1. In general
Respect for your privacy and the management, protection and security of your personal data are a priority for the Dressing Bar (the "company", "Dressingbar", "us"). The company has established this Data Protection Policy, (hereinafter referred to as the "Data Policy" or "Policy"), to inform you of the type of data it collects or produces about you when you visit or purchase from www.dressingbar.gr (hereinafter referred to as "e-shop", "online Store" or "website" or "Dressing"), or become a member of or subscribe to our newsletters' recipient list, or otherwise use Dressing Bar's services or participate in its promotional or other activities, or make use of social media Dressing Bar or otherwise, (hereinafter referred to as "you", "your"); of the purpose of collecting and processing your data and how such data and its recipients are processed; of Dressing bar’s rights and rights regarding your choices in your personal data as well as how to contact us for any issues you may have regarding your personal data.
If there are substantial changes to this Policy or our practices regarding your data change in the future, we will notify you by making the changes publicly available on our website. However, if you would like any clarification or information regarding the changes, or if you have any disagreement, reservation or query regarding them (the changes), you may contact us according to the information listed in the section below. Please note that any information/clarification provided to you in accordance with the above regarding any changes to this Policy does not constitute a replacement, substitution, or modification of this Policy.
Your continued browsing of our website, or use of our services and/or purchase through our online store, also constitutes your automatic and unconditional acceptance of the modified terms of this policy. If you do not agree with the modifications, you should not take any action or use the website or purchase, nor provide personal data, and you are entitled to terminate the agreements between us and request deletion of your account and your data. In any event for any information or clarification, you may contact us and in any case you have the right to exercise your rights as set forth in Section V below.
II. PROCESSING DIRECTOR & DATA PROTECTION OFFICER
1. Who is the Editor?
The company responsible for the processing of your personal data is the company "PALIOURA VASILIKI - IOANNATOU POPI & SIA OE" and the distinctive title "DRESSING BAR OE", based at 36 Irinis Avenue, Illioupoli, Athens, Greece (VAT: 998703513 / Tax Office of Ilioupolis).
2. Who is the Data Protection Officer of the company
Contact details of the Data Protection Officer (DPO) are:
3. Questions and Comments
You may contact us at the contact details listed above and submit any comments, queries, comments or complaints you may have regarding this Policy and the general collection and processing of your personal data. You have the right to submit any complaints regarding the protection of your personal data that may arise from the processing of this data by the company to the Greek Data Protection Authority, which is the supervisory authority in Greece. More details can be found at the following link: www.dpa.gr. However, we consider it our duty to manage any concerns you may have regarding your personal information we process, so we will be happy to contact you.
III. DATA COLLECTION AND PROCESSING
1. What data do we collect about you and how do we collect it?
While browsing our Online Store, or when ordering, opening your account, registering and downloading our newsletter and using our other services, participating in Dressing Bar activities or otherwise, we collect a variety of types of personal data about you, either directly from you or from third parties or by automated means such as:
We do not knowingly collect any information from anyone under the age of 15. Our services are aimed exclusively at people who are at least 15 years old or older. If you are under the age of 15, do not use or provide any information to us, do not register as a member or a recipient of our newsletters, do not make any purchases or provide any information about yourself, including your name, your address, or your contact information (phone, email, etc.). If we find that we have collected or received personal data from a child under the age of 15, we will delete it immediately unless parental or guardian consent has been given. If you think we may have information from or about a child under the age of 15, please contact us.
2. How and why we use your personal information.
All of the above personal data in which you have been mentioned or which you provide to us compulsorily or voluntarily, or we collect from third parties or are produced by automated means, are used for the following legitimate purposes. Please note that in the case that community or national law restricts or prohibits certain company actions for which we use your data, we will cease using any information that pertains to you for these purposes:
The legal basis for using the information about you is one of the following:
If none of the above applies, your consent (which we will ask for before processing the information) is necessary.
|Purpose of Processing Data||Data we process for this purpose||Legalization of Processing|
|Member Registration - Account Creation – Dressing bar Account Management:|
We process your data in order to:Recognize you as a user.
