Политика за поверителност

Last Updated: 07/08/2026

The company under the corporate name "FERRYHOPPER S.A.", having its registered office at 147 Thessalonikis Street, Moschato, 183 46, Greece, with contact details +30 210 2208496 and info@ferryhopper.com, acting as the Data Controller (hereinafter referred to as "Ferryhopper", the "Company", "we", "us", or "our"), is committed to safeguarding the security of your personal data in full compliance with the applicable data protection legislation, in particular Regulation (EU) 2016/679 (the General Data Protection Regulation – "GDPR"), Law 4624/2019, and Law 3471/2006, as in force.

In this context, we process your personal data only to the extent strictly necessary for specified and legitimate purposes, as described below. This Privacy Policy is intended to inform users of our website (hereinafter the "website" or the "online platform") and our mobile application (hereinafter the "application") about the processing of your personal data.

1. For what purposes do we process your personal data, which categories of personal data do we collect, and what is the legal basis for the processing?

Depending on the service we provide to you through the Website, we may collect, as applicable, the following categories of personal data:

  Purpose of Processing Categories of Personal Data Legal Basis
1. Provision of the services requested by you and performance of the contract to which you are a party, including: the intermediation for the booking of travel services (e.g. ferry tickets), the provision of related services (e.g. accommodation, vehicle rental, travel insurance), the management and completion of payments, and communication with you regarding your booking and the provision of the services.

Identity and contact data
This category includes data such as your full name, username and password (where you create an account), or similar user identifier, date of birth, gender, passport or identity card number, place of birth, nationality, passport or identity card expiry date, any discount card numbers (e.g. Unique Islander Number or loyalty card number), as well as contact details, such as your telephone number and/or email address.

Third-party data (e.g. fellow travellers)
We may also process identity data relating to third parties, including minors, whom you register as fellow travellers. The user providing us with third-party personal data is responsible for ensuring that they have obtained the necessary authorisation from such third parties for the use of their personal data within the application. In particular, where the personal data of minors is entered into our application, the user must either be their legal guardian or act with the authorisation of their legal guardian.

Booking and travel data
This category includes data relating to the making and management of bookings, such as booking reference number, trip details (e.g. vessel, destination, travel date), selected services, fellow travellers, as well as booking and travel history.

Financial data

This category includes information relating to your transactions, such as invoicing details (Tax Identification Number (TIN), address, competent Tax Office), as well as information regarding the services purchased (e.g. transaction history).

The Company does not store full payment card details. Any storage of payment credentials is carried out by our payment service providers in the form of pseudonymised identifiers (tokens), which do not permit the direct identification of the full payment card number.

Data Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR).
2. Handling requests and customer support, including processing your enquiries and complaints, as well as communicating with you through the available communication channels.

Communication data

This category includes data collected in the context of your communications with the Company, such as the content of your messages, customer support requests, the subject matter of your communication and any related information (e.g. booking reference number).

1. Where the processing concerns existing customers, processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR).

2. Where the processing concerns prospective customers, processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR).

3. Operation, maintenance and technical support of the website and the application, for the purposes of ensuring their proper and secure operation, addressing technical issues, and improving the user experience.

Technical data

This category includes data relating to and facilitating your use of the website and the application, such as Internet Protocol (IP) address, location, time zone, browser type and version, operating system, device name and manufacturer, device IMEI number, application version in use, log-in data, browsing/usage program, and browsing/usage details.

Processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR).
4. Improvement and enhancement of our services and our business operations in general, where we collect data for statistical analysis regarding the use of the website or the application, your preferences, or the effectiveness of our advertisements.

Usage data

This category includes information relating to your preferences and the analysis of your behaviour when using our website or application, such as your recent searches, frequency of use, frequency of purchasing similar services (e.g. booking tickets with the same fellow travellers, frequency of similar trips), clicks, time spent on each screen, the referring page through which you accessed our website or application, etc.

1. Where the processing concerns existing customers, processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR).

2. Where the processing concerns prospective customers, we rely on the data subject's consent (Article 6(1)(a) GDPR). For more information regarding the trackers (such as cookies) that we use, please refer to our Cookie Policy.

5. Marketing and communications, including the sending of informational and promotional material (e.g. newsletters), the promotion of similar services to existing customers in accordance with applicable legislation, the display of personalised advertisements and the provision of personalised information based on your preferences.

Advertisement data

This category includes information relating to the sending of promotional material to customers, such as information regarding your preferences and your interaction with the relevant communications.

Identity and contact data

1. Where the processing concerns existing customers, processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR).

2. Where the processing concerns prospective customers, we rely on the data subject's consent (Article 6(1)(a) GDPR). For more information regarding the trackers (such as cookies) that we use, please refer to our Cookie Policy.

6. Management of user and affiliate accounts, including registration, authentication and access to the relevant services.

Identity and contact data

Technical data

Communication data

Financial data (as above).

Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract (Article 6(1)(b) GDPR).
7. Collection and analysis of feedback and reviews for the purposes of quality assurance, evaluation of the travel experience, improvement of the services provided, and the production of aggregated statistical information.

Feedback and review data

This category includes information that you provide in the context of satisfaction surveys or questionnaires, such as comments, ratings, reviews and other responses relating to your travel experience.

Processing is necessary for the purposes of the legitimate interests pursued by the Company (Article 6(1)(f) GDPR).
8. Compliance with our legal obligations, in particular those arising under applicable tax, accounting and other regulatory requirements. All of the above. Processing is necessary for compliance with a legal obligation to which the Company is subject (Article 6(1)(c) GDPR).

