Skip to main content

Legal

Privacy Policy

Last updated 22 July 2026

This policy explains what personal information Monobrow Holidays Greece collects when you use our website or enquire with us, why we collect it, who we share it with, and the rights you have over it. We have tried to write it in plain language rather than legal boilerplate.

1. Who we are

Monobrow Holidays Greece IKE, trading as Monobrow Holidays Greece or Monobrow Greece ("we", "us", "our"), is a licensed Greek travel agency and the data controller responsible for the personal information described here.

Legal entity: Monobrow Holidays Greece IKE

Greece Company Registration Number: 182462003000

Registered address: Mysonos 33-35, Athens, Greece 11743

Greek Tourism Authority (EOT) member number: 0206Ε60000378300

Email: theo@monobrowholidays.com

WhatsApp / phone: +30 6955 168 125

2. Information we collect

Information you give us

  • Your name, email address and phone or WhatsApp number.
  • Your travel brief - the destinations, dates, party size, budget band and preferences you enter in our enquiry forms for day tours, transfers, hotels and villas, car hire, ferries and catamaran charters.
  • Anything you write in a free-text box, including special requests.
  • If you are a travel agent: your agency name and any client reference you give us.
  • Your email address, if you choose to subscribe to our newsletter.

Information collected automatically

  • Aggregate, cookie-free usage statistics - pages viewed, approximate country, device type and page speed - through Vercel Web Analytics and Speed Insights. These do not identify you and are not used to track you across other websites.
  • Anti-spam signals processed by Cloudflare Turnstile when you submit a form.
  • Standard technical logs kept by our hosting provider.

Held on your device, not by us

The enquiry basket you build as you browse - the tours, transfers, stays and other services you add - is saved in your own browser's local storage. It stays on your device and only reaches us if you choose to submit the enquiry form. Clearing your browser data removes it.

Sensitive information

Sometimes what you tell us in order to plan a trip is health-related - a mobility limitation, an allergy, a dietary requirement. We use it only to arrange travel that suits you, and we rely on your explicit consent, which you give by choosing to tell us. Please share only what is necessary for us to help.

3. If you booked through a travel agent

Many of our guests book through a travel agent rather than with us directly. If that is how your trip was arranged, this section explains where your information came from and how we use it. The rest of this policy applies to you as well.

Where we got your information

We received it from your travel agent rather than from you. That is normally your name, your contact details including your phone or WhatsApp number, and your booking details, passed to us so we can deliver your trip and look after you while you are in Greece. Your agent is our source for it, and we hold it as a data controller in our own right.

Our WhatsApp concierge service

While you are travelling we look after you over WhatsApp, so you can reach us quickly for anything you need. We rely on our legitimate interests to do this - our interest in delivering the concierge service you were promised when you booked, and in supporting the agent who arranged your trip. You can ask us to stop contacting you this way at any time.

WhatsApp is operated by Meta. The content of your messages is end-to-end encrypted, so Meta cannot read what we send each other, but Meta does process your phone number and related information as an independent controller under its own terms, including outside the European Economic Area. Your chat with us is set to delete automatically after 90 days.

Your rights are the same

You have every right listed in Section 10, including the right to be told - as we are telling you here - that we obtained your information from your travel agent rather than from you directly.

4. Why we use it, and our legal basis

Replying to your enquiry and preparing a quote

Steps taken at your request before entering into a contract

Arranging, booking and managing your trip

Performance of our contract with you

Looking after you by WhatsApp while you are travelling

Our legitimate interest in delivering the concierge service you were promised, and in supporting our travel agent partners

Emailing you a copy of your own enquiry, when you tick that box

Your consent

Newsletters and occasional marketing emails

Your consent, which you can withdraw at any time

Giving approved travel agents access to trade rates

Our legitimate interest in providing B2B pricing securely

Preventing spam and abuse of our forms

Our legitimate interest in protecting the website

Understanding how the site is used, in aggregate

Our legitimate interest in improving the site

Keeping accounting and tax records

Compliance with our legal obligations in Greece

5. Who we share it with

We do not sell your personal information, and we do not share it for advertising. We share only what is necessary, with:

