GDPR Compliance Statement

Divider icon

1. Data Controller

Company Name: Guestin EE
Business Activity: Web Portal Content Services
Registered Office: Leoforos Dimokratias 4-6, Neo Psychiko, 15451, Greece
Tax ID (AFM): 803219460 – Tax Office: KEFODE Attikis
Company Registration No. (GEMI): 192371503000
Phone: +30 697 028 2898
Data Protection Email: info@guestin.com

2. Scope & Legal Framework

This Statement describes how Guestin EE (“Guestin”, “we”) collects, uses and protects personal data in connection with the Guestin™ platform, which connects accommodation providers (hotels and short-term rentals) with local cafés for the provision of breakfast via QR code. Processing is governed by Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019, as in force.
Guestin is committed to upholding the fundamental principles of the GDPR:
  • Lawfulness, fairness and transparency
  • Purpose limitation
  • Data minimisation
  • Accuracy
  • Storage limitation
  • Integrity and confidentiality
  • Accountability

3. Categories of Data & Purposes of Processing

Guestin processes data of accommodation guests (e.g. full name, booking/room details, breakfast preferences) as well as data of partner businesses (accommodation providers, cafés), solely for the following purposes: operation and management of the platform, issuance and redemption of breakfast vouchers, invoicing and settlement of transactions, customer support, and improvement of the service provided.

4. Technical & Organisational Security Measures

Guestin implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
  • Encryption of data in transit and at rest
  • Role-based access control
  • Multi-Factor Authentication
  • Audit logging and activity monitoring
  • Regular backups
  • Periodic penetration testing

5. Data Protection Impact Assessment (DPIA)

Where required under Article 35 GDPR, Guestin carries out a Data Protection Impact Assessment prior to commencing new processing activities that are likely to result in a high risk to the rights and freedoms of natural persons.

6. Data Transfers Outside the EU/EEA

Any transfer of data outside the European Union/European Economic Area is carried out exclusively on the basis of:
  • Standard Contractual Clauses (SCCs)
  • European Commission Adequacy Decisions
  • Additional contractual, technical and organisational safeguards, where required

7. Rights of Data Subjects

Every data subject has the right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing. Data subjects also have the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.

8. Data Retention Period

Personal data is retained only for as long as necessary to fulfil the purposes of processing, as set out below, after which it is securely deleted or anonymised:
Data CategoryRetention PeriodBasis
Reservation / guest data (name, room, breakfast)Up to 18 months from the stayBusiness purpose / statute of limitations for claims
Invoices, receipts, accounting records5 years (may be extended up to 10 years depending on the case)Greek Tax Procedures Code
Marketing / communication consent dataUntil consent is withdrawnArticle 7 GDPR
Audit logs / system security logs12 monthsInformation systems security

9. Contact & Exercising Your Rights

For any query regarding the processing of personal data, or to exercise the rights set out above, you may contact us at: info@guestin.com.
You also retain the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), www.dpa.gr.
GuestIn | Hospitality reimagined | GuestIn