Privacy Policy

Data Controller: Aura Otto Luxury Living

Registered Office / Address: Paralia Mesimvrias, Paralia Dikellon, 681 00, Greece

VAT Number: 139435167

Tax Authority: Alexandroupolis

Contact Telephone: +30 690 611 8567

Email: info@auraotto.com

Last Updated: July 26, 2026

Welcome to Aura Otto Luxury Living. We are fully committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, process, and protect your personal data when you visit our website, make a direct booking, fill out our contact form, or submit an availability inquiry (Request Booking Form).

Our processing operations are carried out in strict compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the applicable Greek data protection legislation. This Privacy Policy applies to the website www.auraotto.com and all services provided by Aura Otto Luxury Living.

Please read this Privacy Policy carefully to understand how we process your personal data and protect your privacy when you use our website and services.

1. What Personal Data We Collect

We collect and process different types of personal data depending on how you interact with us:

  • Booking & Inquiry Data: When you make a booking or submit a request form, we collect your full name, email address, contact telephone number, check-in/check-out dates, and payment information. Additionally, upon arrival or during official check-in, we collect identification data, including your ID card or passport details, as required by law for guest registration.

  • Technical & Operational Data: When you browse our website, technical information such as your IP address, browser type, device information, and pages visited may be automatically collected for security, maintenance, and operational purposes.

  • Consent Preferences: We store your cookie and consent preferences as necessary to remember your choices and comply with applicable legal requirements.

  • Children's Data: Our services are intended for adults making accommodation reservations. We do not knowingly collect personal data directly from children. Any information relating to minors is provided by parents or legal guardians solely for accommodation purposes.

1A. Cookies and Similar Technologies

Our website uses cookies and similar technologies to ensure the proper operation, security, and functionality of the website.

  • Detailed information regarding the categories of cookies we use, their purposes, retention periods, and your choices regarding cookies can be found in our separate Cookies Policy.

  • Where required by applicable law, non-essential cookies will only be used after obtaining your consent.

2. Purposes and Legal Bases for Processing

We process your personal data under the following legal foundations:

  • Performance of a Contract (GDPR Art. 6(1)(b)): To process, manage, and complete your accommodation booking or respond to your availability requests, and to validate booking dates and transaction payments. Providing this information is mandatory; without it, we cannot provide our services.

  • Legitimate Interests (GDPR Art. 6(1)(f)): To optimize our website's performance, layout, and overall user experience. Furthermore, for the safety and security of our guests, staff, and property, selected common and external areas of the property are monitored by a closed-circuit television (CCTV) system. Cameras are not installed inside guest accommodations or private areas. CCTV recordings are retained only for a limited period unless required for the investigation of an incident.

  • Compliance with a Legal Obligation (GDPR Art. 6(1)(c)): To comply with Greek and European legal, tax, police, and financial regulations governing the hospitality industry. This includes our statutory obligation to collect passport or ID details to maintain an official guest registry and report arrivals to the competent tax and police authorities.

  • Consent (GDPR Art. 6(1)(a)): To send you promotional updates and newsletters, but only if you have provided your explicit, opt-in consent to do so. You have the right to withdraw this consent at any time.

3. Sharing and Disclosure of Personal Data

We do not sell or rent your personal data. We only share your data with trusted third parties strictly under the following conditions:

  • Authorized Processors: This may include website hosting providers, reservation management systems (including our online booking platform), technical support providers, and communication service providers acting solely under our instructions and subject to confidentiality obligations.

  • Payment Processing: Online card payments are securely processed via our partner banking institution, Piraeus Bank (ePOS), acting as an independent data controller. You can review Piraeus Bank's Privacy Policy on its official website.

  • Legal & Law Enforcement Authorities: When mandated by law, we will disclose personal data to police, judicial, or regulatory authorities to comply with legal obligations, prevent fraud, or protect the rights, safety, and legitimate interests of our guests, staff, and business.

  • International Transfers: If any personal data is transferred outside the European Economic Area (EEA), we ensure that appropriate safeguards (such as EU Standard Contractual Clauses) are in place to guarantee that your data remains fully protected.

We may also process or disclose personal data where necessary for the establishment, exercise, or defense of legal claims.

4. Data Retention Period

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with applicable legal obligations.

Typical retention periods include:

  • Booking and invoicing records: up to ten (10) years in accordance with Greek tax legislation.

  • Contact and inquiry information: up to twenty-four (24) months after the last communication.

  • Newsletter subscriptions: until consent is withdrawn.

  • CCTV recordings: generally retained for up to fifteen (15) days unless required for the investigation of an incident or legal obligation.

  • Technical and server log information: retained only as necessary for security and operational purposes.

Upon expiration of the applicable retention period, personal data is securely deleted or anonymized.

5. Your Rights Under the GDPR

As a data subject, you possess the following rights regarding your personal information:

  • Right of Access: You have the right to request a copy of the personal data we hold about you.

  • Right to Rectification: You can request that we correct any inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): You have the right to request the deletion of your data, subject to legal or financial retention obligations.

  • Right to Restrict Processing: You can request that we limit the way we process your data under specific legal conditions.

  • Right to Data Portability: You can request your data in a structured, commonly used, and machine-readable format, or ask us to transfer it to another controller.

  • Right to Object: You have the right to object to processing based on our legitimate interests.

  • Right to Withdraw Consent: Where processing is based on your consent (e.g., newsletters), you can withdraw it at any time by clicking "Unsubscribe" or contacting us directly.

To exercise any of these rights, please submit your request to our email: info@auraotto.com. We will respond to your request within one (1) month, free of charge.

  • Right to Lodge a Complaint: If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) via their official portal: www.dpa.gr

  • You also have the right to seek judicial remedies if you believe your rights under applicable data protection legislation have been violated.

  • We may request reasonable information to verify the identity of the person submitting a data protection request before responding to such request.

6. Data Security

We implement strict technical, organizational, and administrative security measures (including encryption protocols and specialized security software) to protect your personal data from unauthorized access, loss, alteration, or disclosure. Please note that, while we implement appropriate security measures, no method of electronic transmission or storage can be guaranteed to be completely secure.

7. Changes to This Privacy Policy

We reserve the right to amend this Privacy Policy from time to time in response to legal or technical updates. Any changes will be posted on this page, and a prominent notification will be placed on our homepage.

8. Contact Information

For any questions, concerns, complaints, or requests regarding this Privacy Policy or the handling of your personal data, please contact us at:

Aura Otto Luxury Living Paralia Mesimvrias, Paralia Dikellon, 681 00, Greece

Email: info@auraotto.com

Telephone: +30 690 611 8567

Online bookings are temporarily unavailable due to maintenance.