Terms of Use & Privacy Policy
Last updated: August 2026
1. General Terms of Use
This website (www.embassia.gr) serves as the official presentation and inquiry portal for short-term holiday accommodations under the brand EMBASSIA, operating in Kythera and Chios, Greece.
By accessing and using this website, visitors agree to these terms. Content, accommodation details, and contact options are provided for informational and direct inquiry purposes. EMBASSIA reserves the right to update website information, features, and imagery without prior notice.
2. Intellectual Property
All photographs, brand marks, logos, graphics, and text published on this website are the property of EMBASSIA or used with appropriate rights. Reproduction, redistribution, or commercial use without prior written consent is strictly prohibited.
3. Data Controller & Contact Information
For the purposes of the General Data Protection Regulation (GDPR - Regulation (EU) 2016/679) and applicable Greek data protection laws, the Data Controller is:
- Name: Mirto Tamvaki
- Brand Entity: EMBASSIA Hospitality
- Contact Email: info@embassia.gr
- Telephone: +30 698 130 5016
- Locations: Kythera & Chios, Greece
4. Personal Data We Collect
We only collect personal information that you voluntarily submit through our contact/inquiry forms or direct communication channels (email, phone, WhatsApp):
- Full name
- Email address and optional telephone number
- Destination of interest (Kythera or Chios), proposed travel dates, guest count, and inquiry message content
Payment Notice: We do not collect, process, or store credit card details or payment credentials directly on this website. Reservations finalized via external platforms (such as Airbnb) are governed by the respective privacy policies and terms of those platforms.
5. Purpose & Legal Basis for Processing
We process your inquiries under:
- Article 6(1)(b) GDPR: Taking steps at the request of the data subject prior to entering into an accommodation contract or reservation.
- Article 6(1)(f) GDPR: Legitimate interest in responding efficiently to customer inquiries and managing guest communication.
6. Data Processors & Third-Party Technical Services
We do not sell, rent, or trade your personal data. To deliver services securely, we utilize selected technical service providers who act as Data Processors under GDPR Article 28:
- Web3Forms (Form Submission & Email Routing): Inquiries submitted through our online contact forms are processed securely via Web3Forms. Web3Forms transmits your submitted information (name, contact details, message) via encrypted HTTPS/SSL connections directly to our official inbox (
info@embassia.gr). Web3Forms acts solely as a technical routing processor and does not sell or distribute your data. - Cloudflare (Hosting & Security): Static assets and secure DNS routing are hosted through Cloudflare Pages, utilizing industry-standard transport security (TLS/HTTPS).
7. Cookies & Local Storage
Our website uses essential technical local storage (to remember your privacy and cookie preferences) and privacy-friendly web metrics. You can adjust your consent choices at any time using the Cookie Settings link in our website footer.
8. Data Retention
Inquiry communications are retained only for as long as necessary to answer your request, complete booking arrangements, or fulfill applicable statutory tax and accounting obligations under Greek legislation.
9. Your Rights Under GDPR
Under EU data protection legislation, you possess the right to:
- Request access to the personal data we hold about you
- Request rectification of inaccurate data or completion of incomplete records
- Request deletion (erasure) of your personal information
- Request restriction of or object to the processing of your data
- Request data portability where applicable
To exercise any of these rights, please email us directly at info@embassia.gr.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) (www.dpa.gr).