PERSONAL DATA PROTECTION POLICY
“City Odyssey”
Privacy Policy
[ V 1.6 ]
This Personal Data Protection Policy (hereinafter the “Policy”) describes the manner in which CITY ODYSSEY O.E. collects, uses, stores, transmits and protects the personal data of the users of the application City Odyssey.
The Company recognises the importance of protecting privacy and undertakes to process personal data in accordance with Regulation (EU) 2016/679 (GDPR), Law 4624/2019 and any other applicable legislation on the protection of personal data.
The use of the Application entails the reading, understanding and acceptance of this Policy.
1.1. The controller of the personal data is CITY ODYSSEY O.E., with its registered seat at 74-76 Agiou Alexandrou Street, P.C. 17561, Palaio Faliro, Attica, with General Commercial Registry (G.E.MI.) number 186118003000, Tax Registration Number (A.F.M.) 802954550 (Tax Office: KEFODE Attikis) and electronic address info@city-odyssey.org.
1.2. For matters concerning the protection of personal data, users may contact the Company at the address info@city-odyssey.org or at any other contact detail referred to in this Policy.
2.1. This Policy applies to all users of the Application, whether they use the Application as guests (Guest Users) or through a registered account.
2.2. This Policy covers every processing of personal data carried out through the Application, the related websites and the connected services.
3.1. The Company may collect and process, depending on the functions used by the user, the following categories of data:
3.2. The extent of the data depends on whether the user uses the Application as a guest or as a registered user and on the permissions the user has chosen to grant.
4.1. For the creation and management of an account in the Application, as well as for the provision of personalised services, the Company collects and processes the personal data provided by the user upon registration or upon the subsequent updating of the user's profile.
4.2. Depending on the method of registration and the services the user chooses to use, such data may include in particular:
(a) first name and surname,
(b) username,
(c) e-mail address,
(d) profile photograph or image (avatar), where selected by the user,
(e) optional profile details, such as age or other information the user chooses to enter for the personalisation of the user experience,
(f) information regarding the type of subscription or account of the user,
(g) technical identifiers required for the management of the account, the subscription and secure access to the services of the Application.
4.3. The above data are used exclusively for:
4.4. The completion of optional details is carried out exclusively at the user's choice and does not constitute a precondition for the creation of an account, unless a specific service requires such details for its proper operation.
4.5. The Company collects and processes exclusively the data that are necessary for the achievement of the above purposes, applying the principle of data minimisation in accordance with the General Data Protection Regulation (GDPR).
5.1. The Application may provide limited access without the creation of an account.
5.2. In such a case, the Company may collect limited technical data that are necessary for the operation, security and basic statistical evaluation of the Application.
5.3. Use as a guest does not, as a rule, permit the storage of personalised preferences or usage history, unless the user specifically selects a relevant function or creates an account.
6.1. The Application uses geolocation data (Location Data) exclusively for the provision of services based on the user's geographic location, such as the display of nearby points of interest, the support of thematic routes, the activation of geofencing functions, the provision of personalised information and the improvement of the browsing experience.
6.2. The processing of location data is carried out only where the user has previously granted the relevant permission through the settings of the operating system of the user's device. The user may at any time revoke or modify this permission.
6.3. Depending on the functions used by the user, the Application may use location data during its active use (foreground location) or, where this is absolutely necessary for the operation of specific browsing services, during an active route (background location), always in accordance with the permissions granted by the user.
6.4. The Application may use geofencing technologies exclusively for the activation of functions relating to the provision of information, notifications or other content when the user approaches specific points of interest.
6.5. Geolocation data are used exclusively for the provision of the services selected by the user and are not used for the creation of a movement history, commercial tracking or the compilation of behavioural profiles, beyond what is expressly described in this Policy.
6.6. The Company applies the principle of data minimisation and uses only the strictly necessary location data for the provision of the corresponding functions of the Application.
7.1. For the smooth operation of the browsing and geolocation services, the Application may temporarily store on the user's device limited data relating to the current usage session and the progress of the browsing.
7.2. This temporary storage is carried out exclusively on the user's device and is used for:
7.3. Such data are neither transmitted to nor stored on the Company's servers, unless this is required for a specific function selected by the user and expressly described in this Policy.
7.4. The temporary storage is retained only for as long as is technically necessary for the provision of the service and is automatically deleted upon completion of the browsing or after a reasonable period of inactivity of the Application, in accordance with the applicable technical implementation.
7.5. The temporary local storage neither creates nor maintains a movement history or a permanent record of the user's locations and is not used to monitor the user's behaviour.
7.6. Should functions requiring different or more extensive processing of location data be added in the future, the Company will inform users in advance by updating this Policy and, where required by applicable law, will request their relevant consent.
