🖱 Click for magic begins

Privacy Policy

Privacy Policy

Pasas Castle respects the privacy of its guests and website visitors. This policy explains what personal information may be processed in connection with enquiries, reservations, stays, communications and use of our website, why it is used and what rights you have.

Our Principle Only What We Need We aim to process only the personal information reasonably necessary to manage your enquiry, reservation and stay.
Your Information Not Sold Pasas Castle does not sell guest personal data. Information is shared only where needed for the purposes described below or where required by law.
i Who Is Responsible for Your Data?
  • For personal data processed directly in connection with Pasas Castle reservations, enquiries and stays, Pasas Castle is responsible for determining how and why that information is used.
  • When you make a reservation through a third-party platform, such as Airbnb or Booking.com, that platform may also process your information under its own privacy policy and for its own purposes.
  • This policy applies to the personal data that Pasas Castle receives or processes directly and does not replace the privacy notices of independent third-party services.
◇ Information We May Collect
  • Identity and contact information: such as your name, telephone number, email address or other contact details provided with an enquiry or reservation.
  • Reservation information: travel dates, number of guests, selected accommodation, booking reference and information necessary to organise your stay.
  • Payment and transaction information: information reasonably necessary to record or verify payment and the status of a reservation.
  • Communications: messages and information you choose to provide when you contact us by telephone, booking platform, WhatsApp, Viber, Instagram or another communication channel.
  • Website information: limited technical information associated with your visit, including cookie preferences and, where applicable and permitted, analytics information.
→ Why We Use Your Information
  • To answer enquiries and communicate with you before, during and after your stay.
  • To create, confirm and administer reservations, payments, requested changes and accommodation arrangements.
  • To provide check-in information, guest assistance, safety information and other services connected with your stay.
  • To comply with tax, accounting, registration, public-authority and other legal obligations that may apply to accommodation providers.
  • To protect our guests, property, systems and legitimate business interests, including the prevention or handling of fraud, disputes or misuse.
§ Legal Bases for Processing
  • Contract: we process information where it is necessary to take steps at your request before a booking or to perform a confirmed accommodation reservation.
  • Legal obligation: some information must be processed or retained because accommodation, tax, accounting or other applicable legislation requires it.
  • Legitimate interests: limited processing may take place where reasonably necessary to operate and protect the accommodation, respond to disputes, maintain security or manage our business, provided that those interests do not override your rights.
  • Consent: where consent is legally required, such as for certain optional cookies or similar technologies, processing takes place only after the appropriate consent has been obtained.
Payment card information: where a booking platform or payment service processes card details directly, Pasas Castle may receive confirmation or transaction information without receiving the complete card details themselves.
⇄ Who May Receive Your Data?
  • Booking and reservation platforms used for your reservation.
  • Payment, banking or transaction service providers where needed to process or verify a payment.
  • Website, hosting, technical or communications providers where their services are necessary for the operation of our website or guest communications.
  • Accountants, professional advisers or public authorities where disclosure is necessary for legal, tax, accounting or dispute-related purposes.
  • We do not disclose personal information to unrelated parties merely for them to sell their own products or services to you.
⌛ How Long We Keep Information
  • Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected.
  • Reservation, invoice, payment and transaction records may need to be retained for longer periods where Greek tax, accounting or other legal obligations require this.
  • Enquiries that do not lead to a reservation are not intended to be retained indefinitely and may be deleted when there is no longer a reasonable need to keep them.
  • Information may be retained for an additional period where reasonably necessary to establish, exercise or defend legal claims.
◉ Cookies & Website Technologies
  • Our website may use strictly necessary cookies or similar technologies that support essential functions or remember privacy choices.
  • Optional analytics, measurement or other non-essential technologies should be activated only where the required consent has been provided through the website's cookie controls.
  • You can use the cookie banner or available browser controls to manage your preferences. Refusing optional cookies should not prevent access to the basic content of the website.
  • Third-party content or services may be subject to the privacy and cookie practices of the relevant provider.
Cookie choice: non-essential cookies are separate from cookies that are technically necessary for the website or a service expressly requested by the visitor.
↗ International Data Transfers
  • Some booking, communications, website or technology providers may process information outside Greece or the European Economic Area.
  • Where a transfer of personal data requires safeguards under applicable data-protection law, the relevant provider or controller must use an appropriate legal mechanism for that transfer.
  • Third-party providers remain responsible for explaining transfers they carry out independently under their own privacy notices.
◆ Security
  • We take reasonable organisational and technical measures to protect personal information against unauthorised access, loss, misuse or disclosure.
  • Access to guest information should be limited to people or service providers who need it for the purposes described in this policy.
  • No internet, email or electronic storage method can be guaranteed to be completely secure, so guests should avoid sending unnecessary sensitive information through ordinary messages.
✓ Your Data Protection Rights
  • Depending on the circumstances and the legal basis for processing, you may have the right to request access to your personal data and obtain information about how it is used.
  • You may ask for inaccurate or incomplete information to be corrected.
  • In the situations provided by law, you may request erasure of your data or restriction of its processing.
  • Where applicable, you may have the right to data portability or to object to certain processing based on legitimate interests.
  • Where processing relies on your consent, you may withdraw that consent at any time, without affecting processing that was lawful before withdrawal.
  • You also have the right to lodge a complaint with the Hellenic Data Protection Authority if you believe that your personal data has been processed in violation of applicable data-protection law.
Please note: some rights are not absolute. For example, information may need to be retained where a legal obligation applies or where it is necessary for the establishment, exercise or defence of legal claims.
↻ Updates to This Policy
  • This Privacy Policy may be updated when our services, website practices or legal obligations change.
  • The version published on this website is the current version. Material changes may be highlighted where appropriate.
☎ Privacy Requests & Contact