Privacy Policy
Original effective date: 10 June 2026 Revision published: 26 September 2026 Revision effective date: 10 October 2026
This revision is published with 14 days’ notice under §14.
Clarity supplement published: 21 September 2026 Clarity supplement effective date: 21 September 2026
The Microsoft Clarity disclosures in §§3.2, 5.2, 7 and 8 apply from 21 September 2026. Clarity recording requires Analytics consent. This supplement does not change the original effective date or the publication and effective dates of the revision of 15 September 2026.
Google Maps supplement published: 24 September 2026 Google Maps supplement effective date: 24 September 2026
The Google Maps disclosures in §§3.4, 5.2, 5.8 and 12 apply from 24 September 2026. Maps on information pages load only after you allow functional cookies. This supplement does not change the original effective date or the publication and effective dates of the revision of 15 September 2026 and the Clarity supplement above.
1. Who we are
This Privacy Policy explains how TRAVEL ACTIVITY GUIDE LTD (“we”, “us”, “The Greek Local”, formerly trading as “Greece Activity Guide”) collects, uses, and shares personal data when you use thegreeklocal.com (the “Site”) or make a booking through it.
-
Registered office: Vavyla 3, Block A, Flat/Office 204, Pera Chorio, 2572 Nicosia, Cyprus
-
Company number: HE 493917
-
VAT number: pending registration
-
Jurisdiction of incorporation: Cyprus
-
Contact for privacy matters: support@thegreeklocal.com
-
Data Protection Officer: not appointed — we are below the Article 37 GDPR thresholds (our core activities involve neither large-scale regular monitoring nor large-scale special-category processing). We review this assessment annually.
We are the data controller for the personal data described in this Policy, except where we act as a processor on behalf of a third party (rare; flagged in §5).
2. The short version
-
We collect the data you give us at booking (name, email, phone, payment details via Stripe), what you do on the Site, and what you tell us in messages. Some Tours also ask for details about each traveller: a passenger list that the law requires on some boat trips, or details the Operator needs for your safety or equipment, such as weight or a diving certification. The booking form shows what each Tour asks for. The Operator sees these details in its portal and on its printed passenger list; where it uses its own reservation system, that system also receives the passenger list. Apart from travellers’ names, we never send these details by email, SMS or WhatsApp, and we delete most of them 30 days after the Tour (§3.1, §7).
-
If you allow Advertisement cookies, we also keep the advertising click identifier and campaign labels from the link that brought you here, the address of the page you first landed on (with no personal tokens), and the address of the website that referred you. We use these only to work out which advertisement or source led to a booking and to report paid bookings to Google Ads or OpenAI Ads when we run those campaigns. With the same consent, the OpenAI Pixel measures eligible page and Tour views and checkout starts, and can send browser-hashed matching data (§8.2). If you do not allow Advertisement cookies, none of this is recorded.
-
If you message us on WhatsApp, or reply to a WhatsApp message from us, the conversation is stored by us and copied into our private Slack workspace so our team can answer you. See §9.3.
-
We use it to deliver the booking, run our service, comply with the law, remind you about a booking you started but did not finish (you can opt out of these reminders at any time), and — only with your separate consent — send marketing.
-
We share booking details with the relevant Operator so they can run the Tour, with Stripe to take payment, with Twilio and Resend to message you, with Clerk to manage your account, and with our hosting providers (Vercel, Neon), with Slack to run our team workspace (§5.2), and, only with your Advertisement consent, the advertising measurement data and paid-booking reports described above to Google Ads or OpenAI Ads when we run those campaigns. We do not sell your data.
-
We keep most booking and payment records for 6 years (accounting/tax, and to defend claims), then delete or anonymise them.
-
You have rights to access, correct, delete, port, restrict, and object — see §11.
3. What we collect
3.1 You give us, directly
-
At checkout: first name, last name, email, phone number, number and ages of participants, pickup location (if applicable), free-text notes (allergies, special requests, accessibility), and, where the Tour asks for them, the other travellers’ names and the details described below under “Details the Operator needs for your Tour”.
-
Transfer bookings only: when you book a transfer (point-to-point transport, such as an airport-to-port transfer), the booking form asks for your pickup and drop-off addresses and, optionally, the flight or sailing number of your arrival (so the Operator can track it and time the pickup) and any access notes you choose to add, such as a gate code, entry instructions, or the name of your villa or hotel. The flight or sailing number and the access notes are optional. All of it is passed to the Operator (§5.1) and kept as part of the booking record (§7). If no listing covers the route you want, we may ask operators to quote for it. To do that we send the pickup and drop-off addresses, the date and time, and the party size to the operators whose service area covers your route — but not your name, contact details, flight or sailing number, or access notes. More than one operator normally receives it, and operators who do not get your booking must delete those details as soon as their quote lapses or another quote is accepted.
-
Details the Operator needs for your Tour: some Tours need more than the lead traveller’s contact details. The booking form shows exactly what each Tour asks for and which questions you may leave blank.
- Passenger lists required by law. Some Tours, typically boat trips, must carry a list of the people on board. For those Tours we ask for the details the list needs, which may include each traveller’s surname, first name, sex, nationality and date of birth and, where the Operator asks for it, a passport or identity-card number. On boat trips in Greece the list covers every person on board, children and infants included.
- Details for your safety or equipment. Some Tours ask for details such as each traveller’s weight, height or shoe size; whether a traveller will drive, with the driving licence number and the country that issued it; or a diving certification level and the date of the last dive.
- An emergency contact. Where the Operator asks for one, we ask for the telephone number of a person who is not on the Tour, whom the Operator can call in an emergency (§3.6).
- Dietary needs. Some Tours ask about dietary needs. The question is always optional (§3.5).
- The Operator’s own questions. An Operator may add up to five questions of its own, for example about experience or preferences, and may suggest answers to choose from. The Operator decides what it asks and why. Each question is checked automatically for contact details and health-related wording before it appears on the booking form, and every change to it is recorded so that we can review it. Operators may not use their own questions to ask about health.
- Yes-or-no questions and confirmations. Some Tours ask a yes-or-no question about each traveller, for example whether the traveller can swim, or ask you to confirm a statement, for example that the lead traveller is of legal drinking age. We record your answer. We do not ask medical questions of our own, and we do not ask you to upload documents.
Where the Tour allows it, you may choose at checkout to give some of these details after booking, up to the deadline shown when you book, through the personal link in your confirmation email or through your Account (§11). We pass these details to the Operator (§5.1). Apart from travellers’ names, we never send them by email, SMS or WhatsApp. Travellers’ names, your yes-or-no answers about swimming and the confirmations you give are kept with the booking; every other detail in this bullet, and every answer to an Operator’s own question, is deleted 30 days after the Tour (§7).
-
Payment: card details and billing address — entered on the Stripe payment page; we do not see or store full card data. We store a Stripe customer ID and a payment-method reference so we can issue refunds.
-
Account (optional): the data above plus an authentication identifier from Clerk. If you sign in with Google or another social provider, we receive the basic profile fields that provider gives us.
-
Customer messages: the content of emails you send us and replies to SMS messages.
-
WhatsApp conversations: if you send a WhatsApp message to our business number, or reply to one of ours, we store the conversation as a thread kept under your phone number: your number, the display name your WhatsApp profile shows us, the text of every message we receive and every reply we send (including which team member sent it), and a count of any attachments. Photos, voice notes and files you send are not kept in our own database: they are held by our messaging provider and copied into our private Slack workspace (§5.2, §9.3) so our team can see them. Messages from numbers we cannot match to a booking or Operator are stored in the same way. The whole thread is copied into our private Slack workspace (§5.2, §9.3). Internal notes our team writes in the thread are never sent to you and are not added to the stored conversation; they remain in our Slack workspace. Anything you volunteer in chat about health, dietary, mobility or similar needs (§3.5) is used only to answer you or to deliver the service you booked, and for nothing else.
3.2 We collect automatically
-
Technical data: IP address, user-agent string, device type, language, browser settings — used for security, abuse prevention, and basic analytics.
-
Usage data: pages visited, searches performed, Tours viewed, items in cart, click and scroll signals — used to improve the Site and (with consent where required) for remarketing. With Analytics consent, Microsoft Clarity also records interactions on eligible public pages for heatmaps and session recordings, as described in §8.
-
Advertising and referral source (only with Advertisement consent): if you arrive from a link that carries an advertising click identifier (Google gclid, wbraid or gbraid; Meta fbclid) or campaign labels (utm_source, utm_medium, utm_campaign, utm_term, utm_content), we keep those values. If you arrive from another website, with or without an advertisement, we also keep that website’s address (for example https://chatgpt.com), never the page or search you came from, and the address of the page on our Site you arrived at (our domain, the page path, and any campaign labels or advertising click identifiers in the link; everything else in the link is discarded, and no landing page is recorded at all if it was a checkout, account, unsubscribe or confirmation page). Hops through our payment or sign-in providers are ignored. Nothing is recorded if you arrive by typing our address or from a bookmark. We keep these for the visit we treat as your first contact; a later visit from a Meta advertisement replaces an earlier plain referral, and a later advertising click renews the click identifier and campaign labels. These values are held in the first-party cookies gag_ad_click, gag_utm and gag_touch (§8) for up to 90 days and are copied to your booking record if you book. They are written only after you accept the Advertisement category in the cookie banner (immediately, if you accepted it on an earlier visit); until then the browser holds them in memory only and discards them if you refuse. If you never accept Advertisement cookies, this advertising-attribution record is not stored. Analytics services may separately receive public page and referring-page information only with Analytics consent (§8).
-
Advertising measurement data, with Advertisement consent: advertising click references, eligible public page and Tour views, checkout starts, and paid-booking conversion details described in §8.2.
-
Cookies and similar: see §8.
3.3 From third parties
-
Stripe — payment-result codes, fraud signals, partially-masked card details (last four digits, expiry, brand).
-
Operators — confirmation/decline messages and any notes they send us about your booking. Where the Operator keeps the Tour’s availability in its own reservation system, that system also sends us the confirmation of your place, any ticket or voucher it issues, and any change or cancellation of your booking made on the Operator’s side.
-
Operators, for bookings they take themselves — if you book directly with an Operator, for example by telephone, the Operator may record the booking on our platform so that its availability, its daily list and, where the law requires it, its passenger list stay correct. The Operator then gives us your name and, where it chooses to add them, your phone number and email address and any of the details described in §3.1 that the Tour asks for. Some of those details may be missing; we do not contact you to complete them. That booking is between you and the Operator: we do not contact you, we take no payment, and it is not a booking made through the Site. We hold those details on the Operator’s behalf so that its records stay correct, and we delete those details on the same schedule as for any other booking (§7).
-
Booking platforms and resellers — if you book an Operator’s Tour on a booking platform or with a reseller that uses us to hold the Operator’s availability, it sends us the details we need to hold your place with the Operator: your name, email address, phone number, your party size by age category (adult, child, infant), its booking reference and, where the Tour collects you from your accommodation, the accommodation you gave it. A platform may also pass on a comment you wrote when booking, in which it may include answers to the Operator’s questions, such as dietary needs, weight or a passport number. We show that comment to the Operator in its portal and on its passenger list as the platform sent it and, on Tours that ask for the details described in §3.1 under “Details the Operator needs for your Tour”, delete our copy of it 30 days after the Tour (§7). The platform or reseller sold you the Tour, holds your customer relationship, and is an independent controller of your data. We hold the details it sends us on the Operator’s behalf, to hold your booking with the Operator, to keep the Operator’s calendar accurate and, where the Operator records attendance, to record whether you arrived; where the accommodation you gave matches one of the Operator’s recorded pickup points, we tell the Operator which point it is. We do not contact you about such a booking unless the platform or reseller has asked us to.
-
Affiliate partners (where applicable): the referral code showing which affiliate brought you to us (§5.7).
-
Advertising platforms: we do not receive data about you from Google Ads or Meta. The click identifiers in §3.2 are read from the link you clicked, not sent to us by the platform. The referring website’s address is read from your browser’s referrer header, not from that website.
-
Auth providers (Clerk and the social providers behind it) — profile data you authorise on sign-in.
We do not buy contact lists and we do not enrich profiles from data brokers.
3.4 Data we do not collect
For the avoidance of doubt, we do not collect:
-
full payment-card numbers, CVCs, or PINs (Stripe handles all of this — we see only masked references);
-
biometric data or genetic data, or health data beyond what you choose to tell us in the customer-notes field or in answer to an optional question such as the one about dietary needs. We do not ask medical questions of our own: where a Tour needs to know that a traveller is fit to take part, it asks you to confirm a statement instead (§3.1);
-
precise geolocation from your device. On some pages, for example maps and the search bar, you can press “Use my location” or “Near me”. Your browser then asks you for permission. Your location is used only in your browser, to centre the map on you or to sort results by how near they are to you, and is never sent to our servers. If you refuse, nothing else changes and your booking is not affected;
-
the contents of your address book, photos, files, or other apps on your device;
-
social-media data beyond the basic profile fields the auth provider returns on sign-in;
-
information about you from third parties for the purpose of building a profile.
3.5 Special-category data in customer notes and optional questions
Where you voluntarily disclose special-category data (Article 9 GDPR, including health information, allergies, religious dietary requirements and disability information) in the customer-notes field, or in answer to an optional question such as the one about dietary needs, so the Operator can accommodate you, you are giving explicit consent to that disclosure for that specific purpose. You may leave any optional question blank. We pass what you tell us to the relevant Operator, treat it with the same care as the rest of your data, and use it for no other purpose. Your answer about dietary needs, and any answer to an Operator’s own question, is deleted 30 days after the Tour (§7).
