Privacy Policy

Last updated: 3 September 2026

This policy explains how ΓΕΩΡΓΙΟΣ ΚΑΙ ΕΜΜΑΝΟΥΗΛ ΠΟΛΙΤΗΣ Ο.Ε., referred to as "we", "us" or the "Company", processes personal data when you visit this Website, contact us or request a transfer.

It is written for the General Data Protection Regulation, Regulation (EU) 2016/679, Greek Law 4624/2019 and Greek Law 3471/2006 on electronic communications. It describes the current Website and booking service.

1. Data Controller

ΓΕΩΡΓΙΟΣ ΚΑΙ ΕΜΜΑΝΟΥΗΛ ΠΟΛΙΤΗΣ Ο.Ε.

Registered seat: Andrea Nathena 22, Heraklion, Crete, Greece
Tel.: +30 6970 225 992
Email: info@kretarides.com

2. Data We Process and Its Source

2.1 Booking and contact data

  • Name, email address and telephone number, including WhatsApp or Viber details when supplied
  • Pickup and destination, date, time, hotel or accommodation and flight number
  • Passenger count, luggage, child seats, selected vehicle and accessibility requests
  • Route, fare, booking reference, status, price proposal decisions and service messages
  • Notes you choose to write and records of changes, cancellation, reminders and support

We receive these data from you or from the person, hotel, agency or travel organiser making the request for you. If a request includes another person's data, we remain responsible for giving that person the information required by Article 14 GDPR, normally at our first contact and no later than one month after receiving the data.

2.2 Website and technical data

  • IP address, request time, security events and approximate country or region in hosting and security logs
  • Browser, device, operating system, language and pages requested
  • Location search and routing queries entered in the booking form
  • Necessary browser storage containing language, consent choice, booking draft and recent order details
  • Page use, clicks, scrolling, campaign parameters, referrer, advertising click identifiers and booking measurement fields as described in section 9

Required fields are marked in the form. Without the required contact, route, pickup and passenger details, we cannot assess or provide the transfer. Optional fields can be left blank. Do not send payment card details because the Website does not take online payment.

3. Purposes and Legal Bases

  • To answer a quote or booking request, confirm and perform a transfer, manage changes and provide support. The basis is Article 6(1)(b) GDPR, requested steps before a contract and performance of a contract.
  • To send confirmations, price decisions, cancellation notices, pickup reminders and optional calendar files or links. These are service messages under Article 6(1)(b) GDPR.
  • To keep accounting information required by law and answer a lawful authority request. The basis is Article 6(1)(c) GDPR.
  • To secure the service, prevent abuse, resolve complaints and establish or defend legal claims. The basis is Article 6(1)(f) GDPR and our legitimate interest in a safe and accountable service.
  • To invite an honest review only with consent, or where Article 11(3) of Greek Law 3471/2006 permits contact with an existing customer about our own similar service. The GDPR basis is consent under Article 6(1)(a), or our legitimate interest under Article 6(1)(f) together with that existing customer exception. Every invitation offers a free and easy way to object.
  • To set or read optional analytics and advertising cookies. The basis is Article 6(1)(a) GDPR and Article 4(5) of Greek Law 3471/2006, namely your consent.
  • To send limited Google consent state and cookieless measurement signals while optional storage is denied. We rely on Article 6(1)(f) GDPR and our legitimate interest in measuring service and campaign results without optional browser storage. You may object by contacting us.
  • To retain a broad source label with a submitted booking when optional measurement storage is not allowed. We rely on Article 6(1)(f) GDPR and our legitimate interest in understanding whether bookings came from OpenAI Ads, Google Ads or an organic ChatGPT referral without retaining click identifiers or browsing history. You may object by contacting us.
  • To measure OpenAI Ads campaign conversions after advertising consent. We use the OpenAI Measurement Pixel and Conversions API for booking events, an opaque advertising reference and protected matching data. The basis is your consent under Article 6(1)(a) GDPR and Article 4(5) of Greek Law 3471/2006.

We do not make a decision producing legal or similarly significant effects solely by automated means. A route estimate or automatic price can be checked by staff, and a custom quote is confirmed separately.

If you actively request accessibility assistance and explicitly agree through the booking option, we process health information you choose to provide only to arrange that assistance. The special category basis is your explicit consent under Article 9(2)(a) GDPR. Otherwise, do not provide diagnoses or other health information.

