Personal data and visitor choices
Privacy Policy
This policy explains how Zakynthos.net may collect, use, disclose and protect personal information when you browse the site, contact us or follow an external partner link.
The final configuration must match the services actually enabled on the live website. The site owner should review analytics, advertising, consent, security, email and affiliate tools before publication.
01
Controller and scope
The operator identified in the website’s published contact details is the controller for personal data processed directly by Zakynthos.net. The installable theme cannot safely invent a legal name, company number or postal address, so the site owner must add those details before launch when required. The WordPress administration email is used as the initial privacy contact and should be verified.
This policy covers the Zakynthos.net website, its contact form, direct correspondence and first-party records used to operate and protect the service. It does not control personal data processed independently by a booking marketplace, accommodation provider, tour operator, map service, social platform or other external website. When you follow an external link, review that service’s privacy information.
The policy is designed for visitors in the European Economic Area and also describes practices relevant to an international audience. Applicable rights and legal bases can vary with the controller, visitor location and service configuration. Nothing here limits rights that cannot lawfully be waived.
02
Information we may process
Ordinary web requests can create server logs containing an IP address, request time, requested page, referring page, browser or device information, response status and security signals. Hosting, caching, firewall and content-delivery providers may process this information to deliver pages, prevent abuse, diagnose errors and maintain availability. Retention should be limited to what is reasonably necessary for those purposes.
When you contact us, we process the name, email address, subject, message and any information you voluntarily include. We also record submission time and limited technical information for spam and security control. Please do not include payment data, identity documents, health information or full booking records. If sensitive information is sent without need, we may delete or minimize it.
If optional analytics or advertising is enabled with valid consent, the relevant tools may process identifiers, approximate location, device characteristics, page interactions, referral source and campaign information. Affiliate links may contain referral parameters and may allow a partner to attribute a later transaction. The exact cookies and providers must be listed in the live consent interface or cookie table.
03
Purposes and legal bases
We process necessary technical data to deliver the website, maintain security, prevent fraud, remember privacy choices and respond to faults. Depending on the activity, the legal basis may be legitimate interests in operating and protecting an editorial service, performance of a request made by you or compliance with a legal obligation. Legitimate interests are balanced against the rights and expectations of visitors.
Contact information is used to respond to the enquiry, investigate a correction, manage a rights request, assess a partnership proposal or protect legal rights. The basis is normally taking steps at your request, legitimate interests in correspondence and editorial accuracy, or legal obligation for a valid data-protection request. We do not add contact-form users to marketing lists merely because they wrote to us.
Optional analytics, personalized advertising and non-essential tracking should rely on consent where required. Consent must be specific, informed, freely given and revocable. Withdrawing consent does not make earlier lawful processing unlawful. The site should provide a persistent way to reopen privacy choices without forcing users to delete all browser data.
04
Cookies and similar technologies
Strictly necessary technologies may support security, load balancing, session continuity, consent storage and core WordPress functions. These should be limited to what the visitor requested or what is necessary to provide the service. Optional categories can include audience measurement, advertising, embedded media and affiliate attribution. They should remain disabled until the required choice is made.
A cookie banner is not sufficient if its controls do not reflect actual scripts. The operator must audit the site after adding plugins, tag managers, advertising code, video embeds, maps or affiliate widgets. Rejecting optional technologies should be as straightforward as accepting them, and content should remain available without consent except where an external feature technically cannot load.
Browser controls can remove or block cookies, but they are not a substitute for a compliant site preference mechanism. Some external partners may receive referral information when you deliberately follow a link even if optional on-site cookies are rejected. Their processing is governed by their own policies and the information shown before or during the handoff.
05
Sharing, processors and international transfers
Personal data may be handled by service providers that host the website, deliver email, filter spam, monitor security, manage consent, measure audiences or support lawful advertising and affiliate attribution. They should receive only the information needed for their role and be subject to appropriate contractual and security obligations. We do not sell contact-form content as a customer list.
Some providers may process data outside the European Economic Area. Where the GDPR applies, transfers should use an adequacy decision, approved contractual safeguards or another lawful mechanism, with supplementary measures where necessary. The appropriate mechanism depends on the provider and destination and must be verified when the live stack is configured.
We may disclose information where required by law, to respond to a valid authority request, to establish or defend legal claims, to investigate abuse or to protect people and the service. We may also transfer operational records during a genuine business reorganization, subject to applicable notice and protection requirements.
06
Retention and security
We retain data only as long as reasonably needed for the stated purpose, legal obligations, dispute handling and security. Server logs should use short operational periods unless an incident requires preservation. Routine enquiries should be removed or anonymized when follow-up is no longer reasonably expected. Legal, rights and partnership records may need longer retention. The live operator should document concrete schedules for its actual systems.
Reasonable safeguards can include encrypted transport, access controls, software updates, backups, spam filtering, least-privilege administration and secure email delivery. No internet service can promise absolute security. Visitors should avoid sending unnecessary sensitive data and should contact us promptly if they believe information has been exposed.
If a personal-data breach creates a risk to individuals, the controller will assess notification duties under applicable law. Processors are expected to report relevant incidents without undue delay so the controller can investigate and take proportionate action.
07
Your rights and complaints
Where the GDPR applies, you may have rights of access, rectification, erasure, restriction, portability and objection, plus the right to withdraw consent. Some rights depend on the legal basis and circumstances and are not absolute. We may request proportionate verification and can retain information where law or a compelling legal reason permits.
Submit a request through the Contact page and state the right you wish to exercise. We aim to respond within the period required by applicable law. If a request is complex or numerous, the law may permit an extension with an explanation. Requests are generally free, although manifestly unfounded or excessive requests may be handled as the law allows.
You may complain to the supervisory authority in your habitual residence, workplace or place of the alleged infringement. In Greece, the competent authority is the Hellenic Data Protection Authority. Contacting us first can help resolve an issue, but it does not remove your right to approach an authority.
08
Children and policy changes
Zakynthos.net is a general travel website and is not directed to children. We do not knowingly invite children to create accounts or submit personal information. A parent or guardian who believes a child has provided personal data should contact us so the situation can be reviewed.
We update this policy when the site’s operator, tools, purposes or legal obligations materially change. The revision date appears above. If a change requires new consent, continuing to browse is not treated as consent; the site should ask through an appropriate mechanism.
Questions about this policy or the live privacy configuration can be sent through the Contact page. The site owner should complete a launch audit before enabling analytics, advertising, embeds or commercial feeds and repeat that audit after significant plugin or partner changes.