3.6 Booking for other people
If you book for other people, you give us their personal data (their names and any other details the Tour asks for about each traveller, described in §3.1). You confirm that you are authorised to do so, that you have informed them how their data will be used (this Policy), and, for any co-traveller’s special-category or identity-document data, that you have their consent to share it with us and the Operator. If you give us an emergency contact’s telephone number, you confirm that you have told that person that the Operator may call them in an emergency and where to find this Policy. We rely on you, as the lead booker, to pass on to your party any information we send about the booking.
4. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR Art. 6 / 9) |
|---|---|---|
| Take, confirm and fulfil your booking | Contact, payment, participant, pickup, notes | Contract (Art. 6(1)(b)) |
| Pass booking details to the Operator so they can run the Tour | Contact + booking details, customer notes, and the details the Tour asks for (§3.1) | Contract (Art. 6(1)(b)); for health information in notes or in an optional answer, explicit consent (Art. 9(2)(a)) as in §3.5 |
| Hold a booking that a booking platform or connected reseller sold you with the Operator, and show it to the Operator to run the Tour (§3.3, §5.1) | Name, email, phone number, party size by age category, platform booking reference and, where applicable, your stated accommodation or pickup point | Legitimate interests (Art. 6(1)(f)) — providing the reservation service the Operator has asked us for; your booking itself is governed by the platform’s terms |
| Keep an Operator’s availability, daily list and passenger list correct for a booking the Operator took itself and recorded with us (§3.3) | Name; phone number and email where the Operator entered them; any of the details described in §3.1 that the Tour asks for | Processing on the Operator’s behalf under its agreement with us; the Operator is the controller and its own legal basis applies |
| Ask operators to quote for a transfer you have requested, and show you their quotes (§3.1, §5.1) | Pickup and drop-off addresses, date and time, party size — no name or contact details | Contract (Art. 6(1)(b)) — steps taken at your request before a contract is made |
| Send transactional emails/SMS/WhatsApp (confirmation, reminders, changes, cancellation, review request) | Contact + booking | Contract (Art. 6(1)(b)) |
| Remind you about a booking you started but did not finish — up to three emails over seven days, opt-out link in every one (§9.4) | Email + the saved booking details | Legitimate interests (Art. 6(1)(f)) + the ePrivacy “soft opt-in” (Art. 13(2) Directive 2002/58/EC as transposed in Cyprus) |
| Collect and pass a passenger list where the law requires one for the Tour (§3.1, §5.1) | Each traveller’s surname, first name, sex, nationality and date of birth and, where the Operator asks for it, passport or identity-card number | Legal obligation (Art. 6(1)(c), Law 4926/2022 art. 13, which lists every person on board of a professional pleasure craft) + Contract (Art. 6(1)(b)) |
| Collect and pass the details an Operator needs for your safety or equipment, the yes-or-no answers and confirmations it asks for, and answers to its own questions (§3.1, §5.1) | Weight, height, shoe size, whether a traveller will drive, driving licence number and issuing country, diving certification and the date of the last dive, yes-or-no answers, confirmations, answers to the Operator’s own questions | Contract (Art. 6(1)(b)); for dietary needs or other health information you choose to give, explicit consent (Art. 9(2)(a)) as in §3.5 |
| Give the Operator an emergency contact where it asks for one (§3.1, §3.6) | Telephone number of a person who is not on the Tour | Contract (Art. 6(1)(b)) as regards you; legitimate interests (Art. 6(1)(f)) in the safety of the Tour as regards the person whose number you give |
| Let you give or correct these details after booking, remind you while any are missing, and keep a record of each change (§3.1, §11) | The details above; when each was changed and whether by you, the Operator or our team; details that are later deleted are recorded only in masked form | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) in a reliable record of what the Operator was told and when |
| Record and evidence your consents (cookie-banner choices; Terms/Privacy acceptance at booking) | Choice made, timestamp, truncated IP, opaque consent ID, document version | Legal obligation (Art. 6(1)(c), Art. 7(1) — demonstrating consent) |
| Administer customer credits (issue, redeem at checkout, restore on eligible cancellations, expiry) | Account, booking, credit ledger | Contract (Art. 6(1)(b)) |
| Attribute a booking to the affiliate whose link brought you to us, and pay their commission (§5.7) | Referral code, booking reference, date, value | Legitimate interests (Art. 6(1)(f)) — measuring and paying for genuine referrals |
| Attribute a booking to the advertisement or source that brought you to the Site (§3.2, §8) | Click identifiers, campaign labels, first landing page, referring website, and a flag recording whether you had granted Advertisement consent at checkout | Consent (Art. 6(1)(a)) via the Advertisement category of the cookie banner; withdrawable at any time (§8) |
| Report a paid booking back to Google Ads, when we run Google Ads campaigns, so we can measure which advertisements work (§5.2) | Google click identifier, booking reference, booking value and currency, time of upload, and a flag confirming that you granted Advertisement consent at checkout; no name, email or phone | Consent (Art. 6(1)(a)), same Advertisement consent; the report is sent only where you had granted it at checkout |
| Answer your WhatsApp messages and keep a record of what was agreed (§3.1, §9.3) | Phone number, WhatsApp display name, message text in both directions, attachment count, our reply and who sent it; copies of attachments in Slack | Contract (Art. 6(1)(b)) for customers with a booking; legitimate interests (Art. 6(1)(f)) in responding to enquiries for everyone else; for health or similar details you volunteer, explicit consent (Art. 9(2)(a)) as in §3.5 |
| Process payments and refunds | Payment, Stripe tokens | Contract (Art. 6(1)(b)) + Legal obligation for financial records (Art. 6(1)(c)) |
| Keep records for tax and accounting | All transactional records | Legal obligation (Art. 6(1)(c)) |
| Customer account, sign-in, sign-out | Auth identifier, account-linked bookings | Contract (Art. 6(1)(b)) |
| Customer support, dispute and refund handling | Whatever data is relevant to the case | Legitimate interests (Art. 6(1)(f)) — running our service responsibly |
| Fraud prevention, abuse and chargeback handling | Technical, payment, behavioural | Legitimate interests (Art. 6(1)(f)) |
| Service analytics, error monitoring | Technical, aggregated or pseudonymous usage | Legitimate interests (Art. 6(1)(f)); cookie-based analytics by consent (see §8) |
| Marketing emails about new Tours, offers | Email, basic interest signals | Consent (Art. 6(1)(a)) — opt-in, opt-out at any time |
| Post-Tour review request (one email; opt-out link inside — §9.1) | Contact + booking | Contract / legitimate interests (Art. 6(1)(b) / (f)) |
| Reviews published on the Site, and possibly re-used in our own marketing materials (§9.1) | First name, review text, optional photo | Consent at the moment you submit |
| Cookies that are not strictly necessary | Various, per §8 | Consent via the cookie banner |
| Measure visits, checkout starts and paid bookings following our ChatGPT advertisements | Advertising click reference, pseudonymous event ID, Tour, value, currency, payment time, public page URL and browser-hashed matching data (§8.2) | Consent via the Advertisement category |
We do not rely on legitimate interest for anything that materially overrides your privacy.
