Privacy policy
Privacy Policy — Helix Transfer
Version: 24 September 2026
1. Who we are
Helix Travel, which operates helixtransfer.gr under the website brand Helix Transfer, is the controller responsible for the processing of personal data described in this policy.
Address: 19 Eslin Street, Ampelokipoi, Athens, 11523, Greece.
Contact email, including for personal data requests: [email protected].
2. Personal data we collect
When you use the contact form, we collect your full name, email address, telephone number and message.
The transfer enquiry form also collects your pickup location, destination, date and time, number of passengers and bags and, if you provide them, the selected service, flight or ferry details, return date and time and any notes.
We also record the enquiry reference, submission time, language and status, your acknowledgement of the privacy notice and the sending status of related emails. If we continue the conversation by email or telephone, we also process the information you provide for that enquiry.
To protect the forms against abuse, temporary technical identifiers derived from the IP address and email address are used. Server operational logs may contain IP addresses, access times, page addresses, browser information and technical errors.
Fields marked with an asterisk are required to submit the relevant form. Without them, online submission cannot be completed; you may contact us at the email address above instead. Please do not include payment card details, passwords, identity document copies or health information in free-text fields. The forms do not request payment or the names of all passengers.
3. Purposes and legal bases
We use transfer enquiry details to check availability, respond, provide a quotation and arrange the transfer. Processing necessary to take steps at your request before entering into a contract and to perform that contract is based on Article 6(1)(b) of the GDPR.
For general messages, related correspondence and protection against fraud and misuse, we rely on our legitimate interests in communicating with people who contact the business and providing secure services, provided those interests are not overridden by your rights (Article 6(1)(f)).
Where records must be retained to meet tax, accounting or other legal requirements, processing is based on the relevant legal obligation (Article 6(1)(c)). Strictly necessary information may also be retained to establish, exercise or defend specific legal claims on the basis of the corresponding legitimate interest.
Reading this policy does not constitute consent to advertising. Submitting a form does not subscribe you to a newsletter or authorise unrelated marketing.
4. What happens when you submit a form
Your enquiry is stored in the website's management system and a notification is sent to our business email account. An automated acknowledgement is also sent to the address you provided when that feature is enabled and no abuse-prevention limit has been applied. The acknowledgement does not mean that a member of staff has already read your enquiry and does not confirm a booking. A booking is completed through separate communication and confirmation.
We do not make solely automated decisions about accepting bookings that have legal or similarly significant effects on you, and we do not use enquiries to build advertising profiles.
5. Who may receive your data
Authorised people handling communications, bookings and technical support have access to the extent necessary for their work. The website and business email hosting infrastructure is provided through a Hetzner dedicated server in Germany.
If a transfer is assigned to a partner driver or transport company, necessary contact and journey details may be shared, such as the name, telephone number, pickup and destination locations, times, passenger and luggage numbers and relevant instructions. Sharing is limited to what is needed for the particular service. Whether a partner acts as a processor or an independent controller depends on the actual arrangement and is determined before data is shared.
Data may be disclosed to competent authorities where required by law or to professional advisers, such as accountants and legal advisers, where necessary for a specific obligation or matter. We do not sell your personal data.
6. Where your data is stored
The website and business mailbox are hosted in Germany, within the European Union. The acknowledgement email is sent to the address you choose; subsequent processing by your own email provider is governed by that provider's practices.
Before introducing a partner or service involving a transfer outside the European Economic Area, we will assess the legal requirements, put the necessary transfer mechanism in place and update this policy with information about the relevant transfers and safeguards.
7. How long we keep your data
Contact messages and transfer enquiries that do not result in a booking are retained for up to 12 months after the last related communication and are then deleted or anonymised. This period applies to the WordPress record and the corresponding emails and working files under our control.
Where an enquiry results in a booking, data is retained for as long as necessary to arrange, perform and settle the service. After completion, only data required by specific tax or accounting obligations is retained for the periods prescribed by applicable law, or data necessary for specific legal claims until the relevant limitation period expires or the matter is finally resolved. These obligations do not justify indefinite retention of the entire enquiry.
The same exception for a specific legal obligation or an outstanding claim may require retention of strictly necessary information beyond the 12-month period. Access is then restricted to the corresponding purpose.
Technical logs and backups are subject to separate retention cycles based on incident investigation, security and necessary recovery needs. They are not used as a permanent customer archive. You can request information about retention of particular records concerning you at [email protected].
8. Cookies and external links
Cookies are small files that may be stored on your device. The core Helix form functions do not require advertising cookies. WordPress may use strictly necessary technical cookies, particularly when authorised administrators sign in.
Cookie consent is not required for strictly necessary functions. Any non-essential cookies or similar trackers used for statistics or advertising must only be enabled after the required information has been provided and you have made a prior choice through an appropriate consent mechanism. If such features are introduced, specific information will be provided about their providers, purposes, duration and how to change your choices.
If you follow an external link, such as a link to a map or a messaging service, you visit another provider's service, which is subject to its own privacy policy.
9. Your rights
Subject to the conditions of the GDPR, you may request access to and a copy of your data, correction of inaccurate information, erasure or restriction of processing. You may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing is based on a contract or consent and is carried out by automated means, the right to data portability may also apply.
Where particular processing relies on consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Rights are not absolute; for example, mandatory retention of accounting documents may prevent their immediate deletion.
To exercise a right, email [email protected]. We may request the additional information necessary to verify your identity. We respond without undue delay and normally within one month. If an extension of up to two further months is necessary because of the complexity or number of requests, we will explain the reason within the first month.
You have the right to lodge a complaint with the Hellenic Data Protection Authority, www.dpa.gr, or the competent supervisory authority where you habitually reside or work, or where the alleged infringement occurred. You do not have to contact us first.
10. Updates to this policy
We update this policy when our services or processing activities change. The current version is available on the privacy page of helixtransfer.gr with its version date. For questions, contact [email protected].