8.1. During the use of the Application, the Company may collect technical and functional data relating to the manner of use of its services, exclusively for the purposes of operation, maintenance, security and continuous improvement of the Application.
8.2. The usage data may include, indicatively:
(a) information regarding the functions of the Application that are used,
(b) duration and frequency of use of the Application,
(c) details regarding the selected routes, content categories or points of interest displayed,
(d) technical information regarding the device, such as the operating system, the version of the application, the device language and other technical characteristics necessary for the proper operation of the Application,
(e) information regarding the performance of the Application and any technical errors affecting its operation.
8.3. Such data are used exclusively for:
8.4. Usage data are not used for the taking of solely automated decisions producing legal effects or significantly affecting the user, nor for the compilation of commercial behaviour profiles, unless the user is informed in advance and there is an appropriate lawful basis for the processing in accordance with the GDPR.
8.5. Where feasible, usage data are subjected to pseudonymisation or aggregate processing, so as to limit the possibility of directly identifying users.
9.1. The Company may use services for the analysis of the use of the Application (Analytics), services for the recording and management of technical errors (Crash Reporting), as well as other related technologies, for the exclusive purpose of ensuring the proper operation, security and continuous improvement of the Application.
9.2. At the time of issue of this Policy, some of the above services may not yet have been activated or may be at a stage of trial or gradual implementation. Their activation will take place only following an assessment of their necessity and in accordance with the requirements of the applicable legislation on the protection of personal data.
9.3. In the event of activation of these services, the Company may collect aggregated or pseudonymised statistical data regarding:
9.4. These services are used exclusively for technical, operational and statistical purposes and are not intended to monitor the personal activity of users or to create commercial behaviour profiles.
9.5. In the event that the activation of a specific service requires the user's consent in accordance with applicable law, the relevant processing is carried out only after prior information and, where required, the obtaining of the user's consent.
9.6. The Company may replace or select different providers of Analytics services or related technologies, where this is necessary for the operation and development of the Application, always complying with the requirements of the GDPR and updating this Policy where required.
10.1. The Application may send notifications regarding content updates, cultural or tourist information, technical announcements, security matters or operational updates.
10.2. The user may manage notification preferences through the user's device or the settings of the Application.
10.3. The sending of optional notifications is based on the user's choices, whereas functional or necessary notifications may be sent within the framework of the operation of the service.
11.1. The Company processes personal data exclusively for lawful, clear and specified purposes.
11.2. The main purposes include the creation and management of accounts, the provision of the functions of the Application, the personalised browsing experience, the storage of preferences, the operation of geolocation services, the management of subscriptions and payments, technical support, the improvement of services, the security of information systems and compliance with legal obligations.
11.3. The Company does not use personal data for purposes incompatible with those described in this Policy.
12.1. The processing of personal data is carried out, as the case may be, on the basis of one or more of the legal bases of the GDPR: the consent of the user, the performance of a contract or the taking of measures prior to the conclusion of a contract, compliance with a legal obligation, the protection of vital interests where applicable, and the legitimate interest of the Company.
12.2. Consent is used in particular for optional functions, such as access to precise location, the storage of location history and optional notifications, where required.
12.3. Where the processing is based on consent, the user may withdraw it at any time in accordance with Article 18.
13.1. The Company may transmit personal data to third-party partners acting on its behalf as processors or, where provided for by applicable law, as independent controllers, exclusively to the extent that this is necessary for the provision, support and secure operation of the Application.
13.2. The categories of recipients may include in particular:
(a) providers of identity management and user authentication services,
(b) providers of cloud infrastructure services,
(c) providers of data hosting and file storage services,
(d) providers of mapping, geographic data and points-of-interest services,
(e) providers of payment and subscription management services,
(f) providers of technical support, information systems security and maintenance of the Application services,
(g) providers of statistical analysis and technical error management services.
13.3. At the time of issue of this Policy, the Company may use, depending on the functions activated in the Application, the services of providers such as:
13.4. The selection of the above providers is made on the basis of their reliability, the security of their services and their compliance with the General Data Protection Regulation (GDPR) or another equivalent regulatory framework for the protection of personal data.
13.5. The Company takes every reasonable technical, organisational and contractual measure so that its partners process personal data exclusively in accordance with its instructions, ensure an appropriate level of security and comply with the obligations of confidentiality and personal data protection provided for by applicable law.
13.6. The Company does not sell, rent or assign users' personal data to third parties for direct marketing purposes.
14.1. Certain service providers used by the Application may be located outside the European Economic Area (EEA).
14.2. In such cases, the Company takes appropriate measures to ensure an adequate level of protection in accordance with the GDPR.
