At FRAGOULIS K & SIA E.E., our goal is to protect and safeguard the privacy of the information provided to us, always respecting the trust of our customers and the users of our website.
We always comply with the applicable national and European legislation on Personal Data Protection and have implemented a series of actions and procedures to be fully compliant with the new General Data Protection Regulation (GDPR) of the European Union. Please read this Privacy and Personal Data Protection Policy carefully.
This Policy sets the basis for the processing by our website of all personal data we collect from you or that you provide to us. We retain certain basic information when you visit our website and recognize the importance of keeping this information secure, as well as informing you about how we intend to use it.
Please read this Policy to learn more about how we collect, store, use, transfer and protect the personal data and information we receive. Also, learn about the rights you have regarding this collection and processing, the ways in which you can exercise them, and how you can generally contact us for any questions.
Table of Contents
- Principles governing data processing
- Lawfulness of processing
- Minors
- Collection and use of Personal Data
- Transfer of Personal Data to third parties
- Rights and how to exercise them
- Links to other websites
- Provision of professional services
- Changes to the personal data protection policy
- Contact
Principles Governing Data Processing
a) Lawfulness and transparency
All personal data we collect is processed lawfully and fairly, always in accordance with applicable legislation and in a transparent manner regarding the information we collect about you.
b) Purpose limitation and data minimisation
FRAGOULIS K & SIA E.E. collects your personal data for specified, explicit and legitimate purposes, and this data is not processed in a manner incompatible with those purposes. Furthermore, only appropriate and necessary data is collected to the extent of the purpose for which it is processed. That is, the information and data you share with us is not subject to further unlawful processing, unless there are reasons of public interest.
c) Accuracy
Your personal data is accurate and, where necessary, kept up to date. FRAGOULIS K & SIA E.E. takes all reasonable measures to immediately delete or correct inaccurate personal data, through the ready-made editing form as well as direct communication via email, as described in detail below.
d) Storage limitation
FRAGOULIS K & SIA E.E. retains your personal data only for the period required for the purposes of its processing or compliance with each individual’s request, or until deletion is requested by the data subject (and in any case no more than 10 years, unless we continue to retain it as provided by applicable law).
e) Integrity, Confidentiality and Data Security
FRAGOULIS K & SIA E.E. implements appropriate security policies and procedures so that your personal data is processed in a manner that guarantees appropriate security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage, using appropriate technical and organisational measures.
Despite the efforts made by FRAGOULIS K & SIA E.E., security cannot be absolutely guaranteed against all threats. In the event of loss or breach of personal data, we have a specialised incident response team and a procedure for handling such incidents in order to restore the breach as quickly as possible, limit potential consequences and comply with our legal obligations. We make every possible effort to limit access to your personal data to those who need to know it. Individuals who have access to the data are obliged to maintain the confidentiality of that data. In the event of a breach of your personal data, we will notify you immediately and by every appropriate means.
Lawfulness of Processing
For the processing of your personal data and information to be lawful, certain conditions must be met. FRAGOULIS K & SIA E.E., always in line with Greek and EU legislation, collects only the personal data that is necessary and required, observing the following lawful conditions:
a) Your consent: For the processing of the data you provide to us, you must first give us your consent by accepting the terms of use and this privacy policy of our website, and the use of cookies. We may occasionally ask your specific permission to process certain personal data, and the processing of your personal data will only be done in this way if you agree. You may withdraw your consent at any time either by completing the “Personal Data Management Request”, through which you may at any time request the withdrawal of your consent to the processing of certain personal data as well as the export, correction or deletion of your personal data held by us, or by contacting FRAGOULIS K & SIA E.E. at info@fragoulis.com.gr.
