LEGAL

Privacy policy

Privacy Policy

Last updated: August 31, 2026

Controller: CaptainBook I.K.E.
Registered office: Petrou Protopapadaki 13, 84300 Naxos, Greece
VAT / TIN: EL801577488, Tax Authority Office of Naxos, Greece
Contact: info@captainbook.io
Tel.: +30 6949 453 468 / +30 6944 052 525
Effective date: 1 September 2026 for accounts created on or after that date; 1 October 2026 for accounts existing before it, together with the Terms and Conditions (Terms §21.15).

1. About this Policy

CaptainBook I.K.E. ("CaptainBook", "we", "us") provides booking and operations software to tour, activity, rental and experience operators. This Policy explains what we do with personal data.

It replaces the Privacy Policy last updated 3 January 2023 in its entirety.

It covers:

  • visitors to captainbook.io and our other websites;

  • operators, meaning the businesses that hold a CaptainBook account, and their staff and users;

  • resellers and partners, and their contacts;

  • prospective customers we contact or who contact us; and

  • guests, meaning the end customers who book an operator's experience, to the limited extent described in Section 3.2.

It does not cover what an operator does with personal data in its own business. Where you booked an experience, the operator is responsible for your data and you should read their privacy notice.

Words defined in the CaptainBook Terms and Conditions have the same meaning here. This Policy forms part of that Agreement.

2. The short version

  • We are the controller of data about operators, their users and our website visitors, and about people we market to.

  • We are a processor of data about guests, which operators put into the Service. The operator decides what happens to it; we act on their instructions.

  • We do not sell personal data, and we do not use guest data for our own marketing.

  • Personal data is hosted primarily in the European Union. Where a supplier processes it outside the EEA, we rely on the European Commission's Standard Contractual Clauses.

  • You can ask us for a copy of your data, ask us to correct or delete it, or object to what we do with it. See Section 9.

3. Our two roles

3.1 Where CaptainBook is the controller

We decide the purposes and means of processing, and this Policy applies in full, for:

  • account, contact and billing data of operators, resellers and their users;

  • data about visitors to our websites, and product and usage telemetry from the Service;

  • security, authentication and access logs;

  • fraud prevention, abuse detection and service improvement;

  • invoicing, accounting and statutory record-keeping;

  • records evidencing acceptance of our Terms, attempts to cancel a subscription, renewal notices sent and retention offers made; and

  • marketing to business contacts and prospective customers.

3.2 Where CaptainBook is a processor

Personal data relating to guests, their party members and an operator's own customers and prospects, meaning everything the operator or its users submit to, or generate through, the Service, is processed by us on the operator's instructions. The operator is the controller.

For that data:

  • the operator decides what is collected, why, and how long it is kept;

  • requests from guests must be made to the operator, not to us. If you contact us about data an operator holds, we will refer you to them and tell them you asked;

  • our obligations are set out in the Data Processing Agreement at Appendix E of the Terms.

We never act as joint controller with an operator unless we have agreed that in writing before the relevant feature is used.

4. What we collect, why, and on what basis

4.1 Operators, resellers and their users

WhatWhyLawful basisName, business name, e-mail, telephone, address, country, language, roleCreating and running your account, supporting you, sending service messagesArticle 6(1)(b), performance of a contractBilling and tax data: plan, billing currency, payment method reference, invoices, VAT numberCharging you, issuing invoices, meeting tax and accounting obligationsArticle 6(1)(b) and 6(1)(c)Authentication and security data: credentials, session and login records, IP address, device and browserSigning you in, keeping the account secure, investigating abuseArticle 6(1)(b) and 6(1)(f), legitimate interests in securing the ServiceProduct telemetry: features used, pages visited, errors encounteredUnderstanding how the Service is used, diagnosing faults, improving itArticle 6(1)(f), and Article 6(1)(a) where consent is required for non-essential cookiesSupport correspondence, chat history, call notesAnswering you and keeping a record of what was saidArticle 6(1)(b) and 6(1)(f)Records of terms acceptance, cancellation attempts, renewal notices and retention offersProving what was agreed and when, and defending payment disputes and chargebacksArticle 6(1)(f), establishing, exercising and defending legal claimsApproximate location derived from IP addressSecurity, fraud prevention and regional defaultsArticle 6(1)(f)

4.2 Website visitors

We collect pages viewed, referrer, approximate location from IP address, device and browser information, and cookie identifiers. Strictly necessary cookies are set on the basis of our legitimate interests and the ePrivacy exemption; functional, analytics and marketing cookies are set only with your consent, which you can withdraw at any time. See Section 10.

