1. WHO WE ARE
This Privacy Policy explains how
GAVEL IKE, a Private Company (IKE), registered in Greece under GEMI number
2654579071000 and VAT/TIN
7031676, trading as “Lyons Concierge” (“Lyons Concierge”, “we”, “us” or “our”), collects and processes personal data through www.lyonsconcierge.com, our communications and the travel, accommodation, rental and concierge services we arrange or provide.
Data controller:
GAVEL IKE, registered office at
299 Kifisias Avenue, 145 61, Greece. Tax office: KEFODE ATTIKIS. Operational contact locations currently displayed on the Website are 299 Kifisias Avenue, Kifisia 145 61, Greece, and Agios Stefanos, Mykonos 846 00, Greece. Email:
info@lyonsconcierge.com. Telephone:
+30 693 918 2219.
2. SCOPE OF THIS POLICY
This Policy applies when you visit the Website, submit an enquiry, request a quotation, make or manage a booking, purchase or request a concierge service, communicate with us by email, telephone, messaging application, live chat or social media, subscribe to marketing, or otherwise interact with Lyons Concierge.
Separate privacy notices may apply where a property owner, transport operator, yacht operator, aviation provider, venue, payment provider or other independent supplier determines its own purposes and means of processing. We encourage you to review the supplier’s notice where it is provided to you.
3. PERSONAL DATA WE COLLECT
- Identity and contact data: name, surname, email address, telephone number, postal address, nationality and preferred language.
- Enquiry and travel data: arrival and departure dates, destination, group size, age of guests where relevant, accommodation preferences, transport details, itinerary, requested services and the content of messages.
- Booking and contract data: booking reference, selected property or service, agreed price, deposits, balance status, cancellation details, special instructions and correspondence relating to the booking.
- Payment and billing data: billing details, transaction references and payment status. Full card data is normally processed directly by the relevant payment provider and should not be sent to us by ordinary email or chat.
- Identification and compliance data: passport or identity-document information, tax details, guest lists or other information where required for check-in, property access, transport, fraud prevention, security or legal compliance.
- Service-preference data: dietary preferences, accessibility needs, allergies or other information you choose to provide so that a requested service can be arranged. Where such information reveals health, religious or other special-category data, we process it only where necessary and with an appropriate legal basis, including explicit consent where required.
- Technical and usage data: IP address, device and browser information, operating system, approximate location, log files, page interactions, referral source, cookie identifiers and consent choices.
- Marketing and communications data: newsletter subscription status, campaign interactions, communication preferences and records of consent or objection.
- Data received from others: information supplied by another guest, a travel advisor, company, property owner, supplier, partner or person acting on your behalf.
4. HOW WE USE PERSONAL DATA AND OUR LEGAL BASES
| Purpose |
Typical data used |
Legal basis |
| Respond to enquiries and prepare quotations |
Contact, travel, preference and message data |
Steps requested before a contract; legitimate interests |
| Create and administer bookings |
Identity, contact, booking, guest, billing and payment-status data |
Contract; legal obligations |
| Arrange villas, transport, yachts, vehicles, aviation, chefs, wellness, security, events and other services |
Identity, contact, itinerary, service preferences and booking data |
Contract; steps requested before a contract |
| Communicate service updates and provide support |
Contact, booking, communications and complaint data |
Contract; legitimate interests |
| Prevent fraud, misuse and security incidents |
Identity, payment-status, device, log and communications data |
Legitimate interests; legal obligations |
| Comply with tax, accounting, regulatory and legal duties |
Contract, invoice, transaction and identification data |
Legal obligations |
| Improve the Website and understand usage |
Technical, usage and cookie data |
Consent for optional analytics; legitimate interests for essential security |
| Send offers and marketing |
Contact details, preferences and marketing interactions |
Consent, or legitimate interests where permitted by law |
| Establish, exercise or defend legal claims |
Relevant booking, communications, payment and incident data |
Legitimate interests; legal obligations |
5. WHERE DATA COMES FROM
We collect data directly from you, from a person acting on your behalf, from a lead guest or group organiser, from travel advisors and corporate clients, from property owners and service providers, from payment and fraud-prevention providers, from social-media or messaging platforms when you contact us, and automatically through the Website and its consented technologies.
When you provide personal data about another person, you confirm that you are authorised to do so and that you have informed that person about the relevant processing.
6. RECIPIENTS AND SERVICE PROVIDERS
We disclose personal data only where reasonably necessary for the purposes described in this Policy. Recipients may include:
- Property owners, villa managers, accommodation operators, house staff and check-in representatives.
- Chauffeur and transfer companies, vehicle-rental providers, yacht and boat operators, helicopter and private-aviation providers.
- Restaurants, venues, chefs, caterers, wellness professionals, event suppliers, security providers and other concierge partners.
- Payment processors, banks, insurers and fraud-prevention providers.
- Website hosting, content-delivery, cybersecurity, cloud, email, CRM, customer-support, live-chat, analytics and marketing providers.
- Professional advisers, auditors, accountants and lawyers.
- Public authorities, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law.
Some suppliers act as independent controllers and are responsible for their own processing. Others process data on our documented instructions under appropriate contractual safeguards.
7. INTERNATIONAL TRANSFERS
Some technology providers or travel suppliers may process personal data outside the European Economic Area. Where required, we use a lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses (SCCs), or another safeguard recognised under applicable data-protection law.
