Data protection

PRIVACY NOTICE

D. THANOPOULOS S.A. (“Company”) takes the privacy of its clients seriously into account. This Privacy Notice is to let you know how the Company protects the privacy of your communications and collects, process, use and store your personal data through our Website as well as the rights you have with regard to the foregoing collection and processing of your personal data. By visiting our Website and using our services you acknowledge of having read and fully taken into account this Privacy Notice.

This Privacy Notice applies only to our Website under the top level domain www.thanopoulos.gr. Users should be aware that our Website may also contain links to other websites, yet our Company cannot be held responsible for the data processing practices or the content of such websites.

 

Definitions

For the purposes of this Privacy Notice the following definitions shall apply :

“Consent” - Any explicit, specific and freely given indication by which the User, after  having been fully informed, signifies her agreement to personal data relating to her being processed. 

“Cookie” - short text of software code, which is transmitted from the web server of our Company and stored at your device each time that you enter the Website. “Personal Data” - Any information relating to an identified or identifiable user of the Website.

“GDPR” - the General Data Protection Regulation (EU) 2016/679, of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC, as amended, replaced or superseded and in force from time to time and as transposed into member-state legislation.

 “Personal Data” - any information which relates to a User, who can be identified directly or indirectly.

“Processing” - Any operation or set of operations which is performed by our Company on the personal data of the users of the Website, whether or not by automatic means, such as collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, blocking, erasure or destruction;

 “User” – Any internet user who accesses and browses at the Website.

 “Website” – The world wide web website which is accessible through the domain name www.thanopoulos.gr including all of its webpages.

 

Subject Matter

The present Notice sets out the terms and conditions which the Company follows in order to protect the privacy of our clients. It describes the conditions under which we make any collection and processing of your personal data and ensure their confidentiality (“Privacy Notice”). 

The Company reserves the right to amend and update this Privacy Notice, whenever it deems it appropriate, and any changes thereof shall come in force and effect from the instance they appear online at the present webpage of the Website.

If any provision of this Privacy Notice is declared void or unenforceable, such provision shall be severed from this Privacy Notice, which shall otherwise remain in full force and effect to the extent that the original intent of this Privacy Notice will not be altered in any material respect.

 

Principles of Data Processing  

We fully respect your fundamental rights and render protection of your privacy a priority of our Company. In this context, when processing your personal data, we follow the following basic principles : 

We submit your personal data to legitimate and legitimate processing, and we maintain full transparency vis-à-vis the way we handle your personal data. 

We collect and process your data only for specified, explicit, and legitimate purposes as outlined in this policy, and we do not process it further in a manner incompatible with these purposes. 

We process your personal data only to the extent that it is appropriate and relevant to the above purposes, while limiting the processing to the measure necessary for these purposes. 

We make reasonable efforts with your own assistance to ensure that your processed data is accurate and, where necessary, updated with regard to the purposes of the processing, taking all reasonable steps to immediately delete or correct it in case of inaccuracy. 

We keep your personal data in a form that allows you to identify yourself only for the time required for the above processing purposes. 

We process your personal data in a way that guarantees its security by using appropriate technical or organizational measures. 

We do not intend to further process your personal data for purposes other than the oneS for which they are collected. 

We inform you that there is no obligation to provide your personal data and that there are no possible consequences from the choice not to provide it. Furthermore, we inform you that your personal data will not be used for automated decision making, including profiling. 

Without prejudice to what is stated in this policy, we do not disclose and transmit your personal data to third parties without your consent, unless permitted by law or by our contractual agreement with you. 

Please be advised that we do not pass on your personal data to a third country or international organization for which there is no European Commission decision under the GDPR. 

In general, we comply with all applicable laws and comply with all our statutory obligations, as data controllers of your personal data.

 

Types of Data Collected

The categories of personal data which we collect from you depend on the products and services you choose to purchase from us. At the point (a) of your access and during your use of our Website, (b) of your registration as user, (c) of your registration at our newsletter service, (d) in the process of purchasing products / services, (e) your participation in our loyalty card scheme and (g) when you consent to give us permission to obtain personal data from personal accounts for social media and / or other online services of third parties, you may provide the following types of personal data to our Company:

At the point of your access and during the use of the Website 

IP Address.

End user device data

General communication data.

Browsing data.

Information on user preferences regarding the Website products / services.

Data regarding executed transactions. 

At the point of your registration for your personal account and/or each time you log-in: 

Username.

Password.

E-mail.

Name / Surname.

Address and contact data.

Tax and invoice data.

Paypal and/or bank account details.

At the point of your registration at our newsletter service : 

E-mail.

At the point of purchasing our products / services : 

Information regarding your order.

Credit / debit card and/or paypal account details or other data regarding the execution of your payment.

Choice of payment method.

Choice of shipping option.

Shipping address.

Tax data.

At the point of applying for the issuance of our loyalty card : 

Name / Surname.

E-mail.

Telephone.

Address and contact data.

At the point of giving us permission to obtain personal data from personal accounts for social media and / or other online services of third parties : 

Information stored in such accounts.

