1. Data controller
The controller for this microsite is Κ. Μαυροχωρίδης – Α. Γλαρούδης Ο.Ε. (Greek General Partnership), trading as Sea World Scuba Diving Center / Kentro Katadyseon Thalassios Kosmos.
- Registered address: Sani Kassandreias 0, 63077 Kassandreia, Halkidiki, Greece
- VAT No.: 084149935
- Competent tax office: Nea Moudania
- G.E.MI. No.: 032111357000
- Business commencement: 19 July 1996
- Email: cdc@seaworld.gr
- Phone: +30 698 364 5088
This policy covers your use of seaworld.gr/cdc/, contact-form submissions and related communications. It does not govern third-party websites reached through external links.
2. Data we collect
Data you provide
- Your full name, email address and optional phone number.
- The course or service that interests you.
- Your message and any information you choose to include.
- Information contained in later email, telephone or WhatsApp communications.
Technical data
- IP address, device and browser type, request date and time, requested pages and technical server logs.
- Security-verification data required by Cloudflare Turnstile to prevent automated abuse.
- Your language preference, stored in the functional
seaworld_cdc_langcookie.
We do not ask for special-category personal data, payment details or medical information through the contact form. Please do not include such information in an initial enquiry.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Answer enquiries, provide information and arrange courses or services. | Performance of a contract or steps taken at your request before entering into a contract. |
| Secure the website, prevent spam or abuse and diagnose technical problems. | Our legitimate interest in operating a safe and reliable service. |
| Meet duties imposed by applicable law. | Compliance with a legal obligation. |
| Use optional, non-essential technologies if introduced. | Consent where required, which you may withdraw. |
We do not use solely automated decision-making or profiling that produces legal or similarly significant effects concerning you.
4. Service providers and recipients
Only authorised members of our team and providers needed to run the site and communications may access relevant data:
- Hostinger: website hosting and server infrastructure.
- Email providers: delivery and storage of correspondence.
- Cloudflare Turnstile: protection against bots and malicious use. See Cloudflare's Privacy Policy.
- Google: Google Fonts and Google Maps on the Contact page. When these services load, Google may receive technical data such as your IP address. See Google's Privacy Policy.
We do not sell or rent personal data. Links to WhatsApp and social networks take you to third-party services that process data under their own policies.
5. Cookies and similar technologies
seaworld_cdc_lang: a functional cookie that remembers your Greek or English choice for up to one year.- WordPress may use strictly necessary session or login cookies for authorised administrators.
- Embedded Google Maps and Cloudflare Turnstile may use their own technical storage or identifiers under their respective policies.
The CDC theme does not intentionally place its own advertising or visitor-analytics cookies. If such technologies are introduced, this notice and the relevant choice mechanism will be updated where required.
6. Retention
We retain messages and contact details only for as long as needed to answer, manage your request and support any resulting course participation or business relationship. They are then deleted or anonymised unless a longer period is required by tax, accounting, contractual or other legal obligations.
Technical and security logs are retained for a limited operational period under the settings of our hosting and security providers, then deleted or aggregated.
7. International transfers
Some technology providers may process data outside the European Economic Area. Where applicable, transfers rely on an adequacy decision, Standard Contractual Clauses or another safeguard recognised by the GDPR.
8. Your rights
Depending on the circumstances, you have rights to information, access, rectification, erasure, restriction, portability and objection. Where processing is based on consent, you may withdraw it at any time without affecting earlier lawful processing.
To exercise a right, email cdc@seaworld.gr. We may reasonably request information to verify your identity. We will respond without undue delay and within the time limits set by the GDPR.
9. Security
We use reasonable technical and organisational safeguards, including HTTPS encryption, access controls, software updates and automated-abuse protection. No method of internet transmission or storage can guarantee absolute security.
10. Children
The website is not intended to collect data from children without the involvement of a parent or guardian. For an enquiry about a course involving a minor, the first contact should be made by a parent or legal guardian.
11. Changes to this policy
We may update this policy when services, technologies or legal requirements change. The newest version will always appear on this page with its updated date.
12. Privacy contact
For questions or requests about your personal data: