Legal
Privacy Policy
This policy explains how Royalty Escapes ("we", "the company") collects and processes your personal data, under Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.
1. Who is the data controller
| Trading name | Royalty Escapes |
|---|---|
| Legal name | ROYALTY ESCAPES ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε. |
| Registered address | 191 Thivon Ave., 1st floor, Peristeri 121 34, Athens |
| VAT no. | 801090074 |
| Companies register (GEMI) | 148844101000 |
| Tourism register (MHTE) | 0259Ε60000729500 |
| Phone | (+30) 2107103532 |
| Email for data protection | info@royalty-escapes.com |
We have not appointed a Data Protection Officer, as we are not required to. For any question about your data, write to info@royalty-escapes.com.
2. What data we process
- Contact data — full name, email, phone and the content of your message, when you use the contact form, email us or call us.
- Booking data — where you book a trip: identity and travel document details, date of birth, billing details, travel preferences.
- Special category data — only where a trip strictly requires it (e.g. health information, dietary or accessibility needs, passport data for visas). We process it solely on your explicit consent, Art. 9(2)(a) GDPR.
- Technical data — our host (Cloudflare) processes your IP address and request metadata to serve the pages and protect them from abuse. The site sets no analytics, statistics or advertising cookies.
Providing contact data is necessary in order for us to answer you; providing booking data is necessary in order to conclude and perform the travel contract. Without it we cannot provide the service.
3. Purposes and legal bases
| Purpose | Legal basis | Retention |
|---|---|---|
| Answering enquiries, quotes, pre-contractual steps | Art. 6(1)(b) — pre-contractual measures at your request | 12 months from the last contact |
| Booking, issuing tickets, performing the travel contract | Art. 6(1)(b) — performance of a contract | 5 years after the trip (limitation of claims) |
| Invoicing, accounting, tax obligations | Art. 6(1)(c) — legal obligation | 10 years (tax legislation) |
| Health / dietary / accessibility needs for a trip | Art. 9(2)(a) — explicit consent | Until the trip ends, then deleted |
| Offers and newsletter, if you sign up | Art. 6(1)(a) — consent | Until you withdraw consent |
| Website security, prevention of abuse and fraud | Art. 6(1)(f) — legitimate interest | Short-lived server logs (up to 30 days) |
4. Recipients and processors
We never sell your data. We disclose it only where necessary:
- Travel providers — airlines, hotels, ferry and coach operators, local partners, insurers, embassies for visas. Disclosure is necessary to perform your booking.
- Cloudflare, Inc. — hosting and delivery of this website (processor).
- FormSubmit — delivers the messages you send through the contact form to our mailbox (processor).
- Google Ireland Ltd. — the Google Maps embed on the Contact page, loaded only if you click "Load map".
- Our accountant, banks and payment providers — for invoicing and payments.
- Public authorities — where the law obliges us.
5. Transfers outside the EEA
Cloudflare, FormSubmit and Google are established in the United States. Where data reaches them, the transfer is based on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with supplementary technical measures (TLS encryption in transit). You may request a copy of the safeguards at info@royalty-escapes.com.
6. Security of processing
The website is static, holds no customer database and is served exclusively over HTTPS (TLS). Access to mailboxes and files is restricted to authorised staff and protected by strong authentication. Booking files are kept in access-controlled systems.
7. Automated decision-making
We carry out no automated decision-making and no profiling within the meaning of Art. 22 GDPR.
8. Children
The website is not addressed to children. Persons under 15 (Art. 21 of Greek Law 4624/2019) may consent to information society services only through the holder of parental responsibility.
9. Your rights
Under Articles 15–22 GDPR you have the right to:
- access your data and receive a copy;
- rectification of inaccurate or incomplete data;
- erasure ("right to be forgotten"), where no overriding obligation applies;
- restriction of processing;
- data portability in a structured, machine-readable format;
- object to processing based on legitimate interest;
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.
To exercise them, write to info@royalty-escapes.com. We reply within one month; the deadline may be extended by a further two months for complex requests, in which case we will tell you. The service is free of charge.
10. Right to lodge a complaint
If you believe your rights have been infringed you may lodge a complaint with the Hellenic Data Protection Authority: 1–3 Kifisias Ave., 115 23 Athens, tel. +30 210 6475600, www.dpa.gr.
11. Cookies
This site uses no tracking cookies. For details see the Cookie Policy.
12. Changes to this policy
We may amend this policy; the version in force is always the one published here. Applicable law is Greek law and Regulation (EU) 2016/679; the courts of Athens have jurisdiction.
Last updated: July 2026