Skip to content

Privacy Policy & Cookie Policy

Last updated: 19 July 2026

This Privacy Policy explains how Sappho Travel collects, uses, stores and shares personal data when you visit https://sapphotravel.com, contact us, submit an enquiry, request or book accommodation, transport, flights, ferries or other travel services, subscribe to communications, or otherwise use our services.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Greek data-protection and electronic-communications legislation, and other applicable laws.

1. Who is responsible for your personal data?

The controller responsible for the processing described in this policy is:

SAPPHO TRAVEL
Trading as: Sappho Travel
Skala Eressos, 81105
Lesvos, Greece
Greek tax number (AFM): EL041768470
Travel agency licence/registration: 77997642000
Telephone: +30 22530 52140
Email: contact@sapphotravel.com

For enquiries specifically relating to the 5th EL*C International Lesbian Conference in 2027, you may contact: elc2027@sapphotravel.com.

2. What personal data do we collect?

The information we collect depends on how you interact with us and which services you request.

2.1 Contact and identification information

  • first name and surname;
  • email address;
  • telephone or WhatsApp number;
  • postal address where required;
  • country of residence;
  • preferred language and contact method;
  • organisation or group name.

2.2 Booking and travel information

  • arrival and departure dates;
  • number and names of travellers;
  • room and accommodation preferences;
  • budget and requested facilities;
  • flight or ferry routes, times and booking details;
  • airline, ferry company, flight number or ferry details;
  • transfer requirements;
  • luggage, vehicle, cabin, seat or child-seat requirements;
  • information needed to issue or administer tickets;
  • correspondence concerning your enquiry or booking.

2.3 Identity and passenger information

Where required to issue tickets, comply with legal requirements or provide a requested service, we may ask for information such as:

  • date of birth;
  • nationality;
  • passport or identity-card information;
  • other passenger details required by the relevant carrier or supplier.

Please do not submit passport numbers, identity-document numbers or payment-card details through a general contact or booking-request form unless we specifically ask you to use that method.

2.4 Accessibility and assistance requirements

You may tell us about practical accessibility, mobility or assistance requirements where this is necessary to investigate suitable accommodation or transport.

We do not need a diagnosis or detailed medical history. Please provide only the practical information needed, such as a requirement for step-free access, a ground-floor room, accessible bathroom facilities, mobility-equipment space, a short walking distance or an accessible vehicle.

Information of this nature may, in some circumstances, reveal health-related information. We process it only where necessary to respond to your request and where an appropriate lawful condition applies.

2.5 Payment and transaction information

Depending on the payment method, we may process:

  • invoice details;
  • payment status;
  • bank-transfer references;
  • payment date and amount;
  • refund information;
  • limited information supplied by a payment provider.

Where payment is processed by a bank or third-party payment provider, that provider may process payment-card or banking information under its own privacy policy. Sappho Travel does not intentionally store full payment-card details on its website.

2.6 Technical and website information

When you use the website, we or our service providers may process:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • referring website;
  • pages visited and interaction information;
  • date and time of access;
  • security, server and error logs;
  • cookie and consent preferences.

2.7 Marketing information

Where you have separately opted in, we may process your email address, preferences and records of consent for newsletters, news or promotional communications.

3. How do we collect personal data?

We may collect personal data:

  • directly from you through the website, email, telephone, WhatsApp or in person;
  • when you submit a contact, enquiry or booking-request form;
  • when you accept a proposal or make a booking;
  • when you pay for a service;
  • from another person making a booking on your behalf;
  • from an organisation or conference organiser arranging services for you;
  • from accommodation providers, carriers or transport suppliers;
  • from payment providers and banks;
  • automatically through website logs, cookies and similar technologies.

If you provide personal data about another traveller, you are responsible for ensuring that you are authorised to provide it and that the traveller has been informed about this policy.

4. Why do we use personal data?

We may use personal data to:

  • respond to questions and requests;
  • identify suitable accommodation, transport or travel options;
  • prepare proposals and quotations;
  • make, confirm and administer bookings;
  • issue flight or ferry tickets;
  • arrange transfers and other travel services;
  • communicate changes, reminders and important travel information;
  • process payments and refunds;
  • issue invoices, receipts and accounting records;
  • manage cancellations, amendments, complaints and claims;
  • verify accessibility or assistance requirements with relevant suppliers;
  • protect the website, customers and business against fraud, abuse and security threats;
  • maintain and improve our website and services;
  • comply with legal, tax, accounting, regulatory and law-enforcement obligations;
  • establish, exercise or defend legal claims;
  • send marketing communications where you have separately agreed to receive them.

5. Legal bases for processing

Depending on the circumstances, we rely on one or more of the following legal bases:

5.1 Steps taken at your request before entering into a contract

We use this basis when you ask us to investigate accommodation, transport, flights, ferries or another travel service, and we need your information to prepare a proposal or quotation.

