Privacy Notice

Last updated: June 30, 2026

This Privacy Notice explains how personal data is collected, used, stored, and disclosed in connection with La Maison Paros, including the website, the direct booking flow, related guest communications, and the administration of reservations.

By using the website or submitting personal data through the booking process, you acknowledge that your information will be processed as described in this Privacy Notice.

1. Identity of the Data Controllers

For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the data controllers are:

Georgopoulos Sotirios

Skiathou 32 Lagonisi

19010, Athens

Greece

Email: info@lamaison.gr

and

Maria Papadimitriou

Skiathou 32 Lagonisi

19010, Athens

Greece

Email: info@lamaison.gr

For the purposes of this Privacy Notice, the above persons act as joint controllers to the extent that they jointly determine the purposes and means of processing personal data relating to accommodation bookings, guest administration, payment handling, and related communications.

2. Scope of This Notice

This Privacy Notice applies to personal data processed through:

- the La Maison in Paros website;

- the direct booking pages and booking administration system;

- booking-related communication by email;

- payment and reservation workflows connected to the accommodation services.

3. Personal Data We Collect

We may collect and process the following categories of personal data:

- identification data, such as guest name;

- contact data, such as email address;

- booking data, such as apartment selected, check-in date, check-out date, number of guests, booking status, cancellation data, and related reservation details;

- payment-related data necessary to process or verify a reservation or payment status;

- communication data contained in messages sent by guests;

- technical data generated through the use of the website and booking system, such as request and system logs where necessary for security, administration, and troubleshooting.

We ask that you do not send special category or sensitive personal data unless specifically requested and legally necessary.

4. Purposes of Processing

Personal data is processed for the following purposes:

- to receive, manage, confirm, and administer bookings;

- to process payments, deposits, refunds, and balance reminders where applicable;

- to communicate with guests before, during, and after a stay;

- to manage cancellations, booking modifications, and guest requests;

- to maintain booking records and internal reservation administration;

- to protect the property, booking system, guests, and controllers against misuse, fraud, abuse, unauthorized transactions, or security incidents;

- to comply with legal, tax, accounting, and regulatory obligations;

- to establish, exercise, or defend legal claims where necessary.

5. Legal Bases for Processing

We process personal data on one or more of the following legal bases under Article 6 GDPR:

- processing is necessary to take steps at the request of the data subject before entering into a contract;

- processing is necessary for the performance of a contract;

- processing is necessary for compliance with a legal obligation;

- processing is necessary for the purposes of legitimate interests pursued by the controllers, including booking administration, fraud prevention, property protection, recordkeeping, and service integrity, except where such interests are overridden by the rights and freedoms of the data subject;

- where applicable, processing is based on consent.

Where consent is relied upon, it may be withdrawn at any time, without affecting the lawfulness of processing carried out before withdrawal.

6. Payment Processing

Payments are processed through PayPal. In connection with a booking, relevant payment and transaction information may be processed by PayPal in accordance with PayPal’s own privacy terms and legal obligations.

We do not store full payment card details on our own systems.

7. Recipients and Service Providers

We may share personal data, where necessary, with service providers and processors supporting the operation of the website, booking process, communications, and technical infrastructure. These may include:

- Vercel, for hosting and serving the booking application and administrative booking interface;

- Squarespace, in connection with the main website and associated website services where applicable;

- PayPal, for payment processing and payment-related transaction handling;

- Google services, including Google Calendar, where used for booking administration and reservation scheduling;

- email and technical infrastructure providers reasonably necessary to deliver booking-related communications and system functionality.

Such providers receive only the data reasonably necessary for their role and process data subject to their own terms or under appropriate contractual safeguards where applicable.

8. Booking Administration and Internal Access

Booking information is processed within the booking administration environment, including the reservation management area used to administer bookings, cancellations, reminders, and guest communications. Access is limited to what is reasonably necessary for accommodation management, administration, legal compliance, and operational security.

9. Data Retention

Personal data is retained only for as long as necessary for the purposes for which it was collected, including:

- for the duration of the booking lifecycle;

- for a reasonable period thereafter in order to manage guest support, disputes, refunds, chargebacks, cancellations, and follow-up matters;

- for any longer period required under applicable tax, accounting, legal, or regulatory obligations.

When personal data is no longer necessary, it will be deleted, anonymised, or restricted as appropriate and reasonably feasible.

10. International Transfers

Some service providers may process personal data outside Greece or outside the European Economic Area. Where such transfers take place, they will be carried out subject to appropriate safeguards required under applicable data protection law.

11. Disclosure Required by Law or Protection of Rights

We may disclose personal data where necessary:

- to comply with applicable law, regulation, legal process, or a lawful request by public authorities;

- to protect the rights, property, safety, or legitimate interests of the controllers, guests, third parties, or the accommodation;

- to investigate fraud, abuse, security incidents, unlawful conduct, or misuse of the booking system;

- to establish, exercise, or defend legal claims.

12. Data Subject Rights

Subject to applicable law, you may have the right to:

- request access to your personal data;

- request rectification of inaccurate or incomplete personal data;

- request erasure of your personal data;

- request restriction of processing;

- object to certain processing;

- request portability of your data where applicable;

- withdraw consent, where consent is the legal basis for processing.

Requests may be sent to: info@lamaison.gr

You also have the right to lodge a complaint with the competent supervisory authority.

13. Security Measures

We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access, taking into account the nature of the data and the risks involved. However, no internet-based system can be guaranteed to be completely secure.

14. Data Accuracy and Third-Party Data

Guests are responsible for ensuring that the personal data they provide is accurate, complete, and up to date.

If a person provides personal data relating to another individual, they are responsible for ensuring that they are entitled to do so and, where required, that the relevant individual has been informed of this Privacy Notice.

15. Children

The website and booking services are not directed at children acting independently. Personal data relating to minors should only be provided by a parent, guardian, or other person legally authorised to do so where necessary in the context of a booking.

16. Changes to This Privacy Notice

We may update this Privacy Notice from time to time. The most recent version will always be posted on the website with the revised update date.

17. Contact

For privacy-related requests or questions, you may contact:

info@lamaison.gr