Statement by the Data Controller: “Regarding the Protection of Personal Data”
Increasing economic and scientific cooperation, as well as mutual reliance on data processing services, result in the exchange of personal data—a trend that is reinforced by the ever-increasing use of modern telecommunications.
For these reasons, it is essential that data processing be carried out with care.
The Data Controller declares that compliance with the principles governing data protection in the processing of such data is its objective, as it is committed to respecting the individual rights and privacy of individuals. The Data Controller handles personal data with special care and always in accordance with EU Regulation 2016/679, the applicable National Law, and current legislation.
For the purposes of this Policy, the following definitions shall apply:
Data Subject: any natural person whose personal data is processed by or on behalf of the Company
Personal Data: any information relating to an identified or identifiable natural person that pertains to their physical, physiological, psychological, emotional, or financial condition, or their cultural or social identity.
Processing: the processing of personal data (“processing”), any operation or set of operations performed on personal data, such as, for example, collection, recording, storage, modification, analysis, use, combination, blocking, erasure, or destruction.
1. Data Controller and Data Protection Officer
The Data Controller is the company named SOFIA BOUTSINI SINGLE-MEMBER IKE – trading as RELAX PALACE – with its registered office in Halandri, 36 Isminis Street, Tax ID No. 081982444, Halandri Tax Office, with email address info@relaxpalace.gr. (“Data Controller”).
2. The Data We Process
With your consent, we process the following general and sensitive personal data that you provide when you interact with the Website or the services and features it offers. This data includes, in particular, your first and last name, contact information, address, and the content of your specific requests, updates, or reports, as well as any additional data that the Data Controller may obtain, including from third parties, in the course of conducting its business activities (“Data”).
In order for us to fulfill the requests you submit via the contact form and/or provide updates regarding adverse events, it is necessary for you to consent to the processing of the data marked with an asterisk (*).
Without this mandatory data or your consent, we cannot proceed further. Conversely, the information requested in fields not marked with an asterisk and your consent to receive informational material are optional, and failure to provide them has no consequences.
In any case, even without your prior consent, the Data Controller may process your data to comply with legal obligations arising from laws, regulations, and EU law, to exercise rights in legal proceedings, to pursue its own legitimate interests, and in all cases provided for by law.
In any case, even without your prior consent, the Data Controller may process your data to comply with legal obligations arising from laws, regulations, and EU law, to exercise rights in legal proceedings, to pursue its own legitimate interests, and in all cases provided for, as applicable, in Articles 6 and 9 of the GDPR.
Processing is carried out both electronically and in paper form and always involves the implementation of the security measures required by applicable law.
3. Why and how we process your data
The data is processed for the following purposes:
(i) to process the requests you submit via the “Form,” to subsequently contact you, or to provide information through it. The legal basis for processing personal data for this purpose is your consent (Article 6(1)(a) and Article 9(2)(a) of the GDPR) and the performance of the contract to which you are a party as a data subject;
(ii) to manage adverse event reports submitted via the Website or the Forms. The legal basis for processing for these purposes is your consent (Article 6(1)(a) and Article 9(2)(a) of the GDPR), as well as the pursuit of any public interest (Article 9(2)(i) of the GDPR) and legal obligations;
in addition, but only with your voluntary consent, which constitutes the legal basis for processing in accordance with Article 6(1)(a) of the GDPR:
(iii) to receive promotional material (direct marketing) from us.
By selecting the appropriate checkboxes, you consent to the processing of your data for these purposes.
Your data may in any case be processed, even without your consent, for the purpose of complying with laws, regulations, EU law (Article 6(1)(c) of the GDPR), to collect statistics regarding the use of the https://relaxpalace.gr/ website and its proper functioning (Article 6(1)(f) of the GDPR).
Personal data is entered into the Data Controller’s IT system in full compliance with data protection legislation, including security and confidentiality protocols, and is based on principles of best practice, legality, and transparency regarding processing.
Data is stored for as long as is strictly necessary to achieve the purposes for which it was collected. In any case, the criterion used to determine this period is based on compliance with the time limits set by law and on the principles of data minimization, storage limitation, and rational file management.
All your data will be processed using manual or automated means, ensuring an appropriate level of security and confidentiality in all cases.
4. Principles applied during processing
We are permitted to process your personal data in order to provide personalized services, in accordance with the law (Article 6(1)(b) of Regulation (EU) 2016/679) and the relevant national implementing legislation. Your personal data is not used for any purposes other than those described in this Statement, unless we obtain your prior consent, or unless such use is required or permitted by law.
Personal data is processed in a manner consistent with the purpose for which it was collected.
The principle of proportionality applies to the processing of personal data. Among other things, it creates an obligation not to collect personal data without a valid reason.
The personal data used should be accurate and up to date.
Personal data used that is no longer accurate or complete should be corrected or deleted.
Except in cases where there is a legal obligation to retain them for a longer period, personal data are not stored for longer than is necessary for the purposes for which they were collected or processed.
The processing of personal data is carried out in accordance with the principles of good faith. This means that data subjects can rely on the fact that those carrying out the processing will exercise due care in all matters relating to data processing.
Data subjects whose personal data has been processed will be informed accordingly, upon request. Specifically, they have the right to be informed of the purposes for which their data is being processed, the type of data involved, and the identity of the recipients of the data. Where necessary, data subjects also have the right to request the correction, non-disclosure, or deletion of their data.
