1. What is personal data?
“Personal Data” is any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one whose identity can be verified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural or social identity of the data subject; Indicative personal data may include your full name, your surname, your name, your address, your email address, location data, IP address, cookie identifiers, your tax identification number, your registration number (for legal entities) and so on (hereinafter referred to as Personal Data or Data for short).
2. Who is the controller?
The private company “Car and Travel ” (GEMI no 145581127000) whose registered office is located at 76 Ikarou Street, Heraklion, Crete, Postal Code 71307, with VAT no. 800949948, tel: +30 6932430390, email: info@carandtravel.gr (hereinafter the “Company”) is the controller of your personal data. The Company, in the course of its business activities, processes personal data relating to natural persons for whom data can be identified (such as, but not limited to, the Company’s customers, suppliers, shareholders and investors, as well as ordinary users of the website), in accordance with the applicable national legislation and European Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation), as in force. If you have any questions regarding this Policy, you may contact the Company and the Data Protection Officer at the following contact details: Email: info@carandtravel.gr Address: 76 Ikarou Street, Heraklion, Crete, Greece, Postal Code 71307 Tel.: +30 6932430390
3. What is the processing of personal data?
Processing means any operation or set of operations which is performed, whether or not by automated means, on personal data or on sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction (GDPR, art. 2).
4. Τhe data we collect from you:
During the online booking we collect and keep only the necessary data of our Customers for the completion of the transaction (name, address details, bank account details where payment via Paypal is selected as a payment method, etc.) and your contact details (phone number, email address, etc.) in order to contact you for issues related to the provision of our services. We only collect as much information as you provide to us. For online payment via Paypal it may be necessary to provide more customer information on the provider’s website. For the terms and conditions in accordance to which your personal data by this provider is kept, please consult the privacy policy of the provider. The data collected through our website may also be combined with data provided in other cases, for example, when you call our call centres, when you send an email, when you enter into a lease agreement. The personal data provided to our Company in these cases may be incorporated into existing databases and stored in order to simplify your data management systems.
5. Data collected by automated means:
When you use our website, your device automatically provides us with data so that we can serve and tailor our response to you. The type of information we collect by automated means generally includes technical information about your device, such as your IP address or other device identifier, the type of device you are using, and the version of the operating system. The data we collect may also include usage information and statistics about your interaction with the Site. It may also include information about the URLs of the web pages you visited, referring/exit pages, page views, time spent on a page, number of clicks, platform type, location data (if you have enabled access to your location) and other information about how you used the website. This information is collected using cookies and other similar tracking technologies. We should inform you that for the administration of our website we use Google Analytics, a web analytics service operated by Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. This information is collected using cookies. This data is necessary for us to optimise our services to you and for online advertising purposes. With each visit to our website, such personal data, including your IP address, will be transmitted to Google. This personal data is stored by Google for its own purposes.Google may transfer similar personal data via the technical process to third parties, but also to Google LLC, in the United States of America. For further details you can visit the following websites: https://policies.google.com/privacy?hl=en https://policies.google.com/privacy?hl=en https://marketingplatform.google.com/about/analytics
6. What data we do not collect:
We do not collect or gain access in any way to special categories of (“sensitive”) personal data or data relating to criminal convictions and offences of our customers. The customer has a duty to refrain from providing such data, which relates to his/her person or to third party data subjects. In the event that a client makes a relevant provision of such data to CRETARENT, such data will be deleted as soon as it comes to our attention. Our Company shall not be liable to clients or third parties for any provision and/or processing of sensitive data, due to the acts or omissions of clients in breach of the above obligation.
7. For what purpose do we collect your personal data?
We collect, process and store your personal data, which you provide us with your entry to the website, your transaction in the online store, by telephone, or by any other means a) for the purposes and in the context of the car rental contract concluded between us, the provision of our services and the fulfilment of our contractual obligations, b) to comply with our legal obligation under national or EU law; c) to exercise any of our legal rights, defend our interests and pursue any legal claim against you; d) to the extent necessary to prevent or prosecute abuse or other unlawful conduct on our website; e) to promote, advertise and inform users about our products and services; f) to promote, advertise and inform users about our products and services.
8. Whom do we transfer your personal data to?
When transferring your personal data we seek to ensure the highest possible level of security. Your data is transferred to our Company, which accesses it to its employees and partners, who are responsible for processing your data on our behalf, as processors. Our partners are natural or legal persons who provide services to us to facilitate the execution of the sales contract between us and the fulfilment of our contractual obligations. Such persons may be: – A partner provider of electronic invoicing services based in Greece. – Partner banks and payment service providers based in Member States of the European Union. During the payment process, we do not record or store payment information during that transaction, such as credit card numbers or other banking or other information. You provide this information directly to the respective payment service provider exclusively. – Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4, Ireland, Fax: +353 (1) 436 1001. Our partners are only provided with the personal data of our Clients necessary for the execution of the rental contract. The recipients of your personal data may be located in a country other than the country where the collection took place, the legislation in which may not provide the same level of protection. Although we seek to enter into the necessary contracts and agreements to ensure the security of your personal data, the Company is not responsible for the processing of your personal data by its partners and which is in accordance with their own privacy policies. By using our website, you give our Company permission to transfer your data to third parties who provide services for us.
9. How long do we keep your personal data?
We retain your personal data for as long as necessary to fulfil the purposes of this privacy policy (unless a different retention period is required by applicable law). At the end of this period your data will be completely deleted.
10. What are your rights?
α) You have the right to be informed about the collection and use of your personal data, b) You have the right to obtain confirmation as to whether or not your personal data is being processed by the Company and, if so, you have the right to access the personal data in a short, intelligible, transparent and easily accessible form, c) You may request the correction of inaccurate or incomplete personal data concerning you, d) You have the right to request the erasure of personal data concerning you without undue delay, under the conditions provided by law, e) You have the right to ask us to restrict our processing activities to specific purposes only, under the conditions set out by law, f) You have the right to receive personal data concerning you in a structured, commonly used and machine-readable format, and the right to transmit such data to another controller, g) You have the right not to have decisions about your personal data taken solely on the basis of automated processing, including profiling.
11. How can you perform your rights?
To exercise or be further informed about your rights and this privacy policy you can contact our company at the email address: info@carandtravel.gr or by phone +30 6932430390. To confirm your identity in order to maintain the confidentiality of your information we may ask you to confirm certain details of your identity or, if you have authorised a third party to exercise your rights on your behalf, ask you to produce their legal documents. If you exercise any of your rights and they are not satisfied, you have the right to lodge a complaint with the Personal Data Protection Authority (www.dpa.gr): 1-3 Kifissias Street, P.K. 115 23, Athens, Greece, Phone: +30-210 6475600, Fax: +30-210 6475628, Email: complaints@dpa.gr.
12. Applicable Law
In any case, your personal data is managed and maintained in accordance with the provisions of Law 4624/2019 on the protection of personal data in compliance with Regulation 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and the repeal of Directive 95/46/EC (General Data Protection Regulation), as in force, as well as any other applicable legislation.