Privacy Notice

Last Updated: May 24th, 2018

At Pap Corp S.A Hotels, we are committed to protecting and respecting your privacy. Please read this notice as it contains important information about how we use personal data that we collect from you or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including personal information about you (hereinafter, the “User”), in conjunction with your access to and use of our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate its understanding, and to freely and voluntarily determine whether they wish to provide their personal data, or those of third parties, to Pap Corp S.A Hotels.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,” “webapp,” “services,” “online services,” it refers to all pages and functions under https://papcorphotels.reserve-online.net/ unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this privacy statement. We may change this notice from time to time. You should check this notice frequently to ensure you are aware of the most recent version.

Identity

When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Pap Corp S.A Hotels.

Data Controller

Pap Corp S.A Hotels operates this booking system through a data processor, as explained below. For the purposes of the General Data Protection Regulation (“GDPR”) (EU) 2016/679, we are the Data Controller. There is a strict contractual framework between the data controller and the data processor for the protection of your personal information. We are:

Pap Corp S.A Hotels

, Thessaloniki
GR

Data Processor

WebHotelier operates this booking system on behalf of Pap Corp S.A Hotels and is committed to protecting the privacy of the users of this system. WebHotelier is:

WebHotelier Technologies Limited
Mnasiadou 9 (Demokritos Building, Office 16)
1065 Nicosia
Cyprus

For the purposes of the GDPR, where WebHotelier processes your personal data on behalf of Pap Corp S.A Hotels, WebHotelier is the the Data Processor. When this notice mentions “data processor,” “processor,” “WebHotelier,” it refers to WebHotelier Technologies Limited.

WebHotelier is a certified PCI-DSS Level 2 Service Provider audited monthly by Trustwave.

The User may contact WebHotelier's Data Protection Officer:

Data Protection Officer
dpo@webhotelier.net

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:

  • personal information about you which we ask you for (e.g. your name, address, and email address) when you make a booking from our booking engine;
  • financial details in order to process your booking when we require pre-payment;
  • details of transactions you carry out through our booking engine and details of the fulfilment of your orders.
  • our data processor may only collect and process personal data collected and/or processed on behalf of us in accordance with our instructions. WebHotelier cannot process it in any other way or for any other purpose.

We grant permission to our data processor:

  • to use your personal information for reserving rooms and/or other services for you at Pap Corp S.A Hotels;
  • to pass on your financial details to Pap Corp S.A Hotels and/or appropriate third party (for example, credit card company) for the purpose of confirming or paying for a booking;
  • to use your information for marketing purposes (where you explicitly agree to this); and
  • to pre-complete forms and other details on our website to make your next visit to our booking engine easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access certain information of the User’s profile from the corresponding social network, solely for internal administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent and undertake to provide the interested party -the data holder- with the information contained in this Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national identification number, data related to racial or ethnic origin, political opinions, religion, ideological or other beliefs, health, biometrics or genetic characteristics, criminal background, trade union membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of sixteen (16), and we request that they not provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the following purposes:

  • To manage the bookings made, including payment management (where applicable) and the management of the user’s requests and preferences.
  • To manage registration in loyalty or membership programs, as well as obtaining and redeeming points.
  • To manage the User’s contact requests with us through the channels provided to this end.
  • To manage the sending of personalised commercial communications from us, by electronic and/or conventional means, in cases in which the User expressly consents.
  • To manage the provision of the contracted accommodation service, as well as additional services.
  • To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy Notice unless a longer retention period is required or permitted by law or if the User requests their withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services or if you have a booking that has not yet been fulfilled)
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them)
  • Whether retention is advisable considering our legal position (such as, for statutes of limitations, litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s consent cannot be undertaken without said consent.

Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect the legality of the processing carried out previously.

To revoke such consent, the User may contact us through the appropriate channels.

By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of a legal obligation or for the execution of the existing contractual relationship between us and the User, the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:

  • to comply with applicable law, including laws outside your country of residence;
  • to comply with legal process;
  • to respond to requests from public and government authorities, including authorities outside your country of residence and to meet national security or law enforcement requirements;
  • to enforce our terms and conditions;
  • to protect our operations;
  • to protect the rights, privacy, safety or property of our own, you or others; and
  • to allow us to pursue available remedies or limit the damages that we may sustain.

