Privacy Policy
How we process personal data under the General Data Protection Regulation (EU) 2016/679.
Last updated: September 2026
1. Data controller
The controller for data collected through this website is:
- Registered name: BLUEVACATION MODAFIRMATI Single Member P.C.
- Registered office: Plateia Eleftherias 9, 72200 Ierapetra, Lasithi, Crete
- GEMI number: 185515041000
- Telephone: +30 2842 110373
- Email for data protection matters: [email protected]
The company is not required to appoint a Data Protection Officer under article 37 GDPR. Please use the details above for any related request.
2. What data we process
This website has no contact form, requires no registration and processes no transactions. Processing is limited to the following:
a. Server logs
The hosting provider automatically records, for each request, the IP address, date and time, the requested address, the browser type and the response code. This is technically necessary to operate and secure the server.
b. Storage on your device
We store your cookie choice locally on your device. See the Cookie Policy for detail.
c. Contact on your initiative
If you contact us by telephone or email, we process the details you give us, solely in order to answer your request.
d. Google Maps
The contact page carries an embedded Google Map. It does not load automatically. It loads only if you press the button provided or have consented to embedded content. On loading, your IP address and details of your device and browser are transmitted to Google Ireland Limited, and Google cookies may be stored on your device. Google acts as an independent controller for that data.
3. Purposes and legal bases
| Processing | Purpose | Legal basis |
|---|---|---|
| Server logs | Operation, security, fault diagnosis | Legitimate interest, art. 6(1)(f) GDPR |
| Cookie choice | Honouring your choice | Legitimate interest and the legal duty to record consent |
| Statistics | Measuring traffic | Consent, art. 6(1)(a) GDPR. Not currently active. |
| Google Maps | Showing our registered office | Consent, art. 6(1)(a) GDPR |
| Answering enquiries | Handling your request | Legitimate interest or pre-contractual steps, art. 6(1)(b) and (f) GDPR |
4. Retention periods
- Server logs: as a rule up to thirty days, unless a longer period is needed to investigate a security incident.
- Cookie choice: up to twelve months, or until you delete it from your browser.
- Correspondence: for as long as needed to handle the request, and thereafter for the period required by tax or civil law if it relates to a transaction.
5. Recipients
We do not sell data and do not pass it to third parties for commercial purposes. Access may be had by:
- the website hosting provider, as a processor bound by a contract under article 28 GDPR,
- Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, only if you choose to load the map,
- public authorities, where there is a legal obligation.
6. Transfers outside the EEA
Fonts, icons, images and scripts are hosted on our own server and are not loaded from third-party networks. Without your consent, no transfer outside the EEA takes place.
If you choose to load the map, data may be transferred to Google LLC in the United States. That transfer is covered by the European Commission adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, under which Google LLC is certified. If you would rather avoid the transfer, do not load the map.
7. Your rights
Under articles 15 to 22 GDPR you have the right to:
- access your data and obtain a copy,
- have inaccurate data corrected or incomplete data completed,
- erasure, where no ground for retention applies,
- restriction of processing,
- data portability, where processing is based on consent or a contract,
- object to processing based on legitimate interest,
- withdraw consent at any time, without affecting the lawfulness of processing carried out before the withdrawal.
We respond to any request within one month. We do not take decisions based on automated processing and do not carry out profiling.
8. Lodging a complaint
If you believe the processing of your data breaches the law, you have the right to complain to the Hellenic Data Protection Authority:
- 1-3 Kifissias Avenue, 115 23 Athens, Greece
- Telephone: +30 210 6475600
- Website: www.dpa.gr
9. Security
The website is served over an encrypted connection (HTTPS). We apply the reasonable technical and organisational measures required by article 32 GDPR, taking into account the limited volume and nature of the data we process.
10. Minors
This website is not directed at minors and does not knowingly collect data from them.
11. Changes to this policy
This policy may be updated. Each new version is published on this page with its last updated date.