Book NowProperty Photos
Open-plan kitchen and dining area at casadimariokalives.com

Privacy Policy

Learn how we collect, use, store and protect your personal information when you visit our website or make a reservation.

Last updated: August 7, 2026

Casa Di Mario Kalives respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store and protect personal information when you visit our website, contact us or make a reservation with Casa Di Mario.

It also explains the rights available to you under the General Data Protection Regulation (EU) 2016/679 – GDPR, Greek Law 4624/2019 and other applicable data-protection legislation. The GDPR applies directly in Greece and is supplemented by Greek national data-protection legislation.

By using this website or submitting personal information through our booking or contact systems, you acknowledge that you have read this Privacy Policy.

1. Data Controller

The data controller responsible for the processing of personal data through this website and in connection with reservations is:

Casa Di Mario Kalives

Property Manager / Host: Maria Kladeraki

  • Address: Palaia EO Rethymnou Chanion 50, Kalyves, Chania, Crete, 73003, Greece

AMA: 00003559329

Email: info@casadimariokalives.com

Telephone: +30 697 403 3259

For any privacy-related question or request concerning your personal information, you may contact us using the details above.

2. Personal Data We Collect

Depending on how you interact with the website and our services, we may collect the following categories of information.

Booking information

  • When you make a reservation, we may collect:
  • first name
  • last name
  • email address
  • telephone number
  • country or region
  • check-in date
  • check-out date
  • number of guests
  • selected additional services
  • pet information where applicable
  • reservation notes or special requests
  • booking number
  • reservation status
  • booking price

payment method.

Identification information

For accommodation management, guest identification and where necessary for administrative, tax, accounting or legal purposes, we may request:

ID Card Number or Passport Number.

We request the document number only and do not normally require a copy of your identity document unless this becomes necessary under applicable law or for a specific legitimate reason.

Payment information

When you choose an online payment method, payment processing is performed by an external payment provider such as Viva or another payment provider made available at checkout.

  • We may receive information such as:
  • payment status
  • payment method
  • transaction identifier
  • amount paid
  • date and time of payment

refund status.

We do not normally receive or store your complete credit or debit card number, CVV or full card credentials.

Those details are processed directly by the payment provider.

Communications

If you contact us by email, telephone, website form or in connection with a booking, we may process:

  • your name
  • contact details
  • message content
  • booking reference

correspondence history.

Technical and usage information

When you visit our website, certain technical information may be processed automatically, including:

IP address;

  • browser type
  • device type
  • operating system
  • approximate location derived from IP address
  • pages visited
  • referring website
  • session information
  • date and time of access

website interaction information.

Server log information may also be processed for security and troubleshooting. Log processing for security purposes is a recognized data-protection use case where appropriate safeguards and retention periods are applied.

3. Why We Collect Your Personal Data

We process personal data only where we have a valid purpose and legal basis.

The GDPR requires organizations to identify why personal information is needed, limit collection to what is necessary and define an appropriate legal basis for processing.

We may process your data for the following purposes.

A. Managing your reservation

  • We use your information to:
  • create and manage your reservation
  • verify booking details
  • calculate the cost of your stay
  • process requested extras
  • communicate booking confirmations
  • manage changes or cancellations
  • prepare the accommodation for your arrival

provide customer support.

Legal basis: performance of a contract or taking steps at your request before entering into a contract.

B. Processing payments

  • We process information required to:
  • receive online payments
  • verify payment status
  • manage refunds where applicable
  • reconcile payments with reservations

prevent payment errors or fraud.

Legal basis: performance of the booking contract and, where applicable, our legitimate interest in managing secure payments and preventing fraud.

C. Legal, tax and accounting obligations

  • We may process and retain information where required for:
  • accounting
  • taxation
  • reservation records
  • invoicing or receipts
  • reporting obligations
  • compliance with Greek law

responding to lawful requests from public authorities.

Legal basis: compliance with a legal obligation.

4. Why We Ask for an ID Card / Passport Number

During the booking or accommodation process, we may request the guest’s ID Card or Passport Number.

  • This information may be used for:
  • guest identification
  • correctly associating a reservation with the responsible guest
  • accommodation administration
  • issuing legally required documents
  • accounting or tax-related processes
  • compliance with applicable regulatory requirements

resolving disputes relating to a reservation where necessary.

We aim to collect only the information reasonably necessary for these purposes.

We do not request identity information for advertising or marketing purposes.

The ID or passport number is treated as confidential personal data and access is restricted to persons who reasonably need it for accommodation or administrative purposes.

5. Legal Bases for Processing

Depending on the specific processing activity, we rely on one or more of the following legal bases under Article 6 GDPR:

Contract

Processing is necessary to enter into or perform your reservation agreement.

