PRIVACY POLICY

The company “V. Petris & S. Salakou G.P.” is the administrator of the website grapestore.gr and declares that it has fully complied with the applicable legislation on the Protection of Personal Data, governed by Regulation (EU) 2016/679 as well as by Law 4624/2019 on the Protection of Personal Data, as in force. This Privacy Policy explains what information we collect from you when you visit our website and/or use our services in general. Please read this carefully in order to learn more both about the data collected during your visit to grapestore.gr and during the provision of our offline services.

The company “V. Petris & S. Salakou G.P.” is fully committed to protecting the personal data of its website visitors and customers. It does not disclose visitor/customer information to third parties unless this is absolutely necessary for the provision of a specific service, such as for the delivery of a product, for the performance of necessary credit and security checks, and within the context of customer search and profiling procedures under the terms of this Policy, as well as with your consent or where the company is required by law to do so, such as pursuant to a prosecutor’s order, court decision, etc. Your personal data collected and processed by our company are always relevant and appropriate for the fulfilment of its obligations towards you.

When using the website, you are responsible for maintaining the confidentiality of your account details and for restricting access to your computer in order to prevent unauthorized access to your account. You agree that you accept responsibility for all activities that occur under your account or password. You must take all necessary steps to ensure that your password remains confidential and secure. In addition, if for any reason you believe that another person knows your password, or that your password is being used or is likely to be used without your consent, you must contact our Company immediately. Otherwise, you shall be responsible for any activity carried out under your username until the time the Company is notified. In any case, the burden of proof shall always lie with the member invoking any alleged lack of authentication and not with the Company.

Please ensure that the information you provide to us is correct, true, up to date, and complete, and inform us immediately of any change in the details you entered when registering. In the case of registration of a legal entity, its full corporate name as well as the name of the contact person must be stated. The company relies on the user’s statements regarding their personal data and bears no responsibility for their accuracy.

The company hereby declares that it may amend its Privacy Policy at any time if this is deemed necessary for the proper fulfilment of its legal obligations and/or is required by law. In such case, the company shall inform its visitors/users/customers through its website and shall simultaneously amend this Policy, which shall always be posted on its website.

The company reserves the right to refuse access to the website, terminate accounts, remove or edit content, at its discretion. In such case, you shall be notified so that you may retrieve your stored data within a specified time period. This notification shall be made by sending an email to the electronic address you entered during registration. If you do not exercise your right to recover your data, such data shall be securely and permanently deleted from our records.

It is noted that the username chosen by the member must not be unlawful, for example vulgar, derogatory, or otherwise inappropriate, nor must it infringe intellectual or industrial property rights or other rights of third parties. In addition, the username must not contain indications of email or internet addresses, personal contact/communication details of the user, or otherwise infringe any rights of third parties.

This privacy statement forms an integral part of the website’s terms of use, and you are bound by it both when browsing the website and whenever you access the website as a member or as a user.

DATA CONTROLLER

Our Company, “V. Petris & S. Salakou G.P.”, headquartered in Agia Paraskevi, Attica, at 442 Mesogeion Avenue, lawfully represented, is the controller of the personal information we collect from you (hereinafter, the “Company”).

WHEN WE COLLECT AND PROCESS YOUR PERSONAL DATA

The Company collects personal data:

(A) when someone visits our website and/or enters our promotional/advertising programs

(B) when the visitor/user registers/creates an account on our website

(C) when the visitor/user uses our products and/or services (online purchases and/or purchases from our physical store)

(D) when the visitor/user participates in any competitions

(E) when the visitor/user contacts our Company with questions regarding our products/services.

WHAT PERSONAL DATA WE COLLECT AND PROCESS

(A) Browsing the website as a visitor

When browsing our website, the data we collect are:

  • the IP address of the internet-enabled device that submitted the request to connect to our website,
  • the date and time of access,
  • the name and URL of the requested file,
  • the website from which access was made (referrer URL),
  • the browser you use, the operating system of your internet-enabled computer, and the name of your access provider, and
  • if you have consented to such geolocation through your browser or operating system or other settings of your terminal device, such functions are also recorded.

