Privacy Policy
Last updated: June 2026
1. Who we are
"GEMP" ("GEMP Apartments") operates short-term rental properties in Athens, Greece. We are the data controller responsible for your personal data. If you have any questions about this policy or your data, you can reach us at hello@gemp.gr.
2. The short version
We collect only the information needed to take your booking and manage your reservation. We do not perform marketing, use advertising trackers, or build visitor profiles. We never ask for or store payment card details on our site. Your data stays with us and our essential service providers — nothing is sold or shared for any other purpose.
3. Information we collect
When you make a booking through our website, we collect:
- Full name
- Email address
- Phone number
- Number of guests
- Check-in and check-out dates
- Chosen payment method (bank transfer or cash)
We do NOT collect: payment card numbers, CVV codes, or card expiry dates — those never enter our site. We also do not collect ID or passport copies, your home address, or any marketing profile or browsing behaviour data.
4. How we use it
We use your personal data solely to:
- Create and manage your reservation
- Communicate with you about your stay, including sending booking confirmation and cancellation emails
- Process payment via bank transfer or cash on arrival
Your data is never used for marketing, advertising, or profiling purposes.
5. Legal basis (GDPR)
We process your personal data under the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — the data we collect is necessary to create and fulfil your booking.
- Legitimate interests (Art. 6(1)(f)) — we have a legitimate interest in administering reservations and communicating with guests about their bookings.
6. Sharing & third parties
We share your personal data only in the following limited circumstances:
- Resend — our email provider processes confirmation and cancellation emails. It receives your email address and the booking details needed for that message.
- Our staff — authorised team members receive your contact details and booking information to operate the reservation.
- Listing platforms (Airbnb, Booking.com, VRBO)— we share only calendar availability (blocked dates) with these platforms. No guest names, email addresses, or other personal details are shared.
We do NOT sell your personal data to anyone.
7. International transfers
Some of our service providers (including Resend and our database provider) may process data on servers located outside the EU/EEA. When this occurs, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
8. Cookies & tracking
We do NOT use analytics cookies, advertising cookies, tracking pixels, or any form of behavioural tracking. Only strictly essential cookies necessary for the website to function and maintain security (such as session management and rate-limiting) may be used. These do not require prior consent under GDPR.
9. Data retention
We keep your booking information only for as long as necessary to fulfil your reservation and handle any follow-up, and to meet our legal and tax obligations. We do not use it for marketing. You may ask us to delete your data at any time by emailing hello@gemp.gr.
Because our site does not have user accounts, there is no account data to retain. Aggregated, non-personal figures may be kept for accounting purposes.
10. Security
We protect your data with the following measures:
- All traffic to our site is encrypted using HTTPS.
- Data is stored in a managed database with strict access controls.
- Access to personal data is limited to authorised staff only.
- No payment card data is stored on our systems.
11. Your rights (GDPR)
Under the General Data Protection Regulation, you have the following rights:
- Right of access
- Right to rectification
- Right to erasure ("right to be forgotten")
- Right to restriction of processing
- Right to object to processing
- Right to data portability
- Right to lodge a complaint with the Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
To exercise any of these rights, please email us at hello@gemp.gr.
12. Children
Our website is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with their data, please contact us and we will delete it.
13. Changes & contact
We may update this privacy policy from time to time. Any changes will be reflected on this page with an updated "Last updated" date. We encourage you to review this page periodically.
If you have any questions, concerns, or requests regarding your personal data, please contact us:
- Email: hello@gemp.gr
- Phone: +30 21 0123 4567
- Location: Athens, Greece