Privacy Policy

    Effective Date: 30 June 2026
    Last Updated: 30 June 2026


    1. Introduction and Identity of the Data Controller

    Welcome to Vivid Greece (“we”, “us”, “our”), a travel blog dedicated to exploring the beauty of Greece. This Privacy Policy explains what personal data we collect from visitors and users of https://vividgreece.com (the “Website”), how we use it, how long we keep it, and what rights you have over it.

    This Privacy Policy applies to all visitors, subscribers, and users who interact with our Website. By using the Website, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue using the Website.

    We are committed to protecting your personal data in accordance with:

    • Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)
    • Greek Law 4624/2019 (national implementation of GDPR)
    • ePrivacy Directive (2002/58/EC) as implemented in Greek law
    • California Consumer Privacy Act (CCPA) — for California residents (see Section 13)

    2. What Personal Data We Collect

    2.1 Data You Provide Directly

    Comments: When you leave a comment on a blog post, we collect your name, email address, website URL (optional), and your IP address. Your name and comment are displayed publicly. Your email address is never published.

    Contact Form: When you contact us via our contact form, we collect your name, email address, and the content of your message. This data is used solely to respond to your inquiry.

    Newsletter / Email Subscription: If you subscribe to our newsletter, we collect your email address. We use this exclusively to send you travel updates, new articles, and occasional promotional content. You may unsubscribe at any time using the link included in every email.

    2.2 Data Collected Automatically

    Log Files: Like all websites, our server automatically records standard log data each time you visit, including your IP address, browser type and version, operating system, referring/exit URLs, pages visited, and the date and time of your visit. This data is used for security, troubleshooting, and aggregated statistical analysis. It is not used to personally identify individual visitors.

    Cookies and Tracking Technologies: We use cookies and similar technologies (pixels, local storage) as described in detail in Section 5 below.

    Analytics Data: We use Google Analytics to understand how visitors interact with our Website. Google Analytics collects information such as pages visited, time spent on pages, and general geographic location (city level). We have enabled IP anonymization; your full IP address is never stored by Google Analytics.

    2.3 Data We Do NOT Collect

    We do not collect:
    – Payment card data or financial information
    – Government-issued identification numbers
    – Sensitive personal data (health, religion, political opinions, etc.)
    – Data from children under the age of 16 (see Section 11)


    3. Legal Bases for Processing (GDPR Article 6)

    We only process your personal data where we have a valid legal basis. The following table sets out the purposes for which we process personal data and the corresponding legal basis under GDPR:

    PurposeLegal BasisGDPR Article
    Operating and maintaining the WebsiteLegitimate interestsArt. 6(1)(f)
    Responding to comments and contact messagesLegitimate interestsArt. 6(1)(f)
    Sending newsletters and email updatesConsentArt. 6(1)(a)
    Analytics and website performance measurementLegitimate interests (anonymized)Art. 6(1)(f)
    Displaying advertising (Google AdSense)ConsentArt. 6(1)(a)
    Spam detection and site securityLegitimate interestsArt. 6(1)(f)
    Compliance with legal obligationsLegal obligationArt. 6(1)(c)
    Affiliate link tracking (third-party)Legitimate interestsArt. 6(1)(f)

    Where we rely on legitimate interests, we have assessed that our interests are not overridden by your fundamental rights and freedoms. You have the right to object to processing based on legitimate interests at any time (see Section 9).

    Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing that took place prior to withdrawal.


    4. How We Use Your Data

    We use the personal data we collect for the following specific purposes:

    • To deliver and improve the Website: Including debugging, performance optimization, security monitoring, and fraud prevention.
    • To publish and moderate comments: Comments you post are visible to other visitors. We moderate comments to prevent spam and abuse.
    • To respond to your messages: If you contact us, we use your contact details to reply.
    • To send newsletters: If you subscribed, we send periodic emails with travel content. We never share your email with third parties for marketing purposes.
    • To serve advertising: We participate in the Google AdSense program. Google may use cookies to show you interest-based ads. We do not pass personal data directly to Google AdSense beyond what Google collects via their own cookies (with your consent).
    • To track affiliate referrals: Some links on our Website are affiliate links (e.g., booking.com, GetYourGuide). If you click through and make a purchase, we may earn a commission. We do not receive personally identifiable data from affiliate partners unless you directly interact with their services.
    • To comply with legal obligations: Including responding to valid legal requests from competent authorities.

    We do not use your personal data for automated decision-making, profiling, or any purpose incompatible with the purposes stated above.


    5. Cookies and Tracking Technologies

    5.1 What Are Cookies

    Cookies are small text files stored on your device when you visit a website. They allow the website to remember your preferences and analyze usage patterns. Cookies may be “session” cookies (deleted when you close your browser) or “persistent” cookies (stored for a defined period).