4. Recipients and Service Providers

  • The assigned driver and, where needed, a licensed cooperating carrier for the transfer
  • Cloudflare and Supabase for hosting, security, the booking database and application services, and Zoho or ZeptoMail for operational email
  • OpenStreetMap, Nominatim, OSRM or OpenRouteService for place and route functions, and AeroDataBox through RapidAPI when authorised staff check a supplied flight number
  • Google Calendar only if you open an add to calendar link. Event details in the link are then sent to Google. A downloaded calendar file stays with your chosen calendar application
  • Google Analytics, Google Ads, Google Data Manager, OpenAI Ads (Measurement Pixel and Conversions API) and Microsoft Clarity for the measurement described in section 9
  • Google, Trustpilot or Tripadvisor for a permitted review invitation or when you open a review link, and WhatsApp, Viber, telephone or email providers when you choose that channel
  • Professional advisers, courts and public authorities where law or a legal claim requires it

A provider receives only data needed for its role. Depending on that role, it acts under our instructions as a processor or determines its own processing as a separate controller. Cooperating carriers receive only operational details needed to perform the transfer.

5. International Transfers

Some providers may process data outside the European Economic Area. For each transfer we use the safeguard that applies to that provider, such as an adequacy decision, an active EU US Data Privacy Framework certification where applicable, or the European Commission Standard Contractual Clauses with suitable supplementary measures. The same safeguard does not necessarily apply to every provider. You may ask us which safeguard applies to your data.

6. Retention

  • Quote requests and contact messages are kept while we answer the request and for as long as reasonably needed for follow up, a complaint or a legal claim. They are then deleted or anonymised.
  • Operational booking details are kept while needed to arrange and complete the transfer, provide support and handle cancellations, complaints or legal claims. We minimise or delete them when those purposes and the relevant limitation periods end.
  • The accounting subset is kept for at least five years from the end of the relevant accounting period. It may be kept longer during a tax audit, legal proceeding or applicable limitation period.
  • Service messages, price decisions and review invitation records follow the related request or booking. Security and delivery logs are kept only while needed to protect the service, investigate an incident or prove delivery.
  • A browser booking draft remains for the browser session. Recent order details remain in that browser for up to 90 days. The language cookie and active consent choice are used for up to 180 days. Their local storage records can remain until replaced or browser data are cleared.
  • Consented campaign information in the browser remains until the session ends or the relevant consent is withdrawn. Google Ads attribution cookies can remain for up to 90 days.
  • OpenAI Ads event and campaign data follow OpenAI's applicable policies and the configured data source. After advertising consent, the Pixel may retain the opaque __oppref click reference and __obref browser reference under those policies and settings. Our session-storage copy is removed when the session ends or advertising consent is withdrawn.
  • Google Analytics user and event data follow the current property retention setting. We review that setting against the need to compare recent and seasonal website use, and reduce it when a shorter period is sufficient. You may ask us for the current setting. Aggregated reports may remain longer. Microsoft Clarity recordings are available for 30 days, while selected session, click and heatmap data remain for up to nine months.

At each review point we delete, anonymise or restrict data no longer needed. A dispute, legal hold, tax audit or rights request may pause deletion for the affected record. We do not keep all passenger details merely because a smaller accounting record must remain.

7. Your Rights

  • Access your personal data and receive a copy
  • Correct inaccurate or incomplete data
  • Request deletion or restriction where the legal conditions apply
  • Receive data you provided in a portable format where the right applies
  • Object to processing based on legitimate interests and object at any time to direct marketing
  • Withdraw analytics or advertising consent at any time through Cookie settings without affecting earlier lawful processing
  • Complain to the Hellenic Data Protection Authority or another competent supervisory authority

We normally respond within one month. A complex or numerous request may require up to two further months, and we will explain the extension within the first month. We may ask for proportionate information to verify identity.

To exercise a right, contact info@kretarides.com.

You may lodge a complaint with the Hellenic Data Protection Authority, 1 to 3 Kifisias Avenue, 115 23 Athens, Greece, telephone +30 210 6475600. HDPA complaint information.

