(Privacy Policy and Data Processing Information)
The company Rontsis B2B, located in [City, Street, and Number] (hereinafter referred to as “the Company,” “we,” or “us”), acts as the Data Controller for the processing of personal data.
The protection of your fundamental right to data privacy is of utmost priority for us. The Company processes your personal data in compliance with the General Data Protection Regulation [GDPR] and all applicable national and European legislation.
Purpose of This Policy
This policy aims to inform you about:
→ The collection, storage, use, sharing, and general processing of your personal data when you visit, register, or use the Company’s website and when you engage with its physical stores.
→ The purposes of processing and the ways your personal data are handled.
→ The duration for which your personal data are retained.
→ The measures we take to protect your personal data.
→ Your rights as a data subject and the procedures to exercise them.
Definitions
In this policy, the following terms have been assigned specific meanings in line with the GDPR:
→ Personal data: Any information relating to an identified or identifiable individual (hereinafter referred to as “personal data” or “data”). Personal data includes information that identifies or can identify you, such as name, postal address, email address, phone number, Tax Identification Number, etc.
→ Processing: Any operation or set of operations performed on personal data, whether by automated means or not, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, restriction, erasure, or destruction.
→ Data Controller: The natural or legal person, public authority, agency, or other entity that determines the purposes and means of processing personal data, in this case, the Company.
→ Data Processor: A natural or legal person, public authority, agency, or other entity that processes personal data on behalf of the Data Controller, in this case, on behalf of the Company.
→ Recipient: A natural or legal person, public authority, agency, or other entity to whom personal data are disclosed, whether a third party or not.
→ Consent: Any freely given, specific, informed, and unambiguous indication of your wishes as a data subject, by which you signify agreement to the processing of personal data relating to you.
→ Personal data breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to personal data transmitted, stored, or otherwise processed.
→ Website: The website princessa.store, which serves as the Company’s online store for presenting and selling products and services (hereinafter referred to as the “website” or “online store”).
→ Social networks: The pages the Company maintains on social networking platforms (Facebook, Instagram, Twitter, LinkedIn, etc.), where you may become a member if desired.
Principles of Data Processing
We ensure the lawful processing of your personal data. Specifically, we process your data according to the principles of:
→ Lawfulness, fairness, and transparency.
→ Purpose limitation.
→ Data minimization.
→ Accuracy.
→ Storage limitation.
→ Integrity and confidentiality.
We continuously ensure effective protection of your personal data by implementing all necessary and appropriate technical and organizational measures.
Protection of Minors
Our website is intended for adults. Minors may access our services only with the consent of their parents or guardians and are not required to submit personal information. In cases where minors provide such information, the website administrators will delete it. The Company assumes no liability for the submission of false personal information during member registration.
What Data We Collect and Process and How
The personal data processed by our Company are appropriate, relevant, and limited to what is necessary for the specific purposes for which they are processed. We collect and process the following categories of personal data:
Personal Data Provided Directly by You
We collect and process the following data that you voluntarily provide to the Company:
- Account Registration:
When you register as a user and create an account on our online store b2b.rontsis.gr, entering the required details, to request a quote, complete a transaction (order, product purchase), or enable communication with you. - Transaction and Purchase:
For quotes or transactions (orders, purchases), we require: name, surname, postal address, email address, landline and mobile number, and, if an invoice is requested, your profession, Tax Identification Number, and Tax Office. - Payment Details:
If you make a purchase using a credit or debit card, details such as cardholder name, card number, expiration date, and CVV number are requested. Payment information is not recorded or stored during the transaction, as you provide it directly to the payment service provider. - Basic Registration:
For account creation, only your email address and password are required. - Mandatory Fields:
Fields essential for transactions are marked as mandatory.
Failure to provide the mandatory personal data required for product purchases will prevent the conclusion or execution of the sales contract.
Data Maintained
We may store the following data in written form and/or electronically:
→ Data provided in physical stores.
→ Data from email communication.
→ Preferences for receiving newsletters.
→ Social network usernames and communication records.
→ Application details for job or partnership opportunities.
Automatically Collected Data
During your visit to our website, the following non-identifiable technical data may be automatically collected for technical reasons:
→ Technical Information: Internet Protocol (IP) address, browser details, country code, etc.
→ Website Analytics: Traffic data, visited sections, viewed products, etc.
→ Preferences: Product preferences to improve user experience.
→ Cookies: Data collected via browser cookies.
These data are processed primarily for technical reasons or in anonymized form for statistical purposes and service improvements.
From Third Parties
We may collect and store certain information about you from third parties, such as details related to product delivery or your address, obtained from courier companies.
Image Data
If you visit our physical stores, your image may be recorded through a closed-circuit television (CCTV) system.
Other Data
We process information related to customer feedback, product reviews, and complaints.
Purposes for Collecting and Processing Your Data
We collect and process your personal data for the following purposes:
- Execution and Management of Our Contractual Relationship: To process sales of products and/or provision of services.
