Privacy Policy

How we collect, use and protect your personal data.

1. Who We Are

 Coastal Cruises & Tours
Agias Paraskevis str. 35 (main office)
Hersonissos, Crete, Greece 70014
Email: info@coastaltourscrete.com
Phone: +302897023802 , +306977181078

We operate as a travel agency offering excursions, boat trips, safari experiences, activities, private tours and related travel services in Crete.

2. What Personal Data We Collect

When you contact us, submit an inquiry, request a booking, or use our website, we may collect:
• Full name
• Email address
• Phone number / WhatsApp number
• Message content and inquiry details
• Booking or reservation details
• Information related to your requested service
• Technical information such as IP address, browser type, device information, and website usage data, where applicable

Under EU data protection rules, personal data can include identifiers such as names, contact details and online identifiers like IP addresses.https://europa.eu/youreurope/business/dealing-with-customers/data-protection/index_en.htm

3. How We Use Your Data

We use your personal data for the following purposes:
• To respond to your inquiries
• To provide information about our tours and services
• To manage bookings and reservations
• To contact you regarding your requested excursion or service
• To improve our website, customer service and business operations
• To comply with legal or regulatory obligations

The GDPR requires that personal data be processed lawfully, fairly and transparently, and only for specified purposes. https://commission.europa.eu/law/law-topic/data-protection/data-protection-explained_en

4. Legal Basis for Processing

We process your personal data only when we have a valid legal basis to do so. Depending on the situation, this may include:
• Your consent
• The performance of a contract or steps prior to entering into a contract
• Compliance with legal obligations
• Our legitimate interests, provided your rights and freedoms do not override those interests

EU guidance for businesses explains that organisations must identify an appropriate legal basis when processing personal data.https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations_en

5. Cookies and Similar Technologies

Our website may use cookies and similar technologies to ensure proper website functionality and, where applicable, to collect analytics or marketing information.

Necessary cookies may be used for essential website functions. Any optional cookies, including analytics or other non-essential trackers, should only be used after you have given your consent. The Hellenic Data Protection Authority and EU guidance both distinguish necessary cookies from optional cookies that require consent.https://www.dpa.gr/en/cookiespolicy/information/whatare_cookies

You can manage your cookie preferences through our cookie banner or through your browser settings. The Hellenic DPA notes that browser settings can also be used to manage cookies. https://www.dpa.gr/en/cookiespolicy/information/browsers_and_cookies

6. Data Sharing

We do not sell your personal data.

We may share your data, where necessary, with:
• Tour operators, boat operators, guides or service providers involved in delivering the requested service
• Website hosting, email, analytics or technical support providers
• Professional advisers, if required
• Public authorities or regulators, where required by law

We only share the minimum data necessary for the relevant purpose.

7. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including to respond to inquiries, manage bookings, meet legal obligations, resolve disputes, and maintain business records. The GDPR includes the principle of storage limitation, meaning data should not be kept longer than necessary. https://commission.europa.eu/law/law-topic/data-protection/data-protection-explained_en

8. Data Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure. GDPR principles include integrity, confidentiality and accountability.https://commission.europa.eu/law/law-topic/data-protection/data-protection-explained_en

9. Your Rights

Depending on the circumstances, you may have the right to:
• Request access to your personal data
• Request correction of inaccurate data
• Request deletion of your data
• Request restriction of processing
• Object to certain processing activities
• Request data portability, where applicable
• Withdraw consent at any time, where processing is based on consent

EU data protection rules require businesses to help individuals exercise their rights under the GDPR. https://commission.europa.eu/law/law-topic/data-protection/rules-business-and-organisations_en

To exercise any of these rights, please contact us at:
Email: info@coastaltourscrete.com

10. Third-Party Links

Our website may contain links to third-party websites or services. We are not responsible for the privacy practices of those external websites, and we encourage you to review their privacy policies separately.

11. Contact and Complaints

If you have any questions about this Privacy Policy or the way we handle your personal data, please contact us at:

Coastal Cruises & Tours
Agias Paraskevis str. 35 (main office)
Hersonissos, Crete, Greece 70014
Email: info@coastaltourscrete.com
Phone: +302897023802 , +306977181078

You also have the right to lodge a complaint with the competent data protection authority.

12. Updates to This Privacy Policy

We may update this Privacy Policy from time to time to reflect legal, technical or operational changes. Any updated version will be posted on this page with the revised effective date.

Effective Date: 10th March 2026