Privacy Policy — Asterousia Trails

Last updated: 4 August 2026

1. Who we are

The Asterousia Trails app (the "App") is provided by Municipality of Gortyna, registered at Agioi Deka, Heraklion, Crete, Greece ("we", "us"), acting as the data controller for the personal data described below.

For anything concerning your data EMAIL: asterousiatrails@gmail.com

2. Our basic principle

The App is designed to work without an account. You can browse trails, view maps, navigate and record your hikes without creating an account and without giving us any personal information at all.

An account is only needed if you want to write a review or create your own trail lists.

3. What data we collect

3.1 Account details — only if you register

Data Purpose Legal basis
Email address Identification, account verification, password reset Performance of a contract (Art. 6(1)(b) GDPR)
Password Account security — stored hashed; we cannot read it Performance of a contract
First / last name (optional) Showing your name on your reviews Performance of a contract

3.2 Location — stays on your device

The App asks for location access in order to:

Your location is never sent to us or to any third party. Location data and recorded hikes are stored only on your device and are deleted when you delete the recording or uninstall the App.

Location access is requested only while you are using the App. While a hike is being recorded a persistent notification is shown, so you always know when the App is using GPS. You can revoke the permission at any time in your device settings.

3.3 Content you create — only if you have an account

published after moderation.

3.4 Anonymous usage statistics

We record which trails are viewed so we can improve the content. Each such record contains only the trail identifier and the event type (e.g. "view").

It contains no user identifier, device identifier, IP address or anything else that could identify you. These statistics cannot be linked back to you.

3.5 What we do NOT do

4. Where data is stored

Account data and content you create are stored on a server we control, located within the European Union. The App always communicates with the server over an encrypted connection (HTTPS/TLS).

5. Third parties

We use as few external services as possible:

Service Role What it receives
OpenTopoMap Base map tiles Your device requests map tiles directly from their servers. They see your IP address and which map area you are viewing — not your route or your identity. You can avoid this entirely by downloading a trail for offline use.
Brevo Email delivery Your email address, solely to send account verification and password-reset messages.

We do not share data with third parties for advertising or commercial purposes.

6. How long we keep data

7. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, portability and to object to processing.

Two of these you can exercise directly inside the App, without contacting us:

account and the content linked to it)*

For anything else, email us at EMAIL: asterousiatrails@gmail.com . We respond within one month.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or your local supervisory authority.

8. Security

Passwords are stored hashed and are not readable by us. All communication uses HTTPS/TLS. Access to the server is restricted and protected.

No method of transmission is completely secure, but we commit to notifying you without undue delay if a breach affecting you occurs.

9. Children

The App is not directed at children under 13 and we do not knowingly collect their data. If we become aware that we have, we will delete it.

10. Changes

If this policy changes materially we will update the date at the top and notify you inside the App.

11. Contact

Municipality of Gortyna -  Agioi Deka, Heraklion, Crete, Greece - email:asterousiatrails@gmail.com