Our company, taking account of the importance of the proper collection, retention, processing and storage of personal data of customers and visitors / users of the e-shop, explicitly states that it keeps all management and protection safety guarantees of individuals with regard to the processing of personal data, in compliance with those specified in the European Regulation No 2016/679, as incorporated into our national law and in force.
The protection of individuals with regard to the processing of personal data is a fundamental right. Article 8(1) of the Charter of Fundamental Rights of the European Union (the “Charter”) and Article 16(1) of the Treaty on the Functioning of the European Union (TFEU) provide that everyone has a right to the protection of personal data.
Our company is committed to keeping your personal data secure and protected. You will find below the information on what personal data we collect, process, and store and why.
For all services provided by our company, the Controller of Your Personal Data is the sole proprietorship ‘KRITIKOU AIKATERINI TOU DIMITRIOU’ based in Rafina, 11 Litous Street, GR-19009, Greece, firstname.lastname@example.org, (+30) 22940 25495.
Processing of personal data on the Company’s website
When you visit the Company’s website, the Company may process:
Data you have entered to register on the website and the services offered (username, password to enter the page, name and surname, contact phone, email address, Tax ID No, etc.);
Personal data automatically collected during your browsing (IP address, device type, browser, redirect webpage, date and time of visit);
Data processed as part of a product purchase / order, payments made, etc).
The processing of personal data is done for the following purposes:
To manage your registration as a platform user;
To develop, fulfil and carry out the contract of sale;
To respond to requests submitted through customer service channels;
To send newsletters by email to keep you informed of discounts and new collections, always following your explicit consent to receive such type of correspondence;
To be aware of your preferences and thus ensure that we offer you exactly what you want and to remain competitive;
To ensure Company’s compliance with statutory obligations (tax, accounting, etc.);
To respond to requests and applications you submit through Customer Service channels (email, telephone, social media);
For marketing purposes: We have the right to process your data for marketing purposes due to the consent you give us, e.g. when you authorise us to send notifications to your mobile device or when you accept the legal terms and conditions in order to participate in a promotion or to post your photos on the Platform or on social media.
Provided that we have received your explicit prior consent, we are entitled to send you, at regular intervals, promotional / advertising messages by email, in order to keep you informed about the news of our company and to help you ‘discover’ our new collections .
How to stop receiving promotional / advertising messages from AENALIA:
(a) by clicking the ‘unsubscribe’ link that will be included in each email you receive from our company;
(b) by contacting us at email@example.com, stating that you no longer wish to receive such type of correspondence.
Once our company receives your request, in either of these ways, it will be processed and you will stop receiving such type of email.
In order to provide you with specialised information, we believe that we have a legitimate interest in compiling a profile with the information we have about you (such as your browsing, your preferences or your shopping history and Favourites) and the personal data you have given us, such as age range or language, as we understand that such processing is also beneficial for you as it allows you to improve your user experience and obtain information according to your preferences.
The processing of your personal data is necessary for the fulfilment of the above purposes and in any case in accordance with the provisions of Article 6 of EU Regulation 2016/679.
Third party IT companies (processors) may administer some of our websites. In these cases, we ensure through contractual terms and regular checks that, if and when they have access to personal data, the law on their protection is adequately observed.
Our company hereby explicitly declares that it will not make any illegal or improper use of your personal data and will not transfer in any way, for any reason, and to any third party personal details and user / visitor information.
However, we do share personal data that you have given us your explicit consent to do so, to the following categories of cooperating with AENALIA companies-businesses, to support, promote, and execute your trading relationship with us, but always under conditions that fully ensure that your personal information does not undergo any unlawful processing:
Companies that contribute to the proper and smooth functioning of our e-shop and to the proper execution of your order, such as web and digital application development companies as well as courier services companies.
Companies providing professional advertising and promotional services.
Financial institutions (banks) as part of carrying out the contract.
The Company and its website is addressed to persons who are aged 18 (eighteen) or over. The Company shall not be liable whatsoever for minor users that may visit voluntarily the Company’s website. In any case, if during the collection of data, the Company realises that the data subject / user is younger, the Company undertakes not to process his or her personal data.
The Company will keep your personal data for as long as is required to fulfil the purposes described in this policy unless a longer period is required or permitted by applicable law. The criteria governing the determination of the data retention period include the following: (a) the duration of our contractual relationship; (b) the time required for the Company to comply with a legal obligation borne by it; (c) the time required in view of the legal position of the Company (such as a defence of rights before courts, audits conducted by regulatory authorities, etc.); (d) as long as the data subject keeps his or her account active.
Rights of the Data Subjects
In the event that you have given your consent to the processing of specific personal data by the Company, you have the right to withdraw consent at any time, with future effect. Withdrawal of consent does not affect the lawfulness of the processing based on consent before it was withdrawn. In the event of withdrawal of consent, the Company may further process the personal data, only in cases where there is another legal reason for the processing.
