Privacy and Data Protection Policy
Effective Date: 09/08/2025
1. Introduction
At Allinblusive MIKE (VAT: 800599575), located at Drosinis G. 15, Thessaloniki 546 44, Greece, protecting your privacy and personal data is of utmost importance to us. This policy details how we collect your personal information, the ways we use it to provide you with our yacht cruise services, and how we share and protect your data. This policy also explains how your data may be shared within our group company Trident Investments Group IKE and its affiliated companies to provide you with integrated services and personalized offers.
2. Data controller & contact details
Data Controller: This refers to Allinblusive MIKE, located at Drosinis G. 15, Thessaloniki 546 44, Greece, which is responsible for deciding how your personal data is processed and ensuring compliance with data protection laws.
Group Controller: When we share your data within our group for joint purposes, Trident Investments Group IKE (Vachou 1, Thessaloniki 54629, Greece) acts as a joint controller.
Data Protection Officer: Chris Kaliptsidis oversees data protection matters across our businesses and can be contacted at info@allinblusive.com or +30 231 22 00000 for any privacy questions or requests.
3. Types of personal data collected
We collect various pieces of personal information required to serve you effectively:
Your full name, phone number, and email address to communicate and manage your bookings.
Passport number, which is necessary for compliance with maritime laws and passenger identification.
Any dietary restrictions or allergies you voluntarily provide, to ensure your safety and comfort onboard.
Booking details, including dates and destinations, to fulfill your cruise arrangements.
Records of communications such as emails, phone calls, and chat interactions to provide customer support and for quality assurance.
Data related to your interaction with our website, including cookies and IP addresses, to enhance your online experience.
Information about our crew and staff collected in accordance with Greek employment laws, including personal and professional details needed for lawful hiring and operations.
4. How we collect data
Your personal data is obtained through several channels to ensure smooth service delivery:
Online booking forms integrated on our website are managed via FareHarbor, a secure third-party platform.
Partner hotels and travel agencies (Booking OTAs such as TripAdvisor and GetYourGuide) may transmit booking details on your behalf.
Real-time communications through our website chat platform (Respond.io), phone calls, emails, and direct in-person interactions provide additional data points.
Our website contact and check-in forms are powered by Squarespace, capturing information you enter directly.
Systems like Zoho CRM, Zoho Marketing Automation, Pylon Epsilon ERP, and Google Cloud store and process your data securely to facilitate operations across our business.
5. Purposes of data processing
We use your personal information for clearly defined and lawful purposes including:
To execute and manage your yacht cruise bookings, ensuring all services meet your expectations.
To comply with Greek maritime regulations and laws designed to safeguard you and other passengers.
To maintain safety standards on board and manage emergency procedures effectively.
To analyze customer information for service improvement and to tailor offers that better fit your preferences.
·To communicate marketing messages and promotions, only with your consent or where we have a legitimate interest in presenting relevant offers.
6. Data sharing and transfers
Your data may be disclosed only under strict controls and for necessary purposes:
When mandated by law, we share customer data in hard copy with maritime and regulatory authorities for legal compliance.
For service enhancement and integrated offerings, your data is shared internally between with our group companies Allinblusive MIKE, Grandeur MIKE, and the Trident Investments Group IKE.
Third-party providers such as FareHarbor, Zoho, Squarespace, Respond.io, Pylon Epsilon, and Google Cloud have access strictly for operational purposes and are bound by confidentiality and data protection agreements.
Your personal data is never sold or shared with unrelated third parties for marketing or other uses.
7. Legal basis for processing
We process your personal data on several lawful grounds:
To fulfill contracts you have entered into with us, such as booking and payment agreements.
To meet our legal obligations, particularly those stemming from maritime safety and passenger identification laws.
To pursue legitimate business interests in improving our services, conducting customer analysis, and offering group-wide benefits.
Based on your explicit consent, particularly concerning marketing communications or processing sensitive information like dietary needs.
8. International data transfers
All your personal data is processed and stored exclusively within secure data centers located in the European Union. In the rare case data is transferred outside the EU, appropriate safeguards are applied to protect your information, respecting GDPR requirements.
9. Data security
We apply comprehensive security measures to protect your personal data against unauthorized access, alteration, or loss, such as:
Utilizing established technical security protocols including encryption and secure cloud infrastructure.
Implementing role-based access controls whereby staff access is limited strictly to what is necessary for their job.
Enforcing strong authentication systems such as passwords and two-factor authentication, with prompt revocation of access when staff roles change or end.
Providing ongoing privacy and data security training to our employees and contractors.
10. Data retention
We keep your personal data only as long as necessary to meet legal and operational requirements:
Consumer data such as your contact and booking details are retained for five years to facilitate future interactions and comply with record-keeping laws.
Transaction and financial records related to payments are retained for twenty years as required by Greek financial regulations.
HR and employment data for crew members are preserved for five years post-employment.
Data related to newsletters or marketing communications are retained until you unsubscribe or for five years, whichever comes first.
Business records essential for regulatory compliance or dispute resolution are retained throughout the company’s existence.
11. Your rights
You have full rights regarding your personal data, including the right to:
Access the personal data we hold about you and receive a copy.
Request corrections to any inaccurate or incomplete information.
Request the deletion of your data where it is no longer necessary or where you withdraw consent.
Restrict or object to certain types of processing, especially marketing activities.
Obtain a copy of your data in a structured, machine-readable format (data portability).
To exercise these rights, please contact us via info@allinblusive.com. We commit to responding to all legitimate requests within 30 days.
12. Cookies and tracking
Our website uses cookies and similar tracking technologies to:
Ensure the website functions correctly and smoothly.
Analyze website visitor behavior to improve content and usability.
Deliver tailored marketing offers based on your interests and interactions.
For detailed information and how to manage your cookie preferences, please see our dedicated Cookie Policy page.
13. Changes to this policy
Any updates to our privacy practices will be posted on our website promptly. If significant changes are made, or changes affect your rights, we will inform you directly through appropriate channels.