- Facilitating Communication Between Us: To enhance customer service, including contacting you by phone, email, or other means to clarify a request for a quote or an order, update you on product availability, order progress, shipping and delivery, debt management, product returns, refunds, warranty provision, and responses to inquiries, complaints, or requests.
- Compliance with Legal Obligations: To fulfill obligations imposed by European and national legislation (e.g., tax laws, e-commerce laws) or by court decisions.
- Safeguarding Legitimate Interests: For example, ensuring the security of our premises and individuals at our physical stores, preventing fraud, ensuring network security, or pursuing our legal claims, both judicially and extrajudicially.
- Managing User Registration and Account Creation: To provide account functionalities and facilitate purchases.
- Adjusting to Your Preferences: To evaluate, improve, and tailor our products and/or services to your preferences.
- Account Security: Protecting your account from fraud and other unlawful activities.
- Secure Browsing and Transactions: Ensuring secure navigation and safe transactions on our e-commerce platform.
- Payment Processing and Fraud Prevention
- Marketing and Information Purposes: With your prior consent, we may use your data for promotional and informational purposes (e.g., newsletters about offers, promotions, and commercial announcements about our products and services, customer satisfaction surveys, or web push notifications).
- Evaluating Job Applications and Resumes: For hiring purposes.
Legal Bases for Processing Your Personal Data
Our data processing is based on one or more of the following legal bases:
- Contract Performance: Necessary to execute the sale or provision of services.
- Compliance with Legal Obligations: As required by applicable European and national laws, such as tax or consumer protection laws.
- Protection of Vital Interests: To safeguard your vital interests as a data subject.
- Legitimate Interests: To protect our legitimate interests, such as safeguarding individuals and property at physical stores, provided these interests outweigh your rights, freedoms, or interests. This includes using CCTV in stores.
- Legal Claims: To establish, exercise, or defend legal claims.
- Consent: When processing is not based on another legal basis or when required by law (e.g., sending newsletters), we will process your data only with your prior, explicit, and freely given consent. You may withdraw your consent at any time with future effect.
Recipients of Your Personal Data
Processing is conducted either by our specially authorized personnel or via IT systems and electronic devices, and in exceptional cases, by third parties.
We share only the necessary data with:
- Third-Party Service Providers and Partners: Entities acting as data processors, such as IT and technology service providers, website hosting services, marketing and promotion firms, email and SMS services, customer service providers, banks (for credit card and payment processing), courier and logistics companies, accountants, and legal advisors.These processors are contractually obligated to:
- Use data exclusively for specific purposes outlined in their agreements with us.
- Ensure data confidentiality.
- Refrain from sharing or transferring data without our permission.
- Comply with data protection regulations.
- Delete or anonymize data upon the termination of our agreement.
- Other Third Parties: Where required for:
- Compliance with public or judicial authorities in case of claims or criminal actions.
- Prevention of unlawful website usage or breaches of our Terms of Use.
- Protection against third-party claims.
- Prevention or investigation of fraud (e.g., cybercrime).
Data Transfers
Personal data collected and processed is stored in Greece or other countries within the European Economic Area (EEA). If data transfer outside the EEA is required, we ensure that equivalent protections apply.
Retention Period of Personal Data
Your personal data is processed and retained only for as long as necessary to fulfill the purpose for which it was collected, unless a longer retention period is required by law.
Examples:
- User Account Data: Retained as long as your account is active. If you delete your account without making a purchase, the data will be deleted within three months.
- Purchase Data: Retained for five years from your last purchase, or longer if required by legal obligations.
- Marketing Data: Retained until you withdraw consent, with consent documentation kept for up to six months after ceasing communications.
- Job Applications: Retained for six months after the position is filled, unless you consent to a longer retention period for future opportunities.
- CCTV Footage: Retained for 15 working days unless an incident occurs, necessitating retention.
Data Protection
We implement advanced security systems and procedures and take all appropriate organizational and technical measures to ensure the utmost security and protection of your personal data against accidental or unlawful processing. We regularly test, evaluate, and adjust our measures to comply with technological standards.
Website Certification – Encryption
The website/e-shop princessa.store utilizes the Security Layer Transport (TLS) 1.2 encryption protocol to ensure secure online commercial transactions (key exchange: ECDHE_RSA with P-256, cipher: AES_256_GCM). Through this standard, your personal data is kept secure via encryption, while it is also ensured that no third party can monitor, intercept, or alter communications between servers and clients.
Processing Transactions with Credit Cards
To complete your transactions via credit card, you must follow the instructions provided on our online store and fill out the secure order form, including all required accompanying documents and details (cardholder name, card number, expiration date, CVV). The personal data you provide for payment is not disclosed to the Company nor stored in its system but is handled solely by the bank managing your card.
User Account Identification
The credentials used to identify you as a user and grant you access to your personal account (“My Account”) on our website/e-shop are:
(a) Your login ID or email address (username or email)
(b) Your personal security password.
