CUSTOMER PRIVACY POLICY

Introductory remarks

This text called the Privacy Policy, explains in simple terms how we process the personal data that we collect from you or that you provide to us in the context of your transactions or communication with our business.

 

Processing Manager

The person responsible for processing personal data is the company named SOFIA MAGIATI, which is based in Agia Paraskevi, Attica, at 25 Peloponnisou Street, 15341 with VAT number 121244350 with no. tel. 6936604807 with the e-mail address dodoandberries@gmail.com which is legally represented.

Our priority is the legal processing of this data and your full and transparent information about it. For any questions do not hesitate to contact us.

 

Privacy Policy Contents

 

  • First Section: General information

1) What is personal data?

2) What is Personal Data Processing

3) Is the processing of your personal data mandatory?

4) When and how we collect your data

5) What principles do we follow when processing data?

 

  • Second Section: Analysis of the processing

A. Categories of etc. that we process

B. Purposes of processing – Lawful bases of processing

C. Time-Place of conservation eg

E. Your rights

 

  • Third Section: Other information

 

SECTION ONE: General Information

 

  1. What is personal data?

The term "personal data" (hereinafter referred to as "data") refers to any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one whose identity can be ascertained, directly or indirectly, in particular by reference to an identifying element of identity, such as a name, an identity number, an address, a telephone number but also by reference to one or more factors that characterize the physical, physiological, genetic, psychological, economic, cultural or social identity of the person concerned due to a natural person.

In a few words, for example, it is any information that is related to and concerns a natural person, whether it immediately reveals his identity to us or can reveal it to us.

As data subjects, our company accepts not only natural persons but also sole proprietorships as well as sole proprietorships.

 

  1. What is Personal Data Processing

Any act or series of acts carried out with or without the use of automated means, on personal data or sets of personal data, such as the collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, information retrieval, use, disclosure by transmission, dissemination or any other form of disposal, association or combination, restriction, deletion or destruction.

That is, almost any action, from the moment data is created to the moment it is destroyed (or completely anonymized), constitutes a processing act.

Processing, for example, is a legal act, as long as it is carried out within the framework defined by the relevant legislation, i.e. the national law 4624/2019 but also the European General Data Protection Regulation (GDPR) 679/2016/EU.

 

  1. Is it mandatory to process your personal data?

Providing some of your data to our business is necessary when you transact or communicate with us.

With this policy, we inform you about the processing rules we follow.

If you do not provide us with the data listed below, we may not be able to complete the transactions you request and generally provide you with our products and services or respond to your contact or other request.

 

  1. When and how we collect your data

We collect your data at the following times:

A. When you transact with our business eg buy our products/services either by visiting our business directly by phone or through our website,

B. When you contact us

C. When you request to receive electronic updates about our news, offers, and events, ie. by registering on the newsletter recipient list

D. When you visit, browse, or use our website

E. When you interact on our official business social media pages

 

  1. What principles do we follow when processing data?

Κατά την επεξεργασία των δεδομένων σας, αποδεχόμαστε, υιοθετούμε και εφαρμόζουμε τις αρχές επεξεργασίας κατά το αρ.5 ΓΚΠΔ, δηλαδή τα δεδομένα σας :

a) are lawfully and legitimately processed in a transparent manner in relation to the data subject ("lawfulness, objectivity, and transparency"),

b) are collected for specified, explicit, and lawful purposes and are not further processed in a manner incompatible with those purposes ("purpose limitation"),

c) are appropriate, relevant, and limited to what is necessary for the purposes for which they are processed ("data minimization"),

d) is accurate and, where necessary, updated; all reasonable measures are taken to immediately delete or correct personal data that is inaccurate, in relation to the purposes of the processing ("accuracy"),

e) are kept in a form that allows the identification of the data subjects only for the period required for the purposes of the processing of the personal data; ("limitation of the storage period"),

f) are processed in a way that guarantees the appropriate security of personal data, including their protection against unauthorized or illegal processing and accidental loss, destruction, or damage, using appropriate technical or organizational measures ("integrity and confidentiality").

 

SECTION TWO: Analysis of the processing

 

A. Categories of etc. that we process

Our company collects and subsequently processes (stores, etc.) based on the following categories of personal data (e.g.):

  1. Name, surname, date of birth, home address/area, telephone number (landline/mobile), email address
  2. Data related to the payment method, data from the transactions you carry out with our business as well as invoicing data (goods/services, value, quantity), purchases history
  3. Data you provide us when you subscribe to our newsletter
  4. Your data when visiting, browsing, or using our site (see also Cookies Policy)
  5. Your name and your profile photo, any comments or messages you have on our social media pages (as long as you interact with them by taking actions such as like, follow, sending comments or messages, etc.)

 

We make it clear to you that not all of the above categories are requested from you every time, but only those that are necessary for the specific need.

 

  1. Purposes of Processing - Legal Basis of Processing

We collect and process the above categories for the following purposes, for example:

  1. Service provision, billing-credits,
  2. Manage products, services, and contract needs (changes, warranties, returns)
  3. Customer service (communication, information about products and services, keeping customer records),
  4. Defending legal claims
  5. Compliance with the legislation (tax etc.)
  6. Newsletter sending
  7. Create a user account (provide account functions, facilitate purchase of products/services)
  8. Promotion of the company's activities (social media)
  9. Attracting new clients (social media)

 

Lawful processing bases

We would like to inform you that the processing for the above purposes is carried out:

  • under the legal basis of no. 6 par. 1 case b' of GDPR 679/2016/EU (i.e. the processing is necessary for the performance of a contract to which the data subject is a contracting party) and
  • under the legal basis of no. 6 par. 1 case c) of GDPR 679/2016/EU (i.e. the processing is necessary to comply with a legal obligation of the controller).
  • under the legal basis of no. 6 par. 1 case c of GDPR 679/2016/EU (i.e. to defend the legitimate interests of our company
  • (additionally) under the legal basis of no. 6 par. 1 case of GDPR 679/2016/EU (i.e. with your consent), in very specific cases of processing, for which we inform you accordingly.

