1. Who is responsible
The controller is [TO COMPLETE: full legal name and legal form], trading as e-dimitriou, with registered address [TO COMPLETE]. Contact us about privacy at info@e-dimitriou.gr or by post at 5th km Trikala–Pyli Road, Trikala, 42100, Greece. Please mark the subject “Privacy request”.
[TO COMPLETE: if a Data Protection Officer has actually been appointed, add their contact details; otherwise remove this instruction. Do not describe the general contact mailbox as a DPO without an appointment.]
2. Scope
This notice covers personal data relating to visitors, customers, prospective customers and people who communicate with e-dimitriou or act for a business customer. Personal data can include business contact details identifying an individual. It does not cover another website’s independent processing simply because we link to that website.
3. Information we process
- Contact information: name, email, telephone and correspondence details.
- Order information: products, quantities, billing and delivery details, order status and relevant transaction records.
- Business information: company details, VAT or invoice information and the names and contact details of representatives.
- Account information, where accounts are used: account identifier, authentication information, saved addresses and preferences.
- Payment-related information: amount, method, payment status, provider reference and information required for refunds. The extent of card-data access depends on the verified payment integration: [TO COMPLETE].
- Enquiries and support records: messages, specifications you supply, returns, complaints and relevant attachments.
- Technical information: IP address, request time, browser/device information and security or server logs, to the extent actually collected.
- Consent and preference records, and optional analytics or marketing information only for the services described in the completed Cookie Policy.
We receive information directly from you and, where relevant, from a person placing an order for you, your employer, a carrier, a payment provider or an adviser handling a transaction. Where data is obtained indirectly, the applicable transparency requirements also apply. Please do not send unrelated sensitive personal information in technical drawings or support attachments.
4. Why we process data and the legal bases
| Purpose | Legal basis and explanation |
|---|---|
| Responding to an individual’s purchase enquiry and fulfilling their order | Steps requested before a contract and performance of that contract, Article 6(1)(b) GDPR. |
| Handling business representatives and corporate orders | Legitimate interests in communicating with business customers and managing the relationship, Article 6(1)(f), after assessing the impact on the person. A company’s contract is not automatically a contract with its employee. |
| Invoices, legally required records and lawful authority requests | Compliance with relevant legal obligations, Article 6(1)(c). |
| Website security, troubleshooting and prevention of misuse | Legitimate interests in protecting systems, transactions and users, Article 6(1)(f), using proportionate measures. |
| Returns, warranty requests and disputes | Contract performance, legal duties, or legitimate interests in establishing and defending legal claims, as applicable to the activity. |
| Optional newsletter or promotional subscriptions, if operated | Consent, Article 6(1)(a), unless a separately assessed lawful electronic-marketing exception is expressly implemented and disclosed. |
| Non-essential cookies or similar tracking | Prior consent where required by electronic-communications law and the relevant GDPR basis, as detailed in the Cookie Policy. |
Contract and invoice information is not processed on the basis of a compulsory “marketing consent”. Withdrawing optional consent does not invalidate earlier lawful processing and does not require deletion of records retained on a separate lawful basis.
5. Information needed to provide a service
We identify mandatory fields when collecting information. Without necessary delivery or contact details, we may be unable to fulfil an order. Without legally required billing information, we may be unable to issue a valid invoice. Optional marketing preferences are not a condition of buying goods or requesting assistance.
6. Who receives information
Access is limited to people and organisations with a relevant purpose. Depending on the service actually used, recipients can include authorised staff; website hosting, maintenance and IT providers; email and communications providers; carriers; banks and payment providers; accounting and legal advisers; and competent authorities where disclosure is required or justified by law.
Manufacturers or suppliers may receive relevant information needed for a direct shipment, technical enquiry or warranty assessment. We should share only what is needed, rather than an entire customer record. Providers may act as processors under our instructions or as independent controllers for their own legal functions.
[TO COMPLETE: confirm the actual provider categories and significant named services, purposes and roles. Remove unused categories; identify any additional sharing, analytics, advertising, reviews or fraud services.]
7. Processing outside the EEA
[TO COMPLETE: state the actual countries and transfer arrangements, including remote support access. If there are no such transfers, make that statement only after checking providers and subprocessors.]
Where data is transferred outside the European Economic Area, a valid transfer mechanism is required where applicable, such as an adequacy decision or appropriate contractual safeguards, together with any necessary supplementary measures. You may ask us for information about relevant safeguards and how to obtain a copy, subject to proportionate redactions protecting others.
8. Retention
We do not apply a single unlimited retention period to every record. Retention depends on the purpose, legally required recordkeeping, unresolved transactions and relevant claims. When a period ends, records should be deleted or irreversibly anonymised under the applicable procedure.
| Record | Period or criterion to be completed |
|---|---|
| Enquiries that do not become orders | [TO COMPLETE: normal period after last contact, and justified exceptions]. |
| Orders, invoices and accounting records | [TO COMPLETE: applicable Greek tax/accounting period and start point, verified by the accountant; lawful extensions where relevant]. |
| Customer accounts | [TO COMPLETE: account lifetime and inactivity/deletion rule; separately retained order records]. |
| Support, returns and legal claims | [TO COMPLETE: case closure plus applicable and proportionate claim-retention period]. |
| Security/server logs and backups | [TO COMPLETE: actual log periods and backup rotation; exceptional incident preservation]. |
| Marketing and consent records | [TO COMPLETE: subscription and proof-of-consent periods; minimal suppression record to respect an opt-out]. |
| Cookies and related identifiers | The verified lifetime stated for each entry in the Cookie Policy. |
9. Your rights
Subject to the applicable conditions, you may request access to your personal data, correction, erasure, restriction of processing and portability. You may object to processing based on legitimate interests for reasons relating to your situation. You may object to direct marketing at any time. Where we rely on consent, you may withdraw it at any time.
To make a request, email info@e-dimitriou.gr. We may seek proportionate information to verify identity where there is reasonable doubt; we do not routinely require an identity document for every request. We normally respond within one month. Where the law permits an extension because of complexity or number of requests, we inform you within the initial month and explain the reason. Requests are normally free; limited exceptions are governed by law.
You may complain to the Hellenic Data Protection Authority or another competent supervisory authority. You do not have to accept our response as final before contacting an authority.
10. Automated decisions, profiling and children
[TO COMPLETE: verify whether the shop or its providers use solely automated decisions with legal or similarly significant effects, including fraud or credit decisions. If none, state that accurately. If used, describe the relevant logic, significance, effects and applicable safeguards.]
The website is intended for customers capable of entering the relevant transaction and is not designed to solicit children’s personal data for marketing. If you believe that a child’s information has been submitted inappropriately, contact us so that we can assess and address it.
11. Security and updates
We apply organisational and technical measures appropriate to the processing risks. Please protect your account credentials and contact us if you suspect misuse. No policy text can guarantee absolute security.
We update this notice when relevant processing changes. A material change of purpose or consent requirement will be addressed through the appropriate additional information or consent process, rather than by assuming that continued browsing is agreement.