Personal Data Protection

  1. Purpose of this Policy 

This Personal Data Protection Policy  sets out the terms and conditions observed by the company, trading as “GRAECUS SA,” for the protection  of the personal data of individuals whose data is processed.  This Policy aims to inform you about the  personal data we collect, store, and use as  needed, and to inform you of your rights under the applicable  law. Additionally, it describes some of the security measures taken by the  Company to protect the privacy of data and provides  assurances regarding actions that the Company will not take.  

The Company reserves the right to modify, update, or revise this  Policy and the terms of service provision periodically, whenever it  deems necessary, without prior notice, in accordance with the law. For  this reason, please check this Policy at  regular intervals to stay informed of  any revised versions. Updates will be posted on the Company’s  website and at its physical locations.  

The “Data Controller”  of your personal data, as defined by  Article 4, paragraph 7 of the General Data Protection Regulation, is the company  trading as “GRAECUS SA,”  located at 10th km Thessaloniki – Kavala, Liti, Postal Code 54500, and  legally represented, email:  info@graecus.com.gr, tel. +30 2310 555540  (hereinafter referred to as the “Data Controller” or the “Company”).  

  • Personal Data Subjects 

The Company collects and processes personal data  from the following categories of individuals:  

  1. Visitors to the Company’s website 
  2. Users of the Company’s website and electronic contact form 

The management and protection of personal data of the above categories  are subject to the present terms, as well as the relevant provisions of the European  Regulation 2016/679 on Personal Data Protection  (GDPR), Law 4624/2019, or other provisions of national and EU law  related to the processing of personal data.  

The Company will not make any improper or  unauthorized use of your data, adhering to the principles of  personal data protection stipulated by the relevant  legal framework. The Company will not disclose,  publicize, exchange, or share the personal data and information you provide, unless  required by law. Furthermore, the Company does not distribute users’  personal information, including  email addresses or any other data related to  website users, to any other organization or partner (see exceptions below, under point 8).   

  1. Personal Data Collected

Each time you complete electronic applications or contact forms, or make use of the services we provide, we collect and process personal data, which includes the following: 1. Identification and Contact Information, such as your full name and email address, which you provide to us.  

  1. Tax Information (such as business name, VAT number, tax office, etc.) which you disclose to us. 
  2. Technical and Other Information derived from  internet use and/or automatically via the browser you use, such as  IP address, internet service provider domain,  browser type and version, and your operating system , among others. 

We do not collect or gain access in any way, through our website, to  special categories of (“sensitive”) personal data or  data relating to criminal convictions and offenses of the individuals.  

  1. Collection and Processing Purposes of Personal Data 

The Company processes individuals’ data for the following lawful and  transparent purposes: 

  1. Communication with customers and suppliers 
  2. Website maintenance 
  3. Contract execution – data processing for payment  handling and order fulfillment 
  4. Tax purposes and invoicing for proof of  product sales 
  5. Product advertising 
  6. Improvement and customization of the website 
  7. Informing users about new products or Company events 

Your personal data is not subject to  automated decision-making processes. If this should change in the future,  this Policy will be updated and reissued.  

  1. Lawfulness of Processing (Legal Bases of Processing) 

The Company processes personal data only when there is a lawful  basis for such processing, specifically when: 

(a) Processing is necessary for the performance of our contract (order) with you and the provision of services you  have requested from us, for the general execution and compliance with our legal  obligations, and for the exercise of the Company’s lawful rights as the  data controller. 

(b) Processing is necessary for establishing, exercising, or defending  the Company’s legal claims and for protecting the Company’s  rights before courts, administrative or judicial authorities, or in extrajudicial  procedures, for the purposes of asserting or defending the rights of the Company  or third parties before any judicial or other authority. 

(c) Processing is necessary for the Company’s compliance with  all types of legal obligations 

(d) Processing is based on your explicit consent, as provided when you visit our website. 

visit our website. 

  1. Data Retention Period 

Personal data on this website is stored only  for the period necessary to fulfill the specific purpose of  processing, subject to any contrary provisions of the  Law.  

  1. Data Deletion 

Your data is deleted as appropriate and always in accordance with  the provisions specified by applicable legislation. 