In general, you are not required to submit personal data to FRAGOULIS K & SIA E.E. online, but we may ask you to provide certain personal data in order to receive additional information about our services and events. FRAGOULIS K & SIA E.E. may also request your permission for certain uses of your personal data and you may either consent to or refuse these uses. If you accept the consent clause for specific services or communications, such as an electronic newsletter, you will be able to unsubscribe from the relevant mailing list at any time by following the instructions contained in each communication. If you decide to unsubscribe from a service or communication, we will endeavour to delete your data as soon as possible, although we may need some time and/or information before we can process your request.
b) Performance of a contract: This occurs when the processing of your personal data is necessary for the fulfilment of our obligations arising from a contract to which you are a party, or at your request prior to entering into a contract.
c) Legal obligation: This occurs when we are required to process your personal data in order to comply with a legal obligation, such as keeping records for tax purposes or providing information to a public body or law enforcement authority.
d) Legitimate interest: We may process data about you when we have a legitimate interest in carrying out a lawful activity in order to ensure the continuity of that activity, provided this does not override your interests.
e) Public interest: Sometimes processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority.
Minors
FRAGOULIS K & SIA E.E. recognises the importance of protecting the personal data of children, especially in an online environment. If the child providing consent to the processing of their personal data has reached the age of 16, the processing is lawful. If the child is under 16 years of age, such processing is lawful only if and to the extent that consent is given or authorised by the person who holds parental responsibility for the child.
Collection and Use of Personal Data
4.1 What data we collect
We receive your personal data if you choose to provide it (for example, if you contact us via email inboxes or if you register as a subscriber for certain services). In some cases, you may have already previously provided your Personal Data to FRAGOULIS K & SIA E.E. By registering and/or submitting your personal data to FRAGOULIS K & SIA E.E., you also consent to the use of such data in accordance with this Statement. Your personal data is not used for any other purposes, unless we receive your permission, or unless required or permitted by law or professional standards.
4.2 Automatic collection of Personal Data
In some cases, FRAGOULIS K & SIA E.E. and its service providers use cookies and other technologies to automatically collect certain categories of data when you visit us online, as well as through any electronic messages we may exchange. The collection of this data allows us to personalise your online experience, improve the performance, usability and effectiveness of FRAGOULIS K & SIA E.E.’s online presence, and measure the effectiveness of our service promotion activities.
4.2.1 IP Addresses
An IP address is a number assigned to your computer each time you access the internet. It allows computers and network servers to recognise and communicate with each other. IP addresses from which visitors appear to originate may be recorded for IT security and system diagnostic purposes. This data may also be used in aggregate form to perform trend analysis and website performance assessment.
4.2.3 Traffic counter
FRAGOULIS K & SIA E.E. uses eXTReMe Tracker as a traffic counter. eXTReMe Tracker is compliant with the General Data Protection Regulation. Its files are stored in Europe and the USA on Amazon AWS.
More information about eXTReMe Tracker’s privacy policy with FRAGOULIS K & SIA E.E. can be found here: https://extremetracking.com/?policy
If you wish to have your personal data deleted from eXTReMe Tracker, you may either contact us through the personal data management form, or send your request to info@fragoulis.com.gr and we will ensure your request is fulfilled.
4.3 Social media applications and widgets
The FRAGOULIS K & SIA E.E. website may host blogs, forums, and other applications or services (collectively referred to as “social media features”). The purpose of social media features is to facilitate the sharing of information and content. Any personal information you provide on any FRAGOULIS K & SIA E.E. social media feature may be disclosed to other users of that social media feature (unless otherwise stated at the point of collection), over whom we may have limited or no control.
The publication of personal data of third parties (images, etc.) through the FRAGOULIS K & SIA E.E. website is unlawful, unless prior consent of the data subjects has been obtained.
Transfer of Personal Data to Third Parties
We do not share personal data with unaffiliated third parties, unless required for our lawful professional and business needs, to respond to your requests, and/or as required or permitted by law or professional standards.
This includes the following third parties:
External service providers: Where required, we will assign to other companies and individuals the performance of certain tasks that contribute to our services on our behalf under data processing agreements. We may, for example, provide personal data to partners to host our databases and applications, to provide data processing services, to send you information you have requested, or to call centres for the purpose of providing support services or conducting interviews during market research projects. All partners of FRAGOULIS K & SIA E.E. are fully GDPR compliant and are contractually bound to observe it. FRAGOULIS K & SIA E.E. transfers personal data to them only when they meet our strict data processing and security standards. We only disclose personal data that enables them to provide their services.
