Α. BASIC DEFINITIONS AND ABBREVIATIONS
This Chapter sets out the key definitions and abbreviations used in this Policy for the purpose of its proper interpretation and implementation. The terms defined herein, together with their corresponding abbreviations, are capitalized throughout the following Chapters.
- Recipient: means any natural or legal person, public authority, agency, or other body to whom Personal Data collected under and for the purposes of this Policy are disclosed.
- HDPA: means the Hellenic Data Protection Authority (1–3 Kifisias Avenue, 115 23 Athens, Greece, Tel.: +30 210 647 5600, website: www.dpa.gr).
- GDPR: means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the Processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
- Personal Data: means any information relating to an identified or identifiable natural person (“Data Subject”). An identifiable natural person is one whose identity can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier (e.g., an IP address), or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
- Processor: means any natural or legal person, public authority, agency, or other body that Processes Personal Data on behalf of the Controller.
- Processing: means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
- Company: means the public limited company (société anonyme) under the corporate name “DKG DEVELOPMENT S.A.”, with its registered office at 602A Vouliagmenis Avenue, Imeras Office Center, Argyroupoli, 16452, Greece, Tax Identification Number (TIN/VAT No.) 801259253, and General Commercial Registry (G.E.MI.) Registration No. 152902909000.
- EEA: means the European Economic Area, comprising the Member States of the European Union, as well as Iceland, Norway, and Liechtenstein.
- Law: means Greek Law 4624/2019, as amended and in force from time to time, which supplements and implements certain provisions of the GDPR in Greece.
- DKG Development Group: means the group of companies listed in Annex A (parent company, subsidiaries, and affiliated companies). For the avoidance of doubt, each company within the DKG Development Group constitutes a separate legal entity and acts as an independent Controller with respect to the Processing of your Personal Data under and for the purposes of this Policy.
- Personal Data Breach: means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise Processed in connection with the operation of the Website.
- Policy: means this Privacy Policy, which governs the Processing of the Personal Data of visitors to and users of the Website while browsing the Website or using the electronic services made available through it.
- Controller: means any natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this Policy, the Controller is DKG DEVELOPMENT S.A., whose details are set out above under paragraph 7.
- Data Subject: means any natural person whose Personal Data is subject to Processing. For the purposes of this Policy, Data Subjects include all visitors to and users of the Website www.dkg-development.com.
Β. INTODUCTION
- Policy Adoption and Applicability: This Policy has been adopted by the Company and applies to all Personal Data relating to visitors to and users of the Website that are collected during their access to and use of the Website. This Policy provides all necessary information regarding the categories of Personal Data we collect, the purposes and legal bases for the Processing, the security measures we implement, and your rights as a Data Subject. Please read this Policy carefully before using the services available through the Website, such as submitting a contact form or subscribing to our newsletter.
- Commitment to Data Protection: The Company, acting as the Controller, is committed to protecting the privacy and Personal Data of visitors to and users of the Website. We are dedicated to maintaining a secure and transparent environment by implementing appropriate technical and organizational measures to ensure the lawful Processing of your Personal Data.
- Legal Compliance Framework: This Policy is intended to ensure the full compliance of the Company and the DKG Development Group with the applicable national and European legal framework, in particular the GDPR, Greek Law 4624/2019, and the decisions, guidelines, recommendations, and other regulatory acts issued by the HDPA.
- Scope of Application: The provisions of this Policy apply to every natural person who visits, browses, or uses the services available through the Website.
- Amendments to the Policy: The Company reserves the right to amend or update this Policy unilaterally at any time in order to reflect changes in applicable legislation, improvements to security measures, or changes to its business activities. The version of this Policy in force from time to time, together with the date of its latest revision, will always be available on the Website.
- Relationship with Applicable Law: The provisions of this Policy are intended to supplement, and not replace or limit, the obligations arising under the applicable data protection legislation. In the event of any inconsistency or conflict between this Policy and the applicable legal framework, the provisions of the GDPR and the applicable legislation shall prevail.
C. OUR ROLE AS CONTROLLER
D. CATEGORIES OF PERSONAL DATA WE COLLECT – PURPOSES AND LEGAL BASES FOR PROCESSING
1. ContactviatheOnlineContactForm
When you contact us through the Website’s online contact form, we collect your full name, email address, telephone number, customer type, and any other Personal Data that you choose to include in your message.
- Purpose: To receive, manage, review, and respond to your requests, enquiries, or messages.
- Legal Basis: The Company’s legitimate interests (Article 6(1)(f) of the GDPR) in providing effective customer service and managing communications with the public.
- Retention Period: Such Personal Data will be retained until your request or enquiry has been fully and finally resolved, unless further retention is necessary for the establishment, exercise, or defence of legal claims.
2. NewsletterSubscription
Where a Newsletter is made available through the Website, and you choose to subscribe, we collect your full name, email address, and telephone number.
- Purpose: To send you newsletters, marketing communications, promotional materials, and information regarding the services, projects, and activities of the Company and the DKG Development Group.
