Follow us

Privacy Policy

Privacy Policy
Hermes Tourist Agency E.E.
Last updated: 09/07/2026

  1. Introduction
    Hermes Tourist Agency E.E. (“Hermes,” “we,” “us,” or “our”) provides private transfer services in Mykonos, Greece. We take the protection of your personal data seriously. This Privacy Policy explains what personal data we collect about you, why we collect it, how we use it, and what rights you have under applicable data protection law — including the EU General Data Protection Regulation (GDPR) and Greek Law 4624/2019.
    This policy applies to our website (https://hermestouristagency.com), our communications with you on WhatsApp, by email, by phone, and in person, and to bookings forwarded to us by third-party platforms or partners.
  2. Who We Are
    This Privacy Policy is issued by:
    Hermes Tourist Agency E.E.
    A Limited Partnership organised under the laws of Greece (Ετερόρρυθμη Εταιρεία)
    Registered address: K2 (Axioti M.) 0, 84600 Mykonos, Greece
    Operational branch: Argyraina, 84600 Mykonos, Greece
    GEMI registration number: 153895938000
    Tax identification number (AFM): 801301539
    Tax office (DOY): ΔΟΥ Μυκόνου
    Authorised representative: Dimitrios Angelis (General Partner and Manager)
    Business email: info@hermestouristagency.com
    Phone: +30 6951343434
    Privacy contact: info@hermestouristagency.com
    We are the data controller for the personal data described in this policy. We have not appointed a Data Protection Officer, as we do not meet the thresholds under GDPR Article 37.
  3. How We Collect Your Personal Data
    4.1 Data you provide to us directly