5. WHERE DATA COMES FROM
We collect data directly from you, from a person acting on your behalf, from a lead guest or group organiser, from travel advisors and corporate clients, from property owners and service providers, from payment and fraud-prevention providers, from social-media or messaging platforms when you contact us, and automatically through the Website and its consented technologies.
When you provide personal data about another person, you confirm that you are authorised to do so and that you have informed that person about the relevant processing.
6. RECIPIENTS AND SERVICE PROVIDERS
We disclose personal data only where reasonably necessary for the purposes described in this Policy. Recipients may include:
- Property owners, villa managers, accommodation operators, house staff and check-in representatives.
- Chauffeur and transfer companies, vehicle-rental providers, yacht and boat operators, helicopter and private-aviation providers.
- Restaurants, venues, chefs, caterers, wellness professionals, event suppliers, security providers and other concierge partners.
- Payment processors, banks, insurers and fraud-prevention providers.
- Website hosting, content-delivery, cybersecurity, cloud, email, CRM, customer-support, live-chat, analytics and marketing providers.
- Professional advisers, auditors, accountants and lawyers.
- Public authorities, regulators, courts or law-enforcement bodies where disclosure is required or permitted by law.
Some suppliers act as independent controllers and are responsible for their own processing. Others process data on our documented instructions under appropriate contractual safeguards.
7. INTERNATIONAL TRANSFERS
Some technology providers or travel suppliers may process personal data outside the European Economic Area. Where required, we use a lawful transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses (SCCs), or another safeguard recognised under applicable data-protection law.
8. RETENTION
We retain personal data only for as long as reasonably necessary for the relevant purpose, including contract administration, legal compliance, accounting, dispute resolution and the establishment or defence of claims. The criteria we use include the nature of the data, the duration of the relationship, legal limitation periods and statutory record-keeping requirements.
- Enquiries that do not result in a booking are generally retained for up to 24 months after the last meaningful contact, unless a shorter or longer period is justified.
- Booking, contract, invoice and transaction records are retained for the period required by applicable tax, accounting and commercial law and for any relevant claims period.
- Marketing data is retained until consent is withdrawn, an objection is made, or the data is no longer reasonably needed for the marketing purpose.
- Security logs are normally retained for a limited period and may be retained longer where necessary to investigate an incident or support a legal claim.
- Cookie retention periods are described in the Cookie Policy and in the live “Manage Consent” interface.
9. SECURITY
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, encryption in transit, secure hosting, backups, logging, staff confidentiality obligations, supplier due diligence and incident-response procedures. No online system is completely risk-free, so you should avoid sending highly sensitive information through unsecured channels.
10. YOUR DATA-PROTECTION RIGHTS
Subject to the conditions and exceptions in applicable law, you may have the right to:
- Receive information about the processing of your personal data and obtain access to it.
- Request correction of inaccurate or incomplete data.
- Request deletion of data.
- Request restriction of processing.
- Receive data you provided in a structured, commonly used and machine-readable format and request portability where applicable.
- Object to processing based on legitimate interests, including profiling, and object at any time to direct marketing.
- Withdraw consent at any time without affecting processing carried out before withdrawal.
- Lodge a complaint with the competent supervisory authority.
To exercise a right, email
info@lyonsconcierge.com with sufficient information to identify you and the request. We may ask for reasonable proof of identity. We normally respond within one month, subject to any extension allowed by law.
11. MARKETING COMMUNICATIONS
You can unsubscribe from promotional emails by using the unsubscribe link in the message or contacting us. Service and booking communications are not marketing and may continue where necessary to administer your request or contract.
12. COOKIES AND SIMILAR TECHNOLOGIES
The Website uses cookies and related technologies. Optional analytics, preference and marketing technologies are used only in accordance with the choices presented in the consent banner. Please see the Cookie Policy and use “Manage Consent” at the bottom of the Website to change or withdraw your choices.
13. CHILDREN
The Website is not directed to children. A booking must be made by an adult with legal capacity. Information about children may be processed where supplied by a parent, guardian or lead guest and where reasonably necessary to arrange family accommodation, transfers, safety requirements or other requested services.
14. AUTOMATED DECISION-MAKING
We do not make decisions producing legal or similarly significant effects solely by automated means unless we inform you separately and provide the protections required by law.
15. THIRD-PARTY WEBSITES AND PLATFORMS
The Website may link to third-party websites, maps, booking services, social networks or communication platforms. Their processing is governed by their own privacy notices. We are not responsible for the privacy practices of independent third parties.
16. CHANGES TO THIS POLICY
We may update this Policy to reflect legal, operational or technical changes. The revised version will be published on the Website with a new effective date. Material changes may also be communicated through an appropriate additional notice.
17. CONTACT AND COMPLAINTS
Controller: GAVEL IKE trading as Lyons Concierge
Registered office: 299 Kifisias Avenue, 145 61, Greece
Tax office: KEFODE ATTIKIS
Email: info@lyonsconcierge.com
Telephone: +30 693 918 2219
You also have the right to complain to the Hellenic Data Protection Authority (HDPA). Website:
www.dpa.gr.
Postal address: 1-3 Kifisias Avenue, 115 23 Athens, Greece.