1. Data controller
The controller for personal data processed through dock38.com and direct reservations is DOCK 38 I.K.E.. Contact: info@dock38.com.
2. Information we may process
- Identity and contact information, such as name, email, telephone number and country.
- Reservation information, including stay dates, apartment category, occupancy, preferences and correspondence.
- Payment metadata, such as payment status, amount, currency and transaction reference. Complete card details are handled by the payment provider and are not stored by Dock 38.
- Technical information, such as IP address, browser type, device information and security logs.
- Information required for check-in, legal reporting, invoicing, safety or fraud prevention.
3. Why we use personal data
We process personal data to answer enquiries, provide and administer accommodation, process payments and refunds, communicate before and after a stay, comply with legal obligations, protect guests and the property, prevent fraud and resolve disputes. Optional marketing is used only where a lawful basis exists.
4. Legal bases
Depending on the activity, processing is based on performance of a contract, steps requested before entering a contract, compliance with legal obligations, legitimate interests in operating and protecting the business, or consent where required.
5. Service providers and recipients
Data may be shared where necessary with reservation platforms, the property-management/channel-management provider, payment processors, banks, hosting and email providers, professional advisers, public authorities and fraud-prevention or security providers. Booking.com, Airbnb and Google process data under their own privacy information when customers use those services.
6. International transfers
Some service providers may process data outside the European Economic Area. Where required, appropriate transfer safeguards are used.
7. Retention
We retain booking, payment, invoicing and guest records for as long as needed to provide the service, handle disputes and comply with Greek tax, accounting, tourism and other legal requirements. Information that is no longer required is deleted or anonymised where appropriate.
8. Your rights
Subject to applicable law, individuals may request access, correction, deletion, restriction, objection or portability, and may withdraw consent where processing relies on consent. Requests can be sent to info@dock38.com. Individuals may also complain to the Hellenic Data Protection Authority.
9. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the data. No internet transmission or storage system can be guaranteed completely secure.
10. Updates
We may update this policy to reflect changes in services, technology or legal requirements. The effective date above shows the current version.