Privacy Policy

Introduction

The protection of your personal data is important to us!

Take some time to read this Privacy Policy and find out how the company with the name "OLGA ZANI" based at 6 Lordou Vyronos Street, Ioannina 45444, tel. +30 26510 23115, e-mail contact info @velonaki.gr (hereinafter the "Company" or "we" or "our"), acting as Processor, collects, stores, uses and generally processes your personal data when you visit, register or use the Company's websites ( hereinafter the "Websites") and its mobile applications (hereinafter the "Apps") as well as when you do business with its physical stores.

This Privacy Policy also describes how we use, share and protect your personal data, the choices you have regarding your personal data, and how you can contact us. For your questions regarding this Privacy Policy, as well as any issue related to the processing of your Data and the exercise of your rights, you can contact the Data Protection Officer (DPO) of the Company at Lordou Byronos 6, Ioannina 45444 or to the email address dpo@velonaki.gr.

1. A few words about the Company's websites

velonaki.gr is the website of the Company, where the online store for the exhibition and sale of the Company's products is located.

2. What is personal data

The term "personal data" refers to information of natural persons, such as name, postal address, e-mail address, contact telephone number, etc., which identify or can identify you, hereinafter "Personal Data or Data".

3. What is the processing of personal data

Any act or series of acts carried out with or without the use of automated means, on personal data or sets of personal data, such as collection, registration, organization, structuring, storage, adaptation or alteration, retrieval , information retrieval, use, disclosure by transmission, dissemination or any other form of disposal, association or combination, restriction, deletion or destruction.

4. It is mandatory to provide your data

Providing the Data to the Company may be necessary to achieve the purposes specified in this Privacy Policy or may be optional.

The mandatory or optional nature of the provision of Data is indicated by an asterisk (*) next to mandatory personal data.

If you refuse to provide the information marked as mandatory on the Websites, it will be impossible to achieve the main purpose of collecting the specific Data, and it may, for example, make it impossible for the Company to fulfill the sales contract or provide the other services available on the Websites.

The provision of additional Data to the Company, beyond those marked as mandatory, is optional and does not have consequences regarding the main purposes of data collection, but its provision serves to optimize the quality of the services provided.

5. What data we collect about you

We take care to collect only your absolutely necessary Data, which is appropriate and clear for the intended purpose. This Data includes the following:

Data when creating a user account on the Websites or Apps
• Υποχρεωτικά: ηλεκτρονική διεύθυνση (e-mail)*, κωδικό πρόσβασης (login password)*
• Προαιρετικά: όνομα, επίθετο, φύλλο, ημερομηνία γέννησης, ταχυδρομική διεύθυνση, αριθμό τηλεφώνου.

Data from your transactions with us, either through our physical stores or through our online store
• For example, we collect notes from our conversations with you, details of any complaints or comments you make, details of purchases you made, products added to or removed from your basket, wish list ), coupon redemptions, websites you visit and how and when you contact us.

Interests and shopping preferences, which help us recommend specific products and services that interest you
• For example, which products you show us a preference in order to receive a personalized offer from us

We will only request and use the Data we have collected to recommend products or services of interest to you and further enhance your shopping experience with us. Of course, it is always your choice whether to share such information with us.

Traffic data of our website or other websites that you have visited before us

Information collected from the use of cookies in your browser. Learn more about how we use cookies.

Copies of documents you provide to prove your age or identity where required by law (such as a copy of a police or student ID).
• For example these copies may include details of your full name, address, date of birth and your face image (photograph). If you provide a passport, the data will also include your place of birth, gender and nationality.

Payment information.

Feedback and product reviews.

Your image may be recorded on CCTV when you visit one of our physical stores

In order to provide the best possible website experience, we collect technical information about your internet connection and browser, as well as the country and telephone code where your computer is located, the web pages displayed when you visit, the advertisements in which you click and whatever search terms you entered.

Your social media username, if you interact with us through these channels, to help us respond to your comments, questions or feedback.

Educational information, such as studies, skills, knowledge of foreign languages, professional experience (only in cases where you apply for a job)

6. How we use your data

We want to give you the best possible shopping experience. To achieve this it is necessary to obtain a complete picture of you by combining the Data we have collected. We then use your Data to offer you offers for products and services that are likely to be of interest to you.

The legislation for the protection of personal data allows us to do the above in the context of our legitimate interest and the need to understand our customers in order to provide them with a high level of service.

Of course, if you ever want to change how we use your Data, you will find details in sections 14 & 15 'What your rights are' and 'How you can exercise your rights' below.

Θυμηθείτε, αν επιλέξετε να μην μοιραστείτε τα Δεδομένα μαζί μας ή να αρνηθείτε ορισμένα δικαιώματα επικοινωνίας, ίσως να μην μπορέσουμε να παρέχουμε κάποιες υπηρεσίες που έχετε ζητήσει. Για παράδειγμα, αν μας ζητήσατε να σας ενημερώσουμε πότε ένα προϊόν είναι και πάλι διαθέσιμο, δεν μπορούμε να σας εξυπηρετήσουμε, εάν έχετε αποσύρει τη γενική συγκατάθεσή σας για να λαμβάνετε ενημερώσεις από εμάς.

Finally, we inform you that the processing of your Data is carried out either by the specially authorized personnel of the Company, or through IT systems and electronic devices by the Company and exceptionally by third parties, who, having contractually committed to the observance of confidentiality and the protection of With your data they carry out tasks necessary to achieve the purposes strictly related to the use of our Websites, its services and the sale of products through our Websites. Information on this can be found below in section 9 “Who are the recipients of your Data? How your Data is shared".

Below you will find details of how we use your Data and why:

To provide information about the Websites, Apps and services you request

Product orders
The Company processes your Data in order to fulfill its contractual relationship, to process the order of products and/or services, to issue and send you your tax documents electronically (e-invoicing) to the electronic address (e-mail) that you you have declared yourself during your registration in its online store, to provide customer service services, to comply with legal obligations, to refute, raise or exercise legal claims. If we do not collect your Data at checkout from either our physical stores or our online store, we will not be able to process your order and comply with our legal obligations. It may be necessary to transfer your Data to third parties for the supply or delivery of the product or service you have ordered, as well as the implementation of the electronic invoicing process by our Company, in accordance with the provisions of the applicable legislation. In addition, we may retain your Data for a reasonable period of time in order to fulfill our contractual obligations, such as product returns, as required by relevant law.

Create a User Account
The Company processes your Data in order to provide you with account functions and to facilitate the purchase of products and/or services.

Contact
The Company uses your Data to respond to your requests/queries, refund requests and/or complaints. The information you share with us enables us to manage your requests and respond to you in the best possible way. We may also keep a record of your queries/requests to us to better respond to any future communications. We do this based on our contractual obligations to you, our legal obligations and our legitimate interests to provide you with the best possible service and to be able to improve our services based on your own personal experience.
Μερικές φορές, θα χρειαστεί να μοιραστούμε τα Δεδομένα σας με έναν τρίτο που παρέχει μια υπηρεσία (όπως courier delivery ή έναν τεχνικό που επισκέπτεται το σπίτι σας). Χωρίς να μοιράζεστε τα προσωπικά σας δεδομένα, δεν θα είχαμε τη δυνατότητα να ικανοποιήσουμε το αίτημά σας. Ακολουθούν περισσότερες πληροφορίες σχετικά με τον τρόπο με τον οποίο μοιράζουμε προσωπικά δεδομένα με τρίτους.

Finding a job
The Company processes your Data for the evaluation of your qualifications and abilities for the position for which you submitted the application or for another position within the Company as well as for the purposes of communicating with you in relation to this purpose.

To share information about our products, services and events, and for other promotional purposes

Sending newsletter/offers
With your consent, we will use your personal data, preferences and transaction details to inform you via e-mail, internet, telephone and/or social media about relevant products and services, including personalized/personalised offers , discounts, etc. Of course you have the possibility to withdraw this consent at any time.

Web push notifications
Depending on your navigation, you may receive, having previously given your consent, notifications about our offers, news, your wish list and your shopping cart. Of course you have the possibility to withdraw this consent at any time.

Participation in contests
The Company processes your Data, in case you agree to participate in contests it conducts, to notify you if you are a winner of the contest and to deliver your prize.

