We use cookies to ensure you get the best experience on our website. For more information on how we use cookies, please see our cookie policy.
Last updated: March 5th, 2026
This Privacy Policy applies to all individuals who interact with the Platform, including Users, Students, and Guardians, as defined in the Students' Terms of Use (hereinafter referred to as "you"). With respect to Hosts, the processing of their personal data is governed by the Hosts' Privacy Policy.
The company under the name "HeyStudent SINGLE MEMBER PRIVATE COMPANY", based in Athens (Attica), with Tax Identification Number 802691928 of the Tax Office KEFODE ATTIKIS and business registration number 181034103000 (hereinafter referred to as the "Company" or "we") hereby informs you, as the Data Controller, in accordance with the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as "GDPR") and the relevant provisions of the Greek legislation on the protection of personal data, as applicable, on the type of personal data collected, the source of their collection, the purposes of their collection and processing, any recipients thereof, their time of retention, any transfer outside the EU, as well as your rights in relation to your data as a Platform User / Student (or Guardian) and how you can exercise them.
The Company is the Data Controller of your personal data processed when using the Platform and the Services provided through it, e.g. when creating a Student Account on the Platform and communicating with the Company in relation to the Platform Services. In certain cases, each Host may act as a joint Data Controller together with the Company, while in other processing activities, the Host shall act as an independent Data Controller.
The personal data that we collect varies depending on the use of our Platform and may include the following:
When you browse and use the Platform, we automatically collect information, including personal data, about the pages you visit, the services you use and how you use them. This information may include information about your interactions with the Platform, log data and device information, IP address, dates and times of access, hardware and software information, geographic location, browser type and version and operating system, cookie data and data from similar technologies, as well as other information about the Platform's use. For more information on the use of cookies and similar technologies, please read the Platform's Cookie Policy.
To sign up on the Platform, the User must provide a full name, while registration may be completed either by submitting an email address or phone number, or by signing up through a Google or Apple account.
To complete the sign-up process, the User must be verified as a Student, which shall be demonstrated by providing proof of student status (such as a Student ID or Student Letter) and by providing a valid ID or passport. This requires successful completion of the Persona platform identity verification system, the terms of which shall apply during the verification process.
The Company also collects the following data from Students who choose to register on the Platform by creating a Student Account: the password they choose to log in to their Account, their Bookings, list of favorite Properties (wish list) as well as any comments of the Booking, university name and expected graduation date.
When a minor registers on the Platform through a Guardian, we may collect the following information from the Guardian: personal details, such as full name, email address or phone number, a valid ID or passport. This requires successful completion of the Persona platform identity verification system, the terms of which shall apply during the verification process.
Contact details and any information included in User/Student communications with the Platform or the Host through communication via the Platform, including the content of the communication and metadata.
Bank card data: The debit/credit card data necessary for payment purposes through the Platform.
Any information contained in or resulting from the evaluation you submit and may relate to your experience on our Platform, the Hosts, the Properties and the services provided.
When registering as a User or logging in to your Account via a third-party service (such as Google, Apple), this service may transmit data to us, such as registration information and your profile details on that service. This information varies and depends on the third-party service. You can adjust the information transmitted through your privacy settings within your profile on those services. Please note that our Company is not responsible for the collection and processing of personal data by these services for their own purposes, carried out in accordance with the privacy policies of each service, and we recommend that you read the policies of each service before browsing them.
The Platform Services do not require the collection of special categories of personal data (such as health data). If, however, we detect or you disclose such data to us on our Platform or in our communications, which may be related to a specific request, we will transfer such data to the relevant Host to respond to your request as an independent data controller and will delete it immediately, unless we need to retain it to support our legal rights.
The Company collects and processes personal data relating to Students who submit a Booking request for a Host's property through the Platform, which (data) is subsequently shared with the Host in the context of their cooperation and the necessary performance of the booking acceptance procedure by the Host.
The Host and the Platform act as joint controllers, with respect to the personal data of Students and Guardians processed in connection with the management of Bookings through the Platform and the facilitation of communication between Hosts and Students or Guardians via the Platform's messaging or chat functionality.
Each Host is independent controller with regard to the Student's personal data for all processing activities conducted for the formal completion of the booking and the submission of the relevant information to the competent state platforms for rental reporting purposes; these processing activities pertain to the Host's own operations relating to property Booking and are carried out using its own resources, particularly in relation to providing the Properties to Students, in accordance with its own policies and its legal obligations.
The Host shall be regarded as an independent Data Controller with respect to any personal data of Students that is collected or otherwise processed by the Host outside the Platform.
Your personal data is being processed by the Company only for legitimate purposes in the context of Platform Services. More specifically, the Company processes your data:
For the processing of your personal data collected in accordance with the above, we rely on the following legal bases for processing, depending on the process and purpose of processing:
The processing of your data is necessary for the performance of the contract to which you are a party, such as the creation of your Student Account and the provision of the requested Services, as well as to take measures at your request prior to the conclusion of the contract.