  • The suppliers who deliver your trip - hotels and villa owners, transfer and car hire companies, ferry operators, guides and catamaran operators. They receive only what they need, typically names, dates and any relevant requirement.
  • The providers who run our systems - Vercel (website hosting), Google (our business email), Cloudflare (spam protection).
  • WhatsApp (Meta) - where we look after you by WhatsApp during your trip. Message content is end-to-end encrypted, but Meta processes your phone number and related information as an independent controller, including outside the EEA. See Section 3.
  • Travel agent partners- where you booked through an agent, we keep that agent updated on their client's arrangements. The same agent is our source for your details, as explained in Section 3.
  • Professional advisers and authorities - our accountants, and regulators or authorities where the law requires it.

6. International transfers

Arranging travel sometimes means sending details to suppliers outside the European Economic Area, and some of our technology providers process data outside the EEA. Where that happens, we rely on appropriate safeguards - either an adequacy decision by the European Commission, or Standard Contractual Clauses. Email us if you would like details of the safeguards that apply.

7. How long we keep it

  • Enquiries that do not lead to a booking: up to 24 months, then deleted.
  • Booking and financial records: for as long as Greek tax and accounting law requires, generally at least five years after the end of the relevant financial year.
  • WhatsApp concierge chats: set to delete automatically after 90 days.
  • Newsletter subscribers: until you unsubscribe.
  • Travel agent portal: a sign-in link expires after 20 minutes, and a signed-in session lasts up to 90 days before a new link is needed.

8. Cookies and similar technologies

We keep this deliberately minimal:

  • We do not use advertising or cross-site tracking cookies.
  • Our analytics are cookie-free and aggregated, which is why you are not met with a cookie consent banner.
  • One necessary cookie is set for approved travel agents who sign in to the trade portal, to keep them signed in. It is secure and HTTP-only.
  • Cloudflare Turnstile may set a short-lived token to confirm you are not a bot.
  • Your enquiry basket uses your browser's local storage, as described above.

9. How we protect it

The site is served over an encrypted connection, and enquiries are delivered to our business email. The travel agent portal stores no passwords at all - access is by a one-time link sent to an approved work address, and the session cookie is signed and HTTP-only. No system can be guaranteed perfectly secure, but we take reasonable technical and organisational steps to protect your information.

10. Your rights

Under the General Data Protection Regulation you have the right to:

  • Accessask for a copy of the information we hold about you
  • Correctionhave anything inaccurate or incomplete put right
  • Erasureask us to delete your information, where we have no ongoing need for it
  • Restrictionask us to pause using it while a concern is resolved
  • Portabilityreceive the information you gave us in a portable format
  • Objectionobject to processing we carry out on the basis of legitimate interests
  • Withdraw consentwithdraw consent at any time, where consent is what we rely on

To exercise any of these, email theo@monobrowholidays.com. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.

Where we received your information from a travel agent rather than from you directly, you have these same rights over it, including the right to be told that the agent was our source. Section 3 explains how that works.

You also have the right to complain to the Hellenic Data Protection Authority, Kifissias Avenue 1-3, 115 23 Athens, telephone +30 210 6475600, www.dpa.gr. We would appreciate the chance to put things right first.

11. Children

Our services are intended for adults. We do not knowingly collect information directly from children, other than the details an adult provides about their party when booking a family trip. If you believe a child has given us information directly, please contact us and we will delete it.

12. Changes to this policy

We may update this policy from time to time. The date at the top shows when it was last revised, and any material change will be reflected here.

13. Contact us

Questions about this policy, or about the information we hold on you, are welcome. Email theo@monobrowholidays.com or message us on WhatsApp, and Theo or Thanasis will come back to you.

Hear from us occasionally

Join our emailing list to stay in touch with Theo & Thanasis.