1. Purpose of this Policy
Protecting the privacy and personal data of our visitors and customers is an important priority.
This Privacy Policy explains what personal data may be collected through econicmarine.gr, how and why it is used, with whom it may be shared, how long it is retained and what rights individuals have in relation to their data.
Personal data is processed in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable Greek and European data protection legislation.
2. Data Controller
The controller responsible for personal data processing carried out through the Website is the entity operating and providing the Econic Marine services.
The full identity and contact details of the Data Controller will be included in the final published version of this Policy.
3. Who this Policy applies to
This Policy applies, among others, to:
- Website visitors;
- individuals submitting enquiries through forms, email or other channels;
- prospective and existing customers;
- individuals for whom a booking is requested or made;
- passengers and participants in our services;
- individuals communicating with us by telephone, email or social media.
4. Personal data we may collect
Depending on how you interact with us, we may collect the following categories of data.
Identity and contact information
This may include:
- name and surname;
- email address;
- telephone number;
- country or place of residence where required.
Enquiry and booking information
This may include:
- requested date;
- type of service or cruise;
- number of participants;
- special requests;
- information required to organise or provide the service;
- communications exchanged with us.
Information about other passengers
If you make a booking or provide information on behalf of other individuals, you may provide us with limited personal data relating to those individuals where necessary to provide the service.
In such cases, you must be entitled to provide us with that information and, where required, must have informed the individuals concerned.
Allergy and intolerance information
If you choose to tell us about allergies, food intolerances or other relevant health information so that we can more safely accommodate your needs during a service, this information is treated with enhanced protection.
Providing this information is generally voluntary and its processing is limited to the specific purpose for which it was provided.
Where required by law, we will seek your explicit consent before processing such information.
Technical information
When you visit the Website, technical information may be collected, including:
- IP address;
- device type;
- browser;
- operating system;
- access date and time;
- pages visited;
- technical logs and security information.
Cookies and usage data
Where the required consent has been provided, information about how the Website is used may be collected through cookies or similar technologies.
Further information is available in our Cookie Policy.
5. How we collect personal data
Personal data may be collected:
- directly from you through Website forms;
- through email or telephone communications;
- during an enquiry or booking process;
- from another person making a booking on your behalf;
- through cooperating booking systems or travel partners where applicable;
- automatically during Website visits through technical logs and, where you have consented, cookies or similar technologies.
6. Purposes and legal bases for processing
We may process personal data for the following purposes.
Responding to enquiries
To respond to requests for information or communications.
Processing may be necessary to take steps at your request before entering into a contract or may be based on our legitimate interest in communicating effectively with prospective customers.
Managing and providing bookings
To organise, confirm and provide services that you have requested or purchased.
This processing will generally be necessary for the performance of a contract or in order to take steps at your request before entering into a contract.
Customer service
To communicate with you concerning your booking, changes to a service, instructions, meeting points, customer requests or complaints.
Legal and regulatory obligations
Where necessary, personal data may be processed to comply with tax, accounting, maritime, port or other obligations imposed by applicable law.
Security and prevention of misuse
Technical data and logs may be used to protect the Website, prevent malicious activity, diagnose technical issues and safeguard our systems and users.
This processing is based on our legitimate interest in maintaining secure and reliable information systems.
Analytics and Website improvement
Where consent is required for the technologies used, analytics or statistical tools are activated only after the user has made the relevant choice.
Marketing communications
If newsletter subscriptions or other promotional communications are offered in the future, they will be sent in accordance with applicable law and, where required, only after consent has been provided.
Consent may be withdrawn at any time.
7. Who may receive personal data
Where necessary, personal data may be disclosed to:
- authorised staff;
- Website hosting and technical support providers;
- email and communications providers;
- booking system providers;
- partners necessary to provide the requested service;
- skippers, crews or vessel operators where necessary;
- payment providers, where used;
- accountants, legal advisers or other professional advisers where required;
- public, tax, port, judicial or other competent authorities where disclosure is required by law;
- analytics, marketing or other online service providers only in accordance with applicable legal requirements and the user’s consent choices.
Partners receive only the data necessary for the purpose for which their access is required.
We do not sell personal data to third parties.
8. International data transfers
Certain technology providers may process information outside the European Economic Area.
Where such transfers occur, the mechanisms and appropriate safeguards required under applicable data protection law are used.
9. Data retention
Personal data is retained only for as long as necessary for the purpose for which it was collected.
When determining retention periods, we take into account:
- the duration of our relationship with the customer;
- the need to administer a booking or enquiry;
- tax and accounting obligations;
- obligations imposed by applicable law;
- the establishment, exercise or defence of legal claims;
- information security requirements.
Data collected solely on the basis of consent will no longer be used for that specific purpose after consent is withdrawn, unless another lawful basis permits or requires its retention.
Information concerning allergies, intolerances or other special health requirements will not be kept for longer than necessary for the safe provision of the relevant service and any legal obligations directly connected with it.
10. Security
Appropriate technical and organisational measures are used to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.
Access to personal data is limited to persons and partners who require the information in order to perform their duties or services.
Although reasonable safeguards are used, no internet transmission or storage system can be regarded as completely free from risk.
11. Your data protection rights
Subject to the conditions set out in applicable law, you may have the right to:
- access your personal data;
- rectify inaccurate or incomplete personal data;
- request erasure of your data;
- request restriction of processing;
- object to certain processing;
- request data portability where applicable;
- withdraw consent at any time where processing is based on consent.
Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
You also have the right to lodge a complaint with the competent supervisory authority. In Greece, the competent authority is the Hellenic Data Protection Authority (HDPA).
12. Automated decision-making
We do not use personal data for solely automated decision-making producing legal effects or similarly significantly affecting individuals, unless this is expressly disclosed and an appropriate lawful basis exists.
13. Third-party websites and services
The Website may contain links to or embedded services provided by third parties.
This Privacy Policy does not govern independent processing carried out by those third parties for their own purposes. We encourage you to review the privacy policies of the relevant services.
14. Changes to this Policy
This Privacy Policy may be updated to reflect changes to our services, technologies or applicable law.
The date of the latest revision is shown at the beginning of the Policy.
15. Privacy contact
Requests concerning personal data may be submitted through the contact details published on the Website.
The full details of the Data Controller and a dedicated privacy contact channel will be added before the final publication of this Policy.