Skip to content
Antzela ApartmentsSidari, Corfu
ΕΛ
  • Home
  • Apartments
  • Location
  • Contact
ΕλληνικάCheck availability →

Guest information

Privacy Notice

Last updated: 6 August 2026

1. Who we are

Antzela Apartments operates Antzela Apartments.

For the purposes of the General Data Protection Regulation (GDPR) and applicable Greek data-protection legislation, Antzela Apartments is the controller of the personal data described in this Privacy Notice.

Legal business name: Antzela Apartments
Property name: Antzela Apartments
Business address: Sidari, Corfu
Email: [email protected]
Telephone: 0030 698 122 4353

2. Information we process

We process only the information reasonably necessary to manage reservations and provide accommodation services.

Guest identity and contact information is stored as part of reservation records. StayFold does not maintain a separate standalone guest-profile database.

This may include:

  • guest name;
  • email address;
  • telephone number;
  • booking reference;
  • booking source, such as Booking.com or a direct reservation;
  • arrival and departure dates;
  • room or accommodation assigned;
  • number of guests;
  • reservation and cancellation status;
  • agreed booking price;
  • payment status and whether payment was handled through a booking platform or directly;
  • limited booking-related requests and operational notes recorded by an authorised user;
  • housekeeping tasks linked to a reservation and any necessary task notes;
  • limited metadata imported from booking emails where used to identify or link a reservation;
  • information required for accounting, tax or other legal obligations.

We do not store payment-card numbers, card security codes, online-banking credentials, bank-account details or other payment authentication information in StayFold.

Where payment is processed by a booking platform, that platform handles payment information under its own terms and privacy notice. We may receive limited information such as the booking price and whether the booking has been paid.

For direct bookings, payments are generally made in cash. StayFold may record the agreed price and payment status but does not store financial-account or card information.

StayFold can generate a draft guest message from reservation information for an authorised user to copy manually into Booking.com, email or WhatsApp. StayFold does not automatically send these drafts and does not retain the generated draft text.

3. How we receive personal data

We may receive personal data:

  • directly from the guest;
  • from Booking.com or another booking platform chosen by the guest;
  • through booking emails or other email communication;
  • through telephone communication;
  • through WhatsApp;
  • from a person making a reservation on behalf of another guest;
  • through communication before, during or after the stay.

Guests commonly choose to contact us through WhatsApp during their stay to ask questions, report an issue or request accommodation-related assistance.

WhatsApp is used as a separate communication service and is not directly integrated with StayFold. We use those communications to respond to the guest and manage the reservation or stay.

We do not normally copy complete WhatsApp or email conversations into StayFold. Where necessary, an authorised user may record a limited operational note, such as a request for additional towels, a maintenance issue or an agreed change to the reservation.

Where booking-email import is used, StayFold may retain limited metadata needed to identify, link or manage the relevant reservation.

Where another person makes a reservation on behalf of a guest, that person should only provide information that they are authorised to provide.

4. Why we use personal data

We process guest information for the following purposes:

  • to create, confirm and manage reservations;
  • to communicate with guests about their arrival, departure and stay;
  • to generate guest-message drafts for manual use by an authorised user;
  • to assign rooms and organise accommodation services;
  • to record the agreed price and payment status;
  • to respond to guest questions and requests;
  • to manage cancellations and reservation changes;
  • to address complaints, incidents or disputes;
  • to maintain necessary business and accounting records;
  • to comply with tax, legal and regulatory obligations;
  • to protect the security and proper operation of our systems;
  • to prevent unauthorised access, misuse or fraud.

We do not sell guest information.

We do not use information stored in StayFold for behavioural advertising, advertising analytics or unrelated marketing.

5. Legal bases for processing

Depending on the circumstances, we process personal data using one or more of the following legal bases.

Performance of a contract

We process information where it is necessary to:

  • take steps requested by a guest before a reservation;
  • create or confirm a reservation;
  • manage the guest’s stay;
  • provide the booked accommodation;
  • communicate about the reservation or accommodation services.

Compliance with a legal obligation

We may process or retain certain information where required by applicable:

  • tax legislation;
  • accounting requirements;
  • accommodation regulations;
  • public-authority requests;
  • other legal obligations.

Legitimate interests

Where appropriate, we may process limited information for legitimate business purposes, including:

  • protecting our systems and user accounts;
  • preventing misuse or unauthorised access;
  • maintaining appropriate operational records;
  • handling complaints or legal claims;
  • investigating security incidents;
  • improving the reliability of our reservation procedures.

We rely on legitimate interests only where those interests are not overridden by the rights and freedoms of the guest.

Consent

We do not normally rely on consent to process information required to manage a reservation or provide accommodation.

Where consent is required for a separate optional purpose, it will be requested separately and may be withdrawn.

6. Who can access personal data

Access to guest information is limited to authorised people who require it to manage the accommodation and reservations.

StayFold uses individual accounts with the following operational roles:

  • owners, who can manage the property and administrative functions;
  • managers, who can manage reservations and authorised administrative functions;
  • housekeeping users, whose access is limited to the operational information and tasks needed for their work.

Accountants or professional advisers may receive limited information where necessary, and technical service providers process information only as required to provide their services. Public authorities may receive information where disclosure is required by law.

