Skip to content
TheList
ExploreVenuesReservations
Sign in
Sign in
ExploreVenuesReservations

Cities

MiamiNew YorkDubaiAbu DhabiPalm JumeirahAl Jazirah Al HamraDubai Sports CityAthens
Home › Privacy Policy

On this page

  • PRIVACY POLICY
  • 1. INTRODUCTION
  • 2. DEFINITIONS
  • 3. THE CONTROLLER
  • 4. OUR PRINCIPLES
  • 5. COLLECTION OF PERSONAL DATA
  • 6. TYPES OF PERSONAL DATA COLLECTED BY “KAVOUSI ALI SINGLE-MEMBER PC”
  • 7. DATA SUBJECT CATEGORIES
  • 8. PROCESSING PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF DATA
  • 9. ASSURANCE OF THE SECURITY OF PERSONAL DATA
  • 10. DATA STORAGE PERIOD
  • 11. DATA RECIPIENTS
  • 12. PROCESSING LOCATION
  • 13. PERSONAL DATA BREACH
  • 14. DATA SUBJECTS’ RIGHTS AND THEIR EXERCISE
  • 15. CONTACT DETAILS OF THE CONTROLLER
  • 16. CONTACT DETAILS OF THE HELLENIC DATA PROTECTION AUTHORITY
  • 17. PRIVACY POLICY UPDATES

Privacy Policy

Copied on 6 August 2026 from the version published at thelist-app.com, which always governs.

Ελληνικά

INFORMATION / PERSONAL DATA SECURITY MANAGEMENT SYSTEM

PRIVACY POLICY

This document is the property of “KAVOUSI ALI SINGLE-MEMBER PC” and its reproduction in part or in whole without the company’s permission is prohibited.

1. INTRODUCTION

This Privacy Policy (hereinafter the “Policy”) concerns the company “KAVOUSI ALI SINGLE-MEMBER PC” (hereinafter the “Company”) and the personal data it maintains with regard to natural persons.

The Company is bound to protect the confidentiality and privacy of Personal Data, and conforms to the relevant provisions of Regulation 679/2016 ‘General Data Protection Regulation’, hereinafter “GDPR”.

2. DEFINITIONS

Personal data: any information relating to and describing a person, such as: identifying details (full name, age, residence, occupation, marital status, etc.), physical characteristics, education, employment (experience, work behaviour, etc.), finances (income, assets, financial behaviour), interests, activities, habits. The person (natural person) to whom the data refer is called the Data Subject.

Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.

Controller: the natural or legal person which determines the purposes and means of the processing of Personal Data.

Processor: the natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.

Personal Data Processing: any operation or set of operations relating to personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Third Party: any natural or legal person other than the Data Subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process personal data.

3. THE CONTROLLER

The Company is the Controller of personal data that are processed in the context of providing its services; the company maintains and processes your personal data with confidentiality and respect for your privacy, taking the technical and organisational measures necessary for further protecting them.

4. OUR PRINCIPLES

The Company is bound to comply with the following Personal Data processing Principles under Article 5 of the GDPR:

Lawfulness, fairness and transparency.

Purpose Limitation – The personal data are collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.

Data minimisation – The personal data are adequate, relevant and limited to what is necessary for the purposes for which they are processed.

Data accuracy/quality – The personal data are accurate and, where necessary, kept up to date.

Retention – The personal data are kept for no longer than necessary or required by law.

Integrity and Confidentiality – The Company warrants the security of the personal data, in particular protection against unauthorised or unlawful processing and against accidental loss or damage, using appropriate technical or organisational measures.

Accountability Principle.

5. COLLECTION OF PERSONAL DATA

“KAVOUSI ALI SINGLE-MEMBER PC” collects information relating to its customers in the following cases, inter alia:

  • When customers contact us, when they visit our Application when they directly contact or visit the premises of the Company for information concerning the services offered by the Company and, by extension, the service they have selected to receive (Internet interconnection and booking application, recreational activities, events, etc. through the Company Application).
  • When the personal data are transmitted to “KAVOUSI ALI SINGLE-MEMBER PC” by Companies,associates or other third parties.
  • Furthermore, “KAVOUSI ALI SINGLE-MEMBER PC” occasionally collects data from third parties that may lawfully transmit information concerning its customers or whose files we may lawfully access, such as external associates, organisations providing information on credit and for the prevention of fraud, attorneys, state services (administrative, tax, judicial, regulatory authorities, insurance funds) or other legal persons under public or private law.
  • Our Company processes personal data for the purposes described below in detail.

6. TYPES OF PERSONAL DATA COLLECTED BY “KAVOUSI ALI SINGLE-MEMBER PC”

The following categories of data concerning the customers of “KAVOUSI ALI SINGLE-MEMBER PC” may be collected and subjected to further processing, as outlined herein:

Contact and Identification Information (e.g. Full Name, Address, city, postcode, country, telephone number, e-mail address, identity card or passport number, date of birth).

Occupational Status Information (e.g. Occupation).

Marital Status Information (Married, Single, Children, etc.).

Payment Information (e.g. IBAN/Account number, preferred payment method).

7. DATA SUBJECT CATEGORIES

The categories of subjects include:

  • Customers.
  • Suppliers.
  • Third parties involved in events related to the provision of our services.
  • Our staff.

8. PROCESSING PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF DATA

The processing of personal data is based on one of the “legal bases” provided for in Article 6(1) of the GDPR. The legal basis on which the processing of each use of your data refers to each processing purpose.

Provision of Entertainment Services – Personal data deemed necessary for the provision of services [Article 9(2)(a) of the GDPR].

Pursuit of our Legitimate Interests – e.g. to improve our services, prevent and detect fraud against us [Article 6(1)(f) of the GDPR]

Compliance with our Legal Obligations – for compliance with our legal obligations towards police, regulatory, tax, accounting, certified public auditing, judicial authorities and services [Article 6(1)(c) of the GDPR].

The provision of personal data such as the foregoing is a legal obligation depending on the specific request.

Processing of Special Categories of Data: According to Article 9(1) and (2) of the GDPR, the processing of special categories of data is permitted solely in specific cases set out by law, including the provision of consent of Article 9(2)(a).

9. ASSURANCE OF THE SECURITY OF PERSONAL DATA

“ALI SINGLE-MEMBER PC” ensures that personal data are subjected to processing, with compliance with policies and procedures, according to the processing purposes. For example, the following security measures are used to protect personal data against abuse or any other form of unauthorised processing:

  • Access to personal data is limited solely to a specific number of individuals and for specific purposes.
  • The staff members of the competent departments who are competent to handle your requests are bound by confidentiality clauses, have classified and limited access solely to the data necessary for completing the provision of services.
  • Sensitive data are stored on a computer with authorised access. When printed, they are locked in cabinets accessible only to authorised persons.

The Company selects trustworthy associates, who are bound in writing, in accordance with Article 28(4) of the GDPR, to perform the same obligations concerning the protection of Personal Data. We reserve the right to audit these associates (Article 28(3)(h) of the GDPR).

The computer systems used to process the data are technically isolated from other systems in order to prevent unauthorised access, e.g. through hacking.

Additionally, access to these computer systems is continually monitored in order to identify and prevent unlawful use at the initial stage.

10. DATA STORAGE PERIOD

The Company stores personal data for the period required: by the corresponding processing purpose and any other associated purpose permitted, as well as the legislation in force at any given time and the applicable legal provisions that concern the processing purpose. The data are retained through the effective term of the contract and, following its expiry, for the period required by the legislation in force at any given time.

Information that is no longer necessary is destroyed securely or anonymised.

With respect to data processed by the Company on the basis of its customers’ consent in particular (e.g. for marketing purposes), these are kept from the date the consent in question is received and until it is revoked.

The Company limits access to the data of its customers to persons who need to use them for the specific purpose.

11. DATA RECIPIENTS

The personal data collected by “KAVOUSI ALI SINGLE-MEMBER PC” may be transmitted to third parties, on the condition that the legitimacy of the transmission is reasoned.

Furthermore, if the legitimacy of the transmission is justified, the personal data may be disclosed to the following categories of recipients:

  • Company customers, whether private citizens or companies, for whom ‘KAVOUSI ALI SINGLE-MEMBER PC’ acts as the ‘Processor’ and who are ‘Controllers’.
  • Company employees or associates who may process the personal data of the customers of ‘KAVOUSI ALI SINGLE-MEMBER PC’ under its instructions.
  • Transport or courier companies.
  • Associated companies, in the context of their competences at any given time.
  • External associates, who are bound in writing, in accordance with Article 28(4) of the GDPR to perform the same obligations concerning the protection of personal data.
  • Any Supervisory Authority, as required by the supervisory framework in force at any given time.
  • Any State or Judicial Authority, where this is required by law or a Court judgment.
  • The Company uses numerous service providers who collaborate in the provision of the services referred to.

While no guarantee can be given for the protection of data transferred over the Internet or a website from cyberattacks, both the Company and is associates work to maintain physical, electronic and procedural security measures for the protection of its customers’ data.

12. PROCESSING LOCATION

The personal data of the customers of ‘KAVOUSI ALI SINGLE-MEMBER PC’ are subjected to processing within the European Economic Area (EEA).

Where the conduct of an investigation for the provision of services outside the EEA is required, this shall take place with the explicit consent of the data subjects. Article 49(4)(a) of the GDPR.

13. PERSONAL DATA BREACH

In the event of a breach of the security and integrity of the personal data kept by ‘KAVOUSI ALI SINGLE-MEMBER PC’, the Company shall take the following measures: (According to Articles 33 and 34 of the GDPR):

  • Examine and evaluate the procedures required to contain the breach.
  • Assess the risk and its impact on the rights and freedoms of the data subjects.
  • Attempt to limit – to the extent possible – the damage caused or that could be caused.
  • Provide notification within 72 hours of being made aware of the breach, where necessary.
  • Evaluate the impact on privacy and take suitable measures to avoid a repeated breach.

14. DATA SUBJECTS’ RIGHTS AND THEIR EXERCISE

Data subjects have the right to request access to the personal data that concern them, the right to rectification / erasure of their personal data, the right to restriction of processing, the right to object to the processing and/or the right to data portability.

If the data processing is based on the subjects’ consent, they may revoke their consent at any time, with effect for the future.

More specifically, Data Subjects have the following rights:

Access: The right to be informed about the processing of their Data by ‘KAVOUSI ALI SINGLE-MEMBER PC’ and the right to access these data.

Rectification: The right to request rectification or supplementation of their data if they are inaccurate or incomplete.

Erasure: The right to request the erasure of their data. ‘KAVOUSI ALI SINGLE-MEMBER PC’ can satisfy this right if:

  • The data are no longer necessary for the purposes for which they were collected.
  • There is no legal basis for processing other than consent.
  • The data subjects exercise their right to object (see below under ‘f’).
  • The data are subjected to processing contrary to the legal provisions in force.
  • The personal data must be deleted in order to comply with a legal obligation.

‘KAVOUSI ALI SINGLE-MEMBER PC’ reserves the right to refuse to satisfy the foregoing right if the data processing is necessary: for the compliance with a legal obligation on the part of ‘KAVOUSI ALI SINGLE-MEMBER PC’, reasons of public interest or the establishment, exercise or defence of legal claims.

Restriction of processing: The right of the data subjects to mark the data with the aim of limiting their processing.

Portability: The data subject’s right to receive their data in a structured, commonly used and machine-readable format, and to request their transmission both to themselves and to a different processor (to be indicated by the data subject).

Objection: The data subject’s right to object to the processing of their data, including profiling, at any time.

The Company shall examine the Customer’s request and respond within one month from the receipt of the request, either regarding its satisfaction or the objective reasons hindering its satisfaction or, taking into consideration the complexity of the request and the number of requests, within a deadline of two further months (Article 12(3) of the GDPR).

The data subjects may exercise the foregoing rights at no cost to them by sending a relevant request/letter/e-mail message to the Data Controller.

If you are not satisfied by our use of your data or our response to the exercise of your foregoing rights, you have the right to lodge a complaint with the Hellenic Data Protection Authority.

You may exercise your foregoing rights at the contact details noted below.

15. CONTACT DETAILS OF THE CONTROLLER

IN regard to any issue concerning the processing of the Personal Data of Company customers (data subjects) and the exercise of their foregoing rights, customers may contact the Company by telephone at +30 210 8959930 (Monday to Friday, 10:00 to 17:00), via e-mail at[email protected]and via post at: 20, Digeni Street, GR-16673, Voula, Attica.

16. CONTACT DETAILS OF THE HELLENIC DATA PROTECTION AUTHORITY

Tel. No: +30 21064.75.600, e-mail:[email protected], postal address: 1-3, Kifisias Avenue, GR-11523, Athens

17. PRIVACY POLICY UPDATES

This policy shall be revised when a material change occurs. This revision shall be available at the secretariat of the company.

Cities

  • Miami
  • New York
  • Dubai
  • Abu Dhabi
  • Palm Jumeirah
  • Al Jazirah Al Hamra
  • Dubai Sports City
  • Athens

Categories

  • Restaurants
  • Clubs

Support

  • Help & FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • Cookies
TheList — Reserve your table© 2026 TheList. All rights reserved.
ExploreSearchBookingsProfile

We use essential cookies to run the site. With your OK we'll add more — you can change this any time. Cookie policy

Cookie preferences

  • Essential

    Needed to sign you in, hold your table, take a payment and remember your city and theme. Always on.

    tl_session · tl_csrf · tl_city · tl_theme · NEXT_LOCALE · thelist.hold · tl_pending_payment · thelist.recent-search · js.stripe.com

  • Analytics

    Would help us see which pages people use, so we can improve them.

    Nothing is stored for this today.

  • Marketing

    Would let us show you offers based on what you've looked at.

    Nothing is stored for this today.

  • Maps

    Loads maps from Google on pages that show one. Google sets its own cookies.

    maps.googleapis.com

  • Help chat

    Loads our help chat so you can ask a question and get an answer. Nothing is requested from it until you open it.

    intercom-id-* · intercom-session-* · intercom-device-id-* · widget.intercom.io