5. Who we share data with
5.1 Tour Operators — independent data controllers
For every booking, the relevant Operator receives: your first name, last name, phone number, email; party size, the travellers’ names and the other details the Tour asks for (§3.1); pickup location, time slot, customer notes (allergies, special requests); for Transfer bookings, the exact pickup and drop-off addresses (including coordinates where you give them), the flight or sailing number and time you provided, and any access notes you added, such as a gate code, entry instructions, or the name of your villa or hotel; the booking reference and the total payable to them.
Transfer quotes. If you ask for a transfer that no listing covers, we send a quote request to the operators whose recorded service area, or the routes of their published transfer listings, covers it. That request contains the pickup and drop-off addresses, the date and time, and the party size, so that they can price the journey. It does not contain your name, contact details, flight or sailing number, or access notes, and more than one operator will normally receive it. Only the operator whose quote you accept receives your identity and contact details, and only once the booking is made. Operators who do not get the booking are required by their agreement with us to delete the request details as soon as their quote lapses, is withdrawn, or another quote is accepted.
Where a Tour asks for the details described in §3.1 under “Details the Operator needs for your Tour”, the Operator receives them so that it can run the Tour safely and, where the law requires it, keep its passenger list. The Operator sees them in its Operator portal and on the passenger list it prints from there; for Tours held in the Operator’s own reservation system, the passenger list also goes into the booking we place in that system (see below). We never send these details by email, SMS or WhatsApp: those messages carry travellers’ names at most, and at most tell the Operator how many details are still missing. A comment passed on by a booking platform is shown to the Operator in its portal and on its passenger list, as the platform sent it (§3.3).
Sharing can also run the other way: where it is necessary to deliver the Tour or to handle a dispute between you and an Operator (for example over a cancellation or a refund), we may pass relevant information from the Operator to you — such as meeting-point instructions, schedule changes, or the Operator’s response to a complaint — and relevant booking information from you to the Operator.
The Operator uses this data to deliver the Tour. The Operator is an independent data controller for its own processing of your data after handover — including for its own legal record-keeping. Operators are required by their agreement with us to comply with applicable data-protection law and to use the data only to deliver the Tour.
Operators’ own reservation systems. Some Operators keep their availability and bookings in their own reservation system, run for them by a software provider. Where you book such a Tour, we place your booking in that system at checkout: the lead traveller’s first name, last name, email address, phone number, and language, the number and categories of participants, any note you entered at checkout, and our booking reference. In the booking’s note we also add, once, one line per traveller with the traveller’s name and, on Tours that ask for them, date of birth, identity-document number and nationality, so that the Operator has its passenger list in its own system. Other details the Tour asks for are not added to the note; the Operator sees them in its portal. If the note has no room for every line, it carries the names only, only the number of travellers, or no traveller lines, and the Operator sees the full list in its portal. For these Tours we ask for every detail at checkout, because a detail given later cannot be added to the Operator’s system. If you correct a detail after booking, the Operator sees the correction in its portal, and we tell the Operator that something changed if the correction comes after the deadline. No payment-card details are sent there. The Operator is the controller of that copy and its software provider is the Operator’s processor. We cannot delete or correct data inside the Operator’s system; the Operator is required by its agreement with us to act on any deletion or correction request we pass on.
Our Operators are currently based in Greece (within the EEA), so sharing booking data with them is not an international transfer. If we onboard an Operator outside the EEA, or an Operator tells us that it uses a subcontractor or supplier outside the EEA, we will put a valid transfer safeguard in place before booking data reaches them, and update this Policy.
After the Tour, the Operator keeps its own copy under its own retention policy and law, subject to the limits our Supplier Agreement places on it — in particular, for Transfer bookings the Operator must delete the pickup and drop-off details, your contact details, flight or sailing details, and any access notes within 5 days of the Transfer, unless a dispute about the booking is open or the law requires it to keep them for longer. That copy is otherwise the Operator’s responsibility, and a subject-access request about data the Operator holds should be directed to the Operator. We can supply the Operator’s contact details on request.
Photographs taken by Operators. Operators frequently photograph or film Tours for their own marketing. To the extent these recordings contain identifiable images of you, the Operator is the controller for that processing — speak to the Operator about consents, takedowns, and copies. Where we have asked the Operator for a copy of an image for our own marketing, we are the controller for that specific copy and you may also contact us.
5.2 Service providers and advertising partners
We share only what each provider needs. For providers acting as our processors, we have data-processing terms in place or rely on their standard data-processing terms incorporated into the service contract. Stripe, Twilio, Resend, Clerk, Vercel, Neon, Slack, Google Analytics and Google Maps Platform act as our processors. Meta, Google Ads and OpenAI Ads have the controller roles described here: for the collection carried out through the Meta Pixel we and Meta are joint controllers within the meaning of Article 26 GDPR, and Google acts as a separate controller in respect of the conversion data we report to it. The essence of our arrangement with Meta is available on request, and each of them applies its own controller terms to what it does with the data afterwards. OpenAI’s controller role and the Restricted Processing exception are described below. Microsoft acts as a data controller for its processing of Clarity data under the Microsoft Privacy Statement.
