Privacy & Personal Data Protection Policy

Last Updated: August 2026

At Hop in Sightseeing, we respect your privacy and are committed to protecting your personal data.
This Privacy & Personal Data Protection Policy explains what personal information we collect,
why we collect it, how we use and protect it, who may receive it, and the rights available to you.

This Policy applies when you visit our website, contact us, make a booking, purchase a service,
subscribe to communications, or otherwise interact with us.

1. Data Controller

The Data Controller responsible for the processing of your personal data is:

UNIQUE DESTINATION TRAVEL ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
Trading as: Hop in Sightseeing
44 Leof. Vasilissis Amalias
Athens 10558, Greece
Telephone: +30 210 428 5 500
Email:
[email protected]

For any question regarding this Privacy Policy, the processing of your personal data,
or the exercise of your data protection rights, you may contact us at
[email protected].

2. Applicable Data Protection Law

We process personal data in accordance with applicable data protection and privacy legislation,
including:

  • Regulation (EU) 2016/679 – General Data Protection Regulation (GDPR);
  • Greek Law 4624/2019, as amended, concerning the implementation of the GDPR in Greece;
  • Greek Law 3471/2006, as amended, concerning privacy and personal data in electronic communications; and
  • any other applicable Greek or European legislation relating to privacy and the protection of personal data.

3. Personal Data We May Collect

Depending on how you interact with us and the services you request, we may collect and process
the following categories of personal data:

  • Name and surname;
  • Email address;
  • Telephone number;
  • Billing address and other billing information;
  • Country of residence, where required;
  • Hotel, accommodation or local pickup/drop-off information;
  • Booking details, including tour, excursion, cruise or other service selected;
  • Travel date and number of passengers;
  • Passenger categories, where relevant to the booking, such as adult, child or infant;
  • Special requests that you voluntarily provide to us;
  • Payment and transaction information;
  • Communications between you and our company;
  • Technical information such as IP address, browser type, device information and website activity;
  • Cookie and similar technology information, subject to your choices and applicable law.

We ask you to provide only the information reasonably necessary for us to provide the service
you have requested.

4. Information Required to Complete a Booking

Certain personal data are necessary in order for us to process and fulfil your booking.
If you do not provide information that is required for the performance of the requested service,
we may be unable to complete or fulfil your booking.

For example, we may require your name, contact details, travel date, number of passengers,
accommodation or pickup information and relevant payment information.

5. How We Collect Your Personal Data

We may collect personal data:

  • directly from you when you make a booking through our website;
  • when you contact us by email, telephone, contact form or other communication method;
  • when you visit our office;
  • when you subscribe to communications;
  • when you interact with our website;
  • through cookies and similar technologies, subject to applicable consent requirements;
  • from travel agents, booking partners or other parties acting on your behalf, where applicable.

6. Why We Use Your Personal Data

We may process your personal data for the following purposes:

  • to process and manage your booking;
  • to provide tours, cruises, excursions, transfers and other services that you have purchased;
  • to arrange pickup and drop-off services;
  • to communicate booking confirmations, vouchers, meeting points, pickup times and operational information;
  • to contact you in the event of a change, delay or problem affecting your reservation;
  • to process payments and maintain transaction records;
  • to provide customer service and respond to enquiries;
  • to comply with accounting, tax, legal and regulatory obligations;
  • to prevent fraud, misuse, security incidents and other unlawful activity;
  • to maintain and improve the security and functionality of our website;
  • to understand how customers use our website and services;
  • to send promotional communications where permitted by law and, where required, with your consent.

7. Legal Bases for Processing

Under the GDPR, we process personal data only where we have a lawful basis for doing so.
Depending on the circumstances, our legal bases may include:

Performance of a Contract

We process personal data when it is necessary to take steps at your request before entering
into a contract or to fulfil a booking or other contract between you and us.

This includes processing required to confirm your reservation, arrange transportation,
provide the booked service, communicate operational information and process your payment.

Legal Obligation

We may process and retain information where this is necessary to comply with legal obligations,
including accounting, taxation, regulatory and other obligations imposed on our company.

