Last Updated: February 21, 2026
KefaloniaTransfers.com (powered by KCG Travel) is committed to protecting your privacy and ensuring the security of your personal data.
This Privacy Policy explains how we collect, use, store, and protect your information when you use our website and services, in compliance with the General Data Protection Regulation (GDPR) and Greek data protection laws.
By using our website and booking our services, you agree to the collection and use of information in accordance with this Privacy Policy.
Data Controller:
[COMPANY_NAME_PLACEHOLDER]
[VAT_NUMBER_PLACEHOLDER]
[ADDRESS_PLACEHOLDER]
[GEMI_NUMBER_PLACEHOLDER]
Contact Information:
For all data protection inquiries, please contact us at: [email protected]
We collect and process the following categories of personal data:
| Data Category | Examples |
|---|---|
| Contact Information | Full name, email address, phone number |
| Travel Details | Flight/ferry number, arrival/departure times, pickup and drop-off addresses |
| Passenger Information | Number of passengers, names of all passengers (for group bookings) |
| Children's Information | Age and name (only for child seat requests) |
| Payment Information | Credit/debit card details (processed securely by Stripe - we do not store full card details) |
| Special Requests | Wheelchair access, special equipment, dietary requirements (for tours) |
| Communications | Content of emails, phone calls, or messages you send us |
| Data Category | Examples |
|---|---|
| Technical Data | IP address, browser type and version, device type, operating system |
| Usage Data | Pages visited, time spent on pages, links clicked, referral source |
| Location Data | General location based on IP address (not precise GPS location) |
| Cookie Data | Session cookies, analytics cookies (see Section 9) |
We collect your personal data through the following methods:
Under GDPR, we must have a lawful basis to process your personal data. Here are the legal bases we rely on:
| Purpose | Legal Basis (GDPR Article 6) |
|---|---|
| Processing bookings and providing transfer services | Contractual Necessity - necessary to perform our contract with you |
| Processing payments | Contractual Necessity + Legal Obligation (tax/accounting laws) |
| Storing financial records for 11 years | Legal Obligation - Greek accounting and tax law |
| Sending booking confirmations, reminders, and service-related emails | Contractual Necessity - essential to provide the service |
| Customer support and complaint handling | Legitimate Interest - to provide customer service and resolve issues |
| Website analytics (Manus Analytics) | Legitimate Interest - to improve our website and services |
| Preventing fraud and ensuring security | Legitimate Interest - to protect our business and customers |
If we process your data based on Legitimate Interest, you have the right to object to this processing. See Section 10 for details on how to exercise your rights.
We use your personal data for the following purposes:
We may share your personal data with the following trusted third parties:
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Name, email, payment card details, transaction amount |
| Resend | Email delivery (confirmations, reminders) | Name, email address, booking details |
| Google Workspace | Email communications (customer support) | Name, email address, message content |
| Manus Analytics | Website analytics and hosting | IP address, browser type, pages visited, session data |
All third-party service providers act as Data Processors under our instructions and are bound by GDPR-compliant Data Processing Agreements (DPAs). They are contractually obligated to protect your data and use it only for the specified purposes.
We may disclose your personal data if required by law or in response to valid requests from public authorities, including:
In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the new owner, subject to the same privacy protections outlined in this Privacy Policy.
Your personal data is primarily stored and processed within the European Union (EU) and the European Economic Area (EEA).
All data transfers within the EU/EEA benefit from GDPR protections. We do not transfer your personal data outside the EU/EEA.
In the rare event that data is transferred outside the EU/EEA (e.g., for technical support or system maintenance), we ensure that such transfers are protected by:
We retain your personal data only as long as necessary to fulfill the purposes outlined in this Privacy Policy or as required by law.
| Data Category | Retention Period | Reason |
|---|---|---|
| Booking & Passenger Data | 11 years from date of service | Greek accounting and tax law |
| Payment Records | 11 years from transaction date | Greek accounting and tax law |
| Email Communications | 11 years from last communication | Legal compliance and dispute resolution |
| Analytics Data (Manus) | 14 months | Standard analytics retention period |
| Session Cookies | Until browser is closed | Technical necessity |
| Customer Support Tickets | 11 years from resolution | Legal compliance and service improvement |
Once the retention period expires, we will securely delete or anonymize your personal data, unless we are legally required to retain it for longer (e.g., for ongoing legal proceedings).