    You may provide us with personal data when you:
    • Submit our website inquiry form
    • Send us a WhatsApp message, email, or phone us
    • Visit our office in person at Mykonos Town
    • Are introduced to us by a hotel concierge, villa manager, travel agency, or tour operator who facilitates your contact with us while you are present
    4.2 Data we receive from third parties
    We also receive your personal data from third parties who arrange or refer transfers on your behalf, including:
    • AtoB Transfer (atobtransfer.com)
    • GetTransfer (gettransfer.com)
    • Hotels, villa managers, and yacht companies that arrange transfers for their guests
    • Travel agencies and tour operators that arrange transfers for their clients
    Where we receive your data from one of these sources, we use it only to deliver the transfer that has been booked. The information we receive is typically your name, contact details, pickup and drop-off locations, date and time, and any special requirements. We do not receive your payment card information from these sources.
  4. Why We Use Your Personal Data and the Legal Basis
    We use your personal data for the following purposes.
    5.1 To provide and deliver your transfer
    We use your booking and contact details to arrange and deliver the transfer you have requested, to communicate with you before, during, and after the transfer, and to share the relevant booking information with the assigned driver. The legal basis is performance of our contract with you (GDPR Article 6(1)(b)).
    5.2 To meet our legal obligations
    We retain booking records, invoices, and related accounting documents to comply with Greek tax and accounting laws. The legal basis is compliance with our legal obligations (GDPR Article 6(1)(c)).
    5.3 To handle disputes and protect our legitimate interests
    We retain records of our communications with you (including WhatsApp messages and emails) so that we can answer queries, resolve disputes, handle insurance or liability claims, and protect our business. The legal basis is our legitimate interest in being able to respond to issues and defend against potential claims (GDPR Article 6(1)(f)).
    5.4 To use software tools that support our operations
    We may use third-party software platforms to assist us in managing customer communications. This may include WhatsApp Business automation platforms, which help us route, organise, or respond to messages using predefined templates, and AI-powered tools, which may be used to draft suggested replies that our staff review before sending. Where any such tool processes your message content, the provider acts strictly on our written instructions under a data processing agreement, does not use your data to train AI models, and is bound by EU Standard Contractual Clauses or equivalent safeguards. A member of our team reviews and sends every outgoing message.
    We may also use automated tools, including AI-based or rule-based parsing software, to read booking confirmations we receive from platforms such as AtoB Transfer and GetTransfer, and to enter the relevant details into our internal scheduling system.
    The legal basis for these activities is performance of our contract with you (GDPR Article 6(1)(b)) and our legitimate interest in operating our business efficiently (GDPR Article 6(1)(f)).
    5.5 What we do not do
    To be clear:
    • We do not assign drivers automatically. Driver assignment is performed manually by our dispatch team.
    • We do not send you fully automated messages. Every message you receive from us on WhatsApp, email, or by phone is reviewed and sent by a member of our team.
    • We do not send marketing or promotional messages, and we do not use WhatsApp for broadcasts. All communications relate to a specific transfer you have booked or inquired about.
    If we introduce any of these in the future, we will update this policy and inform you before doing so.
  5. What Personal Data We Collect
    We collect the following categories of personal data.
    3.1 Identity and contact data
    • Your name
    • Your email address
    • Your phone number, including your WhatsApp number where you provide it
    3.2 Booking and trip data
    • Pickup and drop-off locations
    • Date and time of your transfer
    • Number of passengers
    • Booking reference and source platform
    • Flight or ferry number, where applicable
    • Hotel, villa, or yacht name and address, where you are travelling to or from one
    • Luggage details, where provided
    • Vehicle category or preferences
    • Whether you require a child seat
    3.3 Communications data
    • The content of your WhatsApp messages with us, including text, voice notes, and images you share
    • Email correspondence between you and us
    • Submissions you make through our website inquiry form
    We do not record phone calls.
    3.4 Payment information
    We accept payment through several channels. Where a third-party payment processor or booking platform handles your card data on our behalf, that third party is the controller of that information; we do not store full card numbers. We retain only transaction references and amounts for our accounting records.
    Payment may be made by:
    • Cash directly to the driver
    • Card via our in-vehicle payment terminal, processed by a third-party provider
    • An online payment link, processed by a third-party provider (such as PayPal)
    • Through the booking platform AtoB Transfer or GetTransfer, which handles payment on our behalf
    • Through a travel agency that handles payment before forwarding the booking to us
    3.5 Location data
    During an active transfer, we use a driver location-sharing application installed on the assigned driver’s phone (currently Life360) to coordinate dispatch and to inform you of estimated arrival times. We do not track customer phones, and we do not use dashcams or in-vehicle cameras.
    3.6 Children
    Our service is not directed at children under the age of 15 (the digital consent age in Greece under Law 4624/2019). We do not knowingly collect personal data directly from children. Where a child travels as a passenger in a transfer booked by an adult, we process only the information that the booking adult provides (such as the need for a child seat or the number of children travelling). If you become aware that a child has provided us with personal data without parental consent, please contact us and we will delete it promptly.
  6. Who We Share Your Personal Data With
    We share your personal data with the following categories of recipients, only to the extent necessary for the purposes described above.
    • The driver assigned to your transfer, who receives the relevant booking details (such as your name, pickup location, and contact phone number) — drivers do not have access to the full chat history of our conversations with you.
    • Booking platforms that forward bookings to us, including AtoB Transfer, GetTransfer, hotels, villa managers, travel agencies, and tour operators, where applicable.
    • WhatsApp Business Platform, operated by Meta Platforms Ireland Ltd., where we communicate with you via WhatsApp. Meta’s own privacy policy also applies to your use of WhatsApp.
    • Cloud-based email, calendar, and scheduling software providers that we use to operate our business.
    • Our website hosting provider, currently located in the United States.
    • Third-party payment processors who handle card transactions on our behalf, including providers of in-vehicle card terminals and online payment links.
    • Driver location-sharing applications used to coordinate dispatch and inform you of estimated arrival times during an active transfer (see Section 3.5).
    • Where we use AI or automation tools (see Section 5.4), the relevant tool provider, acting strictly on our instructions under a data processing agreement.
    • Our external accountant and bookkeeping providers, for tax filing and accounting purposes.
    • Our legal advisors and insurers, where necessary in connection with claims, disputes, or legal advice.
    • Public authorities (such as the Greek tax authority, police, courts, or regulatory bodies) where required by law or in response to a valid legal request.