  • Examples include:
  • booking details
  • stay dates
  • guest information
  • payments

cancellations.

Legal obligation

Processing is required to comply with applicable law.

  • Examples may include:
  • tax records
  • accounting information
  • regulatory reporting

legally required reservation records.

Legitimate interests

We may process information where necessary for legitimate business interests, provided those interests do not override your fundamental rights.

  • Examples include:
  • website security
  • preventing fraud
  • troubleshooting
  • managing disputes
  • maintaining service quality

basic internal statistical analysis.

Consent

Where required, we may rely on your consent.

  • This is particularly relevant to certain:
  • analytics cookies
  • non-essential tracking technologies

optional third-party services.

Where processing relies on consent, you may withdraw that consent at any time.

6. Analytics

We may use analytics technologies to understand how visitors use our website and to improve its performance and usability.

  • These may include:

Google Analytics 4

  • Google Analytics may collect information such as:
  • page views
  • session duration
  • device information
  • browser information
  • approximate geographic information
  • website interactions

referral information.

Where required by applicable law, Google Analytics is activated only after the visitor provides the appropriate cookie consent.

WP Statistics

We also use WP Statistics to obtain website traffic and usage statistics.

Depending on its configuration, WP Statistics may process technical visitor information such as:

  • pages visited
  • referring pages
  • browser information
  • device information

IP-related information.

We aim to configure analytics tools in a privacy-conscious manner and only collect information reasonably required for statistical purposes.

7. Google Maps

Our website may use Google Maps to display the location of Casa Di Mario or nearby geographic information.

  • When Google Maps is loaded, Google may receive technical information such as:
  • your IP address
  • browser information
  • device information

interaction with the embedded map.

Where required, Google Maps content may be blocked until the visitor provides consent for the relevant category of cookies or external content.

Google acts independently in relation to certain data processing carried out through its services and maintains its own privacy terms.

8. Cookies

Our website uses cookies and similar technologies.

Cookies are small files stored on your device that may be required for website functionality or may be used for analytics and other purposes.

  • Cookies may include:

Essential cookies

  • These are necessary for the operation of the website and may support:
  • booking functionality

WooCommerce checkout;

  • shopping or booking sessions
  • security
  • language preferences

payment processing.

Essential cookies normally do not require consent where they are strictly necessary to provide a service requested by the visitor.

Analytics cookies

Analytics cookies help us understand how the website is used.

They may relate to services such as Google Analytics.

Where consent is legally required, these cookies will not be activated until consent has been provided.

Third-party cookies

Third-party services such as maps or payment systems may place their own cookies where required for their functionality.

Detailed information about cookies may be provided separately through our Cookie Policy and cookie-consent interface.

9. WooCommerce and Booking System

Our website uses WooCommerce and booking functionality to process reservations.

Information submitted during checkout may be stored in the website’s database and associated with your WooCommerce order or booking.

  • This may include:
  • guest name
  • telephone number
  • email
  • country

ID or passport number;

  • booking dates
  • booking extras
  • pet option
  • total number of nights
  • payment information

order notes.

The information is used solely for legitimate booking, administrative and operational purposes unless otherwise disclosed.

10. Payment Providers

Where you select online payment, information necessary to process your payment may be shared with the relevant payment provider.

  • This may currently include:

Viva

and may in the future include other payment providers displayed during checkout.

Payment providers process payment information under their own security and privacy policies.

We do not control the internal systems used by those providers.

Only information reasonably necessary for the transaction is transferred.

If you select Pay at Casa Di Mario, no external online payment transaction is required at the time of reservation unless otherwise indicated.

11. Who We Share Personal Data With

We do not sell personal data.

We may share information only where reasonably necessary with categories of recipients such as:

  • payment providers
  • web-hosting providers
  • email-service providers
  • website technical support providers
  • booking and e-commerce software providers
  • accountants or professional advisers
  • competent tax authorities
  • regulatory authorities

law-enforcement authorities where legally required.

Service providers that process personal data on our behalf are expected to use appropriate safeguards and process data only for legitimate purposes.

12. International Data Transfers

Some third-party service providers may process information outside Greece or the European Economic Area.

This may occur, for example, when services provided by international technology companies are used.

Where personal data is transferred outside the EEA, appropriate safeguards are expected to be used where required under the GDPR, such as:

  • an adequacy decision by the European Commission

Standard Contractual Clauses;

another legally recognized transfer mechanism.

13. How Long We Keep Your Information

We do not intend to retain personal information indefinitely.

Reservation and guest information is generally retained for up to approximately 3 years after the reservation, unless a longer period is required for:

  • tax obligations
  • accounting obligations
  • legal claims
  • dispute resolution
  • fraud prevention

another applicable legal requirement.