You have the right to request deletion of your data before the retention period ends (see Section 10 - Right to Erasure). However, we may be unable to delete data that we are legally required to retain (e.g., for tax purposes).
Cookies are small text files stored on your device (computer, tablet, smartphone) when you visit our website. They help us provide you with a better experience and allow us to analyze how our website is used.
| Cookie Type | Purpose | Consent Required? |
|---|---|---|
| Essential Cookies (Session Cookies) | Enable core website functionality (booking form, secure connections). Without these cookies, the website cannot function properly. | No - These are strictly necessary |
| Analytics Cookies (Manus Analytics) | Help us understand how visitors use our website (pages visited, time spent, user behavior) so we can improve the user experience. | Yes - These require your consent |
You can control and manage cookies in several ways:
Most web browsers allow you to:
Here are links to cookie management guides for popular browsers:
If you block or delete essential cookies, some parts of our website (especially the booking form) may not work properly.
Manus Analytics helps us understand:
Legal Basis: Legitimate Interest (website optimization and improvement)
Retention Period: 14 months
Your Choice: You can opt out of analytics tracking by disabling analytics cookies in your browser settings or by using browser privacy extensions.
Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:
What it means: You have the right to request a copy of the personal data we hold about you.
How to exercise: Email us at [email protected] with the subject line "Data Access Request".
Response time: We will respond within 30 days.
What it means: You have the right to request correction of inaccurate or incomplete personal data.
How to exercise: Email us at [email protected] with the corrected information.
Response time: We will update your data within 30 days.
What it means: You have the right to request deletion of your personal data in certain circumstances.
When we can delete:
When we CANNOT delete:
How to exercise: Email us at [email protected] with the subject line "Data Deletion Request".
Response time: We will respond within 30 days and delete your data (subject to legal retention requirements) within 30 days of approval.
What it means: You have the right to request that we limit how we use your data in certain circumstances.
When you can restrict:
What it means: You have the right to receive your personal data in a structured, commonly used, and machine-readable format (e.g., CSV, JSON).
Scope: Applies only to data you provided to us and that we process based on consent or contract.
How to exercise: Email us at [email protected] with the subject line "Data Portability Request".
What it means: You have the right to object to processing of your data based on Legitimate Interest.
Examples:
How to exercise: Email us at [email protected] with the subject line "Objection to Processing".
What it means: Where we process your data based on consent, you have the right to withdraw that consent at any time.
Note: Withdrawing consent does not affect the lawfulness of processing before withdrawal.
What it means: You have the right to file a complaint with the Hellenic Data Protection Authority (HDPA) if you believe we have violated your data protection rights.
See Section 17 for HDPA contact details.
To exercise any of these rights, please contact us:
Email: [email protected]
Subject Line: Include the specific right you wish to exercise (e.g., "Data Access Request")
Identity Verification: We may ask you to verify your identity before processing your request (to protect your privacy).
Response Time: We will respond to all requests within 30 days. In complex cases, we may extend this by an additional 60 days and will notify you of the delay.
No Fee: Exercising your rights is free of charge, unless your request is manifestly unfounded or excessive.
Our services are not intended for children under 18 years of age. To book a transfer, you must be at least 18 years old.
We do NOT knowingly collect personal data from children under 18, except for:
By booking a transfer that includes child passengers, the Lead Passenger (parent/guardian) confirms that:
We only collect the minimum necessary information about children:
We do NOT collect or process any other data about children (photos, health data, etc.) unless explicitly requested by the parent/guardian for special requirements (e.g., medical conditions affecting travel).
