Privacy Policy
Privacy Notice
​
Updated on 10-04-2025
​
Nysa Caverns (referred to as « we ») respect your privacy and are committed to protecting your personal data. We aim to provide a safe, secure online experience and ensure that we comply with the General Data Protection Regulation (GDPR). Here’s how we protect your personal data and respect your privacy:
​
Our role in your privacy
When you visit our website, (collectively referred to as “Site”), this notice applies to you. Please read and understand it before providing us with your personal data.
When and how we collect data
From the time you access the website, we are collecting data. Here’s when and how we do this:
-
You browse any page of our website or app
-
You inquire about our services
-
You make an online reservation and payment
-
You opt-in to our Marketing Communications
​
Types of data we can collect
Contact details
Your complete name, land line or mobile number, email address, mailing address, country, company name.
Financial information
Your credit card details, Company Tax Identification Number (TIN).
Data that identifies you
Your passport details, Government-issued ID, IP address, geolocation information.
Data on how you use our website
Your app or URL clickstreams (the path you take through our site/app), products/services viewed, page response times, how long you stay on our pages, what you do on those pages, how often, and other actions.
​
How and why we use your data
Under the GDPR, we can only use your personal data for certain specified purposes and where we have a legal basis to do so. Here are the reasons for which we process your data:
To provide you with the following Services
-
Responding to your inquiries and communicating with you;
-
Processing your hotel reservations;
-
Managing your bookings;
-
Providing you personalized and customized service when you stay with any villas;
-
Facilitating your payments and;
-
Establishing and fulfilling our contract with you
To improve Your Experience when using our site
-
Improving the layout and/or content of the Site, and customizing them according to your interests and preferences;
-
Monitoring and enforcing compliance with our Terms of Use; and
-
Notifying you of service issues and unusual account actions when using our Site, should any occur.
Provide Customer Support
-
Notifying you of any changes to our service,
-
Answering your queries/feedback as well as resolving issues (including any bug fixing) via email or mobile
To enable our business and pursue our legitimate interests
-
Improving and protecting our products, content, services and websites, both online and offline;
-
Monitoring our Services to prevent, investigate and/or report fraud, misrepresentation, security incidents or crime, in accordance with applicable laws;
-
Investigating any complaints that we receive;
-
Complying with applicable law and regulations; and
-
Inviting you to take part in market research, if any.
Marketing Communications
-
Sending you emails and notifications about new services,
-
Inviting you to participate in surveys, promotions and other marketing initiatives,
-
You can opt-out of such messages by following the instructions in the communication.
​
Your privacy rights
You can exercise your rights by sending us an email at reservations@nysacavernsantorini.com. When you make a request, note that such a request is subject to certain conditions.
You have the right to access information we hold about you
This includes the right to ask us supplementary information about:
-
What personal data we obtain about you,
-
How these are collected, processed and disposed
-
Any data breach incident that affects your personal data
-
Your other rights regarding our use of your data
Provision of such information will be subject to the supply of appropriate evidence of your identity. Please note further that:
-
We may withhold personal information that you request to the extent permitted by law.
-
You may instruct us at any time not to process your personal information for marketing purposes.
You have the right to make us correct any inaccurate personal data about you
If the personal information that we hold about your needs to be corrected or updated, we shall make all reasonable efforts to ensure that data collected is current, complete and accurate. If you need to access, correct and/or update your personal information, you may send the request to reservations@nysacavernsantorini.com.
As part of our security measures, we will contact you and conduct the necessary verification measures to process your request. Once we have implemented the necessary corrections, we shall then notify you that your request has been processed and completed
You can object to us using your data for profiling you or making automated decisions about you
You can object to our processing your personal information. Such a request is subject to certain conditions.
You have the right to port your data
We will give you a copy of your data in a mutually acceptable format. We will not do so to the extent that this involves disclosing data about any other individual.
You have the right for your data to be erased
You can do this by asking us to suspend, withdraw, remove or destroy your personal data, if it is no longer necessary for us to hold the data for purposes of your use of our products and services. Such a request is subject to certain conditions.
You have the right to file a complaint regarding our use of your data
Please tell us first, so we have a chance to address your concerns. If we fail in this, you can address any complaint as per applicable law.
You have the right to damages
You have the right to damages arising from inaccurate, incomplete, false, unlawfully obtained or unauthorized use of your personal data by us.
​
How secure is the data we collect?
Your Personal Information is password protected, and any personal Information you provide to the Website is protected from unauthorized disclosure by reasonable technological measures. Information provided is not, however, transmitted via SSL encryption technology. We recommend that you do not divulge your password to anyone. Personal Information may be used for marketing and promotional communications by us. We will not, however, sell or lease your personal information to third parties not associated with us.
​
How long do we store your data?
Generally, we keep your information for the duration of your use of our Services’ use, and, to the extent permitted, after the end of that relationship for as long as necessary to perform the purposes set out in this Notice and to comply with the law.
When we no longer need to use your information, we will remove it from our systems and records or take steps to delete it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which we are subject).
We could keep your Personal data for a longer period on the following cases:
-
For commercial prospecting purposes, for a period of 1 year from the end of the commercial relationship with you, m, or 1 year from your last contact with us, if you reach out to us via our Connect with us form;
-
When we are required to do so under a legal obligation or when data is necessary to establish proof of a right or a contract, your personal data will be archived and kept for the period imposed by the regulations applicable, or for the duration of the applicable legal prescription.
​
Third parties who process your data
In order to fulfill the purposes outlined in this Privacy Notice, we may disclose your personal data to the following parties:
-
Our third party contractors assisting in providing the Services selected by you
-
Professional advisers such as lawyers and auditors;
-
Insurers and credit providers;
-
Authorized third-party services providers including administration processors, technology partners, payment processors and courier services;
-
Banks, credit card companies and their respective service providers as covered by our contracts;
-
Such other party whom you authorize us to disclose your Personal information.
And in order to comply with legal and statutory compliance, we may disclose your personal data:
-
To the extent that we are required to do so by applicable laws, rules, and regulations;
-
In connection with any ongoing or prospective legal proceeding;
-
To any person who we reasonably believe may apply to a court or other competent authority for disclosure of such personal information where, in our reasonable opinion, such court or authority would be reasonably and is likely to order the disclosure of such personal information
​
Privacy Policies of Third-party Websites and Digital Platforms
Our website/application contains hyperlinks and details of third-party websites or digital platforms. We have no control over and are not responsible for, the privacy policies and practices of third parties. We, therefore, advise you to study their privacy policies and use of cookies. Once you leave our website/application, you should check the third-party website’s applicable privacy notice to determine how they will handle any information they collect from you.
​
Cookies
Like most websites, ours uses cookies and other similar technologies, such as local storage, to provide you with a better and more personal user experience. These cookies are safe and secure, and do not contain sensitive information. Unless you adjust your browser settings to refuse cookies, we (and these third parties) will issue cookies when you interact with our website.
How can I block cookies?
You can block cookies by activating a setting on your browser so that cookies are not accepted. You can also delete cookies through your browser settings. Each browser’s website should contain instructions on how you can do this.
If you use your browser settings to disable, reject, or block cookies (including essential cookies), certain parts of our website will not function fully. In some cases, our website may not be accessible at all. Please note that where third parties use cookies, we have no control over how those third parties use those cookies.