Privacy Policy

Last updated: 1 November 2025  ·  RentalCenterCrete.gr

Summary: We are a small, family-owned car rental company based in Chania, Crete. We collect only the information necessary to respond to your rental enquiry and operate our business. We do not sell your data. We use Google Analytics only with your consent. This policy explains exactly what we collect, why, and your rights under the GDPR.

1. Who We Are (Data Controller)

Rental Center Crete
Address: Chania, Crete 73100, Greece
Email: info@rentalcentercrete.gr
Website: https://rentalcentercrete.gr

We are the data controller for personal data processed through this website. We process data in accordance with the EU General Data Protection Regulation (GDPR, Regulation 2016/679) and Greek Law 4624/2019.

2. What Data We Collect and Why

2.1 Quote Request Form

When you submit a quote request, we collect:

  • Email address — to send you a quote and reply to your enquiry
  • Phone / WhatsApp number (optional) — to contact you faster if you request it
  • Rental details (dates, location, vehicle type, driver age) — to prepare an accurate quote
  • Free-text message — any additional information you choose to include

Legal basis: Article 6(1)(b) GDPR — processing is necessary to take steps at your request prior to entering a contract.

2.2 Rental Contracts

If you proceed to rent a vehicle, we collect additional data required by law and to fulfil the contract:

  • Full name, date of birth, nationality
  • Driving licence number, issuing country, expiry date
  • Passport or national ID number
  • Credit/debit card details (for security pre-authorisation only — not stored by us)
  • Flight number or arrival details

Legal basis: Article 6(1)(b) — necessary for the performance of a contract; Article 6(1)(c) — compliance with legal obligations (Greek Road Traffic Code, insurance requirements).

2.3 Google Analytics (with consent)

With your consent, we use Google Analytics 4 to understand how visitors use our website. This may collect:

  • Anonymised IP address
  • Pages visited, time spent, referring source
  • Device type, browser, operating system
  • Geographic region (country/city level)

We have enabled IP anonymisation. Google Analytics data is processed by Google LLC (USA) under Standard Contractual Clauses.

Legal basis: Article 6(1)(a) — your consent, given via the cookie banner. You may withdraw consent at any time by clearing your browser's local storage.

You can opt out of Google Analytics tracking at any time via the Google Analytics Opt-out Browser Add-on.

2.4 Server Logs

Our web server automatically records standard access logs: IP address, date/time, URL requested, HTTP status code, browser user-agent. These are used for security monitoring and troubleshooting. They are retained for 30 days and then deleted.

Legal basis: Article 6(1)(f) — legitimate interest in maintaining the security and proper functioning of our website.

3. Cookies

Cookie namePurposeDurationConsent required?
gdpr_consentStores your cookie consent choice (accepted/declined)Local storage (no expiry)No — necessary for consent management
_gaGoogle Analytics — distinguishes users2 yearsYes
_ga_*Google Analytics — session state2 yearsYes

We set Google Analytics cookies only after you click "Accept cookies" in the consent banner. We do not use advertising, retargeting or social media tracking cookies.

4. How We Use Your Data

  • To respond to your quote request by email or WhatsApp
  • To prepare and send your rental agreement
  • To deliver your vehicle and manage your rental
  • To comply with insurance and legal requirements (e.g. Greek road traffic law)
  • To send an automated confirmation email when you submit a quote form
  • To analyse website traffic and improve our service (only with your consent)

We do not use your data for automated decision-making or profiling. We do not use your email address for marketing without your explicit opt-in.

5. Who We Share Data With

We share personal data only where necessary:

  • Our insurance provider — driver licence and personal data required to issue insurance cover for your rental
  • Greek tax authority (AADE) — invoicing and VAT obligations
  • Google LLC — Google Analytics, under Standard Contractual Clauses (only with your consent)
  • Web hosting provider — server infrastructure for this website, under a data processing agreement

We do not sell, rent or share your personal data with marketing companies, data brokers or third parties for their own purposes.

6. International Transfers

Google Analytics transfers data to the USA. This is covered by Standard Contractual Clauses approved by the European Commission. No other data is transferred outside the European Economic Area (EEA).

7. How Long We Keep Your Data

Data typeRetention periodReason
Quote request data (no booking)6 monthsTo follow up if requested; then deleted
Rental contract data7 yearsGreek tax and accounting law requirements
Insurance documents5 yearsInsurance regulatory requirements
Server logs30 daysSecurity monitoring
Google Analytics data14 monthsGA4 default retention; anonymised after that

8. Your Rights Under GDPR

As an EU/EEA data subject, you have the following rights:

  • Right of access — request a copy of personal data we hold about you
  • Right to rectification — correct inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") — request deletion, subject to legal retention obligations
  • Right to restriction of processing — ask us to limit how we use your data
  • Right to data portability — receive your data in a structured, machine-readable format
  • Right to object — object to processing based on legitimate interest
  • Right to withdraw consent — withdraw any consent given (e.g. analytics cookies) without affecting the lawfulness of prior processing

To exercise any of these rights, email us at info@rentalcentercrete.gr. We will respond within 30 days. We may need to verify your identity before acting on a request.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA): www.dpa.gr · Postal address: Kifisias 1–3, 115 23 Athens, Greece.

9. Security

We take reasonable technical and organisational measures to protect your personal data:

  • HTTPS encryption for all data in transit
  • Honeypot and rate-limiting on our contact forms to prevent spam
  • Access to personal data restricted to personnel who need it to do their job
  • Email communications with customers use standard SMTP with TLS where supported

We do not store credit card numbers. Security pre-authorisations are handled by your card issuer directly.

10. Children

Our website is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has submitted data to us, contact us at info@rentalcentercrete.gr and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.

12. Contact

For any privacy-related questions or to exercise your rights:

Rental Center Crete
Chania, Crete 73100, Greece
Email: info@rentalcentercrete.gr