 

Regarding the sending of newsletter, we inform you that this is only done if:

a) there has been a provision of products/services between us before and you have not objected or

b) if you have voluntarily subscribed to our company's newsletter mailing list, i.e. with your consent.

In every newsletter message you receive, we provide you with the possibility to stop sending them, with the unsubscribe option at any time you wish.

The newsletter is sent only for the promotion of similar and related products or services of our company. Your email address is not shared with third parties.

 

C. Time – Place of conservation eg

The processing of personal data must be limited in time, during the time that is absolutely necessary for the purposes of the processing.

The personal data that we process in accordance with the above are kept for a period of time that is necessary to comply with the legislation (mainly tax) but also to safeguard our legal claims.

In the case of any processing carried out based on your consent, the data will be kept until it is revoked, otherwise, it will be reviewed within 5 years from its receipt.

In the case of using a credit/debit card, we do not store their data (card number-cvv number), while in the case of a telephone transaction, we delete it immediately after its completion.

Your other data is kept at our company's facilities in physical or, as the case may be, digital form.

 

D. Your Rights

We process the above data in accordance with the above protection policy and of course, we support and ensure the exercise of your rights with a corresponding procedure.

Our response to your requests (whether related to the exercise of rights or complaints) is free of charge without delay, and in any case within (1) one month of receiving your request and confirming your identity. However, if your request is complex or a large number of requests are submitted to our business at the same time, we will inform you within this month whether we need to obtain an extension of another (2) two months, within which we will respond to you. The stated times of one (1) plus two (2) months (if required) are the legal and provided for in the GDPR.

If your requests are manifestly unfounded or excessive, our company may impose a reasonable fee, taking into account the administrative costs of providing the information or performing the requested action, or finally refuse to respond to your abusively repeated request.

 

Specifically, you have the following:

  1. Right to be informed about all the above issues and any other related to the processing of your data
  2. Right of access, i.e. right to receive a copy of the data you have provided to us
  3. Right to update/correct, in the event, that any data is or becomes inaccurate so that we can correct it. The update will be made within 7 working days from the date of submitting your written request and confirming your identity.
  4. Right to erasure. This right may be subject to relevant restrictions due to the need to retain some data due to legal obligations.
  5. Right to restriction of processing when:

a) the accuracy of the personal data is contested by you and for a period of time that allows us to verify the accuracy of the personal data,

b) the processing is illegal and you object to the deletion of the personal data and request, instead, the limitation of their use,

c) we no longer need the personal data for the aforementioned processing purposes, but this data is required by you to establish, exercise, or support legal claims and in related cases

  1. Right to portability i.e. the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used, and machine-readable format, as well as the right to transmit said data to another controller without objection from us.
  2. Right to withdraw your consent to specific processing for which you have provided it and to withdraw consent to newsletter sending, i.e. the right to ask not to receive future newsletter messages from our company by email, through the unsubscribe option in any such email you have received.
  3. Right to file a complaint with the Personal Data Protection Authority (www.dpa.gr) in case you believe that we are violating the relevant protection legislation, e.g. regarding your data

 

SECTION THREE: Other information

A. Our business uses modern and up-to-date organizational and technical measures to prevent illegal intrusion, access, or dissemination of your personal data.

B. We inform you that we do not carry out automated individual decision-making or profiling.

C. Our website uses cookies to facilitate your connection to it, to collect statistical traffic data, or for marketing purposes.

D. Contact form

Through the contact form, you can send us a message and receive information about our services. This processing is based on our legitimate interests, namely to provide a means of rapid communication with you. In this context, we ask you for the absolutely necessary data (name, email, message) while we only use them to respond to you in this regard. We urge you not to send us messages that contain sensitive information about you or third parties. In the event that you send us a message of this nature, we declare that we will delete it immediately and will not proceed with further processing or reply.

 

E. Newsletter sending

To sign up for our company's newsletter recipient list, we only ask for your name and email address. Your email will be used exclusively to send you informational material about our news, services and any special offers. We do not sell, give away or share your email. You have the right to withdraw your consent at any time by selecting "unsubscribe" in the emails you receive or by emailing yoginimamagr@gmail.com

 

C. Privacy Policy Revisions

Our company reserves the right to periodically modify or revise this Privacy Policy, at its sole discretion. If changes are made, our business will record the date of amendment or revision in the new Privacy Policy and the updated Policy will apply to you from that date. We encourage you to periodically review this Privacy Policy to review any changes to the way we manage your data.

 

D. Contact - Requests - Complaints

If you have questions, comments, or complaints about the management or protection of your personal data, or if you wish to exercise any of your rights, please contact us at the contact details above.

To submit a complaint or complaint regarding a breach of your personal data, you can contact the Personal Data Protection Authority (Kifisias 1-3, P.O. 115 23, Athens, Telephone Center: 210 6475600, Fax: 210 6475628, e- email for notification of a personal data breach incident: databreach@dpa.gr, general e-mail: contact@dpa.gr