PRIVACY POLICY
For the company Emmanouil Michalakis AVEGTKE (MICHALAKIS ESTATE) the protection of personal data is of primary importance and is treated with the utmost seriousness. Respect for the personal data we manage and ensuring their proper processing is one of the priorities of our Company.
For this reason, we take all appropriate technical and organizational measures to protect the personal data we process and to ensure that their processing is always carried out in accordance with the requirements set by the current legal framework (Law 4624/2019) and especially by the General Data Protection Regulation (EU) 2016/679 (GDPR).
1. WHO ARE WE (CONTROLLER)
The company Emmanouil Michalakis AVEGTKE acts as a Controller for all personal data it collects, registers, organizes, structures, stores, alters, retrieves, processes, transmits, restricts or deletes.
company Emmanouil Michalakis AVEGTKE
Address: P Street, Industrial Area, GR-71601, Heraklion, Crete, Greece
Phone: +30 2810 381303
For issues related to the processing and general management of personal data you can contact us by email dpo@michalakis.gr .
2. OUR WEBSITES
The Company Emmanouil Michalakis AVEGTKE in order to better serve you has created and manages the following websites https://www.michalakis.gr, και https://eshop.michalakis.gr :
https://www.michalakis.gr is the website of our company from which you can be informed about corporate news, about our events and our products.
https://eshop.michalakis.gr is the online store of the Company, through which you can see and buy online the wine products we produce.
3. DEFINITIONS (article 4, GDPR)
Personal data means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
Processing means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Profiling means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.
Controller means the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Processor means a natural or legal person, public authority, agency, or other body which processes personal data on behalf of the controller.
Consent of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
4. WHAT DATA DO WE COLLECT AND PROCESS?
We collect and process personal data for the purpose of marketing and selling wine and other alcoholic beverages from our own production. We take care to collect absolutely only your necessary personal data, which is appropriate and clear for the intended purpose.
For the provision of these services to its customers, the company Emmanouil Michalakis AVEGTKE (Michalakis Estate) collects and processes the following personal data:
- Data when creating a user account in our online store:
Required (necessary): e-mail address *, name *, surname *, postal address *, telephone number *
Optional: login password.
- Details of your transactions with us, either through our physical store or through our online store
– For example, we collect notes from our conversations with you, details of any complaints or comments you make, details of purchases you made, products added to or removed from your cart, wish list you want to buy (wish list), coupon redemptions, websites you visit and how and when you contact us.
- Interests and shopping preferences, which help us to suggest you specific products that interest you.
– For example, which products do you prefer to receive a personalized offer from us.
- Information collected from the use of cookies in your browser. Learn more about how to use cookies here .
- Payment i
- Your social media username, if you interact with us through these channels, to help us respond to your comments, questions, or comments.
- Information on your education, such as studies, skills, knowledge of foreign languages, professional experience (only in cases where you apply for a job).
- CHILDREN
We comply with the law and do not allow children to register on our websites when they are under 16 years old.
For the safety of individuals and goods, the company operates a closed-circuit television (CCTV), through which images of customers, visitors and employees are recorded in the public spaces of our facilities. The registration is done according to the current legislation.
WHAT DO WE DO WITH THE INFORMATION WE COLLECT ABOUT YOU?
We want to offer you the best possible shopping experience. To achieve this, it is necessary to obtain a complete picture of you, combining the data we have collected. We then use your Data to offer you offers for products and services that you may be interested in.
Personal data protection legislation allows us to do the above in the context of our legitimate interest and the need to understand our customers in order to provide them with a high level of service.
Of course, if you ever want to change the way we use your data, you will find details in sections 9: “your rights as a data subject” and 10: “rights of complaint to the Hellenic Data Protection Authority”.
Remember, if you choose not to share the data with us or to refuse certain communication rights, we may not be able to provide some of the services you have requested. For example, if you have asked us to let you know when a product is available again, we may not be able to help you if you have withdrawn your general consent to receive updates from us.
Finally, we inform you that the processing of your data is carried out either by the specially authorized personnel of the Company, or through computer systems and electronic devices by the Company and exceptionally by third parties, who, having contractually committed to the confidentiality and protection of your data performs tasks that are necessary to achieve the purposes that are strictly related to the use of our websites, its services, and the sale of products through our websites. Information on this can be found below in section 9: “your rights as a data subject”.