If we discover that we have inadvertently collected personal data from a child under 18 without proper parental consent, we will delete that data immediately. If you believe we have collected data from a child improperly, please contact us at [email protected].
We take the security of your personal data very seriously and have implemented appropriate technical and organizational measures to protect it from unauthorized access, loss, misuse, alteration, or destruction.
| Security Measure | Description |
|---|---|
| SSL/TLS Encryption | All data transmitted between your browser and our website is encrypted using industry-standard SSL/TLS protocols (HTTPS). |
| Secure Payment Processing | All payment transactions are processed by Stripe, a PCI-DSS Level 1 certified payment processor. We do NOT store full credit card details on our servers. |
| Data Encryption at Rest | Sensitive data stored on our servers is encrypted using strong encryption algorithms. |
| Firewall & DDoS Protection | Our website is protected by advanced firewall systems and DDoS mitigation through our hosting provider (Manus). |
| Regular Security Audits | We conduct regular security assessments and vulnerability scans to identify and address potential threats. |
| Secure Backups | Regular encrypted backups are performed to ensure data can be restored in case of system failure. |
While we implement robust security measures, you also play a role in protecting your data:
Despite our best efforts, no data transmission over the Internet or electronic storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately.
A data breach occurs when personal data is accidentally or unlawfully destroyed, lost, altered, disclosed, or accessed without authorization.
In the event of a data breach that poses a risk to your rights and freedoms, we are legally required under GDPR to:
In the event of a data breach requiring notification, we will contact you via:
We are committed to:
If you suspect that your personal data has been compromised or you notice any suspicious activity related to your booking, please contact us immediately at:
Email: [email protected]
Phone: +30 697 651 4295
Our website may contain links to third-party websites, plugins, or applications (e.g., payment gateways, review platforms, social media).
We are NOT responsible for the privacy practices or content of third-party websites. Once you leave our website, this Privacy Policy no longer applies. We encourage you to read the privacy policies of any third-party websites you visit.
We maintain official pages on the following social media platforms:
When you interact with us on social media (like, comment, share, message), the social media platform may collect data about you according to their own privacy policies, including:
We do NOT control how social media platforms use your data. Please review their privacy policies:
We do NOT use social media plugins (e.g., Facebook Like button, Twitter share button) on our website. We do not embed third-party content that tracks your browsing behavior.
We may display or link to reviews from third-party platforms (e.g., Google Reviews, TripAdvisor). These platforms have their own privacy policies governing how they collect and use reviewer data.
We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our practices, legal requirements, or for other operational reasons.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data. Your continued use of our website and services after any changes indicates your acceptance of the updated Privacy Policy.
Material changes may include:
If you have any questions or concerns about changes to this Privacy Policy, please contact us at [email protected].
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, please contact us:
Powered by KCG Travel
Data Protection Contact:
Email: [email protected]
Phone: +30 697 651 4295
WhatsApp/Viber: +30 697 651 4295
Company Details:
[COMPANY_NAME_PLACEHOLDER]
[VAT_NUMBER_PLACEHOLDER]
[ADDRESS_PLACEHOLDER]
[GEMI_NUMBER_PLACEHOLDER]
Customer Support Hours:
Winter Season (November - May): 09:00 - 17:00
Summer Season (May - October): 09:00 - 21:00
We aim to respond to all privacy-related inquiries within 30 days. For urgent matters (e.g., suspected data breach, security concerns), please call us directly at +30 697 651 4295.
Under GDPR, you have the right to lodge a complaint with a supervisory authority if you believe we have violated your data protection rights.
Official Name: Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)
English Name: Hellenic Data Protection Authority
Address:
Kifisias Ave. 1-3
115 23 Athens
Greece
Website: www.dpa.gr
Email: [email protected]
Phone: +30 210 6475 600
Fax: +30 210 6475 628
We are committed to working constructively with the HDPA and will cooperate fully with any investigations or audits. However, we encourage you to contact us directly first so we can try to resolve any concerns informally before escalating to the supervisory authority.