Legal
Privacy policy
This explains what personal data this website collects, who handles it, and what you can ask us to do about it. It describes only what this site actually does — nothing here is boilerplate for features we do not have.
Who is responsible for your data
This website is operated by EVGENIA ZISIMOPOULOU IKE, trading as Cantera, Little Venice, Mykonos Town, Greece. That company is the data controller.
For anything to do with this policy or your data, write to reservations@canteramykonos.com or call +30 22890 77404.
What we collect
You can read every page of this site without telling us anything about yourself. There is no account to create, no newsletter to join and no contact form. We collect personal data only in the situations below.
- Table reservations. Booking takes you to i-host.gr, which is run by i-Host and is not part of this website. What you enter there — your name, phone number, email, the size of your party and any note you add — is collected on their system under their own privacy policy, and reaches us as a booking so we can hold and prepare your table.
- Calls, emails and WhatsApp. If you phone, write or message us, we have your contact details and whatever you tell us, for as long as it takes to answer you properly. A WhatsApp message is carried by WhatsApp, which is Meta, under their terms rather than ours, and it reaches a phone the restaurant shares with the businesses alongside it.
- Mamma Mia Night. That evening is booked on a separate website with its own operator, its own deposit payment and its own privacy terms. Nothing you enter there passes through this site, and we never see your card details.
- Server records. This site is hosted on Firebase Hosting, which is Google. Like any web server it logs the request — the IP address it came from, the time, the page and the browser — which is what makes it possible to serve the page at all and to spot abuse.
- Measurement, only if you agree. If you accept in the consent banner, we count visits and measure which pages and buttons people use. The cookie policy lists exactly what that involves.
Why we use it
Each of those has a reason behind it, and under the GDPR each reason has a name:
- To give you the thing you asked for. Taking a reservation and answering an enquiry are steps in providing the service you approached us for.
- Because you said yes. Analytics and advertising measurement run on your consent, and on nothing else. You can take it back at any time, and taking it back is as easy as giving it.
- Because the site has to work and stay up. Serving pages, blocking abuse and keeping the site secure are our legitimate interests, weighed against the fact that a server log is a thin and short-lived record.
- Because the law says so. Once you have eaten with us, the transaction record falls under Greek tax and accounting law, which sets its own rules about what is kept.
We do not sell personal data, we do not share it with anyone for their own marketing, and nothing on this site makes an automated decision about you.
Who else sees it
A small number of companies handle data on our behalf or alongside us:
- Google — hosting the site, and, with your consent, tag management and analytics.
- Meta — WhatsApp, if you choose to message us there, and, with your consent, measuring whether an advert led to a visit.
- Anthropic — runs the language model behind the chat assistant; the messages you type to the assistant are processed to generate its replies. Conversations are kept for 30 days — with the page, the language, a coarse country code and your device's timezone — then deleted automatically; statistics are kept only as anonymous counts.
- Cookiebot — the consent banner itself, which has to record what you chose in order to honour it.
- i-Host — the reservation system, once you choose to book.
That is the whole list, and it is short by design. The photographs, the films and the type on this site are served from this site. There is no embedded map, no video player belonging to someone else, no social feed, no reviews widget and no chat window — so apart from the consent banner and the tag manager it controls, nothing on the page reaches out to another company before you click something.
Where your data goes
Google, Meta and Anthropic are United States companies, so some data reaches the United States. Those transfers rely on the European Commission's standard contractual clauses and, where the provider is certified to it, on the EU–US Data Privacy Framework. i-Host and Cookiebot operate within the European Union.
How long we keep it
We do not set an arbitrary clock on everything; we keep each thing for as long as the reason for having it lasts.
- Correspondence about a booking or an enquiry is kept while we are dealing with it and through the season it belongs to, then cleared.
- Records of what you actually spent are kept for as long as Greek tax and accounting law requires the record to exist.
- Measurement data is held by Google in aggregate, under a retention setting that is at most fourteen months.
- Consent choices are kept until you change them or clear your browser, so that we are not asking you the same question on every visit.
Your rights
You can ask us for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, or ask for it in a portable form. Where we rely on your consent you can withdraw it at any time, and withdrawing it does not undo anything that was lawful before.
Write to reservations@canteramykonos.com and we will answer within one month. You do not need to give a reason.
If you think we have got it wrong, you can complain to the Hellenic Data Protection Authority, Kifissias 1–3, 115 23 Athens, www.dpa.gr. We would rather you told us first, but that is your right and not a courtesy.
Children
This is a restaurant website. It is not aimed at children and we do not knowingly collect data from them.
Changes to this policy
If what we do changes, this page changes with it, and the date at the top moves. If a change matters to you it will be said plainly here rather than buried.