Privacy Policy

North Routes > Privacy Policy

Last updated: 7 July 2026

North Routes respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how we collect, use, store, share and protect your personal data when you visit our website, request a quote, make a booking, contact us or use our private transfer, chauffeur or private tour services.

Please read this Privacy Policy carefully.

1. Who We Are

North Routes is operated by:

CHANTZARIDOU OLGA TOU CHARALAMPOU
Greek business name: ΧΑΝΤΖΑΡΙΔΟΥ ΟΛΓΑ ΤΟΥ ΧΑΡΑΛΑΜΠΟΥ
Legal form: Sole Proprietorship
Registered address: 15 Frixou Street, Thessaloniki, Greece
G.E.MI. No.: 193225206000
EUID: ELGEMI.193225206000
VAT No.: 127320791
Email: book@northroutes.gr

For the purposes of applicable data-protection law, including the General Data Protection Regulation (“GDPR”), we are the data controller of the personal data described in this Privacy Policy.

If you have any questions about this Privacy Policy or wish to exercise your data-protection rights, please contact us at:

book@northroutes.gr

2. Personal Data We Collect

We may collect and process the following categories of personal data.

Information you provide when making a booking or requesting a quote

This may include:

  • Full name
  • Email address
  • Telephone number and WhatsApp number, where provided
  • Pickup location
  • Destination
  • Date and time of travel
  • Flight number, where provided
  • Number of passengers
  • Luggage information
  • Vehicle preferences
  • Child-seat requests
  • Booking reference number
  • Booking notes and special travel requests
  • Information you provide when changing or cancelling a booking

Payment and transaction information

When you make an online payment, we may receive information such as:

  • Payment status
  • Payment amount
  • Transaction or order reference
  • Payment date
  • Refund information, where applicable

Payments may be processed through secure third-party payment providers, including Viva.com where this payment option is used. North Routes does not store your complete debit-card or credit-card details.

Communication information

When you contact us by email, phone, WhatsApp, contact form, social media or another communication channel, we may collect:

  • Your contact details
  • The content of your message
  • Booking information connected to your request
  • Any information you voluntarily provide to us

Technical and website information

When you use our website, we may automatically collect limited technical information, such as:

  • IP address
  • Device type
  • Browser type
  • Operating system
  • Pages visited
  • Date and time of visits
  • Referring website or source
  • Cookie preferences
  • General website usage information

This information may be collected through cookies, website logs, analytics tools and similar technologies. Please read our Cookie Policy for more information.

3. Information About Other Passengers

If you make a booking on behalf of another person, you may provide us with their name, contact details or travel information.

You are responsible for ensuring that you have the right to provide this information and that the relevant passenger is aware that North Routes will process their data in accordance with this Privacy Policy.

Please provide only the information that is necessary for us to organise and deliver the booked service.

4. How We Use Your Personal Data

We use personal data only where necessary and for legitimate business purposes.

We may use your personal data to:

  • Respond to your enquiry or quote request
  • Create, confirm, manage and fulfil your booking
  • Arrange your pickup, route, vehicle, driver and requested services
  • Contact you about your booking, including reminders, changes, delays, cancellations or service-related matters
  • Process payments, refunds and invoices
  • Provide customer support
  • Manage airport pickup arrangements and travel details supplied by you
  • Respond to complaints, disputes or claims
  • Prevent fraud, misuse, security incidents or unlawful activity
  • Improve our website, booking process and customer service
  • Meet our accounting, tax, legal and regulatory obligations
  • Send marketing communications only where you have given consent or where permitted by applicable law
  • Comply with requests from public authorities, courts or regulatory bodies where we are legally required to do so

5. Legal Bases for Processing

Under the GDPR, we must have a valid legal basis for using your personal data.

Depending on the situation, we process your personal data on one or more of the following legal bases.

Performance of a contract

We process your personal data when it is necessary to take steps at your request before entering into a contract or to perform a contract with you.

This includes processing data to:

  • Respond to a quote request
  • Confirm and manage your booking
  • Arrange the transfer, chauffeur service or private tour
  • Communicate with you about your journey
  • Handle booking changes, cancellations and refunds

Legal obligation

We may process and retain certain personal data where necessary to comply with legal obligations, including accounting, tax, invoicing and record-keeping requirements.

Legitimate interests

We may process personal data where it is necessary for our legitimate interests, provided that those interests are not overridden by your rights and freedoms.

Our legitimate interests may include:

  • Managing and protecting our business
  • Improving customer service
  • Maintaining website and booking-system security
  • Preventing fraud and misuse
  • Handling complaints and disputes
  • Protecting our legal rights
  • Keeping appropriate business and operational records

Consent

We rely on your consent where this is required by law, including for certain marketing communications and non-essential cookies.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

6. Who We Share Your Data With

We do not sell, rent or trade your personal data.

We may share your personal data only when necessary with trusted third parties that help us operate our business and provide our services.