    We do not sell your personal data, and we do not share it with marketing or advertising partners.
  7. International Data Transfers
    Some of our service providers are located outside the European Economic Area (EEA), principally in the United States. Where this is the case, we rely on the following safeguards to protect your personal data:
    • The EU-US Data Privacy Framework, where the recipient is certified under it
    • EU Standard Contractual Clauses, where applicable
    • Adequacy decisions issued by the European Commission, where they apply
    You can request a copy of the relevant safeguards by contacting us at the privacy contact email listed in Section 2.
  8. How Long We Keep Your Personal Data
    We keep your personal data only as long as necessary for the purposes described in this policy, or as required by law. Our retention periods are:
    • Booking records, invoices, and related accounting documents — 10 years, as required by Greek tax and accounting law
    • Customer contact details (for repeat customers) — for the duration of the customer relationship plus five years, in line with Greek Civil Code limitation periods
    • WhatsApp chat history — up to 24 months after our last contact with you, unless retained for an active dispute or legal claim
    • Email correspondence — up to 24 months after our last contact with you, unless retained for an active dispute or legal claim
    • Website inquiry form submissions that do not result in a booking — up to 12 months
    • Website analytics data — in line with the retention setting of the analytics tool used
    After these periods, we delete or anonymise your personal data, except where we are required to retain it for longer by law.
  9. Your Rights
    Under GDPR, you have the following rights in relation to your personal data:
    • Right of access — to ask us what personal data we hold about you and to receive a copy of it (Article 15)
    • Right to rectification — to ask us to correct any inaccurate personal data (Article 16)
    • Right to erasure — to ask us to delete your personal data in certain circumstances (Article 17)
    • Right to restriction — to ask us to limit how we process your personal data in certain circumstances (Article 18)
    • Right to data portability — to receive your personal data in a structured, commonly used format (Article 20)
    • Right to object — to object to our processing of your personal data based on legitimate interests (Article 21)
    • Right to withdraw consent — where we rely on consent, to withdraw it at any time
    • Right not to be subject to solely automated decisions — Hermes does not make solely automated decisions with significant effects on you
    To exercise any of these rights, please contact us at the privacy email listed in Section 2, or call us at +30 6951343434. We will respond to your request within one month, as required by GDPR Article 12.
    Lodging a complaint
    If you believe we have not handled your personal data in accordance with the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority:
    Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
    Address: 1-3 Kifissias Avenue, 115 23 Athens, Greece
    Phone: +30 210 6475 600
    Email: contact@dpa.gr
    Website: www.dpa.gr
  10. WhatsApp Communications
    We communicate with our customers extensively through WhatsApp Business. The WhatsApp service is operated by Meta Platforms Ireland Ltd., whose own privacy policy also applies to your use of WhatsApp.
    How we obtain your WhatsApp number
    We may communicate with you on WhatsApp where you have:
    • Contacted us first via WhatsApp, such as through a WhatsApp link on our website
    • Voluntarily provided your WhatsApp number to us in the course of an inquiry — for example, by including it in a message via our website contact form, in an email, or in a phone call
    • Submitted a booking through AtoB Transfer, GetTransfer, or another booking platform that included your WhatsApp number
    • Had your WhatsApp number provided to us by a hotel, villa, or travel agency arranging your transfer
    What we use WhatsApp for
    We use WhatsApp Business solely for transfer-related communications, including:
    • Acknowledging inquiries and providing quotes
    • Confirming bookings and payment
    • Sharing driver details and pickup notifications
    • Communicating changes such as delays, cancellations, or vehicle changes
    • Answering your questions before, during, or after your transfer
    We do not use WhatsApp for marketing, promotional offers, broadcast messages, or unrelated services.
    Stopping WhatsApp messages
    You can stop receiving non-essential messages from us at any time by:
    • Replying directly to any of our messages and asking us to stop
    • Emailing us at the privacy contact email listed in Section 2
    • Calling us at +30 6951343434
    We will cease non-essential messaging promptly. If you have an active booking with us, we may still need to contact you with essential trip information (such as driver assignment or arrival time) until your transfer is complete.
    Who can see your WhatsApp messages
    On our side, your WhatsApp messages are visible to:
    • Authorised members of our team (such as dispatchers and customer service staff) who handle bookings and respond to inquiries
    • The driver assigned to your transfer, who receives the relevant booking details (such as pickup location, contact name, and contact phone number) — drivers do not have access to the full chat history
    • Where we use AI or automation tools to assist with replies or scheduling (see Section 5.4), the relevant tool provider acting strictly on our instructions under a data processing agreement
    We do not share your WhatsApp messages with anyone else outside the categories listed above.
  11. Security
    We take appropriate technical and organisational measures to protect your personal data, including:
    • Use of HTTPS encryption on our website
    • Restricted access to customer data, limited to authorised members of our team
    • Confidentiality expectations for staff and drivers handling customer data
    • Use of reputable third-party services (such as Google, Meta, and our payment processors) for data storage and transmission, each with their own security controls
    • Regular review of our practices as our operations grow
    No method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data using appropriate measures, we cannot guarantee its absolute security.
  12. Cookies and Website Tracking
    Our website uses cookies and similar technologies to operate and to understand how visitors use the site. Some cookies are strictly necessary for the website to function, while others (such as analytics cookies) require your consent.
    When you first visit our site, we display a cookie banner that allows you to accept or reject non-essential cookies. You can change your preferences at any time.
  13. Changes to This Privacy Policy
    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes — for example, if we introduce significant new processing activities, new categories of recipients, or new AI-assisted features — we will update the “Last updated” date at the top of this policy and, where appropriate, notify you directly (such as by email or WhatsApp) before the change takes effect.
    For non-material updates (such as clarifications, formatting improvements, or minor wording changes), we will simply update the “Last updated” date without separate notification.
    We encourage you to review this policy periodically to stay informed about how we protect your information.
  14. Language
    This Privacy Policy is published in English. If you would prefer a Greek-language version, please contact us at the privacy email listed in Section 2 and we will provide one.
  15. Contact Us
    If you have any questions about this Privacy Policy or how we handle your personal data, please contact us at:
    Hermes Tourist Agency E.E.
    K2 (Axioti M.) 0, 84600 Mykonos, Greece
    Email: info@hermestouristagency.com
    Phone: +30 6951343434

go top