Privacy Policy

  1. Introduction

The present Privacy Policy describes how the online store www.elaikos.gr collects, uses, stores and protects the personal data of its visitors and customers. We are committed to protecting your privacy and processing your data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable Greek and European legislation.

  1. What is Personal Data?

Personal data is any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one whose identity can be verified, directly or indirectly, in particular by reference to an identifier, such as a name, an identification number, location data, an online identifier or one or more factors that approximate the physical, physiological, genetic, psychological, economic, cultural or social identity of that natural person.

  1. Data We Collect

To start any transaction with our online store, it is necessary for you to disclose certain personal data, which are collected for security reasons and to complete the order. We collect the following types of personal data:

Order/Customer Data:

  • Full Name
  • Address (street, number, city, postal code)
  • Telephone number
  • Email address
  • Sign in/Account data: The time you create an account or sign in.
  • Payment Data: We do not store credit card information. Payments are processed through secure third-party payment gateways.
  • Contact Data: When you contact us via the contact form or by email, we collect your full name and email address.
  • Usage Data: Information about how you use our site (e.g. pages visited, products viewed, time spent on our site). These are collected via cookies. For more information, please see our Cookies Policy.

 

  1. Purposes of Processing and Legal Basis

We process your personal data for the following purposes and on the respective legal bases:

For Processing and Completing Orders:

  • Purpose: Manage, process and execute your orders, ship products, manage payments and refunds.
  • Legal Basis: The performance of a contract to which you are a party (completion of the purchase).

For Customer Account Management:

  • Purpose: The creation and management of your account, order history, address storage.
  • Legal Basis: Contract performance (when you create an account) and our legitimate interest in providing a personalised experience.

For Contact:

  • Purpose: Respond to your questions, comments or requests submitted through the contact form or by email.
  • Legal Basis: Our legitimate interest in communicating effectively with users and providing support, and your consent when you make the request.

For Promotional Activities (Newsletter/Coupons):

  • Purpose: Sending informative material, offers or coupons about our products and services.
  • Legal Basis: Your consent, which you can withdraw at any time.

For User Experience Improvement and Analysis:

  • Purpose: Analyzing the use of the website to improve our services, website functionality and personalize your shopping experience.
  • Legal Basis: Our legitimate interest in improving our website and services. In some cases, your consent (for analytical and marketing cookies).

For Compliance with Legal Obligations:

  • Purpose: Compliance with tax and accounting obligations, compliance with court decisions or requests from Public Authorities.
  • Legal Basis: Compliance with legal obligation.
  1. Data Recipients

The data you provide in our online store are in no case disclosed to third parties for their own purposes. However, in order to complete the purchase of the products you want and to provide our services, we may share your data with the following partners/service providers:

 

Courier/transport companies: For the delivery of the products to the address you have indicated.

Payment Providers: Banking institutions or online payment platforms (e.g., Stripe, PayPal) to process payments.

Accounting/Technical companies: To meet our accounting and tax obligations.

Web Hosting providers: For technical support and operation of the website.

Data analysis service providers (e.g. Google Analytics): To monitor traffic and improve the site.

Email marketing service providers (if used): For the newsletter, provided that you have subscribed.

Advertising service providers (e.g. Google Ads, Facebook Ads): If they are used for targeted advertising.

In all cases, we ensure that our partners adhere to the same strict data protection standards and act as processors on our behalf, bound by the necessary contractual clauses.

In addition, we may disclose your data to Public Authorities if required to do so by a Public Authority and in general to fulfil our legal obligations.

  1. Duration of data retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, in accordance with this Policy, and to comply with our legal obligations.

Order/Customer Data: They are retained for the period required by tax legislation (e.g. 10 years), as well as for the servicing of any guarantees or refunds.

Sign in/Account Data: They are kept for as long as you maintain an active account on our website.

Contact Data: They are kept for as long as necessary to process your request and for a reasonable period of time after its completion, for archiving purposes.

Newsletter Data: They are kept until you withdraw your consent.

Cookies Data: Please refer to the Cookies Policy for the lifespan of cookies.

  1. Your Rights

You have the following rights regarding your personal data, in accordance with the GDPR:

Right of Access: Request access to the personal data we retain about you.

Right of Rectification: Request the correction of inaccurate or incomplete data.

Right to deletion (“Right to Erasure”): Request the deletion of your personal data under certain conditions (e.g. when it is no longer necessary for the purposes for which it was collected).

Right of Processing Restriction: Request the restriction of the processing of your data under certain conditions (e.g. where the accuracy of the data is contested).

Right of Data Portability: Receive your data in a structured, commonly used and machine-readable format and transfer it to another controller.

Right of Rejection: Object to the processing of your data if it is based on legitimate interest or for direct marketing purposes.

Right of Withdrawal of Consent: Withdraw your consent at any time where processing is based on it.

To exercise any of the above rights, please contact us using the contact details provided below.

  1. Data Security

Your data is collected and stored in a personal data file, in accordance with the General Data Protection Regulation 2016/679/EU and in general the Greek and European legislation, in compliance with all the required and foreseen security rules of this file. We take all necessary technical and organizational security measures to protect your personal data from unauthorized access, alteration, disclosure or destruction. These include data encryption, firewalls, and strict data access policies.

  1. Right of Complaint

If you believe that the processing of your personal data violates the GDPR, you have the right to lodge a complaint with the competent supervisory authority. In Greece, this is the Authority for the Protection of Personal Data (DPA).

  1. Contact

For any questions or clarifications regarding this Privacy Policy or the processing of your personal data, you can contact us

Shopping cart0
There are no products in the cart!
Continue shopping