The privacy and protection of our customers’ personal data is of paramount importance to us. We want you to feel happy and secure when visiting our website and to consider the implementation of data protection as a customer-oriented quality feature. Please read this privacy policy carefully because it informs you of your rights and the way and scope of the processing of personal data by our website, which has fully complied with the General Data Protection Regulation (GDPR 2016/679 – General Data Protection Regulation). For the text of the regulation you can click on the link https://eur-lex.europa.eu/legal-content/EL/TXT/?uri=CELEX:32016R0679. The Regulation requires that any information to the data subject about the processing of data must be provided in a concise, transparent, understandable and easily accessible format. For this reason:

“personal data ” is defined as any information relating to an identified or identifiable natural person (“data subject”). It does not include anonymous information. When you yourself fill in the contact form of our website, register on it, register to receive our newsletter, connect to our website from a social media, request information or technical support, use the on-line chat/message boards of our website we collect the given data from you, such as identity data, contact data with you or your financial data. We may also receive your personal data from third parties, such as technical and tracking data from appropriate providers, such as google analytics, google and so on, or from third parties who are permitted by law or have your permission to provide this information to us, such as social media. Of course, this will only be used if the law allows us to do so. We do NOT collect special categories of your personal data, i.e. data “revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, as well as genetic data, biometric data for the purpose of unambiguous identification of a person, data concerning health or data concerning the sex life of a natural person or sexual orientation” (Art. 1 GDPR/GDPR) or data relating to criminal convictions and offences (Article 10 GDPR/GDPR). If you do not allow us to collect your personal data for the purposes mentioned here, we may not be able to provide you with our services in an optimal way.

When their use is necessary for the performance of a contract to which you are a party, i.e. when you make a purchase from our online or physical store and when their use is necessary to comply with our legal obligation, i.e. we file them for accounting and tax purposes.

If you have given us your explicit consent and depending on the personal data you have provided us with, we will send you marketing messages via e-mail, SMS, Viber, etc., in order to inform you about our products and services. At any time you can stop receiving updates from us, either by using the corresponding unsubscribe link at the end of the newsletter, or by contacting our customer service at our call centre (+30) 27520 91242, or by sending an e-mail to info@anassia.com.

Cookies are in simple terms small pieces of code that record your movements while you are browsing our website and are divided into

By using our website, you will need to agree what kind of cookies you allow us to place. When you enter the main page of our website, you will be made aware of a note on the use of cookies and the possibilities of disabling them or not.

Exceptionally, the data is processed by processors on our behalf. These are carefully selected in each case, controlled by us and contractually bound in accordance with Article 28 GDPR. In addition, we may be required to transmit extracts of your request to our contractors (e.g. suppliers, for requests relating to products) for the purpose of processing your request. These may be auditors and professional advisors (lawyers, accountants, bank) and/or companies related to the transfer of products, professional service providers such as marketing, advertising and support services, optimization and web hosting companies, payment verification services, the Cybercrime Unit, Consumer Protection Services and e-Fraud Prevention Services, for cases of malicious use, social media if you choose to link your account to If the transfer of your personal data is required in an individual case, we will inform you of this in order to obtain your consent. We do NOT transfer your personal data to recipients outside the European Union.

We have effectively implemented, both at the time of determining the means of processing and at the time of processing, appropriate technical and organisational measures designed to implement data protection principles and incorporate the necessary safeguards in the processing in such a way that the requirements of the GDPR are met and your rights are protected. We have also implemented appropriate technical and organisational measures to ensure that, by default, only personal data that are necessary for the purpose of the processing are processed. We have active procedures in place to control possible personal data breaches and in such a case we will inform you immediately as well as the competent supervisory authority.

The computers and programs used by our company are created in such a way that the use of personal and identifying information is kept to a minimum. These data are processed only to the extent necessary to achieve the purposes stated in this Policy and will be stored for as long as absolutely necessary to achieve the specific purposes pursued. In any case, the criterion used to determine the storage period is based on compliance with the time limits allowed by law and the principles of data minimization, storage limitation or rational management of our records.

If you are a resident of the European Union, you have the following rights in simple terms:

  1. The right to be informed about how we use your personal data.
  2. The right of access, i.e. you can request a copy of the personal data we hold about you.
  3. The right of rectification, i.e. to correct your personal data that may be incomplete or inaccurate.
  4. The right to erasure (the right to “be forgotten”), i.e. in certain cases to ask us to delete your personal data that we hold (unless there is a legal reason that prohibits us from doing so)
  5. The right to restrict the processing of your personal data.
  6. The right to portability of your data, i.e. to request a copy of your personal data in a common file format and to transfer that data to another company.
  7. The right to object to the processing of your personal data, e.g. for direct marketing purposes.
  8. The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or significantly affects you in a similar way.
  9. The right to complain to the competent data protection supervisory authority in the Member State where you have your habitual residence or place of work.

The above rights are subject to specific rules on when you can exercise them. You do not have to pay to access your personal data (or to exercise any of your rights) unless your request is unfounded, repetitive or excessive, in which case we may refuse to comply. Please note that we may ask for some additional information to confirm your identity when you request access to your rights or to exercise any of your other rights and this is as a security measure that your personal data will not be disclosed to others. We will respond to each of your requests within a period of one (1) month, if we need more time due to complexity or number of requests, we will let you know.

Please check back periodically for any changes to it.

The Data Controller is Yiouli Koukopoulou (+30 6945 119 428, info@anassia.com), who can be contacted for any questions you may have regarding the privacy policy or for the exercise of any of your rights under the GDPR.

Booking form

Full Name *
e-mail *
Phone *
Check In/Check Out *
Number of Visitors
Total Days: 
0.00