The providers we use on our own websites are Google Tag Manager and Google Analytics 4, Mixpanel, Hotjar, Customer.io, Framer, which hosts our marketing site, and the Meta Pixel. Hotjar records how a visitor moves through and interacts with a page, including mouse movement, scrolling and clicks; it is set only with your consent. The Cookie Policy describes each of them, and Section 8.1 explains what happens where a provider processes data outside the EEA.

4.3 Prospective customers and marketing

We process business contact details to tell operators about CaptainBook, on the basis of our legitimate interests in marketing to businesses (Article 6(1)(f)) or your consent (Article 6(1)(a)), depending on the channel and the country. Every marketing message carries an unsubscribe link, and you can opt out at any time by writing to info@captainbook.io.

We do not use guest data obtained through the Service for our own marketing.

4.4 Guests

Where you booked with an operator, the operator decides what is collected. Typically it includes your name and contact details, the booking itself, payment metadata (a processor reference, the last four digits of a card and the payment status; we never store full card numbers), messages exchanged, and any waiver you signed.

Some operators collect health, allergy, dietary, mobility or emergency-contact information for safety reasons. That is special category data under Article 9 GDPR. The operator is responsible for the lawful basis and the Article 9 condition; we process it on their instructions and require it to be collected through the fields provided for the purpose.

5. AI features

Some features of the Service use artificial intelligence supplied by OpenAI and Anthropic, which act as our sub-processors:

  • AI-assisted features for operators: content assistance, summarisation, translation, reporting and pricing suggestions.

  • The AI Sales Assistant: an operator may embed this on its own website. Where an operator has enabled it, what a guest types into it is processed to answer them and to create their booking. The assistant identifies itself as an automated assistant.

  • The AI Assistant for operators: an in-product assistant through which an operator manages its own account.

Under the terms on which we engage them, these providers do not train their models on customer data. AI features do not make decisions about a guest that produce legal or similarly significant effects within the meaning of Article 22 GDPR. The AI Sales Assistant carries out a guest's own request to book, and does not evaluate, score or profile them.

6. Messaging

Where an operator enables them, the Service sends booking notifications by e-mail, SMS and WhatsApp. Those messages are the operator's communications to its guests, and the operator is responsible for the consent required to send them and for honouring opt-outs. We record delivery and opt-out status so that the Service does not message someone who has opted out.

Where an operator has paired a personal WhatsApp account, the messages, contacts and media that WhatsApp makes available to that connection are processed on servers we operate in Germany. The operator instructs us to do that when it pairs the account, and remains the controller of everything that connection exposes, including conversations unrelated to a booking.

7. Who we share personal data with

7.1 Our suppliers (sub-processors)

We use suppliers to run the Service, including hosting, payments, e-mail and SMS delivery, analytics, error monitoring, support messaging and AI. They act only on our instructions, under written data protection terms no less protective than our own obligations, and we remain responsible for them.

The current list, with each supplier's purpose, processing location and transfer safeguard, is at Annex E-2 of the Terms and Conditions. Because it is published as part of the Terms, it is versioned and dated, and the list in force on any past date can be established. Operators are given at least 30 days' notice before a supplier is added or replaced, and may object on reasonable data-protection grounds.

7.2 Parties that decide for themselves

Some organisations receive personal data in connection with the Service but decide their own purposes and are not our suppliers. They include OTA and channel-manager platforms, including GetYourGuide, Viator, Google Things To Do, Project Expedition and the other channels an operator connects, and Stripe, for its own regulatory, fraud-prevention and anti-money-laundering obligations. Each has its own privacy notice.

Where an operator connects its own tools, such as an automation platform, an analytics container or an AI assistant, it sends data to a destination it controls, and it is the controller of that data from the point it leaves the Service.

7.3 Public authorities

We transmit invoicing data to the Greek tax authority (AADE, via myDATA) and, where an operator has enabled Italian electronic invoicing, to the Agenzia delle Entrate. These are disclosures required by law.

We may also disclose personal data where we are legally obliged to, to establish or defend legal claims, or to protect the rights and safety of people or of the Service.

7.4 Business transfers

If CaptainBook is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of it. We will give notice before your data becomes subject to a different privacy policy.

