Privacy Policy

1. Purpose

Through this Policy, the company under the corporate name “LA MER HOTEL SOCIETE ANONYME”, headquartered in Chania and owning this website (hereinafter, for the sake of brevity, the “Company”), aims, in its capacity as Data Controller within the meaning of the applicable legislation, to provide the users/visitors of its website with more specific information regarding the processing of their personal data during their browsing and use thereof, which it carries out when necessary on the basis of their relationship and cooperation with the Company.

2. Basic Definitions

«Data Subject» of personal data: The user of the website and any other natural person who comes into contact with our website.

«Personal Data»: Any information that can directly or indirectly identify a natural person (the «Data Subject»), such as full name, postal address, contact details (telephone number, email address), etc. 

«Processing»: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction of personal data that has come or will come to the knowledge of the Company, either directly from you through the website or in the context of your transactional relationship with it.

«Data Controller»: The company under the corporate name «LA MER HOTEL SOCIETE ANONYME», which owns this website and determines the purposes and means of the processing of personal data. 

«Processor»: A natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller. 

«Recipient»: A natural or legal person, public authority, agency or other body to which the personal data are disclosed, whether a third party or not.

«Data Protection Officer, «DPO»: The Data Protection Officer appointed by the Company, in its capacity as Data Controller, who holds the position and performs the duties provided for by the applicable personal data protection legislation.

3. What data we collect, for what purpose and on what legal basis

We collect and process, as the case may be, the following personal data in the following circumstances:

ActivityDataPurposeLegal Basis
Access to our websiteIP address, date and time of access (timestamp-timezone), access provider, browser and browser version, operating system and operating system version, user/device identifierProvision of personalised services to you, proper establishment of connection, system security and stabilitya) Legal obligation
b) Legitimate interest, in the context of securely making our website available to the public and providing services thereto
Contact formName, e-mail address, content of the messageCommunication, management of request/inquiry/complaint and provision of informationa) Our transactional relationship and your specific request
b) Legitimate interest, in the context of serving you
Newsletter subscriptionE-mail addressInformation and promotion of servicesa) Your consent to subscribe
b) Our transactional relationship and your specific request
Reservation requestArrival/departure date, number of nights, number of rooms, number of guests per category (adults, children), rating preference, destination.

Full name, e-mail address, Country, address, City, Postal Code, contact telephone number, any specific requests/instructions, payment details.

NOTE: Your data are entered through the secure environment of the InterContinental Hotels Group (IHG), following redirection, and are governed by the respective Terms and Policies specified therein.
Registration of details and completion of reservationa) Legal obligation
b) Our transactional relationship and your specific request
Cookies(see Cookie Policy)

We are required to inform you that the personal data you provide to us through our website, for the above purposes, are necessary for us in order to serve you optimally and to handle, manage or resolve your request, inquiry or complaint. Therefore, failure to provide your data, as applicable, renders our communication through the website and our overall transactional relationship ineffective and/or impossible.

4. Processing of special categories of personal data

Our Company does not process, through its website, any special categories of your personal data, such as data relating to your racial or ethnic origin, religious or philosophical beliefs, health data, or data concerning your sex life or sexual orientation, as such data are not necessary for us. For this reason, we request that you do not include such data when completing message fields. Otherwise, such data will be processed by us on your own initiative and as an integral part of any request you submit.

5. Data relating to minors

Our website is not intended for natural persons who have not reached eighteen (18) years of age. Therefore, our Company does not process personal data of minors. 

6. Recipients of your data

The personal data we collect from you in the context of our relationship are processed by:

  1. The authorised and appropriately trained competent personnel of our Company, who are bound by strict confidentiality and secrecy obligations.
  2. Partners of our Company to whom, pursuant to Article 28 GDPR, the Company assigns the performance of specific tasks on its behalf (processors) and with whom it has ensured GDPR-compliant processing for the protection of your data, through the execution of agreements and commitments to implement adequate measures, in accordance with the relevant provisions of the GDPR (Articles 28 and 32), including, indicatively and without limitation, third-party partners and companies supporting our website and applications. 
  3. Public bodies and authorities, such as public services and entities, independent authorities, regulatory authorities, the police, competent authorities, public prosecutors, other administrative services, etc., where we are required to do so under the applicable legal framework.

As a rule, we do not transfer your personal data to third countries (outside the EU or EEA) or international organisations that do not ensure an adequate level of protection (such as through an adequacy decision). Any such transfer shall be carried out in accordance with the relevant provisions of the applicable legal framework, in particular Articles 44 et seq. GDPR. 

7. Retention period of your personal data

We retain your personal data for as long as required by the nature and purpose of the relevant processing activity or as prescribed by the applicable legislative and regulatory framework, considering our Company’s legal obligations, our contractual relationship, and any legal claims that may arise therefrom.