To operate, improve and maintain our business, products and services

• Development and improvement of systems and services for the products we provide you. We do this based on our legitimate business interests.
• We want to offer you offers and suggestions that are more relevant to your interests. To help us form a better and more general understanding of you as a customer, we combine your personal data collected throughout the relationship between us, for example your purchase history in both our physical stores and our online store. For this purpose, we also combine the Data we collect directly from you with Data we receive from third parties to whom you have given your consent to transfer this data to us. For example, by combining this data, this will help us customize your experience and decide what inspiration or content to share with you. We also use anonymized data from customer purchase history to identify trends in different regions of the country. This can then guide which products we display in specific stores.
• To show you the most interesting content on our Websites or Apps, we will use the Data we hold about your favorite products. This is based on your consent to receive Apps notifications or – for our Sites – your consent to placing cookies on your device. For example, we may display a list of products you have recently viewed or offer you recommendations based on your purchase history and any other Data you have shared with us.
• To send you survey and evaluation requests so that we can improve our services. These messages will not contain advertising content and do not require prior consent when sent by email or text message (SMS). We have a legitimate interest in doing so as it helps our products or services to be more relevant to you. Of course, you are free to opt out of receiving these requests from us at any time by updating your preferences in your online account.

To protect our or third parties' rights, property or safety

• Protecting your account from fraud and other illegal activities: This includes using your Data to maintain, update and protect your account. We also monitor browsing activity with us to quickly identify and resolve any issues and protect the integrity of our website. All of the above are part of our legitimate interest. For example, we check your password when you log in and use automated IP address tracking to detect potential fraudulent logins from unexpected locations.
• Operation of CCTV Systems: In order to protect our customers, premises, assets and associates from crime, we operate CCTV systems in our stores that record images for security. We do this based on our legitimate business interests. If we detect any criminal activity or alleged criminal activity through the use of CCTV, fraud monitoring and suspicious transaction monitoring, we will process this Data for the purposes of preventing or detecting illegal activity. Our goal is to protect our customers, employees and partners from criminal activities.
• Processing payments and preventing fraudulent transactions: We do this based on our legitimate business interests. This also helps protect our customers from fraud.

For our compliance with our obligations arising from the law

• To comply with our contractual or legal obligations to share data with law enforcement. For example, following a court order to share data with judicial services.
• To send you communications that are required by law or that are necessary to notify you of changes to the services we provide to you. For example, updates on these privacy notices, product recall notices, and legally required information about your orders. These service messages will not contain advertising content and do not require prior consent when sent by email or text message (SMS). If we do not use your personal data for these purposes, we cannot comply with our legal obligations.

7. For what purpose we process your data

We collect your Data for the purposes of the products and/or services provided by our Company and in particular for:
• managing the sale of the products/or services us, e.g. communicating and informing you about the availability of products and the progress of your order, the issuance and sending of your tax documents in electronic format (e-invoicing), the execution of your order, the shipment of products, the management of your debts to the COMPANY, the making of returns and the provision of guarantees.
• your service based on the currently applicable government measures (e.g. click inside, click away ),
• compliance with the obligations imposed by the current legislation, e.g. tax legislation, e-commerce directive,
• control, improve and adapt to your preferences and choices regarding our products and/or services,
• sending, by electronic or traditional means, administrative, technological, organizational and/or commercial information about the Company's products and/or services.
• our customer satisfaction survey, the promotion of our products/or services, the sending of newsletters about our products and/or services.
• the evaluation of applications and resumes for the purpose of recruitment to our Company.

8. What is the legal basis for processing your data by the Company?

• Data protection legislation sets out various reasons why a company may collect and process your personal data, including: the terms of our contractual relationship
• your consent, where required. For example when you choose to receive newsletters. When collecting your personal data, we will always inform you which data is necessary in relation to a specific service.
• the Company's obligations arising from law (eg tax legislation, e-commerce legislation, etc.)
• the legitimate interest of our Company. In certain cases, we collect your Data in a way that can reasonably be expected as part of the operation of our business and that does not materially affect your rights, freedom or interests. For example, we will use your purchase history to send you or make available personalized offers. We will also combine the purchase history of many customers to identify trends and ensure we can keep up with market demand or develop new products/services.

9. Who are the recipients of your data – How is your data shared?

Access to your Data is given to the absolutely necessary personnel of the Company, who are bound by confidentiality, and the companies cooperating with us or third-party service providers, who process your Data as Processors on our behalf and in accordance with our orders.

