Last updated: 6 October 2026
This Privacy Policy explains how Physis Villas (“we”, “us”, “our”) collects, uses, shares and protects personal data when you visit physisvillaschania.gr (the “Website”), contact us, ask us to hold an offer for you, or book a stay with us. It is issued in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, “GDPR”), Greek Law 4624/2019 and Greek Law 3471/2006 on the protection of personal data in electronic communications.
Please read it together with the cookie settings available on the Website. If anything is unclear, write to us at [email protected].
1. Who is responsible for your data
The data controller is Physis Villas (physisvillaschania.gr), the operator of two holiday villas (Villa Thalia and Villa Erato) in Agia, Chania, Crete, Greece, tourism license no. 1094314.
- Postal address: Agia, Chania, Crete, Greece
- Email: [email protected]
- Telephone / WhatsApp: +30 694 298 6800
We are not required to appoint a Data Protection Officer. All requests concerning your personal data can be sent to the email address above.
2. The personal data we process, why, and on what legal basis
We only collect the data we need for the purposes described below. We do not use your data for any purpose that is incompatible with the purpose for which it was collected.
2.1 Contact form
Data: your name, email address, telephone number (optional), subject and message.
Purpose: to reply to your enquiry and, if it leads to a reservation, to prepare your stay.
Legal basis: steps taken at your request before entering into a contract (Article 6(1)(b) GDPR) and our legitimate interest in answering enquiries about our villas (Article 6(1)(f) GDPR).
2.2 “Hold my offer” form and follow-up emails
On some pages we offer you the option to ask us to hold today’s direct booking rate for your dates for 48 hours.
Data: your name, email address, arrival and departure dates, number of guests, preferred villa, telephone or WhatsApp number (optional), the language and page from which you submitted the form, the date and time and the wording of your consent, and the IP address used to submit the form (kept for security and as proof of consent).
Purpose: to send you the offer by email, to contact you about it, and to send you up to two reminder emails about the same offer within the 48 hour period. We do not add you to a newsletter and we do not send you any other marketing on the basis of this form.
Legal basis: your consent (Article 6(1)(a) GDPR and Article 11 of Law 3471/2006), given by ticking the consent box before submitting the form. You can withdraw your consent at any time by using the unsubscribe link included in every email, or by writing to us. Withdrawal does not affect the lawfulness of processing carried out before it.
2.3 Reservations
Availability searches and reservations are made through our online booking engine, operated for us by WebHotelier at physisvillaschania.reserve-online.net.
Data: the names of the guests, contact details, dates of stay, number of guests, special requests, payment and invoicing details, and any other information you give us about your stay.
Purpose: to confirm and manage your reservation, receive payment, prepare the villa, communicate with you before, during and after your stay, and issue invoices or receipts.
Legal basis: performance of the accommodation contract with you (Article 6(1)(b) GDPR) and compliance with our legal obligations under Greek tax, accounting and tourism legislation (Article 6(1)(c) GDPR).
Payment card data is processed by the booking engine and the payment service providers it uses, under their own security standards. Where card details are made available to us as a guarantee for a reservation, we use them only for that purpose and in line with the booking terms you accepted.
2.4 Email, telephone and WhatsApp communication
Data: your contact details and the content of our communication.
Purpose: to answer you, to deal with your reservation and to keep a record of what was agreed.
Legal basis: steps before a contract and performance of a contract (Article 6(1)(b) GDPR) and our legitimate interest in keeping a record of our communication with guests (Article 6(1)(f) GDPR).
If you contact us through WhatsApp, WhatsApp (Meta Platforms Ireland Ltd.) also processes your data as an independent controller under its own privacy policy.
2.5 Technical data and website security
Data: IP address, browser type and version, device and operating system, pages requested, date and time of access, referring page and technical error data.
Purpose: to deliver the Website, protect it against attacks, abuse and spam, and diagnose technical problems.
Legal basis: our legitimate interest in operating a secure and reliable Website (Article 6(1)(f) GDPR).
2.6 Analytics and advertising (only with your consent)
With your consent, we use Google Analytics 4 to understand how visitors use the Website, and Google Ads conversion tracking to measure the results of our advertising (for example, whether a visit that started from one of our ads led to an enquiry or a booking). These tools are loaded through Google Tag Manager.
When you submit the contact form or the “hold my offer” form and you have accepted advertising cookies, the email address and telephone number you entered are converted on your device into an irreversible code (hashed with the SHA-256 algorithm) and sent to Google, so that the enquiry can be matched to an ad interaction (“enhanced conversions”). Google uses this data only to measure conversions for us.
Legal basis: your consent (Article 6(1)(a) GDPR and Article 4(5) of Law 3471/2006). We use Google Consent Mode: until you make a choice in the cookie banner, analytics and advertising storage is denied by default. You can change or withdraw your consent at any time through the cookie settings icon at the bottom left of every page.
2.7 Embedded third-party content
Some pages show an embedded Google Map and use web fonts provided by Google Fonts, and some scripts are delivered through the cdnjs network. To display them, your browser connects to the servers of the provider, which therefore receives your IP address and technical browser data. We use these services on the basis of our legitimate interest in presenting the Website and the location of the villas in a clear and reliable way (Article 6(1)(f) GDPR).
2.8 Legal claims
Where necessary, we may process the data described above to establish, exercise or defend legal claims, on the basis of our legitimate interest (Article 6(1)(f) GDPR).
