1. Introduction
With this policy, the company under the name “NERA KRITIS ANONYMI EMPORIKI KAI VIOMICHANIKI ETAIREIA” (hereinafter the “Company”, “we” or “us”), headquartered in Acharnes, Attica (Postal Code 13677), 1-3 Aristeidou Street, sets forth and discloses the terms under which, acting as the “Data Controller” in accordance with the Law, it collects, stores, uses, and generally processes your personal data, which it collects when you visit, register with, or use the Company’s website, as well as when you transact directly with us.
This Privacy Policy also describes how your personal data is used, disclosed, and protected, the options available to you regarding your personal data, and how you can contact us. This Privacy Policy complies with the provisions of the European Regulation 679/2016 and any other applicable national, European, and international legislation.
We would also like to assure you that the Company does not collect data relating to minors under the age of 18.
For any matter related to the processing of personal data, please contact in writing the Data Protection Department at the email: info@nerakritis.gr, to the attention of the Data Protection Officer (DPO).
2. What are Personal Data?
The term “personal data” refers to information relating to natural or legal persons, such as full name/business name, postal address, email address, telephone number, etc., which identify or can identify your identity or your business details, hereinafter referred to as “Personal Data” or “Data”.
3. What is the Processing of Personal Data?
Processing of personal data means any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment or combination, restriction, erasure, or destruction.
4. Is it mandatory to provide your Personal Data?
The provision of Data to the Company may be necessary to achieve the purposes specified in this Privacy Policy or may be optional.
If you refuse to provide the information marked as mandatory on the Websites, it will be impossible to achieve the main purpose for which the specific Data are collected, and it may, for example, make it impossible for the Company to contact you or provide other services available on its Website.
The provision of additional Data to the Company, beyond those marked as mandatory, is optional and does not entail consequences regarding the main purposes of Data collection, since their provision serves solely to optimize the quality of the services we provide.
5. What Personal Data do we collect?
We ensure that we collect only the absolutely necessary Personal Data, which are appropriate and relevant for the intended purpose. These Data include the following:
a. Data you provide when you register for our newsletter.
b. Data regarding the products and services you usually prefer, so that we can suggest products or services of interest to you and further improve your shopping experience with us. Naturally, you always have the choice not to share such information with us.
c. Website traffic information.
d. Information collected through the use of cookies in your browser. Learn more about the use of cookies here.
e. To provide the best possible website experience, we collect technical information regarding your internet connection and browser, as well as your computer’s country and telephone code, the web pages you visit, the advertisements you click, and any search terms you used.
f. Your social media username, if you interact with us through these channels, to help us respond to your comments or questions.
g. Educational information, such as studies, skills, knowledge of foreign languages, professional experience (only in cases where you respond to a job advertisement).
6. Purpose of processing and how we use your personal data
We use your data in various ways, depending on the purpose of processing.
There are cases where the Company cannot take action unless it has collected certain personal data from you, such as information required to handle requests to the Company.
Specifically:
- For Communication: The Company uses your Data to respond to requests/questions you submit and/or complaints. The information you share with us allows us to manage your requests and respond in the best possible way. We may also keep a record of your queries/requests so that we can better respond to any future communication. We do this based on our contractual obligations to you, our legal obligations, and our legitimate interests in providing you with the best possible service and improving our services based on your personal experience.
- For Sending newsletters/offers: With your consent, we will use your Personal Data, preferences, and transaction details to inform you via email, online, phone, and/or social media about relevant products and services, including personalized offers. Of course, you may withdraw this consent at any time.
- For Contact Form submissions: When you communicate through our Website contact form, you may be asked to provide personal details such as name, email address, etc.
- For Job Applications: When you send us your CV to express interest in a specific or non-specific job position, you provide us with personal information such as name, contact details, and your resume details.
- With your consent and depending on the case, the following are also possible:
Customer Satisfaction Surveys: Personal data collected through our Website may be used for your participation in Customer Satisfaction Surveys, under the specific conditions set by the applicable legal framework.
Personalized communication (“profiling”): To offer you the best possible browsing experience on our Website, the personal data we collect may be used to send personalized updates, provided you have given your consent, under the specific conditions of the applicable legislation.
7. What are the legal grounds for processing your personal data?
Your personal data that you provide with your explicit consent may be processed by us only when there is a legal basis.
The lawful bases for processing your personal data include:
- Your identification during communication with us for any reason and the overall management of our relationship, such as handling complaints, making suggestions to the Company, or where reasonably necessary for compliance with legal or regulatory obligations, dispute resolution, fraud prevention, and abuse prevention.
- The safeguarding and protection of legitimate interests, both yours and ours. For this reason, we use CCTV and security cameras in the Company’s physical stores to ensure the safety of customers and our facilities, as well as special security software to detect and prevent malicious activities. Specifically, in our online store, we collect information such as your IP address, location data, user devices, etc., to detect or prevent fraud or abuse of our website.
- Compliance with legal obligations, such as regulatory compliance for tax purposes and e-commerce legislation.
- The consent you provide to the Company, under the specific conditions set by the applicable legal framework, to subscribe to newsletters, receive updates on products, offers and/or promotional activities, participate in customer satisfaction surveys, or receive personalized updates.
8. Who are the recipients of your Data and how they are disclosed
8.1. For the fulfillment of the above-mentioned purposes of processing your personal data, the Company may disclose or transfer personal data you have provided to its subsidiaries or affiliated companies, or to third-party service providers who assist in the proper functioning of this website, such as (but not limited to) technology service providers for the protection and security of our electronic systems, advertising agencies, and companies conducting customer satisfaction surveys.
In all the above cases, the Company remains responsible for processing your personal data and defines the details of processing. It also signs a specific contract with the third parties to ensure that processing is carried out in accordance with the applicable legislation and that every natural person can freely and unhindered exercise their rights under the law.
8.2. When you use your social media information on the Website, you may create a public profile that includes information such as username, profile picture, and city. You can also share content with your friends or the public, including information about your interaction with the Company. We encourage you to use the tools we provide to manage social media sharing in order to control the information you make available via the Company’s social media.
9. Storage of your personal data
The Company undertakes to keep with absolute confidentiality the record of personal data you have provided on our Website or disclosed through physical means, solely for the processing purposes mentioned above.
The retention period of the data is decided based on the following criteria, depending on the case:
- When processing is imposed by legal provisions, your personal data will be stored for as long as required by those provisions.
- When processing is based on a contract, your personal data will be stored for as long as necessary for the performance of the contract and for the establishment, exercise, or defense of legal claims arising from it.
- For marketing/promotional activities, your personal data will be kept until you withdraw your consent. This right can be exercised at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
- We will also retain your CV for potential future use for one year from receipt, for possible future employment opportunities. If you accept a job offer at the Company, your personal data will be retained under the employee personal data processing policy, which is communicated to all employees.
- Your consent statement for newsletter subscription is retained as long as newsletters are sent by the Company and no longer than six months after termination of the newsletter service.
To withdraw your consent, please contact the Company’s Data Protection Officer (DPO) at: info@nerakritis.gr.
10. Security of Personal Data
The Company has taken care to implement appropriate technical and organizational measures to securely process your personal data and prevent accidental loss or destruction, and unauthorized and/or unlawful access, use, modification, or disclosure. However, due to the nature of the internet and its open access, it cannot be guaranteed that unauthorized third parties will never manage to bypass the applied security measures and possibly misuse personal data for unauthorized or unlawful purposes.
11. What are your rights regarding your personal data?
Every natural person whose data is processed by the Company retains the following rights:
Right of Access: You have the right to immediate access to information about your personal data, verification of the time and manner of initial storage, and information on processing methods and protection measures.
Right of Rectification: You have the right to study, correct, update, or modify your personal data.
Right of Erasure: You have the right to request the erasure of your personal data from the Company’s records at any time, provided we processed it based on your prior consent. In other cases (e.g., contractual obligations, legal obligations, public interest), this right may be subject to limitations or may not exist, depending on the case.
Right to Restriction of Processing: You may request restriction of processing in the following cases:
(a) when you contest the accuracy of your personal data until verification,
(b) when you oppose deletion and request restriction instead,
(c) when data are no longer necessary for processing purposes but are required for legal claims,
(d) when you object to processing and pending verification of overriding legitimate grounds.
Right to Object: You have the right to object at any time to the processing of your personal data, when such processing is based on our legitimate interests, as well as for purposes of direct marketing and profiling.
Right to Data Portability: You have the right to receive, free of charge, a copy of your “customer file” containing your personal data in electronic or printed form, allowing access, verification, and further use. You may also request, if technically feasible, the direct transfer of your data to another controller. This right applies to data provided by you and processed by automated means, based on your consent or in execution of a contract.
Right to Withdraw Consent: Where processing is based on your prior consent, you have the right to withdraw it freely, without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of the above rights, you may contact the Data Protection Officer (DPO) in writing at: info@nerakritis.gr.
Right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
You have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr):
Telephone: (+30) 210 6475600, Fax: (+30) 210 6475628, Email: contact@dpa.gr
12. Governing Law
Governing Law is Greek Law, as formed in accordance with the General Data Protection Regulation 2016/679/EU, and generally the applicable national and European legal and regulatory framework for the protection of personal data.
13. Information on the issuance of this Privacy Policy
The Data Controller reserves the right to unilaterally amend and update this Policy, in whole or in part, at its absolute discretion, at any time and for any reason without prior notice, except for its posting on the website.
We encourage you to periodically read this Policy to stay informed on how your Data are protected. This Privacy Policy was last modified in October 2021.
