This policy applies to the company “AMBIENCE SERVICES S.A. IKE”, hereinafter referred to as the company.
The company is committed to protecting the personal information collected when you use our website and other services. This Privacy Policy sets out its commitment to protect personal data in relation to its collection, use, transfer and retention.
Introduction
Collection and use of Personal Data
The company has designed a standardized contact form on its website to facilitate communication with all interested parties. This form is used for any queries or requests and directs them to the appropriate department or staff member. In order to administer and respond to your queries and requests, we may collect and store your full name, your e-mail, your address, contact details and any other information you may have provided to us. This information is used strictly to respond satisfactorily to your questions or requests and will not be disclosed to third parties other than those listed in this policy or where disclosure is required or permitted by law.
In addition, we provide the company’s telephone numbers for a more direct contact if required.
There is also the possibility to subscribe to the company’s newsletter, where the user’s name and email address are filled in. In any case, if the user wishes to withdraw his/her consent, the possibility to unsubscribe from the company’s newsletter is provided through the body of the e-mail message received by the user. At the same time, the e-mail address is deleted from the company’s systems.
In some cases, our website may be used by prospective partners, in which case the subject will need to take note of the Subjects – Job Applicants Notice.
For the lawful processing of your data under Regulation (EU) 2016/679, we recognise a legitimate basis before processing personal data. In the above cases, the legal basis for the processing of personal data on our part is the granting of your explicit consent to the processing by submitting the relevant form only if you agree with this policy.
Transfer of Personal Data
The company may transfer personal data collected to the extent reasonably necessary for the management of legitimate business. Such transfers will be protected by appropriate safeguards (e.g., disclosure clauses to subcontractors, disclosure clauses to third-party suppliers, disclosure clauses for personal data necessary for legal compliance, etc.). In addition, we may transfer personal data where such processing is necessary to comply with a legal obligation to which we are subject.
Retention of Personal Data
The company is committed not to retain personal data for a period longer than necessary and we will ensure that we delete it securely. For additional information about the punching and deletion period, please refer to the “Contact” option on the website.
Rights of Subjects
In this section, the company explains the rights arising from Regulation (EU) 2016/679 and how data subjects can satisfy these rights. For further details please refer to the “Contact” section of the website.
5.1 Right of Access
The company believes that the personal data collected directly from the subjects is accurate and complete. Individuals can access their own personal data using the Subject Access Request.
5.2 Right of Correction and Deletion
- The data subject may request the updating, deletion or removal of any information held about him or her, and any third party who processes or uses the data must also comply with this request. A deletion request can only be refused if an exception applies. The right to erasure can be exercised using the Subject Access Request.
The company is obliged to delete the personal data when one of the following applies:
the personal data are no longer necessary for the purposes for which they were collected or processed; - the data subject withdraws his or her consent and there is no other legitimate basis for processing
- the data subject objects to the processing carried out on the basis of the legitimate interests of the Data Controller and there are no other overriding legitimate grounds for the processing;
- the personal data have been unlawfully processed;
If the request to erase the personal data has been received, the identification has been confirmed, the request meets one of the above requirements and there is no legitimate ground for opposing the processing, the company must erase the relevant data in its entirety. The request should be registered in the Data Subjects’ Request Registration File.
If the company cannot delete the personal data, it will ensure that it cannot or will not attempt to use the personal data to justify any decision about an individual or in a way that affects that individual in any way. It also does not give any other organisation access to personal data.
At the same time, it protects personal data with appropriate technical and organisational security, and commits to the permanent deletion of the information if or when it becomes available.
5.3 Right to restriction of processing
The data subject has the right to demand from the administrator, restriction of processing using the Subject Access Request.
5.4 Right of Rejection
The data subject has the right to object, at any time and on grounds relating to his or her particular situation, to the processing of personal data concerning him or her using the Subject Access Request.
5.5 Right to Data Portability
Upon request, the data subject should have the right to obtain a copy of the personal data in a structured format using the Subject Access Request.
These requests should be processed within one (1) month, as there is no excessive burden and it does not compromise the privacy of the individuals. A data subject can also request that his or her data be transferred directly to another system. This request must be implemented free of charge.
If the company cannot fully respond to this request within one (1) month, the Data Protection Officer should nevertheless provide the following information to the Data Subject, or his or her legally authorised representative, within the time period specified:
1) A confirmation of receipt of the request
2) Any information identified to date
3) Details of any information or amendments requested which will not be provided to the data subject, the reason(s) for refusal, and any available procedures for appealing the decision
4) An estimated date by which the remaining responses will be provided
5) An estimate of any costs to be paid by the data subject (e.g. where the request is excessive in nature); and
6) The name and contact details of the Data Protection Officer
Modifications
If the company chooses to change this Privacy Policy, we will post the changes on the company website. Where the changes are significant, we may also choose to send an e-mail to the affected users with the new details. Where required by law, we will get your consent to make these changes.
Contact
If you have any concerns or complaints about this policy, please contact us:
Telephone: +30 211 1097700
E-mail: dpo@ambience.gr
If you believe that our processing of your data violates applicable law, you may lodge a complaint with the competent supervisory authority:
Personal Data Protection Authority (tel:+30-2106475600 – email:: contact@dpa.gr)