Choose how you want to save this trip.
This Privacy Policy explains how Greekaway collects, uses, stores and protects personal data when you visit our website, request or book a service, use PROFILE or MY BOOKINGS, communicate with us, or otherwise interact with Greekaway.
Greekaway processes personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation or “GDPR”), Greek Law 4624/2019 and, where applicable, Greek Law 3471/2006 concerning electronic communications.
This Policy is intended to provide information. It does not constitute consent to every form of processing described below. Where consent is required, for example for optional advertising technologies, marketing communications or certain special-category data, it will be requested separately through an appropriate affirmative action.
The data controller is:
AWAY SYSTEMS O.E. determines the purposes and means of processing personal data through Greekaway, except where another service provider acts as a separate data controller for its own processing activities.
This Policy applies to personal data processed through:
Third-party websites, platforms and services are governed by their own privacy policies.
We process personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality.
We seek to collect only the information reasonably required for the requested service, our legal obligations, security and the proper operation of Greekaway.
We do not sell, rent or trade our customers’ personal data.
Depending on how you interact with Greekaway, we may process the following categories of data.
Please avoid including unnecessary confidential or medical information in free-text fields.
We may process:
Greekaway does not receive or store the complete card number, card security code or full card credentials.
Where cash payment is available, we may record that cash was selected and whether payment was completed. Cash payments do not involve a Stripe card refund.
Greekaway provides passwordless access through a secure magic link sent to the email address associated with a booking.
We may process:
Where profile information is incomplete, Greekaway may use the name and telephone number already provided in existing bookings associated with the same verified email address to complete the customer profile.
Magic links are short-lived and may be used only for their intended purpose. You should not forward or share them with another person.
We may retain information contained in:
Telephone conversations are not recorded unless you are informed in advance and a lawful basis exists.
When you use the website, our systems and infrastructure providers may process:
The website may store information such as:
Some of this information may remain only on your device, while other information may be synchronised with a verified Greekaway profile.
Further details are available in our Cookie Policy.
Where optional analytics or advertising tools are activated and you have provided valid consent, we may process information such as:
Where supported by the selected advertising service and permitted by your consent, contact information such as an email address or telephone number may be transmitted in a securely hashed form for conversion measurement or audience matching.
We do not use payment-card information, private booking notes or special-category data for advertising.
We may obtain personal data:
We process personal data only where a lawful basis applies.
Under Article 6(1)(b) GDPR, we process data to:
Under Article 6(1)(c) GDPR, we process data where necessary to:
Under Article 6(1)(f) GDPR, we may process data where necessary for legitimate interests such as:
Before relying on legitimate interests, we consider whether the processing is necessary and whether your rights and interests override those interests.
Under Article 6(1)(a) GDPR, we rely on consent for activities such as:
You may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
In a genuine emergency, information may be processed where necessary to protect the vital interests of a passenger or another person, in accordance with Article 6(1)(d) GDPR and, where special-category data are involved, the applicable provisions of Article 9 GDPR.
Certain information, including valid contact details, pickup and destination information, service date and time, passenger requirements and payment information where applicable, is necessary to assess and perform a booking.
If required information is not supplied or is materially inaccurate, Greekaway may be unable to provide, confirm or properly perform the requested service.
Optional notes, marketing consent and non-essential cookie consent are not conditions for making a standard booking.
If you make a booking for another person or a group, you confirm that:
The person making the booking is responsible for communicating relevant booking information and applicable terms to the other passengers.
Greekaway may perform a service using a vehicle operated by AWAY SYSTEMS O.E. or assign it to a suitably authorised independent driver or transport provider.
To perform the service, we may share only the information reasonably necessary, such as:
The assigned driver or provider must use this information for performing the service, communicating with the passenger and complying with applicable legal obligations.
A driver or transport provider may act as a separate controller for processing required by their own legal, tax, insurance or transport obligations. Their independent processing is subject to their own legal responsibilities.
Online card payments are processed through Stripe. Depending on the booking flow, Stripe may:
Stripe processes transaction, device, authentication and fraud-prevention information in accordance with its own legal obligations and privacy practices.
For further information, see the Stripe Privacy Policy.
Greekaway does not require a traditional password for PROFILE and MY BOOKINGS. Access is provided through a secure magic link sent to the verified booking email address.
The link is currently valid for a limited period and is designed for one authorised recipient. A secure session may remain active until it expires or you sign out.
We process authentication and security information to:
If you believe that another person has accessed your email account or Greekaway session, contact us immediately.
Greekaway uses Google Maps Platform services to display maps, identify addresses, calculate routes and assist with pickup and destination selection.
Location information entered or selected by you, including addresses, place names and coordinates, may be transmitted to Google for these purposes.
Greekaway does not use the public website to continuously track your movements. Precise device location will be accessed only if an available feature requests it and you actively grant permission through your browser or device. Such permission can be withdrawn through your device or browser settings.
Use of Google Maps is subject to the Google Privacy Policy and the applicable Google Maps terms.
Information concerning accessibility, disability, health or other assistance requirements may constitute special-category personal data under Article 9 GDPR.
Please provide only information genuinely necessary for the safe and appropriate performance of the requested service.
