GDPR · Privacy by Design

Privacy Notice

1. Who this notice covers

VNCARRAS Private Charters · Greece ("VNCARRAS") operates this website as a luxury charter customer-acquisition and enquiry service in Greece. Privacy requests may be sent to charters@vncarrascharters.com.

No payment data at enquiry stage. VNCARRAS does not ask for card numbers, bank credentials, PINs, passwords, passport details or payment through the public enquiry form or transactional enquiry-confirmation email.

2. Data we collect

When you submit a charter enquiry we may collect the information you choose to provide, including your name, email address, mobile/WhatsApp number, preferred contact method, requested yacht, dates, guest count, budget, occasion, charter preference and free-text notes. We also record the unique VNCARRAS enquiry reference, request status, yacht snapshot and limited campaign/source parameters present in the page URL (for example UTM source/campaign) so we can understand how the enquiry reached VNCARRAS and preserve reliable referral records.

We do not intentionally collect special-category personal data. Please do not place medical information, identity-document data, payment details or other sensitive information in the notes field.

3. Why we use the data

We use enquiry data to:

The primary legal basis for handling the enquiry is Article 6(1)(b) GDPR: taking steps at your request before a possible charter contract. Where necessary, Article 6(1)(f) GDPR (legitimate interests) may apply to service security, fraud prevention, referral attribution and the protection of legal/business claims. Article 6(1)(c) may apply where a legal obligation requires processing.

4. No advertising use from an enquiry

Submitting an enquiry does not subscribe you to advertising or promotional messages. VNCARRAS does not use the contact details submitted through this enquiry form for promotional email, promotional WhatsApp/SMS or audience advertising. If VNCARRAS introduces an optional marketing subscription in the future, it will be separate, voluntary and based on a distinct opt-in that can be withdrawn.

5. Who may receive the data

Access is limited to parties that need the information to operate or handle the request. These may include:

We do not sell enquiry personal data to advertisers or data brokers.

6. International transfers

Some technology providers supporting the service may process limited data outside the European Economic Area. Where required, transfers are handled using recognised legal safeguards such as adequacy mechanisms and/or Standard Contractual Clauses. VNCARRAS selects established providers and limits the information used by each provider to the service function required.

7. How long we keep enquiry data

Closed or unsuccessful enquiries are normally retained for up to 12 months after the last substantive contact, then deleted or anonymised unless a longer period is reasonably required for a live dispute, fraud/security matter or legal obligation. Where an enquiry becomes a confirmed charter/referral, core referral and enquiry-history records may be retained for up to 24 months after completion/last relevant transaction to preserve documented lead origin and protect legitimate contractual/legal claims. The responsible vessel operator may have separate statutory retention duties for its own booking/charter records.

8. Secure request-status link and QR

Each enquiry receives a long private status token. The status page intentionally excludes your email address and phone number. The QR code generated by VNCARRAS contains only that private status URL; it does not embed your name, email, phone or payment information. Treat the status link/QR as private and avoid posting it publicly.

9. Your GDPR rights

Subject to the conditions of the GDPR, you may request access, correction, erasure, restriction, portability (where applicable) or object to processing based on legitimate interests. You may contact charters@vncarrascharters.com. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) or another competent supervisory authority.

10. Security and data minimisation

VNCARRAS applies purpose limitation, minimal collection, server-side validation, private API credentials, restricted public status pages and encrypted HTTPS transport. No internet service can promise absolute security; if a security incident materially affects your rights, applicable notification duties will be followed.

11. Changes to this notice

We may update this notice when the service, providers or legal setup changes. Material changes will be reflected by a new version date.

Privacy Notice version 2026-09-23. This page is designed to support GDPR/ePrivacy transparency for the current VNCARRAS MVP and should be reviewed by qualified Greek legal counsel as the commercial/legal entity and operational model develop.