8. International transfers, retention and security

8.1 Where data is processed

Personal data is hosted primarily in the European Union. Some suppliers process data in the United States or other third countries. Where we transfer personal data outside the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with the UK Addendum and Swiss adaptations where relevant, and we carry out a transfer impact assessment where one is required.

8.2 How long we keep it

DataRetentionOperator account and Service dataFor the life of the subscription. After it ends, an operator may export for 30 days; we then delete from active systems within 30 days, and from backups on the backup rotationRecords of terms acceptance, cancellation attempts, renewal notices and retention offers24 months from the event they record, so that we can defend payment disputes and chargebacks, whose windows run to about 18 monthsInvoicing and accounting recordsAs required by Greek tax lawSupport correspondenceWhile needed to support you and to resolve any related disputeWebsite analyticsAs stated in the Cookie PolicyGuest dataDecided by the operator, subject to the periods above

8.3 Keeping it safe

We apply role-based access control with least-privilege defaults and multi-factor authentication for administrative access; encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); segregated environments; managed WAF and DDoS protection; centralised logging and monitoring; secure development with peer review and dependency scanning; independent penetration testing; encrypted daily backups; and a documented incident response plan. The full measures are at Annex E-3 of the Terms.

No online service is completely secure, and there is a residual risk in transmitting data over the internet.

If a personal data breach occurs, we notify the Hellenic Data Protection Authority within 72 hours where Article 33 requires it, affected individuals where Article 34 requires it, and affected operators within 48 hours where we act as their processor.

9. Your rights

Where we are the controller, you have the right to:

  • access the personal data we hold about you, and receive a copy;

  • have inaccurate data corrected;

  • have data erased, where one of the grounds in Article 17 applies;

  • restrict processing while a question about it is resolved;

  • receive data you gave us in a portable form, and have it transmitted to another controller;

  • object to processing based on our legitimate interests, and to direct marketing at any time; and

  • withdraw consent where processing is based on it, without affecting what was done beforehand.

Write to info@captainbook.io, marked "Data Protection". We answer within one month, which we may extend by two further months for complex requests. We will tell you if we need to. We may ask for information to confirm who you are.

If you are a guest, and your request concerns data held by an operator, please contact the operator. We will refer you to them and let them know.

Complaints. You may complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece, www.dpa.gr, or to the supervisory authority where you live or work. We would rather you came to us first.

10. Cookies

We use strictly necessary cookies for authentication, session management, load balancing, security and checkout. We use functional cookies to remember your language, currency and interface preferences, and analytics and marketing cookies only with your consent.

Nothing outside the strictly necessary category is set until you choose. Continuing to browse, scrolling or closing the banner is not consent, and rejecting takes no more effort than accepting. You can change your mind at any time through the cookie settings link in the footer.

Full detail, including categories, providers and durations, is in the Cookie Policy and at Appendix G of the Terms.

Where an operator embeds our booking widget or the AI Sales Assistant on its own website, the operator is the operator of that website for cookie purposes and is responsible for its own banner and consent.

11. Children

The Service is not directed at children. Where a booking includes a minor, the operator is responsible for ensuring the information provided about that child is limited to what is necessary and is supplied by a person with parental responsibility. Where consent is the lawful basis and the individual is a child, Article 8 GDPR applies. In Greece, this applies from the age of 15.

12. Data Protection Officer

We have assessed whether we are required to appoint a Data Protection Officer under Article 37 GDPR and concluded that we are not. We are not a public authority; our core activity is providing booking and operations software, not large-scale processing of special category data nor regular and systematic monitoring of individuals on a large scale. Where special category data is present, it is collected at the discretion of individual operators for safety purposes, through defined fields, and processed by us as a processor on their instructions.

We keep that assessment under review and will appoint a Data Protection Officer, and publish the contact details here, if our processing changes.

Data protection enquiries: info@captainbook.io, marked "Data Protection".

13. Changes to this Policy

We may update this Policy. Where a change is material we will tell account holders at least 30 days before it takes effect, and the current version is always published here. Changes are not retroactive.

This Policy is published in English. Translations are provided for convenience; the English version prevails.

© 2021–2026 CaptainBook I.K.E.

