BlueVacation

Privacy Policy

How we process personal data under the General Data Protection Regulation (EU) 2016/679.

Last updated: September 2026

1. Data controller

The controller for data collected through this website is:

  • Registered name: BLUEVACATION MODAFIRMATI Single Member P.C.
  • Registered office: Plateia Eleftherias 9, 72200 Ierapetra, Lasithi, Crete
  • GEMI number: 185515041000
  • Telephone: +30 2842 110373
  • Email for data protection matters: [email protected]

The company is not required to appoint a Data Protection Officer under article 37 GDPR. Please use the details above for any related request.

2. What data we process

This website has no contact form, requires no registration and processes no transactions. Processing is limited to the following:

a. Server logs

The hosting provider automatically records, for each request, the IP address, date and time, the requested address, the browser type and the response code. This is technically necessary to operate and secure the server.

b. Storage on your device

We store your cookie choice locally on your device. See the Cookie Policy for detail.

c. Contact on your initiative

If you contact us by telephone or email, we process the details you give us, solely in order to answer your request.

d. Google Maps

The contact page carries an embedded Google Map. It does not load automatically. It loads only if you press the button provided or have consented to embedded content. On loading, your IP address and details of your device and browser are transmitted to Google Ireland Limited, and Google cookies may be stored on your device. Google acts as an independent controller for that data.

3. Purposes and legal bases

ProcessingPurposeLegal basis
Server logsOperation, security, fault diagnosis Legitimate interest, art. 6(1)(f) GDPR
Cookie choiceHonouring your choice Legitimate interest and the legal duty to record consent
StatisticsMeasuring traffic Consent, art. 6(1)(a) GDPR. Not currently active.
Google MapsShowing our registered office Consent, art. 6(1)(a) GDPR
Answering enquiriesHandling your request Legitimate interest or pre-contractual steps, art. 6(1)(b) and (f) GDPR

4. Retention periods

  • Server logs: as a rule up to thirty days, unless a longer period is needed to investigate a security incident.
  • Cookie choice: up to twelve months, or until you delete it from your browser.
  • Correspondence: for as long as needed to handle the request, and thereafter for the period required by tax or civil law if it relates to a transaction.

5. Recipients

We do not sell data and do not pass it to third parties for commercial purposes. Access may be had by:

  • the website hosting provider, as a processor bound by a contract under article 28 GDPR,
  • Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, only if you choose to load the map,
  • public authorities, where there is a legal obligation.

6. Transfers outside the EEA

Fonts, icons, images and scripts are hosted on our own server and are not loaded from third-party networks. Without your consent, no transfer outside the EEA takes place.

If you choose to load the map, data may be transferred to Google LLC in the United States. That transfer is covered by the European Commission adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, under which Google LLC is certified. If you would rather avoid the transfer, do not load the map.

7. Your rights

Under articles 15 to 22 GDPR you have the right to:

  • access your data and obtain a copy,
  • have inaccurate data corrected or incomplete data completed,
  • erasure, where no ground for retention applies,
  • restriction of processing,
  • data portability, where processing is based on consent or a contract,
  • object to processing based on legitimate interest,
  • withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.

We respond to any request within one month. We do not take decisions based on automated processing and do not carry out profiling.

8. Lodging a complaint

If you believe the processing of your data breaches the law, you have the right to complain to the Hellenic Data Protection Authority:

9. Security

The website is served over an encrypted connection (HTTPS). We apply the reasonable technical and organisational measures required by article 32 GDPR, taking into account the limited volume and nature of the data we process.

10. Minors

This website is not directed at minors and does not knowingly collect data from them.

11. Changes to this policy

This policy may be updated. Each new version is published on this page with its last updated date.