Legal & Policies
GRBNB.com โ Greece Direct Rentals
GR B&B Network / GRBNB.com ("we", "us", "our") is a direct property rental network and booking facilitation platform connecting guests with independent property owners and hosts across Greece.
We act as a data controller in respect of the personal information you provide when using our website or services.
Contact details for privacy matters:
Email: info@grbnb.com
Website: www.grbnb.com
We collect the following categories of personal data:
Data you provide directly
- Full name
- Email address
- Telephone number
- Travel dates, destination, and guest details
- Special requests or preferences
- Any messages or communications you send to us or to property owners
Data collected automatically
- IP address and approximate geographic location
- Browser type and version
- Device type and operating system
- Pages visited, time spent, and referring URLs
- Push notification preferences (if you opt in)
We do not collect sensitive personal data (such as health, financial, or biometric information).
Under the GDPR, we process your personal data on the following legal bases:
- Contract performance โ processing is necessary to respond to your booking or search enquiry and connect you with property owners.
- Legitimate interests โ to improve our services, ensure website security, and communicate with you about your enquiry.
- Consent โ for optional communications such as push notifications. You may withdraw consent at any time.
- Legal obligation โ where we are required to process or retain data under applicable law.
- To receive, process, and forward your accommodation search or booking request to relevant property owners
- To send you an automated confirmation of your search submission
- To send you property options and direct booking links matching your request
- To respond to your questions, enquiries, and follow-up communications
- To improve the performance, usability, and content of our website
- To deliver push notifications if you have opted in
- To comply with legal and regulatory obligations
We will never use your personal data for unsolicited marketing without your explicit consent.
We share your personal data only in the following circumstances:
- Property owners and hosts โ your name, contact details, and travel requirements are shared with the relevant property owners in order to process your request and facilitate direct booking.
- Email and notification service providers โ we use OneSignal to deliver transactional emails and optional push notifications. OneSignal processes data on our behalf as a data processor under a data processing agreement.
- Legal authorities โ we may disclose your data if required to do so by law, court order, or regulatory authority.
We do not sell, rent, or trade your personal data with any third party for their own commercial purposes.
Our service providers (such as OneSignal) may process data outside the European Economic Area (EEA). Where this occurs, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your personal data.
We retain your personal data only for as long as necessary for the purpose for which it was collected, or as required by applicable law:
- Search and booking enquiry data: retained for up to 2 years from the date of submission
- Communications: retained for up to 2 years
- Technical logs and analytics: retained for up to 12 months
- Push notification preferences: retained until you withdraw consent
After the applicable retention period, your data is securely deleted or anonymised.
If you are located in the European Economic Area (EEA), you have the following rights in relation to your personal data:
- Right of access โ you may request a copy of the personal data we hold about you.
- Right to rectification โ you may request correction of inaccurate or incomplete data.
- Right to erasure โ you may request that we delete your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction โ you may request that we restrict processing of your data in certain circumstances.
- Right to data portability โ you may request your data in a structured, machine-readable format.
- Right to object โ you may object to processing based on legitimate interests.
- Right to withdraw consent โ where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint โ you have the right to complain to the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.
To exercise any of these rights, please contact us at info@grbnb.com. We will respond within 30 days.
We implement appropriate technical and organisational security measures to protect your personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures include:
- Encrypted data transmission (HTTPS/TLS)
- Access controls limiting who can view personal data
- Use of reputable, GDPR-compliant third-party processors
No method of transmission over the internet is 100% secure. If you believe your data has been compromised, please contact us immediately.
Our services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the updated version on this page with a revised effective date. Where changes are significant, we will take reasonable steps to notify you.
Last updated: June 2026