Effective date: 4 October 2026
Avalon Boutique Suites Hotel respects your privacy and processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Greek law.
1. Who is responsible for your data
The data controller is Afoi Brokou OE (Avalon Boutique Suites Hotel), 9 Haritos Street, Medieval Town of Rhodes, 85100 Rhodes, Greece.
Email: info@avalonrhodes.gr
Telephone: +30 22410 31438
2. Scope of this notice
This notice applies when you visit avalonrhodes.gr, contact us, follow a link to our direct booking engine, or interact with services embedded in or linked from our website. The direct booking engine is operated for us by WebHotelier/Revplus and also displays its own privacy information during the booking journey.
3. Personal data we may process
- Website and security data: IP address, device and browser information, request logs, timestamps and technical identifiers required to deliver, secure and maintain the website.
- Booking data: dates, room and occupancy choices, contact and guest details, booking preferences, payment or guarantee information and booking correspondence processed through the WebHotelier/Revplus booking environment.
- Enquiry data: your name, email address, telephone number and the content of messages you send to us.
- Consent and preference data: your cookie choices, language preference and related technical records.
- Analytics and map interaction data: information generated by analytics tools or by Google Maps only where consent is required and has been given.
The newsletter sign-up function on this website is currently unavailable and the website does not currently collect newsletter subscriptions through that form. If it is re-enabled, subscription data will be collected only with clear consent and this notice will be updated.
4. Why we process data and our legal bases
- To provide availability information, process a booking and take steps at your request before entering into a contract, or to perform the accommodation contract.
- To answer enquiries and provide guest service, based on your request, our legitimate interests in operating the hotel, or the performance of a contract.
- To keep the website secure, prevent abuse and maintain reliable operation, based on our legitimate interests and legal obligations.
- To meet accounting, tax, tourism, safety and other legal obligations.
- To use non-essential analytics, maps, preference or marketing technologies where applicable, based on your consent. You may withdraw that consent at any time through the cookie settings.
5. Service providers and recipients
We disclose personal data only where necessary and subject to appropriate safeguards. Our service providers may include:
- WebHotelier/Revplus, for the direct booking engine and reservation technology;
- WPMU DEV/Incsub and related infrastructure providers, for hosting, backups, performance, security and website administration;
- Google Maps, when you choose to load map content that requires consent;
- GTranslate, for website language functionality;
- Complianz, used on this website to record and manage cookie choices;
- professional advisers, payment providers, competent public authorities and other recipients where required to provide the service or comply with law.
Links to social networks or other third-party sites take you to services that operate under their own privacy notices.
6. International transfers
Some service providers may process data outside the European Economic Area. Where this occurs, we require an appropriate transfer mechanism and safeguards under applicable data-protection law, such as an adequacy decision or approved contractual clauses.
7. How long we keep data
We keep personal data only for as long as necessary for the purpose for which it was collected. Booking and accounting records are retained for the periods required by applicable law. Enquiries are retained only as long as needed to respond and manage any related service. Security logs are retained according to operational and security needs. Consent records are retained as necessary to demonstrate and respect your choices. Data is then deleted or anonymised unless a longer period is required for a legal claim or legal obligation.
8. Cookies and similar technologies
Strictly necessary technologies may be used to operate and secure the website. Non-essential technologies are used only according to your choices. Details of the technologies in use, their purposes and how to change your choices are available in our Cookie Policy. You can reopen the cookie settings at any time using the cookie preferences control on the website.
9. Your rights
Subject to the conditions of the GDPR, you may request access to your data, correction, erasure, restriction of processing, data portability, or object to processing. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.
To exercise your rights, contact info@avalonrhodes.gr. We may need to verify your identity. You also have the right to lodge a complaint with the Hellenic Data Protection Authority at www.dpa.gr.
10. Direct booking privacy information
When you continue to the direct booking engine, additional privacy information is available at avalon.reserve-online.net/privacy-policy. The booking engine notice supplements this website notice for data processed during the booking journey.
11. Security
We apply reasonable technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or disclosure. No online service can guarantee absolute security.
12. Changes to this notice
We may update this notice when our services, technology or legal obligations change. The effective date at the top shows the latest revision.
13. Contact
For privacy questions or requests, email info@avalonrhodes.gr or write to Avalon Boutique Suites Hotel, 9 Haritos Street, Medieval Town of Rhodes, 85100 Rhodes, Greece.