Bootes
Thefutureoftravelbusiness
Bootes
Back to home

Privacy Policy and Personal Data Protection

Last updated · July 2026

This policy explains what personal data we collect through bootes.gr and in the course of providing our services, why we process it and what rights you have. We apply the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019.

01Our role: controller and processor

Depending on our relationship with you we act in two different capacities, and that determines who you address your rights to.

  • As a controller, for data about website visitors, prospective clients and clients, meaning the travel agencies, agents and carriers who contact us or work with us.
  • As a processor, for end traveller data entered into booking platforms that our client operates on Bootes technology. In those cases the client is the controller, and we process the data solely on their documented instructions under an Article 28 GDPR processing agreement.

If you are a traveller and wish to exercise a right in relation to a booking made on a client's platform, please contact that booking provider first. We support them so they can respond within the legal deadline.

02What data we collect

As a controller we collect the following:

  • Contact details you enter in the demo form: name, company, work email and your message.
  • Details you give us by email or phone, such as job title, phone number and the content of the conversation.
  • Business and financial details of clients: company name, VAT number, billing address, legal representative and contact persons.
  • Technical data generated automatically while you browse: IP address, device and browser type, pages viewed, date and time.
  • Access data for test environments or the API, such as user identifiers and call logs.

We do not ask for, and do not wish to receive, special categories of data such as health data through this website.

03How we collect data

  • Directly from you, when you complete the enquiry form or contact us.
  • Automatically, through the servers hosting the website, which keep technical logs for security and stability.
  • In the course of performing a contract, when we provision accounts, environments or API access for you.
  • From publicly available professional sources, such as your company website, when we assess a partnership request.

04Processing purposes

  • To answer your request for a demonstration, a quote or information.
  • To conclude and perform the services agreement, and to provide support and maintenance.
  • To issue invoices and meet our tax and accounting obligations.
  • To keep our systems secure, detect abuse and prevent incidents.
  • To improve our services through aggregated, non identifying statistics.

We do not use your details to send commercial messages without your consent or an existing business relationship, and every message carries an unsubscribe option.

05Legal bases for processing

  • Consent, Article 6(1)(a) GDPR, for submitting the form and for any non essential cookies.
  • Performance of a contract or pre contractual steps, Article 6(1)(b), to assess a request and provide the services.
  • Legal obligation, Article 6(1)(c), for tax and accounting records.
  • Legitimate interest, Article 6(1)(f), for system security, fraud prevention and service improvement.

06Cookies

The website runs on the smallest technical footprint we can manage and loads no advertising trackers. Exactly which cookies and storage technologies are used is set out in the Cookie Policy.

07Sharing data with third parties

We do not sell personal data. We share it only where necessary and always with appropriate safeguards:

  • Hosting, cloud infrastructure and email providers, acting as our processors.
  • Accountants, auditors and legal advisers, within the scope of our obligations.
  • Travel service providers such as ferry operators, hotels and activity suppliers, where this is required to complete a booking made through a client's platform.
  • Public authorities, where there is a legal obligation.

08Transfers outside the EEA

We aim to keep data within the European Economic Area. Where a provider operates outside the EEA, the transfer is made under a European Commission adequacy decision or Standard Contractual Clauses, with supplementary technical measures where required.

09Data retention

  • Enquiries that did not lead to a contract: up to 24 months from the last contact.
  • Client and contract data: for the duration of the relationship and afterwards for as long as claims can be brought.
  • Invoices and tax records: for the period required by tax law.
  • Technical logs: as a rule up to 12 months, unless a security incident is under investigation.

Once those periods end, data is securely deleted or anonymised.

10Your rights

You have the right of access, rectification, erasure, restriction of processing, portability and objection, and the right to withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, send a request to [email επικοινωνίας]. We reply within one month. That period may be extended by two months for complex requests, in which case we will tell you.

11Data security

We encrypt traffic with TLS, control access on a least privilege basis, separate production from test environments, take regular backups and keep audit logs. No method of transmission or storage is absolutely secure, but these measures are reviewed regularly.

12Links to third party websites

The website links to partner platforms and third party sites. We do not control their content or privacy practices and accept no liability for them. We recommend reading their own policies.

13Changes to this Privacy Policy

We may update this policy. The version in force is published on this page with an updated date. For material changes affecting you as a client, we also notify you directly.

14Contact

Controller for the data described above:

Bootes

Registered office: [registered address]

Company registry: [company registry number] · [VAT number, tax office]

Email: [email επικοινωνίας]

Phone: [τηλέφωνο]

Website: bootes.gr

15Right to lodge a complaint

If you believe that the processing of your data infringes the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority:

Hellenic Data Protection Authority

1-3 Kifisias Avenue, 115 23 Athens, Greece

Phone: +30 210 6475600

Email: complaints@dpa.gr

www.dpa.gr