Privacy Policy

Last updated: May 2018

We recognize the importance of protecting your privacy and your rights with regards to data protection. The Internet is a very powerful medium when it comes to transmitting personal information; for that reason, we undertake the serious task of respecting the current laws regarding the protection of personal data and the security of the same, with the aim of guaranteeing secure, controlled and confidential navigation for its users and customers when visiting and/or using the Website or then purchase our services.

This Privacy Policy describes how we collect, use, process, and disclose your personal data in conjunction with your access to and use of our Website and services.

It also informs you how you can exercise Your Rights (including the right to object to some of the data handling we carry out). More information about your rights and how you can exercise them is set out in the section below.

1. Who is the controller of your personal data?

When this policy mentions “Company”, “we,” “us,” or “our”, it refers to:

Aegean Outdoors IKE, a Greek company listed in the Hellenic business register under No.144467201000, holding the license number 0259E70000659901 by the Greek Ministry of Tourism and with registered office at Douridos 7, Athens – Greece, which is responsible for the processing of Users’ and/or Customers’ personal data under this Privacy Policy (hereinafter, referred to as the “Company”, “we”, “us”, “our”).

2. What categories of your data do we collect and use?

When you visit the Website or then purchase our services, we collect the categories of personal data as follows:

2.1. Personal data provided by you
  • The personal data that you share with us when you register for an account, subscribe to newsletters and which you provide to us when using our services, including the information entered into our booking platform and included in your comments, reviews or messages sent via telephone to our Operations Team or through the Live Chat.
  • Special categories of personal data (for example, information concerning your health that you provide us in the course of making a booking by filling in the boxes “Physical condition, Health problems, Any special requests (dietary, allergies, particular interests…)” or by other means, such as via telephone to our Operations Team or through the Live Chat or at any moment when making a booking). We will use the special categories of personal data only as strictly necessary to fulfill your request.

The provision of the above personal data, where requested, is necessary for the adequate performance of the contract between you and us and to allow us to comply with our legal obligations. Without it, we may not be able to provide you with all the requested services.

It is important that all the personal data you give us when you register as a User or otherwise when you use the Website is correct and accurate. This includes, by way of example only, ensuring that we have your correct contact (including email) details at all times.

If you plan to submit someone else’s personal data to us, for instance when booking on their behalf, you should only provide us with that third party’s details with their consent and after they have been given access to this Privacy Policy.

Please note that we may collect and use information of children only as provided by their parent or guardian or with their consent. If we become aware that we have processed information of a child without the valid consent of a parent or guardian, we reserve the right to delete it.

2.2. Personal data collected automatically from our Website and from third parties
  • Information about your visits to and use of the Website, such as information about the device and browser you are using, your IP address or domain names of the computers connected to the Websites, uniform resource identifiers for requests made, the time of request, the method used to submit the request to the server, the size of the archive obtained as a response, the numerical code indicating the status of the response given by the server (correct, error, etc.) and other parameters relative to the operating system and the computer environment used, the date and time that you visited, the duration of your visit, the referral source and website navigation paths of your visit and your interactions on the Website including the Services and offers you are interested in. Please note that we may associate this information with your account.

Please see the cookies section of this Privacy Policy for further information on the purposes for which we collect and use this information.

  • To the extent permitted by the applicable law wherein we receive additional information about you, such as fraud detection information and warnings from third party service providers and/or partners for our fraud prevention activities.

3. Why do we collect your data?

In general terms, we use your personal data to provide you with the services you request, process payment, provide customer services, send you marketing and promotional communications, notify you about important changes to our Website and to deliver our content and ads which we think may be of interest to you. More specifically:

Why? On which legal basis?
A. To create and maintain the contractual relation established for the provision of the Service requested by you in all its phases and by way of any possible integration and modification (e.g. facilitating your bookings and taking payments; responding to your questions and concerns; administering your account).

B. For sending you information via email, phone or SMS relative to the established contractual relationship, including any communication relating to modifications thereof.

