Privacy & Cookie Policy
Your privacy is important to us. This policy explains what personal information may be collected when you visit mykonosilios.gr or contact Mykonos Ilios House, why the information is used, how it is protected, and the choices and rights available to you.
Last updated: 15 July 20261. Data controller
The controller responsible for personal data processed through mykonosilios.gr is:
This policy applies to the use of the Mykonos Ilios House website, availability enquiries and communications relating to possible or confirmed stays. The exact property address and detailed arrival information are shared directly with confirmed guests.
2. Personal data we may collect
We may collect personal data when you browse the website, submit an enquiry, communicate with us or proceed with a stay.
Information you provide
- Identification and contact details: your full name, email address and telephone number.
- Stay enquiry details: proposed arrival and departure dates, number of adults, number of children, preferences and information included in your message.
- Communication records: emails, telephone communications, WhatsApp messages and other correspondence relating to your enquiry or stay.
- Booking-related information: information reasonably required to organise or administer a confirmed stay.
Information collected automatically
- IP address and approximate geographic region.
- Browser, device type and operating system.
- Pages visited, referral source and basic usage information.
- Date, time and duration of website requests.
- Security, error and server-log information.
- Cookie identifiers and consent preferences, depending on the choices you make through the website's consent mechanism.
3. How and why we use personal data
Personal data is processed only where there is a defined and lawful purpose. Depending on the circumstances, we may use it:
- to receive and respond to enquiries;
- to provide information about availability, rates, the property and possible stays;
- to take steps requested by you before entering into a booking arrangement;
- to administer a confirmed booking or stay;
- to communicate before, during or after a stay where reasonably necessary;
- to protect the website, our systems and visitors from spam, unauthorised access, fraud or malicious activity;
- to diagnose technical issues and maintain the website;
- to understand website performance and usage where optional analytics consent has been provided;
- to comply with accounting, tax, legal or regulatory obligations;
- to establish, exercise or defend legal claims where necessary.
4. Legal bases for processing
Depending on the nature of the processing, we rely on one or more of the following legal bases:
- Steps before entering into a contract or performance of a contract: when you ask about availability, request a stay or have a confirmed booking.
- Legitimate interests: for ordinary enquiry administration, website security, fraud prevention, service improvement and the protection of our legal rights, provided that those interests do not override your rights and freedoms.
- Consent: for non-essential cookies, analytics, marketing technologies or optional third-party content where consent is required.
- Legal obligation: where processing is required by applicable accounting, tax, regulatory or other legislation.
Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before the consent was withdrawn.
5. Enquiries and availability requests
The website enquiry form may request your arrival date, departure date, number of adults, number of children, full name, email address, optional telephone number and information about your proposed stay.
This information is used to assess and answer your request, discuss availability and provide relevant information about a possible stay.
6. Payments and financial information
The public enquiry form is not intended to collect payment-card information.
Where a payment is required for a confirmed stay, payment instructions or access to an appropriate payment service may be provided separately. A payment provider may process transaction and payment information under its own privacy terms and legal obligations.
We may retain transaction references, invoices and related accounting records where required for booking administration or compliance with applicable law.
7. How long we retain personal data
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected.
- Enquiry correspondence may be retained while the enquiry remains active and for a reasonable follow-up period afterward.
- Information connected with a confirmed stay may be retained for customer-service, record-keeping and legal purposes.
- Invoices, transaction information and accounting records may be kept for the period required by applicable tax and accounting legislation.
- Security and technical logs are normally retained for a limited operational period unless they are needed to investigate an incident.
- Cookie consent records may be retained for as long as necessary to record and demonstrate your choices.
Data may be retained for longer where necessary to comply with a legal obligation, respond to a dispute or establish, exercise or defend a legal claim.
8. Who may receive personal data
We do not sell or rent personal data. Information may be shared only where reasonably necessary with:
- website hosting and infrastructure providers;
- website development, maintenance and security providers;
- email and communications providers;
- spam-prevention and form-security providers;
- booking or payment providers, where used for a confirmed stay;
- accountants, legal advisers and other professional advisers;
- public authorities, courts or regulators where disclosure is legally required;
- another party where necessary to protect our rights, property, visitors or guests.
Providers acting on our behalf are expected to process personal data only for the relevant service and to apply appropriate confidentiality and security measures.
9. International data transfers
Some technology, communications, analytics or platform providers may process information in countries outside Greece or the European Economic Area.