We may use and disclose Other Data for any purpose, except where we are not allowed to under applicable law. In some instances, we may combine Other Data with Personal Data (such as combining your name with your location). If we do, we will treat the combined data as Personal Data as long as it is combined.

International transfers of personal data

We may transfer your personal information to our data processor(s) or/and sub-processor(s) based outside of the EEA for the purposes described in this notice. If we do this, your personal information will continue to be subject to one or more appropriate safeguards set out in the law. These might be the use of model contracts in a form approved by regulators, or having our suppliers sign up to an independent privacy scheme approved by regulators (like the US ‘ Privacy Shield’ scheme).

Our data is stored in the cloud using Amazon Web Services in N. Virginia, USA and in Frankfurt, Germany. If you are accessing any of our systems from outside the USA, you acknowledge that your personal information may be transferred to the USA, a jurisdiction which may have different privacy and data security protections from those of your own jurisdiction, to be processed and stored.

User's Responsibility

The User:

Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User is responsible for the truthfulness of all the data communicated and will keep the information updated, so that said data reflects their actual situation.

Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the third party’s authorisation to provide their data to us for the purposes indicated.

Will be responsible for false or inaccurate information provided through the Website and for damages, whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:

  • To obtain confirmation about whether or not personal data concerning the User are being processed by us.
  • To access their personal details.
  • To rectify any inaccurate or incomplete data.
  • To request the deletion of their personal data when, among other reasons, the data are no longer necessary for the purposes for which they were collected.
  • To confirm revocation of consent.
  • To obtain from us the limitation of data processing when any of the conditions provided in the data protection regulations are met.
  • To request the portability of your data.

Likewise, the user is informed that at any time he/she may file a complaint regarding the protection of their personal data before the competent Data Protection Authority.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in applicable regulations, and to this end adopting the measures of a technical and organisational nature required to guarantee the security of their data and prevent them from being altered, lost, processed or accessed illegally, depending on the state of the technology, the nature of the stored data and the risks to which they are exposed.

Privacy Policy GDPR (General Privacy Protection Data Regulation) Introduction

a. The Privacy Policy ( referred to as the "Policy") covers and concerns the collection, storage, processing and use of personal data conditions by PAP CORP A.E. ( referred to as "Papcorp") during the visit and use of the services and websites (sites) owned by it. Papcorp is the owner, creator and recipient of all the rights of their pages and services, as well as the Editor of the Data that may be declared by you in accordance with Greek law and the legislation on the protection of personal data.

b. This policy does not in any way cover the legal relationship between visitors / users of the pages and any other services not subject to control, and / or management, and / or ownership of Papcorp.

c. This Policy applies only to pages owned and operated by Papcorp and does not apply to information collected through any other web site or to practices of other companies that Papcorp does not control/manage.

d. The pages may include links to other sites not controlled by Papcorp but by third parties (natural or legal persons). Under no circumstances is Papcorp responsible for the terms and conditions for the protection of the Visitors '/ Users' Personal Data, which are adopted and applied by these operators.

e. Using the Papcorp-owned sites, you consent to the collection and processing of information as outlined in this Policy. You also acknowledge that Papcorp may periodically change, modify, add, remove or update this Policy in any way at its sole discretion without prior notice. Please always read the Policy before using our site so that you are aware of the current version of the Policy in the event of any modifications or updates. Last updated Policy: March 2018.

1.Private Use Guarantee

a.For your simple browsing of Papcorp (www.papcorp.com & www. paphotels.gr), no personal information is collected.

b. Personal information is information that identifies you. In addition to any other information you may choose and provide to us, this data may include: your personal information such as your name and surname, date of birth, methods of communication, details of credit cards, including the three-digit security code that appears on the back of your credit card, arrival and departure date, room preferences, and eating habits / preferences.

c. Papcorp does not collect your personal data unless you have provided it explicitly for a specific purpose (e.g when booking a room, subscribing to receive Newsletter via email, participating in surveys or competitions) and if you have given your consent to their use.

d. We store and use your personal data only if you give your consent for this and only to the extent necessary, depending on the purpose of the processing and the time required in each case.
We use your personal information to provide the services you request from Papcorp, such as to process: (a) bookings, (b) purchases of package holidays or other transactions.

We also use personal information to provide you with the necessary information about planning sessions or other events to provide their specific account information for administrative purposes.

In addition, we may use the information: (a) to improve the services of our group's hotels so as to provide you with the expected level of hospitality. We also use the details to send you newsletters, to include you in promotions for new bundles of offers and to conduct market research, as well as to participate in contests via email, telephone or mail. If you apply for employment at the Papcorp Group, we use the personal information you provide to process your job request.

