Privacy Notice
Last Updated:
May 24th, 2018
At ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.
Information & Consent
This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.
By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.
The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε.
When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://plexispace.reserve-online.net/ unless specified otherwise.
By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.
Identity
When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε.
Data Controller
ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:
Plexi Space “ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε” Iera Odos 39 11854, Athens GR
Data Processor
WebHotelier operates this booking system on behalf of ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε and is committed to protecting the privacy of the users of this system. WebHotelier is:
Revplus Hellas S.A. 5th Km Rhodou-Lindou Ave. 851 00, Rhodes Greece
For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Ltd.
WebHotelier is a certified PCI-DSS Level 2 Service Provider audited quarterly by Sectigo Limited.
The User may contact WebHotelier's Data Protection Officer:
Data Protection Officer dpo@webhotelier.net
Obligatory nature of providing the data
The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.
Personal data we collect and process
This will include:
- personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
- financial details in order to process your booking when we require pre-payment;
- details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
- our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.
We grant permission to our data processor:
- to use your personal information for reserving rooms and/or other services for you at ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε;
- to pass on your financial details to ΠΛΕΞΗ ΣΠΕΙΣ ΜΟΝ Α.Ε and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
- to use your information for marketing purposes (where you explicitly agree to this); and
- to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).
Social Login:
In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.
Third-party data (e.g. book for a friend)
In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.
Sensitive Data
Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).
Use of Services by Minors
The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.
Purpose of processing personal data
Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:
- To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
- To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
- To manage the User’s contact requests with us through the channels provided to this end.
- To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
- To manage the provision of the contracted accommodation service, as well as additional services.
- To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.
Data Retention
We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.
The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
- Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)
Legitimate interest for processing your data
The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.
Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.
To revoke such consent, the User may contact us through the appropriate channels.
By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.
Data Disclosure
We will use and disclose Personal Data as we believe to be necessary or appropriate:
- to comply with applicable law, including laws outside your country of residence;
- to comply with legal process;
- to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
- to enforce our terms and conditions;
- to protect our operations;
- to protect the rights, privacy, safety or property of our own, you or others; and
- to allow us to pursue available remedies or limit the damages that we may sustain.
We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.
International transfers of personal data
We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).
Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.
User's Responsibility
The User:
Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.
Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.
Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.
Exercise of Rights
The User may contact us at any time free of charge, to:
- To obtain confirmation about whether or not personal data concerning the User are being processed by us.
- To access their personal details.
- To rectify any inaccurate or incomplete data.
- To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
- To confirm revocation of consent.
- To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
- To request the portability of your data.
Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.
Security Measures
We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.
Personal Data Protection Policy & Video Surveillance System
1. Introduction
Taking into account Law 4624/2019, the Hellenic Data Protection Authority, and the implementation measures of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data, PLEXI declares, through this Personal Data Protection and Video Surveillance Policy, that it respects the privacy of its customers and is committed to protecting the personal data it collects in the course of providing its services in rented rooms and on its website.
Therefore, the types of information that PLEXI may collect during a customer's visit to its rented accommodation premises or its website are outlined below, along with information on how these data are used and managed.
When customers voluntarily provide personal information—such as name, address, or email address—PLEXI treats this data with the utmost confidentiality. Subject to specific provisions of this Personal Data Protection Policy, no personal information is rented, sold, publicly posted, or disclosed to other companies, organizations, or websites.
2. PLEXI as the Data Controller
PLEXI, as the controller of personal data, is a private limited liability company under the name "PLEXI SPACE ROOMS SINGLE-MEMBER S.A.", based in Athens (39 Iera Odos Street). For the purposes of its business operations, it collects and processes personal data of its associates, suppliers, employees, and customers, in accordance with the applicable legal framework. Accordingly, PLEXI acts as a data controller under Article 4(7) of the GDPR.
Email: info@plexispace.com
Phone: +30 210 34 17 700
3. Collection and Protection of Personal Data
PLEXI collects and processes its customers’ personal data, including:
Customer identification data (full name, phone, email, Tax ID number, address, occupation, photograph, marital status, etc.), as provided by the customer during room booking or service use.