The guest-data search, export and anonymisation functions are restricted to authorised owners and managers. Access is also limited to the property or business that the signed-in user is authorised to manage.

7. Service providers

We use selected service providers to operate the accommodation and its supporting systems.

These may include:

  • booking platforms such as Booking.com, where a guest chooses to make a reservation through that platform;
  • Railway, which hosts the StayFold application and PostgreSQL database in an EU-based region and, when enabled, the associated production backups;
  • email providers used for booking and guest communication;
  • WhatsApp, where a guest chooses to communicate with us using that service;
  • accountants or professional advisers where access is necessary for accounting, tax, legal or regulatory purposes;
  • Cloudflare Pages, which hosts the public website and Privacy Notice.

Railway provides the technical infrastructure used to host StayFold. The production database is configured for private service access rather than unnecessary direct public access.

Where scheduled Railway backups are enabled, they are used to support recovery from accidental loss, technical failure or a security incident. Backup settings and restoration tests are maintained in our internal records.

StayFold does not automatically send or retain generated guest-message drafts. Communication sent through Booking.com, email or WhatsApp is processed through the selected communication service.

We do not use a separate analytics platform or external error-monitoring service for guest activity in StayFold.

External providers process information according to their own responsibilities, contractual terms and applicable privacy obligations.

8. International transfers

Some external services, including international booking or communication platforms, may process personal data in countries outside the European Economic Area.

Where personal data is transferred outside the European Economic Area, the transfer should be protected using an appropriate legal mechanism, such as:

  • an adequacy decision;
  • approved contractual safeguards;
  • another transfer mechanism permitted by applicable data-protection law.

9. How long we keep personal data

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected.

The retention period may depend on:

  • whether the reservation is upcoming, active, completed or cancelled;
  • whether the information is still required for guest support;
  • whether there is an unresolved complaint, dispute or legal claim;
  • applicable tax, accounting or legal retention requirements;
  • whether the information is stored in a backup subject to a limited rotation period.

Operational information that is no longer necessary will be deleted or anonymised.

Information that must be retained because of a legal obligation will be kept only for the required period and will not be used for unrelated purposes.

Where scheduled backups are enabled, they may temporarily contain information that has subsequently been deleted or anonymised in the active system. Such information is removed as the backup rotation period expires and is not normally restored unless required for recovery or security investigation.

10. Security

We use technical and organisational measures intended to protect personal data against:

  • unauthorised access;
  • accidental loss;
  • unlawful disclosure;
  • alteration;
  • destruction;
  • misuse.

These measures include, where appropriate:

  • encrypted HTTPS connections;
  • individual session-based user accounts;
  • one-way password hashing using BCrypt;
  • CSRF protection and secure production cookie settings;
  • server-side role and property authorisation;
  • separation of data belonging to different properties or businesses;
  • a privately connected production PostgreSQL database;
  • restricted owner and manager access to guest export and anonymisation tools;
  • automated backend, integration and frontend security tests;
  • controls intended to prevent unnecessary personal data from appearing in logs and exports;
  • audit records for successful and failed sensitive administrative actions without duplicating guest personal data;
  • backup and recovery procedures after they are enabled and verified.

No internet-based system can guarantee absolute security. We review and improve our safeguards according to the type of information processed and the risks involved.

11. Guest rights

Subject to the conditions and limitations of applicable law, guests may have the right to:

  • ask whether we process their personal data;
  • request access to their personal data;
  • request correction of inaccurate or incomplete information;
  • request deletion of information that is no longer necessary;
  • request restriction of processing in certain circumstances;
  • object to certain processing based on legitimate interests;
  • receive certain personal data in a portable format where applicable;
  • withdraw consent where processing is based on consent;
  • submit a complaint to the relevant data-protection authority.

These rights are not absolute.

For example, we may need to retain certain information to comply with tax, accounting or other legal obligations, or to establish, exercise or defend a legal claim.

To exercise a data-protection right, contact:

Email: [email protected]

We may request reasonable information to confirm the identity of the person making the request.

We will respond without undue delay and within the time limits required by applicable law.

Authorised owners and managers can use StayFold’s property-scoped search, structured export and anonymisation functions to support valid requests. Some booking, accounting or legal information may need to remain where retention is required.

12. Automated decision-making

We do not use StayFold guest information to make decisions based solely on automated processing that produce legal or similarly significant effects.

13. Data breaches

If a security incident affects personal data, we will assess:

  • what information was involved;
  • how many people may have been affected;
  • whether the information was accessed or disclosed;
  • the possible consequences for affected guests;
  • the measures required to contain and resolve the incident.

Where required by law, we will notify the Hellenic Data Protection Authority and affected guests.

14. Complaints

Guests are encouraged to contact us first so that we can review and address any concern.

Guests also have the right to submit a complaint to:

Hellenic Data Protection Authority
Website: www.dpa.gr

15. Changes to this Privacy Notice

We may update this Privacy Notice when:

  • our services change;
  • our service providers change;
  • our legal obligations change;
  • the way we process personal data changes;
  • new StayFold features are introduced.

The current version will be published on our website and identified by the “Last updated” date shown at the beginning of this document.

Antzela ApartmentsSidari, Corfu, Greece
  • WhatsApp
  • Telephone

© 2026 Antzela Apartments

Privacy noticeDesigned & built by SeventhCurrent ↗