- Legal Basis: Your explicit consent (Article 6(1)(a) of the GDPR), provided through a clear affirmative action (opt-in) when subscribing to the Newsletter.
- Withdrawal of Consent (Opt-out): You may withdraw your consent at any time by either selecting the unsubscribe link included in every Newsletter or by sending an email to info@dkg-development.com. Upon receipt of your request, we will promptly remove your Personal Data from the relevant mailing list and cease sending you further communications.
3. Automated Collection of Data (Website Browsing)
When you visit and browse the Website, we automatically collect the following categories of information:
a) Internet Identification and Location Data:
Your IP address, browser type and version, installed browser plug-ins, time zone settings, operating system, and general geolocation data.
b) Usage and Behavioural Data:
Your navigation path (URL clickstream) within the Website, the pages or services you view, page response times, download errors, the time spent on individual pages, the frequency of your visits, and your interactions with the Website.
Purpose: To ensure the proper technical operation, security, and optimization of the Website, as well as to perform statistical analysis of its usage and traffic.
Legal Basis: For data that are strictly necessary for the technical operation of the Website, the legal basis is the Company’s legitimate interests (Article 6(1)(f) of the GDPR) in ensuring the secure and uninterrupted operation of the Website. For Personal Data collected through preference, analytics, or advertising cookies, the legal basis is your explicit consent, provided through the Cookie Banner. For further information, please refer to the DKG Development Group Cookie Policy.Νομική Βάση:
4. Special Categories of Personal Data and Data Relating to Minors
The Company does not knowingly collect Special Categories of Personal Data (sensitive Personal Data), including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, health data, or data concerning a person’s sex life or sexual orientation.
The services available through the Website are intended exclusively for individuals who are at least 18 years of age. We do not knowingly collect Personal Data relating to children under the age of 16. If we become aware that such Personal Data has been collected without the required parental consent, we will take appropriate steps to delete it without undue delay.
5. Booking and Contact Data
When you make a reservation at our property, we may collect and Process the following categories of Personal Data:
- Full name
- Email address
- Telephone number
- Postal address
- Identity card or passport number (where required)
- Reservation details, including arrival and departure dates, accommodation preferences, and any special requests
The above Personal Data are collected and Processed for the purposes of managing and fulfilling your reservation, providing accommodation services, communicating with you in relation to your stay, and complying with the legal obligations applicable to the property.
Please note that all reservations for Wyndham Residences Piraeus Marina Zeas are completed through the official booking platform of Wyndham Hotels & Resorts. When you choose to proceed with a reservation, you will be redirected to a third-party website operated by Wyndham Hotels & Resorts or its authorized service providers.
Non–ProcessingofPaymentData
We do not Process, store, or have access to any payment information, including credit or debit card details, submitted during the reservation process.
All booking transactions and the Personal Data associated with such reservations are processed exclusively by Wyndham Hotels & Resorts.
Processing of Personal Data
Any Personal Data you provide during the reservation process, including your contact details, payment information, and accommodation preferences, are collected and Processed directly by Wyndham Hotels & Resorts in accordance with its own Privacy Policy and the applicable data protection legislation.Δεν ελέγχουμε και δεν φέρουμε ευθύνη για τις πρακτικές επεξεργασίας δεδομένων των εν λόγω τρίτων πλατφορμών.
Third–PartyWebsite
Once you are redirected to the booking platform, your use of that website will be subject to the Terms and Conditions and Privacy Policy of Wyndham Hotels & Resorts.
We encourage you to read their Privacy Policy carefully before completing your reservation.
LimitationofLiability
The Company accepts no responsibility or liability for:
- the reservation process;
- payment transactions;
- the Processing of Personal Data; or
- any services provided through the Wyndham Hotels & Resorts booking platform,
as all of the above are managed exclusively by Wyndham Hotels & Resorts.
Ε. HOW WE PROTECT YOUR PERSONAL DATA
The Company implements appropriate state-of-the-art technical, physical, and organizational security measures, including encryption protocols, access control procedures, and information security systems, to protect your Personal Data against accidental or unlawful loss, destruction, alteration, unauthorized access, or disclosure.
F. YOURRIGHTS
Σύμφωνα με τον ΓΚΠΔ, έχετε τα ακόλουθα δικαιώματα αναφορικά με τα προσωπικά σας δεδομένα:
- Right of Access: You have the right to obtain confirmation as to whether we Process your Personal Data and, where that is the case, to receive information regarding the categories of Personal Data concerned, the purposes of the Processing, the recipients to whom the Personal Data have been disclosed, the applicable retention period, and to obtain a copy of your Personal Data.
- Right to Rectification: You have the right to request the correction of inaccurate Personal Data concerning you and the completion of incomplete Personal Data.
- Right to Restriction of Processing: You have the right to request the restriction of the Processing of your Personal Data under the conditions provided for by applicable law.
- Right to Object: You have the right to object, at any time, to the Processing of your Personal Data where such Processing is based on our legitimate interests, including profiling.
