1. Information on personal data pertains to the processing by:
Data controller: Book Villa Crete
2. Collection and storage of personal data, as well as nature and purpose of its utilization
a) When you visit the website
When you visit our site www.bookvillacrete.com, the browser used on your device automatically sends information to our site's server. This information is temporarily stored in a log file. The following information is collected and stored without your intervention until their automatic deletion:
- Your IP address,
- Date and time of access,
- The name and URL of the downloaded file,
- The Uniform Resource Locator used to access the webpage (URL),
- The browser you are using and, if applicable, the operating system of your computer, as well as the name of your access provider.
We process this data is processed for the following purposes:
- To ensure a smooth connection to our website,
- To ensure convenient use of our website,
- To assess the security and stability of our system and
- For further organizational purposes.
The legal basis for data processing is Article 6 (1) (c) of GDPR. Our legitimate interest derives from the data collection purposes mentioned above. Under no circumstances shall we use the data we have collected to draw conclusions about you.
b) When you contact us
Given your explicit consent, fill out your full name, your phone number and your email address in our contact form. We store these data as long as necessary to pursue our legitimate interests.
3. Data disclosure
No personal information is disclosed to third parties for purposes other than those listed below.
We shall disclose your personal information to third parties only if:
You have expressly given your consent - In accordance with Article 6 (1) (a) of GDPR
Disclosure is necessary for exercising, claiming or defending the purposes of our legitimate interests and there is no reason to assume that disclosing your data overrides your legitimate interests - in accordance with Article 6 (1) (f) of GDPR
In the event that disclosure is necessary for compliance with a legal obligation - in accordance with article 6 (1) (c) of GDPR
Disclosure is necessary for the performance of a contract with you - in accordance with article 6 (1) (b) of GDPR
To make a site work properly, we sometimes place small data files called “cookies” on your computer. A cookie is a small text file that a website saves on your computer or mobile device when you visit the site.
Cookies store information associated with the specific computer terminal you are using. However, this does not mean that we are aware of your identity.
Cookies are used to make our internet services more enjoyable. For example, we use so-called "session cookies" so that we can see that you have already visited some single pages on our site. These cookies are automatically erased after you leave our site.
Furthermore, to make the site's functioning more user-friendly, we use "temporary cookies" stored on your device for a certain amount of time. On a subsequent visit it is then automatically recognized that you have previously visited us, and we know which input and settings you prefer, so you do not have to re-enter them.
Data processed by cookies are necessary for the protection of the legitimate interests pursued by us or by a third party - in accordance with Article 6 (1) (f) of GDPR.
Most browsers enable cookies by default. However, you can modify your browser setting so that no cookies are stored on your computer or a hint be always displayed before creating a new cookie. However, disabling cookies may prevent you from taking full advantage of the website.
5. Analysis tools
The Tracking-Tools listed below and are used by us are based on Article 6 (1) (f) of GDPR. With Tracking-Tools, we want to ensure a design based on the needs of our website and its constant optimization. We also use Tracking-Tools to statistically record the use of our website and assess it in order to optimize our services. Those interests should be considered justified within the meaning of the above provision.
Data processing objectives and processed data categories are displayed in Tracking-Tools.
aa) Google Analytics
Google Analytics is a web analytics service provided by Google Inc. (https://www.google.com, Amphitheater Parkway, Mountain View, CA 94043, USA, hereafter "Google"). It is used for customizing and continuously optimizing our web pages. In this context, pseudonymous user profiles are created and cookies are used (see section 4 above). The information generated by cookies about the use of this website, such as:
- Browser type / version,
- Operating system used,
- Referral URL (the page you have previously visited),
- Computer host (IP address),
is transferred to a Google server in the USA and stored there. This information is used to assess the use of the website, to generate reports on the activity of the website, to provide other services related to the activity of the website and the use of the internet for market research and web design purposes. This information may be disclosed to third parties if the law so requires or if third parties process such data. Under no circumstances will your IP address be linked to other Google data. IP addresses are anonymous, so that they cannot be matched to a natural person or legal entity (IP masking).
You can prevent cookies from being installed by adjusting the settings on your browser software accordingly. You should be aware, however, that by doing so you may not be able to make full use of all the functions of our website.
You can also prevent the data generated by cookies about your use of the website (incl. your IP address) from being passed to Google, and the processing of these data by Google, by downloading and installing the browser plugin available at the following link: (https://tools. google.com/dlpage/gaoptout?hl=en). For more information on personal data protection associated with Google Analytics, please refer to the Google Analytics Help Center: https://support.google.com/analytics/?hl=en#topic=3544906
ab) Google AdWords Conversion Tracking
In order to record the use of our website statistically and assess it in order to optimize it, we also use Google AdWords Conversion Tracking. Google AdWords places a cookie (see section 4) on your computer if you have visited our website through a Google ad.
These cookies lose their validity after 30 days and are not used for personal identification. If the user visits a certain page of the AdWords client's website and if the cookie has not yet expired, Google and the client will be able to tell that the user clicked on the ad and was forwarded to this page.
Each Google AdWords client gets a different cookie. Thus, cookies cannot be tracked via the website of AdWords clients. The information collected by the “conversion cookies” is used to provide aggregate conversion statistics to AdWords clients who have opted-in for Conversion- Tracking. Clients of AdWords are informed about the total number of users who clicked on their ad and were forwarded to a Conversion-Tracking-Tag page. However, they do not get any information enabling them to identify users personally. If you do not want to participate in the tracking program, you can also refuse the required setting of a cookie - for example, via a browser setting that generally disables the automatic setting of cookies. However, they do not get any information enabling them to identify users personally.