2. Who are the recipients of your personal data?

Your personal data is processed by the Company's duly authorised personnel.

Your personal data is disclosed only to the extent strictly necessary to third parties where this is required for the provision of the agreed services or for the purposes of pursuing our legitimate interests, including in particular:

  1. Our business partners, such as ferry operators, hotels, vehicle rental companies, technical or commercial connectivity providers, courier companies, payment institutions, etc., depending on the service you have selected, where access to your personal data is necessary for the provision of the services you have requested;
  2. Service providers with whom we cooperate and who provide services directly to Ferryhopper, such as internet services, web analytics, usability analytics, statistical analysis, technical support for the Website and the Application, and advertising services, to the extent necessary for the fulfilment of the above purposes and the provision of the agreed services to the Company;
  3. Public supervisory and regulatory authorities, judicial authorities and other public bodies, where disclosure of your personal data is required by applicable law, regulation or legal process, including, for example, in connection with investigations conducted by judicial authorities into unlawful activities, in compliance with a court order or a request from a supervisory authority, or where such disclosure is necessary to protect our overriding legitimate interests, including for the establishment, exercise or defence of legal claims in the context of judicial proceedings.

3. Do we transfer your personal data outside the European Economic Area (EEA)?

The processing of your personal data within the EEA is subject to a high level of protection under the applicable data protection legislation. As a general rule, we do not transfer your personal data to third countries or international organisations, unless such transfer is strictly necessary for legitimate and clearly defined purposes and one of the following conditions is met:

  1. An adequacy decision has been adopted by the European Commission in respect of the third country to which the personal data is transferred (Article 45 GDPR);
  2. Appropriate safeguards have been provided by the recipient in relation to the transfer of the personal data (Article 46 GDPR);
  3. A derogation for a specific situation applies (Article 49 GDPR).

In all cases, we implement the necessary technical and organisational measures to ensure that your personal data remains protected and is processed with a level of security equivalent to that required under the GDPR.

4. How long do we retain your personal data?

Our general policy is to retain your personal data only for as long as is necessary to fulfil the purposes for which they were collected, as described above, and, in any case, for as long as required or permitted under applicable law and the applicable limitation periods for any potential claims.

The criteria we use to determine the applicable retention periods include, among others:

  1. the period during which we maintain an ongoing relationship with you and provide you with access to the website and the application in accordance with the contractual terms governing the relevant service;
  2. whether we are subject to a legal obligation to retain your personal data, for example, in order to comply with tax or accounting requirements;
  3. whether retention is necessary for the purposes of our legitimate interests, for example, in the event of a complaint, dispute, litigation or regulatory investigation.

With regard to trackers (such as cookies), the retention period applicable to the data they collect is set out in our Cookie Policy.

5. Do we carry out automated individual decision-making based on the processing of your personal data?

We hereby inform you that we do not carry out automated individual decision-making, including profiling, based on the personal data that you provide to us through our website, our application and the services made available through them.

6. What are your rights in relation to your personal data?

You have the following rights under the applicable data protection legislation, the exercise of which depends on whether the specific conditions provided therein are met in each case:

a) Right of access to the personal data we hold about you;

b) Right to rectification of inaccurate or incomplete personal data concerning you;

c) Right to withdraw consent, where consent constitutes the legal basis for the processing;

d) Right to erasure of your personal data;

e) Right to restriction of processing;

f) Right to data portability;

g) Right to object to the processing.

You may exercise any of the above rights or submit a question regarding the processing of your personal data by our Company by sending an email to dpo@ferryhopper.com. We undertake to respond promptly and, in any event, within one month of receipt of your request or query. This period may be extended for a maximum of two (2) additional months. We will always inform you in writing about the progress of your request or any extension of the response period.

If, for any reason, you are not satisfied with our response to your query or request, you may lodge a complaint with the Hellenic Data Protection Authority through its website: https://www.dpa.gr/en

7. What happens when you visit third-party websites or use third-party widgets through Ferryhopper?

Our website contains links to third-party websites and applications (e.g. Facebook, Instagram, Twitter, LinkedIn, Google Play, App Store and Recruitee), the use of which creates a digital footprint relating to you. In relation to this digital footprint, we and the relevant third-party act as joint controllers, to the extent that each of us determines the purposes and means of the processing of personal data. The Company's processing of this digital footprint is based on our legitimate interests (Article 6(1)(f) GDPR), namely improving the functionality of our website and the services provided through it, as well as analysing its traffic and interoperability with the linked applications. We do not participate in, control or assume responsibility for any processing of personal data carried out by such third parties once you begin using their websites, nor are we responsible for their content or the privacy policies they apply. Under no circumstances does this Privacy Policy apply to the websites of third parties. For further information regarding the processing of your personal data by those third parties, we recommend that you consult the relevant privacy policies available on their respective websites.

8. Updates to this Privacy Policy

This Privacy Policy contains all the information required under Articles 13 and 14 of the GDPR. It will be updated whenever the information contained herein changes or where required by the applicable data protection legislation. Where appropriate, we may notify you directly or by any other appropriate means of specific amendments to this Privacy Policy. In any event, we recommend that you review this Privacy Policy periodically to remain informed of any updates.

9. How can you contact us?

If you have any questions regarding the processing of your personal data or this Privacy Policy, please do not hesitate to contact our Data Protection Officer at dpo@ferryhopper.com.