  1. Transfer of Personal Data to Third Parties 

Your personal data is not expected to be transferred to  any organization outside the Company, except (a)  to professionals—service providers (e.g., courier services, payment providers, providers  supporting the Company’s electronic systems and networks) solely  for the purpose of fulfilling their contractual obligations on behalf of the Company, and (b) to the relevant  tax or other public and independent authorities, as part of our mandatory  compliance with applicable legislation and to the extent required. 

  1. Cookies 

Cookies are, simply put, small pieces of code that record your movements while navigating our website. They are categorized as follows:

Necessary Cookies for identifying or maintaining content entered by the subscriber or user during a session on the website throughout that specific session, such as filling out an electronic form or saving a user’s purchases in an online store (e.g., by clicking “add to cart”). This category also includes persistent cookies that are installed for the same purpose and last for several hours.

Authentication Cookies required for verifying the subscriber or user for services needing authentication (e.g., for online banking transactions).

Security Cookies installed to protect the subscriber or user, such as those that detect repeated failed login attempts to a user’s account on a specific website.

 Multimedia Cookies like flash player cookies, during  a session on the website. An example  includes cookies that are installed when a  user views a video on the website.  

 Load Balancing Cookies needed for technical  load distribution during a  website session. 

 Preference Cookies that “remember” the subscriber or user’s choices regarding website  presentation (e.g.,  language selection or search result display).

 Social Media Plugin Cookies installed through  social network plugins for sharing content  among authenticated members who are already  logged in. 

 Advertising Cookies installed  by either the website provider (first-party  cookies) or other parties (e.g.,  ad networks) through the website provider (third-party cookies). 

 Third-Party Cookies for Research and Analysis installed by other entities (e.g., ad networks)  for market research, product improvement, etc., which are not directly related to  user identification. 

 Analytics Cookies for statistical analysis ( web analytics).  necessary cookies that you must accept for functionality reasons  By using our website, you agree to the essential cookies required for functionality and may   choose which optional cookies to activate. Upon entering our homepage, you are notified about  our cookie usage and given options to disable or manage them.  

  1. Data Security 

We assure you that the Company takes and implements all appropriate technical  and organizational measures to ensure the  secure processing of data and to prevent accidental loss, destruction, unauthorized, or  illegal access, use, modification, or disclosure.  We comply with all  legal provisions at the national, European , and international levels concerning the protection of individuals regarding personal data  processing, including the General Data Protection Regulation  (GDPR) (EU) 2016/679. Nevertheless, it should be noted that the nature of the internet does not allow absolute guarantees that  unauthorized third parties  will never be able to  bypass applied technical and  organizational measures to access or misuse personal data for  unauthorized or unlawful purposes.   

The Company guarantees minimal and strictly necessary  use and processing of data  solely for the purposes described here. If we  intend to process  personal data for any purpose beyond what you  initially provided it for, we will request your  explicit consent unless we proceed for other legal reasons  specified in section 6.  

  1. Your Rights 

Under the GDPR (EU)  2016/679, you have the following rights: 

a) Right of Access, 

b) Right of Rectification, 

c) Right of Erasure (under certain conditions, such as when data processing  is no longer necessary for the original purpose, and  no compelling reason exists to continue processing  or storing the data)

d) Right to Restriction of Processing, 

e) Right to Data Portability, 

f) Right to Lodge a Complaint with a Supervisory Authority. 

In summary, you have the right to obtain, upon request, free information  about the personal data stored about you,  to object to its processing, to withdraw your  consent for future processing, to correct your  personal data, to restrict its processing, 

to request the transfer or deletion of the data, and to file a complaint with the  competent supervisory authority if you suspect any  violations of personal data laws. 

For such requests, please contact us in writing with an  original letter to our offices at our headquarters ( 10th km Thessaloniki – Kavala, Liti, PC 54500) or via   email at info@graecus.com.gr, clearly stating your request. 

  1. Right to File a Complaint 

If you believe that the processing of your  data violates GDPR or relevant Greek law, you have the right to file a complaint with a  supervisory authority.  In Greece, the competent authority is the Hellenic Data Protection Authority, Kifisias 1-3, 115 23, Athens,  https://www.dpa.gr, Tel. +30 210 6475600.  

This Policy was updated on 11/10/2024.