
Loading
Lockely

Loading
Lockely
Lockely
Last updated: 7 August 2026
This policy explains what personal data Lockely collects when you book luggage storage in Athens, why we use it, and your rights under the EU GDPR. Controller contact: [email protected] · +30 6944 773 755 · Santaroza 3, 10564 Athens.
Lockely operates a staffed luggage storage counter in Athens and is the data controller for the processing described here. Privacy requests: [email protected] (subject line “Privacy”).
Booking data: email, phone, optional name, bag counts and sizes, drop-off and pick-up times, booking reference, PIN, and QR token.
Payment data: for card payments, Stripe processes the card. We store payment status, amount, and Stripe references — never full card numbers. For cash, we record that payment was collected at the counter.
Account data: if you sign in with email OTP or Google, we store your email and basic profile fields needed for the session.
Operational data: check-in and check-out timestamps, staff actions on your booking, and CCTV in the storage area for security.
Technical data: security cookies for signed-in sessions, and Cloudflare Turnstile tokens when you submit booking or contact forms (to prevent abuse).
Contract: to create and perform your storage booking, identify you at the counter, send confirmation emails, and process refunds.
Legitimate interests: to prevent fraud and abuse, keep the premises secure (CCTV), and improve reliability of the service.
Legal obligation: to keep accounting and tax records where Greek law requires.
Consent: where we ask for optional marketing (we do not currently send marketing emails).
Active booking records are kept for the storage period and a short period afterward for disputes.
Invoices and payment records are kept for the statutory Greek accounting retention period.
OTP codes are hashed and expire within minutes; expired codes are deleted.
CCTV is kept on a short rolling cycle and then overwritten, unless needed for an incident investigation.
Stripe (card payments), Amazon SES (transactional email), our hosting provider on AWS (application and database), Cloudflare (DNS, security, Turnstile), and Google (only if you choose Google Sign-In).
We do not sell personal data. We do not use your booking data for advertising.
Some providers may process data outside the EEA. Where they do, we rely on appropriate safeguards such as EU Standard Contractual Clauses or an adequacy decision.
You may request access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may withdraw consent where processing is consent-based.
You may lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr). We ask that you contact us first so we can help.
We use essential httpOnly session cookies after you sign in. Turnstile may set cookies required for bot protection on forms. We do not set advertising cookies.
The service is intended for adults making travel bookings. We do not knowingly collect data from children under 16.
We may update this policy. The “Last updated” date above shows the current version. Material changes will be reflected on this page before they apply to new bookings.