Privacy Policy
- Introduction
Our company, GEFSINOUS S.A., a Société Anonyme (Anonymous Commercial and Industrial Company) duly incorporated and existing under the laws of Greece, with its registered office at 7 Asklipiou Street, Kryoneri, Attica, Greece, Tel.: +30 210 6254950, Email: info@gefsinus.gr (hereinafter referred to as the “Company“, “we“, “our“, or “us“), respects your privacy and is committed to the lawful processing, protection, and security of your personal data. To this end, the Company has adopted and implements this Privacy Policy (the “Privacy Policy“).
Through this Privacy Policy, we provide you with the information required under applicable data protection legislation regarding the processing of the personal data you provide to us in the context of your relationship with the Company.
The processing of your personal data is governed by the provisions of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the applicable Greek data protection legislation (including Law 4624/2019, Law 3471/2006, and any other applicable legislation, as amended and in force from time to time), as well as the decisions, guidelines, and regulatory acts issued by the Hellenic Data Protection Authority (HDPA).
- Definitions
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below:
“Data Subject” means any user of our website (whether registered or not), as well as any other natural person who interacts with our website.
“Personal Data” means any information relating to an identified or identifiable natural person (“Data Subject”), including, without limitation, name, postal address, contact details (telephone number, mobile number), email address, and any other information capable of identifying that individual, directly or indirectly.
“Processing” means any operation or set of operations performed on Personal Data or on sets of Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction of Personal Data that the Company obtains either directly from you through the website or in the course of your commercial or contractual relationship with the Company.
“Controller” means GEFSINOUS S.A., with its registered office at 7 Asklipiou Street, Kryoneri, Attica, Greece, Tel.: +30 210 6254950, Email: info@gefsinus.gr, which determines the purposes and means of the processing of Personal Data.
“Processor” means any natural or legal person, public authority, agency, or other body that processes Personal Data on behalf of the Controller.
“Recipient” means any natural or legal person, public authority, agency, or other body to whom Personal Data are disclosed, whether or not they are a third party.
“Third Party” means any natural or legal person, public authority, agency, or body other than the Data Subject, the Controller, the Processor, and persons who, under the direct authority of the Controller or the Processor, are authorised to process Personal Data.
“Consent” means any freely given, specific, informed, and unambiguous indication of the Data Subject’s wishes by which the Data Subject, by a statement or by a clear affirmative action, signifies agreement to the processing of Personal Data relating to him or her.
“Data Protection Officer” (“DPO”) means the individual appointed by the Company in accordance with the GDPR and the applicable data protection legislation to perform the duties and responsibilities prescribed by such legislation.
- What Personal Data We Collect, Why We Collect It, and the Legal Basis for Processing
Depending on the nature of our relationship with you, we collect and process the following categories of Personal Data for the purposes and on the legal bases set out below:
| Data | Purpose | Legal basis |
Accessing Our Website | IP address, Date and time of access, Requested URL, Referring URL, Internet service provider (ISP), Browser type, Operating system.
| To enable the proper operation of the Website, establish secure connections, maintain system security and stability, and improve the services provided through the Website.
| Our legitimate interests in operating, maintaining and securing our Website and providing our online services.
|
Contacting Us by Email | Email address First name and surname (where provided) Contents of your message | To communicate with you and to manage, respond to and resolve your enquiry, request or complaint. | a)Performance of pre-contractual measures or our contractual relationship with you, where applicable; and/or
b) Our legitimate interests in responding to enquiries and providing customer support. |
Contacting Us by Telephone | Telephone number First name and surname (where provided) Details of the communication | To respond to your enquiries, requests or complaints and to provide customer support. | a) Performance of pre-contractual measures or our contractual relationship with you; and/or b) Our legitimate interests in providing effective customer service. |
Marketing Communications (Newsletter) | Email address
| To send newsletters and information regarding our products, services, offers, promotions and other marketing communications. | Your consent. |
Full name Employment history Educational background Date of birth Telephone number Postal address | To assess your application, manage recruitment procedures and fill available positions within the Company. | a)Taking steps at your request prior to entering into an employment contract; and/or b)Our legitimate interests in recruiting suitable personnel. | |
Cookies (please refer to our Cookie Policy.) |
|
|
|
We would like to inform you that the Personal Data you provide to us through our website for the above purposes are necessary to enable us to provide you with the best possible service and to process, manage, or resolve your request, enquiry, or complaint. Consequently, failure to provide the requested Personal Data, where applicable, may render communication between you and the Company through the website ineffective and/or impossible and may prevent us from establishing or maintaining our business relationship with you.
Furthermore, with regard to the submission of Curriculum Vitae (CVs) via hr@gefsinus.gr, you will receive an automated response informing you that your CV will be retained as follows:
- a)where you are hired by the Company, for the entire duration of your employment relationship;
- b)where you are not hired, for a period of six (6) months from the date of receipt, after which it will be securely deleted or destroyed. Appropriate technical andorganisational measures are implemented throughout both the retention and deletion/destruction processes.
