Privacy Policy

Policy concerning the Protection of Personal Data & Cookie Policy

 

Welcome to the website of “Papoutsanis e-Shop” (https://www.papoutsanis.gr) (the “Website”).

 

Policy concerning the Protection of Personal Data

 

Last update: 23 August 2023

 

1. Data Controller

This Privacy Policy (hereinafter the “Policy”) applies to the e-shop operated by the company registered as “PAPOUTSANIS SA”, based in Vathy, Avlida, Evia, at the 71st km of the Athens-Lamia National Road, 34100, Greece, tel. +30 22620 85000, (hereinafter the “Company” or “PAPOUTSANIS), which PAPOUTSANIS runs and manages through the website www.papoutsanis.gr (hereinafter the “Website”, the “Site” or the “e-shop”). PAPOUTSANIS is the data controller of your personal data, as set out in Regulation EC/2016/679 (General Data Protection Regulation).

This Policy should be read in conjunction with the Cookies Policy and the e-shop Terms and Conditions of Use, as these texts constitute an integral part of this Policy, and uniformly govern the overall operation of the e-shop and the transactions undertaken through it.

By continuing to navigate our e-shop and/or placing your orders, you automatically and unconditionally accept the terms of this Policy and its occasional amendments.

 

2. Data Subjects

PAPOUTSANIS’ Privacy Policy that follows applies to those of you:

- Who navigate our Site,

- Who create an account and/or purchase products from our e-shop,

- Who contact us,

- Who receive news from us through our promotional campaigns

(hereinafter “you”).

 

3. Channels of Communication

Contact information: With regard to any topic related to this Policy and the processing of your personal data, you may contact us in one of the following ways:

- By phone at +30 22620 85000, Monday to Friday, 9:00-17:00

- By regular mail sent to the following address: 71st km Athens-Lamia National Road, Ritsona, Evia, GR-34100

- By email at: dpo@papoutsanis.gr

 

4. Collecting Information

4.1. Your personal data include any information, either on its own or in combination with other information, that allows you to be uniquely identified, according to the provisions of the Regulation, Greek laws in effect and the decisions of the Hellenic Data Protection Authority (HDPA), as well as the directives and resolutions of competent European bodies.

 

4.2. Indicatively, we also collect the following categories of personal data that pertain to you when:

 

 

You register on the website

 

Contact and identification data (full name, account login information, home address, credit or debit card number, mobile phone or landline number and email address)

 

 

You place an order

 

 

Identification data (full name)

Account login data

Transaction/purchase data (billing address, delivery address, value and time of purchase, type of card, payment method)

Contact information (telephone number, email)

Other financial and tax data (payment method, value of transactions, credit notes, refunds, receipt information)

 

 

You take part in an online survey/contest

 

 

As required by the terms of each survey or contest, on a case-by-case basis

 

 

You contact us

 

 

Data and information or general comments you share with us, e.g. about the products you use

 

 

You sign up for our newsletter

 

Contact data (email)

 

 

4.3. Additionally, we may also collect the following categories of personal data that pertain to you through automated means when:

 

 

You navigate the Website

 

 

Technical data (Internet Protocol [IP] address, operating system)

Analytics data (statistics/pseudonymised data collected through cookies, browser information. Additional information is available in our Cookies Policy)

 

 

 

 

4.4. Note that as regards processing of your personal data by Google, Facebook, Instagram or YouTube, you will have to refer to each of their own privacy policies. These companies are joint Data Controllers with PAPOUTSANIS only when processing your personal data in the event you connect to our e-shop through them.

 

4.5. To clarify, during the payment process, we do not collect, process, record or store the payment information for the particular transaction, e.g. credit card numbers, etc. You provide these particulars directly to the respective payment service provider only.

 

4.6. If you provide personal data on behalf of a third party, you should ensure that the third party in question has previously been made aware of this Policy.

 

4.7. To help keep your data current, please notify us of any changes to the data we process.

 

4.8. This Website is not designed for children and we do not knowingly collect personal data on children or minors under the age of 18. If you are under the age of 18, please do not use our Website and do not provide any information to us (namely: do not create an account on our e-shop, do not provide your email to sign up for our newsletter, do not make any purchases, and do not give us any information about yourself, including your name, address or contact information, etc.).

 

5. Notice of Purpose

5.1. The following table aims to inform you of the purposes for which any type of processing is performed (each operation or series of operations we undertake, which is performed with or without the use of automated means on personal data or a set of personal data, e.g. collection, retention, transmission, etc.) on behalf of PAPOUTSANIS and to set out the legal basis (i.e. the legal reason that allows us to process your personal data in the manner and for the purpose we state) on which each of these is grounded.

