Need Help?
We’re here to help you with any questions about your stay

Learn how we collect, use, store and protect your personal information when you visit our website or make a reservation.
Casa Di Mario Kalives respects your privacy and is committed to protecting your personal data.
This Privacy Policy explains how we collect, use, store and protect personal information when you visit our website, contact us or make a reservation with Casa Di Mario.
It also explains the rights available to you under the General Data Protection Regulation (EU) 2016/679 – GDPR, Greek Law 4624/2019 and other applicable data-protection legislation. The GDPR applies directly in Greece and is supplemented by Greek national data-protection legislation.
By using this website or submitting personal information through our booking or contact systems, you acknowledge that you have read this Privacy Policy.
The data controller responsible for the processing of personal data through this website and in connection with reservations is:
For any privacy-related question or request concerning your personal information, you may contact us using the details above.
Depending on how you interact with the website and our services, we may collect the following categories of information.
payment method.
For accommodation management, guest identification and where necessary for administrative, tax, accounting or legal purposes, we may request:
ID Card Number or Passport Number.
We request the document number only and do not normally require a copy of your identity document unless this becomes necessary under applicable law or for a specific legitimate reason.
When you choose an online payment method, payment processing is performed by an external payment provider such as Viva or another payment provider made available at checkout.
refund status.
We do not normally receive or store your complete credit or debit card number, CVV or full card credentials.
Those details are processed directly by the payment provider.
If you contact us by email, telephone, website form or in connection with a booking, we may process:
correspondence history.
When you visit our website, certain technical information may be processed automatically, including:
website interaction information.
Server log information may also be processed for security and troubleshooting. Log processing for security purposes is a recognized data-protection use case where appropriate safeguards and retention periods are applied.
We process personal data only where we have a valid purpose and legal basis.
The GDPR requires organizations to identify why personal information is needed, limit collection to what is necessary and define an appropriate legal basis for processing.
We may process your data for the following purposes.
provide customer support.
Legal basis: performance of a contract or taking steps at your request before entering into a contract.
prevent payment errors or fraud.
Legal basis: performance of the booking contract and, where applicable, our legitimate interest in managing secure payments and preventing fraud.
responding to lawful requests from public authorities.
Legal basis: compliance with a legal obligation.
During the booking or accommodation process, we may request the guest’s ID Card or Passport Number.
resolving disputes relating to a reservation where necessary.
We aim to collect only the information reasonably necessary for these purposes.
We do not request identity information for advertising or marketing purposes.
The ID or passport number is treated as confidential personal data and access is restricted to persons who reasonably need it for accommodation or administrative purposes.
Depending on the specific processing activity, we rely on one or more of the following legal bases under Article 6 GDPR:
Processing is necessary to enter into or perform your reservation agreement.
cancellations.
Processing is required to comply with applicable law.
legally required reservation records.
We may process information where necessary for legitimate business interests, provided those interests do not override your fundamental rights.
basic internal statistical analysis.
Where required, we may rely on your consent.
optional third-party services.
Where processing relies on consent, you may withdraw that consent at any time.
We may use analytics technologies to understand how visitors use our website and to improve its performance and usability.
referral information.
Where required by applicable law, Google Analytics is activated only after the visitor provides the appropriate cookie consent.
We also use WP Statistics to obtain website traffic and usage statistics.
Depending on its configuration, WP Statistics may process technical visitor information such as:
IP-related information.
We aim to configure analytics tools in a privacy-conscious manner and only collect information reasonably required for statistical purposes.
Our website may use Google Maps to display the location of Casa Di Mario or nearby geographic information.
interaction with the embedded map.
Where required, Google Maps content may be blocked until the visitor provides consent for the relevant category of cookies or external content.
Google acts independently in relation to certain data processing carried out through its services and maintains its own privacy terms.
Our website uses cookies and similar technologies.
Cookies are small files stored on your device that may be required for website functionality or may be used for analytics and other purposes.
payment processing.
Essential cookies normally do not require consent where they are strictly necessary to provide a service requested by the visitor.
Analytics cookies help us understand how the website is used.
They may relate to services such as Google Analytics.
Where consent is legally required, these cookies will not be activated until consent has been provided.
Third-party services such as maps or payment systems may place their own cookies where required for their functionality.
Detailed information about cookies may be provided separately through our Cookie Policy and cookie-consent interface.
