Privacy Policy
Last updated: 4 July 2026
This Privacy Policy explains how Rhodes Youth Hostel collects, uses, stores and protects personal data when you visit this website, contact us through the contact form, use booking-related links, or interact with services available through the website.
- Who we are
This website is operated by:
Rhodes Youth Hostel “ΜΑΓΚΑΦΑΣ ΝΙΚΟΛΑΟΣ ΠΑΝΑΓΙΩΤΗΣ”
Ergeiou 12, Rhodes Old Town
85100 Rhodes, Greece
Email: info@rhodesyouthhostel.com
Telephone: +30 22410 30491
Website: https://rhodesyouthhostel.com
For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the above operator is the data controller for personal data collected through this website, unless otherwise stated.
- Scope of this Privacy Policy
This Privacy Policy applies to personal data processed through this website, including:
visits to rhodesyouthhostel.com;
contact form submissions;
cookie consent choices;
website analytics and statistics;
embedded services such as Google Maps;
booking-related links or booking engine access;
technical and security processing related to website operation.
This website may contain links to external services, including the WebHotelier / PrimalRes booking engine and other third-party services. This Privacy Policy does not replace the privacy policies, booking terms, payment terms or cookie practices of third-party services that process data through their own platforms or systems.
- Personal data we collect
We may collect and process the following categories of personal data.
3.1 Contact form data
When you submit the contact form, we collect the information you provide, which may include:
first name;
last name;
email address;
phone number;
message or special requests, if provided;
consent confirmation;
captcha, security or anti-spam verification data;
technical form submission data needed for security and spam prevention.
The message or special requests field is optional.
Please do not send sensitive personal data through the contact form, such as health information, identification documents, payment card details, financial information, passwords, or other highly confidential information.
3.2 Contact form processing, storage and replies
Contact form submissions are processed through Forminator.
When you submit the contact form:
the information you submit may be stored in the WordPress administration area;
an email notification is sent to Rhodes Youth Hostel;
an automatic reply may be sent to the email address you provided;
consent and anti-spam verification data may be recorded for security and compliance purposes.
Access to contact form submissions is limited to authorised website or business administrators who need access for operational purposes.
3.3 Contact form security and anti-spam
The contact form uses Cloudflare Turnstile or similar anti-spam and security technology to help prevent spam, abuse and automated submissions.
These technologies may process technical data such as IP address, browser information, device signals, interaction data and verification results for security and anti-spam purposes.
3.4 Booking-related data
When you use a “Book now” button or booking-related link on this website, you may be directed to the WebHotelier / PrimalRes booking engine.
If you make or manage a reservation through the WebHotelier / PrimalRes booking process, WebHotelier / PrimalRes may collect and process booking-related personal data on our behalf, such as:
name;
contact details;
stay dates;
reservation details;
booking preferences or requests;
booking communications;
transaction details;
payment-related information, where applicable.
Online payments, deposits or booking-related charges may be processed through Stripe as part of the WebHotelier / PrimalRes booking process.
We do not directly collect, process or store full payment card details on this WordPress website. However, as the accommodation provider and Stripe account holder, Rhodes Youth Hostel may have access to booking-related payment information in Stripe, WebHotelier / PrimalRes or related booking management systems, such as payment status, transaction reference, amount, date, refund information, dispute or chargeback information, and limited payment method details, where necessary for booking management, accounting, fraud prevention, dispute handling, legal compliance or the establishment, exercise or defence of legal claims.
Where WebHotelier / PrimalRes, Stripe or another booking or payment provider processes data through its own platform or system, its own privacy information, payment terms, booking terms and cookie practices may also apply.
3.5 Third-party booking platforms and connected booking channels
If you make a reservation through a third-party booking platform or connected booking channel, that platform may process booking-related data under its own privacy policy and terms.
Booking-related data from third-party booking platforms or connected booking channels may also be managed or synchronised through the WebHotelier / PrimalRes booking and channel management system, where such channels are used.
This processing is separate from ordinary browsing or contact form use on rhodesyouthhostel.com.
3.6 Internal reservation, guest-register and operational records
Reservation and guest information may also be recorded and used internally for:
booking management;
guest check-in and check-out;
accommodation provision;
invoicing and accounting;
tax obligations;
legal compliance;
daily operational records;
guest-register or “door book” obligations;
handling disputes, requests or legal claims.
These internal records may be kept in electronic or paper form, including through software tools used for reservation, guest-register, invoicing, accounting or operational purposes.
3.7 Technical, security and website data
When you visit the website, some technical data may be processed automatically, including:
IP address;
browser type and version;
device and operating system information;
date and time of access;
pages visited;
referring page or URL, where available;
server logs;
security and anti-spam signals;
cookie consent choices.
This data is used for website operation, security, troubleshooting, fraud prevention, spam prevention and maintaining the functionality of the website.
3.8 Cookies and consent data
The website uses a cookie consent system provided by Complianz.