- Right to Data Portability: You have the right to receive your Personal Data in a structured, commonly used, and machine-readable format, or to request that such Personal Data be transmitted directly to another Controller, where the Processing is based on your consent or on a contract and is carried out by automated means.
- Right to Erasure (“Right to be Forgotten”): You have the right to request the erasure of your Personal Data where it is no longer necessary for the purposes for which it was collected, or where there is no other lawful basis for its retention,such as compliance with a legal obligation or the establishment, exercise, or defence of legal claims.
- Right to Withdraw Consent: Where the Processing of your Personal Data is based on your consent, you have the right to withdraw that consent at any time. Such withdrawal shall not affect the lawfulness of any Processing carried out on the basis of your consent before its withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) regarding any matter relating to the Processing of your Personal Data.
G. WITH WHOM WE SHARE YOUR PERSONAL DATA
- Service Providers: We may disclose your Personal Data to trusted third-party service providers acting on behalf of and under the instructions of the Company and/or the DKG Development Group, including providers of information technology services (IT support and cloud hosting), website development and management providers, and newsletter distribution platform providers.
- Processors: In such cases, the Processing is entrusted pursuant to a written Data Processing Agreement (DPA) or other appropriate contractual arrangements in accordance with Article 28 of the GDPR. We engage only those Processors that provide sufficient guarantees for the implementation of appropriate technical and organizational measures to ensure the confidentiality, integrity, and security of your Personal Data.
- Legal Obligations and Protection of Rights: We may disclose your Personal Data to competent judicial, prosecutorial, law enforcement, or administrative authorities where required by applicable law, including for compliance with a court order or other legally binding request.
- Corporate Transactions: In the event of a corporate restructuring, merger, acquisition, or sale of assets, your Personal Data may be disclosed to prospective purchasers or successor entities, subject to appropriate confidentiality obligations and safeguards.
- Protection of Legitimate Interests: We reserve the right to disclose your Personal Data where such disclosure is strictly necessary for the establishment, exercise, or defence of the legitimate interests and legal claims of the Company and the DKG Development Group before courts or other competent authorities.
H. RETENTIONANDDELETIONOFPERSONALDATA
Technical and digital browsing data (such as cookies, IP addresses, and system access logs), as well as identification data (such as names and telephone numbers) collected through property enquiry forms, are retained for up to twelve (12) months (in the case of system logs) or until the specific purpose for which they were collected has been fully fulfilled, whichever is applicable.
Upon expiry of the applicable retention period, such Personal Data are securely deleted or permanently anonymized. For further information regarding our retention periods, you may request a copy of the DKG Development Group Data Retention and Destruction Policy.
I. TRANSFERS OF PERSONAL DATA OUTSIDE THE EEA
The Company and the DKG Development Group store your Personal Data primarily on servers located within the European Economic Area (EEA). Where international technology service providers (such as Microsoft 365, cloud infrastructure providers, or analytics service providers) are used and their servers may be located outside the EEA, the Company ensures that such transfers are carried out subject to appropriate safeguards, including:
- Adequacy Decisions: Personal Data may be transferred to a country or international organization that the European Commission has determined ensures an adequate level of protection (for example, the United Kingdom, Canada, or, in the case of the United States, organizations certified under the EU–U.S. Data Privacy Framework).
- Standard Contractual Clauses (SCCs): Where no adequacy decision exists, the Company relies on the European Commission’s Standard Contractual Clauses (SCCs), together with any supplementary technical and organizational measures that may be required.
- Other Appropriate Safeguards: In specific circumstances, transfers may also be based on Binding Corporate Rules (BCRs) or on your explicit consent where such consent is required for the particular transfer.
The Company regularly assesses its service providers to verify that these data protection safeguards are effectively implemented and maintained.
J. RELATEDPOLICIES
This Policy applies alongside, and should be read in conjunction with, the other data protection policies adopted by the DKG Development Group. You may request a copy of any of the following policies at any time:
- Privacy and Personal Data Protection Policy for Customers and Prospective Customers of the DKG Development Group;
- DKG Development Group Cookie Policy; and
- DKG Development Group Data Retention and Destruction Policy.
Κ. CONTACT INFORMATION
To exercise your rights or if you have any questions, requests, comments, or complaints regarding this Policy or the Processing of your Personal Data, you may contact the Company’s Authorized Privacy Contact, whose details are set out below:
Authorized Privacy Contact:
- Name: Εμμανουήλ Γκιάλας
- Address: 602a Vouliagmenis Ave. 164 52 Argiroupoli, Greece
- Telephone: +30 210 9227299
- E-mail: e.gialas@lavish-hospitality.com
The Company is committed to responding to your requests free of charge and without undue delay, and in any event within one (1) month of receipt. Where a request is particularly complex or where the Company has received a large number of requests, this period may be extended by up to two (2) additional months. In such cases, you will be informed of the extension and the reasons for it within the time limits prescribed by the GDPR.
| 07/07/ 2026 | 1.0 | |||
