WEMA — Wellness & Massage

Privacy policy & data protection

Protecting your personal data is a priority for WEMA. This policy is written in line with the General Data Protection Regulation (EU) 2016/679.

Last updated: January 2026

1. Data controller

The data controller is WEMA — Wellness & Massage. For anything related to your data you can contact us at support@wema.gr.

2. Data we collect

Account details (name, email, phone), booking details (address, session date and time, notes), therapist business details (title, services, prices, service areas, payment details) and technical browsing data.

3. Purposes and legal basis

We process your data to perform our contract with you (managing bookings and your account), to comply with legal obligations, for our legitimate interests (security and service improvement) and, where required, on the basis of your consent (analytics and marketing cookies).

4. Data recipients

Only the details strictly needed to deliver the session are shared with the therapist you choose. We also use hosting and infrastructure providers acting as processors within the EU.

5. Retention

We keep your data for as long as your account is active and for as long as tax or legal obligations require. After that it is securely deleted or anonymised.

6. Your rights

You have the right to access, rectify, erase, restrict and port your data, as well as to object and to withdraw your consent at any time. You may also lodge a complaint with the Hellenic Data Protection Authority.

7. Security

We use encryption in transit, strict database access rules and regular security reviews to protect your information.

For any question, contact us at support@wema.gr.