Personal Data Protection
- Purpose of this Policy
This Personal Data Protection Policy sets out the terms and conditions observed by the company, trading as “GRAECUS SA,” for the protection of the personal data of individuals whose data is processed. This Policy aims to inform you about the personal data we collect, store, and use as needed, and to inform you of your rights under the applicable law. Additionally, it describes some of the security measures taken by the Company to protect the privacy of data and provides assurances regarding actions that the Company will not take.
The Company reserves the right to modify, update, or revise this Policy and the terms of service provision periodically, whenever it deems necessary, without prior notice, in accordance with the law. For this reason, please check this Policy at regular intervals to stay informed of any revised versions. Updates will be posted on the Company’s website and at its physical locations.
The “Data Controller” of your personal data, as defined by Article 4, paragraph 7 of the General Data Protection Regulation, is the company trading as “GRAECUS SA,” located at 10th km Thessaloniki – Kavala, Liti, Postal Code 54500, and legally represented, email: info@graecus.com.gr, tel. +30 2310 555540 (hereinafter referred to as the “Data Controller” or the “Company”).
- Personal Data Subjects
The Company collects and processes personal data from the following categories of individuals:
- Visitors to the Company’s website
- Users of the Company’s website and electronic contact form
The management and protection of personal data of the above categories are subject to the present terms, as well as the relevant provisions of the European Regulation 2016/679 on Personal Data Protection (GDPR), Law 4624/2019, or other provisions of national and EU law related to the processing of personal data.
The Company will not make any improper or unauthorized use of your data, adhering to the principles of personal data protection stipulated by the relevant legal framework. The Company will not disclose, publicize, exchange, or share the personal data and information you provide, unless required by law. Furthermore, the Company does not distribute users’ personal information, including email addresses or any other data related to website users, to any other organization or partner (see exceptions below, under point 8).
- Personal Data Collected
Each time you complete electronic applications or contact forms, or make use of the services we provide, we collect and process personal data, which includes the following: 1. Identification and Contact Information, such as your full name and email address, which you provide to us.
- Tax Information (such as business name, VAT number, tax office, etc.) which you disclose to us.
- Technical and Other Information derived from internet use and/or automatically via the browser you use, such as IP address, internet service provider domain, browser type and version, and your operating system , among others.
We do not collect or gain access in any way, through our website, to special categories of (“sensitive”) personal data or data relating to criminal convictions and offenses of the individuals.
- Collection and Processing Purposes of Personal Data
The Company processes individuals’ data for the following lawful and transparent purposes:
- Communication with customers and suppliers
- Website maintenance
- Contract execution – data processing for payment handling and order fulfillment
- Tax purposes and invoicing for proof of product sales
- Product advertising
- Improvement and customization of the website
- Informing users about new products or Company events
Your personal data is not subject to automated decision-making processes. If this should change in the future, this Policy will be updated and reissued.
- Lawfulness of Processing (Legal Bases of Processing)
The Company processes personal data only when there is a lawful basis for such processing, specifically when:
(a) Processing is necessary for the performance of our contract (order) with you and the provision of services you have requested from us, for the general execution and compliance with our legal obligations, and for the exercise of the Company’s lawful rights as the data controller.
(b) Processing is necessary for establishing, exercising, or defending the Company’s legal claims and for protecting the Company’s rights before courts, administrative or judicial authorities, or in extrajudicial procedures, for the purposes of asserting or defending the rights of the Company or third parties before any judicial or other authority.
(c) Processing is necessary for the Company’s compliance with all types of legal obligations
(d) Processing is based on your explicit consent, as provided when you visit our website.
visit our website.
- Data Retention Period
Personal data on this website is stored only for the period necessary to fulfill the specific purpose of processing, subject to any contrary provisions of the Law.
- Data Deletion
Your data is deleted as appropriate and always in accordance with the provisions specified by applicable legislation.
