Privacy Policy
This Privacy Policy explains how Fanes Breeze Lodges I.K.E. handles the personal data of visitors and guests of the website faneslodges.com. We process personal data in accordance with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and applicable Greek data protection law. We take your privacy seriously and collect only the data we genuinely need. Last updated: 29 June 2026.
1. Data Controller and Data Protection Contact
The data controller is:
Fanes Breeze Lodges I.K.E. (a Greek Private Company / Ιδιωτική Κεφαλαιουχική Εταιρεία)
Address: Fanes, 851 06, Rhodes, Greece
Registration number: 174728920000
Greek tax number (AFM): 802345860
Email: milan@faneslodges.com
Phone: +420 724 315 369
Website: faneslodges.com
Data Protection Officer (DPO): Given the nature and scale of our activities, we are not legally required to appoint a Data Protection Officer, and we have not appointed one. For all matters concerning the protection of your personal data and the exercise of your rights, please contact us at our dedicated address: privacy@faneslodges.com (or milan@faneslodges.com).
This address is monitored and used to handle data subject requests; it is not merely a general booking inbox.
2. What Data We Process, Why, and on What Legal Basis
Below we set out each processing purpose, the categories of data, and the legal basis under Art. 6(1) GDPR. For purposes based on legitimate interest, we also state the specific interest; you have the right to object to such processing (see Section 9).
Bookings and performance of the accommodation contract: first and last name, email, phone, country, dates of stay, number of guests, and notes. Purpose: to handle and manage your reservation and provide the accommodation. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
Payments: data necessary to process the deposit payment via the Stripe payment gateway. Purpose: to take and reconcile payment. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Card details are entered directly into Stripe; we never see, access, or store your card numbers.
Contact form and enquiries: name, email, subject, and message. Purpose: to respond to your enquiry and, where applicable, to take steps at your request prior to entering into a contract. Legal basis: our legitimate interest in answering enquiries (Art. 6(1)(f) GDPR) and/or performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR). The legitimate interest is proper and timely communication with prospective and current guests.
Reservation enquiries via Telegram and AI processing: voice messages, photos, and text that you send us through our Telegram reservation bot, including the data they contain (name, dates, number of guests, free text). Purpose: to transcribe and structure your enquiry and turn it into a reservation. Legal basis: our legitimate interest in processing enquiries efficiently and accurately (Art. 6(1)(f) GDPR), and taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR). See Section 5 (Automated and AI Processing).
Newsletter: email address. Purpose: to send you marketing communications. Legal basis: consent (Art. 6(1)(a) GDPR), given via double opt-in. You may unsubscribe at any time.
Synchronisation with online travel agencies (OTAs): booking data received from platforms such as Booking.com or Airbnb. Purpose: to match and manage bookings across channels. Legal basis: our legitimate interest in consistent availability management and avoiding overbooking (Art. 6(1)(f) GDPR) and performance of the accommodation contract (Art. 6(1)(b) GDPR). See also Section 12 (Data received from OTAs).
Security and abuse prevention: IP address and browser information (user agent), technical logs. Purpose: website security and prevention of fraud and abuse. Legal basis: our legitimate interest in protecting the website and its users from misuse (Art. 6(1)(f) GDPR).
Accounting and tax obligations: booking, payment, and invoice data. Purpose: bookkeeping and compliance with tax duties. Legal basis: compliance with a legal obligation (Art. 6(1)(c) GDPR) under Greek accounting and tax law.
3. Processors and Other Recipients
To operate the website and to handle bookings, payments, and communication, we use the processors listed below, who may process your personal data on our behalf under a data processing agreement. Access to your data is granted only to the extent necessary for the relevant purpose, and each processor is contractually bound to protect it.
Stripe — payment processing and fraud prevention (Ireland / US).
Supabase — database, authentication, and storage hosting (EU).
Hostaway — channel manager and synchronisation with online travel agencies (OTAs).
Resend — sending of transactional emails.
Google (Gemini) — AI transcription and structured processing of reservation enquiries (extraction of details from photos). Transfer to the US (see Sections 4 and 5).
Telegram — operation of the reservation chatbot through which you send us enquiries (outside the EEA).
Meta / WhatsApp (WhatsApp Business / Cloud API) — guest messaging (US).
Coolify / Hetzner — website hosting and server infrastructure (Germany).
We use Open-Meteo to display weather information; no personal data is sent to this service.
We may also disclose your personal data to public authorities where required to do so by law.
4. International Transfers
Most of our processors process data within the European Union / European Economic Area. Transfers outside the EEA, in particular to the United States, occur with the following processors:
Stripe (payment processing) — transfer to the US.
Google / Gemini (AI processing of enquiries) — transfer to the US.
Meta / WhatsApp (guest messaging) — transfer to the US.
Telegram (reservation chatbot) — processing outside the EEA.
Where such a transfer takes place, it is safeguarded in accordance with the GDPR by appropriate measures: in particular the European Commission's adequacy decision under the EU–US Data Privacy Framework, where the recipient is certified, and/or the European Commission's Standard Contractual Clauses under Art. 46 GDPR, or other recognised mechanisms.
You can request a copy of the relevant safeguards, or information on where they are available, at privacy@faneslodges.com.
5. Automated and AI Processing
We process the enquiries you send us through our Telegram reservation bot with the help of artificial intelligence tools, so that we can turn them into a reservation quickly and accurately:
Voice messages are transcribed into text using an automatic speech-recognition service (Whisper).
From photos you send us (for example handwritten notes or booking details), we automatically extract the relevant details using Google Gemini Vision.
Purpose: to speed up and improve the accuracy of processing reservation enquiries. Legal basis: our legitimate interest in efficient enquiry handling and taking steps at your request prior to entering into a contract (Art. 6(1)(f) and (b) GDPR).
We do not take any decision producing legal or similarly significant effects solely by automated means. Specifically, there is no automated decision-making or profiling within the meaning of Art. 22 GDPR — the output of the AI processing is always reviewed and confirmed by a human before a reservation is accepted.
Transcription and extraction take place only to the extent necessary to handle your enquiry; the input data is processed by the processors named above (see Section 3) and may be transferred to the US (see Section 4).
6. Cookies
We use strictly necessary cookies only: a session cookie for the admin login (Supabase) and a cookie for the payment process (Stripe checkout).
We do not use any analytics or marketing cookies, and we do not use any third-party trackers.
Because we only use strictly necessary cookies, this notice is purely informational — there is no tracking for you to opt out of. Full details are in our separate Cookies Policy.
7. Data Retention
We keep personal data only for as long as is necessary for the relevant purpose, or for as long as required by law. The following periods apply per category:
Booking records and accounting / tax documents: for the period required by Greek accounting and tax law, typically up to 10 years.
Newsletter email address: until you unsubscribe (withdraw your consent).
Contact-form enquiries and related communication: for as long as necessary to handle the enquiry and any follow-up, typically 12–24 months, unless we need to keep it longer (e.g. because a booking arises).
Input data from Telegram reservation enquiries (voice, photos, text): we delete it once it has been turned into a reservation, unless it needs to be retained as part of the booking records.
Technical logs and security data: short-term, typically a matter of months.
Payment data: for the period set by the payment gateway provider (Stripe) and by tax law.
Once the applicable retention period ends, we delete or anonymise the data.
8. Whether Providing Data Is Required
Providing your name, contact, and payment details is necessary to conclude and perform the accommodation contract. Without this data, we cannot accept your reservation or provide the accommodation.
Providing your email address for the newsletter is entirely voluntary and consent-based; not providing it has no consequences for your reservation or your stay.
9. Your Rights
In relation to the processing of your personal data, you have the following rights under the GDPR:
The right of access to your personal data (Art. 15).
The right to rectification of inaccurate or incomplete data (Art. 16).
The right to erasure (the right to be forgotten) (Art. 17).
The right to restriction of processing (Art. 18).
The right to data portability (Art. 20).
The right to object to processing based on legitimate interest (Art. 21), including processing for direct marketing purposes.
The right to withdraw consent: where processing is based on consent (the newsletter), you may withdraw it at any time (Art. 7(3) GDPR). Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. You can withdraw newsletter consent by clicking the unsubscribe link in every email or by writing to privacy@faneslodges.com.
The right to lodge a complaint with a supervisory authority (Section 11).
10. How to Exercise Your Rights
You can exercise your rights by contacting us by email at privacy@faneslodges.com (or milan@faneslodges.com) or by phone at +420 724 315 369.
We will handle your request without undue delay and within the time limits set by the GDPR. To verify your identity, we may ask you for additional information.
You can unsubscribe from the newsletter at any time by clicking the unsubscribe link included in every email we send.
11. Right to Lodge a Complaint
If you believe that the processing of your personal data infringes your rights, you have the right to lodge a complaint with a supervisory authority.
Because the controller is established in Greece, the competent (lead) supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), website: dpa.gr.
You may also lodge a complaint with the supervisory authority in the EU member state of your habitual residence or of the place where the alleged infringement occurred.
12. Data Received from Online Travel Agencies (OTAs)
If you book your stay with us through an online travel agency (OTA), such as Booking.com or Airbnb, we receive your personal data from that platform (via the Hostaway channel manager) rather than directly from you.
The categories of data received in this way typically include: first and last name, contact details to the extent provided by the platform, the dates and details of the booking, and the number of guests. The source of this data is the relevant booking platform.
We process this data to handle and manage your reservation on the same legal basis and for the same retention periods as for direct bookings. This Privacy Policy also applies to data received in this way.
13. Contact
For any question regarding the protection of your personal data, please contact us:
Fanes Breeze Lodges I.K.E.
Fanes, 851 06, Rhodes, Greece
Data protection email: privacy@faneslodges.com
General email: milan@faneslodges.com
Phone: +420 724 315 369