5.2 Performance of a contract

We use this basis when processing is necessary to make, administer or complete a booking or another service agreement with you.

5.3 Legal obligations

We may process and retain information where required by tax, accounting, consumer, travel, regulatory, judicial or other applicable laws.

5.4 Legitimate interests

We may rely on legitimate interests for purposes such as:

  • responding to general business correspondence;
  • maintaining records of enquiries and communications;
  • protecting our systems and preventing fraud;
  • managing disputes and legal claims;
  • improving our services and business processes;
  • maintaining appropriate internal administrative records.

Where we rely on legitimate interests, we consider whether those interests are overridden by your rights and freedoms.

5.5 Consent

We rely on consent where appropriate, including for:

  • optional marketing communications;
  • optional analytics, advertising or similar cookies;
  • certain processing of voluntarily supplied sensitive information where consent is the appropriate condition.

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect processing that was lawful before consent was withdrawn.

5.6 Legal claims and special-category information

Where special-category information is involved, we will process it only where an additional lawful condition applies, for example where you have provided explicit consent, where it is necessary to protect vital interests in an emergency, or where processing is necessary for the establishment, exercise or defence of legal claims.

6. Is providing personal data compulsory?

You are not generally required to provide personal data merely to browse the website.

However, certain information is necessary for us to respond to a request, prepare a quotation, make a booking, issue a ticket, arrange a transfer or meet legal requirements.

If you do not provide necessary information, we may be unable to offer, confirm or provide the requested service.

Information marked as optional is not required unless it later becomes necessary for the specific service you choose.

7. Who may receive your personal data?

We share personal data only where reasonably necessary for the purposes described in this policy or where required by law.

Recipients may include:

  • hotels, apartments, guesthouses and other accommodation providers;
  • taxi, minibus, coach, car-hire and other transport providers;
  • airlines, ferry companies, reservation systems and ticketing providers;
  • conference or event organisers where this is necessary for an agreed arrangement;
  • banks and payment-service providers;
  • accountants, tax advisers, auditors, lawyers and insurers;
  • website hosting, email, IT-security, backup and technical-service providers;
  • newsletter or communications providers where you have subscribed;
  • public authorities, regulators, courts or law-enforcement bodies where required.

Suppliers receiving your data may act as independent controllers for the services they provide. Their own privacy policies and legal obligations may also apply.

We do not sell or rent personal data to third parties.

8. International transfers

Some airlines, booking systems, technology providers or other recipients may be located outside the European Economic Area or may process information in other countries.

Where personal data is transferred outside the European Economic Area, we will use an appropriate legal mechanism where required, such as:

  • a European Commission adequacy decision;
  • approved standard contractual clauses;
  • another lawful safeguard or derogation permitted by the GDPR.

You may contact us for further information about the safeguards relevant to a particular transfer.

9. How long do we keep personal data?

We keep personal data only for as long as reasonably necessary for the purpose for which it was collected and for any applicable legal, accounting, tax, regulatory or claims period.

Our usual retention approach is:

  • General enquiries that do not result in a booking:
    normally retained for up to 24 months after the last meaningful contact, unless there is a reason to retain them for longer.
  • Unsuccessful accommodation or travel requests:
    normally retained for up to 24 months after the request is closed.
  • Confirmed bookings and contractual correspondence:
    retained for the duration of the booking and afterwards for the period needed for accounting, tax, contractual and legal purposes.
  • Invoices, receipts and accounting records:
    retained for the period required by Greek tax and accounting law.
  • Complaint, dispute or claim records:
    retained until the matter is resolved and any relevant limitation period has expired.
  • Marketing records:
    retained until you unsubscribe or withdraw consent, together with limited records needed to demonstrate or respect your communication preference.
  • Website security logs:
    normally retained for a limited period appropriate to security and troubleshooting.
  • Cookie consent records:
    retained for the duration configured by the cookie-management tool and renewed where
    appropriate.

We may retain limited information for longer where necessary to comply with law, protect legal rights, prevent fraud or record that a person has opted out of marketing.

10. How do we protect personal data?

We use reasonable technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures may include:

  • encrypted website connections using HTTPS;
  • access controls and password protection;
  • restricted staff access based on operational need;
  • software, plugin and security updates;
  • email and server-security controls;
  • backups and recovery procedures;
  • secure payment arrangements;
  • staff procedures for handling booking information.

No internet transmission or storage system can be guaranteed to be completely secure. Please do not send unnecessary sensitive information by ordinary email or through general contact forms.

11. Your data-protection rights

Subject to the conditions and limitations of applicable law, you may have the right to:

  • receive information about how your personal data is processed;
  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request erasure of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • object at any time to direct marketing;
  • request data portability where applicable;
  • withdraw consent where processing is based on consent;
  • not be subject to certain decisions based solely on automated processing.

