PRIVACY POLICY & PROTECTION OF PERSONAL DATA
Data Controller
Our Company, APOSTOLIDIS S.A., www.acalight.gr, hereinafter referred to as “Company”, “we”, or “us”, situated in Industrial Area of Serres and specializing in the processing and trading of lighting and electrical equipment, in compliance with the EU General Data Protection Regulation 679/2016, Chapter III, Article 13, wishes to inform you of the nature and use of the personal data we collect from you during your visit on our premises or in our website
Principles relating to processing of personal data
a) processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’),
b) collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; (‘purpose limitation’),
c) adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimisation’),
d) accurate and, where necessary, kept up to date (‘accuracy’),
e) kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’),
f) processed in a manner that ensures appropriate security of the personal data (‘integrity and confidentiality’).
Peprsonal data processed
The term “Personal data” refers to all information pertaining to any individual directly or indirectly identifiable. Such information includes:
- Identity data: first name, surname, VAT number.
- Contact details: residential address, personal email, phone number.
- Personal means of payment: IBAN.
- Order details: product code, shipping address, quantity and price.
- Employment applications: full name, personal email, phone number, education and work history details featured in the curriculum vitae.
Personal data collection
In addition to our personal contact with clients, suppliers and partners, we collect data via email or by other means of correspondence such as fax and phone orders.
Also, by accepting “cookies”, you provide us with technical information such as your browser version, computer model, operating system, internet service provider, etc. Moreover, while navigating online, you provide us with various information regarding your preferences or prior visits to our website. Website visitors could modify browser settings so that they receive warnings about the kind of “cookies” used as well as the option to block them.
When you apply for a position with us in our website or by email, your CV remains in our database for one year, and revisited periodically throughout this time for subsequent job openings.
Furthermore, we have installed cameras outside our facilities and inside our warehouse to protect our staff and property from any intrusion. These cameras observe our grounds only. CCTV warning signs are visible to all employees and guests. Surveillance footage remains stored for up to 15 days, unless earlier obtained by us or any Authority for investigation purposes.
Why maintain and process personal data?
The Company and / or third parties acting on our behalf do so for the sole purpose of trading electrical and lighting products.
With your permission only, we will use your personal data to provide you with carefully planned offers for upcoming events and promotions that may appeal to you.
The personal data you enter in our email address facilitate our communication and our response to your message. We hereby guarantee that this information shall not be used for any purposes other than the ones outlined in this Policy without your prior notice or approval.
How long do we keep your personal data for?
Your personal data are physically stored in a secured space with controlled access for as long as it is necessary in order to serve the purposes for which we collect them and for the duration of our cooperation, unless legal issues demand that we maintain the data for a specific period before destroying them or if the Company retains the data for its own rights of advocacy in judicial or regulatory matters.
Hellenic Data Protection Authority (HDPA)
If you realize or suspect that your personal data protection is compromised in any way, you must contact the Hellenic Data Protection Authority at:
Hellenic Data Protection Authority
Kifissias 1-3, 11523 Athens
Telephone: +30 (210) 6475600
Fax: +30 (210) 6475628
Email: contact@dpa.gr
Personal Data Controller
To exercise your individual rights and to request information relevant to personal data protection, you may contact us at:
Industrial Area of Serres
Serres
Greece
Τ. +30 2321077020
E. info@acalight.gr
Legal grounds for personal rights processing
In processing your personal data, we are constrained by the following legal restrictions:
■ Contractual
Your personal data are processed per your request within the scope of our contract.
■ Consensual
Processing of your personal data requires your willing, explicit and written consent and only to the extent necessary in the context and the timeframe of the occasion.
■ Legal
Our duty is to comply with ours and other editors’ legal obligations and interests, unless there exist preceding interests and fundamental rights and freedoms that impose the protection of your personal rights.
Personal data recipients
The Company ensures lawful and appropriate use of personal data and prevents any unauthorized access. In the course of providing the requested service and always within the limits set forth by law, we share your personal data with:
a) Our personnel, who are bound by strict confidentiality agreements.
b) Vendors contracted to manage, maintain, and upgrade our information and CCTV systems for safer and more effective operations, who are contractually committed for the safekeeping and the confidentiality of the data.
c) Public authorities, in situations prescribed by law, court rulings, and dictates for compliance.
d) Financial institutions or other payment facilitators, in cases you are using them to make payments to us. We may also exchange information with financial intermediaries in case we deem it necessary to prevent fraud.
e) Business affiliates who have been assigned the safe and legal transportation of the products to our customers and who are contractually obligated to keep your personal data safe and secret.
Your legal rights
If not prevented by preceding legal or regulatory mandates or issued court rulings, we are obligated to submit to you, and you are entitled to:
- Acquire a copy of your data which we have collected and processed.
- Demand the amendment of any incorrect data.
- Deny the processing of your data or restrict their use.
- Demand deletion of the data.
- Rescind your consent for processing.
- Require that we transfer or transmit the data to a third party of your choice.
Ownership – Intellectual & Industrial Property Rights
Our website’s contents, featuring trademarks, pictures, graphics, photographs, text, etc., constitute property on which we have full and exclusive ownership, except for those that belong to third parties, and are protected by national, European, and international laws. Their appearance on our web page does not constitute allowance to use and does not relinquish our rights in any way. The publication, reproduction, transfer, transmittance, distribution, presentation, and any other misappropriation of the contents of this site as well as the use of any service or part of our services anywhere and anyway for commercial exploitation or other purposes without our expressed consent is strictly forbidden.
Transfer to third countries
In the event of your personal data transference to a third country, the Company has taken all appropriate measures of protection and has ensured that your data is being transferred to countries that offer adequate protection by EU standards.