Legal
Privacy Policy
Last updated 8 October 2026
Who we are
This website is operated by Future Hotels International SMPC, Building C, Monumental Plaza, Kifisias 44, Marousi Attikis 15125, Athens, Greece (“Future Hotels,” “we,” “us”). We are the data controller for the personal data described below, under the EU General Data Protection Regulation (GDPR) and applicable Greek law. Contact us at hello@futurehotels.eu.
What we collect, why, and on what legal basis
We only collect what's needed to run the parts of the site you actually use:
- Travellers’ Club sign-up — your full name, email address, phone (optional) and country, submitted via our sign-up form, and the date you joined, on terms that confirm you are 18 or over, to review your request and issue your membership, member number and card. Processed to take steps toward the membership contract you request (GDPR Art. 6(1)(b)). If you tick the marketing checkbox, we'll also email you about newly announced member hotels and offers — that's based on your separate, opt-in consent (Art. 6(1)(a)), which you can withdraw at any time (see “Your rights” below).
- Your birthday (optional) — the day and month of your birth (never the year), only if you add it yourself in your member area, used to mark your birthday with a welcome or an offer from member hotels. Based on your consent (Art. 6(1)(a)); you can remove it at any time from your account.
- Hotel membership applications — the details you submit in the application form (hotel name, location, your name, role, email, phone and message), sent to our team to review. Processed to respond to your enquiry and take steps toward a contract at your request (Art. 6(1)(b)), or our legitimate interest in evaluating applications (Art. 6(1)(f)).
- Hotelier portal accounts — your hotel name, contact name, email and a password, to create and manage your account and verify you as an approved member before granting access to the opportunities board. Processed to perform the membership contract (Art. 6(1)(b)).
- Embedded video and audio — the About page carries interviews and podcast episodes hosted by YouTube, SoundCloud and Spotify. They are click-to-load: the preview image is served from our own domain, and nothing is requested from those providers unless you press play. If you do, that provider receives your IP address and device information and may set its own cookies, as an independent controller under its own privacy policy. We embed YouTube through youtube-nocookie.com to limit this. No data reaches any of them if you don't press play.
- Google Analytics (consent only) — if, and only if, you accept it on the banner, we use Google Analytics to measure how the site is used. It sets its own cookies and Google acts as our processor, with IP anonymisation on and advertising and personalisation signals disabled. This is based on your consent (Art. 6(1)(a)), which you can withdraw at any time by clearing this site's data in your browser and choosing “Decline”. Declining means no Google script loads and no data leaves your browser. Google may process this data outside the EU/EEA under the safeguards described below.
- Site analytics — for every visitor, not just those who fill in a form, we use Vercel Web Analytics to see aggregate traffic patterns: page views, referring site, approximate country and device type. It’s cookieless and doesn’t identify you individually, based on our legitimate interest in understanding and improving the site (Art. 6(1)(f)). See our Cookie Policy for more detail.
We do not sell your personal data, and we don't carry out automated decision-making that produces legal or similarly significant effects on you.
We do use it for advertising, but only if you asked us to. That is a separate, optional tick when you join the Travellers' Club, it is off unless you turn it on, and your membership is identical either way. What it involves is set out under Advertising, if you asked for it below.
Where it's processed, and international transfers
Depending on which parts of the site you use, your data may be processed by infrastructure providers acting on our behalf, under data processing agreements: Vercel (hosting and analytics), Supabase (account and application data), Resend (transactional email, where used), and — only where you have accepted analytics cookies — Google (Google Analytics). The hotel membership application is processed via Formspree. Travellers’ Club sign-ups are not: those go directly to Supabase, and the confirmation and membership emails are sent through Resend.
Some of these providers may process data outside the EU/EEA, including in the United States. Where that happens, we rely on the safeguards recognised under GDPR Chapter V — the EU Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework — to make sure your data stays protected to the same standard.
What member hotels see
Member hotels receive some Travellers’ Club data too. When you give your member number at a member hotel, that hotel sees only what its desk needs: your first name and the initial of your surname, your member number, the year you joined, your tier, and any hotel credit due on the stay.
