Privacy Policy
Last updated: 03/06/2026
This Privacy Policy explains how Samara Panagiota (“we”, “us”) collects, uses, and protects your personal data when you visit or make a purchase from https://eshop.enjoy-crete.com.
1) Data Controller
Samara Panagiota
Address: Stavrakia, 70013, Crete
Email: [email protected]
Phone: +30 6946140777
VAT (if applicable): 142917284
2) What data we collect
- Account & checkout data: name, billing/shipping address, email, phone.
- Order details: products purchased, quantities, order totals, invoices/receipts.
- Payment data: payment status and transaction references from our payment provider (we do not store full card details).
- Technical data: IP address, browser/device information, cookies/analytics (where enabled).
- Support communications: messages you send us (email/contact form) and our replies.
3) Why we use your data (legal basis)
- To process orders (contract performance).
- To issue invoices/receipts and comply with tax/accounting obligations (legal obligation).
- To provide customer support (legitimate interest / contract performance).
- To improve our website and prevent fraud/abuse (legitimate interest).
- Marketing newsletters only if you explicitly opt in (consent).
4) Payments (Viva Wallet)
Card/online payments are processed securely by our payment provider Viva Wallet. We do not store your full card number, CVV, or other sensitive card credentials on our servers. Viva Wallet may process personal data to complete the payment and prevent fraud, acting as an independent controller for certain processing.
5) Who we share data with
We share personal data only when necessary, for example:
- Payment providers: Viva Wallet (to process payments).
- Shipping/courier providers: only the details required to deliver your order.
- IT/hosting providers: for secure operation of the website (under appropriate safeguards).
- Accountants/legal obligations: when required by law.
We never sell your personal data.
6) Cookies
We use cookies necessary for the website to function (e.g., cart/session). If we use analytics or marketing cookies, we will ask for your consent where required by law. You can control cookies from your browser settings.
7) Data retention
We keep your data only as long as necessary for the purposes above and to meet legal/tax requirements. Order and invoice records may be retained for the period required by applicable law.
8) Security
We implement technical and organizational measures to protect your data (access controls, encryption where applicable, monitoring, and backups). No method of transmission or storage is 100% secure, but we strive to use commercially acceptable means.
9) Your rights
Depending on your location (e.g., EU/EEA), you may have rights to access, correct, delete, restrict, object, and port your data, and to withdraw consent at any time (where processing is based on consent). To exercise your rights, contact us at [email protected].
10) Complaints
If you believe your data protection rights have been violated, you may lodge a complaint with your local supervisory authority.
11) Changes to this policy
We may update this policy from time to time. The latest version will always be available on this page.