Legal
Privacy Policy
Last updated 22 July 2026
This policy explains what personal information Monobrow Holidays Greece collects when you use our website or enquire with us, why we collect it, who we share it with, and the rights you have over it. We have tried to write it in plain language rather than legal boilerplate.
1. Who we are
Monobrow Holidays Greece IKE, trading as Monobrow Holidays Greece or Monobrow Greece ("we", "us", "our"), is a licensed Greek travel agency and the data controller responsible for the personal information described here.
Legal entity: Monobrow Holidays Greece IKE
Greece Company Registration Number: 182462003000
Registered address: Mysonos 33-35, Athens, Greece 11743
Greek Tourism Authority (EOT) member number: 0206Ε60000378300
Email: theo@monobrowholidays.com
WhatsApp / phone: +30 6955 168 125
2. Information we collect
Information you give us
- Your name, email address and phone or WhatsApp number.
- Your travel brief - the destinations, dates, party size, budget band and preferences you enter in our enquiry forms for day tours, transfers, hotels and villas, car hire, ferries and catamaran charters.
- Anything you write in a free-text box, including special requests.
- If you are a travel agent: your agency name and any client reference you give us.
- Your email address, if you choose to subscribe to our newsletter.
Information collected automatically
- Aggregate, cookie-free usage statistics - pages viewed, approximate country, device type and page speed - through Vercel Web Analytics and Speed Insights. These do not identify you and are not used to track you across other websites.
- Anti-spam signals processed by Cloudflare Turnstile when you submit a form.
- Standard technical logs kept by our hosting provider.
Held on your device, not by us
The enquiry basket you build as you browse - the tours, transfers, stays and other services you add - is saved in your own browser's local storage. It stays on your device and only reaches us if you choose to submit the enquiry form. Clearing your browser data removes it.
Sensitive information
Sometimes what you tell us in order to plan a trip is health-related - a mobility limitation, an allergy, a dietary requirement. We use it only to arrange travel that suits you, and we rely on your explicit consent, which you give by choosing to tell us. Please share only what is necessary for us to help.
3. If you booked through a travel agent
Many of our guests book through a travel agent rather than with us directly. If that is how your trip was arranged, this section explains where your information came from and how we use it. The rest of this policy applies to you as well.
Where we got your information
We received it from your travel agent rather than from you. That is normally your name, your contact details including your phone or WhatsApp number, and your booking details, passed to us so we can deliver your trip and look after you while you are in Greece. Your agent is our source for it, and we hold it as a data controller in our own right.
Our WhatsApp concierge service
While you are travelling we look after you over WhatsApp, so you can reach us quickly for anything you need. We rely on our legitimate interests to do this - our interest in delivering the concierge service you were promised when you booked, and in supporting the agent who arranged your trip. You can ask us to stop contacting you this way at any time.
WhatsApp is operated by Meta. The content of your messages is end-to-end encrypted, so Meta cannot read what we send each other, but Meta does process your phone number and related information as an independent controller under its own terms, including outside the European Economic Area. Your chat with us is set to delete automatically after 90 days.
Your rights are the same
You have every right listed in Section 10, including the right to be told - as we are telling you here - that we obtained your information from your travel agent rather than from you directly.
4. Why we use it, and our legal basis
Replying to your enquiry and preparing a quote
Steps taken at your request before entering into a contract
Arranging, booking and managing your trip
Performance of our contract with you
Looking after you by WhatsApp while you are travelling
Our legitimate interest in delivering the concierge service you were promised, and in supporting our travel agent partners
Emailing you a copy of your own enquiry, when you tick that box
Your consent
Newsletters and occasional marketing emails
Your consent, which you can withdraw at any time
Giving approved travel agents access to trade rates
Our legitimate interest in providing B2B pricing securely
Preventing spam and abuse of our forms
Our legitimate interest in protecting the website
Understanding how the site is used, in aggregate
Our legitimate interest in improving the site
Keeping accounting and tax records
Compliance with our legal obligations in Greece
5. Who we share it with
We do not sell your personal information, and we do not share it for advertising. We share only what is necessary, with:
- The suppliers who deliver your trip - hotels and villa owners, transfer and car hire companies, ferry operators, guides and catamaran operators. They receive only what they need, typically names, dates and any relevant requirement.
- The providers who run our systems - Vercel (website hosting), Google (our business email), Cloudflare (spam protection).
- WhatsApp (Meta) - where we look after you by WhatsApp during your trip. Message content is end-to-end encrypted, but Meta processes your phone number and related information as an independent controller, including outside the EEA. See Section 3.
- Travel agent partners- where you booked through an agent, we keep that agent updated on their client's arrangements. The same agent is our source for your details, as explained in Section 3.
- Professional advisers and authorities - our accountants, and regulators or authorities where the law requires it.
6. International transfers
Arranging travel sometimes means sending details to suppliers outside the European Economic Area, and some of our technology providers process data outside the EEA. Where that happens, we rely on appropriate safeguards - either an adequacy decision by the European Commission, or Standard Contractual Clauses. Email us if you would like details of the safeguards that apply.
7. How long we keep it
- Enquiries that do not lead to a booking: up to 24 months, then deleted.
- Booking and financial records: for as long as Greek tax and accounting law requires, generally at least five years after the end of the relevant financial year.
- WhatsApp concierge chats: set to delete automatically after 90 days.
- Newsletter subscribers: until you unsubscribe.
- Travel agent portal: a sign-in link expires after 20 minutes, and a signed-in session lasts up to 90 days before a new link is needed.
8. Cookies and similar technologies
We keep this deliberately minimal:
- We do not use advertising or cross-site tracking cookies.
- Our analytics are cookie-free and aggregated, which is why you are not met with a cookie consent banner.
- One necessary cookie is set for approved travel agents who sign in to the trade portal, to keep them signed in. It is secure and HTTP-only.
- Cloudflare Turnstile may set a short-lived token to confirm you are not a bot.
- Your enquiry basket uses your browser's local storage, as described above.
9. How we protect it
The site is served over an encrypted connection, and enquiries are delivered to our business email. The travel agent portal stores no passwords at all - access is by a one-time link sent to an approved work address, and the session cookie is signed and HTTP-only. No system can be guaranteed perfectly secure, but we take reasonable technical and organisational steps to protect your information.
10. Your rights
Under the General Data Protection Regulation you have the right to:
- Accessask for a copy of the information we hold about you
- Correctionhave anything inaccurate or incomplete put right
- Erasureask us to delete your information, where we have no ongoing need for it
- Restrictionask us to pause using it while a concern is resolved
- Portabilityreceive the information you gave us in a portable format
- Objectionobject to processing we carry out on the basis of legitimate interests
- Withdraw consentwithdraw consent at any time, where consent is what we rely on
To exercise any of these, email theo@monobrowholidays.com. We will respond within one month. There is no charge unless a request is clearly unfounded or excessive.
Where we received your information from a travel agent rather than from you directly, you have these same rights over it, including the right to be told that the agent was our source. Section 3 explains how that works.
You also have the right to complain to the Hellenic Data Protection Authority, Kifissias Avenue 1-3, 115 23 Athens, telephone +30 210 6475600, www.dpa.gr. We would appreciate the chance to put things right first.
11. Children
Our services are intended for adults. We do not knowingly collect information directly from children, other than the details an adult provides about their party when booking a family trip. If you believe a child has given us information directly, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised, and any material change will be reflected here.
13. Contact us
Questions about this policy, or about the information we hold on you, are welcome. Email theo@monobrowholidays.com or message us on WhatsApp, and Theo or Thanasis will come back to you.