Privacy Policy



Diava Restaurant

Last updated: 14/07/2026

This Privacy Policy explains how Diava Restaurant collects, uses, stores and protects personal data when you visit our website, contact us, make a reservation, submit an enquiry or interact with our services.

We are committed to protecting your privacy and handling your personal data in accordance with applicable data protection laws, including the General Data Protection Regulation — Regulation (EU) 2016/679 — and applicable Greek data protection legislation.

1. Who we are

For the purposes of this Privacy Policy, the data controller is:

ΜΟΝΟΡΑΤΙΑ RΕSΟRΤ ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
Trading as: Diava Restaurant
Address: Ano Pedina, Zagori, Greece

2. Personal data we may collect

Depending on how you use our website and services, we may collect the following categories of personal data:

Contact details

Such as your name, surname, email address, telephone number and communication preferences.

Reservation and enquiry details

Such as requested date and time, number of guests, seating preferences, special requests, dietary preferences, allergies, event enquiries or other information you choose to provide.

Website and technical data

Such as IP address, browser type, device information, pages visited, time spent on the website, referring pages and cookie preferences.

Communication data

Such as emails, forms, telephone enquiries, messages or social media communications sent to us.

3. How we collect personal data

We may collect personal data when you:

visit our website

complete a contact, reservation or enquiry form

make or request a reservation

contact us by email, telephone or social media

accept or manage cookies

interact with third-party services connected to our website

4. Why we use your personal data

We may use your personal data for the following purposes:

To respond to enquiries

To reply to your questions and provide information about reservations, menus, opening hours, private dining, events or restaurant services.

To manage reservations

To process reservation requests, confirm bookings, manage changes and communicate with you before your visit.

To provide restaurant services

To manage guest preferences, dietary requirements, allergies, special requests and service-related communication.

To send newsletters or marketing communications

Where you have given your consent or where otherwise permitted by law, we may send you news, offers, events or updates relating to Diava Restaurant.

To improve the website and services

To understand how visitors use our website and improve its content, performance and user experience.

To comply with legal obligations

To comply with accounting, tax, regulatory, safety or legal obligations.

To protect our rights and security

To prevent fraud, protect website security, enforce terms, resolve disputes or defend legal claims.

5. Legal basis for processing

We process personal data only where we have a lawful basis to do so. Depending on the situation, the legal basis may include:

Consent, for example for newsletter subscriptions and non-essential cookies.

Contractual necessity, for example when processing data needed for a reservation or service.

Legal obligation, for example tax, accounting or regulatory requirements.

Legitimate interest, for example responding to enquiries, improving our services, protecting website security and managing our business, provided your rights do not override those interests.

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6. Cookies

Our website uses cookies and similar technologies. Some cookies are necessary for the website to function, while others are used only with your consent, where required.

For more information, please see our Cookie Policy.

7. Sharing personal data with third parties

We may share personal data with trusted third parties where necessary for the operation of our website and services. These may include:

reservation or booking system providers

website hosting and technical support providers

email marketing or newsletter platforms

analytics providers

payment providers, where applicable

professional advisers, such as accountants, lawyers or consultants

public authorities, where required by law

service or event partners, where necessary to fulfil your request

Third parties are expected to process personal data only for the purposes agreed with us and in accordance with applicable data protection requirements.

8. International transfers

Some third-party service providers may process data outside the European Economic Area. Where this occurs, we take appropriate steps to ensure that personal data remains protected, including by relying on appropriate legal safeguards where required.

9. How long we keep personal data

We keep personal data only for as long as necessary for the purposes described in this Privacy Policy.

Indicatively:

reservation and enquiry data may be kept for as long as necessary to manage the request and follow-up communication

accounting or legal records may be kept for the period required by applicable law

newsletter data is kept until you unsubscribe or withdraw consent

cookie consent records may be kept for a reasonable period to demonstrate compliance

10. Your rights

Subject to applicable law, you may have the following rights regarding your personal data:

right of access

right to rectification

right to erasure

right to restriction of processing

right to object to processing

right to data portability

right to withdraw consent

right to lodge a complaint with a supervisory authority

In Greece, the competent supervisory authority is the Hellenic Data Protection Authority.

11. How to exercise your rights

To exercise your rights or ask questions about how we process your personal data, please contact us at:


We may need to verify your identity before responding to certain requests.

12. Security

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration or disclosure.

However, no method of transmission over the internet or electronic storage is completely secure. We therefore cannot guarantee absolute security.

13. Children’s data

Our website is not directed at children. We do not knowingly collect personal data from children through the website without appropriate consent where required.

If you believe that a child has provided us with personal data, please contact us so that we can take appropriate steps.

14. Links to third-party websites

Our website may contain links to third-party websites, reservation platforms, maps, social media pages or partner services. We are not responsible for the privacy practices or content of these third-party websites.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. Any changes will be published on this page with an updated “Last updated” date.

16. Contact

For privacy-related questions, please contact:

Diava RestaurantAno Pedina, Zagori, Greece

Diava Restaurant Logo

© Copyright 2026 Diava Restaurant - All Rights Reserved