Certain accounting or legally required records may therefore be retained longer where Greek law requires it.

Data no longer reasonably required for operational, statistical or legal purposes may be deleted or anonymised.

The GDPR principle of storage limitation requires organisations to define and justify how long personal data is needed and to remove information that is no longer necessary.

14. Data Security

We take reasonable technical and organisational measures to protect personal information against:

  • unauthorised access
  • accidental disclosure
  • alteration
  • destruction
  • misuse

loss.

  • Measures may include:
  • encrypted website connections using HTTPS
  • restricted administrative access
  • website security controls
  • access credentials
  • software updates
  • backups
  • firewall and security systems

limited access to reservation information.

No internet-based system can guarantee absolute security. However, we take reasonable measures appropriate to the nature of the information processed.

15. Your GDPR Rights

Under applicable data-protection law, you may have the following rights.

Right of access

You may ask whether we process personal data relating to you and request a copy of that information.

Right to rectification

You may request correction of inaccurate or incomplete personal data.

Right to erasure

In certain circumstances, you may request deletion of personal data.

This right is not absolute and may not apply where we must retain information for legal, tax or contractual purposes.

Right to restriction

You may request restriction of processing under certain circumstances.

Right to data portability

Where applicable, you may request certain information you provided in a structured and commonly used format.

Right to object

You may object to certain processing carried out on the basis of legitimate interests.

Right to withdraw consent

Where processing is based on consent, you may withdraw your consent at any time.

Withdrawal does not affect processing that was lawful before consent was withdrawn.

These rights correspond to the rights recognized by the Hellenic Data Protection Authority under Articles 15–22 GDPR.

16. How to Exercise Your Rights

  • To exercise a privacy right, contact:

Email: info@casadimariokalives.com

Please provide enough information for us to identify the relevant reservation or personal information.

We may need to verify your identity before completing certain requests to avoid disclosing information to an unauthorized person.

Requests will be handled in accordance with the time limits required by applicable data-protection law.

17. Complaints to the Data Protection Authority

If you believe your personal information has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.

  • In Greece, the supervisory authority is the:

Hellenic Data Protection Authority

Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα

The Authority provides guidance on individual rights, transparency and personal-data processing under the GDPR.

You are encouraged to contact us first so that we have an opportunity to investigate and resolve your concern.

18. Children

Reservations must be made by a person who is at least 18 years old.

The website is not intended for children to independently create reservations or submit personal information.

Information relating to children may nevertheless be included in a reservation where provided by an adult responsible for the booking and where reasonably necessary for accommodation management.

19. Special Requests

Guests may voluntarily provide information through the booking notes or other communications.

Please avoid including unnecessary sensitive personal information.

For example, unless genuinely required for the provision of the accommodation, guests should avoid submitting information concerning:

  • medical conditions
  • health information
  • religious beliefs
  • political opinions

other sensitive personal matters.

If such information is provided voluntarily, it will only be used where reasonably necessary to address the guest’s request and where processing is legally permitted.

20. Email Communications

  • We may send transactional emails relating to your reservation, including:
  • booking confirmation
  • payment confirmation
  • reservation updates
  • cancellation information
  • refund information

important information regarding your stay.

These communications are part of the accommodation service and are not considered marketing emails.

We will not automatically add booking customers to a promotional mailing list unless an appropriate legal basis exists.

21. Automated Decision-Making

Casa Di Mario does not normally use personal data to make decisions based solely on automated processing that produce significant legal effects concerning guests.

  • Automated systems may nevertheless be used for routine functions such as:
  • booking availability
  • price calculation
  • online payment processing

reservation confirmation.

These systems support the booking process but do not generally involve profiling intended to make significant decisions about an individual.

22. External Links

Our website may contain links to websites operated by third parties.

We are not responsible for the privacy practices or content of external websites.

Users should review the privacy information provided by the relevant third-party website before submitting personal information.

23. Changes to This Privacy Policy

  • We may update this Privacy Policy from time to time to reflect:
  • changes to website functionality
  • new payment methods
  • new service providers
  • changes to analytics technologies
  • legal or regulatory requirements

changes to our internal practices.

The latest version will always be published on this website.

The Last updated date at the beginning of this Privacy Policy indicates when the latest revision was made.

24. Contact Information

For questions concerning this Privacy Policy or the processing of your personal information, contact:

Casa Di Mario Kalives

Palaia EO Rethymnou Chanion 50

Kalyves, Chania, Crete

  • 73003 Greece

AMA: 00003559329

Telephone: +30 697 403 3259

Email: info@casadimariokalives.com

Need Help?

We’re here to help you with any questions about your stay

Call Us !