MONTECRISTO SUMMER CLUB
Privacy Policy
Last updated: [date of publication]
This Privacy Policy explains how your personal data is collected, used and protected when you visit and use the website www.montecristosummerclub.com (the “Website”). We are committed to processing your personal data lawfully, fairly and transparently, in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”), Greek Law 4624/2019 and Greek Law 3471/2006 on the protection of personal data in electronic communications.
- Who we are (Data Controller)
The data controller responsible for the processing of personal data through the Website is:
- Legal name: ΧΡ. ΤΖΩΡΑΣ & ΣΙΑ Ε.Ε. (CHR. TZORAS & SIA E.E.), a limited partnership established under Greek law
- Distinctive title / brand: “Monte Christo Summer Club” Activity: Beverage service / hospitality and events
- Registered address: Pyrgi, Agios Markos, Corfu, Greece
- VAT number (Α.Φ.Μ.): 801949737 — Tax Office (Δ.Ο.Υ.): Corfu
- General Commercial Registry (Γ.Ε.ΜΗ.) no.: 166874033000
- Email for privacy matters:
- Telephone: +30 693 973 0056
We have not appointed a Data Protection Officer (DPO), as we are not required to do so under Article 37 GDPR. For any question relating to this Policy or to your personal data, you may contact us using the details above.
- Scope of this Policy
This Policy applies to personal data we process in connection with the Website and our related communications. It does not apply to third-party websites or services that you may reach through links on our Website, including the ticketing platform on which ticket purchases are completed (see Section 6). Those services have their own privacy policies, which we encourage you to read.
- What personal data we collect
3.1 Data you provide to us
- Contact and enquiries: your name, email address, telephone number and the content of your message when you use a contact form, or contact us by email or phone.
- Newsletter / marketing sign-up: your email address (and, optionally, your name) where you choose to subscribe to updates about our events.
- Social media interactions: any information you share with us through our social media pages.
3.2 Data we collect automatically
- Technical and usage data: IP address, device and browser type, operating system, referring website, the pages you visit, and date/time of access, collected through our servers and through cookies and similar technologies (see Section 5).
3.3 Data we do not collect
We do not collect or process your payment card details or ticket purchase information on this Website. These are collected directly by the ticketing platform (see Section 6).
- Why we use your data and our legal bases
Purpose | Legal basis (GDPR) |
|---|---|
Operating, maintaining and securing the Website | Legitimate interests — Art. 6(1)(f) |
Responding to your enquiries and requests | Legitimate interests, or steps prior to a contract — Art. 6(1)(f) / 6(1)(b) |
Presenting event and concert information and directing you to the ticketing platform | Legitimate interests — Art. 6(1)(f) |
Sending you our newsletter and marketing communications about events | Your consent — Art. 6(1)(a) (and Art. 11 of Law 3471/2006) |
Analytics, statistics and improving the Website | Your consent for non-essential cookies — Art. 6(1)(a) |
Complying with our legal obligations (e.g. tax and accounting, responding to lawful requests) | Legal obligation — Art. 6(1)(c) |
Establishing, exercising or defending legal claims | Legitimate interests — Art. 6(1)(f) |
Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
- Cookies and similar technologies
The Website uses cookies and similar technologies. Strictly necessary cookies, required for the Website to function, are always active. Non-essential cookies (such as analytics and marketing cookies) are used only with your prior consent, which you give through our cookie consent banner and can change or withdraw at any time. Full details of the cookies we use, their purpose and duration are set out in our separate Cookie Policy.
- Ticket purchases and redirection to the ticketing platform
Tickets for our concerts and events are not sold or paid for on this Website. When you choose to buy a ticket, you are redirected to Ticketmaster (www.ticketmaster.gr), an external platform operated by its own company. From that point, the purchase takes place entirely on Ticketmaster’s environment.
Ticketmaster acts as an independent data controller for any personal data you provide there (such as your name, contact details and payment information). We do not control and are not responsible for Ticketmaster’s processing of your data, which is governed by Ticketmaster’s own privacy policy, available at www.ticketmaster.gr. We do not receive your payment details.
- Who we share your data with
We do not sell your personal data. We may share it with:
- Service providers acting as our processors under Article 28 GDPR — for example, our website hosting provider, email/newsletter platform, analytics provider and IT support. They process data only on our instructions.
- The ticketing platform (Ticketmaster), as an independent controller, when you choose to proceed to purchase (see Section 6).
- Social media platforms, where you interact with our pages or where such tools are used on the Website with your consent.
- Professional advisors (such as accountants and lawyers) and public authorities, where required by law.
- International transfers
Some of our service providers (for example, analytics or communication tools) may process data outside the European Economic Area (EEA), including in the United States. Where this happens, we ensure an appropriate safeguard is in place, such as an adequacy decision of the European Commission (including the EU–US Data Privacy Framework) or the European Commission’s Standard Contractual Clauses under Article 46 GDPR. You may request more information using the contact details in Section 1.
- How long we keep your data
We keep personal data only for as long as necessary for the purposes described above:
- Enquiries and contact messages: for as long as needed to handle your request and a reasonable period afterwards
- Newsletter / marketing: until you unsubscribe or withdraw your consent.
- Technical / server log data: for a limited period
- Accounting and tax records: for as long as required by Greek tax and accounting legislation (generally at least five (5) years).
When data is no longer needed, we delete or anonymise it.
- Your rights
Under the GDPR and Greek Law 4624/2019, you have the right to:
- request access to your personal data;
- request rectification of inaccurate or incomplete data;
- request erasure (“right to be forgotten”), where applicable;
- request restriction of processing;
- object to processing based on our legitimate interests, and to object to direct marketing at any time;
- request data portability;
- withdraw your consent at any time, where processing is based on consent.
To exercise your rights, contact us using the details in Section 1. We will respond within one (1) month, as provided by Article 12 GDPR. Exercising your rights is free of charge, unless requests are manifestly unfounded or excessive.
If you believe your data protection rights have been infringed, you have the right to lodge a complaint with the supervisory authority:
Hellenic Data Protection Authority (HDPA) Kifisias Avenue 1–3, 115 23 Athens, Greece Tel.: +30 210 6475600 · Fax: +30 210 6475628 Email: · Complaints: Website: www.dpa.gr/en |
We would, however, appreciate the chance to address your concerns before you approach the Authority, so please consider contacting us first.
- Children
The Website and our events are not directed at children. Where processing is based on consent and offered to minors, under Greek law (Article 21 of Law 4624/2019) such consent is valid only if the minor is at least 18 years old; for children under 18, the consent of the holder of parental responsibility is required. We do not knowingly collect personal data from children under 18 without such consent. Age restrictions for specific events are set by the organiser and/or the ticketing platform.
- Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, in accordance with Article 32 GDPR. While no method of transmission over the internet is completely secure, we work to protect your data and to keep our measures under review.
- Automated decision-making
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you.
- Changes to this Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top shows the latest version. Where changes are material, we will take reasonable steps to inform you.
Contact
For any question about this Policy or about how we handle your personal data, please contact us at , or by post at the registered address in Section 1.
This Privacy Policy is provided in English for the international audience of the Website. In case of any discrepancy with a Greek-language version, please contact us for clarification.