At the point of accepting the receipt of advertisements [e.g. banners, hyperlinks or plugins] and any other type of commercial communications placed at or communicated through the Website or through our social media channels : 

All personal data directly provided by you.

Non-personally identifiable information regarding the popularity of such commercial communications.

Any other personally identifiable information directly provided by you during the use of our electronic commerce services or during interaction with our social media channels.

In addition, when you communicate with us by email or by any other means, we collect and process personal data relating to such communications under the terms and conditions hereof in order to correspond to your requests and to improve our services.

Our Company may store your credit / debit card and/or paypal data under strict conditions of confidentiality and with the use of secure communication protocols. In addition, if you communicate with us via email or by other means, we will collect your personal data related to such communications under the terms and conditions of this Privacy Notice, in order to respond to your requests and to improve our services.

Our Company does not collect or gain access in any way to special categories ("sensitive") of personal data or data relating to criminal convictions and offenses by its clients. You have an obligation to refrain from posting such data concerning yourself or third party data subjects. In the event that you submit such data to our Website, these will be removed as soon as we become aware of them. We have no liability to you or to any third parties for any processing of sensitive data due to your actions or omissions in breach of this obligation.

 

Purposes and Legal Bases of Data Processing 

Personal data necessary for the provision of our services within our contractual relationship is collected and processed by our Company pursuant to article 6 § 1 (b) of the GDPR for the following purposes :

Performance of our contractual obligations towards our Users and Clients.

Immediate, adequate and appropriate delivery of our products and provision of our services.

Tax use and use for pricing and proof of delivery of ordered products / services.

Communicating with our clients in the framework of the execution of our services and for the resolution of any complaints.

In addition, your personal data is collected and processed by our Company pursuant to Article 6 § 1 (f) of the GDPR when necessary for the purpose of pursuing the following legitimate interests :

The smooth operation of our Website.

The user-friendly performance of our Website.

The improvement of your online experience, while browsing and using our site.

The recording of your consumer habits through the use of anonymous statistical data.

Improvement, management and review of our products and services to meet the needs of our clients as appropriately as possible.

Administration, organization and function of our business.

Management of our clientele.

Extrajudicial or judicial use for the protection of our lawful rights and interests.

Our Company collects and processes your personal data solely for the purposes mentioned above and only to the extent that is strictly necessary to effectively serve them. Data collected are relevant, appropriate and no more than what is required in view of the above purposes, whereas we strive to keep them accurate and up to date. Furthermore, your data are retained only for the period required to achieve the purposes, for which they are collected and processed, and are afterwards deleted.

 

Consent

Our Company may process personal data only with your lawful consent for the following purposes :

For your registration to our newsletter service.

For your participation in our loyalty card scheme.

For the purposes of commercial communication, marketing and advertising of our services or third party services via SMS, telephone, e-mail, internet, fax, mail, social media and / or any other appropriate communication channels.

For personified market research and / or analysis purposes to better understand your needs, preferences, interests, experiences and / or habits as a consumer.

To operate and manage any reward programs.

For your participation in competitions and other promotional activities. 

You give us your consent to the processing of your personal data for the above purposes with an electronic statement in a manner clearly distinguishable from other consents or notice and in an intelligible and easily accessible form using clear and plain language. Your consent is freely given and your personal data is given without such a provision being a legal or contractual obligation or a requirement on behalf of our Company for the performance of a contract between us.

In this context, by giving your consent, you explicitly state that you wish to provide your consent for the above purposes in accordance with the terms and conditions of this policy. You may provide your consent in the following ways :

When setting up your user account.

When ordering products / services as well as when drawing up any type of contract through our website.

When registering for our newsletter service.

When registering for our loyalty card.

You have the right to withdraw your consent at any time. Withdrawal of your consent does not affect the lawfulness of the treatment of your data prior to its revocation. Your consent is also revoked in the same manner as provided.

 

Data Recipients

Our Company shares your data with subsidiary companies in the process of pursuing the purposes of data processing at Group level.

Our Company does not assign your personal data or interconnect its database with any third parties, public authorities or other organizations for financial or other consideration.

For the execution of the purposes mentioned in this Notice, our Company may provide access to or transmit the following types of your data to the following processors for and on behalf of :

Your financial data with the credit institutions, with which we partner each time to process payments to and from your bank accounts and credit card accounts;

Your personal data to our internet and data hosting providers for hosting purposes.

Your personal data to our information technology maintenance and support providers for the smooth operation of Website and our information and communication systems.

Consumer behavior data and contact information to third-party marketing and advertising companies for the commercial communication, marketing and advertising of our services or third-party services.

Your personal data to third-party consultants to provide data analysis services.

Your financial details and contact details with collection agencies in the event of due payments towards our Company.

Your personal data to auditors, accountants, financial or professional consultants as well as investors as part of the transfer of part or all, merger, division of a branch or other succession, liquidation or other bankruptcy procedure of our business.

The processing of your personal data by our data processors mentioned above is executed under our control and orders and is subject to the same data protection policy or to a policy of at least the same level of protection.

In the event that we are required by a court or other administrative authority and in any other case that we are legally bound to do so, our Company may transfer your personal data to public authorities to the extent specified by law prior to you being informed.