Our website uses WooCommerce and booking functionality to process reservations.
Information submitted during checkout may be stored in the website’s database and associated with your WooCommerce order or booking.
order notes.
The information is used solely for legitimate booking, administrative and operational purposes unless otherwise disclosed.
Where you select online payment, information necessary to process your payment may be shared with the relevant payment provider.
and may in the future include other payment providers displayed during checkout.
Payment providers process payment information under their own security and privacy policies.
We do not control the internal systems used by those providers.
Only information reasonably necessary for the transaction is transferred.
If you select Pay at Casa Di Mario, no external online payment transaction is required at the time of reservation unless otherwise indicated.
We do not sell personal data.
We may share information only where reasonably necessary with categories of recipients such as:
law-enforcement authorities where legally required.
Service providers that process personal data on our behalf are expected to use appropriate safeguards and process data only for legitimate purposes.
Some third-party service providers may process information outside Greece or the European Economic Area.
This may occur, for example, when services provided by international technology companies are used.
Where personal data is transferred outside the EEA, appropriate safeguards are expected to be used where required under the GDPR, such as:
another legally recognized transfer mechanism.
We do not intend to retain personal information indefinitely.
Reservation and guest information is generally retained for up to approximately 3 years after the reservation, unless a longer period is required for:
another applicable legal requirement.
Certain accounting or legally required records may therefore be retained longer where Greek law requires it.
Data no longer reasonably required for operational, statistical or legal purposes may be deleted or anonymised.
The GDPR principle of storage limitation requires organisations to define and justify how long personal data is needed and to remove information that is no longer necessary.
We take reasonable technical and organisational measures to protect personal information against:
loss.
limited access to reservation information.
No internet-based system can guarantee absolute security. However, we take reasonable measures appropriate to the nature of the information processed.
Under applicable data-protection law, you may have the following rights.
You may ask whether we process personal data relating to you and request a copy of that information.
You may request correction of inaccurate or incomplete personal data.
In certain circumstances, you may request deletion of personal data.
This right is not absolute and may not apply where we must retain information for legal, tax or contractual purposes.
You may request restriction of processing under certain circumstances.
Where applicable, you may request certain information you provided in a structured and commonly used format.
You may object to certain processing carried out on the basis of legitimate interests.
Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal does not affect processing that was lawful before consent was withdrawn.
These rights correspond to the rights recognized by the Hellenic Data Protection Authority under Articles 15–22 GDPR.
Please provide enough information for us to identify the relevant reservation or personal information.
We may need to verify your identity before completing certain requests to avoid disclosing information to an unauthorized person.
Requests will be handled in accordance with the time limits required by applicable data-protection law.
If you believe your personal information has been processed unlawfully, you have the right to lodge a complaint with the competent supervisory authority.
The Authority provides guidance on individual rights, transparency and personal-data processing under the GDPR.
You are encouraged to contact us first so that we have an opportunity to investigate and resolve your concern.
Reservations must be made by a person who is at least 18 years old.
The website is not intended for children to independently create reservations or submit personal information.
Information relating to children may nevertheless be included in a reservation where provided by an adult responsible for the booking and where reasonably necessary for accommodation management.
Guests may voluntarily provide information through the booking notes or other communications.
Please avoid including unnecessary sensitive personal information.
For example, unless genuinely required for the provision of the accommodation, guests should avoid submitting information concerning:
other sensitive personal matters.
If such information is provided voluntarily, it will only be used where reasonably necessary to address the guest’s request and where processing is legally permitted.
important information regarding your stay.
These communications are part of the accommodation service and are not considered marketing emails.
We will not automatically add booking customers to a promotional mailing list unless an appropriate legal basis exists.
Casa Di Mario does not normally use personal data to make decisions based solely on automated processing that produce significant legal effects concerning guests.
reservation confirmation.
These systems support the booking process but do not generally involve profiling intended to make significant decisions about an individual.
Our website may contain links to websites operated by third parties.
We are not responsible for the privacy practices or content of external websites.
Users should review the privacy information provided by the relevant third-party website before submitting personal information.
changes to our internal practices.
The latest version will always be published on this website.
The Last updated date at the beginning of this Privacy Policy indicates when the latest revision was made.
For questions concerning this Privacy Policy or the processing of your personal information, contact: