Last reviewed: 25 August 2026
This policy explains what personal data exploreattica.com collects, why, and what you can do about it. It is written to describe what this site actually does rather than to cover every eventuality.
1. Who is responsible
The data controller is:
Ruslan Losnov Plateon 55, Athens 104 35, Greece [email protected]
No Data Protection Officer has been appointed; this site does not carry out large-scale monitoring or process special categories of data, and is not required to appoint one.
2. What this site does not do
- It takes no bookings and holds no reservation, passenger or itinerary data.
- It takes no payments and never sees card details.
- It has no user accounts, no login and no newsletter.
- It does not sell personal data, and does not share it for third-party advertising beyond the affiliate attribution described below.
When you book through a partner widget, you leave this site and deal with that partner directly. Whatever you give them is governed by their privacy policy, not this one.
3. What is collected, why, and on what basis
| Data | Purpose | Legal basis |
|---|---|---|
| Analytics data via Google Analytics 4 — pages viewed, approximate location from IP, device and browser, referrer | Understanding which guides are used and where readers arrive from | Consent, Art. 6(1)(a) GDPR |
| Behavioural data via Microsoft Clarity — session recordings, click and scroll heatmaps | Seeing where pages confuse readers, e.g. dead clicks on a table | Consent, Art. 6(1)(a) GDPR |
| Affiliate attribution cookies set by Travelpayouts and its partner programmes | Attributing a booking so the site earns its commission | Consent, Art. 6(1)(a) GDPR |
| Your email address and the content of your message, if you write in | Answering you, and correcting the site | Legitimate interest, Art. 6(1)(f) — responding to a message you chose to send |
| Server and hosting logs, including IP address | Delivering the site, security, abuse prevention | Legitimate interest, Art. 6(1)(f) |
Nothing in the first three rows loads before you consent. See the cookie policy.
A note on session recording
Microsoft Clarity records how a visitor moves through a page — mouse movement, scrolling, clicks — and replays it as a session. Clarity masks text content by default, and this site has no forms, logins or payment fields, so there is nothing sensitive for it to capture. It is still more intrusive than a page counter, which is why it is listed separately here and why it runs only with consent.
4. Who receives data
- Google Ireland Limited (Google Analytics 4)
- Microsoft Corporation (Clarity)
- Travelpayouts and the individual partner programmes it connects to — Kiwitaxi, GetTransfer, GetYourGuide, WeGoTrip, Booking.com, DiscoverCars, Localrent, Airalo
- Zomro, the hosting provider, which processes server logs. Zomro's terms of service place the contract under Latvian law and name Podaon SIA (Latvia, reg. 40103450338) among its contracting entities.
5. Transfers outside the EEA
Google and Microsoft may process data in the United States. Both self-certify under the EU–US Data Privacy Framework, and standard contractual clauses apply where relevant. If you do not consent to analytics, no data reaches either of them from your visit.
6. How long data is kept
Analytics data is retained according to the retention period configured in Google Analytics (14 months, the GA4 default — change this line if you raise it). Clarity recordings are retained according to Microsoft's own policy. Email correspondence is kept for as long as needed to deal with the matter and any follow-up, then deleted. Server logs are kept for a short period for security purposes.
7. Your rights
Under the GDPR you can request access to your data, correction, erasure, restriction of processing, portability, and you can object to processing based on legitimate interest. Where processing rests on consent, you can withdraw it at any time — through the cookie settings link in the site footer — without affecting the lawfulness of what happened before.
To exercise any of these, email [email protected]. Because this site holds no accounts, in most cases the only data tied to you personally will be an email you sent.
If you believe your data has been handled unlawfully you can complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 11523 Athens, www.dpa.gr — or to the supervisory authority in your own country of residence.
8. Children
This site is aimed at adults planning travel and is not directed at children. It does not knowingly collect data from anyone under 16.
9. Changes
Material changes to this policy will be reflected in the "last reviewed" date above. The current version is always the one published here.