2. Sensitive personal data

The term "sensitive personal data" refers to relevant information with racial or ethnic origin, political opinions, religion or other beliefs, health, criminal records or membership of unions. We do not collect generally sensitive personal data unless it is voluntarily offered by you. We may use such data provided by you solely to provide better service to you and meet your particular needs.

3.Storing your data

The data provided by you will be retained / stored by us only for as long as it is required to fulfill the purpose for which you have communicated your data to us and in compliance with the applicable laws.

If you have given us your explicit consent to the use of your personal data for advertising purposes (subscription to the Newsletter), we will use your data for this purpose until you withdraw your consent. You can revoke your consent at any time with effect for the future.

4. Non-disclosure of information

a. Papcorp complies strictly with the Greek Law on the Record of Personal Data. Any information that may be claimed and collected is not disclosed to third parties and is in no way publicized or exploited by Papcorp.

b. Papcorp commits not to sell, rent or in any way publish or / and disclose the personal data of visitors / users to any third party.

c. Papcorp may distribute your personal data to third parties only in the following cases.

-Provided you have your explicit consent to the disclosure of your personal data,

- If the transfer of personal data is required by a provision of the Law, a court order or a prosecutor's order and only to the competent authorities.

-In Business Transactions: Since we are developing our business, like in cases where we sell, buy, restructure or reorganize our businesses or assets. In the event of a merger, consolidation, sale, liquidation or transfer of our assets, Paphopr may, in its sole and absolute discretion, transfer, sell or define the range of information it has collected, including without limitation non-personal information and personal information in one or more businesses.

d. Papcorp does not sell, share, disclose, transmit or distribute in any way your personal data to third parties, unless expressly permitted under this Policy. It is possible that personal data may occasionally be transmitted to third parties acting on Papcorp or on its behalf or in connection with Papcorp's activity for further processing in line with the purpose for which data collection was originally intended (eg companies car rental). These third parties have been contractually bound by Papcorp to use personal data only for the above reasons and will not forward personal information to third parties and will not disclose it to third parties unless required by law .

e. In the event that the disclosure of personal data to a third party is necessary for any reason, Papcorp will make every effort, whenever possible, to ensure that the processing of the data is carried out in accordance with the purposes and within the limits which had taken place from the outset.

5. Right of access

a. If access to some of the services and content of the Papcorp web sites requires users to register their personal data, they have the right to be assured that in any case their personal data is always up to date . Furthermore, users have the legitimate right to ask for their correction or deletion. In addition, they may at any time ask to stop contact and communication with them.

b. If you wish to contact us to be informed about the use of your personal information, please contact Pap corp SA, Tsimiski & Salaminos 9, 54626 Thessaloniki or send us an email at paphotels@papcorp.gr or use the contact form you will find on the site. When communicating with us, please provide the name of the electronic page where you provided your data, as well as which specific information you would like to be corrected, modified or deleted. Your requests will be treated promptly and correctly. Requests for deletion of data are subject to all relevant legal and moral provisions regarding reporting, holding or storage obligations imposed on Pap corp.

c. It is clarified that in accordance with applicable laws and regulations, you must send with your request proof of your identity and receive a reply within thirty (30) days of receipt of the request

6. Security and Confidentiality

a.Access to visitor / user contact information is limited to employees or service providers who reasonably believe they need to know this information to provide products or services to visitors / users or to perform their work.

b. In order to ensure the security and confidentiality of personal data collected by Papcorp during the electronic connection to the Web site, Papcorp uses data networks protected, inter alia, by industrial firewalls and user codes. As regards the management of personal data, measures have been reasonably designed to protect information from loss, misuse, unauthorized access, disclosure, distortion or destruction (only authorized employees have the right to access personal information and can do so only for authorized business functions). Although we cannot guarantee the exclusion of loss, misuse or distortion of the data, we try to avoid unfortunate circumstances.

c. To protect your privacy, we inform you not to include sensitive personal data in any emails you send us. Please do not send us your credit card numbers or any sensitive personal information via e-mail.