| Provider | Role | Data it processes | Where | Transfer safeguard |
|---|---|---|---|---|
| Stripe Payments Europe Ltd (EU contracting entity) | Payment processing, fraud screening | Payment + contact data | Ireland; US group entity Stripe, LLC | DPF Active (EU + UK + Swiss; certified 2026-05-11); SCCs in Stripe’s DPA as fallback |
| Twilio Inc. (contracting via Twilio Ireland Ltd) | SMS and WhatsApp delivery; receipt of WhatsApp messages and attachments you send us | Name, phone number, message content, attachments you send | Ireland; group entities incl. USA | DPF Active (EU + UK + Swiss) |
| Resend (legal entity Plus Five Five, Inc.) | Transactional email delivery | Name, email, message content | USA | DPF Active (EU + UK; no Swiss cert); DPA also incorporates the EU SCCs |
| Clerk, Inc. | Authentication and account management | Auth identifier, email, name | USA | DPF Active (EU + UK + Swiss); DPA includes SCCs |
| Vercel Inc. | Application hosting and CDN | Technical data, anything in requests | USA; EU edge | DPF Active (EU + UK + Swiss) |
| Neon (Neon, LLC, an affiliate of Databricks, Inc.) | Database hosting (EU region) | All stored personal data, at rest in the EU | EU region; US parent | DPF Active via Databricks, Inc. (Neon, LLC is a listed covered entity); terms via the Databricks DPA |
| Slack Technologies, LLC (a Salesforce company) | Our private team workspace: (a) booking-lifecycle alerts (new booking, Operator decline, payment failure, dispute, cancellation, email-delivery failure); (b) a copy of every WhatsApp conversation with customers and Operators, which our team reads and replies to from Slack | (a) Customer name, phone, email, booking reference, Tour title, date and time, party size and any free-text notes you gave at booking; (b) phone number, your name (where we can match the number to a booking) or WhatsApp display name, booking reference and Tour title, full message text in both directions, and a copy of any photo, voice note or file you send | Ireland; group entities incl. USA | DPF Active via Salesforce, Inc. (Slack is a listed covered entity) |
| Google Ireland Ltd / Google LLC: (a) Google Analytics 4, loads only after Analytics consent; (b) Google Ads conversion reporting, when we run Google Ads campaigns and only after Advertisement consent | (a) Usage analytics; (b) a server-to-server report that a booking was paid, retracted if the booking is cancelled before payment is taken or fully refunded (partial refunds are not reported) | (a) Technical + usage data (Consent Mode v2, default-denied); (b) Google click identifier, booking reference, booking value and currency, upload time, and a flag confirming that you granted Advertisement consent at checkout. No name, email, phone or other identity field is sent | Ireland; group entities incl. USA | DPF Active (EU + UK + Swiss) |
| Google Ireland Limited / Google LLC (Google Maps Platform): on information pages, and for maps that only help you choose from a list of pickup points, loads only after Functional consent; necessary in the transfer booking form | Maps and place search (§5.8) | IP address and technical data, the text you type in a place search box, the map area you view and your interactions with the map | Ireland; group entities incl. USA | DPF Active (EU + UK + Swiss); standard contractual clauses (see §5.8) |
| Microsoft Ireland Operations Limited / Microsoft Corporation (Microsoft Clarity), loads only on eligible public pages after Analytics consent | Heatmaps and session recordings to improve navigation and identify confusing pages; advertising storage is denied | Technical and usage data, public page and referring-page information, pseudonymous browser/session identifiers, clicks and scrolling. Input and dropdown contents are masked. No customer account IDs or booking references are supplied | Ireland; Microsoft Azure infrastructure, including USA and other countries where Microsoft operates | SCCs between Microsoft’s Irish and US entities; Microsoft also participates in the EU–US DPF. See the Microsoft Privacy Statement |
| Meta Platforms Ireland Ltd / Meta Platforms, Inc. (Meta Pixel) — active; loads only after Advertisement consent | Advertising measurement | Technical + event data | Ireland; group entities incl. USA | DPF Active (EU + Swiss; no UK Extension — UK-origin transfers rely on Meta’s UK addendum/IDTA) |
OpenAI Ads measurement. When you grant Advertisement consent, OpenAI Ireland Limited receives advertising click references, technical and event data, and browser-hashed matching data through the OpenAI Pixel and Conversions API. Under the OpenAI Ad Tools Data Processing Addendum, we and OpenAI each act as independent controllers for this measurement unless the Addendum's Restricted Processing terms apply. The Addendum requires a valid mechanism for onward transfers of EEA or Swiss personal data; its UK SCCs govern UK personal data processed by OpenAI OpCo, LLC.
We do not send booking or identity data to Meta from our servers. The Meta click identifier (fbclid) is stored on your booking record for our own attribution only.
Booking platforms and resellers. They are not our processors and do not act on our instructions; each is a separate, independent controller. Where your booking was made on such a platform, we exchange with it only the operational messages that booking needs: confirmation, amendment, cancellation, and the booking reference. We do not send it your data for marketing.
5.3 Authorities
We disclose data to courts, regulators, tax authorities, or law-enforcement bodies where legally required, or where necessary to protect our or a third party’s rights, property, or safety.
5.4 Business transfers
If we reorganise, merge, or are acquired, your data may transfer to the successor entity. We will notify Account holders before any such transfer takes effect.
5.5 What we do not do
We do not sell personal data. Apart from the Meta Pixel described in §5.2 and in our Cookie Policy — which loads only if you accept the Advertisement category, and which Meta may use to build advertising audiences — we do not share personal data with advertising networks for cross-site profiling. The only data we send to advertising platforms from our servers are the Google Ads conversion report described in §5.2, sent when we run Google Ads campaigns, and the OpenAI Conversions API report described in §8.2. The Google Ads report contains a click identifier, a booking reference and the booking value, but no name, email address or phone number, and it is sent only where you granted Advertisement consent at checkout. We do not pass your data to a sister site or third party for their own marketing. The operational exchange with a booking platform or reseller, or with an Operator’s reservation system, described in §3.3, §5.1, and §5.2 is not marketing. We honour the Global Privacy Control browser signal as an opt-out of any sale or sharing of personal data.
5.6 Profiling and personalisation
We may rank Tours, surface “popular” or “trending” results, and recommend Tours based on which destination and date you searched for, which Tours you have viewed or booked, and aggregated booking patterns across all customers. How ranking works is also explained in our Terms of Service.
This is personalisation, not automated decision-making with legal effects under Article 22 GDPR. You can browse without an Account; if you have an Account you can ask us to disable personalisation by emailing support@thegreeklocal.com. We do not build psychographic profiles for marketing and do not share profile data with third parties.
5.7 Affiliates who referred you
If you arrive at the Site through an affiliate’s link (a ?ref= parameter) and later book, we record the referral so the affiliate can be credited (see §8 for the cookie involved). The referring affiliate can see, in their dashboard: the booking reference, the booking date, and the booking value, together with the commission due to them. The affiliate is never shown your name, email, phone number, or any other identifying detail. Legal basis: our legitimate interest in measuring and paying for genuine referrals (Art. 6(1)(f)).
5.8 Maps and place search
Our pages show maps and let you search for a place, for example your hotel, using Google Maps Platform, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. When a map loads or you type in a place search box, your device sends Google your IP address, the text you type, the map area you look at and your interactions with the map. If you allow it, your browser may also share your approximate location so that the map can centre on you. Google processes this data on our behalf under the Google Maps Platform terms and may transfer it to Google LLC in the United States under the EU–US Data Privacy Framework and the standard contractual clauses. Maps on information pages load only after you allow functional cookies, either in the cookie banner or by pressing “Show map” on a page. The map inside the transfer booking form loads without that choice and does not depend on your cookie choices, because a transfer cannot be booked without marking the exact pickup or drop-off point on it; maps that only help you choose from a list of pickup points load only after you allow functional cookies. We keep only the point you choose (its coordinates and the name you type) as part of your booking.
6. International transfers
Our Operators are currently in Greece, within the EEA — sharing booking data with them is not an international transfer. See §5.1 for what happens if that changes.
Several of our service providers (§5.2) are US-headquartered. Where we transfer personal data outside the EEA we rely on:
-
the European Commission’s adequacy decisions where one exists;
-
the EU-US Data Privacy Framework for certified US recipients;
-
the European Commission’s Standard Contractual Clauses otherwise;
-
in all cases, supplementary measures (encryption in transit and at rest, access controls) appropriate to the risk.
