8. Privacy Policy (GDPR)
8.1. Data Controller
The controller of the personal data collected through the Website is:
[Nadia Stamatoukou full name or business name]
[Business address]
[Contact phone number]
[Contact email]
8.2. What Data We Collect
Depending on how the Website is used, we may collect:
- Contact details: full name, email, phone number, country/city.
- Booking / participation data: details related to the retreat, workshop or course you choose, dates, accommodation preferences where applicable.
- Billing / payment data: billing details, such as full name/business name, tax identification number and address, through third-party payment providers where applicable.
- Communication data: content from contact forms, emails or other communication channels.
- Technical data: IP address, browser type and version, device information, cookies and usage statistics through analytics tools.
8.3. Purposes of Processing
We process your personal data for the following purposes:
- Managing contact requests and responding to questions.
- Managing bookings and participation in retreats, workshops, classes and remote programs.
- Issuing documents and complying with tax and accounting obligations.
- Sending updates related to programs in which you have registered to participate.
- Sending newsletters and offers, provided that you have given your consent.
- Improving the Website, analyzing usage statistics and strengthening system security.
8.4. Legal Basis for Processing
Data processing is carried out, depending on the case, on the basis of:
- performance of a contract or pre-contractual steps,
- compliance with legal obligations,
- legitimate interest in operating, improving and securing the Website,
- the user’s consent, especially for newsletters and marketing communications.
8.5. Who Has Access to the Data
Access to the data is limited to authorized persons working with the Company, such as Website administrators, accountants or retreat organization partners, to the extent necessary for the provision of services.
Data may be transferred to third-party service providers, such as hosting providers, email marketing platforms and payment providers, with whom the necessary processing agreements have been concluded in accordance with the GDPR.
We do not sell, rent or assign your personal data to third parties for their own independent commercial use.
8.6. International Transfers
If data is transferred outside the European Economic Area (EEA), this will take place only with appropriate safeguards, such as Standard Contractual Clauses or another lawful basis under the GDPR.
8.7. Data Retention Period
Personal data is retained only for as long as necessary to serve the purposes of processing.
Data related to transactions and tax obligations is retained for the period required by applicable legislation.
Data retained on the basis of consent, such as newsletter subscriptions, is deleted when you withdraw your consent or request its deletion.
8.8. Cookies & Similar Technologies
The Website uses cookies and similar technologies to improve the browsing experience, analyze traffic and, where applicable, support marketing activities.
On your first visit to the Website, a relevant cookie consent banner appears, through which you can accept or configure your preferences.
You can also delete or disable cookies through your browser settings; however, this may affect certain Website functions.
8.9. Rights of the Data Subject
Under the GDPR, you have the following rights:
- Right of access to your personal data.
- Right to rectify inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”), where applicable.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing, especially for direct marketing purposes.
- Right to withdraw consent at any time, where processing is based on consent.
To exercise your rights, you can contact us at: [contact email].
You also have the right to lodge a complaint with the Hellenic Data Protection Authority through the website
www.dpa.gr.
8.10. Data Security
We take appropriate technical and organizational security measures to protect your personal data from unauthorized access, alteration, loss or destruction.
Although every possible effort is made to protect data, no method of transmission over the internet or electronic storage method can guarantee absolute security.
8.11. Minors
The Website’s services are not intended for persons under the age of 18 without the consent of a parent or guardian.
If it is found that personal data of a minor has been collected without lawful consent, that data will be deleted as soon as possible.