Skip to main content
← Back to home

Privacy Notice

Last updated: 28 August 2026 · v2.8

1. Controller and contact

The controller is CLARITY GROUP ΟΕ, 52 Ploutonos Street, Dafni 17236, Greece, VAT No. 801813489, GEMI No. 163834903000. Privacy requests may be sent to info@claritygroup.gr or by telephone to +30 210 991 9847.

2. Data we process

Depending on how you use Beyond Stay, we process identity and contact data; property, stay dates and guest information; booking references and status; and, where needed for guest registration or booking administration, one identification detail selected by the guest, such as a Greek Tax ID (AFM), National ID number or passport number. We also process payment method, payment identifiers and financial records (not full card details); bank-transfer verification data; service and concierge requests; preferences and, where voluntarily supplied, accessibility, allergy or dietary information; communications; newsletter consent and preferences; promotion-code use; technical logs, security data and cookie choices; and documented evidence relating to incidents, damage or complaints. Beyond Stay does not ask guests to submit medical diagnoses, medication, skin-condition details or other wellness health history through its wellness request forms; suitability discussions are handled privately by the relevant professional.

3. Purposes and legal bases

We process data to provide quotes, conclude and perform bookings, register and identify guests where required for the stay, collect and reconcile payments, coordinate services, communicate operational information and handle refunds or complaints (contract and pre-contractual steps); meet tax, accounting, fraud-prevention, safety and legal obligations; protect the platform, properties and legal claims (legitimate interests and legal claims); and send newsletters or promotional communications only where consent or another lawful basis applies. The guest-registration acknowledgement confirms that the submitted information is accurate and that the Privacy Notice has been read; it is not marketing consent. Where a guest chooses to provide allergy or accessibility information that may reveal health-related information, Beyond Stay requests separate explicit consent and uses the information only to coordinate the specific request safely and, where necessary, share it with the selected service provider.

4. Service providers and recipients

Data may be shared on a need-to-know basis with authorised Clarity Group personnel; property owners or operators where necessary; connected booking and property-management systems for availability, reservation and guest-registration processing; authorised payment processors for card payments; banks for transfers and refunds; transactional email providers; hosting, database, storage and infrastructure providers; accountants, insurers, legal advisers and public authorities; and selected experience or service providers necessary to perform an accepted request. Each recipient receives only the information needed for its role.

5. Payments

Card details are entered into secure payment components operated by an authorised payment processor and are not stored by Beyond Stay. We retain payment references, status, amounts, timestamps, refund information and reconciliation records. Bank-transfer information is used to match funds to a booking and to process any required manual refund.

6. Newsletters and promotions

Newsletter subscription is optional. We store email, preferred language, consent source and time, delivery history and unsubscribe status. Every marketing email contains an unsubscribe facility. Unsubscribing from marketing does not stop essential booking, payment, safety or service communications. Promotion-code redemption data is kept to enforce eligibility, limits and fraud prevention.

7. Damage and incident data

Where an incident or damage claim arises, we may process photographs, property condition records, correspondence, invoices, repair estimates, witness or provider reports and payment or insurance claim records. This information is used only to investigate, communicate, defend or pursue documented claims and is restricted to authorised persons and relevant advisers or authorities.

8. Retention

We retain booking, transaction and tax records for the periods required by applicable accounting, tax and limitation rules. Operational records are kept only as long as needed for the booking, statutory guest registration, support and legitimate claims. For each Guest Guide check-in submission, the complete identification detail is sent to a restricted Beyond Stay operations mailbox as an internal recovery record for reservation administration and statutory reporting. Access to that mailbox is limited to authorised personnel, and the message must not be forwarded outside the authorised workflow. The identification number is also sent to the relevant reservation record in the connected booking-management system. An encrypted Beyond Stay backup remains available only to authorised administrators so the information can be recovered if synchronization, reservation administration or statutory reporting requires follow-up. Access to the complete value is restricted and audit-stamped. The encrypted backup is retained only for the documented operational, tax, legal and limitation periods applicable to the stay and is then deleted securely. The same process applies when the shared fallback Guest Guide code is used and no connected reservation record exists. Beyond Stay may retain the guest name, contact and stay details, identification type and masked ending, submission and processing status, timestamps and privacy-notice version for operational evidence. Internal email and statutory-registration records are retained only for the applicable operational, tax, legal and limitation periods. Marketing data is retained until consent is withdrawn or the record becomes inactive, subject to a limited suppression record that prevents future unwanted messages. Voluntarily supplied allergy or accessibility information is restricted to the relevant request and removed, anonymised or access-restricted when it is no longer needed for safe coordination or a legal claim.

9. International transfers and security

Some technology providers may process data outside the EEA. Where required, transfers rely on adequacy decisions, standard contractual clauses or another lawful safeguard. We use role-based access, encryption in transit, server-side payment and booking controls, audit records and access restrictions; however no internet system can be guaranteed risk-free.

10. Your rights

Subject to the GDPR and applicable law, you may request access, correction, erasure, restriction, portability and objection, and may withdraw consent at any time. A request can be sent to info@claritygroup.gr. We may need to verify identity and may retain data where a legal obligation or overriding legal claim applies. You may lodge a complaint with the Hellenic Data Protection Authority.

11. Cookies and changes

Necessary cookies support security, language, checkout and consent choices. Optional analytics or marketing technologies are used only according to the cookie controls and applicable consent. Material changes to this Notice are published with an updated version and date.

Beyond Stay newsletter

Local inspiration and selected offers.

Occasional destination guides, stay ideas and offers. No unnecessary emails.

We use essential cookies for the platform to function. Analytics and marketing cookies require your consent.