Privacy Notice
Last Updated: 23/03/2021

At Rocabella Mykonos Hotel, we are committed to protecting and respecting your privacy. Please read
this notice as it contains important information about how we use personal data that we collect from you
or that you provide to us.

Information & Consent

This Privacy Notice describes how we collect, use, process, and disclose your information, including
personal information about you (hereinafter, the “User”), in conjunction with your access to and use of
our booking system.

By reading this Privacy Notice, the user is hereby informed on how we collect, process and protect
personal data furnished through the booking engine.

The User must carefully read this Privacy Notice, which has been written clearly and simply, to facilitate
its understanding, and to freely and voluntarily determine whether they wish to provide their personal
data, or those of third parties, to Rocabella Mykonos Hotel.

When this notice mentions “booking system,” “booking engine,” “system,” “website,” “platform,” “app,”

“webapp,” “services,” “online services,” it refers to all pages and functions under https://www.rocabella- unless specified otherwise.

By accessing the platform or providing information, you agree to our privacy practices as set out in this
privacy statement. We may change this notice from time to time. You should check this notice frequently
to ensure you are aware of the most recent version.


When this notice mentions “we,” “us,” or “our,”, “data controller,”, “controller,”, it refers to Rocabella
Mykonos Hotel.

Obligatory nature of providing the data

The data requested in the forms accessible from the booking engine are, in general, mandatory (unless
specified otherwise in the required field) to meet the stated purposes. Accordingly, if they are not
provided or are not provided correctly, we will be unable to process the request.

Personal data we collect and process

This will include:
1. personal information about you which we ask you for (e.g. your name, address, and email address)
when you make a booking from our booking engine;
2. financial details in order to process your booking when we require pre-payment;
3.details of transactions you carry out through our booking engine and details of the fulfilment of your

We grant permission to our data processor:

1. to use your personal information for reserving rooms and/or other services for you at Rocabella
Mykonos Hotel
2. to pass on your financial details to Rocabella Mykonos Hotel and/or appropriate third party (for
example, credit card company) for the purpose of confirming or paying for a booking;
3. to use your information for marketing purposes (where you explicitly agree to this); and
4. to pre-complete forms and other details on our website to make your next visit to our booking engine
easier (e.g. when amending or cancelling a booking).

Social Login:

In the event of registration and/or access through a third-party account, we may collect and access
certain information of the User’s profile from the corresponding social network, solely for internal
administrative purposes and/or for the purposes indicated above.

Third-party data (e.g. book for a friend)

In the event that the User provides third-party data, they declare that they have the third party’s consent
and undertake to provide the interested party -the data holder- with the information contained in this
Privacy Notice, duly exonerating us and our data processor from any liability in this regard. However, we
may carry out the necessary verifications to verify this fact, adopting the corresponding due diligence
measures, in accordance with the data protection regulations.

Sensitive Data

Unless specifically requested, we ask that you not send us, and you not disclose, on or through the
Services or otherwise to us, any Sensitive Personal Data (e.g., social security numbers, national
identification number, data related to racial or ethnic origin, political opinions, religion, ideological or
other beliefs, health, biometrics or genetic characteristics, criminal background, trade union
membership, or administrative or criminal proceedings and sanctions).

Use of Services by Minors

The Services are not directed to individuals under the age of eighteen (18), and we request that they not
provide Personal Data through the Services.

Purpose of processing personal data

Depending on the User’s requests, the personal data collected will be processed in accordance with the
following purposes:
1. To manage the bookings made, including payment management (where applicable) and the
management of the user’s requests and preferences.
2. To manage registration in loyalty or membership programs, as well as obtaining and redeeming
3. To manage the User’s contact requests with us through the channels provided to this end.
4. To manage the sending of personalized commercial communications from us, by electronic and/or
conventional means, in cases in which the User expressly consents.
5. To manage the provision of the contracted accommodation service, as well as additional services.
6. To manage surveys and/or evaluations regarding the quality of the services provided by us and/or the
perception of its image as a company.

Data Retention

We will retain your Personal Data for the period necessary to fulfill the purposes outlined in this Privacy
Notice unless a longer retention period is required or permitted by law or if the User requests their
withdrawal from us, opposes or revokes their consent.

The criteria used to determine our retention periods include:
1. The length of time we have an ongoing relationship with you and provide the Services to you (for
example, for as long as you have an account with us or keep using the Services or if you have a
booking that has not yet been fulfilled)
2. Whether there is a legal obligation to which we are subject (for example, certain laws require us to
keep records of your transactions for a certain period of time before we can delete them)
3. Whether retention is advisable considering our legal position (such as, for statutes of limitations,
litigation or regulatory investigations)

Legitimate interest for processing your data

The data processing required in fulfilment of the aforementioned purposes that require the User’s
consent cannot be undertaken without said consent.
Likewise, in the event that the User withdraws their consent to any of the processing, this will not affect
the legality of the processing carried out previously.
To revoke such consent, the User may contact us through the appropriate channels.
By the same token, in those cases in which it is necessary to process the User’s data for the fulfilment of
a legal obligation or for the execution of the existing contractual relationship between us and the User,
the processing would be legitimized as it is necessary for compliance with said purposes.

Data Disclosure

We will use and disclose Personal Data as we believe to be necessary or appropriate:
1. to comply with applicable law, including laws outside your country of residence;
2. to comply with legal process;
3. to respond to requests from public and government authorities, including authorities outside your
country of residence and to meet national security or law enforcement requirements;
4. to enforce our terms and conditions;
5. to protect our Operations;
6. to protect the rights, privacy, safety or property of our own, you or others; and
7. to allow us to pursue available remedies or limit the damages that we may sustain.
We may use and disclose Other Data for any purpose, except where we are not allowed to under
applicable law. In some instances, we may combine Other Data with Personal Data (such as combining
your name with your location). If we do, we will treat the combined data as Personal Data as long as it is

User’s Responsibility

The User:
Guarantees that they are of legal age or legally emancipated, where applicable, fully capable, and that
the information furnished to us is true, accurate, complete and up-to-date. For these purposes, the User
is responsible for the truthfulness of all the data communicated and will keep the information updated,
so that said data reflects their actual situation.
Guarantees that he/she has informed third parties on whose behalf he/she has provided data, where
applicable, of the aspects contained in this document. Also guarantees that he/she has obtained the
third party’s authorization to provide their data to us for the purposes indicated.
Will be responsible for false or inaccurate information provided through the Website and for damages,
whether direct or indirect, that this may cause to us or third parties.

Exercise of Rights

The User may contact us at any time free of charge, to:
1. To obtain confirmation about whether or not personal data concerning the User are being processed
by us.
2. To access their personal details.
3. To rectify any inaccurate or incomplete data.
4. To request the deletion of their personal data when, among other reasons, the data are no longer
necessary for the purposes for which they were collected.
5. To confirm revocation of consent.
6. To obtain from us the limitation of data processing when any of the conditions provided in the data
protection regulations are met.

Security Measures

We will process the User’s data at all times in an absolute confidential way and maintaining the
mandatory duty to secrecy with regard to said data, in accordance with the provisions set out in
applicable regulations, and to this end adopting the measures of a technical and organizational nature
required to guarantee the security of their data and prevent them from being altered, lost, processed or
accessed illegally, depending on the state of the technology, the nature of the stored data and the risks
to which they are exposed.