1. Information we collect
We collect the information you provide when requesting or booking a transfer, including your name, email address, telephone number, journey date and times, pickup and destination details, flight or ferry information, passenger and luggage counts, special requests, booking reference, and payment status. Stripe processes complete card details; we retain payment identifiers and status rather than complete card numbers. Cloudflare Turnstile processes limited device, network, and interaction information to distinguish legitimate visitors from automated abuse.
2. Why we use it
Khimaira Studios Ltd processes booking information to arrange the requested transfer and take payment. We may also process records to meet tax, accounting, and other legal obligations; to prevent fraud and protect our services; and to handle enquiries, complaints, or legal claims where those are our legitimate interests.
3. Who receives it
Information required to perform your journey is shared with JTR TRANSFER SERVICES O.E., Perissa, Santorini, Greece, as the transport provider, and with its assigned drivers. Information is also shared where necessary with Stripe for payment processing, Cloudflare for bot and abuse prevention, our website and database hosting providers, our transactional email provider, and professional advisers or public authorities where legally required. Recipients act under their own legal obligations or under data-processing arrangements, as applicable.
4. International transfers
Some service providers may process information outside Greece or the European Economic Area. Where required, we rely on an adequacy decision or appropriate safeguards such as the European Commission’s standard contractual clauses. You may contact us for more information about safeguards relevant to your booking.
5. Retention
Booking, payment, and communication records are kept for the period needed to deliver the service, meet Greek tax and accounting requirements, resolve disputes, and establish or defend legal claims. Failed login and technical security records are kept only as long as reasonably necessary for service protection. Records are deleted or anonymised when those purposes and applicable legal periods end.
6. Your rights
Subject to applicable law, you may request access to, correction of, deletion of, or restriction of your personal information; object to processing based on legitimate interests; and request applicable data portability. Where processing relies on consent, you may withdraw it without affecting earlier lawful processing. We may need to verify your identity before responding.
7. Cookies and local storage
The public booking site does not use advertising or analytics cookies. Cloudflare Turnstile runs on public forms to prevent automated abuse and may store strictly necessary security information. A secure session cookie is used only when authorised staff sign in to the operations dashboard. The service worker may cache public website assets on your device to improve reliability; it does not store booking form submissions.
8. Security and complaints
We use access controls, encrypted transport, restricted database credentials, signed staff sessions, and payment-provider controls to protect information. No internet service is risk-free. Contact us first if you have a concern. You may also complain to the UK Information Commissioner’s Office, the Hellenic Data Protection Authority, or another competent supervisory authority.
9. Changes
We may update this notice when our services, providers, or legal obligations change. The effective date below identifies the current published version.