Copies of identification documents, such as an ID card or passport.
Financial data relevant to completing transactions, such as bank account number, credit/debit card number, etc. PLEXI complies with the Payment Card Industry Data Security Standard (PCI DSS) in this regard.
Technical and personal data, including browsing history, IP address, screen resolution, browser, operating system and settings, access times, and referring URLs. If the customer uses a mobile device, PLEXI may also collect device identifiers, settings, and location data.
PLEXI may also collect data from individuals who are not guests—e.g., from social events (weddings, baptisms, parties, etc.) or corporate gatherings held on its premises.
The legal bases for this processing are contract performance (Article 6(1)(b) GDPR) and PLEXI’s legitimate interests (Article 6(1)(f) GDPR).
4. Purpose of Processing
Customer information is used for the following purposes:
To manage room reservations and provide the corresponding services.
To personalize services based on customer preferences.
To facilitate future service provision by storing customers’ data.
To communicate with customers and send information, products, and services that might interest them.
Customers can unsubscribe anytime by sending an email to info@plexispace.com.
To validate customer information, ensuring relevance and accuracy.
To comply with any legal obligations.
To protect PLEXI’s legitimate interests, through the use of a Closed Circuit Television (CCTV) system for the safety of premises, staff, and customers.
Warning signs indicate areas under surveillance. PLEXI ensures cameras are installed and operated only where necessary, minimizing any impact on fundamental rights. CCTV coverage is limited to entrances, exits, reception areas, cash handling areas, and technical facilities.
The system is not used for employee performance monitoring. Data from surveillance are not used against customers without proper notice.
5. Methods of Data Collection
PLEXI collects customer data through:
In-person interactions
Telephone communications
Its website
Email correspondence
6. Use and Disclosure of Personal Data
Access to personal data is restricted to authorized PLEXI personnel and partner service providers bound by confidentiality and contractual obligations.
Data may be disclosed to:
Employees or external partners who require access to perform their duties (reservations, payment services, IT support, etc.).
Public authorities (Tax Authorities, Ministries, the Data Protection Authority) to comply with legal or regulatory obligations.
Other third parties with the customer’s consent.
Servers within the European Union, under secure conditions and confidentiality obligations. For customers outside the EU, data may be transferred to fulfill contracts or payments, taking all required safeguards.
7. Technical and Organizational Measures
PLEXI enforces strict technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure, or destruction. Specifically:
Regular audits of data collection, storage, and processing procedures.
Controlled and limited access to data by authorized personnel under confidentiality agreements.
Data processing agreements with third-party contractors that meet legal standards.
Continuous protection of data confidentiality, integrity, and availability throughout its life cycle.
8. Data Retention Period
Retention periods are determined by specific criteria:
As required by law — data is retained for the period mandated by relevant legal provisions.
Contract-based data — retained for as long as necessary to perform the contract and pursue legal claims.
Tax-related data — retained for up to 10 years after account deletion, as required by law.
Customer data — retained for 20 years after the end of the contractual relationship, to account for potential legal claims.
Video surveillance data — retained for 7 days, after which it is automatically deleted.
If an incident occurs, relevant footage may be stored:
Up to 1 month if legal investigation is required.
Up to 3 months if the incident involves a third party.
9. Customer Rights Regarding Personal Data
Customers have the following rights regarding their data:
Right of access — to obtain a copy of their personal data.
Right to rectification — to request immediate correction of inaccurate data.
Right to erasure — to request deletion of personal data.
Right to withdraw consent — at any time, stopping PLEXI from further use.
Right to restriction of processing — to limit how data are used.
Right to data portability — to request transfer of data to another entity.
If a breach of personal data leads to material or non-material damage, the customer has the right to lodge a complaint with the Hellenic Data Protection Authority.
10. Provisions for Children
Services provided by PLEXI, both on-site and online, are intended for a general audience and not directed toward children. PLEXI does not knowingly collect data from persons under 16 years of age.
Individuals under 16 must not provide personal information (name, address, phone, email, etc.) without prior guardian consent or authorization.
