Privacy Policy
1. GENERAL
The website https://internetcode.gr was designed and operates under the control of the Business operating under the name ΜΙΧΑΛΗΣ ΜΙΧΑΗΛ ΣΤΑΜΑΤΙΟΣ and email: m+website@internetcode.gr.
The Business monitors developments in Personal Data protection legislation and adapts the Website’s operations to the applicable legal framework to ensure that your Personal Data are protected during collection, processing and storage.
2. SCOPE
This Personal Data Protection Policy has been prepared and adopted by the Business and applies to all processing of Users’ personal data in connection with the operation of the Website and for the purposes of providing the Services.
This Privacy Policy is addressed to Users of the Website. Accordingly, the words “you” and “your”, and second-person forms generally, refer to the User of Internetcode.gr. First-person plural forms refer to actions of the Business.
The Privacy Policy applies to everyone who browses the Website, uses the Services, interacts with the Business either through communications with us or when visiting our social media pages (messages, comments and reviews on our pages, channels and profiles), reviews the services of the Business and/or the Website on third-party websites, and so on. In the cases listed above by way of example, the Business may collect and process your Personal Data.
3. CONTENT
This Privacy Policy describes the basic principles, safeguards, legal bases and purposes under which the Business collects, stores and processes your Personal Data.
4. REGULATORY FRAMEWORK
The Business collects, processes and protects your Personal Data in accordance with the requirements of the General Data Protection Regulation (EU) 2016/679 (GDPR), as supplemented by the relevant provisions of applicable national and European legislation, Law 4624/2019, and the instructions, decisions, guidelines and opinions of the Hellenic Data Protection Authority (HDPA) and the European Data Protection Board (EDPB).
5. BINDING EFFECT
Use of the Website and the Services requires and also confirms your acceptance of the Privacy Policy as in force, including any amendments, additions and changes made by the Business.
Every User must familiarise themselves fully with the Privacy Policy, accepts that it applies to the processing of their personal data, and assumes responsibility for respecting, following and complying with the Privacy Policy in the course of their interactions, activities and browsing on Internetcode.gr.
6. DATA SOURCES
The Business collects Personal Data concerning you either directly from you or through partner businesses. Data are collected through the Website and/or by other means (social media, Cookies, analytics, etc.).
7. TERMS & DEFINITIONS
For the purposes of this Privacy Policy, the following definitions apply:
-
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
-
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
-
Personal Data or Data means any information relating to an identified or identifiable natural person (Data Subject or Subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that natural person’s physical, physiological, genetic, mental, economic, cultural or social identity.
-
Special Categories of Personal Data or sensitive personal data means any information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic data, biometric data, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
-
Processing means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
-
Recipient means a natural or legal person, public authority, agency or other body to which personal data are disclosed, whether or not it is a third party.
-
Third party means any natural or legal person, public authority, agency or body other than the data subject, the controller, the processor, and persons who, under the direct authority of the controller or processor, are authorised to process personal data.
-
Consent of the data subject means any freely given, specific, explicit and fully informed indication of the data subject’s wishes by which they signify agreement, by a statement or a clear affirmative action, to the processing of personal data relating to them.
For other terms used in the Privacy Policy, please consult the GDPR and the Terms of Use.
8. CONTROLLER
For all personal data processing carried out by the Business in connection with, and for the purposes of, operating the Website, exclusively for the purposes and in the manner determined by the Business, the Controller is Michalis Michail, son of Stamatios, email: m+website@internetcode.gr.
