Privacy Policy
Kavala Amygdaleonas Aerodrome “Lydia” – LGKM
1. Who we are and how to contact us
The website available at www.lgkm.aero (hereinafter the “Website”) is operated by the limited liability company under the corporate name “EGNATIA AVIATION AEROPORIKI ETAIREIA AEROPORIKES EPICHEIRISEIS ETAIREIA PERIORISMENIS EUTHYNIS” (hereinafter “Egnatia Aviation”, the “Company”, “we”, “us” or “our”). The Website presents Kavala Amygdaleonas Aerodrome “Lydia” (LGKM) and the services and activities carried out by Egnatia Aviation in connection with the operation of the aerodrome. Unless expressly stated otherwise, Egnatia Aviation is the controller of the personal data described in this Policy.
Registered office: Amygdaleonas Aerodrome “Lydia”, 640 12 Amygdaleonas, Kavala, Greece. Telephone: +30 251 151 1000. General email: info@lgkm.aero. DPO email: privacy@egnatia-aviation.com.
2. Scope of this Privacy Policy
This Policy explains how we collect and process personal data when you visit or use the Website, communicate with us, submit a general or B2B enquiry, submit a Prior Permission Required (“PPR”), request aerodrome services, participate in a customer survey, exercise a data-protection right or otherwise interact with Website functions.
Separate privacy notices may apply to processing carried out outside the Website, including CCTV, physical access, on-site visitor management, personnel, contractors, suppliers, emergency or safety investigations and other aerodrome operations. Where a more specific notice is provided, that notice supplements this Policy and prevails for the relevant processing.
3. Personal data we may collect
3.1 Data you provide directly
-
Identification and contact data, such as name, surname, telephone number, email address, postal address and signature, where applicable.
-
Professional and organisational data, such as company, aircraft operator, role, department, business activity and representative capacity.
-
PPR and aerodrome-service data, such as aircraft registration, aircraft type, callsign, operator, pilot or representative details, flight itinerary, arrival and departure information, requested services, fuel, parking, passenger or crew numbers, invoicing request and operational comments.
-
Communication data, including the content of messages, enquiries, correspondence, complaints and supporting documents.
-
Survey and feedback data, such as ratings, comments and the date or type of visit. The survey is designed not to request direct identification or contact data. Participants should not include personal data or information identifying themselves or other persons in free-text responses.
-
Consent and preference data, including your cookie choices and any optional consent to receive invitations to future surveys, research or service-feedback activities.
-
Data included in a request to exercise your rights, including information reasonably necessary to verify your identity where there are justified doubts.
3.2 Data collected automatically
When you use the Website, certain technical information may be recorded automatically, including IP address, date and time of access, requested pages, browser and device information, operating system, referring page, server logs, security events and cookie or similar technology identifiers. Non-essential analytics, preference, advertising or embedded-content technologies are activated only where the applicable consent requirements have been satisfied.
3.3 Data obtained from other persons
We may receive personal data from an aircraft operator, pilot, employer, representative, handling agent, travel or service coordinator, business partner or another person submitting a request on your behalf. For example, a PPR applicant may provide limited details relating to crew members, passengers, representatives or the operator. We may also receive information from public authorities or official sources where this is necessary and lawful.
3.4 Special-category and unnecessary data
The Website is not intended for the submission of health data, biometric data, criminal-conviction data or other special-category personal data. Please do not include such information, confidential operational material or copies of identity documents in free-text fields unless expressly requested and strictly necessary for a lawful purpose.