The purpose of all the above is to ensure comfortable use of the website. The legal basis for processing is Article 6(1)(f) GDPR, which allows us to process data where this is necessary for the purposes of our legitimate interests.

The above data are stored temporarily for the processing of your browsing session and are then automatically deleted. As soon as you stop using our website, geolocation data are deleted.

(B) Member registration / account creation on the website

When registering as a member on our website, the data we collect are:

  • Predefined data during your registration as a member, as well as in other fields on our website, such as first name, surname, address, telephone number, email address, username, and password. Of these data, any optional fields are provided by you solely at your own choice and discretion.
  • Your email address in the event that you subscribe to the list in order to receive newsletters from our company (without necessarily registering as a member at the same time).
  • You also provide personal data that are relevant and appropriate for the performance of each specific sale, such as the full delivery address, the full billing address, and details relating to payment.
  • Communication data such as IP address, which are technically necessary for your browsing on the website and/or for making purchases, and which are retained for as long as required by law.

The purpose of collecting your personal data is to provide you with personalized services and to manage your account. Upon registration as a user, you will be able at any time to view your purchase history and have your details saved for any future purchase you may wish to make.

The legal basis for processing is your consent pursuant to Article 6(1)(a) GDPR.

We will use your data for as long as you maintain your account, or for up to twelve (12) years, at which point we will request your consent again, unless we retain your data for another reason (for example, you have made purchases from our website and we retain your data for tax purposes). You have the right at any time to terminate your account, in which case your data will be deleted, unless you have made purchases through our website (in which case we will retain your data for as long as required for tax purposes) or unless there are pending matters and/or legal disputes between us arising from the sale made.

(C) Online purchases or purchases from our physical store

When making a purchase online or from our physical store, the data we collect are those deemed necessary to complete the sale of our products. We also use your personal data to inform you about the status of your order and for product returns. We will further use your data to verify your payments and to handle any complaints you may have. Your personal information is used to verify your identity and age, in order to determine whether you are entitled to make purchases online, and also to confirm your address with our third-party partners. In the event of purchasing products or services directly from our physical store, we do not record your details, except in cases where you request the issuance of an invoice. In such case, only the data necessary for the issuance of the lawful tax document are recorded.

The legal basis for processing is Article 6(1)(b) GDPR, as the collection of such information is carried out for the performance of the sales contract.

Tax data and supporting tax documents shall be retained by our company for a period of twelve (12) years, for tax audit purposes.

(D) Participation in competitions

By participating in competitions through our website, our newsletter, or via social media, you may enter competitions that we organize from time to time. For this participation, we only need your full name, your email address, and, where applicable, your telephone number, in order to contact you. If you participate through your account on social media, we also process the data of your account that are publicly available on such media.

The legal basis for processing is your consent, pursuant to Article 6(1)(a) GDPR.

The above data shall be retained for one (1) month after the end of the competition and the announcement of the winners. Your personal information shall then be deleted, unless you have chosen to subscribe to another of our services (for example, the sending of newsletters).

In the case of a tangible prize, the winner’s information is retained for two years, which is also the warranty period, in order to make possible any subsequent repair or replacement in the event of a defect.

(E) Communication with our Company

Whenever you contact us with general questions regarding our Company or our products/services, we keep the information you disclose to us in order to respond to any request you may have.

During the above communication, the data we collect are those necessary for us to be able to contact you, namely your full name, telephone number, and email address, as well as the content of the letters or emails you have sent us.

The purpose of retaining the above data is to respond to all your requests and to keep a record of our communication with you.

The legal basis for processing is Article 6(1)(f) GDPR, namely the legitimate interest of our company.

Your above information shall be deleted twelve (12) months after your last communication with us.

COMMUNICATION AND MARKETING

If you have made a purchase from our website, you may from time to time receive updates containing general information and/or advertising content (newsletters/sponsored advertisements). For the above marketing activities, the user/visitor/member agrees that the Company will process and use their personal data.

All users/members of the website may withdraw their consent to the use of their personal data and choose not to receive communications for marketing purposes (newsletters). If you wish to stop receiving marketing communications (newsletters) from us and/or selected third parties, you must inform us accordingly or untick the relevant box relating to the receipt of newsletters.

