Privacy policy (sample — have legally reviewed before launch)
1. Controller
Controller under the GDPR (example): Nyktor Example GmbH, Sample Street 1, 24100 Kardamyli, Greece, email: privacy@nyktor.example
2. General information on processing
We process personal data only where necessary to operate this website and provide our content and services (orientation text). Legal bases must be specified before launch (e.g. Art. 6(1)(b) or (f) GDPR).
3. Contact form
When you send us a message via the contact form, we process the data you provide to handle your request. If outbound email is configured (e.g. via a provider such as Resend), we use that data to deliver your message; align details on processors, retention and withdrawal with legal counsel before production use.
4. Cookies & consent
Where we use non-essential cookies or similar technologies, we require your consent — for example through a consent management tool. Before go-live: document the cookie list, purposes and retention periods.
5. Embedded services & booking
Features such as maps, analytics or booking widgets (e.g. Lodgify) may transfer data to third parties. Document which services are active and what data flows before launch.
6. Your rights
Data subjects have rights under the GDPR including access, rectification, erasure, restriction, portability and objection (overview). Contact: privacy@nyktor.example (placeholder — replace with a real address).