6. Social Media Plug-ins
Facebook, Twitter and Instagram social plugins are enabled by default on our website in order to make it more popular, in accordance with Article 6 (1) (f) of GDPR. This commercial purpose should be regarded as legitimate interest under the provision of the CDPR. The responsibility for this function, which is compatible with personal data protection, must be ensured by the respective providers. Plug-ins are integrated through the so-called "double click" method for the best protection of the website visitors.
On our website, Facebook plugins are used to personalize their use. That's why we use the "LIKE" or "SHARE" button. This is an offer from Facebook.
When you visit a web page that contains such a plugin, your browser opens a direct connection to the Facebook servers. The content of the plugins is transferred from Facebook directly to your browser which then embeds it into the website.
By integrating the plugins, Facebook receives the information that your browser has accessed on the corresponding page of our site, even if you do not have a Facebook account or are not connected to Facebook. This information (including the IP address) is transferred from your browser directly to Facebook in the USA and stored there.
If you are logged into Facebook, Facebook can assign the visit to our website directly to your Facebook account. If you interact with the plugins, for example by pressing the "LIKE" or "SHARE" button, the corresponding information is also transmitted directly to a Facebook server and stored there. The information will also be posted on Facebook and displayed to your Facebook friends.
Facebook may use this information for the purpose of advertising, market research and tailor-made Facebook pages. For this purpose, Facebook uses information such as interest and relationship profiles to evaluate your use of our website in relation to the advertisements displayed on Facebook, to inform other Facebook users about your activities on our website, and to provide other services related to the use of Facebook.
If you do not want Facebook to assign the data collected via our website to your Facebook account, you must log out of Facebook before visiting our website.
Our website includes plugins from the short-message network Twitter Inc. (Twitter). The Twitter plugins (tweet button) can be recognized by the Twitter logo on our website. An overview of tweet buttons can be found here: (https://about.twitter.com/resources/buttons).
When you visit a page of our website that contains this type of plugin, a direct connection is established between your browser and the Twitter server. Twitter receives the information that you have visited our website with your IP address. If you click on the Twitter "tweet button" while logged in to your Twitter account, you can link the contents of our pages to your Twitter profile. This allows Twitter to associate your visit to our website with your user account. Please note that we, as the provider of the internet pages, are not aware of the content of the transmitted data and its use by Twitter.
If you do not want Twitter to be able to associate your visit to our website, please log out of your Twitter account before visiting our website.
Our website uses Instagram social plugins, Instagram LLC., 1601 Willow Road, Menlo Park, CA 94025, United States of America ("Instagram").
Plugins are labeled with the Instagram logo, for example with the Instagram camera icon.
When you visit a page of our website that contains this type of plugin, your browser opens a direct connection to the Instagram servers. The content of the plugins is transferred from Instagram directly to your browser which then embeds it into the website. By integrating the plugins, Instagram receives the information that your browser has accessed on the corresponding page of our site, even if you do not have an Instagram profile or are not connected to Instagram.
This information (including the IP address) is transferred from your browser directly to n Instagram server in the USA and stored there. If you are logged into Instagram, Instagram can assign the visit to our website directly to your Instagram account. If you interact with the plugins, for example by pressing the "Instagram” button, the corresponding information is also transmitted directly to an Instagram server and stored there.
The information will also be published on Instagram and displayed to your contacts there.
If you do not want Instagram to assign the data collected via our website to your Instagram account, you must log out of Instagram before visiting our website.
7. Rights of the data subject
You have the right:
- In accordance with Art. 15 GDPR, to request information about your personal data processed by us. In particular, you can request information on the processing purposes, the category of personal data, the categories of recipients to whom your data has been disclosed, the planned retention period, the rights to rectification, deletion, limitation of processing, or opposition to processing.
- Pursuant to Art. 16 GDPR, to demand the correction of incorrect personal data stored by us immediately.
- In accordance with Art. 17 GDPR, to demand the deletion of your personal data stored, unless processing such data is required for the exercise of the right to freedom of expression and information, for the fulfillment of a legal obligation, for reasons of public interest or for the assertion, exercise or defense of legal claims.
- In accordance with Art. 18 GDPR, to demand the restriction of the processing of your personal data, if the accuracy is disputed, the processing is unlawful or no longer necessary, however, you require the data for the assertion, exercise or defense of legal claims or if you have objected to the data processing in accordance with Art. 21 (1) GDPR.
- Pursuant to Art. 20 GDPR to obtain your personal data provided to us in a structured, common and machine-readable format or to request that it be forwarded to another data controller.
- Pursuant to Art. 7 (3) GDPR, to revoke your once granted consent for your data processing at any time. As a result, we will not be allowed to continue the data processing based on this consent in the future.
- According to Art. 77 GDPR, to complain to a supervisory authority. You can contact the national supervisory authority.
8. Right to object
In accordance with Art. 6 (1) (f) GDPR, if your personal data is processed based on legitimate interests, you have the right to file an objection against the processing of your personal data in accordance with Art. 21 GDPR, provided that there are reasons for this arising from your particular situation or the objection is against marketing. In the latter case, you have a general right of objection, which is implemented by us without specifying any particular situation.
If you would like to exercise your right of revocation or objection, please send an e-mail to email@example.com.
9. Data security
We use the popular SSL (Secure Socket Layer) method within the site visit, in conjunction with the highest level of encryption supported by your browser. In general, this is a 256-bit encryption. If your browser does not support 256-bit encryption, we will use 128-bit v3 technology instead. Whether a single page of our website is encrypted is shown by the closed representation of the key or lock icon in the lower status bar of your browser.
We also take appropriate technical and organizational security measures to protect your data against accidental or intentional manipulation, partial or total loss, destruction or against unauthorized access by third parties. Our security measures are continuously improving in line with the technological developments.