By entering these credentials, your personal data is secured through encryption during its transmission over the internet and to the Company’s servers.
While we take all necessary measures to safeguard your personal data, you, as the account user, must also follow the required security measures. Since only the user knows their password, you are solely responsible for ensuring the confidentiality of this password to prevent unauthorized access. We recommend regularly changing your password using the feature provided on our website. Additionally, if you are using a shared computer, ensure you log out of your account.
Restriction of Access to Data
The Company takes all necessary security measures to ensure that within the organization, access to your personal data is restricted to authorized and appropriately designated personnel, solely for the purposes of processing. All personnel with access to your personal data are bound to maintain its confidentiality.
Data Transfer Security
As detailed above in the section “Data Recipients,” the Company always ensures the protection of your data during its sharing, transfer, or transmission.
Your Rights
As a data subject, you have the following rights:
- Right to Information: The right to full, transparent, easily accessible, and comprehensible information regarding the processing of your personal data.
- Right to Access: The right to receive confirmation from the Company on whether your personal data is being processed and, if so, access to the data and information regarding its processing.
- Right to Rectification: The right to request the rectification of any inaccurate personal data without undue delay and the completion of incomplete data (e.g., change of address). If you maintain a user account, you can log in to make corrections/updates without submitting a request.
- Right to Erasure: The right to request the Company to delete your personal data without undue delay, provided the specific conditions outlined in the GDPR (Article 17 GDPR) are met.
- Right to Restrict Processing: The right to request restriction of processing, provided the specific conditions outlined in the GDPR (Article 18 GDPR) are met.
- Right to Object: The right to object, at any time, to the processing of your personal data for reasons related to your specific situation. In this case, the Company will no longer process the data unless it demonstrates compelling legitimate grounds for the processing, which override your interests, rights, and freedoms, or for the establishment, exercise, or defense of legal claims.
- Right to Data Portability: If the processing is carried out by automated means, the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit the data to another controller without objection from the Company, provided this is technically feasible.
- Right to Withdraw Consent: If processing is based on your prior consent, you may withdraw it at any time with future effect (i.e., the withdrawal only applies to future processing and does not affect the lawfulness of processing based on consent before withdrawal). If you have a user account on our website, you can withdraw consent to stop receiving communications for promotional purposes (newsletters) by sending an email to [email protected].
- Right to Lodge a Complaint: If you believe your personal data has been processed in violation of the GDPR, you have the right to file a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
Exercising Your Rights
The Company undertakes to fulfill your rights as quickly as possible and, in any case, within one (1) month of receiving a written request. This deadline may be extended by two (2) additional months if necessary due to complexity or the number of requests. In such cases, you will be informed of the extension within one month of receipt of your request, along with the reasons for the delay.
If a request is submitted electronically, the response will be provided electronically, where possible.
If we do not act on your request, we will inform you within one month of receipt, explaining the reasons and your right to file a complaint with a supervisory authority or seek judicial redress.
In the case of a request, we may ask you to verify your identity. If a third party submits a request on your behalf, written authorization for the specific action will be required.
Cookies
Our website may use cookies to:
→ optimize site functionality
→ enhance the visitor/user experience during navigation
→ measure website traffic
→ improve overall quality of products and services for statistical and promotional (marketing) purposes
Deleting Cookies
You can delete cookies stored on your computer, for example:
→ In Internet Explorer (version 11), delete cookie files (instructions available at http://windows.microsoft.com/en-gb/internet-explorer/delete-manage-cookies#ie=ie-11).
→ In Firefox (version 36), delete cookies via “Tools,” “Options,” and “Privacy,” selecting “Use custom settings for history” from the dropdown menu, then “Show Cookies” and finally “Remove All Cookies.”
→ In Chrome (version 41), delete cookies by selecting “Customize and Control,” then “Settings,” “Show advanced settings,” and “Clear browsing data,” selecting “Cookies and other site and plug-in data” before choosing “Clear browsing data.”
Deleting all cookies may negatively impact website usage, preventing you from utilizing all functionalities.
Automated Decision-Making/Profiling
We do not engage in automated decision-making or profiling.
Links
The website princessa.store contains links to other websites. This privacy policy applies only to data collected on our website and does not cover data protection practices of other sites.
Policy Updates
This policy was last updated on November 2, 2020.
It may be revised periodically and updated as required by applicable national and European legislation without prior notice to users. Therefore, we recommend regularly reviewing this page for updates.
Contact Us
For any matter regarding the processing of your personal data and the exercise of your rights, you can contact us by phone at telephone or via email at email.
(*) European Regulation (EU) 2016/679 of the European Parliament and Council of April 27, 2016, “on the protection of natural persons regarding the processing of personal data and the free movement of such data and repealing Directive 95/46/EC.”
(**) A natural person is identifiable if their identity can be directly or indirectly determined, especially by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to their physical, physiological, genetic, psychological, economic, cultural, or social identity.
Rontsis B2B