7. Anonymous Data and "Cookies"

a. The pages can use cookies for the proper operation of their services and their pages. Cookies are small pieces of information stored on a computer in order to identify the corresponding browser during your browsing on websites. Cookies can be used to store items, such as logins and user preferences. Any website may send a cookie to your browser, provided that the browser settings allow it. A browser allows a website to access only cookies sent to you, and not cookies from other sites. The visitor / user may configure his / her browser in such a way that he or he warns the user to use cookies on specific page services or to prevent the acceptance of the use of cookies under any circumstances. If the visitor / user does not wish to use cookies to identify them, they may not have access to these services.

b. Cookies used by us

The cookies we use do not store personal data or personal information that may lead to identification of the person to whom they are concerned and which have been otherwise collected. If you do not wish to collect information through cookies, please configure your internet browser to delete all existing cookies from your computer's hard disk, block all cookies in the future, and receive a warning before saving a cookie.

Google Analytics

This site uses Google Analytics, a web analytics service from Google Inc. ("Google"). Google Analytics uses a special "cookie" format, that is, a text file stored on your computer and allows you to analyze how your website is used by you. The use of this site generated by the cookie is typically passed to a Google server in the U.S. and are stored there. We would like to point out that Google Analytics has expanded to this site to include the "gat._anonymizeIp" Code and to ensure IP addressing (IP Masking) is anonymous. Because of the anonymity of IPs on this site, Google has shortened your IP address within the territory of the EU and the Member States of the European Economic Community. Only in exceptional cases is the full IP address transmitted to a Google server in the U.S. and there is its conciliation.

Google uses this information on our behalf to analyze your use of this site in order to compile reports on site activities and provide the site administrator with additional services related to its use and use Internet. The IP address that is transmitted to Google Analytics by your browser is not combined with other data from Google. You can prevent cookies from being saved by selecting the appropriate setting in your browser software (see Section 5 (c) above). In addition, you may prohibit Google from logging out of and relating to the use of the site by the cookie (including your IP address) and processing this data by uploading and installing the browser plug-in is available at

https://tools.google.com/dlpage/gaoptout?hl=en.
You can find more information about terms of use and privacy at

http://www.google.com/analytics/terms/us.html, http://www.google.com/analytics/learn/ privacy.html? hl = http://www.google.com/intl/en/policies/privacy/

 

8. Personal Information and Children

a. Most of the information provided by Papcorp websites is addressed to people aged 18 and over. If, however, minor users visit pages with inappropriate / abusive / immoral material that can not be continuously checked, Papcorp will not be held responsible.

b. Papcorp will not collect, use, or disclose personal information from minors under the age of 18 without having previously obtained the consent of the parent or guardian. We undertake to provide the guardian with: (i) notice about the specific type of personal data collected by the minor; and (ii) the possibility of opposing further collection, use or storage of such information.

c. Papcorp does not knowingly collect personal information from minors under the age of 18. If it finds that it has collected any personal information from a minor under 18 without a verifiable parental consent, it will delete the information from its database as soon as possible.

d. Papcorp complies with child protection legislation and any relevant legal provision.

9. Links to other websites

The stated Policy only applies to Papcorp's websites, excluding websites belonging to any third party. Papcorp can provide links to other websites that may interest our guests. Our concern is to ensure that they are also high-quality websites. However, due to the nature of the World Wide Web, Papcorp cannot guarantee the level of personal data protection of any web site that is associated with this site, nor is it responsible for the content of any other than this web site and this Policy does not apply to any site linked to this and not owned by Papcorp.

10. Applicable law

a. The management and protection of the personal data of the visitor / user of the services of the pages of Papcorp is subject to the terms of this policy and the relevant provisions of the Greek legislation (Law 2472/1997 with the amendments to Law 3625/2007 and Law 3471 / 2006) on the protection of personal data, as amended and currently in force and supplemented by the decisions of the Chairman of the Personal Data Protection Commission and other relevant legislative acts in this context, any possibility The relevant regulation will be an amendment to the present scope.

b. In any case, Papcorp reserves the right to modify the terms of this privacy policy within the existing or potentially new legal framework.

c. The use of the services of the pages implies the full and unconditional acceptance of the terms hereof.

d. In the event that a visitor / user does not agree with the terms of protection of personal data provided herein, he / she shall not use the services of the pages.

e. Any provision of these terms found to be in breach of this legal framework or to become invalid shall be automatically void and shall be withdrawn from the present, without in any way undermining the validity of the other terms.

f. In order to resolve any dispute arising out of the validity and application of this Policy, applicable law shall be governed by Greek law and the courts of Thessaloniki shall be competent in the area.