                                                                                                                                          

Purpose of Processing

 

Data

 

Legal Basis for Processing

 

Creating and Managing an Account

 

We collectthe personal data you enter to create an account and/or those you enter when placing an order and which are automatically stored in your account; we process themfor the purpose ofcreating and maintaining an account on our e-shop

Identification data(first name, last name)

 

Contact data(email or telephone)

 

Account login data(our email address/particulars you have provided to a linked provider - Facebook - name and profile picture, email/Google, email or telephone number)

 

Favourite product data

 

Order history data

 

Comments(contents of the comment and full name/pseudonym you use)

 

a) Fulfilment of our contractual relationship.We process your personal data based on the contract between us at a pre-contractual stage, when entering into it, for its duration or following its dissolution.

 

b) compliance with legal obligations we are subject to.We process your personal data that is necessary as part of meeting our legal obligations related to the management and retention of tax-related data arising from the sales contract

 

c) our legal interest.We process your personal data to exercise or defend against any legal claims.

 

Filling an order

We collectyour personal data when your order is placed, cancelled or during the return of a product and for contacting you with regard to your order. We process themfor the purposeof delivering your orders, processing, managing and monitoring your order and updating you on its status, as well for managing and completing your payments, and ensuring the security of our financial transaction

 

a) Identification data(full name)

 

 

Transaction details(billing address, delivery address, value, time of purchases, payment method, delivery method)

 

Contact information(telephone number, email)

 

Financial data(payment method, value of transactions, credit notes, refunds)

 

b) Tax data(receipt particulars)

 

a) Fulfilment of our contractual relationship.We process your personal data based on the contract between us at a pre-contractual stage, when entering into it, for its duration or following its dissolution.

 

b) compliance with legal obligations we are subject to.We process your personal data that is necessary as part of meeting our legal obligations related to the management and retention of tax-related data arising from the sales contract

c) our legal interest.We process your personal data to exercise or defend against any legal claims.

 

Responding to requests

 

We collectthe personal data you provide when you contact us by phone or email, and when you fill out the contact form on our Site, or when you send us a message through the chat feature on social media. We process the datafor the purpose ofhandling complaints you submit via email or phone, resolving problems related to your orders or after-sales faulty products, responding to your other requests and documenting comments related to the products we sell (either through the e-shop or at physical stores)

 

Identification data(first name, last name)

 

Contact data(email, telephone)

 

Transaction data, where required (type of purchase, time of purchase, time and place of delivery, cancellation, complaints, order history)

 

Information you share when you contact us

 

Given the variety of requests submitted to PAPOUTSANIS, processing is performed based on the following legal grounds:

 

a) Fulfilment of our contractual relationship.We process your personal data based on the contract between us at a pre-contractual stage, when entering into it, for its duration and/or following its dissolution, particularly when you contact us with requests related to your order,

 

b) compliance with legal obligations we are subject to.We process personal data necessary to adopting tools/means of serving customers before and after sales,

 

c) your consent, when circumstances require us to contact you regarding your service, following a request you have submitted.

You can withdraw your consent at any time by sending an email todpo@papoutsanis.gr

 

E-shop operation

 

We collectcertain personal data derived from your navigation of the e-shop with automated means and we process itfor the purpose ofensuring the Site functions properly and safeguarding transaction security, responding to any technical issues, optimising commercial processes and technical systems,for the purpose ofproviding the best possible service and navigation experience on the Site

 

a) Technical(Internet Protocol [IP] address, operating system)

 

b) Other data through cookies and log files

 

a) Our company’s legal interestto ensure the flawless technical function of our e-shop, the management and optimisation of technical systems and transaction security, which must be balanced fairly against your privacy and your rights.

 

b) Your consentby accepting cookies through the cookie banner on our Website when navigating the e-shop – for further details, see our Cookies Policy.

You can withdraw your consent through the cookie banner on our Website.

 

Commercial Communication

 

We collectyour personal contact details when:


a) you enter them in the appropriate field on our websitefor the purpose ofsending Newsletters


b) you have made purchases on the e-shopfor the purpose ofrunning promotional campaigns for products related to your purchase

 

Contact data(email)

 

 

 

 

 

 

 

 

 

 

 

 

 

a) Your consent.We process your data for commercial correspondence after your consent to register for our newsletter.

You can withdraw your consent at any time by clicking on the “unsubscribe” button in the email you receive or by contacting our Company.

 

b) Our legal interest.If you have made purchases from our e-shop, we process your email or other data you have provided for this purpose so we can contact and recommend related products or new products and services we believe will interest you.

 

Participation in an online survey or contest

 

We collectyour personal data when we carry out
- online surveys
- contests

and you express your desire to take part by sending us the data required by each contest/survey and we process itfor the purpose ofcompleting the contest/survey

 

Identification data(first name, last name)

 

Contact data(email, telephone)

 

Data used for participating in contests

 

Data related to comments you

send us

 

Your consentto our processing of your personal data so you can take part in any online surveys or contests we carry out as specified by the terms of each contest.

You can withdraw your consent at any time by sending an email to:dpo@papoutsanis.gr

 

 

 

5.2. The processing of your personal data which you have expressly disclosed to us is based on our obligation under Article 23 of Regulation (EC) 1223/2009 regarding maintenance of a procedure for collecting feedback.

