1. INTRODUCTION
The online store toulipaflowers.gr ("we", "us" or "us") is committed to protecting and respecting the personal data we hold. This privacy statement describes how personal data is collected and used and provides information about the rights of individuals. It applies to the personal data provided to us, either by ourselves or by others. We may use the personal data provided to us for the purposes described in this privacy statement or as specified prior to the collection of personal data.
Personal data is any information about an identified or identifiable person. When collecting and using personal data, our policy is to be transparent about why and how personal data is processed.
We process personal data for many purposes and the means of collection, the legal basis for processing, use, disclosure and preservation for each purpose are listed in the relevant sections below.
The personal data provided to us is provided either directly by the person concerned, by a third party acting on behalf of an individual, or from publicly available sources (such as internet searches).
In the event that we receive personal data relating to a person from a third party, we ask that third party to inform the person of the necessary information regarding the use of his data. Where necessary, reference may be made to this privacy statement.
2. SECURITY
We take seriously the security of all the data we have. Staff are trained in data protection, confidentiality and security.
We have a framework of policies and procedures that ensure that we regularly review the appropriateness of the measures we take to keep the data we hold secure.
All card payments are processed through Alpha Bank's "Aplha e-Commerce" electronic payment platform and use TLS 1.2 encryption with 128-bit encryption protocol (Secure Sockets Layer - SSL). Encryption is a way of encrypting information until it reaches its intended recipient, who will be able to decrypt it using the appropriate key.
All information you provide to us is stored on our secure servers.
Unfortunately, the transmission of information over the Internet is not entirely secure. While we will do our best to protect your personal data, we can not guarantee the security of the data transmitted on our site. Any transmission is at your own risk. Once we receive your information, we will use strict security procedures and features to try to prevent unauthorized access.
3. DATA WE KEEP
3.1 Purpose
This section shows how toulipaflowers.gr uses customer data. Customers are individuals or organizations that buy our product. We provide services to both individuals and organizations. The exact data that will be retained will depend on the services that will be provided.
When dealing with individuals, we may collect and process personal data in order to meet a contractual or operational obligation. We ask individuals to provide only the personal data required to fulfill our contractual or operational obligations.
3.1.1 Why do we process data?
When data is collected, it is used for various purposes, as follows:
Providing services to you.
Individual needs of our customers and to ensure that their needs are properly met.
Management.
To manage and organize our businesses and services, we can collect and process personal data. This may include (but is not limited to) maintaining internal business records, managing candidates and customer relations, managing candidate / client applications.
Regulatory.
In the context of our work and activities, at toulipaflowers.gr we may from time to time require the collection and processing of personal data to meet regulatory, legal or ethical requirements. This may include (but is not limited to) verifying the identity of individuals.
3.1.2 What data is editable?
The data that can be processed depends on the service provided and the recipient of that service.
Customer service.
Personal information may include name, contact information, IP addresses, business address, job titles, credit card information and other specific information.
3.1.3 How long do we keep data?
We retain the personal data we process for as long as it is deemed necessary for the purposes for which it was collected, there may also be circumstances that will require the retention of data for a longer period of time, however this will typically be for legal purposes.
3.2 Professional contacts
Business contacts are individuals or organizations that we use to provide a service on our behalf or for toulipaflowers.gr. The personal data from our contacts, which cover both potential and previous customers, can be found in the customer relationship management tool (CRM tool).
This information is entered into the system after contact between an employee of the online store toulipaflowers.gr and an individual or professional contact.
3.2.1 Why do we process data?
When keeping personal data about business contacts, they are used for various purposes, as follows:
Promotion and development of our services.
Hosting and facilitating events.
Relationship management.
Administration and management.
3.2.2 What data do we keep?
Personal data that can be stored in the CRM tool includes, but is not limited to, name, email address, physical address, job title, and contact details.
3.2.3 How long does the data last?
We retain the personal data we process from us for as long as is deemed necessary for the purposes for which they were collected.
3.3 Our human resources
We collect personal data about our people, in the context of the administration, management and promotion of our business activities.
Our staff handbook and partnership agreement further explain how personal data about our staff and associates is maintained.
3.3.1 Applicants
When a person submits a job application at toulipaflowers.gr. personal data is collected through the application process.
There are several purposes for collecting personal data for applicants.
Work.
We process the personal data of an applicant in order to evaluate his potential employment at toulipaflowers.gr.
Administration and management.
We may also use this personal data for up-to-date management decisions and for management purposes.
The personal data collected for applicants shall be kept for as long as is necessary to fulfill the purpose for which they were collected or for a maximum of one year, if such reasons are no longer necessary.
