Privacy policy (sample — have legally reviewed before launch)

1. Controller

Controller under the GDPR (example): Nyktor Example GmbH, Sample Street 1, 24100 Kardamyli, Greece, email: privacy@nyktor.example

2. General information on processing

We process personal data only where necessary to operate this website and provide our content and services (orientation text). Legal bases must be specified before launch (e.g. Art. 6(1)(b) or (f) GDPR).

3. Contact form

When you send us a message via the contact form, we process the data you provide to handle your request. If outbound email is configured (e.g. via a provider such as Resend), we use that data to deliver your message; align details on processors, retention and withdrawal with legal counsel before production use.

4. Cookies & consent

Where we use non-essential cookies or similar technologies, we require your consent — for example through a consent management tool. Before go-live: document the cookie list, purposes and retention periods.

5. Embedded services & booking

Features such as maps, analytics or booking widgets (e.g. Lodgify) may transfer data to third parties. Document which services are active and what data flows before launch.

6. Your rights

Data subjects have rights under the GDPR including access, rectification, erasure, restriction, portability and objection (overview). Contact: privacy@nyktor.example (placeholder — replace with a real address).