Where a restricted international transfer takes place, appropriate safeguards should be used as required by applicable data-protection law. These may include an adequacy decision, approved contractual protections or another lawful transfer mechanism.
10. External links and third-party platforms
The website may include links to external services such as Instagram, WhatsApp, mapping services or other websites.
When you choose to open an external link, the third party may receive technical information and may process personal data according to its own privacy policy, cookie practices and terms.
We do not control the independent processing carried out by external websites or platforms. You should review the relevant third party's privacy information before providing personal information.
11. Data security
Reasonable technical and organisational measures are used to protect personal data against unauthorised access, accidental loss, destruction, alteration, disclosure or misuse.
These measures may include access controls, website security tools, software updates, encrypted connections, restricted administrative access and appropriate backup procedures.
No internet transmission or storage system can be guaranteed to be completely secure. Visitors should therefore avoid sending sensitive or confidential information through the general enquiry form.
12. Children's information
The website and enquiry form are intended to be used by adults. A guest organising a family stay may provide the number of children travelling, but the public form does not request the children's names or direct contact details.
A parent or legal guardian should make any enquiry involving a child. Please do not provide unnecessary personal details about children in the message field.
13. Your data-protection rights
Subject to the conditions and limitations of applicable law, you may have the right to:
- receive clear information about how your data is processed;
- request access to personal data held about you;
- request correction of inaccurate or incomplete information;
- request deletion of personal data where applicable;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive or transfer certain personal data in a structured, commonly used and machine-readable format where the portability right applies;
- withdraw consent where processing relies on your consent;
- lodge a complaint with the competent data-protection authority.
Requests may be sent to info@mykonosilios.gr . We may need to request reasonable information to verify your identity before completing a request.
14. Cookie policy
Cookies are small text files that a website stores on a visitor's computer, telephone or other device. Similar technologies may include local storage, tags, pixels and scripts.
Cookies may be used to provide essential website functions, remember cookie preferences, protect forms, understand website usage or load optional third-party functionality.
Cookie categories
| Category | Purpose | Consent status |
|---|---|---|
| Strictly necessary | Supports core website operation, security, consent-preference storage, form submission and other functionality required for the website to work correctly. | Normally active without optional consent because these technologies are necessary for the service requested by the visitor. |
| Functional | Remembers optional preferences or enables enhanced functions that are not strictly required for the basic website. | Used only where permitted by applicable law and, where required, after consent. |
| Statistics / analytics | Helps us understand how visitors reach and use the website, which pages are viewed and whether the website performs correctly. | Used only after consent where the technology is not strictly necessary. |
| Marketing | May be used to measure advertising, understand campaign performance or personalise marketing across websites and platforms. | Used only after consent. |
| External media and third-party content | May be set when loading maps, videos, social-media content or other services supplied by third parties. | Loaded only after consent where consent is legally required. |
The website's cookie-consent panel should display the current services, cookie names, providers, purposes and storage periods configured on the website. That live information takes account of the website's actual technical configuration.
15. Consent and cookie preferences
Strictly necessary cookies may be placed without optional consent where they are required for the website or for a service specifically requested by the visitor.
Optional analytics, marketing and non-essential third-party technologies should remain inactive until you make an affirmative choice through the cookie-consent mechanism.
Where a consent-management tool is available, you can use it to:
- accept all optional categories;
- reject optional categories;
- select individual categories or services;
- review or change your choices later;
- withdraw previously provided consent.
Refusing optional cookies should not prevent access to the website's basic content, although optional embedded services may remain unavailable until the relevant consent is provided.
16. Browser cookie controls
Most browsers allow you to view, remove or block cookies through their privacy or security settings. You may also configure a browser to warn you before a cookie is stored.
Browser-level blocking may affect necessary website functionality, saved preferences or the operation of forms and embedded services.
Removing cookies may also delete a previously stored cookie-consent choice, meaning that the website may ask for your preferences again.
17. Changes to this policy
This Privacy & Cookie Policy may be updated when the website, services, technology providers, cookie configuration or applicable legal requirements change.
The latest version will be published on this page with an updated revision date. Material changes may also be communicated through the website or another appropriate method where necessary.
18. Contact
For questions about this policy, the processing of your personal data or the exercise of your rights, contact:
- Controller: AYS
- Website: Mykonos Ilios House — mykonosilios.gr
- Email: info@mykonosilios.gr
- Telephone: +30 698 446 0000
- Business address: 18 Andrea Papandreou Street, 166 74, Greece
- Property location: Mykonos, Greece