Legal
Privacy Policy
Last updated: 19 July 2026
This page explains what happens to your personal data when you visit this website, write to us about Casa di Lavalle, stay with us, or book through Booking.com or Airbnb. It applies to everyone who contacts us or stays at the property, regardless of where you live, in line with the EU General Data Protection Regulation (GDPR) and Greek data protection law.
We have tried to write this in plain language rather than legal boilerplate. If anything here is unclear, write to us and we will explain it properly.
Who is responsible for your data
Casa di Lavalle is a single guesthouse in Skalados, Tinos, Greece. It is owned and run by Argentina & George, a private individual — not a company. Argentina & Georgeis the “data controller” for the purposes of this policy: the person responsible for deciding how your data is used, and for answering your questions about it.
- Address
- Skalados, Tinos 84200, Greece
- Property Registry Number
- AMA (Property Registry Number): 00002254020
- lavalletinos@gmail.com
- Phone
- +30 6973 999 211
What this website does
This website is informational. It describes the house and lets you get in touch — it does not take bookings, does not process payments, and does not handle card details. Reservations are made directly on Booking.com or Airbnb, who are independently responsible for the data you give them at that stage (see “Booking through Booking.com or Airbnb,” below).
This site uses no cookies and no analytics or tracking scripts of any kind. Nothing on it identifies you or follows you between visits or between pages. The “Enquire” and “WhatsApp” buttons simply open your own email or WhatsApp app with our address filled in — nothing you type is sent to a server we control before you choose to send it from your own app. No contact form on this site posts data anywhere.
Data we collect, and why
We collect personal data in three different situations, for three different reasons.
1. When you send us an enquiry
If you email us or message us on WhatsApp, we receive whatever you choose to write — typically your name, contact details, travel dates, and number of guests. We use this to answer your question and, if it leads to a booking, to help arrange your stay. Our legal basis for this is legitimate interest: responding to someone who has contacted us, and taking steps at their request towards a possible booking. We keep enquiry messages for as long as needed to respond to your enquiry, and no longer than 24 months.
2. When you check in
Greek law requires every short-term-rental host to record identity information for each adult guest — full name, ID or passport number, and nationality — and to report it to the relevant authorities. We collect this at check-in for that reason alone. Our legal basis is a legal obligation, not your consent, and we keep it separately from enquiry records, used only for this purpose and for exactly as long as the applicable Greek regulations require.
3. When you book through Booking.com or Airbnb
If you reserve through one of those platforms, they pass us the booking details we need to host you — usually your name, dates, and a way to contact you. Booking.com and Airbnb are themselves independently responsible (separate data controllers) for how they collect and use your data up to that point. Their own privacy policies apply to that part of the process:
Other companies involved
A few other companies handle data on our behalf, or independently as part of running this website and this business:
- Vercel, our website host, which serves this site.
- Google/Gmail (based in the USA), who host our enquiry email address.
- Booking.com and Airbnb, as above.
Google is certified under the EU–US Data Privacy Framework, the recognised legal basis for transferring data to Gmail’s US infrastructure.
We do not sell, rent, or trade your data, and we do not use it for advertising.
How we keep your data safe
We keep the amount of data we hold deliberately small: we only ever ask for what a given purpose actually needs, and nothing more. Identity records collected at check-in are kept privately and are not shared with anyone beyond the authorities we are legally required to report to. Our email accounts are protected with strong, unique passwords and two-factor authentication.
Sensitive data and children
We do not ask for or knowingly collect any special category of data — health, religion, political opinion, and similar — through this website. This website is not directed at children, and we do not knowingly collect data from them.
Your rights
Under the GDPR, you have a set of rights over your own data, and you can ask us at any time to:
- tell you what data we hold about you (access)
- correct it if it is wrong (rectification)
- delete it (erasure)
- limit how we use it (restriction)
- give you a copy in a portable format (portability)
- stop using it for a particular purpose (objection)
These rights are not absolute — for example, we cannot delete identity records we are legally required to keep — but we will always tell you plainly if and why a request cannot be met in full. To exercise any of these rights, email lavalletinos@gmail.com. We will respond within a reasonable time and, where the law requires it, within one month.
If you are unhappy with how we have handled your data, you also have the right to complain to Greece’s data protection regulator:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias Avenue 1-3, PC 115 23, Athens, Greece
Telephone: +30-210 6475600
Email: contact@dpa.gr
https://www.dpa.gr/en
Changes to this policy
We may update this page from time to time — for example, if we start using a different email provider or change how we work with Booking.com or Airbnb. The date at the top of this page shows when it was last changed.