You can request the safeguards in place for any specific transfer by emailing support@thegreeklocal.com.
7. How long we keep data
| Category | Retention |
|---|---|
| Booking records (incl. customer details on a booking) | 6 years after the booking date — for tax, VAT and accounting (Article 6(1)(c)), and for our legitimate interest in defending claims within the Cyprus limitation period (Article 6(1)(f)) |
| Reservation records for bookings sold by a booking platform or reseller, and bookings an Operator recorded itself | Held on the Operator’s behalf for as long as the booking record exists; the details a Tour asks for under “Details the Operator needs for your Tour” (§3.1), other than names and the answers and confirmations kept with the booking, and on such Tours a comment passed on by a booking platform (§3.3), are deleted 30 days after the Tour; deleted or returned to the Operator when its agreement with us ends, as that agreement provides |
| Advertising click identifiers, campaign labels, landing page and referring website on a booking (excluding the raw OpenAI Ads attribution reference covered separately below) | Kept with the booking record (6 years, see above). When we run Google Ads campaigns, the Google Ads report for a booking is sent when your payment is taken (retried if the first attempt fails, for up to 30 days) and retracted if the booking is cancelled before payment or fully refunded; partial refunds are not reported. Withdrawing Advertisement consent deletes the cookies (§8) and stops any further capture. Identifiers already copied to a completed booking are kept with that booking on the basis of the Advertisement consent under which they were collected; if you withdraw that consent we delete them from the booking record too, and keep only aggregate spend figures that no longer identify you |
| Advertising cookies gag_ad_click, gag_utm, gag_touch | 90 days from when they were last set (a later advertising click renews gag_ad_click and gag_utm; gag_touch is replaced only by a stronger signal, see §3.2), or immediately when you refuse or withdraw Advertisement consent |
| Details a Tour asks for (§3.1): date of birth, sex, nationality, passport or identity-card number, weight, height, shoe size, whether a traveller will drive, driving licence details, diving certification and the date of the last dive, emergency contact number, dietary needs and answers to the Operator’s own questions; and, on Tours that ask for these details, a comment passed on by a booking platform | Deleted 30 days after the Tour date, and in any case within 60 days. Travellers’ names, your yes-or-no answers about swimming and the confirmations you gave remain part of the booking record. The record of changes to these details (§4) stays with the booking record, but the deleted details are removed from it at the same time |
| Unfinished (draft) bookings | 14 days after capture, then deleted |
| Transfer quote requests that do not lead to a booking (addresses, date and time, party size, and the quotes we received) | 14 days after the quoting deadline passes, then deleted — the same period as unfinished bookings above |
| Payment records | 6 years, same reason |
| Consent records (cookie-banner choices; Terms/Privacy acceptance at booking) | 6 years, to evidence consent (truncated IP, opaque consent ID, document version) |
| Reminder-email opt-out list | Kept indefinitely — the suppression entry is what honours your opt-out |
| Account data (no booking activity) | Deleted 30 days after Account closure |
| Customer credits | Until expiry (per Terms §11) or 6 years after issue, whichever is later |
| Marketing email subscribers | Until you unsubscribe; suppressed indefinitely after that to honour the opt-out |
| Customer-service emails | 3 years after the case is closed |
| WhatsApp conversations (message text, attachment count, display name, phone number, our replies) | 24 months after the last message in the conversation. Deleting a booking does not delete the conversation; use the erasure route in §11 |
| Reviews | Indefinitely while published; removed within 30 days of a valid takedown request |
| Server logs (IP, user-agent) | 90 days for security; anonymised in aggregate after that |
| Google Analytics data | 24 months, then aggregated |
| Microsoft Clarity heatmaps and session recordings | Recordings are generally kept for 30 days. Recordings marked as favourites or labelled may be retained for up to 9 months; heatmap and click data are retained for 9 months. See Microsoft’s Clarity retention policy |
| Analytics identifiers on a booking (Google Analytics client and session identifiers, an opaque consent identifier, and a flag recording whether Analytics consent was granted at checkout), recorded only with Analytics consent so we can send pseudonymous purchase and refund events to Google Analytics 4 (§8) | Kept with the booking record (6 years, see above) |
| Raw OpenAI Ads booking attribution reference and consent audit identifier | Cleared after successful delivery or Advertisement-consent withdrawal. Otherwise, daily cleanup clears it once the first paid event is more than 7 days old or the booking was created more than 90 days ago. The server does not use it after the 90-day limit. |
| Cookies | See §8 — each cookie’s lifespan is published in the cookie banner |
After the retention period we delete or anonymise the data. Some records may persist longer where we must keep them by law or are using them in a live dispute.
Aggregated and anonymised data. Where data has been anonymised so you can no longer be identified, it falls outside the scope of personal data and we may retain and use it indefinitely for service improvement and trend analysis.
Operator-held data. Once data has been shared with an Operator (§5.1), the Operator’s own retention policy applies to its copy, within the limits our Supplier Agreement places on it (including the 5-day deletion rule for Transfer details described in §5.1); our deletion does not delete the Operator’s copy.
8. Cookies and similar technologies
Cookies have their own policy: the Cookie Policy at thegreeklocal.com/cookies lists every cookie we set, what it does, how long it lives, and the legal basis for each. The short version:
-
When you first visit the Site you are shown a consent banner with equal-weight Accept / Reject / Customise options across six categories (Necessary, Functional, Analytics, Performance, Advertisement, Other). Non-essential cookies are not deployed until you consent.
-
You can change or withdraw your choice at any time via the Cookie Consent link in the footer; we re-ask after 12 months, or sooner if the Cookie Policy materially changes.
-
Your banner choices are recorded in a consent audit log (see §4 and §7) so we can demonstrate consent.
-
The affiliate referral cookie (ref_code) is set only when you arrive through an affiliate’s link. It sits in the Functional category and is set only if you accept that category, because it serves our commission arrangement with the affiliate rather than a service you asked us for. It stores a partner code only, lives 90 days, and is never used to track you across sites. See §5.7 for what the affiliate can see.
-
Advertising attribution cookies (gag_ad_click, gag_utm, gag_touch) are first-party cookies in the Advertisement category. They are set only after you accept that category, live 90 days from when they were last set, are readable only by our server (HttpOnly, SameSite=Lax, Secure), and hold the click identifier, campaign labels, first landing page and referring website described in §3.2. If you refuse or later withdraw Advertisement consent, your browser immediately asks our server to delete them. After a grant we also keep one small entry in your browser’s local storage (gag_touch_sent) recording only that a first-touch record exists and when; it holds no attribution data and is removed when you withdraw. At checkout we also record whether Advertisement consent was in force, so every identifier on a booking sits next to the consent that allowed it.
-
Google Analytics 4, Microsoft Clarity, Meta Pixel and OpenAI Pixel are active on the Site. Each loads only after you consent to the relevant category: Analytics for Google Analytics 4 and Clarity, and Advertisement for Meta Pixel and OpenAI Pixel. Google Consent Mode v2 is set to default-denied. Clarity’s advertising storage consent remains denied regardless of your Advertisement choice.
