Legal
Privacy Policy
How we handle your personal data
Last updated: July 2026
1. Data controller
The controller responsible for processing personal data through this website is “OIKOS”, located at Korrisia, Kéa, Kikladhes, Greece 84002.
For any matter regarding your data you may contact us at oikoskeas@gmail.com or +30 22880 22507.
2. What data we process
Our website has no contact forms, user registration, shopping cart, or online booking system. We do not ask you for your name, email, or any other details to browse the site.
We process data only in the following cases:
- Technical browsing data (e.g. IP address, browser type) automatically logged by our hosting provider for server security and operation.
- Anonymous traffic statistics via Vercel Web Analytics, a cookieless measurement tool that stores nothing on your device and does not identify you or track you across other websites (e.g. page-view counts, country, device type).
- Information you voluntarily provide when you contact us by phone, email, or social media (e.g. your name and your request).
3. Table reservations
The website takes no online reservations. Bookings are made only by phone or in person, and are written down in a paper reservation book kept at the restaurant. They are not entered into any digital application, not stored in the cloud, and not passed to third parties.
For a reservation we typically note:
- Your name and a contact phone number.
- Date, time, and number of guests.
- Any note you choose to give us (e.g. seating preference, high chair, special occasion).
- Allergies or dietary restrictions, only if you volunteer them. These are health data (Article 9 GDPR): we process them solely on your explicit consent, only so we can serve you safely, we share them only with the kitchen and floor staff who need them, and we do not keep them after your visit.
- Invoicing details (company name, VAT number, address), only if you ask for an invoice instead of a receipt.
4. What we do not do
We think it matters just as much to state plainly what does not happen:
- There are no security cameras (CCTV) on our premises.
- We do not publish photographs in which guests are identifiable — our social media shows the food and the space.
- We keep no newsletter list and send no marketing messages.
- We never sell, rent, or trade personal data with anyone.
- We do not build profiles, and we make no decisions about you based solely on automated processing (Article 22 GDPR).
5. Purpose & legal basis
Each category of data has its own legal basis:
- Technical browsing data and anonymous statistics: our legitimate interest (Article 6(1)(f) GDPR) in the secure, proper, and improving operation of the website. Because the statistics are anonymous and cookieless, no consent is required.
- Reservation details: performance of a contract, or steps taken at your request before entering one (Article 6(1)(b)).
- Allergies and dietary restrictions: your explicit consent (Article 9(2)(a)).
- Invoicing details: compliance with a legal obligation under tax law (Article 6(1)(c)).
- What you write to us by email or message: our legitimate interest in answering your request.
- Loading the Google map: your consent (Article 6(1)(a)), which you may withdraw at any time.
6. Cookies
The website sets no cookies of its own and uses no tracking or advertising cookies. The embedded Google map on the Contact page loads only after you give consent (the “Accept” button in the cookie banner) or click “Load map”. You can change your choice anytime via “Cookie settings” in the footer. See our Cookie Policy for details.
7. Recipients & processors
We do not sell or rent personal data. The following may be involved:
- Vercel Inc. — hosting provider and provider of the Web Analytics tool, as a data processor.
- Google — only if you choose to load the map (Google Maps) on the Contact page.
- Our accountants — only for the receipts and invoices we issue, as part of our tax obligations.
8. Transfers outside the EEA
Some of the above providers (e.g. Vercel, Google) may process data on servers outside the European Economic Area. Where they do, the transfer is covered by the European Commission’s Standard Contractual Clauses (SCCs) or equivalent GDPR safeguards.
Reservation details are transferred nowhere at all: they stay on paper, inside the restaurant.
9. Retention period
- Reservation book: kept for a short period after the reservation date, then securely destroyed.
- Allergies and dietary restrictions: not retained after your visit ends.
- Receipts and invoicing details: for as long as tax law requires.
- Server logs and anonymous statistics: for a limited period, according to our providers’ policies.
- Emails and messages: only as long as needed to handle your request.
10. Your rights
Under the GDPR you have the right to access, rectify, erase, restrict, object to, and port your data, as well as to withdraw consent. To exercise any right, contact us at oikoskeas@gmail.com or +30 22880 22507. We reply within one month at the latest.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifisias Ave, 115 23 Athens, www.dpa.gr).
11. Security
The website is served over an encrypted connection (HTTPS). We take reasonable technical and organisational measures to protect your data. The reservation book is kept in a staff-only area of the restaurant.
12. Changes to this policy
We may update this policy. The current version always shows the last-updated date at the top.