1. Data controller
The controller responsible for booking information is Mezé² Restaurant, located at Naxos, Greece. You can contact us at pansorokos@gmail.com · +30 2285 026 401 · https://www.instagram.com/mezemezenaxos.
The booking platform is technically provided by Multiapp, acting as a technical service provider/data processor where applicable.
2. Data we collect
- Full name, email address, telephone number and country code.
- Booking date, time, number of guests and information connected with the booking.
- Random secure-access identifiers used to view and cancel reservations. Only a SHA-256 cryptographic hash of the identifier is stored in the database.
- Security and operational data such as IP address, request date/time, browser type, referrer and error logs.
- Your consent choices for analytics and advertising measurement.
3. Purposes and legal bases
- Booking administration and communication: performance of a contract or steps requested before entering into one (Article 6(1)(b) GDPR).
- Security, abuse prevention and technical support: legitimate interests in operating a secure service (Article 6(1)(f) GDPR).
- Legal duties and claims: compliance with legal obligations or the establishment, exercise or defence of legal claims.
- Analytics and advertising measurement: only with prior consent (Article 6(1)(a) GDPR and Article 4(5) of Greek Law 3471/2006).
4. How booking information is used
Booking information is used to register, confirm, amend or support your reservation and to send related communications. We do not sell your booking information.
The secure link in your email lets you view reservations associated with the same email address and, where permitted, cancel them. The link is personal, expires after a limited period and can be revoked.
If you accept advertising measurement, contact details may be normalised and converted locally into a one-way SHA-256 cryptographic value before being supplied to Google for enhanced conversion measurement. This does not take place without the relevant consent.
5. Recipients and service providers
Information may be accessed by authorised business staff, the platform's technical provider, hosting and email providers and, where you have consented, Google and Meta for analytics and/or advertising measurement. Information may also be disclosed to authorities where required by law.
6. Retention
Booking information is retained for up to 12 months after the booking date, unless a longer period is required for a legal obligation, security or legal claims. Technical cookie retention periods appear in the table below.
7. Cookies and similar technologies
Necessary cookies support the operation of the service and store consent choices. Analytics, Google Ads and Meta Pixel are enabled only after the relevant consent. When advertising-cookie storage is denied, Google Consent Mode may send limited measurement signals without advertising identifiers. The interactive Google map loads only when you choose to display it.
| Name | Category | Purpose | Duration | Provider |
|---|---|---|---|---|
meze_naxos_google_consent_v2 |
Necessary | Stores consent choices and prevents the banner from appearing on every visit. | 180 days | meze-naxos.multiapp.gr |
PHPSESSID |
Necessary | Maintains the secure technical service session, when used. | Browser session | meze-naxos.multiapp.gr |
_ga, _ga_* |
Analytics | Distinguishes visitors and measures service usage. | Up to 2 years | |
_gid |
Analytics | Short-term statistical visitor distinction, when used. | 24 hours | |
_gcl_*, _gcl_au |
Advertising | Measures Google advertising clicks and conversions. | Up to 90 days | |
_gcl_ls (local storage) |
Advertising | Locally stores advertising-click measurement information. | Up to 90 days or until cleared | |
NID, SOCS, AEC |
Third-party map | Functionality, preferences and security for the embedded Google Maps service. | 6 to 13 months, depending on the cookie |
More information: How Google uses cookies
8. Managing and withdrawing consent
You can change or withdraw your choices at any time. Withdrawal does not affect the lawfulness of processing carried out before it.
9. International transfers
Some providers, including Google and Meta, may process information outside the European Economic Area. Where required, transfers rely on a recognised adequacy mechanism or appropriate safeguards such as Standard Contractual Clauses.
10. Your rights
Subject to the GDPR's conditions, you may have rights to information, access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent.
You may also lodge a complaint with the Hellenic Data Protection Authority.
11. Security and automated decisions
We apply appropriate technical and organisational measures to protect information. The booking service does not make decisions producing legal or similarly significant effects based solely on automated processing.
12. Changes and contact
This policy may be updated when the service or legal framework changes. The date of the latest version appears at the top.
For questions or rights requests: pansorokos@gmail.com · +30 2285 026 401 · https://www.instagram.com/mezemezenaxos.
The exact cookie list may change when third-party services are updated. This table is updated when the implementation changes materially.