These rights are not absolute. For example, we may need to retain information where required by law or where it is necessary to establish, exercise or defend legal claims.

To exercise a right, contact contact@sapphotravel.com.

Please describe your request clearly. We may need to ask for reasonable information to verify your identity before acting on it.

We normally respond within one month, subject to extensions permitted by law for complex or multiple requests.

12. Complaints

Please contact us first if you have concerns about how we process your personal data, so that we have an opportunity to investigate and respond.

You also have the right to lodge a complaint with the:

Hellenic Data Protection Authority
Kifisias 1–3
115 23 Athens
Greece
Telephone: +30 210 6475600
Website:

www.dpa.gr

If you live in another European Economic Area country, you may also be entitled to contact the supervisory authority in that country.

13. Marketing communications

We will send promotional emails or similar direct marketing only where an appropriate legal basis applies.

Where consent is required, marketing consent will be optional and separate from any consent or acknowledgement needed to submit an enquiry or make a booking.

You may unsubscribe at any time by:

Unsubscribing from marketing does not prevent us from sending essential messages concerning an enquiry, booking, payment or travel service.

14. Children’s personal data

Our services are not directed specifically at children using the website independently.

We may process information about children where an adult includes them in a family or group travel booking. The adult making the booking is responsible for providing accurate information and having authority to provide the child’s details.

We collect only the information reasonably necessary to provide the requested travel service or comply with legal and carrier requirements.

15. Automated decision-making

Sappho Travel does not ordinarily make decisions producing legal or similarly significant effects solely through automated processing.

Accommodation and travel requests submitted through the website are reviewed manually.

16. Contact forms and stored submissions

Information submitted through a website form may be:

  • sent to the relevant Sappho Travel email account;
  • stored temporarily or permanently within the WordPress website database;
  • processed by spam-prevention, security, hosting or email-delivery services;
  • transferred to our booking, accounting or customer-service records where necessary.

Please do not use contact forms to send information that is not needed for your request.

17. Third-party websites and embedded content

Our website may link to third-party websites, including airlines, ferry companies, accommodation providers, event organisers, payment providers, social-media services and travel-information websites.

Third-party websites operate under their own privacy and cookie policies. We are not responsible for how those third parties process personal data when you visit their websites or use their services.

Embedded content, such as maps, videos, social-media posts or booking widgets, may allow the third-party provider to collect technical or usage information. Optional third-party content should be activated only in accordance with your cookie preferences where consent is required.

18. Cookies and similar technologies

18.1 What are cookies?

Cookies are small text files placed on or read from your device when you visit a website. Similar technologies may include local storage, pixels, tags, scripts and software-development kits.

18.2 Why do we use cookies?

We may use cookies and similar technologies to:

  • operate and secure the website;
  • remember cookie and website preferences;
  • support forms and user sessions;
  • prevent spam and abuse;
  • measure website use and performance;
  • display embedded content;
  • support marketing or advertising where applicable and consented to.

18.3 Cookie categories

Strictly necessary cookies

These cookies are required for the website to function properly or to provide a service requested by the user. They may include security, session, form, load-balancing and cookie-preference cookies.

Strictly necessary cookies do not require consent, but they should be limited to what is genuinely necessary.

Preferences or functionality cookies

These cookies remember optional choices or enhance website functionality. Depending on their purpose, consent may be required before they are activated.

Analytics cookies

These cookies help us understand how visitors use the website, such as which pages are visited and whether errors occur.

Analytics cookies will be activated only where permitted by applicable law and, where required, after you have consented.

Marketing and advertising cookies

These cookies may be used to measure campaigns, create profiles or show advertising based on interests.

Marketing and advertising cookies will not be activated unless you have given the required consent.

Third-party media and embedded-content cookies

Maps, videos, social-media features or other embedded third-party content may set cookies or collect usage information.

Where consent is required, such content should remain blocked until the relevant cookie category has been accepted.

18.5 Managing cookie preferences

When you first visit the website, you should be offered a clear choice to:

  • accept optional cookies;
  • reject optional cookies;
  • choose individual cookie categories.

Optional cookies should remain disabled unless and until you actively consent to them.

You can change or withdraw your cookie choices at any time by pressing the cookie settings icon in the left bottom corner of your screen.

You can also delete or block cookies through your browser settings. Blocking necessary cookies may prevent parts of the website from working correctly.

Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.

19. Changes to this policy

We may update this Privacy Policy & Cookie Policy to reflect changes in our services, website, suppliers, legal obligations or processing activities.

The most recent version will be published on this page with an updated revision date.

Where a change is significant, we may provide an additional notice where appropriate.

20. Contact us

For questions about this policy, our use of personal data, or a request to exercise your rights, contact:

Sappho Travel
Skala Eressos, 81105
Lesvos, Greece
Telephone: +30 22530 52140
Email: contact@sapphotravel.com
Sappho Travel
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.