Privacy Policy
Last updated: 2026-07-21
Data controller
The data controller for this website is NISOS KEA I.K.E., Epar.Od. Limaniou Korissias-Keas, Korissia, Kea 84002, Greece.
Contact for any data-protection matter: nisoskea2023@gmail.com · tel. +30 22880 28121. We have not appointed a Data Protection Officer: the scale and nature of the processing do not require one under Art. 37 GDPR.
What this policy covers
This policy concerns the website. The site is static and informational: it has no contact form, user accounts, newsletter, online shop or online bookings. There is nothing to fill in, and we collect no data you submit.
If you phone or email us — which is exactly where the site’s links lead — we then process what you tell us (your name, phone, date and party size for a table, say), solely to answer you or hold the table. That does not pass through the website and lands in none of its databases.
Visiting the site does not constitute “acceptance” of processing: where consent is required we ask for it explicitly, and you can withdraw it with one click.
What we process, why, and on what legal basis
The complete list of processing connected to the website:
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Operation & security of the site | Technical logs kept by the hosting provider: IP address, browser type, page, timestamp | Legitimate interest — Art. 6(1)(f) | Held by the provider (Vercel) for a limited technical period. We do not export, store or link them to any person. |
| Aggregate traffic statistics | Page views and link clicks, without cookies and without a persistent device identifier | Legitimate interest — Art. 6(1)(f) | Aggregate figures only. There is no individual record to delete. |
| Showing the Google map on the contact page | IP address and device data, processed by Google | Consent — Art. 6(1)(a) | Determined by Google. Nothing is sent until you load the map. |
| Answering your phone call or email | Whatever you give us: name, phone or email, details of your request or booking | Legitimate interest / pre-contractual steps — Art. 6(1)(f) and (b) | As long as needed to answer you or serve the booking, plus any period tax law imposes on receipts. |
What we do not do
Just as important as what we do, so it is stated plainly:
- We do no profiling and take no decisions about you by automated processing (Art. 22 GDPR).
- We do not sell, rent or trade data with ad networks or data brokers.
- We send no newsletter and run no promotional messaging through the site — there is nothing to subscribe to.
- We collect no special categories of data through the site (health, allergies, ethnicity, beliefs). If you mention an allergy on the phone, we use it only to serve you safely at your table.
- We do not address minors and do not knowingly seek their data; the site asks no one for data in any case.
- We use no social plug-ins, pixels or external fonts that would track you.
Who else sees the data
We pass no data to third parties for their own purposes. We rely on the following providers:
- Vercel Inc. (USA) — hosting and cookieless statistics, as a processor acting on our behalf.
- Google Ireland Ltd — only if you load the map; Google then acts under its own policy and responsibility.
- Where applicable, our accountant and public authorities, when tax or other law requires it, or to establish and defend legal claims.
Transfers outside the EEA
Hosting runs on infrastructure with an EU presence, but the provider is US-based and access from there cannot be excluded. Such transfers are covered by the European Commission’s Standard Contractual Clauses and/or the EU-US Data Privacy Framework. You may request a copy of the relevant safeguards at nisoskea2023@gmail.com.
Security
The site is served only over HTTPS (TLS encryption) and is static: there is no database, form or login area to breach, and no customer file on it. That simplicity is our main security measure — we do not store what we do not need.
No transmission over the internet is perfectly secure and we give no absolute guarantee. In the event of a breach posing a risk to your rights, we notify the Authority and you as Arts. 33-34 GDPR require.
Your rights
As a data subject you have the following rights:
- Information and access — to learn whether we process data about you, which, why, and to obtain a copy.
- Rectification — to have inaccurate data corrected or incomplete data completed.
- Erasure (“right to be forgotten”) — where no lawful ground for keeping it remains.
- Restriction of processing — in certain cases, instead of erasure.
- Objection — to processing based on our legitimate interest, on grounds relating to your situation.
- Withdrawal of consent — at any time, without affecting the lawfulness of what came before. For the map this is one click in the Cookie Policy.
- Portability — to receive the data you gave us in a structured, commonly used format, where applicable.
How to exercise your rights
Send your request to nisoskea2023@gmail.com or call +30 22880 28121. We reply free of charge, within one month at the latest; if the request is complex the deadline may be extended by two months and we will tell you within the first month.
We may need to verify your identity before replying, so that your data is not handed to someone else. Note that because the website collects no identifying details, in most cases we hold no data to match to you.
Right to complain
If you believe the processing of your data breaches the law, you may complain to the Hellenic Data Protection Authority: 1-3 Kifisias Ave., 115 23 Athens · tel. +30 210 6475600 · contact@dpa.gr. We would nonetheless be glad if you contacted us first.
Links to third parties
The site links to external pages (Instagram, Google, press coverage). These are plain links: they load nothing and reveal nothing until you click them. Once you leave here, the third party’s privacy policy applies, for which we are not responsible.
Changes to this policy
If the processing changes — a booking form or newsletter being added, for instance — we will update this policy first and, where needed, ask for your consent again. The date of the last update is shown at the top of this page. See also the Cookie Policy.
Governing law
Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019 apply, together with the rest of Greek and European data-protection law.