PRIVACY NOTICE / STATEMENT
Update on Personal Data Processing

Introduction
We would like to assure you that for AEGEAN SPEED LINES N.E. the protection of our customers' personal data is of paramount importance. That is why we are taking appropriate steps to protect the personal data we process and to ensure that the processing of personal data is always carried out in accordance with the obligations laid down by the legal framework, both by the company itself and by third parties who process personal data on behalf of the company.

Data Controller – Data Protection Officer (DPO)
AEGEAN SPEED LINES N.E., having its registered office at 85 Vouliagmenis Avenue, 16674 Glyfada, Greece, email: This email address is being protected from spambots. You need JavaScript enabled to view it., tel: +30 210 96 90 950, website: www.aegeanspeedlines.gr, informs that, for the purposes of its business, it processes personal data of its customers in accordance with applicable national law and the European Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter referred to as the "Regulation") as it is currently in force.
For any matter concerning the processing of personal data, please contact the Data Protection Officer directly (DPO) Mr. Nick Stamoulos, email: This email address is being protected from spambots. You need JavaScript enabled to view it., telephone: +30 210 96 98 153.

What are the legal grounds for processing your personal data?
The personal data you provide to us with (such as your name, contact details, email address, telephone number, information on your travel itinerary, such as your reservation code, transaction details which you made the reservation with, such as the details of the card with which you completed the payment, as well as health information related to the issue of tickets, or the reporting of passenger accidents, as well as the transfer of patients by boat, are processed only when we have legal grounds to do so.

Legal grounds for processing your personal data are:
(a) the provision of the services you appoint us for and you wish to receive from us such as the issue of tickets and therefore the fulfillment of our contractual obligations in this context.
(b) safeguarding and protecting the legitimate interests of yours as well as ours. So, we are entitled to use closed circuit television (CCTV) and security cameras to be able to protect the security of individuals, materials, facilities, including our vessels.
(c) complying with a statutory obligation, such as returning fares, managing your claims for compensation, discounting fares for people with reduced mobility etc.
(d) the consent you provide us with under the specific conditions set out in the legal framework in order to receive updates on products, services, offers, sometimes customized to your personal preferences by AEGEAN SPEED LINES N.E. or third-party associates processing your personal data according to the each time applicable legal framework.
(e) the explicit disclosure by the data subject and the processing necessary to protect the vital interests of the data subject or other natural person in cases where it is physically or legally impossible to grant consent on such data, are legal grounds upon which we process any information involving health data. This becomes relevant when issuing tickets, reporting passenger accidents, servicing people with reduced mobility and transferring patients.

How and why we use your personal data
* For managing your travel reservations and for the provision of our services
When you travel with us, we use the information required to provide our services, such as ticketing, check-in, ticket replacement or refund, managing your bookings and your customer service individually or in groups.

* For communicating with you and managing our relationship with you
We may need to contact you by email or phone for administrative purposes, such as confirming your bookings and payments, informing you of your route, managing requests for unsolicited services, material damage and, in general, handling your complaints.

* For keeping you up-to-date with our news and offers
Once you have granted the relevant consent, we will send you promotional messages about our travel services, updates, products and offers, sometimes personalized to your preferences and interests if you have opted for such personalization, in order to improve your customer experience.

* To improve our services and protect our business interests
The business purposes for which we will use your information help us improve our services, meet your expectations, control transactions from our sales, to respond to any requests contesting debit charges on your cards, and to manage our sales clearances.

* For complying with our legal obligations
For example, when collecting information related to passenger accidents, we handle ticket replacement or refund requests, passenger & vehicle damage claims, keeping records of passenger identification.

* For safeguarding our legitimate interests and for the protections of persons and goods
When we are entitled to use closed circuit television (CCTV) and security cameras to be able to protect the security of individuals, materials, facilities, including our vessels.

Where do we share your data?
AEGEAN SPEED LINES N.E. informs you that it shares your personal data with the following categories of recipients:

* Governmental authorities, Law enforcement agencies
Where this is necessary for the execution of a route, in accordance with the provided procedures, and where it is required on a case-by-case basis to provide more information in relation to the list of passengers on particular routes.