14.3. Such measures may include adequacy decisions of the European Commission, Standard Contractual Clauses (Standard Contractual Clauses) or other lawful mechanisms provided for by the GDPR.
15.1. The Company retains users' personal data only for as long as is necessary to fulfil the processing purposes described in this Policy, to comply with the obligations imposed by applicable law or for the establishment, exercise or defence of legal claims.
15.2. Data relating to the user's account are retained for as long as the account remains active. Following the deletion of the account, the data are deleted or anonymised, unless their further retention is required by a provision of law or for the protection of the Company's legitimate interests.
15.3. Data relating to subscriptions, electronic payments, tax or accounting obligations are retained for the period provided for by the applicable tax, accounting and other applicable legislation.
15.4. Temporary data stored exclusively on the user's device to support the browsing and geolocation functions are retained only for as long as is technically necessary for the operation of the Application and are automatically deleted in accordance with the technical implementation applied on each occasion.
15.5. Data that may be held by third-party service providers on behalf of the Company are retained in accordance with the respective retention policies of those providers, their contractual obligations and the requirements of the applicable legislation on the protection of personal data.
15.6. Upon expiry of the above periods, the personal data are deleted, anonymised or destroyed in a secure manner, unless their further retention is required by applicable law.
16.1. The Company applies appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration, unlawful or accidental destruction, disclosure or any other form of unauthorised processing.
16.2. These measures are designed taking into account the nature of the data, the purpose and the risks of the processing, the state of the art and generally accepted information systems security practices and may include, as the case may be, encryption, access control, secure user authentication, event logging mechanisms, the creation of backups, monitoring of the security of the information systems and procedures for recovery from security incidents.
16.3. The Company periodically reviews and assesses the effectiveness of the technical and organisational security measures it applies and takes every reasonable measure for the continuous upgrading of the level of protection of personal data.
16.4. In the event of a personal data breach incident, the Company acts in accordance with the provisions of the General Data Protection Regulation (GDPR) and applicable law, taking every necessary measure to limit the consequences of the incident, to restore the security of the information systems and, where required, to notify the competent supervisory authority and the data subjects within the prescribed legal deadlines.
16.5. Notwithstanding the application of a high level of security measures, no method of data transmission over the internet or of electronic storage can be considered absolutely secure. For this reason, the Company cannot guarantee the absolute security of the information, but makes every reasonable effort for their continuous protection.
17.1. Every natural person whose personal data are subject to processing by the Company is entitled to exercise the rights provided for by the General Data Protection Regulation (GDPR) and the applicable legislation on the protection of personal data.
17.2. The user may, as the case may be and under the conditions provided for by applicable law, exercise the rights of access, rectification, erasure, restriction of processing, data portability, objection to processing, as well as the right to withdraw consent where the processing is based thereon, without prejudice to the lawfulness of the processing carried out prior to the withdrawal.
17.3. For the exercise of the above rights, the user may contact the Company using the contact details referred to in this Policy. The Company may request the strictly necessary information for the verification of the identity of the applicant, where this is required for the protection of personal data.
17.4. The Company examines every request for the exercise of rights and responds without undue delay and, in any event, within the deadlines provided for by the GDPR, unless there are lawful grounds for extension or restriction in accordance with applicable law.
17.5. The exercise of the rights provided for in this Policy is without prejudice to the user's right to lodge a complaint with the competent supervisory authority for the protection of personal data or to exercise any other right afforded to the user by applicable law.
18.1. Where the processing of personal data is based on the user's consent, the user may withdraw such consent at any time.
18.2. The withdrawal of consent does not affect the lawfulness of the processing carried out prior to the withdrawal.
18.3. The withdrawal may be carried out through the settings of the Application, through the settings of the device or through communication with the Company.
19.1. The Company reserves the right to amend this Policy at any time, in particular for reasons of compliance with legislation, changes to the functions of the Application or changes of technical providers.
19.2. The version in force from time to time is published through the Application or the official website of the Company. In the event of material changes, the Company may inform users in an appropriate manner.
20.1. For any matter concerning the processing of personal data, the exercise of rights or this Policy, users may contact the Company at the contact details referred to in Article 1 and in particular at the address info@city-odyssey.org.
20.2. If the user considers that the processing of the user's personal data infringes applicable law, the user is entitled to lodge a complaint with the competent supervisory authority for data protection.
20.3. For Greece, the competent supervisory authority is the Hellenic Data Protection Authority. [ E-mail: contact@dpa.gr – Tel: 210-64.75.600 – 1-3 Kifisias Avenue]
LAST UPDATE: 09/07/2026
***************