3.4 Suppliers
We collect and process personal data about suppliers, subcontractors and their affiliates. The data is used to manage our relationships, contract and receive services from them, and in some cases to provide professional services to our customers.
3.4.1 Why do we process data?
Receipt of goods and services.
We process personal data in relation to our suppliers and their staff as required to obtain the Services.
Providing services to our customers.
When a supplier helps us to provide professional services to our customers, we process personal data about the people involved in providing the services in order to manage our relationship with the supplier and the relevant people and to provide such services to our customers.
Management and development of our businesses and services. We process personal data in the course of our work, including:
- managing our relationships with suppliers.
- the development of our businesses and services (such as identifying customer needs)
- improvements in service delivery
- the maintenance and use of computer systems.
- hosting or facilitating the organization of events;
- the management of our website and our systems and applications.
Safety, quality and risk management activities.
We have established security measures to protect the information of our customers and their customers (including personal data), which include the detection, investigation and resolution of security threats. Personal data may be processed as part of our security monitoring. For example, automated crawling to detect malicious emails. We have implemented policies and procedures for monitoring the quality of our services and risk management in relation to our suppliers. We collect and maintain personal data as part of our supplier procurement procedures. We monitor the services provided for quality purposes, which may involve the processing of personal data.
We operate in compliance with any requirement of law, regulation or professional body of which we are a member.
We are subject to legal, regulatory and professional obligations. We need to maintain certain records to show that we are complying with these obligations and that these files may contain personal data.
3.4.2 What data do we keep?
We will retain the names of the suppliers, the names of the contacts and the contact details of the suppliers.
3.4.3 How long does the data last?
We retain the personal data we process for as long as is deemed necessary for the purpose for which they were collected. The data may be retained for longer periods when required by laws or regulations and in order to establish, exercise or defend our legal rights.
4. PEOPLE WHO USE OUR WEBSITE
When users visit our site, personal data is collected both through automated monitoring and through interaction with various forms on the site or applications (collectively referred to as sites).
Personal data may be collected when individuals fill out forms on our sites or respond to us by telephone, email or otherwise. This includes the information provided when a person registers data to use our sites, subscribe to our service, do a survey.
For more information, visit the Cookie Policy
5. RESPONSE TO PERSONAL DATA
We will only share personal data with others when we are legally permitted to do so. When we share data with others, we set up contractual arrangements and security mechanisms for data protection and compliance with data protection, confidentiality and security standards.
The personal data held by us can be transferred to:
Third party organizations that help us offer goods, services or information
Fraud prevention agencies
Law enforcement agencies or regulatory bodies or those required by law.
Occasionally, we may receive requests from third parties for authorization to disclose personal information, such as to check compliance with applicable laws and regulations, to investigate an alleged crime, to create, to exercise or to defend legal rights. We will only fulfill requests for personal data, where we are allowed to do so in accordance with applicable law or regulation.
6. TREATMENT INSTALLATIONS
Where possible, personal data may be transferred and stored at a destination outside the European Economic Area (EEA). It may also be processed by staff working outside the EEA and working for us. We will take all reasonable steps to ensure that your data is treated securely in accordance with this privacy statement.
We have taken steps to ensure that all personal data is provided with adequate protection and that all transfers of personal data outside the EU are legal. When we transfer personal data outside the EU to a country not defined by the European Commission as an adequate level of personal data protection, the transfers will be the subject of an agreement that meets the EU requirements for the transfer of personal data outside the EU.
7. RIGHTS OF INDIVIDUALS
- Individuals have certain rights over their personal data and data controllers are responsible for enforcing these rights as follows:
- Individuals can request access to the personal data they hold as data controllers.
- Individuals may ask us to correct the personal information they submit to us or, if necessary, to contact us through the relevant site registration page or by modifying the personal information retained in the relevant applications with which they were registered.
- Individuals may request that we delete their personal information.
- Where we process personal data on the basis of consent, individuals may withdraw their consent at any time by contacting us or by clicking the unsubscribe link in a message received from us.
- Individuals may have other rights to restrict or oppose the processing of our personal data and the right to transfer data.
- Individuals can request information about human intervention in any automated data processing we may undertake.
8. COMPLAINTS
We hope you will never need to, but if you want to complain about the use of your personal data, send an email with the details of your complaint to [email protected]. We will review and respond to any complaints we receive.
You always have the right to complain to the data protection regulator.
9. DATA CONTROL AND COMMUNICATION
The data controller of toulipaflowers.gr is the Tulipa Flower Shop (Bardas Konstantinos).
If you have any questions about this privacy statement or how and why you process personal data, please contact us at [email protected].
10. CHANGES TO OUR DECLARATION OF PERSONAL DATA PROTECTION
Updates to this privacy statement will appear on this site. This privacy statement was last updated on 11/13/2021.