- Processing of Special Categories of Personal Data
The Company does not intentionally collect or process, through its website, Special Categories of Personal Data (sensitive personal data), including data revealing racial or ethnic origin, religious or philosophical beliefs, health data, or data concerning your sex life or sexual orientation, as such data are not necessary for the purposes of our processing activities.
Should you voluntarily provide such Personal Data when submitting an enquiry, request, comment, or otherwise communicating with us, such data will be processed only where your explicit consent has been obtained or where such processing is necessary for the establishment, exercise, or defence of legal claims, in accordance with applicable data protection legislation.
- Personal Data Relating to Minors
The Company does not knowingly collect or process Personal Data relating to individuals under the age of eighteen (18).
If we become aware that a minor has provided us with Personal Data without the consent of their parent or legal guardian, we reserve the right to delete such data without undue delay.
If you become aware that a minor has disclosed Personal Data to us without the required consent of their parent or legal guardian, please contact us immediately.
Notwithstanding the above, where the processing of Personal Data is based on consent pursuant to Article 6(1)(a) GDPR in connection with the direct provision of information society services to a child, such consent shall be valid where the child is at least fifteen (15) years of age. Where the child is under the age of fifteen (15), such processing shall be lawful only if, and to the extent that, consent has been given or authorised by the holder of parental responsibility over the child, in accordance with Article 8 GDPR and Article 21 of Greek Law 4624/2019.
- Who Receives Your Personal Data
The Personal Data collected in the context of our relationship with you may be processed by:
- duly authorised and appropriately trained employees of the Company who are bound by strict obligations of confidentiality;
- carefully selected third-party service providers acting as Processors on behalf of the Company pursuant to Article 28 GDPR. The Company has entered into appropriate data processing agreements with such Processors and has ensured that they implement adequate technical and organisational measures in accordance with Articles 28 and 32 GDPR. Such Processors may include, without limitation, IT service providers, website hosting and maintenance providers, providers of website functionality (such as live chat services), application support providers, and marketing service providers (including providers of newsletter distribution services);
- public authorities, regulatory bodies, law enforcement authorities, judicial authorities, prosecutors, administrative authorities, and other competent public bodies where disclosure is required by applicable law or pursuant to a lawful request;
- other companies within our corporate group, namely GEFSINOUS LTD, GEFSINOUS NORTH S.A., GOLDEN SANDWICH, and OLIVARTIA, where this is necessary in order to respond to your request to communicate with one of those companies.
As a general rule, the Company does not transfer your Personal Data to countries outside the European Union (EU) or the European Economic Area (EEA), or to international organisations that do not ensure an adequate level of data protection.
Where an international transfer is necessary, it will be carried out in full compliance with the applicable legal framework, including Articles 44 et seq. GDPR, and you will be informed accordingly where required.
- Retention of Personal Data
We retain your Personal Data in accordance with applicable legal and regulatory requirements, taking into account the purpose and nature of the processing, the duration of our contractual or business relationship, our legal obligations, and any potential legal claims that may arise.
Where processing is based on your consent, your Personal Data will be retained for the period required by the applicable legislation and the specific purpose for which the consent was obtained, including any statutory retention obligations imposed upon the Company.
In any event, unless a longer retention period is required or permitted by law, the Company applies a maximum retention period of twenty (20) years, corresponding to the general limitation period for legal claims under applicable law. This period may be extended where necessary for the establishment, exercise, or defence of legal claims, during pending litigation, or where required in connection with investigations or audits conducted by competent public authorities.
Once the applicable retention period has expired, and where the Personal Data are no longer required, they will be securely and irreversibly deleted or anonymised.
- Your Rights under the GDPR
You remain in control of your Personal Data at all times.
Whether you are a registered user or a visitor to our website, you may exercise, at any time, the rights granted to you under the GDPR, in particular Articles 12 to 23, as well as under applicable national legislation.
These rights include:
- Right to Information and Transparency (Articles 12, 13 and 14 GDPR), namely the right to be informed about how your Personal Data are collected, used, and processed, including through this Privacy Policy.
- Right of Access (Article 15 GDPR), enabling you to obtain confirmation as to whether we process your Personal Data and, where applicable, to receive a copy of such data.
- Right to Rectification (Article 16 GDPR), enabling you to request the correction of inaccurate Personal Data or the completion of incomplete Personal Data.
- Right to Erasure (“Right to be Forgotten”) (Article 17 GDPR), subject to the Company’s legal obligations or other lawful grounds for retaining your Personal Data.
- Right to Restriction of Processing (Article 18 GDPR), where, for example, you contest the accuracy of your Personal Data, the processing is unlawful, or the Personal Data are no longer required for the original processing purposes but must be retained for legal reasons.
- Right to Data Portability (Article 20 GDPR), where processing is based on your consent or on a contract and is carried out by automated means. In such cases, you may receive the Personal Data you have provided to us in a structured, commonly used, and machine-readable format and request that they be transmitted to another controller, where technically feasible.
