Privacy · Hotels & Agencies
Privacy Notice — Hotels & Agencies
Last updated 19 June 2026. How we process personal data relating to partner organisations (hotels, travel agencies, cruise) and their authorised staff. Aristevo is the data controller; contact privacy@aristevo.com.
What we collect
Business identity and contacts (company name, ΑΦΜ, address, contact persons, email/phone); account and integration data (login or API credentials, usage logs); the booking data you submit (ride details, your own reference, retail price, and the guest details needed to perform the transfer); and settlement and invoicing data via myDATA.
Guest data
When you submit a guest’s personal data to arrange a ride, Aristevo processes it to fulfil that booking, governed by our Passenger privacy notice. You are responsible for having a lawful basis and for informing the guest before sharing their data with us.
Why we use it & legal basis
To operate the partnership and receive and fulfil bookings (performance of a contract); for settlement, invoicing and tax/accounting (legal obligation and contract); and for account security, fraud prevention and support (legitimate interests).
Who we share it with
The assigned driver/fleet, with the data needed to perform the guest’s ride; our payment, hosting and messaging providers, as processors; and the tax authority (ΑΑΔΕ/myDATA) and authorities where legally required.
How long we keep it
Partnership and booking records for the duration of the partnership and as needed for disputes; tax and accounting records for the period required by Greek law; accounts and credentials while active and for a limited period afterwards.
Your rights & complaints
Access, rectification, erasure, restriction, portability, objection and withdrawal of consent — privacy@aristevo.com. Complaints: Greek Data Protection Authority (dpa.gr).