The cookie banner allows visitors to accept, deny or manage cookie preferences. The website uses essential cookies and may use cookies or similar technologies for statistics, maps, booking tools and security features.
The cookie consent system may store information about your cookie choices so that the website can remember your preferences.
We use Google Analytics through Google Site Kit to collect statistics about how visitors use our website, subject to cookie consent where required. This may include information such as pages visited, approximate location, device and browser information, traffic source, session information and interactions with the website, including clicks to the booking engine.
We do not currently use Google Tag Manager, Meta Pixel, Hotjar, newsletter tracking or advertising/remarketing cookies.
For more information, please see our Cookie Policy.
3.9 Website analytics and Google Site Kit
This website uses Google Site Kit to connect Google services, including Google Analytics and Google Search Console.
Google Analytics helps us understand how visitors use the website, such as which pages are viewed, how visitors arrive at the website, which devices and browsers are used, and whether visitors interact with links such as the “Book now” button or booking engine links.
We use this information to understand website performance, improve the website, measure interest in our rooms and services, and identify technical or usability issues.
Google Search Console helps us understand how the website appears in Google Search, including search queries, impressions, clicks and indexing information. Search Console data does not directly identify individual visitors to us.
Where required, non-essential analytics cookies are only used after consent through the cookie banner.
3.10 Google Maps
The Contact page may include an embedded Google Maps service.
Google Maps is blocked by the cookie consent system until the visitor gives the relevant consent. If you choose to enable the map, Google may process technical data and may use cookies or similar technologies according to its own privacy terms.
3.11 WordPress technical and administrator cookies
WordPress may set technical cookies for website administrators or authorised users when they log in to the WordPress administration area.
These cookies may support:
login sessions;
screen preferences;
admin dashboard functionality;
basic website management functionality.
These cookies are not intended for ordinary website visitors who do not log in to the website.
3.12 Newsletter and marketing emails
We do not currently send newsletters or marketing emails through this website.
If newsletter or marketing email functionality is introduced in the future, it will only be used where legally permitted and, where required, after explicit opt-in consent.
Visitors will be able to withdraw consent or unsubscribe from marketing communications.
- Why we use personal data
We process personal data for the following purposes:
to respond to enquiries submitted through the contact form;
to answer questions about rooms, availability, arrival, location or hostel services;
to send automatic confirmation replies after contact form submission;
to support booking-related communication;
to direct visitors to the booking engine where they choose to make or manage a reservation;
to manage reservations, guest records and accommodation-related operations;
to process, verify, manage or support booking-related payments, deposits, refunds, disputes, chargebacks or payment confirmations where applicable through WebHotelier / PrimalRes, Stripe or the relevant booking or payment provider;
to operate, maintain and secure the website;
to prevent spam, fraud, abuse and automated submissions;
to remember cookie consent choices;
to display third-party services, such as Google Maps, where consent has been given;
to collect website statistics and understand how visitors use the website, where permitted and subject to consent where required;
to measure interactions with booking-related links, including clicks to the booking engine;
to understand search performance and website visibility through Google Search Console;
to maintain website logs and troubleshoot technical issues;
to comply with legal, accounting, tax or regulatory obligations;
to protect our legal rights and legitimate business interests.
- Legal bases for processing
We process personal data only when there is a lawful basis to do so.
Depending on the situation, the legal bases may include the following.
5.1 Contract or steps before entering into a contract
We may process your data when you contact us about room availability, reservations, arrival details or services connected with a possible or existing stay.
This may include responding to enquiries, assisting with booking-related questions, managing booking-related communication, or providing accommodation services.
5.2 Legitimate interests
We may process data where necessary for legitimate business interests, including:
responding to ordinary enquiries;
operating and maintaining the website;
protecting the website from spam, abuse and security threats;
managing normal guest communication;
sending administrative email replies related to enquiries;
keeping appropriate business and operational records;
troubleshooting technical issues;
understanding website performance and basic search visibility;
protecting legal rights.
We rely on legitimate interests only where our interests are not overridden by your rights and freedoms.
5.3 Legal obligation
We may process or retain certain data where required by applicable law, including accounting, tax, accommodation, guest-register, consumer protection, legal claim or regulatory obligations.
5.4 Consent
We rely on consent where required, including for certain non-essential cookies, analytics cookies, third-party embedded content, optional future marketing emails, or other optional processing that requires consent.
You may withdraw consent where processing is based on consent. Withdrawing consent does not affect processing that took place before withdrawal.
- Contact form submissions and retention
Contact form submissions are sent to us by email and may also be stored in the WordPress administration area through Forminator.
We normally retain contact form submissions for up to 12 months, unless a longer period is necessary for:
booking management;
dispute handling;
legal obligations;
accounting requirements;
security investigation;
the establishment, exercise or defence of legal claims.
If you want us to delete a contact form submission, you may contact us at info@rhodesyouthhostel.com. We will review the request in accordance with applicable law.
- Cookies, analytics and third-party services
This website uses Complianz to manage cookie consent.
The cookie banner gives visitors the option to:
accept cookies and relevant third-party services;
deny non-essential cookies;
manage preferences.
Google Maps is blocked until the visitor gives the relevant consent. This helps prevent Google Maps from loading automatically before consent.
The website uses Google Analytics through Google Site Kit for website statistics, subject to cookie consent where required.
The website does not currently use Google Tag Manager, Meta Pixel, Hotjar, newsletter tracking, advertising scripts or remarketing cookies.
If additional analytics, marketing or advertising tools are introduced in the future, the cookie banner, Cookie Policy and this Privacy Policy will be updated where required, and consent will be requested where legally required.
- Who we share data with
We may share or make data available to service providers only where necessary for the purposes described in this Privacy Policy.
These may include:
Kinsta, for managed WordPress hosting and website infrastructure;
Papaki, Plesk or relevant email service providers, for domain, DNS, email and SMTP services;
WordPress and website plugin providers, where relevant to website functionality;
Forminator, for contact form functionality, storage, email notifications and automatic replies;
Complianz, for cookie consent management;
Cloudflare, including Cloudflare Turnstile, for security, bot protection and anti-spam verification;
Google, including Google Analytics, Google Site Kit and Google Search Console, for website statistics, search performance information and technical website insights;
Google Maps, where the visitor enables the map;
WebHotelier / PrimalRes, for direct booking engine, booking management and channel management services;
Stripe, where online payments, deposits, refunds, disputes, chargebacks or booking-related charges are processed as part of the WebHotelier / PrimalRes booking process;
third-party booking platforms or connected booking channels, where a reservation is made through those platforms or where booking-related data is managed or synchronised through the booking/channel management system;
technology or software providers used for internal reservation, guest-register, invoicing, accounting or operational records, where applicable;
professional advisers, accountants or legal advisers where necessary;
public authorities, courts or regulators where required by law.
Some third-party providers may act as processors, while others may act as independent controllers for their own services.
Where you use a third-party service directly, such as a booking engine, payment provider, booking platform or Google Maps, the provider’s own privacy information may also apply.
- International transfers
Some service providers may process data outside Greece, the European Union or the European Economic Area.
Where required, such transfers should take place under appropriate safeguards recognised by applicable data protection law, such as adequacy decisions, standard contractual clauses or other lawful transfer mechanisms.
- How we protect personal data
We use reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.
These measures may include:
managed hosting;
access controls;
website security measures;
anti-spam tools;
software updates;
backups;
restricted administrative access;
cookie consent management;
form security verification;
two-factor authentication for administrative access where applicable.
No website, email system or internet transmission is completely secure. For that reason, you should not send highly sensitive information through the contact form.
- How long we keep data
We keep personal data only for as long as necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
Indicative retention periods:
Contact form submissions: up to 12 months.
Contact form email notifications and replies: as long as necessary to respond and manage the enquiry.
Booking-related communication: as long as necessary for booking management, accounting, legal or dispute purposes.
Reservation, guest-register and operational records: as long as necessary or required for accommodation, tax, accounting, legal or regulatory obligations.
Payment-related records: as long as necessary for booking management, accounting, tax, refund, dispute, chargeback, fraud prevention, legal or regulatory purposes.
Cookie consent records: according to the consent tool settings and applicable requirements.
Analytics data: according to the retention settings of Google Analytics and applicable requirements.
Server and security logs: for a limited period necessary for security, troubleshooting and fraud prevention.
Legal and accounting records: as required by applicable law.
- Your rights
Subject to applicable law, you may have the right to:
request access to your personal data;
request correction of inaccurate or incomplete data;
request deletion of your personal data;
request restriction of processing;
object to processing based on legitimate interests;
request data portability, where applicable;
withdraw consent where processing is based on consent;
lodge a complaint with a competent data protection authority.
To exercise your rights, contact us at:
info@rhodesyouthhostel.com
We may need to verify your identity before responding to a request.
- Complaint to a supervisory authority
If you believe that your personal data has been processed unlawfully, you may lodge a complaint with the competent data protection authority.
For Greece, the competent authority is the Hellenic Data Protection Authority.
Hellenic Data Protection Authority
Kifissias 1-3
115 23 Athens, Greece
Website: www.dpa.gr
Email: contact@dpa.gr
Telephone: +30 210 6475600
- Children
This website is not intended for children to submit personal data without appropriate parental or guardian involvement.
If you believe that a child has submitted personal data through the website, please contact us.
- Links to third-party websites and services
This website may contain links to third-party websites or services, including booking platforms, booking engines, payment services, map services or other external providers.
We are not responsible for the privacy practices, content or security of third-party websites.
You should review the privacy information of any third-party service you use.
- Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the website, services, legal requirements or business operations.
The updated version will be posted on this page with a revised “Last updated” date.