- Transfer of Personal Data to Third Parties
Your personal data is not expected to be transferred to any organization outside the Company, except (a) to professionals—service providers (e.g., courier services, payment providers, providers supporting the Company’s electronic systems and networks) solely for the purpose of fulfilling their contractual obligations on behalf of the Company, and (b) to the relevant tax or other public and independent authorities, as part of our mandatory compliance with applicable legislation and to the extent required.
- Cookies
Cookies are, simply put, small pieces of code that record your movements while navigating our website. They are categorized as follows:
Necessary Cookies for identifying or maintaining content entered by the subscriber or user during a session on the website throughout that specific session, such as filling out an electronic form or saving a user’s purchases in an online store (e.g., by clicking “add to cart”). This category also includes persistent cookies that are installed for the same purpose and last for several hours.
Authentication Cookies required for verifying the subscriber or user for services needing authentication (e.g., for online banking transactions).
Security Cookies installed to protect the subscriber or user, such as those that detect repeated failed login attempts to a user’s account on a specific website.
Multimedia Cookies like flash player cookies, during a session on the website. An example includes cookies that are installed when a user views a video on the website.
Load Balancing Cookies needed for technical load distribution during a website session.
Preference Cookies that “remember” the subscriber or user’s choices regarding website presentation (e.g., language selection or search result display).
Social Media Plugin Cookies installed through social network plugins for sharing content among authenticated members who are already logged in.
Advertising Cookies installed by either the website provider (first-party cookies) or other parties (e.g., ad networks) through the website provider (third-party cookies).
Third-Party Cookies for Research and Analysis installed by other entities (e.g., ad networks) for market research, product improvement, etc., which are not directly related to user identification.
Analytics Cookies for statistical analysis ( web analytics). necessary cookies that you must accept for functionality reasons By using our website, you agree to the essential cookies required for functionality and may choose which optional cookies to activate. Upon entering our homepage, you are notified about our cookie usage and given options to disable or manage them.
- Data Security
We assure you that the Company takes and implements all appropriate technical and organizational measures to ensure the secure processing of data and to prevent accidental loss, destruction, unauthorized, or illegal access, use, modification, or disclosure. We comply with all legal provisions at the national, European , and international levels concerning the protection of individuals regarding personal data processing, including the General Data Protection Regulation (GDPR) (EU) 2016/679. Nevertheless, it should be noted that the nature of the internet does not allow absolute guarantees that unauthorized third parties will never be able to bypass applied technical and organizational measures to access or misuse personal data for unauthorized or unlawful purposes.
The Company guarantees minimal and strictly necessary use and processing of data solely for the purposes described here. If we intend to process personal data for any purpose beyond what you initially provided it for, we will request your explicit consent unless we proceed for other legal reasons specified in section 6.
- Your Rights
Under the GDPR (EU) 2016/679, you have the following rights:
a) Right of Access,
b) Right of Rectification,
c) Right of Erasure (under certain conditions, such as when data processing is no longer necessary for the original purpose, and no compelling reason exists to continue processing or storing the data)
d) Right to Restriction of Processing,
e) Right to Data Portability,
f) Right to Lodge a Complaint with a Supervisory Authority.
In summary, you have the right to obtain, upon request, free information about the personal data stored about you, to object to its processing, to withdraw your consent for future processing, to correct your personal data, to restrict its processing,
to request the transfer or deletion of the data, and to file a complaint with the competent supervisory authority if you suspect any violations of personal data laws.
For such requests, please contact us in writing with an original letter to our offices at our headquarters ( 10th km Thessaloniki – Kavala, Liti, PC 54500) or via email at info@graecus.com.gr, clearly stating your request.
- Right to File a Complaint
If you believe that the processing of your data violates GDPR or relevant Greek law, you have the right to file a complaint with a supervisory authority. In Greece, the competent authority is the Hellenic Data Protection Authority, Kifisias 1-3, 115 23, Athens, https://www.dpa.gr, Tel. +30 210 6475600.
This Policy was updated on 11/10/2024.