Where such information is required, Greekaway will process it:
We do not use accessibility or health-related information for advertising or unrelated profiling.
Greekaway uses cookies, local storage, session storage and similar technologies.
Strictly necessary technologies may be used without consent where they are required for security, booking functionality, session management or remembering privacy choices.
Optional analytics and advertising technologies are used only after valid consent, where required. Depending on the tools subsequently activated, these may include services provided by Google, Meta Platforms or TikTok for:
Rejecting optional technologies will not prevent access to the essential booking functions of Greekaway, although some optional features may be unavailable.
You can change or withdraw your choices through Cookie Settings, available in the website footer and on the Legal page. Full details are provided in our Cookie Policy.
Booking confirmations, payment updates, security messages and service communications are transactional communications and may be sent where necessary to perform a booking or comply with legal obligations.
Promotional emails, messages or similar direct marketing will be sent only where a lawful basis exists and, where required, after your consent.
You may unsubscribe from promotional communications at any time by:
Unsubscribing from marketing does not prevent Greekaway from sending necessary booking, payment, security or legal communications.
Cookie consent and consent to direct marketing are separate choices.
If you choose to communicate through WhatsApp, WhatsApp and Meta may independently process your telephone number, device information and communication metadata under their own privacy policies. You may use email instead if you do not wish to communicate through WhatsApp.
Personal data may be disclosed, where necessary, to the following categories of recipients:
Service providers acting on our behalf receive only the information required for their assigned purpose and are subject to contractual, confidentiality and data-protection obligations where required by law.
Certain providers, including Stripe, Google, WhatsApp, advertising platforms and independent transport providers, may act as separate data controllers for some of their activities.
Their processing may include compliance with their own legal obligations, fraud prevention, platform security, payment-network requirements, transport records or the operation of their services.
Where a third party acts as an independent controller, its own privacy policy also applies. Greekaway does not control processing performed independently by that provider.
Some service providers may process personal data outside Greece or the European Economic Area.
Where personal data are transferred to a country outside the EEA, we rely on an appropriate transfer mechanism where required, such as:
You may contact us for information concerning the safeguards applicable to a particular transfer.
We retain personal data only for as long as reasonably necessary for the purposes for which it was collected, including contractual, tax, accounting, security and legal-claim requirements.
Our general retention criteria are:
When information is no longer required, it is deleted, anonymised or placed beyond normal use pending secure deletion from backup cycles. Properly anonymised statistical information may be retained without identifying an individual.
Greekaway applies appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, accidental loss or unlawful destruction.
These measures may include:
No internet service can guarantee absolute security. If a personal-data breach occurs, Greekaway will assess it and notify the Hellenic Data Protection Authority and affected individuals where required by the GDPR.
Greekaway does not make decisions producing legal or similarly significant effects concerning customers solely through automated processing.
Stripe and other payment providers may use automated systems to detect fraud, authenticate transactions or assess payment risk.
Where optional advertising technologies are enabled with consent, advertising providers may create audiences or profiles based on website interactions. Such advertising processing is not used by Greekaway to make decisions producing legal or similarly significant effects concerning you.
You may withdraw advertising consent through Cookie Settings.
Greekaway services are not intended to be booked independently by persons under 18 years of age.
An adult may make a booking that includes children and provide the limited information necessary for their transportation, safety or participation in a service.
We do not knowingly create advertising profiles directed at children or request unnecessary information about them. If we learn that a minor has submitted personal data without appropriate authority, we may suspend the relevant request and take reasonable steps to delete the information.
Subject to the conditions and limitations of the GDPR, you may have the right to:
These rights are not absolute. For example, certain data may need to be retained for tax obligations, payment disputes, fraud prevention, the protection of other persons or the establishment and defence of legal claims.
To exercise a data-protection right, contact:
Please describe your request clearly and identify the booking or email address concerned.
We may request information reasonably necessary to verify your identity and prevent disclosure of data to an unauthorised person. We will not request more verification information than necessary.
Requests are normally handled without charge and within one month. Where a request is particularly complex or numerous requests are received, this period may be extended by up to two additional months. We will inform you of any extension and the reasons for it.
Manifestly unfounded or excessive requests may be refused or subject to a reasonable fee where permitted by law.
You have the right to lodge a complaint with the Hellenic Data Protection Authority.
Hellenic Data Protection Authority
1–3 Kifisias Avenue 115 23 Athens Greece
For complaints concerning the exercise of GDPR rights, the Authority will generally expect you first to have submitted the relevant request to Greekaway and allowed the applicable response period to expire.
You may also seek judicial remedies where available under applicable law.
The website may contain links to social networks, mapping services or other third-party websites. Following such a link may allow the third party to process data under its own privacy policy. Greekaway is not responsible for the independent privacy practices of third-party websites.
We may update this Policy where our services, providers, technology or legal obligations change. The effective date, last-updated date and version number will be amended accordingly.
Material changes will be communicated in an appropriate and visible manner. Where a new purpose requires consent, the relevant processing will not begin until valid consent has been obtained.
For any question concerning this Policy or the processing of personal data by Greekaway, contact:
AWAY SYSTEMS O.E. — Greekaway