top of page

Privacy Policy

1. Introduction

At Villa Stefania Dream, we are committed to protecting your privacy and ensuring that your personal data is handled securely and transparently. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR) (EU 2016/679). This policy is valid since 07/03/2025 

 

2. Data Controller

The data controller responsible for processing your personal data is:

Villa Stefania Dream
📍 Rethymno, Crete, Greece
📧 Email: villastefaniadream@gmail.com
📞 Phone: +30 6951771698

 

3. What Personal Data We Collect

We collect and process the following types of personal data:

  • Booking Information: Name, email address, phone number, payment details, and special requests

  • Communication Data: Emails, messages, and feedback

  • Technical Data: IP address, browser type, device information, and website usage (via cookies)

  • Marketing Preferences: Your consent to receive promotions and newsletters

 

4. How We Use Your Personal Data

We only process your data when legally permitted under GDPR. We use your personal data for:

  • Fulfilling Your Booking: To confirm reservations, process payments, and manage your stay

  • Customer Support: To respond to inquiries and provide assistance

  • Marketing & Promotions (only with your consent): To send special offers and updates

  • Website Improvements: To analyze trends and enhance our online experience

  • Legal Compliance: To meet obligations such as tax regulations and fraud prevention

 

5. Legal Basis for Processing

We process your data under the following legal bases:

  • Contractual Necessity: To manage bookings and provide hotel services

  • Legitimate Interest: To improve our services and communicate with guests

  • Legal Obligation: To comply with tax and regulatory requirements

  • Consent: For marketing communications (you can withdraw your consent at any time)

 

6. Data Retention

We retain personal data only for as long as necessary for the purposes outlined in this policy:

  • Booking records: Up to 5 years (for legal and accounting purposes)

  • Marketing data: Until you opt out

  • Website analytics: As per cookie expiration settings

Once data is no longer needed, it is securely deleted.

 

7. Data Security & Protection

We implement strict security measures to protect your data from unauthorized access, loss, or misuse. Access is restricted to authorized personnel only.

 

8. Your GDPR Rights

Under GDPR, you have the following rights:

✅ Right to Access – Request a copy of your personal data
✅ Right to Rectification – Correct inaccurate or incomplete data
✅ Right to Erasure ("Right to be Forgotten") – Request deletion of your data when no longer necessary
✅ Right to Restriction of Processing – Limit how we process your data
✅ Right to Data Portability – Request your data in a structured format
✅ Right to Object – Stop data processing for marketing purposes
✅ Right to Withdraw Consent – Opt out of marketing at any time

To exercise these rights, contact us at villastefaniadream@gmail.com. We will respond within 30 days as required by GDPR.

9. Sharing Your Data

We do not sell or rent your data. However, we may share your information with:

  • Payment processors (e.g., banks or payment platforms)

  • Booking partners (e.g., third-party reservation systems)

  • Legal authorities (if required by law)

All third parties are required to comply with GDPR data protection standards.

 

10. Cookies & Tracking

Our website uses cookies to enhance your browsing experience. You can manage cookie settings via your browser. 

 

11. Updates to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date.

 

12. Contact & Complaints

If you have any concerns about your data, you can contact us at:

📧 Email: villastefaniadream@gmail.com
📞 Phone: +30 6951771698

 

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.

bottom of page