Legitimate Interests

Where permitted by law, we may process personal data where this is necessary for our legitimate
business interests, provided that those interests are not overridden by your fundamental rights
and freedoms.

Examples may include fraud prevention, security, maintaining business records, improving our
services and responding to customer enquiries or complaints.

Consent

Where processing requires your consent, such as certain marketing communications or
non-essential cookies, we will request that consent separately.

Where processing is based on consent, you may withdraw your consent at any time.
Withdrawal of consent does not affect the lawfulness of processing carried out before the
withdrawal.

8. Booking and Operational Communications

When you make a booking with us, we may contact you using the contact details you provided
in order to fulfil that booking.

These communications may include:

  • booking confirmations;
  • payment information;
  • booking vouchers;
  • meeting point and departure information;
  • hotel or accommodation pickup details;
  • changes to departure times or locations;
  • information concerning the operation of your booked tour or service;
  • important safety or service information.

These are service-related communications and are different from promotional marketing messages.

9. Marketing Communications

We may send you information about our tours, excursions, cruises, services or special offers
where this is permitted by applicable law.

Where your consent is required, we will obtain it before sending such communications.
You may withdraw your consent or opt out of marketing communications at any time.

You may contact us at
[email protected]
if you no longer wish to receive marketing communications.

Opting out of marketing communications will not prevent us from sending you communications
that are necessary in relation to an existing booking.

10. Payments

Payments may be processed through banks, payment gateways and electronic payment service
providers.

Depending on the payment method selected, your payment provider may process your payment
card or account information directly in accordance with its own privacy and security policies.
We may receive transaction information necessary to confirm and manage your payment,
such as payment status, transaction reference and amount.

We do not use payment information for purposes unrelated to your transaction except where
required by law or necessary for fraud prevention, accounting or dispute resolution.

11. Sharing Your Personal Data

We do not sell your personal data.

Where necessary to provide the services you have requested, we may share relevant information
with selected third parties, including:

  • tour operators;
  • cruise operators;
  • transportation and transfer providers;
  • hotels or accommodation providers where required for pickup arrangements;
  • guides and other service providers directly involved in your booking;
  • banks and payment service providers;
  • website hosting, IT and technical service providers;
  • professional advisers such as accountants, lawyers and auditors;
  • public, tax, judicial or regulatory authorities where disclosure is required by law.

We provide service providers only with personal data reasonably necessary for them to perform
the relevant service.

Service providers processing personal data on our behalf are required, where applicable,
to process such data in accordance with our instructions and appropriate confidentiality and
data protection obligations.

12. Tour Operators, Suppliers and Transfer Providers

Some services sold through our website are provided or partly performed by third-party tour
operators, cruise companies, transfer providers or other travel suppliers.

Where necessary to fulfil your booking, information such as your name, number of passengers,
hotel or pickup location, local telephone number and relevant booking information may be provided
to the supplier responsible for delivering that service.

Where a supplier processes your information independently for its own purposes, that supplier
may also act as a separate data controller and its own privacy policy may apply.

13. International Transfers of Personal Data

Some of the technology, payment, hosting or service providers that we use may process or store
personal data outside Greece or outside the European Economic Area (EEA).

Where personal data are transferred outside the EEA, we will take appropriate measures as
required by the GDPR, such as relying on an adequacy decision of the European Commission or
appropriate contractual and organisational safeguards, where applicable.

14. How Long We Keep Your Personal Data

We retain personal data only for as long as reasonably necessary for the purposes for which it
was collected and processed.

The applicable retention period depends on the type of information and the reason for processing.
For example:

  • booking information is retained as necessary to provide the service and deal with subsequent enquiries, disputes or claims;
  • financial and transaction records are retained for the periods required by applicable accounting and tax legislation;
  • customer communications may be retained where reasonably necessary for customer service, dispute resolution or legal purposes;
  • marketing information is retained until you unsubscribe, withdraw consent or we otherwise determine that it is no longer necessary;
  • technical and security information is retained for an appropriate period based on security and operational requirements.

