Privacy Policy of Egnatia Aviation

This Privacy Policy is intended to inform you about the information collected from you when you visit this website, how it may be used, how you can control the use and disclosure of your information and the measures taken to protect that information. This Policy forms an integral part of the Terms of Use, which are incorporated by reference.

The website of the Limited Liability Company under the name “EGNATIA AVIATION AEROPORIKI ETAIREIA AEROPORIKES EPICHEIRISEIS ETAIREIA PERIORISMENIS EUTHYNIS”, which is based in Amygdaleonas Airport “Lydia”, Kavala, Greece (hereinafter the “Company” or the “Website”) as the Data Controller, informs you as a person to whom the respective personal data concern (hereinafter the “Data Subject”) that during the visit or use of the website www.egnatia-aviation.aero, the processing of your personal data is governed by applicable European and national data protection legislation, including Law 4624/2019, Regulation (EU) 2016/679 of the European Parliament and of the Council adopted on 27 April 2016 and entered into force on 25 May 2018 (hereinafter the “GDPR”), as well as of the decisions, instructions and regulatory acts of the Personal Data Protection Authority.

1. Personal Data collected and processed by the Company

The Company ensures the fair and lawful collection and processing of personal data. Personal data is information that directly or indirectly identifies the Data Subject, in particular by reference to an identifier of their identity, such as full name, contact telephone number and e-mail address. The above personal data collected is strictly necessary for the implementation of the action requested by the Data Subject.

The Data Subject shall ensure that the personal data provided is correct and accurate and undertakes to notify the Company of any change or modification thereto. Any loss or damage caused to the Website or to any third party through the communication of incorrect, inaccurate or incomplete information in the contact form is the sole responsibility of the Data Subject.

2. Use of the Website by minors

In accordance with the specific provisions of Article 8 par. 1(a) of GDPR in conjunction with article 21 of the Law 4624/2019, minors under fifteen (15) years of age are prohibited from disclosing their personal data through the Company’s website, without the prior consent of their guardian.

3. Purpose of data processing

The purpose of the collection and processing of personal data from the Website is the communication of the Company with the Data Subject for the best possible service of the request sent to the e-mail address and/or through the contact forms. Further, the Website collects personal data necessary for its basic functions, such as navigation and access to secure areas of the Website (necessary cookies). When the Data Subject enters the Website, the Company may, with their explicit consent, also collect browsing data for analytical purposes (e.g. e.g. traffic monitoring), and for statistical purposes (Browser Type, Operating System, Internet Protocol Addresses (IP)), in order to understand how the Data Subject interacts with the Website and to improve the Website in this direction. More information about this category of personal data can be found in the Website’s Cookies Policy.

The Company collects and processes personal data solely for the aforementioned purposes and only to the extent strictly necessary to effectively serve these purposes. This data is in each case relevant and no more than is required in view of the above purposes, and is accurate and, if necessary, updated.

3A. Newsletter and Marketing Communications

Where the Data Subject voluntarily subscribes to the Company’s newsletter or marketing mailing list, the Company processes the Data Subject’s email address for the purpose of sending newsletters, promotional communications, training opportunities, company news, events, and other marketing-related information.

The legal basis for such processing is the Data Subject’s consent pursuant to Article 6(1)(a) GDPR.
The Data Subject may withdraw consent at any time by using the unsubscribe link included in each communication or by contacting the Company at privacy@egnatia-aviation.com. Withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

For the management and distribution of marketing communications, the Company uses HubSpot as a data processor. Personal data submitted through the newsletter subscription form may be transferred to and processed by HubSpot in accordance with applicable data protection legislation and HubSpot’s Privacy Policy.
Where personal data is transferred outside the European Economic Area, the Company ensures that appropriate safeguards are implemented in accordance with Chapter V of the GDPR, including Standard Contractual Clauses or other lawful transfer mechanisms where applicable.

4. Data retention time

The personal data collected shall be kept and stored in a secure environment, exclusively for the purposes of their collection and processing (see paragraph no. 3) and only for the time necessary to achieve those purposes, without prejudice to the more specific provisions laid down by the legislation in force. After the expiry of the aforementioned periods, the data shall be deleted-destroyed in a secure manner, unless the continuation of their retention is provided for by the legislation in force, such as in the case of a civil case or an investigation of a criminal offence, a tax audit, etc.

5. Data security

The processing of personal data by the Company is carried out in a manner that ensures its confidentiality. The Company takes all appropriate organizational and technical measures to ensure the security of the data and to protect it from accidental or unlawful destruction, accidental loss, alteration, unauthorized dissemination or access and any other form of unlawful processing.

6. Data breaches

The Company undertakes that in the event of a breach of its database; it will inform the Data Subjects as well as the Data Protection Authority within 72 hours of the breach.

7. Recipients of the data

The recipient of the personal data is the Company as well as the persons performing the processing on its behalf. The Company guarantees that it will not transfer, disclose or make available the Data Subject’s personal data to third parties for any purpose or use, unless such transfer, disclosure or making available is required by applicable law, by a court decision, public prosecutor’s order or warrant, or by a decision of another competent public or administrative authority legally empowered to require such disclosure.

Personal data may be transferred to recipients located outside the European Union and/or the European Economic Area only where such transfer is necessary for the purposes described in this Privacy Policy and is carried out in accordance with the provisions of the applicable data protection legislation. In such cases, the Company shall ensure that appropriate safeguards are in place, including, where applicable, an adequacy decision by the European Commission, Standard Contractual Clauses approved by the European Commission, or any other lawful transfer mechanism provided under the applicable data protection framework.

8. Data processors

The Company uses third party service providers (lawyers, accountants, web hosting providers as well as certified applicant tracking systems) to manage one or more aspects of its activities, including the processing of personal information. When the Company uses of an external company or partner, it uses contractual obligations and other appropriate means to ensure that the Data Subject’s personal data is used in a manner consistent with applicable law and this Policy.

9. Use of Cookies

The Website uses cookies necessary for its basic functions. Further, it may use cookies in order to analyse visitor behavior, track preferences, and gather information about the Data Subject. It uses cookies to manage login sessions and to provide personalized web pages so that the Website reflects the particular needs and interests of each Data Subject. In this way, the Website remembers the Data Subject’s actions and preferences (such as display preferences, language, etc.) for a certain period of time, so that the Data Subject does not have to re-enter these preferences each time they visit the Website, unless they wish to do so.

For more detailed information about the cookies collected by the Website, see the Cookies Policy.

10. Links to third-party websites

Any connection of the Website through special links, hyperlinks or banners with any other third party website does not imply that the Website assumes any responsibility for the policy followed on the Website regarding the protection and management of personal data. The Data Subject should ensure that they are informed about the protection and management of their data by the aforementioned websites.

11. Access, rectification and erasure (‘right to be forgotten’) Rights

According to the GDPR (Articles 15-18, 20-21 GDPR), the Data Subject has the right of access to data, rectification, erasure, restriction of processing, data portability and opposition. The above rights can be exercised by sending an e-mail to the email address of the Data Protection Officer of the Company privacy@egnatia-aviation.com from the email address through which the original e-mail was submitted, in order to identify the Data Subject.

12. Contact with the Data Protection Authority

In the event that the Data Subject considers that the protection of their personal data is compromised in any way, they may contact the Personal Data Protection Authority at the following details:

Personal Data Protection Authority
www.dpa.gr
1-3 Kifisias, 115 23, Athens
Tel. 210 6475628
E-mail: complaints@dpa.gr

As this notice and the personal data protection conditions contained herein may be subject to change, the Subject should regularly update the content of this notice and check for any changes.

Last update: 03.06.2026