The above rights may be restricted only if such restriction is provided for by law. This applies, in particular, in the context of scientific research.
In particular, personal data is protected against unauthorized disclosure and any unlawful processing. The measures implemented ensure a level of security appropriate to the nature of the data to be protected and the risks that may arise from their processing.
The data controller is responsible for compliance with and implementation of EU Regulation 2016/679 and the National Implementing Law.
Our employees involved in the processing of personal data are appropriately informed and trained. The procedures for the processing of third-party personal data pursuant to an agreement will be set forth in writing, ensuring that the contracting third party processes personal data securely and complies with the principles set forth in this Statement and the EU GDPR. In the event that the third party is deemed unable to ensure a satisfactory level of personal data security, we will terminate the cooperation.
5. Individuals with access to the data
The Data is processed by electronic and manual means in accordance with the procedures and practices related to the aforementioned purposes and is accessible to the Data Controller’s staff who are authorized to process the Personal Data and supervisors, and in particular employees belonging to the following categories: technical staff, Information and Network Security staff, and administrative staff, as well as other staff members who need to process the data to perform their duties.
The Data may also be disclosed to countries outside the European Union (“Third Countries”): i) to institutions, authorities, and public bodies for institutional purposes; ii) to professionals, independent consultants—whether working individually or collectively—and other third parties and providers who supply the Data Controller with commercial, professional, or technical services necessary for the operation of the Website (e.g., provision of IT and cloud computing services) for the purposes mentioned above and to support the Data Controller in providing the services you have requested; iii) to third parties in the event of mergers, acquisitions, transfers of businesses or branches, audits, or other extraordinary transactions;
The recipients listed above receive only the data necessary for their respective functions and process such data solely for the purposes stated above and in accordance with data protection laws. The Data may also be disclosed to other legitimate recipients as specified from time to time by applicable laws.
Except as noted above, the Data will not be disclosed to third parties, whether natural or legal persons, who do not perform commercial, professional, or technical duties for the Data Controller, and will not be disseminated. The individuals who receive the data will process it, as applicable, as Data Controllers, Processors, or persons authorized to process personal data for the purposes mentioned above and in accordance with applicable data protection laws.
With regard to the transfer of data outside the EU, even to countries whose laws do not guarantee the same level of protection of personal data privacy as that provided by EU law, the Data Controller hereby informs you that the transfer will in any case be carried out in accordance with the methods permitted by the GDPR, such as, for example, based on the user’s consent, based on the standard contractual clauses approved by the European Commission, by selecting parties that participate in international programs for the free flow of data (e.g., EU-US Privacy Shield) or that are implemented in countries deemed safe by the European Commission.
6. Your rights
If you wish, you may at any time request to exercise your rights under Articles 15–22 of the GDPR, to obtain information regarding your personal data held by us, the recipients of such data, the purpose of their storage and processing, as well as to have them modified, corrected, or deleted, by sending an email to the addresses listed above, from the email address you have provided, by completing the relevant request form that may be provided to you by the Data Controller, along with an attached copy of your police ID. You also have the right to review the personal data we hold and, in general, to exercise any right provided for by data protection legislation.
The personal data you provide to the Data Controller through our Website, either during registration or at a later stage, is collected, used, and processed in accordance with the applicable provisions on the protection of personal data under the new European General Data Protection Regulation (EU) 2016/679.
You have the following rights in detail:
- Right to access your personal data: Upon your request, we will provide you with information regarding the personal data we hold about you.
- Right to correct and complete your personal data: If you notify us, we will correct any inaccurate personal data concerning you. We will complete incomplete data if you notify us, provided that such data is necessary for the purposes of processing your data.
- Right to erasure of your personal data: Upon your request, we will erase the personal data we hold about you. However, certain data will only be deleted after a specified retention period, for example because in some cases we are legally required to retain the data, or because the data is necessary to fulfill our contractual obligations to you.
- Right to block your personal data: In certain cases provided for by law, we will block your data if you request it. Further processing of blocked data is limited to a very restricted extent.
- Right to withdraw your consent: You may withdraw your consent to the processing of your personal data at any time with effect for the future. The lawfulness of the processing of your data remains unaffected by this action, up to the point of withdrawal of your consent.
- Your right to object to the processing of your data: You may object at any time to the processing of your personal data in the future if we are processing your data on the basis of one of the legal grounds provided for in Article 6 (1e or 1f) of Regulation (EU) 2016/679. If you object, we will stop processing your data, provided there are no legitimate grounds for further processing. The processing of your data for advertising purposes does not constitute a legitimate reason.
7. Privacy
The Data Controller implements specific technical and organizational security measures to protect personal data and information from loss, misuse, alteration, or destruction. Our partners who assist us in operating this website also comply with these provisions.
The Data Controller makes every reasonable effort to retain the personal data collected only for as long as necessary for the purpose for which it was collected or until its deletion is requested (whichever occurs first), unless it continues to retain them in accordance with applicable law.
8. Revisions to the Statement
We reserve the right to modify or periodically revise this Statement at our sole discretion. In the event of changes, the Data Controller will record the date of modification or revision in this Statement, and the updated Statement will apply to you from that date. We encourage you to review this Statement periodically to see if there are any changes in how we handle your personal data.
This constitutes a Statement of Compliance with the provisions of EU Regulation 2016/679 and the National Implementing Law.