Disclosure of Data by the Company

The Company shares your Data with:

• Companies of the Company's group for the purposes and in the context of the conditions mentioned above in section 7 of this Privacy Policy
• Stores and/or commercial businesses that cooperate with the Company for the sale of their products/services
• Third party service providers who process personal data on behalf of the Company, for example (indicatively mentioned) for credit card and payment processing, electronic issuance and sending of your tax documents (e-invoicing), transfers and deliveries, hosting, management and maintenance of our data, distribution of emails, research and analysis, management of brand and product promotions, Google, Facebook, and management of certain services and elements. When we use third party service providers we enter into agreements obliging them to implement appropriate technical and organizational measures to protect your personal data.
• Other third parties, to the extent required for the following purposes: (i) compliance with a government request, court order or applicable law, (ii) preventing illegal uses of our Websites and Apps or violations of the Websites and Apps Terms of Use us and our policies, (iii) our own protection against third-party claims, and (iv) helping to prevent or investigate cases of fraud (e.g. counterfeiting)
• To other third parties when you yourself have given your consent

Notification by you

• When you use certain social media features on our Sites or Apps, you may create a public profile that includes information such as your username, profile picture, and city. You may also share content with your friends or the general public, including information about your interaction with the Company. We encourage you to use the tools we provide to manage Company social media sharing to control the information you make available through Company social media assets.

Here is the policy we apply to those with whom we share your Data in accordance with the above
• We only provide the information needed to perform their specific services .
• They can only use your Data for the exact purposes we specify in our contract with them.
• We work closely with them to ensure that your privacy is respected and protected at all times.
• If we stop using their services, any of the data you hold will be deleted or anonymized.

To improve your customer experience on our Sites and Apps, we use the following companies, who will process your Personal Data as part of their contracts with us:
Courier Partner
mailchimp
Google
Twitter
Instagram
Facebook
YouTube

For more information about sharing your Data with third parties, please contact our Company's Data Protection Officer.

10. How do we ensure that processors respect your data?

The Processors on our behalf have agreed and contractually committed to the Company:

• to observe confidentiality,
• not to send your Data to third parties without the permission of the Company,
• take appropriate security measures,
• comply with the legal framework for the protection of personal data and in particular Regulation 979/2016 /EU (aka GDPR).

11. International Data Transfer

The personal data we collect (or process) in the context of our Websites will be stored in Greece. However, some of the Data recipients with whom the Company shares your Personal Data may be located in countries other than the one in which your Personal Data was originally collected. The legislation in those countries may not provide the same level of data protection compared to the country that originally provided your Personal Data. However, when we transfer your Personal Data to recipients in other countries, including the US, we are committed to protecting your Personal Data as described in this Privacy Policy and in accordance with applicable law.

We take measures to comply with applicable legal requirements for the transfer of personal data to recipients in countries outside the European Economic Area or Switzerland that do not ensure an adequate level of protection. We use various measures to ensure that your Personal Data transferred to these countries is adequately protected under data protection rules. These include signing the Contractual Clauses, certifying that the recipient has adopted the European binding rules or adheres to the EU-US and Switzerland-US Privacy Shield.

12. How long do we keep your data?

We retain your Personal Data for as long as necessary to fulfill the purposes set out in this Privacy Policy (unless a longer retention period is required by applicable law). Generally this means that we will keep your personal data for as long as you have an account with our Company. In relation to your Personal Data related to product purchases, we retain this data for a longer period in order to comply with our legal obligations (such as tax and commercial law and for warranty purposes). At the end of this retention period, your data will be completely deleted or anonymized, for example by aggregating with other data, so that it can be used in a non-identifiable way for statistical analysis and business planning.

Some examples of customer data retention periods:

Orders
When you place an order, we will keep the personal data you have given us for five years so that we can comply with our legal and contractual obligations. In the case of some products, such as electrical goods, we will keep the data for 10 years.

Guarantees
If your order included a warranty, the relevant personal data will be retained until the end of the warranty period.

Newsletter
Your declaration of consent for the sending of a newsletter is kept for as long as the newsletter is sent to you by the Company and in any case no longer than six months from the cessation of its sending.

13. Is your data safe?

We are committed to safeguarding your Personal Data. Recognizing the importance of the security of your Personal Data, we have taken all appropriate organizational and technical measures to secure and protect your Data from any form of accidental or unlawful processing. We use the most modern and advanced methods, in order to ensure the maximum possible security.
The isotope velonaki.gr uses the SSL/TLS protocol, for secure online commercial transactions. This encrypts all the Data you provide, including your credit card number, name and address, so that it cannot be decrypted or changed in transit over the Internet.
In addition, the data used to identify you as an account user are two: the Login Code (Username) and the Personal Secret Security Code (Password). Each time you register your details, you are given access to your personal account. The specific process is achieved safely through encryption during their transfer to the internet and the servers of the Company. By the same standards, you are given the possibility to change your Personal Secret Security Code (Password) as often as you wish. After entering the desired code, the new code is coded and stored in the Company's systems. For this reason, you are the only one who knows your password and you are solely responsible for keeping the password confidential from third parties.