 

5.3. Where the legal basis for processing your data is our Company’s legal interest, you may object to the processing by contacting the Company at dpo@papoutsanis.com.

 

5.4. Where your consent is required for commercial communication (e.g. for sending the PAPOUTSANIS newsletter), you can choose to receive such communication at the email you provide us. In the event you consent to communication without providing an email address (e.g. while creating an account), we will use the contact email you gave us during registration.

 

5.5. Each withdrawal of consent will also apply in the future.

 

5.6. It is possible that some of your personal data may be processed based on our legal interest and our Company's compliance with its legal obligations for other purposes, such as when we receive documents, requests, orders, case files, warrants, etc. from third-party legal authorities or bodies, e.g. supervisory, prosecutorial, judicial or tax authorities, to investigate offences and to protect you against fraud or to combat any form of criminal activity and infringement of legal rights.

 

5.7. No profiling is performed while reviewing the quality of products when you submit your comments, but this data is collected and used separately for communication using the method of communication you have used.

 

6. Data Storage Period

We will store your personal data for the duration of your interaction with PAPOUTSANIS and/or for as long as necessary to fulfil the purposes of processing as described above (e.g. if you maintain an account, if you are registered to receive our newsletter, if you participate in contests, if you order one of our products, for tax purposes, etc.). Your personal data is deleted once the purposes for which they are stored have been fulfilled (e.g. if you maintain an account, if you order a product from our e-shop, if you participate in contests we hold, for tax purposes, etc.). If their purpose has not been fulfilled, the data remains on the e-shop database until you request their deletion (e.g. if you ask to have your account deleted), unless their retention is mandated by legal obligations (e.g. tax purposes) or to defend our Company's legal rights.

 

7. Rights of the Data Subject

7.1. Based on GDPR, you have rights regarding the information that applies to you and which PAPOUTSANIS collects and processes. These rights include the right to ask the Company for access to the information we collect during a transaction, as well as its rectification or deletion; the right to object to the processing of information that pertains to you at any time and for reasons related to your particular circumstances, including profiling; and the right to ensure that Papoutsanis restricts processing if you question the accuracy of information and for as long as required to verify the accuracy of such information, if processing is unlawful, if you prefer to restrict use instead of deleting the data, and if you object to processing, as related to the right to object. Additionally, you have the right to receive information that pertains to you and which you have provided to Papoutsanis in a structured, commonly used and machine-readable format when processing is performed by automated means (right to data portability). You can exercise your rights using the contact information for our Company, as above.

 

7.2. When exercising your rights, we retain the right to ask you to provide certain information that verifies your identity if you submit a request to exercise your rights relative to these files.

 

7.3. Your request should include specific and true details and/or actual events so that we can answer and/or respond to them accurately. Otherwise, our Company reserves every right to refuse any requests that are unfounded, excessive, abusive or illegal.

 

7.4. We will respond to your timely and accurate requests within one (1) month of receiving them, unless these are particularly complex or if you have submitted a series of requests together. If we need more time to respond to your request, we will inform you to that effect within the month.

 

7.5. We will not charge you with the cost of exercising your rights with regard to your personal data unless, as the law provides, you request for access to information is unfounded or excessive, in which case we have the right to impose a reasonable fee under these circumstances. In any event, we shall inform you of any charges before we complete your request.

 

7.6. You may contact us at the details listed above and submit your comments, questions, observations or complaints with regard to this Policy and the collection and processing of your personal data in general.

 

8. Information Recipients

8.1. As part of the proper function of the e-shop and the fulfilment of its contractual obligations, our Company works with third-party companies which acquire access to only the type of data that is absolutely essential for activities, such as the following cases:

 

Data Recipients

 

Examples

 

Service providers and our partners who provide services on our behalf based on our instructions

 

 

When we work with third parties for:

  • the delivery of products
  • payments and refunds
  • provision of accounting and legal services
  • conducting marketing and communication campaigns
  • improving the quality of our products
  • the functional and computerised organisation of our Website

 

Any public, police, administrative or judicial authority

 

 

When mandated by law or the decision of a competent court or authority or other competent body/organisation (e.g. in the event of a legal provision, departmental order or official preliminary investigation)

 

 

Recipients of your personal data may be third-party companies with which we work to develop new functions and for the technical maintenance and support of the Website and our e-shop, and our accounts on Facebook, LinkedIn, Instagram and YouTube.

 

8.2. When transferring your personal data, we constantly ensure the highest possible level of security. As such, your data shall be transferred only to service providers and partner companies which have been carefully selected and are bound by contract in advance.

 

8.3. All partner companies which support our systems and the operation of our Company acquire access only to data that is absolutely essential for the services they provide us. They are contractually bound to maintain the confidentiality of your data and all technical and organisational measures for secure processing and to not use your information in any other manner other than to help us provide the products and services for which we have agreed.

 

8.4. As a rule, the Company stores your personal data on servers located inside the European Economic Area (EEA).

 

9. Amendments to the Policy

It is possible we may revise this Policy by posting an updated version on our Website or by contacting you via email. This Policy was last revised on August 2023.