To fulfill a contract, or take steps linked to a contract
C. To meet the legal, regulatory and compliance requirements and to respond to requests by government or law enforcement authorities conducting an investigation. To comply with the law
D. To carry out anonymous, aggregative statistical analyses so that we can see how our Website, products and services are being used and how our business is performing. To pursue our legitimate interest (i.e. improving our Website, its features and our products and services)
E. To send you (in cases permitted by law excepting where you did not object) advertising material via email or, where permitted by the law, other equivalent electronic communication regarding products and services similar to those already purchased by you and offered on our Website. On some occasions, we may send you a personalised and tailored version of the aforementioned advertisement materials. Soft Opt-in/To pursue our legitimate interest (i.e. marketing)
F. Without prejudice to the provisions of the preceding paragraph E, and only with your consent, to send you via email, phone, mail, SMS or MMS the best deals, offers and newsletters about our services. Where you give your consent (by ticking the appropriate check box)
G. To keep our Website and systems secure and to prevent and detect fraud, security incidents and other crime. To pursue our legitimate interest (i.e. ensuring the security of our Website)
H. To verify compliance with our terms and conditions and for the establishment, exercise or defense of legal claims. To pursue our legitimate interest (i.e. compliance with our terms and conditions, protection of our rights in the event of any dispute or claim)
I. To tailor and personalise online marketing notifications and advertising for you based on the information on your use of our Website, products and services and other sites collected through cookies (please see the Cookies section of this Privacy Policy for further information) Where you give your consent (i.e. through the cookie banner or by your browser’s settings)

4. Who sees, receives and uses your data and where?

4.1. Categories of recipients of your data

We share your personal data, for the purposes described in this privacy policy, to the following categories of recipients:

  • Our authorized employees and/or collaborators that assist and advise us on administration, products, legal affairs, Operations Team, and information systems, as well as those in charge of maintaining our network and hardware/software equipment;
  • Airlines, hotels, car hire companies, insurance companies, tour operators as well as those other parties to which it is necessary to disclose your personal data in order to provide you with the requested services that will be operating as autonomous data controllers. Please note that airline companies are required, in accordance with new regulations introduced in the US and other countries, to allow customs and border authorities to have access to flight passenger data. For that reason, in certain situations, we may communicate data collected on passengers included in the reservation to the competent authorities of the countries included in the Customer’s travel itinerary if required by the local law.
  • Our third-party service providers, which process your personal data on our behalf and under our instructions for the purposes described hereinabove acting as data processors, such as those providing us with IT and hosting services call centre and customer support, analytics and administration services etc.
  • Payment providers and financial institutions (e.g. for chargeback, fraud detection and prevention purposes) acting as autonomous data controllers.
  • Competent authorities when we are required to do so by the current law.
  • Competent authorities and Law and enforcement third parties when this is necessary so that we can enforce our terms of use and protect and defend our rights or property or the rights or property of any third party.
  • Third parties that receive the data (e.g. business consultants, professionals for delivering due diligence services or assess value and capabilities of the business) when it is necessary in connection with any sale of our business or its assets (in which case your details will be disclosed to our advisers and any prospective purchaser’s advisers and will be passed to the new owners.

5. How long do we retain your data?

We retain your personal data for as long as is required to achieve the purposes and fulfill the activities as set out in this Privacy Policy, otherwise communicated to you or for as long as is permitted by applicable law.

What are your data protection rights and how can you exercise them?

You can exercise the rights provided by the Regulation EU 2016/679 (Articles 15-22), including the right to:

Name of the right Content
Right of access To receive confirmation of the existence of your personal data, access its content and obtain a copy.
Right of rectification To update, rectify and/or correct your personal data.
Right to erasure/right to be forgotten and right to restriction To request the erasure of your data or restriction of your data which has been processed in violation of the law, including whose storage is not necessary in relation to the purposes for which the data was collected or otherwise processed; where we have made your personal data public, you have also the right to request the erasure of your personal data and to take reasonable steps, including technical measures, to inform other data controllers which are processing the personal data that you have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.
Right to data portability To receive a copy of your personal data you provided to us for a contract or with your consent in a structured, commonly used and machine-readable format (e.g. data relating to your purchases) and to ask us to transfer that personal data to another data controller.
Right to withdraw your consent Wherever we rely on your consent (see p. 3 – F, G and I), you will always be able to withdraw that consent.
Right to object, at any time You have the right to object at any time to the processing of your personal data in some circumstances (in particular, where we don’t have to process the data to meet a contractual or other legal requirement (see p. 3-D, G, H), or where we are using your data for direct marketing (p. 3-E).

You can exercise the above rights at any time by:

  • Contacting us via email at info@aegeanoutdoors.com
  • As for direct marketing, please note that you can also object at any time by clicking the unsubscribe link which we provide in each communication sent to you
  • As for online targeted ads and the withdrawal of your consent please refer to our Cookie section of this Privacy Policy

Your rights in relation to your personal data might be limited in some situations. For example, if fulfilling your request would reveal personal data about another person or if we have a legal requirement or a compelling legitimate ground we may continue to process your personal data which you have asked us to delete.

You also may have the right to make a complaint if you feel your personal information has been mishandled. We encourage you to come to us in the first instance but, to the extent that this right applies to you, you are entitled to complain directly to the relevant Data Protection Supervisory Authority.