The hotel uses this to credit your stay, honour your member benefits, and handle your stay claims and member offers. If you send it a stay claim or show it a member voucher, it also sees what you sent it: the dates of the stay, the booking reference and any note you add, or which of its offers the voucher is for. We share this to provide the membership you joined (GDPR Art. 6(1)(b)).
Hotels never see your email address, phone number or other contact details, your birthday, your preferences, or your stays and activity at other hotels.
Each member hotel is an independent controller of what it receives, and handles it under its own privacy notice.
Owners’ Club
A member hotel can designate the people behind it to the Future Hotels Owners’ Club. If your hotel designates you, it gives us your name, email address, role and relationship to the hotel, so that we can invite you. The hotel tells you before it designates you.
We use these details to send you the invitation and to run your membership. Sending the invitation rests on our legitimate interest, and your hotel’s, in recognising the people behind it (Art. 6(1)(f)); running the membership you accept is part of providing it (Art. 6(1)(b)).
When you stay at another member hotel, it sees only your name (your first name and the initial of your surname), the hotel you represent, that you are an Owners’ Club member, and the year you joined. Other hotels never see your email address or your relationship to your hotel.
You can ask us at any time to end your membership and erase your details: write to hello@futurehotels.eu.
Advertising, if you asked for it
When you join the Travellers' Club there is an optional tick marked Show me Future Hotels advertising. It is unticked. Your membership, your member number, your card and every benefit are identical whether you tick it or not, and we will never make it a condition of anything.
If you do tick it, we give your email address to Google and Meta so they can recognise you as an existing member and show you our advertising, and so we can ask them to reach people whose interests resemble yours. That second part means our ads may be shown to people who never gave us anything — they are found by resemblance, not from your details.
Your address is hashed before it is sent, which means we do not hand it over in readable form. Hashing is not anonymity. The whole point is that it identifies you to them, because that is how the matching works. It remains your personal data, and everything on this page still applies to it.
For this, Google and Meta are joint controllers with us: we decide to run the campaign and supply the list, they do the matching and the serving. You can exercise your rights against either of us, whatever the arrangement between us says. Write to hello@futurehotels.eu and we will act on it, including telling them to remove you.
The lawful basis is your consent, and nothing else. You can withdraw it at any time from your preferences page — the link is in every email we send you, not only the marketing ones, so it is there even if you asked for advertising and no emails. Withdrawing stops it from then on. It does not make what we did while it was on unlawful, and it cannot pull back an advert already shown.
Members who joined before this option existed were never asked about advertising, so it is off for all of them. We are not treating an old answer about email as permission for something we never described.
Your rights
If you are in the EU/EEA, UK or a jurisdiction with similar protections, you have the right to access, correct, delete or export your personal data, to object to or restrict certain processing, and to withdraw consent (e.g. marketing emails) at any time without affecting the lawfulness of processing before withdrawal. To exercise any of these rights, email hello@futurehotels.eu — we’ll respond within one month, as GDPR requires.
You also have the right to lodge a complaint with a supervisory authority. In Greece, that's the Hellenic Data Protection Authority, or the data protection authority in your own EU/EEA member state.
How long we keep it
Membership data: for as long as you are a member. Membership does not expire, so neither does the record — but you control it. You can close your membership and have your details deleted at any time, from your preferences page or by emailing us, and we act on it straight away. The only things that survive are records we are required to keep by law, for example for tax or accounting.
Travellers’ Club sign-ups that never confirm their email are of no use to us and are deleted periodically.
The record of what you agreed to: we keep the answer you gave, the date, and which version of the wording you were shown, for as long as we rely on that permission and for one year afterwards, because we have to be able to show it was given. That is all we keep for this — we do not log your IP address or your browser to evidence consent.
Keeping your data secure
We use industry-standard safeguards — encrypted connections (HTTPS), access controls on our databases, and service-role credentials that never reach your browser — to protect the data described above. No method of transmission or storage is perfectly secure, but we work to keep your data safe and to limit access to those who need it to run the site.
Children
This site is not directed at children, and we don't knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we'll delete it.
Cookies
See our Cookie Policy for details on the cookies this site uses.
Changes to this policy
We may update this policy as the site evolves. Material changes will be reflected by updating the date above.