* Associates of our company (travels agents, advertising agents etc.)
AEGEAN SPEED LINES N.E. appoints associates to whom the company entrusts the processing of personal data on its behalf (e.g. ticketing agencies). In these cases, AEGEAN SPEED LINES N.E. will remain responsible for the processing of your personal data and will specify the details of the processing, signing a specific contract with the associates to which it assigns processing activities in order to ensure that the processing is carried out in accordance with the applicable legal framework and that any natural person may freely and without hindrance exercise the rights conferred on him/her by the legal framework.
Furthermore, AEGEAN SPEED LINES N.E. may also transfer to third-party associates for the purpose of distributing promotional material and information about products, services, and offers, provided that the relevant consent has been granted by any natural person as mentioned above and that the foregoing shall apply to the written assignment of processing.

Storage time
The data storage time is decided on the basis of the following specific criteria, as appropriate on each case:
When processing is required as a requirement under provisions of the applicable legal framework, your personal data will be stored for as long as required by the relevant provisions.
When processing is done on the basis of a contractual relationship, your personal data will be stored for as long as is necessary to perform the contract and for the foundation, exercise, and / or support of legal claims under the contract.
For promotional and marketing purposes, your personal data is retained until your consent is withdrawn. This can be done by you at any time. Withdrawal of consent does not affect the legality of consent-based processing in the period before its revocation.

What are your rights with respect to your personal data
Any natural person whose data is being processed by AEGEAN SPEED LINES N.E. enjoys the following rights:

Right of Access:
You have the right to be aware and verify the legitimacy of the processing. So, you have the right to access the data and get additional information about how your date is processed.

Right to Rectification:
You have the right to study, correct, update or modify your personal data by contacting the Data Protection Officer (DPO) at the above contact details.

Right to Erasure (“Right to be forgotten”):
You have the right to request the erasure of your personal data when we process it based on your consent or in order to protect our legitimate interests. In all other cases (such as, for example, where there is a contract, due to an obligation to process personal data required by law, for reasons of public interest), this right is subject to specific restrictions or and may not apply, depending on the case.

Right to Restriction of Processing:
You have the right to request a restriction on the processing of your personal data in the following cases: (a) when the accuracy of the personal data is questioned and until such accuracy is verified; (b) when you oppose the erasure of personal data and request (instead of erasure) the limitation of its use; c) when personal data is not needed for processing purposes, but is, however, indispensable for the foundation, exercise, support of legal claims; and (d) when you object to the processing and until it is verified that there are legitimate reasons that concern us and supersede the reasons for which you oppose processing.

Right to Oppose Processing:
You have the right to oppose at any time the processing of your personal data where, as described above, such processing is necessary for the purposes of legitimate interests we seek as processors, as well as for processing for direct marketing and consumer profiling.

Right to Data Portability:
You have the right to receive your personal data free of charge in a format that allows you to access, use, and edit them, using commonly used editing methods. You also have the right to ask us, if technically feasible, to pass the data directly to another processor. This right exists for the data you have provided to us and is processed by automated means based on your consent or for the performance of a relevant contract.

Right to Withdraw Consent
Where processing is based on your consent, you have the right to withdraw such consent freely, without prejudice to the lawfulness of the processing based on your consent prior to its withdrawal.

In order to exercise any of the above-mentioned rights you may refer to the Data Protection Officer (DPO) Mr. Nick Stamoulos, email: This email address is being protected from spambots. You need JavaScript enabled to view it., telephone: +30 210 96 98 153.

 

Right to file a complaint with the Data Protection Authority
You have the right to file a complaint with the Data Protection Authority (www.dpa.gr): Telephone: +30 210 6475600, Fax: +30 210 6475628, email: This email address is being protected from spambots. You need JavaScript enabled to view it.

Personal Data Security
AEGEAN SPEED LINES N.E. implements appropriate technical and organizational measures aimed at the safe processing of personal data and the prevention of accidental loss or destruction and / or unauthorized access to, use, modification or disclosure thereof. In any case, the way in which the internet operates and the fact that it is free to anyone cannot guarantee that unauthorized third parties will never be able to violate the applicable technical and organizational measures by gaining access and possibly using personal data for unauthorized and / or unfair purposes.

Profiling
Profiling is defined as any form of automated processing of personal data that involves the use of personal data to evaluate certain personal aspects of a natural person, in particular to analyze or predict aspects of personal preferences and interests or movements.
Please be advised that profiling is taking place for marketing purposes when you consent to receive updates about our services and offers, personalized to your personal preferences and interests. Furthermore, profiling is provided to provide the Miles& Bonus service as defined in the specific update available at the dedicated section of the website. Finally, profiling may be carried out by social networking agents who are appointed by the company for marketing its products.