    5.2 Categories of Cookies We Use

    Strictly Necessary Cookies — Required for the Website to function. Cannot be disabled without affecting core functionality. No consent required.

    Analytics Cookies — Used to understand how visitors interact with our Website. We use Google Analytics with IP anonymization enabled.

    Advertising Cookies — Used by Google AdSense to display relevant advertisements. These may involve cross-site tracking.

    Functional Cookies — Enhance usability by remembering your preferences (e.g., name/email for future comments).

    5.3 Cookie Reference Table

    Cookie NameProviderCategoryDurationPurpose
    cookieyes-consentCookieYes / usNecessary1 yearStores your cookie consent preferences
    wordpress_logged_in_*WordPressNecessarySessionAdmin authentication (not set for regular visitors)
    comment_author_*WordPressFunctional1 yearRemembers name/email for future comments
    _gaGoogle AnalyticsAnalytics2 yearsDistinguishes users (anonymized)
    _gidGoogle AnalyticsAnalytics24 hoursDistinguishes users (anonymized)
    _gatGoogle AnalyticsAnalytics1 minuteThrottles request rate
    IDEGoogle AdSenseAdvertising~1 yearUsed to target and measure ad effectiveness
    ANIDGoogleAdvertising~1 yearAd personalization (requires consent)
    test_cookieGoogleNecessarySessionChecks if browser accepts cookies

    5.4 Managing Your Cookie Preferences

    You can change or withdraw your cookie consent at any time via the Cookie Settings link in the footer of this Website. You can also configure your browser to reject or delete cookies:

    Note that disabling certain cookies may impair the functionality of the Website.

    5.5 Google Analytics Opt-Out

    You may opt out of Google Analytics tracking across all websites by installing the Google Analytics Opt-out Browser Add-on.


    6. Affiliate Links and Third-Party Services

    Vivid Greece participates in affiliate marketing programs. This means some links to external services (e.g., hotels, car rentals, tours) are affiliate links. If you click such a link and make a purchase or booking, we may receive a commission at no extra cost to you. Affiliate links are disclosed where applicable.

    Third-party services we currently use include:

    ServicePurposePrivacy Policy
    Google AnalyticsAnalyticsgoogle.com/policies/privacy
    Google AdSenseAdvertisinggoogle.com/policies/privacy
    AkismetSpam filteringakismet.com/privacy
    WordPress.com / AutomatticPlatform infrastructureautomattic.com/privacy
    Booking.com (affiliate)Hotel referralsbooking.com/content/privacy

    Each of these providers has its own privacy policy and acts as either a data processor (under a Data Processing Agreement with us) or an independent data controller. We encourage you to review their respective policies.


    7. Data Sharing and Disclosure

    We do not sell, rent, trade, or otherwise disclose your personal data to third parties for their own commercial purposes.

    We may share your data only in the following circumstances:

    • Service Providers: We share data with trusted third-party providers (listed in Section 6) who process it on our behalf under Data Processing Agreements that comply with GDPR Article 28.
    • Legal Requirements: We may disclose your data if required by law, court order, or competent governmental authority (e.g., the Greek Cyber Crimes Unit, a court subpoena).
    • Protection of Rights: We may disclose data when necessary to protect the rights, property, or safety of Vivid Greece, our users, or the public.
    • Business Transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections.

    8. International Data Transfers

    Some of our third-party providers (e.g., Google Analytics, Google AdSense) are based in the United States. When we transfer your personal data outside the European Economic Area (EEA), we ensure that appropriate safeguards are in place, specifically:

    • Standard Contractual Clauses (SCCs): Adopted by the European Commission, binding our processors to GDPR-equivalent standards.
    • Adequacy Decisions: Where the European Commission has determined that a third country provides adequate protection.

    For more information about Google’s data transfers and safeguards, see Google’s Privacy Policy.


    9. Your Rights Under GDPR

    As a data subject under GDPR, you have the following rights. These rights apply to data we hold about you in our capacity as data controller:

    RightWhat It MeansHow to Exercise
    Right of Access (Art. 15)Obtain a copy of the personal data we hold about you, along with information about how we process it.Email us at info@vividgreece.com
    Right to Rectification (Art. 16)Request correction of inaccurate or incomplete personal data.Email us at info@vividgreece.com
    Right to Erasure (Art. 17)Request deletion of your personal data where there is no compelling reason for us to continue processing it (“right to be forgotten”).Email us at info@vividgreece.com
    Right to Restriction (Art. 18)Request that we restrict processing of your data under certain conditions (e.g., while accuracy is contested).Email us at info@vividgreece.com
    Right to Data Portability (Art. 20)Receive your data in a structured, machine-readable format and/or have it transmitted to another controller.Email us at info@vividgreece.com
    Right to Object (Art. 21)Object to processing based on legitimate interests or for direct marketing purposes. Processing will cease unless we demonstrate compelling legitimate grounds.Email us at info@vividgreece.com
    Right to Withdraw Consent (Art. 7(3))Withdraw consent at any time for processing based on consent (e.g., newsletter, non-essential cookies). Withdrawal does not affect prior lawful processing.Unsubscribe link in emails / Cookie Settings
    Right Not to Be Subject to Automated Decisions (Art. 22)Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.We do not engage in such processing.

