Last updated: 29 August 2026
Protecting your personal data matters to us. This Privacy Policy explains, in plain language, what data we collect through the marmariparadise.com website, why we collect it, how long we keep it, who we share it with and what rights you have.
It has been drawn up in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679 – "GDPR"), Law 4624/2019 and Law 3471/2006.
1. Who we are — Data Controller
The controller of your data is:
| Legal name | ΚΟΥΒΑΡΗ ΠΑΝΑΓΙΩΤΑ (Panagiota Kouvari) — sole trader |
| Trading name | Marmari Paradise Resort Hotel |
| Legal form | Sole trader (Greek «ατομική επιχείρηση») |
| Registered office | Marmari Gerolimena, 23071 Marmari Lakonias, Greece |
| Premises | Marmari Gerolimenas, 23071 Marmari Lakonias, Greece |
| Tax ID (A.F.M.) | 043489730 |
| Tax Office (D.O.Y.) | Sparta |
| G.E.MI. no. | 18068639000 |
| MH.T.E. no. | 1248K133K0413300 |
| Telephone | +30 27330 52101 |
| info@marmariparadise.com |
Sole trader — there is no separate legal entity. The business is carried on by a natural person. The controller within the meaning of Article 4(7) GDPR is therefore Panagiota Kouvari, acting as a natural person, who operates the business under the trading name above. The registry details in the table (Tax ID, G.E.MI.) belong to that same person; there is no company or other legal entity behind them.
Data Protection Officer (DPO): No Data Protection Officer has been appointed, as none of the conditions of Article 37(1) GDPR applies. For any data protection matter you may contact us directly using the details above.
2. What this Policy covers
This Policy covers the marmariparadise.com website and the communications that start from it (contact forms, event enquiries, newsletter).
It does not cover:
- The booking system
marmariparadise.reserve-online.net, which runs on a separate third-party platform and has its own privacy policy — see section 6. - The processing of data that takes place on the hotel premises (e.g. guest registration card, invoicing, any video surveillance system). That is governed by separate notices provided on site.
- Third-party websites that our site links to (e.g. Facebook, Instagram). We are not responsible for their privacy practices.
3. What data we collect and why
3.1 Contact form
When you fill in the form on the "Contact" page, we collect:
- Full name
- E-mail address
- The content of your message
Purpose: to answer your enquiry. Legal basis: Article 6(1)(b) GDPR (taking steps at your request prior to entering into a contract), and additionally Article 6(1)(f) GDPR (our legitimate interests in replying to those who contact us).
3.2 Event enquiry form
When you request a quote for a wedding, christening or corporate event, we collect:
- First name and Last name
- E-mail address
- Telephone
- Type of event (wedding, christening, corporate, anniversary, other)
- Number of people
- Preferred date (optional)
- Your message (optional)
Purpose: to prepare and send you a quote and to make arrangements for your event. Legal basis: Article 6(1)(b) GDPR (pre-contractual steps at your request).
Note: The type of event (e.g. "christening") may indirectly reveal religious beliefs. We do not use this information for any purpose other than organising the specific event, and we do not build profiles on the basis of it. If you prefer, select "Other" and describe the event in your message.
3.3 Newsletter
If you subscribe to the newsletter, we collect your e-mail address.
Purpose: to send you news and offers from the hotel. Legal basis: Article 6(1)(a) GDPR (your consent), in conjunction with Article 11 of Law 3471/2006.
You can unsubscribe at any time, free of charge, either through the unsubscribe link in every message or by e-mailing info@marmariparadise.com. Withdrawing consent is as easy as giving it and does not affect the lawfulness of processing carried out before the withdrawal.
3.4 Data collected automatically
Like every website, our server records technical data for each visit:
- IP address (regarded as personal data)
- Date and time of the request
- Page requested and response code
- Browser and operating system type (user agent)
- Referring page (referrer), where present
Purpose: operation, security and stability of the website — detecting errors and protecting against attacks and abuse. Legal basis: Article 6(1)(f) GDPR (our legitimate interests in keeping the website secure and functional).