Last updated: August 31, 2026

Controller: CaptainBook I.K.E.
Registered office: Petrou Protopapadaki 13, 84300 Naxos, Greece
VAT / TIN: EL801577488, Tax Authority Office of Naxos, Greece
Contact: info@captainbook.io
Tel.: +30 6949 453 468 / +30 6944 052 525
Effective date: 1 September 2026 for accounts created on or after that date; 1 October 2026 for accounts existing before it, together with the Terms and Conditions (Terms §21.15).

1. About this Policy

CaptainBook I.K.E. ("CaptainBook", "we", "us") provides booking and operations software to tour, activity, rental and experience operators. This Policy explains what we do with personal data.

It replaces the Privacy Policy last updated 3 January 2023 in its entirety.

It covers:

  • visitors to captainbook.io and our other websites;

  • operators, meaning the businesses that hold a CaptainBook account, and their staff and users;

  • resellers and partners, and their contacts;

  • prospective customers we contact or who contact us; and

  • guests, meaning the end customers who book an operator's experience, to the limited extent described in Section 3.2.

It does not cover what an operator does with personal data in its own business. Where you booked an experience, the operator is responsible for your data and you should read their privacy notice.

Words defined in the CaptainBook Terms and Conditions have the same meaning here. This Policy forms part of that Agreement.

2. The short version

  • We are the controller of data about operators, their users and our website visitors, and about people we market to.

  • We are a processor of data about guests, which operators put into the Service. The operator decides what happens to it; we act on their instructions.

  • We do not sell personal data, and we do not use guest data for our own marketing.

  • Personal data is hosted primarily in the European Union. Where a supplier processes it outside the EEA, we rely on the European Commission's Standard Contractual Clauses.

  • You can ask us for a copy of your data, ask us to correct or delete it, or object to what we do with it. See Section 9.

3. Our two roles

3.1 Where CaptainBook is the controller

We decide the purposes and means of processing, and this Policy applies in full, for:

  • account, contact and billing data of operators, resellers and their users;

  • data about visitors to our websites, and product and usage telemetry from the Service;

  • security, authentication and access logs;

  • fraud prevention, abuse detection and service improvement;

  • invoicing, accounting and statutory record-keeping;

  • records evidencing acceptance of our Terms, attempts to cancel a subscription, renewal notices sent and retention offers made; and

  • marketing to business contacts and prospective customers.

3.2 Where CaptainBook is a processor

Personal data relating to guests, their party members and an operator's own customers and prospects, meaning everything the operator or its users submit to, or generate through, the Service, is processed by us on the operator's instructions. The operator is the controller.

For that data:

  • the operator decides what is collected, why, and how long it is kept;

  • requests from guests must be made to the operator, not to us. If you contact us about data an operator holds, we will refer you to them and tell them you asked;

  • our obligations are set out in the Data Processing Agreement at Appendix E of the Terms.

We never act as joint controller with an operator unless we have agreed that in writing before the relevant feature is used.

4. What we collect, why, and on what basis

4.1 Operators, resellers and their users

WhatWhyLawful basisName, business name, e-mail, telephone, address, country, language, roleCreating and running your account, supporting you, sending service messagesArticle 6(1)(b), performance of a contractBilling and tax data: plan, billing currency, payment method reference, invoices, VAT numberCharging you, issuing invoices, meeting tax and accounting obligationsArticle 6(1)(b) and 6(1)(c)Authentication and security data: credentials, session and login records, IP address, device and browserSigning you in, keeping the account secure, investigating abuseArticle 6(1)(b) and 6(1)(f), legitimate interests in securing the ServiceProduct telemetry: features used, pages visited, errors encounteredUnderstanding how the Service is used, diagnosing faults, improving itArticle 6(1)(f), and Article 6(1)(a) where consent is required for non-essential cookiesSupport correspondence, chat history, call notesAnswering you and keeping a record of what was saidArticle 6(1)(b) and 6(1)(f)Records of terms acceptance, cancellation attempts, renewal notices and retention offersProving what was agreed and when, and defending payment disputes and chargebacksArticle 6(1)(f), establishing, exercising and defending legal claimsApproximate location derived from IP addressSecurity, fraud prevention and regional defaultsArticle 6(1)(f)

4.2 Website visitors

We collect pages viewed, referrer, approximate location from IP address, device and browser information, and cookie identifiers. Strictly necessary cookies are set on the basis of our legitimate interests and the ePrivacy exemption; functional, analytics and marketing cookies are set only with your consent, which you can withdraw at any time. See Section 10.

