Privacy Policy
Data controller
The data controller is Omnia Vincit Amor Single Member P.C., trading as Bandanna Mykonos, at Bandanna Mykonos, Ano Mera Road, 84600 Mykonos, Cyclades, Greece.
For privacy requests you can contact us at [email protected] or +30 22890 71800.
Personal data we process
- Contact and reservation details you provide, such as your name, email address, phone number, party size, requested date and time, and message.
- Information needed for your visit, such as dietary, accessibility, event, or other special requests.
- Basic website and security data, such as your IP address, browser, device, pages visited, and access time.
- Website performance data collected through Cloudflare Web Analytics when you allow analytics.
- Your Google Maps choice and its consent receipt, including a random identifier, page, time, and timezone.
- Information you send in a privacy request or other legal communication.
Please do not include sensitive or unnecessary personal information unless we need it for your request, for example an allergy or accessibility need relevant to your reservation.
Purposes and legal bases
- To respond to reservation, contact, private-event, and general information requests: Article 6(1)(b) GDPR for pre-contractual steps requested by you and Article 6(1)(f) GDPR for our legitimate interest in handling hospitality communications.
- To manage bookings, seating, guest preferences, service notes, and operational follow-up: Article 6(1)(b) GDPR and, where applicable, Article 6(1)(f) GDPR.
- To protect the website, prevent abuse, maintain service continuity, and troubleshoot technical issues: Article 6(1)(f) GDPR.
- To measure and improve website performance through cookie-free analytics when you consent: Article 6(1)(a) GDPR.
- To remember, record, and apply your Google Maps choice: Article 6(1)(f) GDPR for the necessary record and Article 6(1)(a) GDPR when Google Maps loads based on consent.
- To comply with legal, accounting, tax, regulatory, or authority requests: Article 6(1)(c) GDPR.
- To establish, exercise, or defend legal claims: Article 6(1)(f) GDPR.
- Where a specific processing activity requires consent, such as optional marketing or non-essential tracking introduced in the future, Article 6(1)(a) GDPR. Consent can be withdrawn at any time.
Providing data
Providing the data marked or requested as necessary in forms is required if you want us to review and answer your request. If you do not provide that data, we may be unable to respond, confirm a booking, or process the request.
Providing optional information in free-text fields is voluntary.
Recipients of personal data
Personal data may be handled by authorized personnel and by service providers that help us operate the website, communicate with guests, and manage reservations.
These recipients process data under contractual or legal confidentiality obligations and only to the extent necessary for the relevant purpose. We do not sell personal data.
- Website hosting, maintenance, and security providers.
- Cloudflare, for website delivery, security, performance analytics, and consent receipts.
- Email, phone, messaging, and reservation service providers.
- Google, if you choose to load a map.
- Social and other third-party services, if you choose to visit them.
- Professional advisors, public authorities, or legal advisors where disclosure is required by law or necessary to protect rights.
International transfers
Some providers may process personal data outside the European Economic Area. Where required, we use a lawful safeguard such as an adequacy decision or the European Commission’s Standard Contractual Clauses.
You may request information about applicable transfer safeguards by contacting [email protected], unless those safeguards are already made available directly by the relevant provider.
Retention periods
- Reservation, contact, and event requests are kept for the time needed to manage the request and for a reasonable period afterwards, generally up to 12 months after the last relevant contact unless a longer period is required by law or needed for legal claims.
- Technical logs and security events are kept for the period reasonably necessary to ensure security, investigate incidents, and meet legal obligations.
- Consent receipts are kept for 395 days.
- Website performance data is kept under the applicable Cloudflare service settings.
- Data connected to accounting, tax, or legal obligations is kept for the period required by applicable law.
- Data connected to legal claims may be kept for the limitation period applicable to the claim.
Your rights
Under GDPR, where the legal conditions are met, you may have the right to access your personal data, request rectification, request erasure, request restriction, object to processing based on legitimate interests, receive data portability, withdraw consent, and lodge a complaint with a supervisory authority.
To exercise your rights, contact [email protected].
- In Greece, the supervisory authority is the Hellenic Data Protection Authority.
- In Italy, the supervisory authority is the Garante per la protezione dei dati personali.
Cookies and external content
For information about cookies and similar technologies, please read the separate Cookies Policy.
Cloudflare Web Analytics loads only when you allow analytics. It measures website performance without cookies or browser storage.
Google Maps loads only when you allow external content or select the map’s load button. Third-party services process personal data under their own policies when you choose to use them.
Security measures
We use appropriate safeguards to protect personal data against unauthorized access, loss, alteration, or disclosure.
Policy updates
We may update this Privacy Policy from time to time. The date shown at the top of this page indicates the latest revision.