These may include:

  • Drivers, transport partners or subcontracted service providers who need relevant booking details to provide the transfer or service
  • Website hosting, website-maintenance and technical-support providers
  • Booking-system providers, including the Chauffeur Booking System and related booking-management tools
  • E-commerce and payment-management tools, including WooCommerce where used
  • Payment service providers, including Viva.com where used for online payments
  • Email and communication service providers
  • Mapping, location and route-planning services, including Google Maps or Google Places where used through the booking process
  • Accountants, legal advisers, insurers and professional advisers
  • Public authorities, tax authorities, law-enforcement bodies, courts or regulatory bodies where required by law or necessary to protect our legal rights

We share only the personal data that is relevant and necessary for the relevant purpose.

Where third parties process personal data on our behalf, we take reasonable steps to ensure that they are required to protect your data and use it only in accordance with applicable law and our instructions.

7. International Data Transfers

Some of the service providers we use may process or store personal data outside the European Economic Area (“EEA”).

For example, this may occur where we use international providers for website services, analytics, mapping, communications, payment processing or cloud-based tools.

Where personal data is transferred outside the EEA, we will take appropriate steps to ensure that the transfer is lawful and that your information receives an adequate level of protection. These steps may include the use of an adequacy decision, Standard Contractual Clauses approved by the European Commission or other appropriate safeguards recognised under applicable data-protection law.

8. How Long We Keep Your Data

We keep your personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, tax, dispute-resolution and operational requirements.

In general:

  • Booking, transfer and customer-service records are kept for up to 5 years after the relevant service or transaction, unless a longer retention period is required by law or necessary to deal with a legal claim.
  • Invoice, payment and accounting records are kept for the period required by applicable tax and accounting legislation.
  • Cancellation and refund records are retained for as long as necessary to manage the relevant transaction, resolve potential disputes and comply with legal obligations.
  • Enquiries and communications that do not result in a booking are normally retained for up to 2 years, unless longer retention is necessary for a legitimate business or legal reason.
  • Marketing information is retained until you withdraw consent, unsubscribe or ask us to stop contacting you, unless we have another lawful reason to retain it.
  • Cookie-related information is retained according to the periods described in our Cookie Policy or cookie-consent tool.

We may retain information for longer where this is necessary to establish, exercise or defend legal claims, respond to authorities or meet a legal obligation.

9. Marketing Communications

We may send you marketing communications about North Routes, including news, services, offers or travel-related updates, only where you have given consent or where otherwise permitted by applicable law.

You can unsubscribe from marketing emails at any time by:

  • Clicking the unsubscribe link in the email, where available
  • Contacting us at book@northroutes.gr
  • Updating your communication preferences where that option is available

Even if you opt out of marketing communications, we may still contact you about an existing booking, payment, cancellation, safety matter or other service-related issue.

10. Cookies and Similar Technologies

Our website may use cookies and similar technologies to operate properly, remember preferences, improve performance, analyse website traffic and, where applicable, support marketing activity.

Some cookies are strictly necessary for the website and booking process to function. Other cookies, such as analytics or marketing cookies, may require your consent.

For detailed information about the cookies we use and how you can manage your preferences, please read our Cookie Policy.

11. Data Security

We take reasonable technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

These measures may include secure website connections, access controls, password protection, system updates, secure payment processing and restricted access to booking information.

However, no internet transmission, website or electronic storage system can be guaranteed to be completely secure. You should also take reasonable steps to protect your own devices, passwords and personal information.

12. Your Rights

Subject to the conditions and limitations set out in applicable law, you have the right to:

  • Request access to the personal data we hold about you
  • Request correction of inaccurate or incomplete data
  • Request deletion of your personal data in certain circumstances
  • Request restriction of processing in certain circumstances
  • Object to processing based on our legitimate interests
  • Request portability of certain data that you have provided to us
  • Withdraw consent at any time where processing is based on consent
  • Object to direct marketing at any time
  • Lodge a complaint with a supervisory authority

To exercise any of these rights, please contact us at:

book@northroutes.gr

We may need to verify your identity before responding to a request. We will respond within the time periods required by applicable law.

You also have the right to lodge a complaint with the competent data-protection authority. In Greece, this is the Hellenic Data Protection Authority.

13. Automated Decision-Making

North Routes does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on you.

Our booking system may automatically calculate availability, routes, prices or booking information based on the details you provide. However, this does not replace human review where needed and does not constitute automated decision-making of the type described above.

14. Children

Our services are intended to be booked by adults.

We do not knowingly collect personal data directly from children for independent booking purposes. A parent, guardian or responsible adult may provide limited information about a child where necessary to arrange a child seat or safely provide a booked transfer service.

Please do not provide unnecessary information about children.

15. Third-Party Websites and Services

Our website may contain links to third-party websites, social-media platforms, payment providers, map services or other external services.

We are not responsible for the privacy practices, content or security of third-party websites or services. We recommend that you read the privacy policy of any third party before submitting personal data to them.

16. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, website, legal requirements or data-processing practices.

The latest version will always be available on our website. The “Last updated” date at the top of this page shows when this Privacy Policy was most recently revised.

17. Contact Us

For questions about this Privacy Policy, your personal data or your privacy rights, please contact:

North Routes
Operated by: CHANTZARIDOU OLGA TOU CHARALAMPOU
Email: book@northroutes.gr
Address: 15 Frixou Street, Thessaloniki, Greece
G.E.MI. No.: 193225206000
VAT No.: 127320791

hello.