Security of Transactions
Last updated : 2 June 2025
Scope
This page describes how we safeguard every online payment on www.villa-loutraki.gr.TLS/HTTPS encryption
All forms and payment pages are served over TLS 1.3 with an “https://” URL.Payment-card processing with WebHotelier
• We never see full card numbers; WebHotelier’s Payments Assistant Manager tokenises them.
• WebHotelier holds a PCI-DSS Level 2 certificate, audited by Trustwave.
• Transactions are protected by 3-D Secure / SCA under PSD2.Server & platform security
• Hosting in an ISO 27001 EU data centre with Web Application Firewall.
• Early-TLS protocols disabled; only modern cipher suites allowed.
• Daily encrypted off-site backups; access needs 2-factor authentication.Fraud monitoring
WebHotelier’s real-time risk engine evaluates every payment; suspicious activity is held for manual review.Access control
Only authorised staff can reach the admin dashboard, protected by unique credentials and TOTP/HW-key 2-factor login.Data minimisation & retention
Card tokens deleted seven days after check-out; accounting files kept ten years as required by Greek tax law.Your responsibilities
Keep your device updated, never share security codes, and notify us immediately of any suspected unauthorised use.Contact
reservations@villa-loutraki.gr | +30 6970 497 702