The short version: this website does not sell anything. You tell us where you want to go, that message arrives in an inbox, and a person replies. There is no account, no checkout and no card. We do not sell data, we run no advertising trackers, and we do not build a profile of you.
§1. Who is responsible
The data controller is [LEGAL NAME], [ADDRESS], Greece. ΑΦΜ [VAT NUMBER]. Contact for anything on this page: privacy@ktelio.gr.
We have not appointed a Data Protection Officer. At this size and with this kind of processing, Article 37 does not require one.
§2. What we collect
Ktelio is a booking service, and the booking is arranged by email, not on this page. The website exists to take your enquiry; everything after that happens in a conversation with a person. Nothing here charges you and there is no account to create, which makes the list short.
| What | When | Why we need it |
|---|---|---|
| Your name | On the request form | So the reply is addressed to a person, and so the operator has a name if we go on to buy a ticket for you |
| Email address | On the request form | It is where the answer goes. Without it there is no way to reply |
| Phone number | Optional, on the request form | Only used if something about your request cannot be settled by email |
| Journey details — route, date, number of travellers, anything you type in the notes | On the enquiry form | It is the question you are asking us, and what we go and look up |
| Page views | Every visit | Aggregate counts of which pages get read, and of which city pairs are searched for — so we know which routes to add next. Route names only, never anything you type into a form. No cookie, no identifier that follows you to another site |
There is no payment on this site, so there is no payment data. No card number, no billing address, no cardholder name — not stored, not transmitted, not seen. If that changes, this page changes first and you will be told what is collected before you are asked for it.
We do not knowingly collect data about anyone under 18. Requests should come from an adult.
§3. Why, and on what legal basis
- To answer you — GDPR Art. 6(1)(b), steps taken at your request before any contract. You asked a question; the data is what lets us answer it.
- Our legitimate interests — Art. 6(1)(f). Keeping the site up, and keeping a record of what we quoted so that we can stand behind it. Weighed against your interests and kept to the minimum that does the job.
- A legal obligation — Art. 6(1)(c). Once we do sell you something, Greek tax law sets how long the record has to be kept, and that overrides our own preference to delete.
- Your consent — Art. 6(1)(a), and only for the newsletter. One click to withdraw, and we will not ask a second time.
Answering a request is not the same as marketing to you. We do not add you to anything because you wrote to us.
§4. Who else sees it
Two companies, because two services run on this site. Each is listed with what it actually receives. Two things that used to be here are gone: live chat, removed along with the third-party script and cookies it brought, and Google Fonts — the typefaces are now served from this site, so no font request leaves for anyone else.
| Who | What they get | Where |
|---|---|---|
| Web3Forms delivers the request form |
Everything you typed into the form, so it can be turned into an email | EU/US — transfers rely on the EU–US Data Privacy Framework and standard contractual clauses |
| Vercel hosting and page counts |
Server logs including IP, and aggregate analytics with no cookie and no cross-site identifier | EU region |
The KTEL operator. If you go ahead and we buy a ticket on your behalf, the operator gets the passenger name and a contact detail, because that is what issuing a ticket requires. They are a separate controller for what they then do with it. Nothing is sent to any operator while you are only asking.
We do not sell personal data, and we do not share it with advertisers, data brokers or anyone else not named above.
§5. How long we keep it
- A request that goes nowhere — deleted within 12 months. If you ask sooner, sooner.
- A request that became a booking — kept as long as Greek tax and accounting law requires for the transaction record, and no longer for anything else.
- Analytics — aggregate from the start. There is nothing in it to delete, because there is nothing in it that is about you.
§6. Your rights
Under the GDPR you can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to processing based on legitimate interests, ask us to restrict it, or ask for it in a portable format. Write to privacy@ktelio.gr and we will answer within one month.
No charge, and no need to explain why. We may ask one question to establish that the request comes from you, which is a safeguard for you rather than an obstacle.
§7. Cookies and what runs on the page
Ktelio itself sets no cookies. There is no consent banner on this site, and that is not an oversight — there is nothing to consent to on our side.
One thing does store data, and it is worth naming plainly:
- Your browser’s own storage. While you move through a request, the
route and date you picked are held in
sessionStorageso the next page knows what you chose. It never leaves your device and it is gone when you close the tab. This is not a cookie and does not require consent.
On the typefaces. They used to load from Google’s servers, which meant your IP address reached Google on every page you opened. A German court held in 2022 that doing this without consent can breach the GDPR. Since August 2026 the font files sit on this site and are served from it, so no request for them leaves for anyone else and there is nothing here to consent to. We are naming the old arrangement rather than quietly deleting the paragraph, because if you visited before that date it did happen.
§8. What we do not hold
Sometimes the clearest statement is the negative one. Ktelio has:
- no card numbers, no billing addresses, no payment data of any kind
- no passwords, because there are no accounts
- no advertising or cross-site tracking of any kind
- no profile of you, and no automated decision-making that affects you
The site is served over HTTPS. What we do hold sits in the inbox and the services named in §4, each behind its own login with two-factor authentication. If a breach ever puts your rights at risk, we notify the Hellenic Data Protection Authority within 72 hours and tell you directly where the regulation requires it.
§9. When this changes
Two things on the horizon will change what is on this page: taking payment, and self-hosting the fonts. Neither has happened. When either does, this page is updated before the change goes live, not after, and the date at the foot of the page moves.
§10. Complaints and contact
privacy@ktelio.gr reaches a person.
You also have the right to complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1–3, 115 23 Athens, dpa.gr, or to the supervisory authority where you live.