Last updated: 18/05/2026
This Privacy Policy explains how Corfu City Tours (“we”, “our”, the “Website”) collects, uses, and protects personal data of visitors and customers in accordance with the GDPR and applicable laws.
Data Controller – Contact Details
Corfu City Tours, Mitropolitou Methodiou 7, Kerkira 491 00, Greece. Phone: +30 2661100332, +30 6932600208. Email: info@corfucitytours.com.
For privacy-related requests (access/rectification/erasure, etc.), please contact info@corfucitytours.com. [corfucitytours.com]
Personal Data We Collect
- Data you provide to us:
- When you contact us via the contact form (WordPress/Divi), we may collect your name, email address, phone number (if requested), and the content of your message.
- When you place a booking/purchase of services (via WooCommerce/booking system), we may collect information required to complete the booking and deliver the service (such as name, email, phone, selected tour/service, date/time, number of participants, notes) and, where applicable, billing details.
Data collected automatically:
When you browse the Website, we may collect technical data such as IP address, browser type/version, operating system/device information, and security/technical logs for Website operation and protection.
Note: The Website does not provide visitor user accounts and does not use a comments feature.
Purposes of Processing & Legal Bases (GDPR)
We process personal data for:
- Responding to enquiries/communication (legitimate interests and/or taking steps prior to a contract at your request).
- Providing the booked service and managing transactions (performance of a contract).
- Billing/accounting and tax compliance where applicable (legal obligation).
- Security and proper operation of the Website (legitimate interests).
- Non-essential cookies (e.g., analytics/marketing) only if relevant tools are enabled and, where required, your consent is obtained.
Payments – Viva Smart Checkout (Viva Wallet)
Payments are processed via Viva Wallet (Viva Smart Checkout). We do not store full card details on our servers. Payment details are processed in the provider’s secure environment and we may receive only information necessary to manage the transaction (e.g., payment status, order/transaction identifier).
Cookies & Consent
The Website uses essential cookies required for basic operation, security and (where applicable) the booking/checkout flow. In the future, non-essential cookies (analytics/marketing) may be used only if the relevant tools are enabled and—where required—your consent is obtained via a cookie banner/consent tool. You can manage cookies through your browser settings and/or via the consent tool (once installed). Disabling certain cookies may affect functionality such as checkout or payments.
Data Sharing – Service Providers
We share personal data only where necessary for Website operation and service delivery, such as:
- Hosting/Infrastructure: SiteGround.
- Domain/Email services (where applicable): Papaki.
- Payment provider: Viva Wallet (to process payments).
- Technical support/security/backup (where applicable): services and plugins supporting security, performance and backups.
We do not sell or rent personal data to third parties.
International Transfers
Some providers may process data outside the EEA. Where required, appropriate safeguards under the GDPR are applied.
Data Retention
- Contact requests: as long as needed to handle the request plus a reasonable period for documentation/security.
- Bookings/transactions: as long as needed to provide the service and as required by accounting/tax obligations (where applicable).
- Security logs: for a reasonable period for security and troubleshooting.
Your Rights (GDPR)
You have rights of access, rectification, erasure (where applicable), restriction, objection, data portability, and withdrawal of consent (where processing is based on consent). To exercise your rights, contact info@corfucitytours.com.
You also have the right to lodge a complaint with the relevant supervisory authority.
Security
We apply appropriate technical and organisational measures. However, no method of transmission or storage is 100% secure.
Changes to this Policy
We may update this Policy from time to time. The “Last updated” date will be revised accordingly.