RETENTION PERIOD OF INFORMATION
The Company will retain the personal data collected through its Website for the strictly necessary period to fulfill the purposes of processing outlined above and to comply with its legal obligations, in accordance with legislative requirements. If you withdraw your consent for the collection and processing of your personal data, we will delete your data from our electronic and physical records, unless its retention is necessary to comply with a legal obligation according to the aforementioned, or for the establishment, exercise, or defense of our rights or legal interests before judicial or other authorities.
The company retains the data collected from the use of Cookies (trackers) according to the periods specified in the cookie tool in the respective cookie logging tables.
The Company retains personal data from the Contact Form for a maximum period of one (1) year.
These data can be deleted earlier if the applicant/interest party requests their deletion and if their retention is not necessary to comply with a legal obligation as data controllers.
The Company is committed to the secure destruction of your personal data without the possibility of recovery once the retention period has expired or after you submit a deletion request.
SECURITY OF INFORMATION
The security of your personal data is an absolute commitment for us. To achieve this, we implement all modern and appropriate technical and organizational measures suitable for the purposes of processing. We regularly monitor the effectiveness of these measures, including:
- SSL Protocol (Secure Sockets Layer): The SSL Protocol used by our Website is currently the global standard for the authentication of websites to users and for encrypting data between users and web servers. An SSL-encrypted communication requires that all information sent between a client and a server be encrypted by the sending software and decrypted by the receiving software, thus protecting personal information during transmission. Additionally, all information sent via the SSL protocol is protected by a mechanism that automatically verifies whether the data has been altered during transmission.
- Secure Data Handling: Personal data collected from the communication forms is sent encrypted and stored in the Company’s email or in a special program that our website uses to maintain a history of communications that have taken place. The processing of this data is carried out only by members of the Company and is not shared with third parties.
By implementing these measures, we aim to ensure the integrity and confidentiality of your personal data against unauthorized access, loss, or misuse.
YOUR RIGHTS
You have the right to exercise, as applicable, the following rights regarding your personal data:
- Right of Access/Information: To know if we are processing your data, which data we are processing, for what purpose, and who the recipients are.
- Right of Rectification: To correct any inaccuracies or incomplete data about you.
- Right of Erasure (Right to be Forgotten): To request the deletion of your personal data from our records, provided the processing is no longer necessary, or the retention of your data is not required to comply with legal obligations or to protect our legal interests before the courts.
- Right to Restrict Processing: To limit the processing of your data when there is a dispute over the accuracy of your data.
- Right to Data Portability: To receive your data in a structured, commonly used format or to have it transmitted to another controller.
- Right to Object: To oppose the processing of your data under specific conditions.
- Right to Withdraw Consent: To withdraw your consent at any time, without affecting the legality of the processing based on consent prior to the withdrawal.
- Right to be Informed: To be notified of any unauthorized or malicious activity within the Company’s data systems that may lead to unauthorized access to your personal data.
The Company does not use automated decision-making methods, including profiling.
The Company will make every effort to respond to your request within thirty (30) days from receipt. However, if the complexity of your request or the volume of information makes it impossible to satisfy your request within 30 days, the Company is committed to informing you in writing within this period of the reasons for the delay and to make every effort to fulfill your request as soon as possible, and in any case within two (2) additional months.
The Company reserves the right not to satisfy your request if it is deemed clearly unfounded or excessive and will inform you of the reasons for this.
In any case, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr, Tel: +30 210 6475600, Fax: +30 210 6475628, Email: contact@dpa.gr.
CONTACT
If you have any questions regarding this Policy or our privacy practices, or if you wish to exercise any of your rights, you can contact us at the following email address: info@nessos.gr
CHANGES TO THIS POLICY
The Company reserves the right to modify this Policy in accordance with applicable privacy and data protection laws. Visitors to our Website should regularly review this Privacy Policy to stay informed about any updates. The Company is committed to notifying visitors and users through appropriate channels in compliance with the requirements set by the EU General Data Protection Regulation (GDPR) 679/2016.
Last modified on: 05/05/2025
Version: 1.0