1. Who we are
This website is operated for Scirocco Restaurant, Protodikeiou Square, Chora Naxos 84300, Cyclades, Greece.
2. Personal data we may collect
Depending on how you use the website, we may process:
- your name, email address, telephone number and message when you use the contact form;
- reservation information when you choose to use our online reservation service;
- technical information such as browser/device information, IP-related security data and basic request logs;
- analytics information if you consent to analytics cookies;
- advertising/marketing information if you consent to marketing cookies.
We do not use the website contact form to collect payment-card data.
3. Why we use personal data
We use personal data to answer enquiries, help with reservations, operate and secure the website, comply with legal obligations and, only where you have chosen it, measure website usage or support advertising/marketing.
Legal bases
- Your request / pre-contractual steps: when you contact us about a reservation or service.
- Legitimate interests: for general enquiries, website administration, fraud prevention and security, where those interests do not override your rights.
- Consent: for optional analytics and marketing technologies.
- Legal obligation: where Greek or EU law requires processing or retention.
4. Contact form and reservations
Messages submitted through the contact form are sent to authorised Scirocco recipients by email. The form is protected by Cloudflare Turnstile to reduce automated abuse and spam. Cloudflare may process technical information required to perform this security check.
If you follow a link to an external online reservation provider, that provider may process reservation information under its own privacy terms. We recommend reviewing the provider’s privacy information before submitting a reservation.
6. Service providers and international transfers
We may use hosting/email and technical service providers to operate the website. Where enabled by your choices, Google and Meta may also receive information for analytics or marketing purposes. Cloudflare processes information required for Turnstile security checks.
Some providers may process data outside Greece or the European Economic Area. Where required, such transfers should be protected by recognised safeguards such as adequacy decisions or Standard Contractual Clauses.
7. How long we keep data
We keep personal data only for as long as necessary for the purpose for which it was collected, including answering your enquiry, handling a reservation, maintaining security records, or meeting legal/accounting obligations. Consent preferences are stored for the period stated in the cookie table unless you change or clear them earlier.
8. Your GDPR rights
Subject to the conditions of applicable law, you may have the right to request access, correction, deletion, restriction, portability or objection to processing. Where processing is based on consent, you may withdraw that consent at any time without affecting processing that was lawful before withdrawal.
You can change optional cookie consent at any time using the Cookie settings button above. You may also lodge a complaint with the Hellenic Data Protection Authority or another competent supervisory authority.
9. Security
We use reasonable technical and organisational measures designed to protect personal data, including HTTPS transport, access controls and anti-abuse protection on the contact form. No internet system can be guaranteed to be completely secure.
10. Changes to this policy
We may update this policy when our website, services, legal requirements or third-party technologies change. The latest version will always be published at /privacy-policy.html with the updated date shown above.