Give access to the functions and services of the Member Account.Use the services / features of your Account (Purchase History, Wishlist Address Management, etc.)
|a) The personal information that you provide us with when setting up your Dressing bar account:|
Name - Surnamee-mailpassword
b) Transaction Data
c) Wishlist cookie data
|The legal basis for processing is:|
a) Your consent to your registration and the creation of an account on the Dressing bar site and the voluntary provision of your data which is optional for this purpose.b) Our legitimate interest in securing your account and identifying you where appropriate, which is to your advantage to avoid fraud or security incidents.
c) Fulfillment of the terms governing the creation - management and operations of your account.
|Receipt, Management and Execution of your order submitted to the Dressing bar via e-shop or by phone, involving:Receipt of Customer’s orderOrder entryProduct pricingManagement of payments, fees and chargesDelivery of products to the customerWithdrawal or return of a productProcessing and overall order managementCustomer contact for updates and order notificationsActivation of mechanisms to prevent fraud against you or us.Security of your use of gift vouchers etc.||a) Your personal data you declare to us when submitting your order:|
NameLast nameMobile or landline phone (optional)e-mailproduct delivery addressPayment and card details
If the call is recorded you will be notified in advance with a relevant voicemail message.
b) Transaction Data
c) Market Data
|The legal basis for processing is:|
a) The performance of the contractual relationship that the Company assumes to fulfill for you under the purchase contract.
b) Compliance with the legal obligation of the company to comply with tax regulations and provisions.
c) Legitimate interest in collecting a purchase price and detecting fraud which also benefits you in the event that someone attempts to deceive you, for example by using your payment information.
|Customer service and management before or after the sale including:|
Communication from the customer to the Company's media (conventional media e.g. email or call center; or multimedia communication e.g. Viber; or other means e.g. Social Media)Communication from the Company at the request of the customer regarding the information provided by the customer.Service in general regarding matters relating to the company, the e-shop, its products, services, its order, its account, its programs or contests, any guarantees it provides, and its social media company.Complaints or clarificationsExercise of rightsManagement and optimization of the e-shop user experience and service in general
|Processing for this purpose includes the essential data that either you give us when you submit your request, namely:Identity dataContact InformationMarket DataTransaction DataInformation you provide us with at our request|
or the data we develop for you.
If the call is recorded you will be notified beforehand with a relevant voicemail
|The legal basis for processing is:|
a) Compliance with the company's legal obligation to adopt pre-sale and after-sale customer service tools/ tools for our response to your queries related to the exercising of your rights.
b) The legitimate interest of the company: to respond to your requests through various communication channels; to optimize its customer service and management services; and to provide its customers with the opportunity to communicate with and manage any issue they may have in the best possible way, bearing in mind both the customers’ needs and benefits and also anything reasonably expected of the customers. Any user may opt out at any time by accessing their personal information for this purpose (e.g. the data on their purchases tab regarding the service), by reporting it to customer service personnel, or by contacting the company on all media outlets concerning any of the above.
c) Contract execution if you contact us specifically regarding management of issues relating to your order
d) The customer's consent to receive communication from the Company for this purpose when he / she requests the Company to contact him / her.
|Advertising & Marketing|
Management of subscription to the Dressing bar newsletter list.Sending general and personalized newsletters.Sending direct commercial communication via email, sms, Viber or other multimedia, push notifications etc.Conducting promotional activities e.g. organizing competitions, activating existing customers, rewarding good customers, loyalty etc.Purchasing offers and incentives based on your preferences.Voluntary participation in competitionsInvestigating the degree of customer satisfaction with Dressing bar's products and services.Instant commercialized personalized communication by sending customized updates based on customer preferences.
|For the purpose of advertising and marketing the company processes identity and communication data, purchase and transaction data, profile data, demographic data, cookies data, and/or a combination of the above. For this purpose, our company processes data related to the type of products you purchase, your recent purchases, market value, market frequency, and purchase history, etc.||The legal basis for processing is:|
a) A legitimate interest of the company to process its customers data granted to us in the context of a purchase or other transaction with us for the purpose of direct commercial communication for related products or purposes. In these cases you can request opt-out by pressing the unsubscribe button on your email or mobile message or by contacting us.We also believe that we have a legitimate interest in developing a profile with the information we have about you (e.g. your shopping history, your preferences when browsing the e-shop) but also based on your purchases and your interaction with newsletters, your age, your gender and your place of residence, as we understand that processing this data is also beneficial to you as you improve your Dressing bar experience and gain access to information that interests you.
b) Consent where you voluntarily provide us with your data, authorizing us to send you newsletters and personalized information via email, sms, Viber and other media and when you accept push notifications regarding fulfillment of the terms governing the creation, management and operation of your account.
|Business Analysis and Improvements regarding:|
Continuous operation of the e-shopTechnical integrity and security of transactionsOptimization of technical systemsAddressing technical issuesReporting and data reporting
|The information we process for this purpose is a combination of the information you provide us with (for example, account registration information), cookies we obtain, and similar technologies.||The legal basis for processing is:|
a) Compliance with a legal obligation for information security and confidentiality.
b) Legitimate interest in: network security and preventing fraud and unauthorized access to data; our business continuity, upgrading our systems and our partners; developing our business and managing and optimizing techniques and systems; and in our business processes, which take precedence over the rights and freedoms of the entities who reasonably expect that the processing can be done for this purpose. You have the right to oppose the above treatment on a case by case basis. It is noted, however, that the company has the right to state compelling and lawful reasons for processing that override the interests, rights and freedoms of the entities.
|Statistical analysis to evaluate and improve e-shop services and processes including:|
Evaluation and improvement of business processesBetter responsiveness and management of the e-shopResearch and/or analysis to better understand e-shop customer needsResearch and evaluation to improve existing products and/or services and develop new onesEvaluation of new programs, offers, etc.Adoption of new business models, programs and partnerships.Promotion of the company, our products and our services.Distribution and marketing of our products in other countries.Trade and disposal of new products and services.Advertising and promotion of our company.Improvement in your experiencesDelivery of relevant contentQuality surveysStatistical analysis
|All the data collected for the purposes of the previous processing purposes is aggregated for statistical purposes only and all the necessary guarantees are made that subjects will not be identified. Data collected from the respective cookies that perform such processing will also be used.||The legal basis of this treatment is|
a) The legitimate interest of the Company in the further consistent processing of aggregated data for the purpose of statistical analysis to improve its products and services, while respecting all necessary data collection and processing safeguards that do not identify a particular entity and do not affect the rights and freedoms of data subjects.
b) Legal interest in: distributing our products; analyzing the usability and functionality of the e-shop; our customers 'satisfaction, and our customers' preferences regarding the offered products; and improving our business. We work to improve our partnerships, always respecting your rights, freedoms and interests with respect to your personal data.
3. To whom we share your personal information and why
In the context of the operation of the e-shop, the fulfillment of its contractual obligations and your best service, our company reserves the right to work with third-party service providers, who provide us with support and access only your essential data for the service they offer us (e.g. registering at the eshop and managing your account; executing a contract of buying and selling between us and generally providing our services to you; operating, managing and editing the Dressingbar.gr website; optimizing our products and services, etc.). These third party service providers are contractually bound not to use your information in any way other than to help us provide you with the products and services we agree to.
We also reserve the right to disclose your personal data to a third party to whom we reserve the right to choose to transfer all or part of our business. In addition, in the event of a merger, acquisition, or other change in our business, new owners, shareholders, etc. have the right to use your personal data in the same manner as in this privacy statement.
Moreover, your personal data may be disclosed to the competent judicial, police and other administrative authorities upon their lawful request and in accordance with any applicable laws. In addition, in the event of a statutory order, service order or formal preliminary examination, the company has the right to make available the relevant information without delay.
IV. PROTECTION AND MANAGEMENT OF YOUR PERSONAL DATA
1. Security of your personal data
We apply appropriate technical and organizational measures to protect the personal information we hold against unauthorized disclosure, use, conversion or destruction. Where appropriate, we use encryption and other technologies that can help secure the information you provide. We also ask our service providers to comply with strict requirements for the protection and security of personal data.
In particular, the information you submit to the company is managed solely by specially authorized personnel of the company who are under our control and work solely according to our orders. In carrying out the processing, the company selects persons or third-party affiliates with corresponding professional qualifications, who provide adequate guarantees in terms of technical knowledge and personal integrity regarding confidentiality. The company, through its contractual commitments and its affiliates, takes all the necessary security measures to protect and safeguard the privacy, confidentiality and integrity of personal data. In any case, their security in the platform environment is without prejudice to reasons beyond its sphere of influence, as well as to reasons arising from technical or other weaknesses of the company's non-controlling network or due to force majeure or accidental events.
You must not disclose the details/codes you have provided for the opening of your account, which is personal and non-transferable. For personalized communication, our company also uses appropriate mathematical and/or statistical processes to compile the profile and performs regular quality and security checks on the systems and algorithms used to correct inaccuracies in data.
2. Length of time personal data is kept
We will keep your personal information for as long as you continue to interact with us (have an account, register to receive commercial communication from us, make a purchase from our online store, contact our customer service points, participate in a competition etc.) and for as long as it is necessary for the fulfillment of the purposes outlined above, or for the period during which liability could arise from processing, in accordance with applicable law, or if those purposes no longer exist, we are obliged to keep them within the law, for example for tax purposes. In addition, we retain your data until you request that we delete it, or we maintain and process your data with your consent until you object to this, or until you object to it being processed by us on the basis of our legitimate interest.
In determining the retention time of your personal data, we consider the nature of your data, the amount, the purpose of processing it, its security, etc. You have the right to ask us to delete your data. To exercise of your right, please refer to the relevant section in this policy.
