Last updated: June 2026
This privacy policy explains clearly how Pap-illon (“we”, “the business”) collects, uses, stores and protects your personal data when you visit papillon-symi.com, use the contact form, or interact with features that load third-party services (e.g. map, review widget).
This policy applies to this informational website. We do not sell products online through the website; transactions take place in our physical store only.
1. Legal framework & data controller
We process personal data in accordance with:
- Regulation (EU) 2016/679 (GDPR)
- Applicable Greek implementation law (Law 4624/2019) and related regulations
- Electronic communications and ePrivacy rules, where applicable
The data controller for the activities described here is ΧΡΗΣΤΟΣ ΑΓΓΕΛΟΣ ΠΑΠΑΚΩΝΣΤΑΝΤΙΝΟΥ-ΕΥΑΓΓΕΛΙΑ ΤΡΙΠΕΔΗ Ο.Ε.. Identity and contact details appear in the “Business details” block at the top of this page.
For privacy enquiries and rights requests: info@papillon-symi.gr. We aim to respond within 30 days (up to 60 days in complex cases, with notice).
2. Data we collect
- Contact form: name, email, optional phone, subject, message, submission date/time and site language.
- Privacy consent: record that you accepted the privacy policy when submitting the form.
- Technical data: IP address, request date/time, browser language, user agent, referrer — via hosting server logs.
- Cookies & local storage: essential session cookies (CSRF, Laravel session), Google reCAPTCHA for form security, and — only with your consent — Google Maps and TripAdvisor rating widget. Cookie choice is stored in browser localStorage (
papillon_cookie_consent).
3. What we do not collect or do
- No user accounts, passwords or payment details on the website.
- No marketing, remarketing or analytics cookies unless enabled in the future with an updated cookie policy and separate consent where required.
- We do not sell, rent or trade your personal data.
- No automated decision-making or profiling with legal or similarly significant effects.
4. Purposes & legal bases (GDPR)
| Purpose | Data | Legal basis |
|---|---|---|
| Replying to contact requests | Form fields, consent | Consent (Art. 6(1)(a)) & legitimate interest in customer service (6(1)(f)) |
| Form security (reCAPTCHA, honeypot, rate limit) | Verification token, IP, Google technical data | Legitimate interest in abuse prevention (6(1)(f)) |
| Website operation, language, security | Session cookies, logs | Legitimate interest (6(1)(f)) |
| Google Maps display | Maps loading data | Consent (6(1)(a)) — “Accept all” only |
| TripAdvisor rating widget | TripAdvisor widget loading data | Consent (6(1)(a)) — “Accept all” only |
5. Whether provision is mandatory
Contact form fields are voluntary but necessary for us to reply. Without a valid email and message we cannot respond. Privacy policy acceptance is required to submit the form. Essential cookies are required for site operation; third-party services (Maps, TripAdvisor) load only if you accept them.
6. Recipients, processors & transfers
Data is hosted with our hosting provider (EU/EEA where applicable). Access is limited to authorised staff and technical support under confidentiality.
Data may be shared with:
- Google LLC (reCAPTCHA v3, Google Maps) — processing outside the EEA may occur with appropriate safeguards (e.g. Standard Contractual Clauses). Policy: policies.google.com/privacy
- TripAdvisor LLC (rating widget, consent only) — TripAdvisor Privacy
- Email provider (SMTP) — contact form notifications.
Links to Instagram, Facebook etc. lead to third-party sites; we do not embed social media tracking pixels on this website.
7. Retention
- Contact messages: up to 24 months after reply, unless longer retention is legally required or communication is ongoing.
- Server logs: per hosting policy (typically 30–90 days).
- Cookie consent: until you change choice, revoke consent, or clear browser data.
- Backups: may exist temporarily in backups with limited retention.
8. Your rights
Under the GDPR you may request: access, rectification, erasure, restriction, data portability (where applicable), object to processing based on legitimate interest, and withdraw consent at any time without affecting prior lawful processing.
To exercise your rights: info@papillon-symi.gr. To revoke cookie consent, use cookie preferences.
You may lodge a complaint with Hellenic Data Protection Authority (www.dpa.gr).
9. Security
We apply HTTPS, security headers, restricted admin access, honeypot, rate limiting, reCAPTCHA and software updates. No online measure guarantees absolute security. We will act in accordance with GDPR if a serious incident affects your data.
10. Children
This website is not directed at children under 16. We do not knowingly collect minors’ data without parental consent. Contact us for deletion if you believe we have received such data.
11. Changes
We may update this policy. Material changes will be posted on the website; renewed consent will be requested where required.
12. Related documents
Cookie policy · Terms of use · Disclaimer · Allergens · Contact