We use Google Tag Manager to manage measurement and advertising tools. Depending on the consent you give in the cookie banner, the following may be activated:
- Google Analytics 4 — statistical analysis of website traffic ("Statistics" category).
- Google Ads — measurement of advertising campaign performance ("Marketing" category).
- The Meta / Facebook advertising pixel — also under the "Marketing" category.
None of these load before you state your consent. See the detailed table of names, providers and durations in the Cookies Policy.
3.5 Cookies and local storage
The website uses necessary cookies, plus statistics and marketing cookies only if you give your consent. Full details in the Cookies Policy.
4. What we do not do
To be clear:
- We do not sell your data to anyone.
- We do not use it for automated decision-making or profiling (Article 22 GDPR).
- We do not knowingly collect special categories of personal data (health, religion, political opinions, etc.) — Article 9 GDPR. Please do not include such information in the free-text fields, unless it is necessary (e.g. a dietary restriction for an event) — in that case we process it solely in order to serve you.
- We do not accept payments through this website; we do not store card details.
5. How long we keep your data
| Data | Retention period | Why |
|---|---|---|
| Contact form messages | 12 months from the last communication | Following up on the enquiry and any return to it |
| Event enquiries | 24 months from submission | Events are planned far in advance; a longer horizon is needed |
| Event enquiries that resulted in a contract | For the duration of the contract and 5 years afterwards | Tax/accounting obligations and establishment of legal claims |
| Newsletter | Until you unsubscribe | Consent applies until it is withdrawn |
| Technical server log files (logs) | Up to 30 days | Security and error detection |
| Language preference (local storage) | Until you delete it from your browser | It stays on your device and is not sent to us |
Once these periods expire, the data is deleted or anonymised, unless retention is required by law or is necessary for the establishment, exercise or defence of legal claims.
6. Who we share your data with
We do not pass your data on to third parties, with the exception of the providers below, who act as processors on our behalf (Article 28 GDPR), and the cases required by law (e.g. a request from a judicial or prosecuting authority).
6.1 Website hosting — Vercel
The website is hosted on the Vercel Inc. platform (340 S Lemon Ave #4133, Walnut, CA 91789, USA). Vercel processes the technical log files (IP, user agent) described in section 3.4. Privacy policy: https://vercel.com/legal/privacy-policy
6.2 E-mail service
The messages you send through the forms are delivered to the business mailbox @marmariparadise.com, which is hosted by the provider IpHost (18 Terpsitheas Street, 12351 Agia Varvara, Athens, Greece).
6.3 Booking system — WebHotelier
When you click "Book now", you are taken to a third-party website: https://marmariparadise.reserve-online.net.
From the moment you leave our website, the data you provide (name, contact details, stay details, financial details, and optionally your tax ID for invoicing) is collected through the WebHotelier booking platform, operated by Revplus Hellas S.A. (5th km Rhodes–Lindos Ave., 851 00 Rhodes, Greece) as a processor on our behalf.
- WebHotelier Data Protection Officer: dpo@webhotelier.net
- Privacy policy of the booking system: https://marmariparadise.reserve-online.net/privacy-policy
- According to the provider's policy, data is stored on Amazon Web Services infrastructure in Frankfurt (Germany) and North Virginia (USA) — see section 7 on international transfers.
We recommend that you read the booking system's privacy policy before completing a booking.
6.4 Content management — Sanity
The text and photos on the website (e.g. on the "Rooms" page) are managed through the Sanity content infrastructure. They are retrieved by our servers, not by your browser: your browser does not connect to Sanity and Sanity does not receive your IP address. This service does not place any cookies. Privacy policy: https://www.sanity.io/legal/privacy
6.5 Map — Google Maps
On the "Contact" page we embed a map from the Google Maps service (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland).