Business transfer: In the event of a reorganisation, restructuring, merger, sale or other transfer of assets, we will transfer data, including personal data, on a reasonable scale, provided that the recipient agrees to respect your personal data in a manner consistent with applicable data protection laws. We will continue to ensure the confidentiality of any personal data and will inform you when your personal data becomes subject to a different privacy policy.
Courts, judicial or regulatory authorities: FRAGOULIS K & SIA E.E. may disclose personal data in order to respond to requests from courts, judicial, governmental or law enforcement authorities, or where required and prudent to comply with applicable law, court rulings or orders from courts or judicial authorities.
Public Bodies: FRAGOULIS K & SIA E.E. may disclose personal data in cases of audits by public bodies and authorities, such as audits relating to personal data protection, security, and tax audits.
Personal data that may be disclosed to the following recipients includes:
- MANBIZ ISP – AFOI I MANELIDI OE
- Vimeo
- Hetzner
FRAGOULIS K & SIA E.E. will not transfer the personal data you provide to any third parties for their own direct marketing purposes.
Rights and How to Exercise Them
If you have submitted personal data to FRAGOULIS K & SIA E.E., you have the following rights:
Right of access: You have the right to access and export your personal data. Before providing you with personal data, we may ask you for proof of identity and sufficient information about your transactions with us from which we can locate your personal data.
Right of rectification: If the data we hold about you is inaccurate, you may correct it through the editing of your profile, the “Personal Data Management Request”, or alternatively ask us to correct any inaccuracies in it.
Right to object and restriction of processing: You have the right to object to the processing of your personal data by us if we no longer have the right to use it, for any lawful reason, or to request that its processing be restricted in certain cases, such as for reasons of data accuracy and lawfulness.
Right to data portability: Upon your request, we will transfer your data to another data controller, where technically feasible, provided that the processing is based on your consent or is necessary for the performance of a contract.
Right to erasure: You have the right to request the deletion of your data in certain cases, such as if it is no longer necessary for processing or has been in our records for a long period of time.
You may exercise the above rights by completing the “Personal Data Management Request”, through which you may at any time request the export, correction or deletion of your personal data held by us.
You may also submit a request or exercise the above rights by contacting us at info@fragoulis.com.gr and we will make all reasonable and practical efforts to comply with your request, to the extent it is consistent with applicable law and professional standards.
Links to Other Websites
The FRAGOULIS K & SIA E.E. website may contain links to other websites for your convenience and information. These websites operate independently and, as they are not affiliated with FRAGOULIS K & SIA E.E., are not under our control and we are not responsible for any unlawful processing of your personal data. They may follow their own privacy policy, which we encourage you to review if you visit any link to other websites, before disclosing any personal data.
Provision of Professional Services
FRAGOULIS K & SIA E.E. receives personal data in the course of providing professional services — typically when providing services to individuals, employers, businesses with individual clients and the public sector. Our relationships with clients are governed by engagement letters and general terms of business, including the use of personal data we receive. FRAGOULIS K & SIA E.E. provides various types of services and its role may not always be clear to individuals who are data subjects. However, FRAGOULIS K & SIA E.E. complies with its obligations arising from the applicable Greek and European legislation on personal data protection, as applicable, and the applicable regulatory guidelines related to the management of personal data.
Changes to the Personal Data Protection Policy
FRAGOULIS K & SIA E.E. may periodically amend this Policy so that it adapts to national and EU legislation and reflects our latest privacy practices. When we make changes, we will record the date of modification or revision at the end of this page and, where deemed necessary, we will notify you of the changes.
Contact
If you have any questions, comments or complaints regarding our management or protection of your personal data, or if you wish to modify your personal data or exercise any of your rights as a data subject, please contact us at info@fragoulis.com.gr.
This policy was last revised on 23 May 2018 and is effective from 25 May 2018.
Fragoulis Stylianos IKE
