Privacy Policy

Last Updated 22/09/2026

Scope of this Privacy Policy

This Privacy Policy informs you of our policies and procedures regarding the collection, use, and disclosure of Personal Data we collect from you as Visitors, when you use this Site www.hosperly.com and Hosts, when you register to the Services (“Hosperly”).

By accessing and using this Site and the Services, you confirm that you have read and fully understood this Privacy Policy, that you agree to the collection and the usage of your own and others’ Personal Data in accordance with the Privacy Policy and that you have the authority to provide Us with all information submitted by you via the Site and the Services, including but not limited to Personal Data of third parties. 

Who we are

We or Us means Tourmie P.C, a company duly established under the laws of the Hellenic Republic, having its registered office at Nikolaou Stavrinidi 16, Heraklion, Crete, Greece, which owns and operates Hosperly.

Definitions

Hosts means hotels, property managers and other accommodation businesses that use the Services.
Account Data means information relating to a Host’s account with Hosperly, including the Host’s name, contact details, billing and subscription information, and other information necessary for the billing and invoicing of the Services and for our communication with the Hosts.

Guests means individuals who make or hold a reservation at a property managed through the Services.

Services means Hosperly’s hosted, internet accessible property management software, designed to help hotels and property managers handle their properties, reservations, Guests and daily operations, and refers to all services provided by Us to Hosts, which may include, among others, the management of booking and payment system, communications with Guests, as well as the integration and synchronization of content with third-party channels via channel managers and functionalities.

Controller means the entity which determines the purposes and means of the Processing of Personal Data.

Processor means the entity which Processes Personal Data on behalf of and in accordance with the documented instructions of the Controller.

Visitor means a person simply visiting our Site, as well as the person interacting with our Site, e.g., by filling in and sending the contact form, or ordering our Newsletter. 

We as Controller

Α. When you visit our Site

We use cookies and similar technologies in connection with this Site and the Services. Cookies and similar technologies collect 

  • Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions and operating system and platform;
  • Information about your visit, including the full Uniform Resource Locators (URL), clickstream to, through and from our website (including date and time), products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs) and methods used to browse away from the page.

These technologies may be used to operate, secure and improve the Site and the Services, remember user preferences, understand how the Site and the Services are used and, where applicable, support marketing activities. There are four types of cookies:

Essential Cookies

Essential cookies are necessary for the operation, security and functionality of the Site and the Services. They may enable users to log in, maintain an authenticated session, remember security settings, prevent fraudulent activity, maintain system stability and provide access to features requested by the user.

Because these cookies are necessary to provide the relevant functionality or maintain the security of the Site and the Services, they generally cannot be disabled without affecting their operation.

Functional Cookies

Functional cookies allow the Site and the Services to remember choices and preferences made by users and provide enhanced functionality. For example, they may remember language, region, interface or other settings selected by the user and help provide a more personalised experience.

Where required by applicable law, we will obtain the user’s consent before placing or using functional cookies that are not strictly necessary for the operation of the Services.

Analytics Cookies

Analytics cookies and similar technologies help us understand how users interact with the Site and the Services, including which features are used, how frequently the Services are accessed and how users navigate through the Services. We may use this information to monitor performance, identify errors, understand usage patterns and improve the functionality, performance and user experience of the Services.

Where required by applicable law, we will obtain the user’s consent before using analytics cookies or similar technologies.

Where analytics technologies are provided by third parties, those third parties may process certain information. Details of applicable third-party technologies may be provided through our cookie consent mechanism or cookie notice. Please review the third-party terms.

Marketing Cookies

Marketing cookies and similar technologies may be used to support advertising, marketing and promotional activities, including measuring the effectiveness of campaigns, understanding interactions with our communications and, where applicable, presenting content or advertisements that may be more relevant to users.

We will only use marketing cookies or similar technologies, after obtaining the user’s consent.

Users may withdraw or modify their consent to the use of non-essential cookies at any time through the cookie settings or consent mechanism made available through the Site and the Services. Withdrawing consent will not affect the lawfulness of processing carried out before the withdrawal.

B. For billing and contractual administration

We process Account Data as necessary to manage our contractual relationship with Hosts, including account administration, subscription management, invoicing, payment processing, contract management and related communications.