The map does not load automatically. A static preview is displayed and the map is activated only if you expressly ask for it. Once you activate it, Google receives your IP address and may place cookies on your device. Legal basis: your consent (Article 6(1)(a) GDPR). Google privacy policy: https://policies.google.com/privacy
You can always see where we are without activating the map, by using the address and the directions we set out on the same page.
7. Transfers outside the European Economic Area
Our providers Vercel and Google are companies with US parent entities, while the booking system uses AWS infrastructure that includes a region in the USA. Some data may therefore be transferred outside the EEA.
Such transfers are made only with the safeguards of Articles 44 et seq. GDPR:
- Adequacy decision — for providers certified under the EU–U.S. Data Privacy Framework, on the basis of the European Commission's Implementing Decision (EU) 2023/1795 (Article 45 GDPR); and/or
- Standard Contractual Clauses of the European Commission (Article 46(2)(c) GDPR), accompanied by technical and organisational measures.
Specifically, as at the date of publication:
- Revplus Hellas S.A. (WebHotelier) — is established in Greece (Rhodes). No transfer to a third country takes place.
- Vercel Inc. and Google — are established in the USA. Transfers rely on the EU–U.S. Data Privacy Framework and/or on Standard Contractual Clauses, as declared by each provider. You can check any organisation's active certification at https://www.dataprivacyframework.gov.
You can request a copy of these safeguards at info@marmariparadise.com.
8. Your rights
As a data subject you have the following rights:
| Right | What it means | GDPR Article |
|---|---|---|
| Access | To find out whether we process your data and to obtain a copy | 15 |
| Rectification | To have inaccurate data corrected or incomplete data completed | 16 |
| Erasure ("right to be forgotten") | To have your data deleted, where grounds exist | 17 |
| Restriction | To have processing "frozen" in certain cases | 18 |
| Data portability | To receive your data in a structured, commonly used format | 20 |
| Objection | To object to processing based on legitimate interests | 21 |
| Withdrawal of consent | To withdraw your consent at any time, without retroactive effect | 7(3) |
How to exercise them: send us an e-mail at info@marmariparadise.com or a letter to our address. Exercising your rights is free of charge.
How long you will wait: we reply within one (1) month of receiving the request. That deadline may be extended by a further two months if the request is complex — in that case we will inform you within the first month (Article 12(3) GDPR).
We may ask for additional information in order to confirm your identity, so that your data is not disclosed to someone else.
9. Right to lodge a complaint
If you believe that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the supervisory authority (Article 77 GDPR):
Hellenic Data Protection Authority (HDPA) Kifissias Ave. 1–3, 115 23 Athens, Greece Telephone: +30 210 6475600 E-mail: contact@dpa.gr Website: https://www.dpa.gr
We would appreciate it, however, if you contacted us first so that we can try to resolve the matter.
10. Data security
We take appropriate technical and organisational measures to protect your data (Article 32 GDPR), including:
- Encryption of the communication between your browser and the website (HTTPS/TLS on all pages).
- Restricting access to the incoming messages to only the staff who need to handle them.
- Data minimisation: we ask only for what is necessary for each purpose.
- Regular updating of the website software.
No transmission of data over the internet is completely secure. In the event of a breach likely to result in a high risk to your rights, we will inform you in accordance with Articles 33–34 GDPR.
11. Children
The website is not directed at children. We do not knowingly collect data from children under 15 years of age without the consent of the person holding parental responsibility (Article 8 GDPR, as specified by Article 21 of Law 4624/2019). If we become aware that we have collected such data, we delete it.
12. Changes to this Policy
We may update this Policy, for example if our services or the legal framework change. The version in force at any given time is always published on this page, with an updated "Last updated" date. Where changes are material and affect you, we will inform you by appropriate means.
13. Contact
For any matter relating to your personal data:
Marmari Paradise Resort Hotel Marmari Gerolimenas, 23071 Marmari Lakonias, Greece Telephone: +30 27330 52101 E-mail: info@marmariparadise.com
