Privacy policy
Contents
CHAPTER I
Data controller
- Legal name
- FantaStic
- Registered seat
- Hello Str, Greece
- VAT number
- 000000000
- Tax office
- None
- test@test.gr
CHAPTER II
Privacy policy
Data controller
The controller of your personal data is FantaStic — — Hello Str, Greece. VAT number (ΑΦΜ) 000000000, company registry (ΓΕΜΗ) .
For anything concerning your data: test@test.gr or .
What we process
Buyers
- Name and email address.
- For invoicing: company name, VAT number (ΑΦΜ), tax office (ΔΟΥ) and billing address.
- Order details: the event, the table or seats, the amount, the order reference, the payment method and its status.
Hosts and guests
- The guest's name and email address, their seat at the table and their reply to the invitation.
- Optionally, and only where the guest gives them: dietary restrictions and accessibility needs.
- The time of entry to the evening, from the QR code scanned at the door.
Technical data
- IP address and basic request details, for abuse protection and security logs.
We do not process card details: they are entered only on the payment processor's page.
Purposes and legal bases
- Performance of the contract (GDPR Art. 6(1)(b)): the reservation, payment, confirmations, invitations, tickets, admission to the evening and table seating.
- Explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)): dietary information and accessibility needs. Giving them is optional and consent can be withdrawn at any time by writing to test@test.gr, without affecting the lawfulness of processing carried out beforehand.
- Legitimate interests (GDPR Art. 6(1)(f)): security of the service, rate limiting, and audit records of staff actions.
- Legal obligation (GDPR Art. 6(1)(c)): issuing and keeping tax documents.
Recipients
- The venue and the caterer, for seating and catering.
- Door staff, for ticket checks.
- The payment service provider, for card payments.
- The email delivery provider, the hosting provider and the database provider, acting as processors on our behalf under contract.
- Public authorities, where the law requires it.
We do not sell or disclose personal data for advertising purposes.
Transfers outside the EU
Where a provider operates outside the European Economic Area, data is transferred only with the appropriate safeguards required by the GDPR — the European Commission's standard contractual clauses, or an adequacy decision.
Retention
- Orders and tax documents: for as long as tax law requires.
- Guest data, dietary information and accessibility needs: deleted or anonymised after the evening is settled.
- Temporary table holds and expired links: deleted.
Your rights
You have the right of access, rectification, erasure, restriction of processing, portability, objection, and withdrawal of consent. Write to test@test.gr and we will reply within one month at the latest.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (ΑΠΔΠΧ) — www.dpa.gr.
Guests entered by a host
If your details were entered by the host of a table, you are informed by the invitation email (GDPR Art. 14), which states who is inviting you and to which event. You may decline the invitation or ask for your details to be deleted at test@test.gr.
Automated decisions
No automated decisions with legal or similarly significant effects are taken, and no profiling is carried out.
Cookies and local storage
- We use no analytics or advertising cookies.
- One login cookie is used only for the organiser's staff signing in to the administration area.
- Your browser's session storage holds the identifier of your temporary table hold, for as long as the selection and checkout last.
- Your card details are entered only on the payment processor's page, which applies its own privacy policy.
Security
Access to the data is limited to the committee members who need it for their work, through roles and permissions, and their actions are logged.
This English text is a translation provided for convenience; the Greek version is the binding one.
Version 1.0 · In force from 21 September 2026