The providers we use on our own websites are Google Tag Manager and Google Analytics 4, Mixpanel, Hotjar, Customer.io, Framer, which hosts our marketing site, and the Meta Pixel. Hotjar records how a visitor moves through and interacts with a page, including mouse movement, scrolling and clicks; it is set only with your consent. The Cookie Policy describes each of them, and Section 8.1 explains what happens where a provider processes data outside the EEA.

4.3 Prospective customers and marketing

We process business contact details to tell operators about CaptainBook, on the basis of our legitimate interests in marketing to businesses (Article 6(1)(f)) or your consent (Article 6(1)(a)), depending on the channel and the country. Every marketing message carries an unsubscribe link, and you can opt out at any time by writing to info@captainbook.io.

We do not use guest data obtained through the Service for our own marketing.

4.4 Guests

Where you booked with an operator, the operator decides what is collected. Typically it includes your name and contact details, the booking itself, payment metadata (a processor reference, the last four digits of a card and the payment status; we never store full card numbers), messages exchanged, and any waiver you signed.

Some operators collect health, allergy, dietary, mobility or emergency-contact information for safety reasons. That is special category data under Article 9 GDPR. The operator is responsible for the lawful basis and the Article 9 condition; we process it on their instructions and require it to be collected through the fields provided for the purpose.

5. AI features

Some features of the Service use artificial intelligence supplied by OpenAI and Anthropic, which act as our sub-processors:

  • AI-assisted features for operators: content assistance, summarisation, translation, reporting and pricing suggestions.

  • The AI Sales Assistant: an operator may embed this on its own website. Where an operator has enabled it, what a guest types into it is processed to answer them and to create their booking. The assistant identifies itself as an automated assistant.

  • The AI Assistant for operators: an in-product assistant through which an operator manages its own account.

Under the terms on which we engage them, these providers do not train their models on customer data. AI features do not make decisions about a guest that produce legal or similarly significant effects within the meaning of Article 22 GDPR. The AI Sales Assistant carries out a guest's own request to book, and does not evaluate, score or profile them.

6. Messaging

Where an operator enables them, the Service sends booking notifications by e-mail, SMS and WhatsApp. Those messages are the operator's communications to its guests, and the operator is responsible for the consent required to send them and for honouring opt-outs. We record delivery and opt-out status so that the Service does not message someone who has opted out.

Where an operator has paired a personal WhatsApp account, the messages, contacts and media that WhatsApp makes available to that connection are processed on servers we operate in Germany. The operator instructs us to do that when it pairs the account, and remains the controller of everything that connection exposes, including conversations unrelated to a booking.

7. Who we share personal data with

7.1 Our suppliers (sub-processors)

We use suppliers to run the Service, including hosting, payments, e-mail and SMS delivery, analytics, error monitoring, support messaging and AI. They act only on our instructions, under written data protection terms no less protective than our own obligations, and we remain responsible for them.

The current list, with each supplier's purpose, processing location and transfer safeguard, is at Annex E-2 of the Terms and Conditions. Because it is published as part of the Terms, it is versioned and dated, and the list in force on any past date can be established. Operators are given at least 30 days' notice before a supplier is added or replaced, and may object on reasonable data-protection grounds.

7.2 Parties that decide for themselves

Some organisations receive personal data in connection with the Service but decide their own purposes and are not our suppliers. They include OTA and channel-manager platforms, including GetYourGuide, Viator, Google Things To Do, Project Expedition and the other channels an operator connects, and Stripe, for its own regulatory, fraud-prevention and anti-money-laundering obligations. Each has its own privacy notice.

Where an operator connects its own tools, such as an automation platform, an analytics container or an AI assistant, it sends data to a destination it controls, and it is the controller of that data from the point it leaves the Service.

7.3 Public authorities

We transmit invoicing data to the Greek tax authority (AADE, via myDATA) and, where an operator has enabled Italian electronic invoicing, to the Agenzia delle Entrate. These are disclosures required by law.

We may also disclose personal data where we are legally obliged to, to establish or defend legal claims, or to protect the rights and safety of people or of the Service.

7.4 Business transfers

If CaptainBook is involved in a merger, acquisition or sale of assets, personal data may be transferred as part of it. We will give notice before your data becomes subject to a different privacy policy.