-
With Analytics consent, GA4 records pseudonymous journey events such as searches and result counts, Tour and list views, checkout steps, successful account creation, and genuinely paid or refunded booking value. We do not send names, email addresses, phone numbers, form contents, free-text search terms, or selected booking dates and times to GA4. Our application does not supply customer or form fields to GA4 as user-provided data.
-
With Analytics consent, Microsoft Clarity uses heatmaps and session recordings of public-page clicks, scrolling and navigation to help us improve the Site and understand where visitors leave. It receives technical and usage data, public page and referring-page information, and pseudonymous browser/session identifiers. We do not supply names, email addresses, account IDs or booking references to Clarity. Input and dropdown contents are masked. We exclude account, administration, sign-in, booking and checkout pages, links containing private access tokens, and pages with sensitive query information. The legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time through Cookie Settings. We use Clarity for analytics only and keep its advertising storage consent denied. Microsoft’s processing is described in its Privacy Statement.
8.1 Other tracking technologies
-
Local storage and session storage — used in the browser for the same purposes as cookies (preferences, cart state). Treated the same way for consent purposes.
-
Server-side logs — every request is logged with IP, user-agent, URL, and response code, for 90 days, for security and abuse prevention.
-
Anti-fraud signals — Stripe runs its own device-fingerprinting on the payment page (Radar), as part of Stripe’s processing under its privacy policy.
8.2 OpenAI Ads measurement / Μέτρηση διαφημίσεων OpenAI
English. With your Advertisement consent, we use the OpenAI Pixel and Conversions API to measure eligible public page and Tour views, checkout starts and genuinely paid bookings so OpenAI can attribute activity to our advertisements in ChatGPT. The Pixel stores the advertisement's oppref click reference in the first-party __oppref cookie. It can also automatically detect supported customer information entered in recognisable forms and other sources on the Site, normalise it and securely hash it in your browser using SHA-256 before including the hashes with conversion events. Raw customer information is not sent to OpenAI through this automatic advanced matching. We mark our OpenAI events so they are not used for future user-level personalisation; this does not disable automatic advanced matching. For a paid booking, our server may send the click reference with a pseudonymous event identifier, the Tour identifier, booking value and currency, first-payment time and a public Tour-page URL. We do not manually include your name, email address or phone number in that server report. You can withdraw Advertisement consent at any time in Cookie Settings.
Ελληνικά. Με τη συγκατάθεσή σας στην κατηγορία Διαφήμισης, χρησιμοποιούμε το OpenAI Pixel και το Conversions API για να μετράμε επιλέξιμες προβολές δημόσιων σελίδων και Εκδρομών, την έναρξη ολοκλήρωσης κράτησης και κρατήσεις που πληρώθηκαν πραγματικά, ώστε το OpenAI να μπορεί να αποδίδει τη δραστηριότητα στις διαφημίσεις μας στο ChatGPT. Το Pixel αποθηκεύει την αναφορά διαφημιστικού κλικ oppref στο cookie πρώτου μέρους __oppref. Μπορεί επίσης να εντοπίζει αυτόματα υποστηριζόμενα στοιχεία πελάτη που καταχωρίζονται σε αναγνωρίσιμες φόρμες και άλλες πηγές στον Ιστότοπο, να τα κανονικοποιεί και να τα κατακερματίζει με ασφάλεια στον browser σας με SHA-256 πριν συμπεριλάβει τις τιμές κατακερματισμού στα συμβάντα μετατροπής. Μη κατακερματισμένα στοιχεία πελάτη δεν αποστέλλονται στο OpenAI μέσω αυτής της αυτόματης προηγμένης αντιστοίχισης. Επισημαίνουμε τα συμβάντα OpenAI ώστε να μη χρησιμοποιούνται για μελλοντική εξατομίκευση σε επίπεδο χρήστη· αυτό δεν απενεργοποιεί την αυτόματη προηγμένη αντιστοίχιση. Για μια πληρωμένη κράτηση, ο διακομιστής μας μπορεί να αποστείλει την αναφορά κλικ μαζί με ένα ψευδωνυμοποιημένο αναγνωριστικό συμβάντος, το αναγνωριστικό Εκδρομής, την αξία και το νόμισμα της κράτησης, τον χρόνο της πρώτης πληρωμής και τη διεύθυνση URL μιας δημόσιας σελίδας Εκδρομής. Δεν περιλαμβάνουμε χειροκίνητα το όνομα, τη διεύθυνση email ή το τηλέφωνό σας σε αυτή την αναφορά διακομιστή. Μπορείτε να ανακαλέσετε τη συγκατάθεση Διαφήμισης ανά πάσα στιγμή στις Ρυθμίσεις cookies.
9. Email and message tracking
9.1 Email open and click tracking
Our transactional emails are delivered by Resend and contain a small tracking pixel and link-rewriting that lets us see whether an email was opened and which links were clicked. We use this only to detect delivery failures (so we can resend by SMS/WhatsApp) and to diagnose support issues (“I never got the email”). We do not aggregate this into marketing profiles. You can defeat the tracking by viewing emails in plain-text mode or blocking remote images.
Marketing emails (where offered) carry the same pixel; the unsubscribe link in every marketing email removes you from the list with one click.
Review-request emails. After your Tour we send one email inviting you to review it. We treat this as part of delivering the service (see §4). If you would rather not receive review invitations, the opt-out link in the email stops them; reviews you do submit are published under your first name and may also appear in our own marketing materials, as explained at the moment you submit.
9.2 SMS messages
SMS notifications are sent from our alpha-sender ID “GreekLocal” through Twilio — typically a confirmation, a 24-hour reminder, and notices of changes or cancellation. Carrier charges may apply depending on your network and roaming status. To opt out of further SMS messages, reply STOP. We will continue to send time-critical operational notices (cancellation, change) by another channel for the duration of an active Booking.
9.3 WhatsApp messages
We may send WhatsApp messages through Twilio’s WhatsApp Business API where you have given us your number. The first message in a conversation is a pre-approved template; the WhatsApp client lets you block or report at any time. To opt out, reply STOP, block the number, or email us. WhatsApp itself processes message metadata under its own privacy policy.
If you write back. Replies and new messages you send to our WhatsApp number are received through Twilio, stored by us as a conversation thread under your phone number (§3.1), and copied into a private channel in our Slack workspace (§5.2) so a team member can answer. The copy shows your name where we can match the number to a booking (otherwise your WhatsApp display name or number), your booking reference and Tour title, each message in full, and a copy of any photo, voice note or file you send. Our replies are typed in Slack, sent back to you through Twilio, and stored in the same thread with a record of which team member sent them. Internal notes our team writes in the thread are never sent to you and are not added to the stored conversation; they remain in our Slack workspace. The same applies to WhatsApp conversations with Operators (see the Supplier Privacy Notice). Please do not send identity documents, card details or health information over WhatsApp unless we ask for something specific to deliver your booking; anything of that kind you do send is used only for that purpose (§3.5). Retention is set out in §7 and erasure in §11.