3. Cookies and similar technologies
Cookies are small files stored on your device. We use:
- Strictly necessary cookies and local storage, which are needed for the Website to work, to remember your cookie choices, and to avoid showing you the “hold my offer” window again after you have submitted it. These do not require consent.
- Analytics cookies (for example
_gaand_ga_*set by Google Analytics), only with your consent. - Advertising cookies (for example
_gcl_auand related Google Ads identifiers), only with your consent.
The full list of cookies, their purpose and their duration is shown in the cookie settings window, where you can accept or reject each category. Rejecting non-essential cookies does not affect your ability to use the Website or to book. The booking engine sets its own cookies once you move to it.
4. Who receives your data
We do not sell your personal data and we do not share it with third parties for their own marketing. Your data is disclosed only to the following recipients, to the extent necessary:
- Website and email hosting: our hosting provider in Greece (name-servers.gr), which hosts the Website, its database and our mailbox.
- Network security and content delivery: Cloudflare, Inc., which protects the Website against attacks and delivers it quickly.
- Booking engine: WebHotelier, which operates our online reservation system on our behalf.
- Google: Google Ireland Ltd. and Google LLC, for Google Tag Manager, Google Analytics, Google Ads conversion measurement, Google Maps and Google Fonts, as described in sections 2.6 and 2.7.
- Website support: the agency that develops and maintains the Website (AiolosWeb), which may access data stored on the Website only to the extent needed for technical support.
- Professional advisers: our accountant and, where needed, legal advisers, who are bound by professional secrecy.
- Public authorities: tax, tourism, police or judicial authorities, where we are required to do so by law.
Providers that process data on our behalf act as processors under written agreements that oblige them to protect your data and to use it only on our instructions.
5. Transfers outside the European Economic Area
Some providers (in particular Google LLC and Cloudflare, Inc.) may process data in the United States or other countries outside the European Economic Area. Such transfers take place on the basis of the European Commission’s adequacy decision for the EU-U.S. Data Privacy Framework, where the recipient is certified under it, or on the basis of the European Commission’s Standard Contractual Clauses together with additional safeguards (Article 46 GDPR). You can ask us for more information about these safeguards.
6. How long we keep your data
- “Hold my offer” requests: up to 12 months from submission, after which they are automatically deleted, unless the request led to a reservation.
- Contact form messages and email enquiries that do not lead to a reservation: up to 24 months from our last communication.
- Reservation, invoicing and accounting records: for the period required by Greek tax and accounting legislation, which is in principle five (5) years from the end of the financial year to which they relate, and longer where the law requires it or a tax audit or legal dispute is pending.
- Analytics data: for no longer than 14 months in Google Analytics.
- Proof of consent: for as long as the related data is kept and for as long as needed to demonstrate that consent was given.
- Server and security logs: for a short period, as set by our hosting and security providers, usually a few weeks.
When the retention period ends, the data is deleted or anonymised.
7. Your rights
Under the GDPR you have the right to:
- access your personal data and receive a copy of it (Article 15);
- rectify inaccurate or incomplete data (Article 16);
- erase your data, where there is no legal reason for us to keep it (Article 17);
- restrict the processing of your data in the cases provided by law (Article 18);
- receive the data you provided to us in a structured, commonly used and machine-readable format, and have it transmitted to another controller (data portability, Article 20);
- withdraw your consent at any time, where processing is based on consent, without affecting the lawfulness of processing before the withdrawal (Article 7(3)).
Right to object (Article 21 GDPR): where we process your data on the basis of our legitimate interest, you have the right to object at any time, on grounds relating to your particular situation. We will then stop the processing unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or the processing is needed for legal claims. You can always object to the use of your data for direct marketing, and we will then stop such use.
To exercise any of these rights, write to [email protected]. We will reply without undue delay and in any case within one month, which may be extended by two further months for complex or numerous requests, in which case we will inform you. We may ask you for information to confirm your identity before responding. Exercising your rights is free of charge, unless a request is manifestly unfounded or excessive.
Right to lodge a complaint: if you believe that the processing of your data infringes the law, you can lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr, or with the supervisory authority of the EU country where you live or work.
8. Do you have to give us your data?
Using the Website does not require you to give us any personal data. The fields marked as required in our forms are necessary for us to answer you or to hold your offer, and the data requested during booking is necessary to conclude and perform the accommodation contract and to meet our legal obligations. If you do not provide it, we may not be able to answer you or to accept your reservation.
9. Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.
10. Children
The Website is intended for adults. We do not knowingly collect personal data directly from children under 15. Reservations must be made by an adult, who may provide the details of children travelling in the same party where this is necessary for the stay.
11. Security
We take appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These include encrypted connections (HTTPS), a web application firewall, protection against brute-force login attempts, restricted access to the administration area and regular software updates. No method of transmission over the internet is completely secure, but we work to protect your data and to respond promptly to any incident, in accordance with Articles 33 and 34 GDPR.
12. Links to other websites
The Website contains links to other websites and social networks (for example Instagram, Facebook and TikTok). We are not responsible for their privacy practices. When you visit them, their own privacy policies apply.
13. Changes to this policy
We may update this Privacy Policy to reflect changes in the law, in our services or in the tools we use. The date of the latest version is shown at the top of this page. Where changes are significant, we will make this clear on the Website and, where required, ask for your consent again.