9. PROCESSING DETAILS
| Processing | Purpose of processing | Data we process | Legal basis for processing | Retention period * |
|---|---|---|---|---|
| Collection, storage and use of data from the Website’s contact form | Your data are processed for the purposes of communicating with you and responding to, fulfilling and managing your request, resolving problems, answering questions and complaints, exploring a possible collaboration between us, and so on. | Email, telephone number, message | Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the data subject’s request prior to entering into a contract (Article 6(1)(b) GDPR) Consent (Article 6(1)(a) GDPR) |
We retain the personal data we collect from you through the Website for three months after our communication has concluded |
| Collection, storage and use of data we collect by telephone, social media, email and any other means through which you communicate with the Business | Your data are processed for the purposes of communicating with you and responding to, fulfilling and managing your request, resolving problems, answering questions and complaints, providing information and support, and so on. | Name, email, telephone number, message and any other information you provide to us | Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the data subject’s request prior to entering into a contract (Article 6(1)(b) GDPR) Processing is necessary for the purposes of the legitimate interests pursued by the Controller [(communication with Users, feedback, support, etc.) (Article 6(1)(f) GDPR)] |
We retain the personal data we collect from you through any form of non-public communication with the Business for three months after our communication has concluded |
| Collection and use of information about social media Users who communicate and interact with the Business through social media (Facebook, Instagram, Linkedin, Google Maps, etc. | Responding to requests, questions, ratings, reviews and complaints you submit when visiting social media platforms (Facebook, Instagram, Linkedin, Google Maps, etc.) and interacting with Users and third parties. Managing the Business’s social media pages, profiles, accounts and channels | Profile name, comments, tags, reviews, reactions (likes / shares), posts and reposts, messages, contact details (email, telephone number) and other information that Users and third parties share with the Business through social media. | Consent [Article 6(1)(a)] (The processing of data you share on these pages is also subject to the relevant privacy policy of each social media platform) Processing is necessary for the purposes of the legitimate interests pursued by the Controller (feedback, responding to Users’ messages) [Article 6(1)(f) GDPR] |
We retain access to your personal data for as long as you are connected in any way to the accounts, pages, profiles or channels (like / follow / subscribe), or for as long as records of your activity (your posts on a page of the Business, comments on posts, etc.) remain on the relevant social media platform |
| Collection and use of information collected through the Website’s Cookies | The collection of information through Cookie technology contributes, among other things, to the smooth operation of the Website, recording and retaining your choices while browsing, enhancing security and preventing cyberattacks, statistically analysing Users’ activity on the Website, monitoring and improving the way the Website operates, personalising advertisements displayed to Users elsewhere on the internet, and generally improving your experience when using the Website | Activity information, visits to the Website, statistical data on Website usage | Consent [Article 6(1)(a) GDPR] through acceptance of the relevant Cookies, except for strictly necessary and functional Cookies, whose installation you cannot prevent and for which the legal basis for processing is the Controller’s legitimate interest (proper and effective operation of the Website) [Article 6(1)(f) GDPR]. | Cookies are either temporary (session Cookies), which are retained until you close your browser, or permanent (persistent Cookies), which are retained for a longer period. Cookies are retained according to their type and are deleted either automatically when they expire, manually through your device’s browser, or through Cookie Management, if that function is available, whenever you wish. |
* The period for which the Business may retain your Personal Data is also determined by the Business’s relevant obligations under applicable legislation (tax legislation, etc.) and the statutory provisions on the maximum retention period.
10. SPECIAL CATEGORIES OF DATA
The Business does not collect or seek access in any way to special categories of personal data (sensitive data). Users of Internetcode.gr must not send or enter on the Website special-category data concerning themselves or third parties, except where strictly necessary. The Business reserves the right to delete any information posted or sent by a User that reveals unnecessary special-category data. The Business is not liable to the User, any third party or the Authorities for any damage suffered by the Data Subject as a result of the processing of special-category data arising from an act or omission of the User in breach of this prohibition. A User’s voluntary entry of Special Categories of Data on the Website, or transmission of such data to the Business, is deemed to constitute their explicit consent to the processing of their Data by the Website in the context of assisting them, answering a question, providing services, and so on.
11. MINORS’ DATA
The services of the Website and the Business are intended for adults. The Business does not process minors’ data and will immediately delete a minor’s data if it becomes aware or is informed that any minor is using the Website. The Business is not liable under any circumstances to anyone for any damage arising from a minor’s use of the Website. Full and exclusive responsibility rests with the parent, guardian, legal guardian, person exercising parental responsibility, and any other person responsible for the minor’s personal care, as well as with the minor themselves in cases provided for by law.
12. PROCESSING PRINCIPLES
The Business collects, stores and processes your Personal Data lawfully and transparently for specified, explicit and legitimate purposes and does not further process them in a manner incompatible with those purposes.
The Business makes the necessary efforts to ensure that the Personal Data it holds and processes are always accurate and up to date, as well as adequate and relevant, and that collection and processing are limited to the data strictly necessary for the purposes of processing and to the extent necessary for those purposes.
Personal Data are retained in a form that permits identification of data subjects only for as long as necessary for the purposes of processing the Data or for other lawful purposes.
Personal Data are processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and accidental loss, leakage, interception, destruction or damage, using appropriate technical or organisational measures.
13. DATA SUBJECT RIGHTS
The Business grants data subjects the rights provided for by law and facilitates their exercise. At the same time, we provide data subjects with full information about their rights. Specifically, data subjects have the following rights:
-
The right to be informed about the processing of their personal data.
-
The right of access to their personal data and to information relating to the processing and their rights.
-
The right to request rectification of inaccurate personal data and completion of incomplete personal data.
-
The right to request erasure of their personal data.
-
The right to request restriction of the processing of their personal data.
-
The right to receive their personal data and/or request that those data be transmitted to another controller (right to data portability).
-
The right to object to the processing of their personal data
-
The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them (right to human intervention).
To exercise your rights, you may send your request to the Business by email at m+website@internetcode.gr.
The Business will respond in writing within one (1) month of receiving the request and verifying the applicant’s identity, informing them of the actions taken following receipt of the request. This period may be extended by a further two months where necessary, taking into account the complexity and number of requests. The Business will inform the data subject of the extension within one month of receiving the request, together with the reasons for the delay.
These rights may be exercised free of charge. If your requests are manifestly unfounded or excessive, particularly because of their repetitive nature, the Business may either: (a) charge a reasonable fee, taking into account the administrative costs of providing the information or communication or taking the action requested; or (b) refuse to act on the request.
Furthermore, if you exercise one or more of the rights referred to above to rectification, erasure or restriction of the processing of your personal data, the relevant requests will also be forwarded to any third-party recipient to whom the personal data may have been disclosed for the purposes of processing, unless this proves impossible or involves disproportionate effort.
If you believe that your personal data have been affected in any way, you may contact the Business by email at m+website@internetcode.gr or by telephone on 6976153849. We are available at any time and ready to help you resolve the issue quickly, fairly and effectively. If your issue remains unresolved, you may also contact the Hellenic Data Protection Authority, with which you may lodge a relevant complaint: www.dpa.gr, 1–3 Kifisias Avenue, postal code 115 23, Athens, telephone: +30 210 6475600, email: contact@dpa.gr.
14. CONSENT
We provide all the information you need to give your prior consent, where required, to the Business’s processing of your personal data for one or more specific purposes. You may withdraw your consent at any time, easily and free of charge, without affecting the lawfulness of processing based on your consent before its withdrawal. Where an automated option for withdrawing your consent is not provided, please contact the Business by any means and we will provide all necessary information about the withdrawal you wish to make.
Before giving your consent, please read this Privacy Policy carefully and make sure that you agree with its content.
Your acceptance of this Privacy Policy, by ticking the relevant checkbox on the pages of internetcode.gr or by a similar means, is deemed to constitute your freely given consent (where required and where no other legal basis exists) to the collection, processing and onward transfer of your personal data for purposes related to the use of the Website and the Services, as described in this Privacy Policy.
To use the Website’s Services, you must provide certain data that we request. Refusal to provide the requested personal data makes it impossible to communicate with the Business and, generally, to use the Services of Internetcode.gr and fulfil the purposes of processing described above.
15. ACCESS TO DATA
The Business may allow authorised persons to access your data for (i) the maintenance and repair of the information systems and equipment (PCs, servers, hardware) that support the Website’s operation, and (ii) the further development and maintenance of the Website (development / support).
In connection with the operation of Internetcode.gr, the Business may disclose your personal data to partner companies, suppliers and service providers (e.g. advertising / promotion, cloud / hosting services). When the Business entrusts the processing of your Data to third parties, it selects Processors that provide sufficient assurances that appropriate technical and organisational measures will be implemented so that processing meets legal requirements and your rights are protected.
