Privacy & Personal Data
Information about your visit, your enquiries and your data protection rights.
Last updated: 7 October 2026
Data controller & privacy contact
This notice covers the MEDLUXE destination portals at medluxe.com and medluxe.ai, including their www addresses and these privacy pages. It describes browsing these portals and contacting MEDLUXE using their email and telephone links.
MEDLUXE ENERGY MONOPROSOPI AE, the Greek company operating medluxe.com and medluxe.ai, is the data controller for the operation of these destination portals and the enquiries it handles through them. Contact us about your personal data at info@med-luxe.com, by telephone at +30 211 008 3841, or at Aglavrou 16–18 & Sikelias Str, Koukaki, Athens 11741, Greece.
MEDLUXE is also the shared brand used by separate businesses in Greece, Bali and Dubai. Enquiries handled directly by a separate destination business are subject to that business's privacy information.
The linked destination websites, booking platforms and social networks have their own privacy information and settings. This notice does not replace those notices or the information provided for a particular booking.
What data is involved
- Website visits: hosting and security services may process your IP address, browser and device information, requested pages, request times and technical or security logs to deliver and protect the website.
- Enquiries: if you email or call us, the receiving business receives the information you choose to provide, such as your name, email address, telephone number, travel interests and message.
- No account or payment collection on these portals: these pages contain no registration, booking, payment or contact-submission form. Email and telephone links open the relevant application on your device.
Please provide only the information needed for your enquiry. Do not include payment card details, passwords, medical records or identity documents in an ordinary email.
Why data is used
Technical information supports website delivery, troubleshooting and protection against misuse. Contact information supports responding to your enquiry and taking steps you request before a possible booking or agreement.
Where the GDPR applies, the relevant grounds are legitimate interests in operating a secure website and managing ordinary correspondence, steps requested before a contract, and compliance with applicable legal obligations. Where a separate optional activity relies on consent, that consent must be requested separately and can be withdrawn. Sending an enquiry does not constitute consent to marketing.
Cookies & browser storage
These destination portal pages do not load analytics, advertising tags or third-party embeds, and do not save language preferences or other optional settings in your browser. There are no optional tracking cookies to accept on these pages.
The hosting or security infrastructure may use strictly necessary cookies when needed to protect access. For example, Cloudflare may supply __cf_bm for bot protection, which expires after 30 minutes of inactivity, or cf_clearance following a security challenge, with a lifetime determined by the challenge settings. These examples apply only when supplied by the infrastructure.
You can inspect or clear cookies and site data through your browser settings. Blocking necessary security cookies can affect access checks. Choices made on a linked destination website are separate from these portals. Cloudflare cookie information.
Service providers & international processing
The portals use Sites and Cloudflare infrastructure for hosting and delivery. When you contact MEDLUXE, email or telephone providers and the team handling your enquiry may process the relevant communication. Following an external link connects you to that provider under its own privacy arrangements.
Depending on the destination and providers involved, processing may take place outside your country, including outside the European Economic Area. Where the GDPR applies, an international transfer requires a permitted transfer mechanism, such as an adequacy decision or appropriate safeguards, unless a specific legal exception applies. Contact us for the recipients, locations and safeguards relevant to your enquiry.
How long information is kept
These portals do not maintain a visitor account or enquiry database. Technical-log retention depends on the hosting and security services. For correspondence, the relevant criteria are the time needed to answer and follow up your enquiry, any resulting contractual relationship, and applicable record-keeping or legal-claim requirements. You may request the retention period or criteria applying to your particular information using the contact below.
Your data protection rights
Subject to the applicable law and its conditions, you may request access to your personal data, correction, deletion, restriction of processing and portability. You may also object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it without affecting the lawfulness of earlier processing.
Send a request to the privacy contact below, identifying the website or destination involved. We may need proportionate information to verify your identity. Under the GDPR, requests generally require a response within one month; a permitted extension must be explained within that period. You may complain to the competent data protection authority, including the Hellenic Data Protection Authority where applicable.
Security & updates
These portals use HTTPS and restrictions on external content and embedded pages. No website or communication method can guarantee absolute security. The date at the top identifies this notice's latest update; material changes to the portals' data handling should be reflected here.
Make a privacy request
Tell us which website or destination your request concerns and what you would like to access, correct or delete.
info@med-luxe.comMEDLUXE ENERGY MONOPROSOPI AE
Contact address
Aglavrou 16–18 & Sikelias Str
Koukaki, Athens 11741, Greece
+30 211 008 3841