7. Information about cookies

Cookies are small files which are stored on your computer, they hold a modest amount of data specific to you and allows a server to deliver a page tailored to you on your computer, hard drive, smartphone or tablet (hereinafter referred to as, “Device”). Later on, if you return to our Website, it can read and recognise the cookies. Primarily, they are used to operate or improve the way our Website works as well as to provide business and marketing information to the Website owner.

In accordance with the notice of cookie usage appearing on our Website’s homepage and our Cookie Policy you agree that, when browsing our Website, you consent to the use of cookies described herein, except to the extent that you have modified your browser settings to disable their use. This includes but is not limited to browsing our Website to complete any of the following actions: closing the cookie notice on the Homepage, scrolling through the Website, clicking on any element of the Website, etc.

What follows is a description of the type of cookies used in the website:

7.1 Types of cookies according to the managing entity

Depending on what entity manages the computer or domain from which the cookies are sent and processed, there exist the following types of cookies:

  • First party cookies: these are sent to your Device from a computer or domain managed by us and from which the service you requested is provided.
  • Third party cookies: these are sent to your Device from a computer or domain that is not managed by us, but by a separate entity that processes data obtained through cookies.
7.2. Types of cookies according to the length of time you stay connected:

Depending on the amount of time you remain active on your Device, these are the following types of cookies:

  • Session cookies: these are designed to receive and store data while you access the Website. These cookies do not remain stored on your Device when you exit the session or browser.
  • Persistent cookies: these types of cookies remain stored on your Device and can be accessed and processed after you exit the Website as well as when you navigate on it for a pre-determined period of time. The cookie remains on the hard drive until it reaches its expiration date. The maximum time we use persistent cookies on our Website is 2 years. At this point the browser would purge the cookie from the hard drive.
7.3. Types of cookies according to their purpose

Cookies can be grouped as follows:

  • a) Technical cookies: these cookies are strictly necessary for the operation of our Website and are essential for browsing and allow the use of various features. Without them, you cannot use the search function or book other available services on our Website.
  • b) Personalisation cookies: these are used to make navigating our Website easier, as well as to remember your selections and offer more personalised services. In some cases, we may allow advertisers or other third parties to place cookies on our Website to provide personalised content and services. In any case, your use of our Website serves as your acceptance of the use of this type of cookie. If cookies are blocked, we cannot guarantee the functioning of such services.
  • c) Analytical cookies for statistical purposes and measuring traffic: these cookies gather information about your use of our Website, the pages you visit and any errors that may occur during navigation. We also use these cookies to recognise the place of origin for visits to our Website. These cookies do not gather information that may personally identify you. All information is collected in an anonymous manner and is used to improve the functioning of our Website through statistical information. Therefore, these cookies do not contain personal data. In some cases, some of these cookies are managed on our behalf by third parties, but may not be used by them for purposes other than those mentioned above.
  • d) Advertising and re-marketing cookies: these cookies are used to gather information so that ads are more interesting to you, as well as to display other advertising campaigns along with advertisements on the Website or on those of third parties. Most of these cookies are “third party cookies” which are not managed by us and, because of the way they work, cannot be accessed by us, nor are we responsible for their management or purpose.
    To that end, we can also use the services of a third party in order to collect data and/or publish ads when you visit our Website. These companies often use anonymous and aggregated information (not including, for example, your name, address, email address or telephone number) regarding visits to this Website and others in order to publish ads about goods and services of interest to you.
  • e) Social cookies: these cookies allow you to share our Website and click “Like” on social networks like Facebook, Twitter, Google+, and YouTube, etc. They also allow you interact with each distinct platform’s contents.

The information contained in the above list of cookies has been provided by the other companies which generate them.

These companies have their own privacy policies in which they set forth both their own declarations as well as applicable disabling systems.

Aegean Outdoors is not responsible for the contents and accuracy of third party cookie policies contained in our Cookie Policy.

You must keep in mind that if your Device does not have cookies enabled, your experience on the Website may be limited, thereby impeding the navigation and use of our services.

There are a number of ways to manage cookies. By modifying your browser settings, you can opt to disable cookies or receive a notification before accepting them. You can also erase all cookies installed in your browser’s cookie folder. Keep in mind that each browser has a different procedure for managing and configuring cookies.

8. Update of this Privacy Policy

We reserve the right to modify this Privacy Policy at any time in accordance with this provision. If we make changes to this Privacy Policy, we will post the revised Privacy Policy on our Website and update the “Last Updated” date at the top of this Privacy Policy.