9.4 Abandoned-booking reminder emails
If you enter your email address and start a booking on the Site but do not complete it, we may send you up to three reminder emails over the following week to give you a chance to finish. We only remind you about that specific booking — we do not use your email for general marketing without your separate consent. A notice next to the email field on the booking form tells you this at the moment we collect the address.
Legal basis: the ePrivacy “soft opt-in” for messages about a sale you began (Article 13(2) of Directive 2002/58/EC, as transposed into Cyprus law), combined with our legitimate interest under Article 6(1)(f) GDPR in completing a sale negotiation you started. You can opt out at any time using the unsubscribe link in every reminder email; we keep your address on a suppression list (§7) so the opt-out sticks.
10. Security
We protect personal data with measures appropriate to the risk, including:
At the application layer — TLS 1.2+ for all traffic, HTTPS strictly enforced; session cookies marked Secure, HttpOnly, and SameSite=Lax by default; CSRF protection on state-changing actions; protection against common web vulnerabilities (XSS, SQL injection, SSRF).
At the data layer — encryption at rest for the production Postgres database (Neon, EU region); encrypted daily backups; payment-card data never received by our servers; tokenisation of cancel-links, supplier-action links, rebook links and the personal link for your travel details, so URLs do not leak primary keys. That personal link shows none of your travel details until you confirm the booking’s email address or the lead traveller’s surname, and it then shows dates of birth and identity numbers only in part.
At the operations layer — role-based access control with least privilege; multi-factor authentication on admin Accounts and third-party dashboards; audit logging of sensitive operations (refunds, account changes, supplier changes, data exports); secrets stored in encrypted environment variables; regular dependency updates; regular review of access lists.
No system is perfectly secure. If we discover a personal-data breach likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours of becoming aware, and where the breach is high-risk to you, notify you directly without undue delay.
If you discover a security issue with the Site, please report it to support@thegreeklocal.com before disclosing it publicly. We will not pursue claims against good-faith security researchers who follow this responsible-disclosure approach.
11. Your rights
Under the GDPR you have the right to:
-
Access — a copy of the personal data we hold about you.
-
Rectification — correction of inaccurate or incomplete data. If you chose to give some details after booking, you can give or correct them yourself through the personal link in your confirmation email, and if you have an Account you can do so there for any booking, until the deadline shown when you book, which the Operator sets for its Tour (normally 48 hours before departure). Otherwise, or after that time, contact us and we will pass the correction to the Operator.
-
Erasure — deletion of your data where a GDPR ground applies. We cannot delete records we are legally required to keep (for example financial records during the 6-year retention window). For WhatsApp conversations, tell us the phone number you messaged from; we will delete the stored conversation and its copy in our Slack workspace, except for anything we must keep to evidence a booking or a dispute, and we will instruct our messaging provider to delete its copy.
-
Restriction — to ask us to suspend processing while a dispute is resolved.
-
Portability — a copy of the data you provided, in a structured, machine-readable format.
-
Objection — to object to processing based on legitimate interests, including direct marketing (we will stop processing for direct marketing in all cases).
-
Withdraw consent — to withdraw any consent at any time, without affecting processing already carried out. Withdrawing Advertisement consent via the footer link deletes the attribution cookies and stops further capture (§8); it does not undo a Google Ads or OpenAI Ads report already sent for a completed booking.
-
Lodge a complaint with a supervisory authority. Our lead authority is the Office of the Commissioner for Personal Data Protection (Επίτροπος Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Iasonos 1, 1082 Nicosia, Cyprus — dataprotection.gov.cy. You may also complain to the data-protection authority in your own country of residence. If you are in the United Kingdom, that includes the Information Commissioner’s Office (ico.org.uk).
11.1 Right to object — direct marketing
Article 21(2) GDPR gives you an absolute right to object to processing of your data for direct-marketing purposes. Where you exercise it, we will stop processing your data for direct marketing immediately and indefinitely, with no need to give a reason. The unsubscribe link in every marketing email is one way to exercise it; emailing us is another.
11.2 How to make a request
Email support@thegreeklocal.com with enough detail for us to locate your data (your email address, booking reference, or Account email, or, for WhatsApp conversations, the phone number you messaged from). We may need to verify your identity before responding. We respond within one month; complex or numerous requests may take up to three months in total, in which case we will tell you within the first month. There is no charge, except where requests are manifestly unfounded or excessive (Article 12(5) GDPR).
The data you submit when exercising a right (your message, proof of identity) is itself processed so we can fulfil the request and evidence our compliance — legal basis Article 6(1)(c) GDPR.
11.3 Automated processing in our fraud and payment checks
Some checks in our payment and fraud-prevention process are automated. Our payment processor, Stripe (including Stripe Radar), screens transactions for fraud, and a transaction assessed as high-risk may be automatically declined — which means a Booking may not complete.
If an automated decline affects you, you can ask us to review it, give us your point of view, and contest the outcome, by emailing support@thegreeklocal.com. Apart from this fraud-screening, we do not make decisions that produce legal or similarly significant effects on you based solely on automated processing.
12. Third-party links and embedded content
Pages on the Site may link to, or embed content from, third-party services — for example maps and place search by Google Maps Platform (see §5.8), embedded videos, or links to Operator social-media profiles. Where third-party content is embedded, the third party may set its own cookies and collect technical data as soon as the content loads. We disclose this in the cookie banner and, where consent is required, load the embed only after you consent.
Following an external link takes you outside the Site. We are not responsible for the privacy practices of third-party sites — please read their own policies.
13. Children
The Service is intended for adults. We do not direct the Site at children under 16, as our Cookie Policy also states. We do not knowingly collect personal data of children except as part of a booking made by an accompanying adult: for example children’s names on a family Tour or, where a Tour must carry a passenger list, the details that list requires for every child and infant on board (§3.1). We collect a child’s data only where it is provided by and with the consent of a parent or guardian as part of their own booking. Children cannot create Accounts. If we discover we hold a child’s data collected outside this case, or without valid parental consent, we will delete it — and if you believe that has happened, contact us.
14. Changes to this Policy
We may update this Policy from time to time. The current version is always at thegreeklocal.com/privacy with the effective date at the top. We will post any material change on this page at least 14 days before it takes effect. Account holders may also be notified by email.
This Policy is drafted in English. Any translation (including the Greek version) is provided for convenience only; if the versions diverge, the English version prevails.
15. Contact
Privacy questions or requests: support@thegreeklocal.com Postal: Vavyla 3, Block A, Flat/Office 204, Pera Chorio, 2572 Nicosia, Cyprus
We aim to acknowledge within 3 working days and resolve within the GDPR’s one-month window (see §11.2). For reporting illegal content on the Site, see Terms of Service §16.