Our Company does not execute cross-border transfers of your personal data to third countries outside the European Economic Area, for which the European Commission has not issued an adequacy decision.

 

Data Security and Confidentiality

In order to ensure the proper use and integrity of your personal data and to prevent their unauthorized or accidental access, processing, deletion, alteration or other use, our Company applies appropriate internal policies and takes all appropriate organizational, technical, physical, logical and procedural security measures, as well as technical standards, in accordance with applicable laws and regulations.

The processing of your data by our Company is conducted in a manner that ensures their confidentiality and physical and logical security, taking into account the latest developments, implementation costs and the nature, scope, context and purposes of the processing, as well as the risks for your rights and freedoms, which are applicable in each circumstance.

Your personal data is processed solely by authorized personnel of our Company, bound by strict obligations of confidentiality.

 

Retention of Personal Data

We keep your personal data for as long as it is each time necessary for the relevant purposes of their processing.

Our Company may retain your personal data after the expiration of their relevant processing purposes in the following limited cases :

In case that there is a legal obligation under a relevant statutory provision.

For reasons of tax and social security audit reasons within the statutory limitation period.

For research or statistical purposes of for the proper organization and operation of our business provided that anonymity or pseudonymization of your data takes place.

In case of any claims against our Company, for as long as necessary to defend our rights and legitimate interests before any competent court and any other public authority.

After the period of retention, your personal data is erased from our databases and systems in accordance with our data protection policies and provided that their retention is no longer required for the fulfillment of the purposes we have described above.

 

Your Rights

Without prejudice to applicable law and subject to any limitations thereof, you have the following rights :

Request for access to your personal data and information related to their processing and obtain a copy thereof.

Request for the rectification of any inaccuracies or any missing personal data of yours.

Request for the erasure of your personal data.

Request for the restriction of the processing of your personal data in cases explicitly provided for by law.

Request for the portability of your personal data to another controller in a structured, commonly used and machine-readable format (eg cd).

Object to the processing of your personal data in cases explicitly provided for by law.

Object to a decision taken solely on the basis of automated processing, including profiling, which has impact on you or significantly affects you. Any requests relevant to the above are addressed in writing to our contact details mentioned in this Notice.

Our Company will respond to any of your requests within one month from their receipt. Upon prior notice, this period may be extended by a further two months if necessary, taking into account the complexity of the request and the number of any other pending requests. In case of rejection of your request, we will provide relevant justification.

If your request does not meet the requirements of applicable law, our Company reserves the right either to: (a) impose a reasonable fee, taking into account the administrative costs of providing the information or communicating or executing the requested action, or (b) reject your request.

In the event of any violation of your personal data, which may place your rights and freedoms at a high risk, and provided that it does not fall under one of the exceptions expressly provided for by applicable law, we undertake to inform you without undue delay.

If there are any doubts as to the identity of the individual submitting the request, we reserve the right to request the provision of additional information necessary to confirm his / her identity.

If your rights are infringed, we inform you that you have the right to file a complaint with the Greek Data Protection Authority or with any other competent supervisory authority.

 

Your Obligations

By using our Website and by providing your personal data upon your consent, you acknowledge that you are required to state your actual, accurate and complete information requested by our Company. Furthermore, you must inform our Company of any changes to your information so as to ensure it is kept up-to-date and accurate.

If you are found to be in breach of your obligations or if our Company has reasonable suspicion that the information you provide is false or incomplete or in any way contrary to applicable law or this Privacy Notice, we retain the right to reject your application for registration or to suspend or terminate your account immediately without notice. In this case, you have no right to any compensation due to the rejection of your application, or the suspension or termination of your account.

You acknowledge that our Company may delete, cross-check, supplement or modify the information you provide based on information lawfully provided by third parties. In this case, our Company will provide you with relevant notice in compliance with applicable law.

By using our Website you confirm that you are over sixteen (16) years old. If you are under the age of sixteen (16) you have the obligation to abstain from any use of our Website and from any transfer of your personal data without the consent of the person who exercises your parental responsibility. If you fail to comply with the foregoing obligations, you must immediately notify our Company. In any case, using the Site, you acknowledge that our Company is not responsible for your violation of the obligations mentioned above to the extent that it is unable, even if it makes reasonable efforts, to verify your age or to receive consent from your guardian.

 

Cookies

Our Website uses cookies. For more information please review our Cookie Notice [hyperlink]. 

 

International Jurisdiction and Applicable law

Any dispute between you and our Company arising from or in relation to the subject matter of this Privacy Notice shall be governed and construed in accordance with Greek law without reference to its conflict of laws principles and shall be subjected to the exclusive jurisdiction of the competent courts of Athens, Greece.

If a provision of the present Privacy Notice is canceled by a decision of a competent court as unlawful, invalid or unenforceable, this will not affect the validity and enforceability rest of its provisions, which will remain in full force and will be accordingly applied.

 

CONTACT

For any request in relation to the protection of your personal data you may contact our Data Protection Officer as follows : 

[Street]

[City]

[Country]

[E-mail]