4. Purposes and legal bases of processing
|
Processing activity |
Main data involved |
Purpose |
Legal basis |
|
Website operation and security |
Technical data, logs, IP address, device/browser data |
To provide the Website, maintain functionality, prevent abuse, investigate incidents and protect systems, users and operations. |
Legitimate interests (Art. 6(1)(f) GDPR) in secure and effective Website operation; legal obligations where applicable (Art. 6(1)(c)). |
|
General contact and B2B enquiries |
Identity, contact, professional and message data |
To receive, assess, answer and follow up your enquiry and, where relevant, take steps before entering into a contract. |
Steps at your request before a contract / contract performance (Art. 6(1)(b)); legitimate interests in managing communications and business enquiries (Art. 6(1)(f)). |
|
PPR and aerodrome-service requests |
Identity, contact, professional, aircraft, flight, service and operational data |
To assess and manage the request, confirm or refuse permission/services, communicate operational information, arrange fuel, parking or other services, maintain safety/security records and document the operation. |
Pre-contractual steps / contract (Art. 6(1)(b)); compliance with aviation, safety, accounting or other legal obligations (Art. 6(1)(c)); legitimate interests in safe and efficient aerodrome operations, security and claims management (Art. 6(1)(f)). |
|
Invoicing, accounting and payments |
Identity, business, billing, tax, transaction and payment-status data |
To issue and retain invoices, receive payment, maintain accounting records, prevent fraud and comply with tax obligations. |
Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)); legitimate interests in fraud prevention and financial administration (Art. 6(1)(f)). |
|
Invitations to future surveys, research or service feedback |
Name and contact details; consent record |
To contact you regarding voluntary surveys, research or service-feedback activities where you selected the optional consent box. |
Consent (Art. 6(1)(a)). You may withdraw consent at any time without affecting prior lawful processing. |
|
Customer satisfaction surveys |
Survey answers, ratings and comments. |
To evaluate service quality, identify areas for improvement, investigate specific feedback and produce aggregate statistics. |
Legitimate interests in evaluating and improving our services (Art. 6(1)(f)). |
|
Non-essential cookies and third-party content |
Cookie identifiers, usage and device data, interaction data |
Analytics, preferences, embedded content or other purposes described in the Cookie Policy and consent tool. |
Consent (Art. 6(1)(a) GDPR and applicable electronic-communications law). Strictly necessary technologies are used without consent only where legally permitted. |
|
Rights requests, complaints and legal claims |
Identity, contact, request/complaint data, supporting evidence and correspondence |
To comply with data-protection law, respond to requests, demonstrate compliance, establish facts and manage legal claims. |
Legal obligation (Art. 6(1)(c)); legitimate interests in establishing, exercising or defending legal claims and demonstrating compliance (Art. 6(1)(f)). |
Where processing is based on legitimate interests, we balance those interests against the rights and interests of the persons concerned. You may request further information about the relevant balancing assessment.
5. Mandatory and optional information
Fields marked as mandatory are required to process the relevant request, provide a service, comply with legal or operational requirements. If you do not provide required information, we may be unable to answer an enquiry, assess or confirm a PPR, provide requested aerodrome services or issue an invoice.
Optional information and optional consents are not required in order to submit a PPR, receive aerodrome services or make an ordinary enquiry. Refusing or withdrawing consent to future survey invitations does not affect the processing of the underlying PPR or service request.
6. Personal data relating to other persons
If you provide personal data relating to another person—for example a pilot, crew member, passenger, company representative or aircraft owner—you must be authorised to provide the information, ensure that it is accurate and provide the person with this Policy or otherwise ensure that they receive the information required by data-protection law.
We will use third-party data only to the extent necessary for the relevant PPR, operation, service, transaction, safety requirement, communication or legal obligation. Where appropriate, we may provide a separate notice directly to the person concerned.
7. Recipients and service providers
Personal data may be disclosed, on a need-to-know basis, to:
-
authorised employees, managers and operational personnel of Egnatia Aviation and the relevant aerodrome functions;
-
website hosting, maintenance, development, cybersecurity, IT support, email and cloud-service providers;
-
Microsoft 365 / Microsoft Forms or other survey and collaboration providers used for the customer satisfaction survey and related communications;
-
banks, accounting providers, tax advisers and auditors, where relevant;
-
fuel, ground handling, maintenance, transport, accommodation or other service providers where required to fulfil a request and where their role has been communicated;
-
lawyers, insurers, professional advisers, debt-recovery providers and competent courts or dispute-resolution bodies;
-
civil aviation, tax, law-enforcement, judicial, regulatory, emergency, safety or other public authorities where disclosure is required or permitted by law;
-
social-media, video, mapping, weather, analytics or other third-party providers when you choose to interact with their services or when technologies are activated in accordance with your cookie choices.
8. International transfers
Some technology, cloud, survey, social-media or embedded-content providers may process personal data in countries outside the European Economic Area (“EEA”). Where we make or permit such a transfer, we use an applicable legal transfer mechanism, such as an adequacy decision, the European Commission’s Standard Contractual Clauses together with appropriate supplementary measures, or another mechanism permitted by the GDPR.
Where you independently choose to visit or interact with a third-party website or platform, that provider’s own privacy information and transfer arrangements apply. You may contact the DPO for further information about safeguards relevant to transfers carried out by us.
9. How long we retain personal data
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, as described in this Privacy Policy, and thereafter only for as long as required or permitted by applicable law.
The applicable retention period is determined by taking into account, in particular:
-
the nature and purpose of the relevant processing;
-
the duration of our relationship or interaction with the person concerned;
-
applicable aviation, safety, security, accounting, tax and regulatory requirements;
-
the need to maintain appropriate operational, transaction and compliance records;
-
applicable limitation periods;
-
any pending complaint, investigation, dispute or legal claim; and
-
the need to establish, exercise or defend legal rights.
Accordingly, correspondence, enquiries and service requests are retained for the period necessary to manage and complete the relevant request and, where appropriate, for a reasonable period thereafter. PPR, operational, invoicing and service-related records may be retained for the periods required by applicable aviation, safety, security, accounting, tax, insurance and contractual obligations.
Where processing is based on consent, the relevant personal data are retained until consent is withdrawn, unless their continued retention is required or permitted on another lawful basis.
Cookie and similar-technology data are retained for the periods specified in the Cookie Policy and the Website’s consent-management mechanism.
Personal data relating to security incidents, complaints, data-protection requests, investigations or legal claims may be retained until the relevant matter has been finally resolved and the applicable statutory or limitation periods have expired.
At the end of the applicable retention period, personal data are securely deleted, destroyed or anonymised, unless their continued retention is required or permitted by law. The Company periodically reviews the personal data it retains in order to ensure that they are not kept for longer than necessary.
10. Cookies and similar technologies
The Website uses cookies and similar technologies. Technologies that are strictly necessary for the functioning, security, consent-management or communication features of the Website may be used without prior consent where permitted by law. Analytics, preference, advertising and non-essential third-party technologies are used only after the required consent has been obtained.
You can accept, reject or manage non-essential technologies through the Website’s consent-management tool and may change or withdraw your choices at any time through the persistent cookie-settings control. Further information, including provider, purpose and duration, is set out in the Cookie Policy.
11. Microsoft Forms and other third-party services
The Website currently links to a customer satisfaction survey hosted through Microsoft Forms. When you open and submit that form, Microsoft may process technical and account-related information in accordance with its own privacy documentation and may also act as a processor for the Company in relation to survey responses stored within the Company’s Microsoft environment.
The customer satisfaction survey is designed to collect responses anonymously. The Company does not request the participant’s name or email address through the survey and does not use the survey to identify individual participants. Participants should avoid including identifying information in free-text responses.
The Website may also contain links to or embedded content from social-media platforms, video providers, mapping, weather or other services. Depending on the implementation and your choices, these providers may receive technical data, such as your IP address and information about your interaction. Their own terms and privacy policies apply to processing carried out as independent controllers.
12. Security of personal data
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. Measures may include access controls, role-based permissions, authentication, backup and recovery, security monitoring, staff confidentiality obligations, processor contracts, incident-management procedures and periodic review.
No online service can be guaranteed to be completely secure. You should not send unnecessary sensitive information through ordinary email or free-text fields and should notify us promptly if you suspect unauthorised access or misuse affecting your interaction with the Website.
13. Personal data breaches
We assess and manage personal data breaches in accordance with Articles 33 and 34 GDPR. Where a breach is likely to result in a risk to the rights and freedoms of natural persons, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. Where the breach is likely to result in a high risk to affected persons, we also communicate the breach to them without undue delay, unless a lawful exception applies. Not every security incident therefore requires notification to the Authority or to individuals.
14. Your data-protection rights
Subject to the conditions and limitations of the GDPR, you may have the right to:
-
obtain confirmation as to whether we process your personal data and request access to it;
-
request correction of inaccurate data and completion of incomplete data;
-
request erasure of personal data where the legal conditions are met;
-
request restriction of processing in the circumstances provided by law;
-
receive data you provided to us in a structured, commonly used and machine-readable format and request transmission to another controller, where processing is automated and based on consent or contract;
-
object, on grounds relating to your particular situation, to processing based on legitimate interests; where data are processed for direct marketing, object at any time;
-
withdraw consent at any time, where processing is based on consent, without affecting processing carried out before withdrawal;
-
lodge a complaint with a competent supervisory authority.
These rights are not absolute. For example, we may retain information where processing is required by law or necessary for the establishment, exercise or defence of legal claims.
15. How to exercise your rights
You may submit a request through the Website’s “GDPR – Subject Rights Request Form” or contact the DPO using the details in section 1. Requests are generally free of charge. We respond without undue delay and in principle within one month, subject to any lawful extension for complex or numerous requests.
You are not required to use the same email address from which you originally contacted us. However, where we have reasonable doubts concerning the identity of the person making the request, we may ask for proportionate additional information necessary to verify identity. We will not request more information than reasonably necessary.
16. Children
The Website and its PPR, business and aerodrome-service functions are not directed to children. We do not knowingly request personal data from children under 15 through consent-based online services. Where Article 8 GDPR and Article 21 of Greek Law 4624/2019 apply to an information-society service offered directly to a child on the basis of consent, parental or guardian authorisation is required for a child under 15.
A person submitting a PPR or business request must have the legal capacity and authority required for the relevant action. If we learn that data have been submitted by a child without the required authorisation, we will take appropriate steps to delete or otherwise lawfully manage the information.
17. Links to other websites
The Website may link to third-party websites and services. We do not control their privacy practices and this Policy does not apply to processing carried out by those third parties as independent controllers. You should review their privacy information before providing personal data or using their services.
18. Right to lodge a complaint
If you believe that your personal data have been processed unlawfully, you may first contact our DPO so that we can examine the matter. You also have the right to lodge a complaint with the Hellenic Data Protection Authority:
Hellenic Data Protection Authority
Kifissias 1–3, 115 23 Athens, Greece
Telephone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
As this notice and the personal data protection conditions contained herein may be subject to change, the Subject should regularly update the content of this notice and check for any changes.
Last update: 26.06.2026