These measures are reviewed and amended when deemed necessary.

14. What are your rights

• You have the right to access your personal data. This means that you have the right to be informed by us if we are processing your Data. If we process your Data, you can ask to be informed about the purpose of the processing, the type of your Data we keep, to whom we give it, how long we store it, whether automated decision-making takes place, but also about your other rights, such as correction, deletion of data, restriction of processing and filing a complaint with the Personal Data Protection Authority.

• You have the right to correct inaccurate personal data. If you find that there is an error in your Data you can submit a request to us to correct it (eg correct a name or update a change of address).

• You have a right to erasure/right to be forgotten. You can ask us to delete your data if it is no longer necessary for the aforementioned processing purposes or you wish to withdraw your consent in the event that this is the only legal basis.

• You have the right to portability of your Data. You can ask us to receive the Data you have provided in readable form or ask us to pass it on to another controller.

• You have the right to restrict processing. You can ask us to restrict the processing of your Data pending the consideration of your objections to the processing.

• You have the right to object and withdraw consent to the processing of your Data. You can object to the processing of your Data and we will stop processing your Data unless there are other compelling and legitimate reasons that override your right. If you have given your consent to the collection, processing and use of your personal data, you can withdraw your consent at any time with future effect.

• Opting out of receiving Marketing Communications. You can choose not to receive marketing communications from the Company by modifying your options in the user account (my profile) of our Sites. You can also choose not to receive marketing communications by changing your email and sms registrations, clicking the delete link or following the instructions included in the message. Alternatively you can contact us using the contact details in the 'Questions and Comments' section below.

• In case we rely on our legitimate interest. In cases where we process your personal data based on our legitimate interest, you can ask us to stop for reasons related to your personal situation. We must then do so unless we believe we have a compelling legitimate reason to continue processing your Personal Data.

15. How you can exercise your rights

In order to exercise your rights, you can submit a request to the Data Protection Officer at the Company's postal address or at its email address (dpo@velonaki.gr) with the title "Exercise of Right" and we will make sure that review and reply to you as soon as possible.

Exceptionally:
• if you wish to correct your Data in your user account, you can log in to it and make any correction/change without the submission of a Request is required.
• if you wish to withdraw your consent to send a newsletter, you can do so by selecting the link "To delete from the "newsletter mailing list" click here" located at the bottom of each newsletter.
• if you wish not to receive web push notifications from the Company you can disable the option from your browser setting.

Identity Verification
To protect the confidentiality of your information, we will ask you to verify your identity before proceeding with any request you make under this Privacy Policy. If you have authorized a third party to make a request on your behalf, we will ask them to demonstrate that they have your permission to act for this purpose.

16. When we respond to your requests

We respond to your Requests free of charge without delay, and in any case within (1) one month of receiving your request. However, if your Request is complex or there are a large number of your Requests we will inform you within the month if we need to obtain an extension of another (2) two months within which we will respond to you.

If your Requests are manifestly unfounded or excessive in particular due to their repetitive nature, the Company may impose a reasonable fee, taking into account the administrative costs of providing the information or carrying out the requested action, or refuse to proceed with the Request .

17. What is the applicable law when we process your data

Applicable Law is Greek Law, as formulated in accordance with the General Regulation for the Protection of Personal Data 2016/679/EU, and in general the applicable national and European legislative and regulatory framework for the protection of personal data.
Competent courts for any arising disputes related to your Data are the Courts of Ioannina.

18. Where you can appeal if we breach the applicable law for the protection of your personal data

You have the right to submit a complaint to the Personal Data Protection Authority (postal address Kifisias 1-3, P.K. 115 23, Athens, tel. 210. 6475600, e-mail address (e-mail) contact@dpa.gr ), if you consider that the processing of your Personal Data violates the applicable national and regulatory legal framework for the protection of personal data.

19. How will you be informed of any changes to this policy?

We update this Privacy Policy whenever necessary. If there are significant changes to the Privacy Policy or the way we use your Personal Data, we will post an update to this on our website before the changes take effect and we will notify you as soon as possible.

We encourage you to read this Policy periodically to know how your Data is protected. This privacy policy was last modified on July 13, 2022.