You may find on our website links to and from the websites of our partner networks, advertisers, and other third parties. These websites have their own privacy policies, and we accept no responsibility for them, nor do we guarantee the proper or lawful use of your personal data by them.

SOCIAL MEDIA

The website gives you the option to interact with social media, such as Facebook and Instagram. These may allow access to and/or connection with your social media accounts. We do not control these social media services or your profiles on them, and we cannot change your privacy settings on such services or set rules regarding the way your personal information is used on such services. These matters can only be controlled by you and the providers of the social media services. The Company is not responsible for any acts or omissions of any social media service provider or for your use of the features included on their platform.

WHO HAS ACCESS TO YOUR DATA

Access to all personal data collected by our Company is granted exclusively to the competent personnel of the Company. Your personal data will be used solely for the purpose referred to each time above, and such information will not be disclosed or sold to third parties for other unrelated purposes.

By way of exception, our Company may disclose the personal data of its visitors/users/members to third legal entities and/or natural persons in the following cases:

  • following the prior express consent of the data subject,
  • to the relevant payment service provider, and only the details necessary for processing the payments made by the user through our website or through other connected applications, for refunds, and for the management of complaints and questions related to such payments and refunds,
  • where required for the Company’s compliance with the relevant provisions of the law and to the competent authorities,
  • whenever disclosure of the visitor’s/user’s/customer’s personal data to any third natural or legal person cooperating with our Company (indicatively, accountant, lawyer, carrier, professional advisor, subcontractor, etc.) is absolutely necessary for the fulfilment of the Company’s obligations,
  • for the exercise of any lawful right of the Company in order to protect its legitimate interest (including providing information to third parties for the prevention of fraud and the reduction of credit risk).

YOUR CONSENT

By browsing the website, or registering as a member on the website, or purchasing any product from the website, or subscribing to our newsletter list, you declare that you accept and consent to this Policy and provide us with your explicit consent for the collection and processing of your personal data referred to above.

In the event of purchasing products from the website, you provide your consent:

(a) By sending a request for an order, you consent to receiving at your email address the notifications that are necessary and which constitute a prerequisite for the proper progress of your order.

(b) To our sending you newsletters regarding products and/or services made available through our website. You may withdraw this consent at any time by contacting our Company via email or by not selecting the relevant box concerning the sending of newsletters.

The Company does not store credit card data or details, which are securely handled and under the sole responsibility of the payment service provider through whose website the processing and execution of payments are carried out. The same applies to payment data used by online payment providers.

In the event, however, of disclosure by the member — made only to our competent authorized employees, who are the only persons having access to any information regarding your transactions necessary for the processing of your request — of postal savings account and/or bank account information, the member consents that the Company shall use such information for any refunds to the member, for example in the event of withdrawal. As regards refunds made to members’ credit/debit cards or to accounts held by members with online payment providers, the entities solely responsible for the related data processing are the cooperating banks (issuing and acquiring bank) or the third online payment provider.

The Company shall under no circumstances be liable for the actions concerning your personal data carried out by third-party websites from which you connected to or gained access to its website.

YOUR RIGHTS REGARDING YOUR PERSONAL DATA

Data subjects have the following rights:

Right of access: you have the right to know whether we process your image and, if so, to receive a copy of it.

Right to restriction: you have the right to ask us to restrict processing, for example not to delete data that you consider necessary for the establishment, exercise, or defense of legal claims.

Right to object: you have the right to object to the processing.

Right to erasure: you have the right to request that we delete your data.

You may exercise your rights by sending an email to [email protected], or a letter to our postal address 442 Mesogeion Avenue, 15342 Agia Paraskevi, or by submitting your request in person at the same address. We also point out that the exercise of the right to object or to erase does not imply the immediate deletion of data or modification of processing. In any case, we will respond to you in detail as soon as possible, within the deadlines set by the General Data Protection Regulation.

RIGHT TO LODGE A COMPLAINT

If you consider that the processing of data concerning you infringes Regulation (EU) 2016/679 and/or the provisions of national legislation, you have the right to lodge a complaint with a supervisory authority. The competent supervisory authority for Greece is the Hellenic Data Protection Authority, 1-3 Kifisias Avenue, 115 23, Athens, https://www.dpa.gr/, tel. 2106475600.