- Right to Object (Article 21 GDPR), where processing is based on the Company’s legitimate interests and you object on grounds relating to your particular situation. This includes the right to object to automated decision-making, including profiling, where applicable (Article 22 GDPR).
- Right to Withdraw Consent (Article 7(3) GDPR) at any time where processing is based on your consent. Withdrawal of consent shall not affect the lawfulness of any processing carried out before such withdrawal.
You also have the right to lodge a complaint with the competent supervisory authority if you believe that the processing of your Personal Data infringes the GDPR (Article 77 GDPR). You may lodge such complaint with the supervisory authority in the Member State of your habitual residence, your place of work, or the place where the alleged infringement occurred.
In Greece, the competent supervisory authority is the Hellenic Data Protection Authority (HDPA), located at 1–3 Kifisias Avenue, 115 23 Athens, Greece, Tel.: +30 210 6475600, Email: contact@dpa.gr.
- Exercising Your Rights and Submitting Complaints
You may exercise your rights under the GDPR at any time by any of the following means:
- by sending an email to info@gefsinus.gr, together with the completed Data Subject Rights Request Form made available by the Company;
- by sending a written request to the Company’s registered address or by delivering it in person to our offices, using the relevant Data Subject Rights Request Form provided by the Company.
Your request must be accompanied by appropriate evidence verifying your identity. The Company reserves the right to request additional information where necessary to confirm your identity before responding to your request.
Requests will be processed following receipt of the duly completed Data Subject Rights Request Form, which is available on our website, and in accordance with the instructions contained therein.
The Company will make every reasonable effort to respond to your request within one (1) month of its receipt. Where the request is particularly complex or where multiple requests have been submitted, the Company reserves the right to extend this period as permitted under Article 12 GDPR. In all cases, you will be informed of the progress of your request within one (1) month from the date on which it was submitted.
- Security of Processing
The Company implements appropriate technical and organisational measures designed to ensure a level of security appropriate to the risks associated with the processing of Personal Data. In particular, such measures are intended to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or unauthorised access to Personal Data transmitted, stored, or otherwise processed, while also safeguarding both the physical and technical security of our information systems, in accordance with Article 32 GDPR.
The Company has adopted and maintains internal policies and procedures and processes Personal Data in accordance with the principles set out in Article 5 GDPR, ensuring the confidentiality, integrity, and availability of your Personal Data.
- Social Media
The Company maintains an official presence on the following social media platforms:
- TikTok
In relation to certain processing activities carried out through these platforms, the Company and the operators of the respective social media platforms act as independent Controllers of your Personal Data.
Each social media platform provider is responsible for operating its own information technology infrastructure, implementing its own technical and organisational security measures, and determining the processing of Personal Data carried out through its services. Consequently, each provider maintains a separate legal relationship with you as a user of its platform and, where applicable, as a Data Subject.
For further information regarding the processing of your Personal Data by the providers of these social media platforms and the rights available to you, please refer to the respective privacy policies of each platform.
Any Personal Data that you voluntarily make available through our social media pages, including comments, photographs, videos, reactions (“likes”), public messages, or similar content, are published on the relevant social media platform that you have chosen to use.
The Company does not process such Personal Data for any purpose other than:
- providing information regarding our products, services, promotional campaigns, discounts, special offers, competitions, and other marketing activities; and
- responding to your enquiries and communicating with you where you choose to contact us through our social media channels.
Such processing is carried out on the basis of the Company’s legitimate interests pursuant to Article 6(1)(f) GDPR, namely to communicate effectively with customers and prospective customers and to provide high-quality customer service.
- Additional Statements
The Company shall not be liable for any direct, indirect, incidental, consequential, or other loss or damage arising out of or in connection with the use of, or inability to use, this website. Users are solely responsible for protecting their own devices and systems against viruses, malware, or any other malicious software.
The Company does not make decisions producing legal or similarly significant effects based solely on automated processing, including profiling, in relation to your Personal Data.
The Company reserves the right to amend or update this Privacy Policy at any time. Users will be informed of any material changes, and the most recent version of the Privacy Policy will always be published on the Company’s website. We therefore recommend that you review this Privacy Policy periodically to remain informed of any updates.
The Company confirms that your Personal Data will not be processed for purposes other than those expressly described in this Privacy Policy without first informing you and, where required by applicable law, obtaining your prior consent.
Controller Details |
Address:7 Asklipiou Street Kryoneri, Attica 14568, Greece Telephone: +30 210 6254950 Fax: +30 210 6254954 Email: info@gefsinus.gr Website: www.gefsinus.gr
|
Hellenic Data Protection Authority (HDPA) |
Address: 1–3 Kifisias Avenue 115 23 Athens, Greece Telephone: +30 210 6475600 Fax: +30 210 6475628 Email: contact@dpa.gr Website: www.dpa.gr
|
Data Protection Officer (DPO) |
Email: dpo@gefsinus.gr
|