Privacy Policy
This policy explains what personal data we collect through mybnbmanager.gr, why we need it, how long we keep it and what rights you have over it. It covers property owners, guests staying at the properties we manage, our staff, and visitors to this website.
This is a courtesy translation. In case of any discrepancy, the Greek text prevails.
Data controller
- Legal name
- Κωνσταντίνος Καλλιακούδης
- Registered address
- Σπάρτη
- VAT number
- 143850347 · Tax office Σπάρτης
- info@mybnbmanager.gr
- Phone
- +30 698 303 3004
- Website
- www.mybnbmanager.gr
1.What we process
Depending on your relationship with us:
- Owners: name, email, phone, address, emergency phone, bank account (IBAN), a profile photo if you upload one, your properties’ details (address, registry number) and the financial history of our work together.
- Guests: name, email, phone, nationality, identity or passport number, date of birth, address, stay dates and value.
- Staff and contractors: name, email, phone, the tasks assigned to them and photos they upload while carrying them out.
- Technical data: IP address and basic browsing information logged by our hosting providers for security, plus the cookies described in our cookie policy.
We do not collect special categories of data (health, beliefs and so on) and we make no automated decisions with legal effects for you.
2.Why, and on what legal basis
| Managing your property and your account | Performance of a contract (Art. 6(1)(b) GDPR) |
| Issuing invoices and keeping tax records | Legal obligation (Art. 6(1)(c) GDPR) |
| Guest details for the short-term rental registry and the climate resilience levy | Legal obligation (Art. 6(1)(c) GDPR) |
| Contacting you about bookings, tasks and charges | Contract / legitimate interest |
| Platform security and blocking automated abuse | Legitimate interest (Art. 6(1)(f) GDPR) |
| Push notifications on your device | Consent — given on the device and withdrawn there |
3.Who we share it with
We do not sell personal data and we do not make it available to third parties for their own commercial purposes. We use the following providers, acting as processors on our behalf:
- Supabase — database, authentication and file storage, hosted on servers inside the European Union (Ireland).
- Vercel — application hosting, executing on servers inside the EU (Frankfurt).
- Resend — sending notification emails.
- Stripe — card payment processing. Card details are entered directly with Stripe and never pass through our servers.
- Cloudflare — protecting our public forms from automated abuse.
- Your browser’s notification service (Apple, Google, Mozilla), if you have enabled push notifications.
Some of these providers are established outside the EU. Where that is the case, the transfer relies on the European Commission’s Standard Contractual Clauses or on an adequacy decision. We also disclose data to public authorities where the law requires it, and to our accountant or legal adviser where necessary.
4.How long we keep it
- Account and property data: for as long as we work together and a reasonable period afterwards, so that we can answer claims.
- Invoices and tax records: for as long as tax law requires — at least five (5) years.
- Guest details: for as long as short-term rental law and the levy’s documentation require.
- Messages inside the platform: for the life of the account, unless you ask us to delete them.
5.Your rights
You have the right to access, rectify, erase, restrict and port your data, and to object to processing. Where processing rests on consent, you may withdraw it at any time without affecting the lawfulness of what came before.
Write to us at info@mybnbmanager.gr for any of the above; we answer within one month at the latest. If you believe the processing breaches the law, you may complain to the Hellenic Data Protection Authority (1-3 Kifissias Ave., 115 23 Athens, www.dpa.gr).
6.Security
Access requires an account and is enforced at the database level, so each owner sees only their own properties. All traffic is encrypted (HTTPS) and uploaded files are not publicly reachable. No service is perfectly secure; if an incident affects you we will tell you without undue delay, as the GDPR requires.
7.Changes
If this policy changes materially we will update the date at the foot of the page and, where the change affects you directly, notify you by email.