In some cases, we reserve the right to anonymize your data for research or statistical purposes, so that it is no longer associated with an identifiable person, and we reserve the right to use this information for an indefinite period of time. In any case, your data is securely stored.
|Purpose of processing ||Maintenance time|
|Managing Your Account||Until you delete your Account|
|Order receipt, order fulfillment||We will process your data for the time required to manage the purchase of the products or services you have acquired, including any refunds, withdrawals, complaints or claims related to the purchase of that product or service. We will keep some of your information that we need until you tell us to stop saving it.|
|Purchases||If you purchase products, we will retain your transaction information for as long as it takes to complete the sale and to comply with any legal obligations (for example, for tax and accounting purposes).|
|Customer service||If you contact customer service, a relevant file will be created (including details of your question and our response) and we will keep it for as long as it remains relevant to our relationship. Temporary files may be useful until more permanent files are available and will only be maintained on a temporary basis.|
|Market research||If you are not registered with us for other purposes (eg. promotions) and we use your publicly available information to understand your purchase or preferences, we will keep your information for a short time to complete this particular market research.|
|Usability and Quality Analysis||We will process your data during the period during which we perform an action or specific quality survey or until we anonymize your browsing data.|
|Marketing||We will keep your data until you unsubscribe from the newsletter, or until you have given your consent, if granted, or until you object to its processing, for a maximum of five (5) years.However, some elements of your promotional profile, such as records of how we interact with you, will naturally expire after a period of time, so we automatically delete them after a specified period (usually 3 years) depending on the purpose. for which we collected them.If we have not been in contact with you for a long time (usually 3 years), then we will stop sending you promotional announcements and will delete the history of your responses. This will happen, for example, if you never click on our newsletter, if you never log into a digital contact point or if you never contact us or make a purchase, or contact customer service during that time. The reason is that, in these cases, we assume you prefer not to receive notifications.|
|Business analytics||Business analytics data is usually collected automatically when you use Dressing bar’s contact points and is anonymized/ collected immediately.|
3. Transfer of your personal data to third countries
The Company normally holds your personal data within the European Economic Area. Where data is to be transmitted to third countries outside the European Economic Area for which there is no decision of competence by the European Commission or to International organizations, all appropriate safeguards provided by the applicable law on the protection of personal data concerning transfers to third countries and the relevant information will be posted on the company's website at www.dressingbar.gr.
V. YOUR RIGHTS AND OPTIONS
You have the following rights regarding the personal information we hold and process:
requesting that that it not be used for direct marketing
We offer easy ways to exercise these rights, such as unsubscribing links, by phone at +30 2109950099, or by sending an email to email@example.com
Some of the mobile apps we offer may also send you unsolicited messages about, for example, new products or services. You can turn off these messages through the settings on your phone or app.
We may request certain information about you for the purpose of identifying you for the safety of your information. Your rights are exercised free of charge, although when you exercise one of your rights abusively we may ask for a fee, in accordance with the conditions set by law. In any case, we will respond to your requests within one month, except in exceptional cases where our response time to a request may be longer.
Access (a. 15)
You can ask us:
You may ask us to correct inaccurate personal data.
We can strive to verify the accuracy of the data before correcting it.
You can ask us to delete your personal information:
We do not require you to comply with your request to delete your personal data if your personal data is required to be processed:
You may ask us to limit (i.e. keep but not use) your personal data when:
When processing is based on consent, and is done by automated means, you may ask us to provide your personal data in a structured format that is widely used, in a machine-read format, or you may request that it be transferred directly to another controller. However, this right, by law, only applies to data that is provided by the subject himself and not to that deduced by the controller on the basis of data provided by the subject.
You may at any time object to any processing of your personal data which is based on the legitimate interest of the company or the performance of a duty performed in the public interest.
You have the right to revoke your consent to us and such revocation takes effect immediately.
You have the right to complain to your local supervisor about the processing of your personal data. In Greece, the Data Protection Supervisory Authority is the Personal Data Protection Authority - APCC (www.dpa.gr).
We take the confidentiality of all files that contain personal data seriously and we reserve the right to ask you for proof of identity if you request such files.
We will not charge you for the exercise of your rights with respect to your personal data, unless, as required by law, your request for access to information is unfounded or excessive, under which conditions we may charge a reasonable fee. We will inform you of any charges before we complete your request.
We aim to respond to any valid request within one (1) month of its receipt, unless it is particularly complex or you have submitted several requests, in which case we aim to respond within three months. We will let you know if we are going to need more than one (1) month for the reasons listed above. We may ask you if you can tell us exactly what you want to receive or what the exact nature of your concern is. This will help us to process your request more quickly.
In any event, you must provide specific and factual information and/or facts to enable us to respond and/or satisfy your request accurately, otherwise we reserve the right to avoid any errors that may be beyond our control. Our company may also refuse claims that are unfounded or excessive or abusive or malicious or generally unlawful under the provisions of the law.