C. Contact Form

We process Personal Data submitted through our contact form to respond to enquiries, provide requested information, communicate with the relevant individual and, where appropriate, follow up on requests or potential business opportunities.

D. Newsletter 

If you wish to receive our Newsletter, for example, announcements about new offers and actions of ours, you may enter your e-mail address on the Site to specifically request registering for the Newsletter. Your email address is solely used for the purpose of sending our Newsletter, and you are removed from the Newsletter recipient list once you choose to unsubscribe. You may be removed from this list, easily and without cost, by selecting the “unsubscribe” link within the e-mail content. You can also send an email to marketing@hosperly.com

To send the Newsletter, we use HubSpot, a US based company, as a provider of an electronic communication platform. For the privacy policy of https://legal.hubspot.com/privacy-policy

E. Compliance with legal obligations
We may process Personal Data where necessary to comply with legal or regulatory obligations applicable to us, including accounting, tax, record-keeping, security and other mandatory requirements.

F. Legitimate interests
We may process Personal Data where necessary for our legitimate interests, provided that such interests are not overridden by your rights and freedoms. Such interests may include operating and improving the Services, maintaining the security and integrity of our systems, preventing fraud or misuse, managing our business relationships, and defending or exercising legal claims.

We as Processor 

When the Host uses our Services to process Guest or other third-party Personal Data, the Host determines the purposes and means of processing and Hosperly acts as a Processor under the Host’s documented instructions, described in the Data Processing Addendum, the DPA [hyperlink]. 

Information Sharing and Disclosure

We do not sell your Personal Data and will not share or disclose any of your Personal Data with third parties except as described in this Policy. We do not share personal information about you with third parties for their marketing purposes (including direct marketing purposes).

We may share Personal Data with our associates who assist us to provide this Site and the Services, and we take measures to ensure that our associates provide the same level of data protection as we do.

We may disclose Personal Data to government or law enforcement officials, if we receive a legally binding request, and, if permitted, we will notify you of the disclosure. 

We may share or transfer your Personal Data in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company. You will be notified of any change in ownership or use of your Personal Data, as well as any choices you may have regarding your Personal Data.

How We Process Personal Information

We collect and process Personal Data in a transparent manner, to the extent necessary for specified, explicit, and legitimate purposes, and do not process it further in a manner incompatible with those purposes. We take care that the data we collect is accurate and, when necessary, updated. We take all reasonable steps to immediately delete or rectify personal data if inaccurate. We process data in a way that guarantees their security, including their protection against unauthorized or unlawful processing and accidental loss, destruction, or degradation, using appropriate technical or organizational measures. We are ready to prove at any moment how we adhere to the above principles. We take the appropriate technical and organizational measures for the security, confidentiality, integrity, and availability of the data. We will retain your personal data only as long as is necessary, and then we will delete it.

Data Subject Rights

The General Data Protection Regulation or “GDPR” provides protection on certain rights with respect to their Personal Data collected by Us via the Site or when Hosts purchase the Services.  

When Hosperly processes personal data via our Services, the Hosts (as the Controllers) are responsible for the requests of the individuals and individuals should address their requests to them. 

In summary, the rights under GDPR include the right:

  1. To be informed about the collection and use of your Personal Data;
  2. To request access to your Personal Data, or to restrict processing of your Personal Data, and to receive your Personal Data or have it transmitted to another Controller;   
  3. To request that the Controller corrects your Personal Data on your behalf, in case such data is processed incompletely or inaccurately, provided that any modification pertaining to certain fields, (for example, bank details), requires the  completion of an approval process;
  1. To request deletion or destruction of your Personal Data, subject to certain limitations under applicable law;
  2. To restrict processing of your Personal Data where applicable under the GDPR; 
  3. To object to a processing activity that is carried out for the purposes of legitimate interests pursued by the Controller; and
  4. To lodge a complaint with a relevant data protection authority.     

Changes to this Privacy Policy

Our Privacy Policy may be updated from time to time, and we will notify you of any material changes by posting the new Privacy Policy on the Site at Privacy Policy and revising the “Effective starting” date at the top of this policy. 

Contacting Us

If you have any questions about this Privacy Policy, please contact us at: privacy@hosperly.com