GDPR – Personal Data Protection
Last updated: 27 July 2026
Niotis Travel applies the principles of the General Data Protection Regulation (EU) 2016/679 and relevant Greek law. This page summarises how personal data protection and the exercise of your rights are organised. For detailed information about data categories, please also read the Privacy Policy.
1. Processing principles
Personal data is processed lawfully, fairly and transparently, collected for specified purposes, limited to what is necessary, kept accurate and protected with appropriate safeguards. It is not retained longer than necessary.
2. Lawfulness of processing
Processing takes place where necessary for a pre-contractual request or a transfer/tour contract, compliance with a legal obligation, a legitimate interest that does not override your rights, or freely given and withdrawable consent.
3. Data subject rights
- The right to information and access to your data.
- The right to correct inaccurate or incomplete data.
- The right to erasure where legal conditions are met.
- The right to restrict processing.
- The right to portability for data you provide that is processed automatically on the basis of consent or contract.
- The right to object, particularly where processing relies on legitimate interests or concerns direct marketing.
- The right to withdraw consent at any time.
- The right not to be subject to a decision based solely on automated processing that produces significant legal effects, where applicable.
4. How to exercise your rights
Requests may be submitted using the Contact page details. Reasonable identity information may be requested for your protection. Requests are handled without undue delay and within statutory time limits. The extension allowed by the Regulation may apply to particularly complex or numerous requests, with appropriate notice.
5. Processors
Where external providers support hosting, technical services, communications, payments or other functions, providers are selected that offer sufficient guarantees and are contractually required to process data only on documented instructions and with suitable security measures.
6. Incident protection
Procedures are maintained to identify, assess and handle personal data breaches. Where an incident may create a risk to individuals, the required notification procedures are followed with the competent supervisory authority and, where necessary, affected individuals.
7. Complaint
You have the right to lodge a complaint with the Hellenic Data Protection Authority, without prejudice to any other administrative or judicial remedy.
8. Contact
For GDPR questions or to exercise a right, contact Niotis Travel through the Contact page. Specific data protection officer details, if one is appointed, may be added later through page administration.