11. Updates and Changes
PLEXI may periodically amend this Privacy Policy to comply with evolving legislation. Customers are encouraged to review this page frequently for updates.
In the event of significant changes expanding PLEXI’s rights to use already collected personal data, customers will be informed and given the option to consent to the future use of their data.
Πολιτική Προστασίας Προσωπικών Δεδομένων & Σύστημα Βιντεοεπιτήρησης
1. Εισαγωγή
Λαμβάνοντας υπόψη τον Ν. 4624/2019, την Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα και τα μέτρα εφαρμογής του Κανονισμού (ΕΕ) 2016/679 του Ευρωπαϊκού Κοινοβουλίου και του Συμβουλίου της 27ης Απριλίου 2016 σχετικά με την προστασία των φυσικών προσώπων έναντι της επεξεργασίας δεδομένων προσωπικού χαρακτήρα, η «PLEXI» δηλώνει, μέσω της παρούσας Πολιτικής, ότι σέβεται την ιδιωτικότητα των πελατών της και δεσμεύεται να προστατεύει τα προσωπικά δεδομένα που συλλέγει κατά την παροχή των υπηρεσιών της στα ενοικιαζόμενα δωμάτια και στον ιστότοπό της.
Παρακάτω περιγράφονται τα είδη πληροφοριών που ενδέχεται να συλλέγονται κατά την επίσκεψη πελάτη στις εγκαταστάσεις ή στην ιστοσελίδα, καθώς και ο τρόπος χρήσης και διαχείρισής τους.
Όταν οι πελάτες παρέχουν οικειοθελώς προσωπικά στοιχεία (όπως όνομα, διεύθυνση ή email), η «PLEXI» τα χειρίζεται με απόλυτη εμπιστευτικότητα. Με την επιφύλαξη των ειδικότερων όρων της παρούσας πολιτικής, τα δεδομένα αυτά δεν εκμισθώνονται, δεν πωλούνται, δεν δημοσιοποιούνται και δεν κοινοποιούνται σε τρίτους χωρίς νόμιμη βάση.
2. Η «PLEXI» ως Υπεύθυνος Επεξεργασίας
Η «PLEXI», ως υπεύθυνος επεξεργασίας προσωπικών δεδομένων, είναι ανώνυμη εταιρεία με την επωνυμία «PLEXI SPACE ROOMS SINGLE-MEMBER S.A.» και έδρα την Αθήνα (Ιερά Οδός 39).
Στο πλαίσιο της δραστηριότητάς της, συλλέγει και επεξεργάζεται προσωπικά δεδομένα συνεργατών, προμηθευτών, εργαζομένων και πελατών σύμφωνα με το ισχύον νομικό πλαίσιο και ενεργεί ως υπεύθυνος επεξεργασίας κατά το άρθρο 4(7) του GDPR.
Email: info@plexispace.com
Τηλέφωνο: +30 210 34 17 700
3. Συλλογή και Προστασία Προσωπικών Δεδομένων
Η «PLEXI» συλλέγει και επεξεργάζεται ενδεικτικά τα εξής δεδομένα:
Στοιχεία ταυτοποίησης πελατών (ονοματεπώνυμο, τηλέφωνο, email, ΑΦΜ, διεύθυνση, επάγγελμα, φωτογραφία, οικογενειακή κατάσταση κ.λπ.)
Αντίγραφα εγγράφων ταυτοποίησης (ταυτότητα ή διαβατήριο)
Οικονομικά στοιχεία για συναλλαγές (τραπεζικός λογαριασμός, κάρτα κ.λπ.), σύμφωνα με το πρότυπο ασφαλείας PCI DSS
Τεχνικά δεδομένα (IP, ιστορικό περιήγησης, πρόγραμμα περιήγησης, λειτουργικό σύστημα, ώρες πρόσβασης κ.λπ.)
Δεδομένα συσκευών και τοποθεσίας (σε περίπτωση χρήσης κινητού)
Ενδέχεται επίσης να συλλέγονται δεδομένα από άτομα που δεν είναι πελάτες, π.χ. σε εκδηλώσεις (γάμοι, βαπτίσεις, εταιρικές συγκεντρώσεις).