You have the right to obtain information as to whether or not your personal data are being processed by the Company, to access the data and to receive additional information about their processing,
You have the right to request updating and rectification of your personal data, or to have your incomplete personal data completed.
You have the right to request the erasure of your personal data, which request will be satisfied provided that there is no other legal basis for processing (such as an obligation to process personal data imposed by law),
by clicking the ‘unsubscribe’ link that will be included in each email you receive from our company.
You have the right to request restriction of processing of your personal data in the following cases: (a) when you dispute the accuracy of the personal data, until it is verified; (b) when you object to the erasure of personal data and request a restriction instead of erasing them; (c) when personal data are not required for processing purposes, but they are necessary for the establishment, exercise, or defence of legal claims; and (d) when you object to processing and until it is verified that there are legitimate reasons that concern us and prevail over the grounds on which you object to the processing,
You have the right to object at any time to the processing of your personal data when it is based on the legal basis (Article 6(1)(e) or (f) of the GDPR) which will be satisfied unless the Company demonstrates compelling and legal reasons for their processing.
You have the right to receive your personal data free of charge in a structured, commonly used and machine-readable format or to request, if technically feasible, that we transmit the data directly to another controller where: (a) the processing is based on consent in accordance with Article 6(1)(a) or Article 9(2)(a) of the GDPR or on a contract pursuant to Article 6(1)(b), and (b) where the processing is carried out by automated means.
You have the right to request an exemption from decision-making by based on processing by automated means, including profiling. The controller shall no longer process personal data unless the controller demonstrates compelling and lawful reasons for processing that override the interests, rights and freedoms of the data subject or for the establishment, exercise or defence of legal claims.
In order to improve the user-friendly browsing and use of our website. Cookies are small files containing textual information which are stored in your hard drive during your visit at our website. We need cookies for your identification and authorisation following your successful subscription to the protected area throughout the duration of your visit. However, cookies are also used to monitor the preferences of the visitors of the website. This helps us to adjust in a better way our website content to your needs, as well as to improve our offers towards you. Cookies do not allow us to identify the users. You can deactivate these cookies any time at the system settings of your browser, as well as you can delete the already existing cookies. All users can view our offers without activating the cookies. However, in case you have chosen not to accept cookies, you may not be able to benefit from the entire features of our site.
Necessary cookies are absolutely necessary for the proper operation of the Site. This category includes only cookies that ensure basic functions and security features of the website. They do not store any of your personal information.
Non-Necessary cookies are all cookies that are not necessary for the operation of the website and are used specifically for the collection of personal data of the user through detailed information, ads and other embedded content. To use these Cookies we must first secure user consent. This type of cookies includes cookies that allow us to measure the traffic of our website and monitor the sources of traffic, by collecting data. They can also help us understand which products and activities are most popular.
We do not store in cookies that we use sensitive personal identification information, such as your address, your password, your credit or debit card details, etc.
If you want to delete all cookies that are already on your computer, please visit the support and help area of your web browser for instructions on how to locate the file or directory that stores cookies.
The Company effectively implements, both at the time of determining the means of processing and at the time of processing, appropriate technical and organisational measures, such as pseudonymisation designed to apply data protection principles, such as minimising data and incorporating the necessary guarantees into such processing in such a way as to meet the requirements of applicable law and to protect the rights of individuals.
The Controller is the sole proprietorship ‘KRITIKOU AIKATERINI TOU DIMITRIOU’ based in Rafina, 11 Litous Street, GR-19009, Greece, firstname.lastname@example.org, (+30) 22940 25495.
The Company provides support for all questions, comments, concerns or complaints relating to the protection of personal data or even in the event that you wish to exercise any right regarding the protection of your data. You can contact the Data Protection Officer either via email at DPO@aenalia.gr or by an official letter at the company’s registered office:
11 Litous Street, GR-19009, Rafina, Greece
If you exercise any of the above rights, we will take all possible steps to satisfy your request within one month of receiving your request. In any case, within the above period, we will inform you about satisfying your request or the objective reasons preventing it from being satisfied.
Right to lodge a complaint with the Authority
Postal Address: 1-3 Kifisias Ave., Athens, Greece (GR-11523)
Call Centre: (+30) 2106475600
Fax: (+30) 2106475628
However, you must have attempted to exercise your rights in the Company before contacting the competent Authority.
All payments made by card are processed via the online payment platform of Piraeus Bank which uses TLS 1.1 encryption with an 128-bit encryption protocol (Secure Sockets Layer – SSL). Encryption is a way of encoding the information until it reaches its specific recipient, who will be able to decode it using the appropriate key. No card details are entered / recorded / stored in our online store.