified subscription or website.

You may at any time in the future opt-in to receive e-mail offers.

You can opt out of our advertising and marketing communications at any time by any of the following methods:

a. Selecting the UNSUBSCRIBE link included in our emails.

b. Contacting our Marketing Team at info@dioniboutiquehotel.gr

BY VISITING OUR WEBSITE OR/AND OUR BOOKING ENGINE

We use "cookies" on our websites. Cookies are pieces of information that an Internet site transfers to your device's web browser for record-keeping purposes. The use of cookies is an industry standard -- you'll find them almost everywhere on the Internet. Dioni Boutique Hotel and our booking engine use cookies to recognize visitors when they return to our sites. Once we know it's you, we can customize your online visit.

We may also evaluate our content and services and tailor our websites, for visitors, based on other information we collect, such as IP addresses, which are numbers assigned to your computer whenever you use the Internet, pixel tags (or clear gifs), and the type of Internet browser or operating system you are using. This information is collected in the aggregate, but we may tie it to your personal information through cookie use as described above.

You may refer to our booking engine’s Privacy Policy for detailed information regarding the Cookies used by the booking engine.

If you do not wish to have data relating to your visits to our websites collected through the third parties mentioned above, you may opt-out by visiting the third parties opt-out pages, or through our dedicated cookies policy section in the footer of our website.

WHY WE COLLECT PERSONAL INFORMATION

1.To establish and maintain a responsible commercial relationship with you and to provide ongoing service.

2.To understand your needs and preferences. We maintain a record of the products and services you receive from us and we may ask for additional information so that we can serve you better. For example, we may record your preference for type of room.

3.To develop, enhance, market or provide products and services. For example, we look at our guests' use of our services so that we can better understand how to improve our services.

4.To manage and develop our business and operations. For example we analyze guest patterns of usage of our hotels and services to help us manage them efficiently and plan for future growth.

5.To meet legal and regulatory requirements.

WHEN DO WE DISCLOSE PERSONAL INFORMATION

We disclose personal information only in these limited circumstances:

1.We may disclose a guest's personal information to a person who, in the reasonable judgment of Dioni Boutique Hotel, is seeking the information as an agent of the guest - for example, a travel agent who is booking a reservation on behalf of the guest.

2.Personal information will be shared with a third party involved in supplying the guest with the services they have purchased to the extent necessary to effect the supply and the processing of the transaction.

3.Personal information may be shared with a third party retained by Dioni Boutique Hotel to perform functions on its behalf such as reservations handling, data processing or storage, guest surveys or research.

4.Personal information may be shared with an agent retained by Dioni Boutique Hotel to evaluate a customer's credit worthiness or in order to collect a customer's account.

5.Personal information may be shared with a public authority or an agent of public authority if in the reasonable judgment of Dioni Boutique Hotel it appears that there is an imminent danger to life or property which could be avoided or minimized by disclosure of the information, or which disclosure is compelled by legal authority.

Any such disclosure of a guest's personal information by Dioni Boutique Hotel to a third party will be made only on a confidential basis conditioned upon the information being used only for the purpose for which it has been disclosed.

PRINCIPLES

1. Dioni Boutique Hotel will not collect, use or disclose your personal information for any other purpose than those identified above, except with your consent.

2. Dioni Boutique Hotel will never sell, rent, distribute nor make public your personal information in any way.

3. Dioni Boutique Hotel will protect your personal information with appropriate security safeguards.

4. Dioni Boutique Hotel will take appropriate steps to protect the confidentiality of your personal information when dealing with third parties.

5. Dioni Boutique Hotel will strive to keep your personal information as accurate and up to date as is necessary for the purposes identified above.

6. Dioni Boutique Hotel will honor your request to access your personal information in as timely fashion as is reasonably possible.

You are always free to refuse to provide personal information to us.

You may also withdraw your consent with respect to the use of your personal information for marketing purposes at any time, subject to legal or contractual restrictions and reasonable notice, by e-mailing us at info@dioniboutiquehotel.gr, using 'Unsubscribe' as the subject line, and providing us sufficient personal identifiers so we can act effectively on your request.

However, in either case, this may limit our ability to serve you.

If you have questions or concerns about our privacy practices or wish to make a request in respect of your personal information, please contact our Privacy Officer (info@dioniboutiquehotel.gr).

Change of our Privacy Policy

If we decide to change our privacy policy, we will post any changes on this page of the site so that you always know how we use the information we collect and under what circumstances we disclose it to others.

List of Processors:

Website: Mozaik

Online reservations system: Bookwize

Property Management System: Galaxy

Newsletter service: Mailchimp

Contact

You can contact us anytime either regarding clarifications on our privacy policy or regarding questions you may have on the use of your personal information:

e-mail: info@dioniboutiquehotel.gr

Phone number: +30 2682027381

Address: I. Kalou 4, Preveza, 48100