Νομική βάση επεξεργασίας:
Εκτέλεση σύμβασης (άρθρο 6(1)(β) GDPR)
Έννομο συμφέρον (άρθρο 6(1)(στ) GDPR)
4. Σκοπός Επεξεργασίας
Τα δεδομένα χρησιμοποιούνται για:
Διαχείριση κρατήσεων και παροχή υπηρεσιών
Εξατομίκευση υπηρεσιών
Μελλοντική εξυπηρέτηση
Επικοινωνία και αποστολή ενημερώσεων/προσφορών (με δυνατότητα διαγραφής μέσω email)
Επαλήθευση στοιχείων
Συμμόρφωση με νομικές υποχρεώσεις
Προστασία εννόμων συμφερόντων μέσω συστήματος CCTV
Η βιντεοεπιτήρηση περιορίζεται σε εισόδους, εξόδους, υποδοχή, ταμεία και τεχνικούς χώρους.
Δεν χρησιμοποιείται για αξιολόγηση εργαζομένων ούτε εις βάρος πελατών χωρίς ενημέρωση.
5. Τρόποι Συλλογής Δεδομένων
Τα δεδομένα συλλέγονται μέσω:
Φυσικής παρουσίας
Τηλεφώνου
Ιστοσελίδας
6. Χρήση και Κοινοποίηση Δεδομένων
Η πρόσβαση περιορίζεται σε εξουσιοδοτημένο προσωπικό και συνεργάτες.
Τα δεδομένα ενδέχεται να κοινοποιούνται σε:
Εργαζομένους και συνεργάτες (κρατήσεις, πληρωμές, IT κ.λπ.)
Δημόσιες αρχές (φορολογικές, υπουργεία κ.λπ.)
Τρίτους με συγκατάθεση του πελάτη
Αποθηκεύονται σε διακομιστές εντός ΕΕ με ασφάλεια.
Για πελάτες εκτός ΕΕ, ενδέχεται να υπάρξει διαβίβαση με τις απαιτούμενες εγγυήσεις.
7. Τεχνικά και Οργανωτικά Μέτρα
Η «PLEXI» εφαρμόζει μέτρα όπως:
Τακτικοί έλεγχοι διαδικασιών
Περιορισμένη πρόσβαση σε εξουσιοδοτημένο προσωπικό
Συμβάσεις με τρίτους για προστασία δεδομένων
Διασφάλιση εμπιστευτικότητας, ακεραιότητας και διαθεσιμότητας
8. Χρόνος Τήρησης Δεδομένων
Σύμφωνα με τον νόμο: όσο απαιτείται
Συμβάσεις: όσο διαρκεί η σχέση και για νομικές αξιώσεις
Φορολογικά: έως 10 έτη
Δεδομένα πελατών: έως 20 έτη
CCTV: 7 ημέρες
Σε περίπτωση περιστατικού:
έως 1 μήνα για έρευνα
έως 3 μήνες αν εμπλέκεται τρίτος
9. Δικαιώματα Πελατών
Οι πελάτες έχουν δικαίωμα:
Πρόσβασης
Διόρθωσης
Διαγραφής
Ανάκλησης συγκατάθεσης
Περιορισμού επεξεργασίας
Φορητότητας δεδομένων
Μπορούν επίσης να υποβάλουν καταγγελία στην Αρχή Προστασίας Δεδομένων.
10. Ανηλίκοι
Οι υπηρεσίες δεν απευθύνονται σε παιδιά κάτω των 16 ετών.
Ανήλικοι δεν πρέπει να παρέχουν στοιχεία χωρίς γονική συναίνεση.
11. Τροποποιήσεις Πολιτικής
Η «PLEXI» μπορεί να τροποποιεί την πολιτική για συμμόρφωση με τη νομοθεσία.
Σε σημαντικές αλλαγές, οι πελάτες ενημερώνονται και καλούνται να συναινέσουν εκ νέου.
