Privacy Policy

Introduction

The protection of your privacy is of paramount importance to us. We are taking all necessary and appropriate measures to protect your personal data and to ensure compliance with our relevant legal obligations. By using this website, placing orders, purchasing in our store, contacting us, joining our mailing list, sending a message to us or arranging an appointment, we process personal data as described in this Privacy Policy. We do not collect or process personal data of minors under 16 years old.

General information and Data Controller

The undertaking under the trade name “Christakis”, having its registered seat in Athens, 5, Kriezotou Str., is the data controller regarding collection, storage and processing of personal data through this webpage as well as through the social media webpages which are linked to this webpage, always in accordance with the General Regulation (EU) 2016/679 on personal data protection as well as with Law No. 4624/2019, for the following categories of data subjects:

  1. Customers;
  2. Users of this website (https://www.christakisathens.com/);
  3. Individuals that communicate with us for the submission of complaints, queries etc;

This Privacy Policy applies to the above data subjects. The categories of personal data that we collect and process for each one of the above categories, as well as the purposes and legal bases for each processing activity are set out in detail below.

Important Definitions

  • Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
  • “Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
  • “Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data;
  • “Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
  • “Recipient” means a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.
  • “Third party” means a natural or legal person, public authority, agency or body other than the data subject, controller, processor and persons who, under the direct authority of the controller or processor, are authorised to process personal data;
  • “Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Which are the categories of personal data that we process

We collect and process the following categories of personal data:

  1. Identification data (name, surname);
  2. Contact details (phone number, email address);
  3. Additional information (such as residence address, city, postal code, and other information you provide us by filling in forms (both online and offline);
  4. Information related to appointments booked by you (interest of the appointment, preferred date and time etc.);
  5. Transaction & purchase information (such as order number, item, order details, selected payment method, bank card details);
  6. Public information of your social media account if you communicate with us through such account (e.g. Messenger account);
  7. Information related to use of our website and online services. For more information about cookies and similar technologies, please check our Cookies Policy.

For which purposes we process your personal data

We process your personal data for the following purposes:

  • Processing of your orders and management of payments

We process your identification data as well as the information related to your purchase, including your payment details, so as to process and fulfill the orders you place through the website, by telephone or in store and manage your payments;

  • Performance of your orders

We process your contact details as well as additional information related to your residence address for the purposes of performance of your orders and delivery of the products that you purchase;

  • Customer service and management of requests

If you submit a question or otherwise ask us to get into contact with you, we will use the personal data provided by you to handle your request;

  • Arrangement of appointments

We process your identification data, contract details, as well as preferred date and time and interest of the appointment so as to allow you to arrange an appointment with our sartorial experts;

  • Management of your customer account

We use your identification data, as well as your contact details and additional information that you provide us through completing the relevant forms for the purposes of creation, management and maintenance of your customer account;

  • Marketing communication

If you join our mailing list, we process your contact details (email address) in order to send you information and commercial offers concerning existing of new products and services and in order to keep you up to date on news and exclusive offers by joining our mailing list;

  • Compliance with our legal obligations

We process your orders and payments details, payment proofs and other financial documents for the purposes of compliance with our obligations deriving from tax legislation. Moreover, we may process your personal data in case that it is necessary in order to comply with requests or orders of any nature from the competent judicial or administrative authorities;

  • Prevention of fraud and ensuring of operation of our business

We may also use your personal data if necessary in the context of our legitimate interest of preventing fraud and ensuring safer e-commerce shopping experience in our website, as well as in the context of our legitimate interest to unimpeded operation of our business;

  • Management and improvement of navigation in our website

We process your personal data for the purposes of management and improvement of your navigation in our website, through the use of cookies. For more information about cookies and similar technologies, please check our Cookies Policy.

Which are the legitimate grounds of processing

We process your personal data for the above purposes exclusively when we have a legitimate ground to do so. Specifically, legitimate grounds for processing your personal data are:

  • Processing for the purposes of management of your orders and payments and performance of your orders, management of customer requests, management of your customer account and arrangement of appointments is necessary for the performance of our contract or in order to take steps at the request of the data subject prior to entering into a contract (article 6 par. 1 (b) of the GDPR);
  • Processing for the purposes of compliance with the applicable provisions of tax legislation as well as for the purposes of compliance with requests of judicial and administrative authorities is necessary for compliance with our legal obligations (article 6 par. 1 (c) of the GDPR);
  • Processing for ensuring safer experience through use of our website as well as for ensuring unimpeded operation of our business is necessary for the purposes of our legitimate interests (article 6 par. 1 (f) of the GDPR);
  • Processing of your personal data for the purposes of addressing to you management communication will take place only under the condition that you provide us with your explicit respective consent (article 6 par. 1 (a) of the GDPR). You may withdraw your consent at any time by sending an email at info[at]christakisathens[dot]com.