The processing is necessary for the purposes of legitimate interests pursued by the Company or a third party, such as Hosts, such as:
The processing is necessary to comply with legal obligations to which the Company is subject, such as for example tax legislation, consumer protection legislation or legitimate law enforcement requests.
Your personal data is being processed upon obtaining your specific consent for specific purposes which require prior consent, such as the use of optional cookies on the Platform.
Your data is being stored in a secure manner on servers and computer systems within the EU and is being processed within the European Economic Area (EEA). However, in the event that data needs to be transferred to a third country, the Company will take appropriate measures (safeguards), such as ensuring that such transfer takes place in a country that enjoys an adequacy decision or will apply standard contractual clauses, to ensure an adequate level of data protection and the lawfulness of the processing.
Students and Guardians' data will be accessible by Hosts, who either act as joint controllers with the Company or as independent controllers.
In order for the Company to fulfill the above-mentioned purposes and its relevant obligations, it may disclose Users'/Students' personal data to categories of persons or entities (recipients).
Recipients will have access only to as much of your personal data as is strictly necessary for the fulfilment of the tasks or the provision of the services undertaken towards the Company.
The recipients' categories are the following:
Your personal data will be retained by the Company only for as long as is necessary for you to use our Services and for the Company to be able to provide such Services to you, for the Company to comply with applicable law, to resolve any disputes with any parties, and for the seamless provision of our Services, including the detection and prevention of fraud or other illegal activities. In particular:
In any case of account or data deletion, we delete your data, with the exception of personal data which:
Please note that, in any case, the relevant Host will retain your necessary data in accordance with its practices and for as long as required by applicable law and its legal obligations as an independent controller.
If you have a question about the specific retention period for certain types of personal data we process, please contact us using the contact details provided below.
You have the following rights under the GDPR (Articles 12-22) as a data subject:
To exercise any of your rights in relation to your personal data you may contact us by e-mail to support@heystudent.com.
Please note that in order to respond to any of the above requests, we will require you to provide us with appropriate proof of your identity.
The Company may not satisfy a request where it demonstrates compelling and legitimate grounds for the processing which override the interests, rights and freedoms of the data subject, or for the establishment, exercise or defence of its legal claims. Furthermore, the exercise of certain of the above rights may result in an impediment to the provision of the Services.
In any case, we inform you that we will respond to your requests without delay, and in any case, within one month of receipt of the request. This period may be extended by a further two months, if necessary, taking into account the complexity of the request and the number of requests, upon informing you of such extension within one month of receipt of the request and the reasons for the delay.
In any case, we inform you that we will respond to your requests without delay, and in any case, within one month of receipt of the request. This period may be extended by a further two months, if necessary, taking into account the complexity of the request and the number of requests, upon informing you of such extension within one month of receipt of the request and the reasons for the delay.
Finally, you have the right to submit a query to the Company regarding the way your personal data is processed and protected, and in case you consider that any of your rights are violated, you have the right to file a complaint to the Hellenic Data Protection Authority, by addressing the complaint to the Authority electronically by filling in the corresponding online form depending on the type of complaint at https://www.dpa.gr/el/polites/katagelia_stin_arxi.
The Company implements appropriate technical and organisational measures and procedures to protect the personal data processed against the risks of accidental or unlawful destruction, loss (including accidental events), access, alteration and unauthorised disclosure. Your data is stored in the Company's secure repositories and is only accessible by a limited number of Company staff, during the performance of their work, who have special access rights to these systems and are bound by a confidentiality obligation. In addition, third party processing providers acting on behalf of the Company in the performance of their duties are contractually obliged to implement appropriate technical and organisational measures to ensure the best possible protection of personal data against accidental or unlawful destruction, damage or loss, alteration or unauthorised access and, in general, unlawful processing of data.
External links: The Platform may include hyperlinks to third party websites. These hyperlinks have been established for the sole purpose of facilitating the Users during their browsing on the Internet and do not constitute in any way the acceptance or approval by the Company of the content of the third party websites. By clicking on these hyperlinks, you are directed away from the environment of our Platform. We do not control third party websites and we are not responsible for their content or the collection and processing of data that may take place by the third party. If you follow a hyperlink to a third party website, we advise you to read the third party's privacy policy.
Social Plug-ins/Buttons: Our Company appears on social media. You can visit these networks by clicking on the Social Plug-ins/Buttons on our Platform. These third-party services may collect and process personal data in accordance with their own policies. We are not responsible for the processing performed by these media, and it is your responsibility to be informed about their own privacy policies.
We encourage you to periodically review this Policy to keep up to date on how the Company processes your data.
This Policy may change from time to time in order for the Company to respond to User feedback, changes in the Services provided or changes in the legal framework. If there are material changes to this Policy, the Company will notify Users either by displaying a notice on the Platform before the changes take effect, or by sending Users a notice by email.
If you have any questions about this Privacy Policy and how we process your personal data, you can contact us by email to the following email address: support@heystudent.com
Capitalized terms have the same meaning as given to them in the Platform's Terms of Use. In addition, for the purposes of this Policy, the following definitions are provided: