PRIVACY AND PERSONAL DATA PROTECTION POLICY
1. INTRODUCTION
This Privacy and Personal Data Protection Policy (“Policy”) describes how the sole proprietorship Ioannis Stoupakis, son of Nikolaos, located in Chios, GR-82132, Greece, and operating under the trade name “Keeping Goods” (“we”, “our business”) collects, uses, stores, and protects the personal data you provide when using our website www.keepinggoods.com and our services for the collection, storage, and delivery of goods.
This Policy has been drafted in accordance with the European Union’s General Data Protection Regulation (GDPR – Regulation 2016/679) and the applicable Greek data protection legislation.
2. DEFINITIONS REGARDING PERSONAL DATA
According to Article 4 of EU Regulation 2016/679:
– Personal Data: any information relating to an identified or identifiable natural person (“Data Subject”).
– Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing of personal data.
– Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
– Recipient: a natural or legal person, public authority, agency or another body to which personal data are disclosed, whether a third party or not. Public authorities that may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients.
– Data Subject: natural persons whose personal data are collected and processed by the Controller (in this Policy, data subjects include users of our website, customers, employees, and other third parties who interact with us).
3. DATA CONTROLLER
The Data Controller is Ioannis Stoupakis, in Chios, GR-82132, Greece.
Contact Information:
Phone: +30 6947000515
Email: info@keepinggoods.com
4. PERSONAL DATA WE COLLECT
We collect and process the following personal data:
4.1 Data you provide directly:
– Identification data (email address, login password, first and last name, date of birth, country, postal address, phone number, passport number or other official document indicating nationality)
– Billing and order details
– Payment information (bank account numbers, credit/debit card details)
– Copies of invoices or purchase receipts
– Information regarding goods to be received and stored
4.2 Data collected automatically:
– Website browsing data (IP address, cookies, device identifiers)
– Website usage data (pages visited, time spent, clicks, answers to questions)
– Device and connection data (device type, OS, browser)
5. PURPOSES AND LEGAL BASIS FOR PROCESSING
5.1 Purposes of processing:
– Provision of goods collection, storage, and delivery services
– Management of your account on our website
– Communication with you regarding orders and services
– Payment processing
– Compliance with legal and tax obligations
– Improvement of our services
– Transaction security and fraud prevention
5.2 Legal basis for processing:
– Contract performance: Processing is necessary for the performance of the service contract entered with you.
– Legitimate interest: We have a legitimate interest in processing your data for security, service improvement, and fraud prevention.
– Legal obligation: We are required to retain certain data for tax and accounting purposes.
– Consent: In specific cases, processing is based on your consent (e.g., for newsletters).
6. DATA RETENTION PERIOD
We retain your personal data for as long as necessary to fulfill the purposes outlined in this Policy, unless a longer retention period is required or permitted by law.
Specifically:
– Transaction data, invoices, and related documents are retained for 5 years in accordance with tax and accounting obligations.
– Account data is retained for as long as your account remains active and for 12 months after your last activity.
– Payment data is retained only as long as necessary to complete the transaction, unless you have consented to store it for future transactions.
7. DATA RECIPIENTS
Your personal data may be shared with:
– Authorized personnel of our business who require access to provide services
– Partner companies providing services on our behalf (e.g., web hosting, payment processing, delivery services)
– Public authorities when required by law or legal process
All third parties processing data on our behalf are contractually bound to protect your personal data in accordance with the GDPR.
8. DATA SECURITY
We take appropriate technical and organizational measures to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include:
– Data encryption
– Restricted access to personal data for authorized personnel only
– Use of secure servers and systems
– Regular security checks and system updates
– Staff training on data protection
9. USER CONSENT
By using any of our services, you agree to this Privacy Policy, including:
Lawful disclosure / disclosure without lawful provision:
The Data Subject is informed of and consents to the possible transfer of their personal data to law enforcement and regulatory authorities in the event of illegal or non-contractual use of our website, or when deemed necessary to protect state and public safety, or in connection with the prosecution of criminal acts.
To give or withdraw your consent for receiving updates at any time, contact us at info@keepinggoods.com or use the unsubscribe links found in our emails.
10. YOUR RIGHTS
Under the GDPR, you have the following rights regarding your personal data:
– Right of access: To receive information about the personal data we hold about you
– Right to rectification: To request correction of inaccurate or incomplete data
– Right to erasure: To request deletion of your data under certain conditions
– Right to restriction of processing: To request the restriction of data processing
– Right to data portability: To receive your data in a structured, commonly used, and machine-readable format
– Right to object: To object to the processing of your data under certain conditions
– Right to withdraw consent: If processing is based on your consent, you can withdraw it at any time
To exercise any of the above rights, contact us using the information provided in Section 3.
11. COMPLAINTS
If you believe your data protection rights have been violated, you may file a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
12. DATA TRANSFERS OUTSIDE THE EU/EEA
Your personal data is stored and processed within the European Union/European Economic Area (EU/EEA). If we need to transfer your data outside the EU/EEA, we will ensure an adequate level of protection using appropriate safeguards, such as standard contractual clauses approved by the European Commission.
13. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this Policy at any time. Any changes will be posted on our website, and where appropriate, we will notify you by email. We encourage you to review this Policy regularly for any updates.
14. CONTACT
For any questions regarding this Privacy Policy or to exercise your rights, contact us using the information provided in Section 3.