In any event, we apply a maximum retention period of twenty (20) years (general limitation period for claims). Upon expiry of the above period, data that are no longer necessary shall be securely and irreversibly deleted

8. Your rights under the GDPR

In any event, you remain in control of the processing of your personal data. Each user, as a data subject, may exercise at any time the rights provided for under the GDPR, in particular Articles 12 to 23 thereof, as well as under the applicable national legislation, including in particular: 

  1. Right to information, communication and transparency regarding the exercise of your rights (Articles 12, 13, 14 GDPR), namely your right to be informed about how your personal data are used (as described in detail in this Privacy Policy).
  2. Right of access. This means that you are entitled to obtain access to the data we process and to receive information regarding how the Company handles such data (Article 15 GDPR).
  3. Right to rectification. This means that you are entitled to request the correction or completion of your personal data if such data are inaccurate or incomplete (Article 16 GDPR).
  4. Right to erasure («right to be forgotten»). This means that you are entitled to request the deletion of some or all of your personal data in specific circumstances, where there is no lawful basis for us to continue the processing or where there is a legal obligation to erase such data (Article 17 GDPR).  
  5. Right to request restriction of processing. This means that you may request the restriction of the processing of your personal data. A valid request will mean that we may store your personal data but may not further process them (Article 18 GDPR). 
  6. Right to data portability. This allows you to obtain and reuse the personal data you have provided to us for your own purposes across different services. You are entitled to receive and transfer an electronic copy of your personal data easily and to request that we transfer such data to another controller (Article 20 GDPR).
  7. Right to object to the processing of your personal data. This means that you may request that we no longer process your data unless we demonstrate compelling legitimate grounds requiring the continuation of such processing (Articles 21 and 22 GDPR).   
  8. Right to withdraw your consent previously given (Article 7(3) GDPR) at any time for processing activities based on consent. The lawfulness of the processing of your data prior to the withdrawal of your consent shall not be affected by such withdrawal.

You also have the right to lodge a complaint with the competent supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement, if you consider that the processing of your personal data infringes the GDPR (Article 77 GDPR) and that your request has not been adequately addressed by us. In Greece, the competent Supervisory Authority is the Hellenic Data Protection Authority (www.dpa.gr ).

9. How to exercise your rights

You may exercise your rights either by sending an e-mail to dataprotection@gelasakis.com or by sending a postal letter to the registered office of our Company.

Our Company shall make every effort to take the required actions within one (1) month from the date of receipt of your request, unless the activities required to satisfy the request involve particularities and/or complexities, in which case the Company reserves the right to extend the completion period. In any event, you will receive information regarding the progress of your request within one (1) month of its submission.

10. Security of the processing of personal data

Our Company takes, among other things, adequate and appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with processing, particularly against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed, as well as to safeguard both technical and physical security in accordance with Article 32 GDPR. The Company maintains relevant Policies and generally complies with the principles relating to processing in accordance with the GDPR (Article 5 GDPR), ensuring the availability, integrity and confidentiality of your data.

11. Social Media

Our Company uses the following social media pages: Instagram, Facebook, Pinterest.

With regard to certain processing activities, we and the controllers of the above social media platforms act as Joint Controllers of your data within the meaning of Article 26 GDPR. As regards the processing of data by the controllers of the social media platforms, we can exercise only limited influence. Therefore, we act within the scope of the possibilities available to us and in accordance with the applicable personal data protection legislation. 

The controller of each social media platform manages the overall information technology infrastructure of the respective service, implements its own technical and organisational data protection measures, and maintains its own relationship with you as a user and, therefore, as a Data Subject (provided that you are a registered member of the relevant social media service).

For further information regarding the processing of your data by the providers of social media platforms and, in general, regarding your rights, please refer to the relevant Privacy/Data Protection Policies of each respective provider.

The data you provide when visiting our social media pages, such as comments, videos, images, “likes”, public messages, etc., are published on the social media platform that you choose and are not used or processed by us for any purposes other than providing information to you and serving you when you wish to contact us through such means.

The above processing of your personal data is carried out on the basis of Article 6(1)(f) GDPR, in the context of providing our services to you in the best possible manner.

12. Specific statements of the Company

  1. The Company declares that it shall not be liable for any damage (direct, indirect, actual or consequential) that may be caused to the visitor in connection with the website or its use. The visitor is solely responsible for protecting their system against viruses and other malicious software. 
  2. The Company declares that it does not make decisions or carry out profiling based on automated processing of your data.
  3. The Company declares that this Privacy Policy may be amended at any time, however, the updated version will always be published.. 
  4. The Company declares that no other use of the visitor’s personal data shall be made for purposes other than those stated herein without prior notice to, and where required, consent from, the visitor.

Last updated: June 2026