8. International transfers, retention and security

8.1 Where data is processed

Personal data is hosted primarily in the European Union. Some suppliers process data in the United States or other third countries. Where we transfer personal data outside the EEA to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), together with the UK Addendum and Swiss adaptations where relevant, and we carry out a transfer impact assessment where one is required.

8.2 How long we keep it

DataRetentionOperator account and Service dataFor the life of the subscription. After it ends, an operator may export for 30 days; we then delete from active systems within 30 days, and from backups on the backup rotationRecords of terms acceptance, cancellation attempts, renewal notices and retention offers24 months from the event they record, so that we can defend payment disputes and chargebacks, whose windows run to about 18 monthsInvoicing and accounting recordsAs required by Greek tax lawSupport correspondenceWhile needed to support you and to resolve any related disputeWebsite analyticsAs stated in the Cookie PolicyGuest dataDecided by the operator, subject to the periods above

8.3 Keeping it safe

We apply role-based access control with least-privilege defaults and multi-factor authentication for administrative access; encryption in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent); segregated environments; managed WAF and DDoS protection; centralised logging and monitoring; secure development with peer review and dependency scanning; independent penetration testing; encrypted daily backups; and a documented incident response plan. The full measures are at Annex E-3 of the Terms.

No online service is completely secure, and there is a residual risk in transmitting data over the internet.

If a personal data breach occurs, we notify the Hellenic Data Protection Authority within 72 hours where Article 33 requires it, affected individuals where Article 34 requires it, and affected operators within 48 hours where we act as their processor.

9. Your rights

Where we are the controller, you have the right to:

  • access the personal data we hold about you, and receive a copy;

  • have inaccurate data corrected;

  • have data erased, where one of the grounds in Article 17 applies;

  • restrict processing while a question about it is resolved;

  • receive data you gave us in a portable form, and have it transmitted to another controller;

  • object to processing based on our legitimate interests, and to direct marketing at any time; and

  • withdraw consent where processing is based on it, without affecting what was done beforehand.

Write to info@captainbook.io, marked "Data Protection". We answer within one month, which we may extend by two further months for complex requests. We will tell you if we need to. We may ask for information to confirm who you are.

If you are a guest, and your request concerns data held by an operator, please contact the operator. We will refer you to them and let them know.

Complaints. You may complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, Greece, www.dpa.gr, or to the supervisory authority where you live or work. We would rather you came to us first.

10. Cookies

We use strictly necessary cookies for authentication, session management, load balancing, security and checkout. We use functional cookies to remember your language, currency and interface preferences, and analytics and marketing cookies only with your consent.

Nothing outside the strictly necessary category is set until you choose. Continuing to browse, scrolling or closing the banner is not consent, and rejecting takes no more effort than accepting. You can change your mind at any time through the cookie settings link in the footer.

Full detail, including categories, providers and durations, is in the Cookie Policy and at Appendix G of the Terms.

Where an operator embeds our booking widget or the AI Sales Assistant on its own website, the operator is the operator of that website for cookie purposes and is responsible for its own banner and consent.

11. Children

The Service is not directed at children. Where a booking includes a minor, the operator is responsible for ensuring the information provided about that child is limited to what is necessary and is supplied by a person with parental responsibility. Where consent is the lawful basis and the individual is a child, Article 8 GDPR applies. In Greece, this applies from the age of 15.

12. Data Protection Officer

We have assessed whether we are required to appoint a Data Protection Officer under Article 37 GDPR and concluded that we are not. We are not a public authority; our core activity is providing booking and operations software, not large-scale processing of special category data nor regular and systematic monitoring of individuals on a large scale. Where special category data is present, it is collected at the discretion of individual operators for safety purposes, through defined fields, and processed by us as a processor on their instructions.

We keep that assessment under review and will appoint a Data Protection Officer, and publish the contact details here, if our processing changes.

Data protection enquiries: info@captainbook.io, marked "Data Protection".

13. Changes to this Policy

We may update this Policy. Where a change is material we will tell account holders at least 30 days before it takes effect, and the current version is always published here. Changes are not retroactive.

This Policy is published in English. Translations are provided for convenience; the English version prevails.

© 2021–2026 CaptainBook I.K.E.

© 2021-2026 CaptainBook.io - All rights reserved.
Legal Terms - Privacy policy

© 2021-2026 CaptainBook.io - All rights reserved.
Legal Terms - Privacy policy

© 2021-2026 CaptainBook.io - All rights reserved.
Legal Terms - Privacy policy