Skip to privacy policy

The Grand Forgetmenot 2 / Tolo

Privacy,
in plain language.

Last updated

July 16, 2026

The short version

This is a brochure website. It uses one browser-storage record only when you ask it to remember that you acknowledged the privacy notice. It does not currently use analytics, advertising pixels, profiling, or optional scripts.

01

Scope and controller

This policy explains how this website handles personal information. The current controller trading identity is The Grand Forgetmenot 2, Tolo, Argolis, Greece. Confirmation of the exact legal entity and registered address remains pending. Final production compliance sign-off remains blocked until the hotel owner and Greek/EU counsel confirm those details; this policy will then be updated.

Privacy questions and requests can be sent to hello@forgetmenothotel.com.

02

Information we process

Website delivery and security data

Our hosting provider, Vercel, may process request and security logs when you visit. Those logs may include your IP address, approximate location derived from the IP address, user agent, timestamps, requested URL, and technical diagnostics.

Information you choose to email

We receive your email address, message, and any information you include only when you choose to email us. This website has no contact form, no booking transaction, and no payment collection. Booking links currently lead to information on this site; they do not complete a reservation or collect payment.

What we do not do

We do not currently use optional analytics, ad pixels, social tracking, profiling, or solely automated decisions with legal or similarly significant effects. We do not sell personal information or share it for cross-context behavioral advertising.

03

Purposes and legal bases

  • Delivering and protecting the website: our legitimate interests in providing a secure, reliable site and diagnosing errors.
  • Remembering the notice acknowledgement: the storage is limited to the preference-memory function you request. We treat access to the terminal-equipment record as strictly necessary for that function. Related personal-data processing, if any, is based on our legitimate interests in operating a clear and minimally intrusive privacy interface. This is not consent to analytics or advertising. This classification remains provisional pending the owner and counsel review required for final production compliance sign-off.
  • Responding to an inquiry: steps you ask us to take before a possible contract, or our legitimate interests in answering your message.
  • Meeting legal duties: compliance with a legal obligation when applicable.
  • Future marketing subscriptions: consent, if we later offer a subscription. No on-site marketing subscription is active today.

Where processing relies on legitimate interests, we consider the limited nature of the data, your reasonable expectations, and the safeguards described here.

04

Browser storage

The website currently uses only one first-party browser storage record:

Current browser storage
NamePurposeDuration
fmnPrivacyChoiceRemembers that you asked us not to repeat this privacy notice. It does not grant analytics or advertising permission.180 days

No optional analytics or advertising storage is active. You can remove the saved acknowledgement through or through your browser controls.

05

Recipients

Vercel processes hosting, network, request-log, and security data for this website. Providers that operate our email service may process messages you choose to send. We may also disclose information when required by law, to protect legal rights or safety, or in connection with a legitimate business reorganisation, subject to applicable legal requirements.

International transfers

Service providers may process information outside Greece or the European Economic Area. The account-specific processing regions, transfer mechanism, and supplementary measures are not yet verified. Final production compliance sign-off is blocked until the owner and counsel verify the applicable provider contracts and, where required, an adequacy decision, approved standard contractual clauses, or another legally recognised safeguard.

06

Retention

The notice acknowledgement lasts for 180 days unless you clear it earlier. Account-specific retention for hosting and security logs is not yet verified. The email provider and approved retention period for correspondence are also pending. Final production compliance sign-off is blocked until the owner and counsel approve a purpose-specific retention and deletion schedule and reconcile it with this policy.

07

Your GDPR rights

Where the GDPR applies, you may have the right to:

  • access your personal information and receive a copy;
  • correct inaccurate or incomplete information;
  • request deletion or restriction of processing;
  • object to processing based on legitimate interests;
  • receive portable information where the legal requirements are met;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • complain to a data protection authority.

Send requests to hello@forgetmenothotel.com. We may need to verify your identity. We aim to respond within one month, subject to legally permitted extensions for complex or numerous requests.

You may complain to the Hellenic Data Protection Authority (HDPA), or to another competent supervisory authority where applicable.

08

Other disclosures

California privacy disclosures

California residents may have rights to know, access, correct, or delete personal information and to receive equal service when exercising applicable rights. Because this site does not sell personal information or share it for cross-context behavioral advertising, there is no sale or sharing opt-out to offer for current site activity. Applicability depends on statutory thresholds and the circumstances of the business; contact us to make a request.

Children

This website is intended for a general audience and is not directed to children. We do not knowingly collect personal information from children through this site. If you believe a child has sent us personal information, contact us so we can review and delete it where appropriate.

Security

Current website technical controls include encrypted HTTPS delivery provided by the host, restrictive response headers, and no optional analytics or advertising scripts. Account access, provider contracts, incident procedures, and other organisational controls still require owner verification under the compliance roadmap. No internet transmission or storage system is completely secure.

Changes to this policy

We may update this policy when the website, providers, or legal requirements change. The date at the top will show the latest revision. Material changes will be highlighted in an appropriate way before they take effect when required.