The Website uses Google Analytics.
More information:
https://developers.google.com/analytics/devguides/collection/analyticsjs/cookie-usage.
Google Analytics privacy and information security policy:
You can manage personalised advertising at:
https://www.google.com/settings/ads/anonymous.
The Business is a joint Controller with Google Inc. for some processing activities, while for other processing operations Google and the Business are separate Controllers.
Google plays a decisive role in determining certain purposes and means of processing the data collected through its technology. It is the sole Controller for any processing of Data exclusively for the purposes and in the manner determined by Google. In particular, Google may use even your non-anonymous data for its own purposes, such as profiling and combining them with other data from user accounts on its other services. Processing of your Data in connection with Google Analytics, whether by the Business or by Google, is carried out on the basis of your prior consent.
16. DATA TRANSFERS
If the processors are established outside the European Union (EU), specifically outside the European Economic Area (EEA), or if data processing is to take place outside the EU, your personal data are transferred only: (i) to a country covered by an adequacy decision of the European Commission; or (ii) where the controller or processor has provided appropriate safeguards and enforceable data subject rights and effective legal remedies are available; or (iii) in any other case provided for by law.
17. DATA STORAGE LOCATION
The personal data you enter on the Website are stored on the server that hosts the Website and the Business’s email, which is located within the European Union.
18. DATA CONFIDENTIALITY & SECURITY
The Business’s primary concern is to provide high-standard services while respecting the rights, fundamental freedoms, privacy and confidentiality of communications of internetcode.gr Users. We therefore take all appropriate and necessary measures within the legal framework, adopting modern technological procedures, advanced technical equipment and software, by design and by default in our systems.
The Business takes care to ensure that access to your data is authorised. Accordingly, only the Business’s designated employees and the “Processors” it works with process your personal data.
The Business adopts the latest security and malware protection methods and ensures that your data are protected against unauthorised access and processing. The Website uses an SSL certificate for the secure encryption and transmission of information.
The Business assumes that a User who enters personal data on the Website is the person to whom those data relate or has obtained the Data Subject’s consent to enter them. The Business is unable and is not obliged to verify the identity of the person entering the data and therefore bears no liability for the entry. The User making the entry is liable to both the Business and the data subject for any false, unauthorised and/or unlawful entry.
The Business is not liable for risks to the security or protection of your personal data within the Website’s electronic environment that fall outside its sphere of control and influence, or for risks arising from a third party’s act or omission, force majeure or fortuitous events.
If you are directed to third-party websites through specific links (links, hyperlinks, banners, frames) on Internetcode.gr, the Business is not responsible for protecting your data on those websites. Full responsibility for their content, information, visitor security, protection of visitors’ personal data and the quality of services provided rests with the owners, administrators and rights holders of those websites, which you visit at your own risk.
19. APPLICABLE LAW – DISPUTE RESOLUTION
For any dispute you may have with the Business concerning this Policy or the use of the Website and the Services, we are willing to listen and promptly resolve any problem while respecting your rights.
Disputes arising in relation to this Policy and any personal data processing in connection with the operation of Internetcode.gr are governed by Greek law, as supplemented by the relevant provisions of applicable national and European legislation and the instructions, guidelines, decisions and opinions of the Hellenic Data Protection Authority (HDPA).
Any dispute between the Business and Users or third parties will be resolved through amicable negotiations between them in accordance with the principles of good faith and fair dealing. If the dispute is not resolved in this way, it will be addressed through alternative out-of-court dispute resolution methods, such as Mediation, within a strict time limit of two (2) months from the dispute being raised. If it is demonstrably not resolved by these methods, the Greek Courts will have jurisdiction, with local jurisdiction vested in the Courts of Athens, whose jurisdiction you irrevocably acknowledge.
20. DRAFTING – AMENDMENTS
This Privacy Policy was drafted by the legal professionals of the internetlaw team.
The Business may update or amend the Privacy Policy at any time to reflect changes in the operation of the Website, the services it offers and legal provisions. Amendments will be posted on this webpage.
Policy last updated: 1 November 2023.