Privacy Policy

Divider icon

1. Introduction

This Privacy Policy explains how Guestin EE, owner of the Guestin™ trademark, collects, processes, stores and protects personal data in connection with the operation of the Guestin™ platform, which connects accommodation providers (hotels and short-term rentals) with local cafés/restaurants for the provision of breakfast via QR code. Data processing is governed by Regulation (EU) 2016/679 (GDPR) and Greek law, as in force.

2. Data Controller

Company Name: Guestin EE
Business Activity: Web Portal Content Services
Registered Office: Leoforos Dimokratias 4-6, Neo Psychiko, 15451, Greece
Tax ID (AFM): 803219460 – Tax Office: KEFODE Attikis
Company Registration No. (GEMI): 192371503000
Phone: +30 697 028 2898
Email: info@guestin.com

3. Categories of Personal Data

Guestin collects and processes the following categories of data:
  • Identification details (full name, contact details)
  • Booking details (stay dates, number of guests, QR codes)
  • Validation data at partner cafés/restaurants
  • Technical data (IP address, cookies, device data)

4. Purposes of Processing

Data is processed for the following purposes:
  • Issuance and validation of QR codes
  • Connecting accommodation providers with partner cafés/restaurants
  • Financial reconciliation and settlement of transactions
  • Improving the user experience
  • Compliance with legal obligations

5. Legal Basis for Processing

Processing of data is based on one or more of the following legal grounds, depending on the case:
  • Performance of a contract with the data subject
  • Legitimate interest of Guestin or a third party
  • Compliance with a legal obligation
  • Consent of the data subject, where required

6. Data Retention Period

Personal data is retained only for as long as necessary for each purpose of processing, as set out below, after which it is securely deleted or anonymised:
Data CategoryRetention PeriodBasis
Reservation / guest data (name, room, breakfast)Up to 18 months from the stayBusiness purpose / statute of limitations for claims
Invoices, receipts, accounting records5 years (may be extended up to 10 years depending on the case)Greek Tax Procedures Code
Marketing / communication consent dataUntil consent is withdrawnArticle 7 GDPR
Audit logs / system security logs12 monthsInformation systems security

7. Data Disclosure

Data may be shared, to the extent necessary, with the following recipients:
  • Partner cafés/restaurants
  • Payment service providers (e.g. Stripe)
  • Hosting service providers
  • Public authorities, where required by law
Any transfer of data outside the European Union/European Economic Area is carried out only on the basis of Standard Contractual Clauses (SCCs), European Commission adequacy decisions, or other additional safeguards.

8. Rights of Data Subjects

Every data subject has the right of access, rectification, erasure (“right to be forgotten”), restriction of processing, data portability, and objection to processing. Data subjects also have the right to withdraw their consent at any time, without affecting the lawfulness of processing based on consent prior to its withdrawal.

9. Security Measures

Guestin implements appropriate technical and organisational measures to protect data, including:
  • Data encryption
  • Role-based access control
  • Multi-Factor Authentication (MFA)
  • Regular security audits
  • Secure data hosting infrastructure

10. Cookies & Tracking Technologies

The Guestin™ platform may use cookies and similar technologies to ensure its proper functioning, analyse traffic, and improve the user experience. Users may manage their cookie preferences through their browser settings.

11. Contact & Exercising Your Rights

For any query regarding the processing of personal data, or to exercise the rights set out above, you may contact us at: info@guestin.com.
You also retain the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), www.dpa.gr.
GuestIn | Hospitality reimagined | GuestIn