Recipients of your personal data

Your personal data are processed exclusively by our authorized employees for the purposes of management of your orders and management of your payments, as well as by our duly authorized subcontractors/data processors (e.g. transportation subcontractors, accounting providers, legal counsels etc.) to the extent necessary for the performance of your orders, compliance with our legal obligations and pursuit of our legitimate interests.

We may also share your personal data with competent judicial, administrative and/or other public authorities upon respective lawful request.

How long will we keep your personal data

  • When processing takes place for the purposes of performance of your order, your personal data shall be kept for as long as required for the management and performance of your contract;
  • When processing takes place for the compliance with our legal obligations, your personal data shall be kept for as long as necessary for our compliance with such legal obligations;
  • When processing takes place in the context of our legitimate interests, we will keep your personal data for as long as necessary for the purposes of fulfillment of such legitimate interests, always in accordance with the applicable law provisions;
  • When processing takes place on the basis of your consent, we will keep your personal data until withdrawal of your consent, otherwise for as long as necessary for the fulfillment of the purposes for which such data have been collected. You may withdraw your consent at any time by contacting us at info[at]christakisathens[dot]com.

Data transfers

We will not transfer your data outside the EU.

Your rights related to processing of your personal data

Right of Access:

You have the right to request access to your data which are processed by us or on our behalf as well as to request additional information about their processing.

Right to Rectification:

You have the right to correct, update or modify your personal data in case that they are incorrect or outdated.

Right to Erasure:

You have the right to request the deletion of your personal data subject to the each time applicable law provisions.

Right to Restriction of Processing:

You have the right to request the restriction of the processing of your personal data in the following cases: (a) when the accuracy of the personal data is questioned and until such data is verified, (b) when you object to the deletion of personal data and request the limitation of their use rather than their deletion, (c) when such personal data are not needed for processing purposes, they are, however, indispensable for the foundation, exercise, support of legal claims, and (d) when you oppose to the processing and until it is verified that there are legitimate grounds that concern us and supersede the reasons for which you are opposed to the processing.

Right to object:

You are entitled to object to the processing of your personal data, under the conditions specified in the each time applicable law provisions.

Right to data portability:

You have the right to receive your personal data free of charge in a format that allows you to access, use, and edit them with commonly used editing methods. Moreover, you have the right to ask us, if technically feasible, to pass the data directly to another controller. Such right exists for the data you have provided to us and their process is carried out by automated means based on your consent or performance of a relevant contract.

Right to withdraw your consent:

In the cases where processing of your personal data is based on your consent, you may at any time proceed to withdrawal of your consent.

You may exercise at any time any of your above rights related to processing of your personal data by contacting us at the following email: info[at]christakisathens[dot]com

You also have the right to submit at any time a complaint before the Personal Data Protection Authority (www.dpa.gr). Switchboard: +30 210 6475600, Fax: +30 210 6475628, e-mail address: complaints@dpa.gr.

Security of Personal Data

We implement all necessary and appropriate technical and organizational measures for the protection of your personal data from any accidental loss, destruction, deterioration or unauthorized and/or unlawful access, use, modification or disclosure.

Moreover we ensure that our employees and/or subcontractors who are authorized to process personal data for the purposes set out above, undertake in writing to comply with all necessary confidentiality and personal data protection obligations.

Connections with other sites

Our site may contain links to foreign websites. We are not responsible for the privacy practices or the content of other sites. Therefore, we suggest that you read carefully the privacy statements of these foreign sites.

Applicable Law and Jurisdiction

Courts of Athens are exclusively competent for any dispute that may arise in the context of use of the present website and Greek law shall be applicable.

Amendments

In case of amendment to the present Privacy Policy, the updated version will be uploaded at our official website (https://www.christakisathens.com/) and shall bear date of update.