    Response Time: We will respond to all requests within one calendar month (30 days). In complex cases, we may extend this by a further two months, notifying you within the first month.

    Verification: To protect your data, we may need to verify your identity before fulfilling a request.

    Complaints: If you believe we have not handled your data lawfully, you have the right to lodge a complaint with the supervisory authority:

    Hellenic Data Protection Authority (HDPA)
    Kifisias 1–3, 115 23 Athens, Greece
    Phone: +30 210 6475 600
    Website: www.dpa.gr
    Email: contact@dpa.gr

    We would, however, appreciate the opportunity to address your concerns directly before you approach the HDPA. Please contact us first at info@vividgreece.com.


    10. Data Retention

    We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law:

    Data TypeRetention PeriodReason
    Comments (name, content)Indefinitely (public record) or until deletion requestedEditorial record
    Comment author emailIndefinitely or until deletion requestedSpam prevention, identity verification
    Contact form messages12 months after last correspondenceResponse and follow-up
    Newsletter email addressesUntil unsubscription + 30 daysConfirmation of removal
    Server log files (IP, access logs)30 days (rolling)Security and debugging
    Google Analytics data26 months (GA default, anonymized)Traffic analysis
    Cookie consent records1 yearProof of consent (GDPR accountability)

    At the end of the retention period, data is securely deleted or anonymized.


    11. Children’s Privacy

    The Website is not directed to individuals under the age of 16 years. We do not knowingly collect personal data from children. If you believe that a child under 16 has provided us with personal information without appropriate parental consent, please contact us immediately at info@vividgreece.com and we will take prompt steps to delete such information.

    Under Greek law (Law 4624/2019, Art. 21), the age of digital consent in Greece is 15 years. We apply the higher standard of 16 to align with the majority of EU member states.


    12. Data Security

    We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

    • SSL/TLS Encryption (HTTPS): All data transmitted between your browser and our Website is encrypted using TLS 1.2 or higher.
    • Access Controls: Access to personal data is restricted to authorized personnel on a need-to-know basis.
    • Software Updates: We maintain up-to-date WordPress core, plugins, and themes to patch known security vulnerabilities.
    • Two-Factor Authentication (2FA): Enabled on all administrative accounts.
    • Regular Backups: Encrypted backups of Website data are performed regularly.
    • Spam Protection: We use Akismet to filter spam comments, which involves transmitting comment data to Akismet’s servers.

    Data Breach Notification: In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of the breach, as required by GDPR Article 33. Where the breach is likely to result in a high risk, we will also notify affected individuals without undue delay (GDPR Article 34).

    Please be aware that no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.


    13. California Residents — CCPA Rights

    If you are a resident of California, you have additional rights under the California Consumer Privacy Act (CCPA):

    • Right to Know: You may request information about the categories and specific pieces of personal information we collect, use, disclose, and sell.
    • Right to Delete: You may request deletion of personal information we have collected from you, subject to certain exceptions.
    • Right to Opt-Out of Sale: We do not sell personal information as defined under CCPA.
    • Right to Non-Discrimination: You will not receive discriminatory treatment for exercising your CCPA rights.

    To exercise your CCPA rights, contact us at info@vividgreece.com with the subject line “CCPA Request”.


    14. Third-Party Links

    Our Website contains links to external websites (e.g., hotels, local tour operators, transport providers, travel booking platforms). We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policies of every external website you visit before providing any personal data.

    Affiliate links and booking partnerships are disclosed wherever applicable.


    15. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make changes:

    • The “Last Updated” date at the top of this page will be revised.
    • For material changes (i.e., changes that significantly affect your rights or how we use your data), we will notify you by posting a prominent notice on the Website and/or by email to newsletter subscribers.
    • Your continued use of the Website after any changes constitutes your acceptance of the updated Policy.

    We recommend reviewing this page periodically.


    16. Contact Us

    If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

    Michalis Saridakis
    Vivid Greece
    Email: info@vividgreece.com
    Website Contact Form: vividgreece.com/contact

    We aim to respond to all data-related inquiries within 30 days.


    This Privacy Policy has been drafted in compliance with Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019, and the ePrivacy Directive (2002/58/EC). It is effective as of the date stated above.