When personal data are no longer necessary and there is no legal reason requiring us to retain
them, they will be deleted or anonymised as appropriate.

15. Data Security

We implement appropriate technical and organisational measures designed to protect personal data
against accidental or unlawful destruction, loss, alteration, unauthorised disclosure,
unauthorised access and other unlawful processing.

Access to personal information is limited to authorised personnel and service providers who
require access for legitimate business purposes and are subject to appropriate confidentiality
and security obligations.

Although we take reasonable steps to protect your personal data, no method of transmission or
electronic storage can be guaranteed to be completely secure.

16. Cookies and Similar Technologies

Our website uses cookies and similar technologies.

Some cookies are technically necessary for the operation of the website and the services you
request. Other cookies, such as analytics, functionality or advertising cookies, may require
your prior consent.

Where consent is required, such cookies will not be used until you have made the relevant choice
through our cookie consent mechanism.

You may change your cookie preferences through the cookie settings available on our website.
Withdrawal of consent does not affect processing that occurred before consent was withdrawn.

For more detailed information about the cookies used on our website, please see our
Cookie Policy.

17. Your Rights Under the GDPR

Depending on the circumstances and subject to the conditions provided by law, you may have the
following rights regarding your personal data:

  • Right of access – to obtain information about whether and how we process your personal data and to request a copy of your data;
  • Right to rectification – to request correction of inaccurate or incomplete personal data;
  • Right to erasure – to request deletion of your personal data where the legal requirements are satisfied;
  • Right to restriction of processing – to request restriction of processing in certain circumstances;
  • Right to data portability – where applicable, to receive certain personal data in a structured, commonly used and machine-readable format and to request its transmission to another controller;
  • Right to object – to object to certain processing based on legitimate interests and to object at any time to processing for direct marketing;
  • Right to withdraw consent – where processing is based on consent, to withdraw that consent at any time;
  • Rights relating to automated decision-making – where applicable, rights concerning decisions based solely on automated processing that produce legal or similarly significant effects.

These rights are subject to the conditions and limitations established by applicable law.
For example, the right to erasure does not require us to delete information that we are legally
obliged to retain.

18. How to Exercise Your Rights

To exercise a data protection right or ask a question concerning your personal data,
please contact:

Hop in Sightseeing – Privacy Request
Email: [email protected]
Address: 44 Leof. Vasilissis Amalias, Athens 10558, Greece

To protect your personal data, we may need to verify your identity before completing certain
requests.

We will respond to requests within the time limits required by applicable data protection law.
Under the GDPR this will normally be within one month, although the period may be extended where
permitted by law due to the complexity or number of requests.

19. Right to Lodge a Complaint

If you believe that the processing of your personal data infringes applicable data protection
law, you have the right to lodge a complaint with the competent supervisory authority.

For Greece, the supervisory authority is:

Hellenic Data Protection Authority
1–3 Kifisias Avenue
115 23 Athens, Greece
Telephone: +30 210 6475600
Email: [email protected]
Website:
Hellenic Data Protection Authority

Where applicable, complaints may also be submitted through the Authority’s official online
complaint procedure.

20. Children

Our travel and tourism services may be used by minors when accompanied or booked by a parent,
guardian or other authorised adult.

Where information concerning a minor is necessary for a booking, we ask that it is provided by
or with the authority of the minor’s parent or legal guardian.

We do not knowingly use children’s personal data for direct marketing without an appropriate
legal basis.

21. Third-Party Websites

Our website may contain links to websites or services operated by third parties.
We are not responsible for the privacy practices or content of independent third-party websites.
We encourage you to review their privacy policies before providing personal information to them.

22. Changes to This Privacy Policy

We may update this Privacy & Personal Data Protection Policy from time to time to reflect changes
in our services, technology, business practices or applicable law.

The latest version will always be published on this page together with the date of the most
recent update.

23. Contact Us

If you have any questions about this Privacy Policy or how we process your personal data,
please contact us:

Hop in Sightseeing
44 Leof. Vasilissis Amalias
Athens 10558, Greece
Telephone: +30 210 428 5 500
Email: [email protected]