8. Children and Data About Other People

The person making a booking must be at least 18. Children may travel as passengers, and we process only details needed for passenger count, child seats and safe service. The Website is not directed to children and we do not knowingly ask a child to consent to analytics or advertising.

9. Cookies, Browser Storage and Measurement

9.1 Strictly necessary storage

  • The language preference is kept in a cookie for up to 180 days and in browser storage until the choice changes or browser data are cleared.
  • The consent choice is treated as current for up to 180 days. Its browser record can remain until it is replaced or browser data are cleared.
  • A booking draft, including details entered in the form, remains in session storage until the browser session ends.
  • Recent submitted request details remain in local storage for up to 90 days so the customer can retrieve the request.
  • Cloudflare may set short lived security cookies when a threat check or challenge is needed. These are used only for security and delivery.

9.2 Optional cookies

  • Google Analytics may set _ga and _ga followed by a property identifier for up to two years after analytics consent to distinguish browser visits and measure website use.
  • Microsoft Clarity may set _clck for up to one year and _clsk for about one day, with related Microsoft domain cookies described by Microsoft, after analytics consent to provide session, click and layout insights.
  • Google Ads may set _gcl cookies for campaign attribution for up to 90 days when the relevant optional category is enabled.
  • After advertising consent, the OpenAI Ads Pixel may store the opaque __oppref advertising click reference and the opaque __obref browser reference. It may also store the consent state in the __oaiq_consent cookie and the oaiq_consent browser record. The Conversions API does not require a browser cookie.
  • With relevant consent, campaign information may be kept in session storage until the session ends or consent is withdrawn.

9.3 Google Consent Mode

Google Consent Mode starts with analytics and advertising storage denied. The Google tag can load before acceptance and may send limited cookieless consent and measurement data even after rejection. This can include network details such as IP address and approximate area, page address and title, browser and device details, event time, campaign parameters and a temporary identifier. Booking measurement can also include route category, fare, currency, vehicle category, time until pickup and language. We exclude the customer's name, readable email address, telephone number, hotel, free text notes and public booking reference from these denied storage signals.

While Google storage is denied, the tag is instructed not to read or write optional Google analytics or advertising cookies. Microsoft Clarity does not load without analytics consent. Enabling a category permits the corresponding cookies and fuller measurement. Withdrawing a category sends the updated choice and stops its active use. When both optional categories are rejected, the Website also attempts to remove Google cookies it can access.

9.4 Privacy-minimised booking source

When optional measurement storage is not allowed, the Website may keep only a broad source label with a submitted booking: OpenAI Ads, Google Ads or an organic ChatGPT referral. The label is derived in volatile page memory and is not placed in browser storage. In this limited record we do not retain an advertising click reference, campaign, keyword, referring address, page history, device details or analytics identifier, and we do not send an OpenAI Ads conversion. This processing is based on our legitimate interest in understanding how customers find the service; you may object by contacting us.

9.5 Consented completed transfer measurement

With advertising consent, after staff marks a transfer completed, we may send Google Ads the fare, completion time, an internal reference, protected contact matching data and an advertising click identifier when available. This measures completed transfer revenue and prevents duplicate records. Readable contact details and journey details are excluded.

9.6 OpenAI Ads conversion measurement

After advertising consent, the OpenAI Ads Measurement Pixel and Conversions API may receive a booking event, the source page, the opaque __oppref click and __obref browser references when available, an event identifier, the fixed fare in euro minor units with currency code EUR, and SHA-256 protected matching values derived from an email address, telephone number or name when supplied. We do not send raw contact details, hotel details, free-text notes or route details in this OpenAI Ads event. The event is used only to measure and optimise the Kreta Rides campaign. OpenAI processes the data under its applicable policies; you can withdraw advertising consent in Cookie settings.

Accept, reject or manage categories in the first banner. Open Cookie settings in the footer at any time to change the choice. Acceptance and rejection are remembered for the same 180 day period. The booking service remains available without optional cookies.

10. Security and Policy Changes

We use access controls, encrypted transport, restricted administration, validation, logging and service monitoring appropriate to the processing. No internet service can promise absolute security. Tell us promptly if you believe booking data or a private link has been exposed.

We update this policy when processing, providers or legal requirements change. The date above identifies the published version. A material change affecting consent will trigger a new choice where required.

See also our Legal Notice and Booking Terms.