Below you will find details on how we use your data and why:
To provide information for websites for:
- Product orders: The Company processes your data in order to fulfill its contractual relationship, to process product ordering, to provide customer service, to comply with legal obligations, to oppose, raise or enforce legal requirements. If we do not collect your data when completing the order either from our physical or from our online store, we will not be able to process your order and comply with our legal obligations. Your data may need to be passed on to third parties for the supply or delivery of the product you have ordered. In addition, we may retain your data for a reasonable period Product orders of time in order to meet our contractual obligations, such as product returns, as required by law.
- Creation a User Account: The Company processes your data in order to provide you with the account functions and to facilitate the conclusion of product purchase.
- Communication: The Company uses your data to respond to your requests / inquiries, refund requests and / or complaints. The information you share with us, enables us to manage your requests and respond to you in the best possible way. We may also maintain a record of your requests / inquiries to us in order to better respond to any future communication. We do this based on our contractual obligations to you, our legal obligations and our legitimate interests in order to provide you with the best possible service and to be able to improve our services based on your personal experience.
- Sometimes, we will need to share your Data with a third party that provides a service (such as courier delivery). Without sharing your personal data, we would not be able to satisfy your request.
- Apply for Job: The Company processes your Data for the evaluation of your qualifications and abilities for the position for which you applied or for another position within the Company as well as for reasons of communication with you in relation to this purpose.
For the communication of product information, as well as for other promotional purposes
- Newsletter / offers: With your consent, we will use your personal data, preferences, and transaction details to inform you via email, internet, telephone and / or social media about relevant products and services, including personalized / personalized offers, discounts, etc. Of course, you have the option to revoke this consent at any time.
- Web push notifications: Depending on your navigation, you can receive, having previously given your consent, notifications about our offers, news, your wish list and your shopping cart. Of course you can revoke this consent at any time.
- Participation in Competitions: The Company processes your data in case you agree to participate in competitions that it conducts, to notify you if you are a winner of the competition and to deliver your gift.
For the operation, improvement and maintenance of our business, products and services
- Development and improvement of systems and services for the products we provide. We do this based on our legitimate business interests.
- We want to offer you offers and suggestions that are more relevant to your interests. To help us develop a better and more general understanding of you as a customer, we combine your personal data gathered throughout our relationship, for example your shopping history in both our physical and online stores. To this end, we also combine the data we collect directly from you with data we receive from third parties to whom you have given your consent to transfer this data to us. We also use anonymous customer history data to track trends in different parts of the country.
- In order to send you research and evaluation requests so we can improve our services. These messages will not contain promotional content and do not require prior consent when sent by email or text message (SMS). We have a legitimate interest in doing so, as this helps our products to be more relevant to you. Of course, you are free to refuse to receive these requests from us at any time by updating your preferences to your online account.
For our (or third parties) protection of rights, assets or security
- Protect your account from fraud and other illegal activities: This includes using your data to maintain, update and protect your account. We also monitor browsing activity with us to quickly identify and resolve any issues and protect the integrity of our website. All of the above are part of our legitimate interest. For example, we check your password when you log in and use automated IP address tracking to detect possible false logins from unexpected locations.
- Operation of CCTV Systems: In order to protect our customers, premises, assets and associates from crime, we operate CCTV systems in our winery that capture images for safety. We do this based on our legitimate business interests. If we detect any criminal activity or alleged criminal activity through the use of CCTV, fraud monitoring and suspicious transaction monitoring, we will process this data for the purpose of preventing or detecting illegal acts. Our goal is to protect our customers, employees and associates from criminal activities.
- Processing payments and preventing fraudulent transactions: We do this based on our legitimate business interests. This also helps protect our customers from fraud.
For our compliance with our legal obligations
- In order to comply with our contractual or legal obligations to exchange data with law enforcement. For example, following a court decision to exchange data with judicial services.
- To communicate with you as required by law or necessary to inform you of changes in the services we provide. For example, updates on these privacy notices, product recall notices, and legally required information about your orders. These service messages will not contain promotional content and do not require prior consent when sent by email or text message (SMS). If we do not use your personal data for these purposes, we will not be able to comply with our legal obligations.
6. WHAT IS OUR PROCESSING PURPOSES & LEGAL PROCESSING BASIS
All the above personal data are collected and subjected to processing for the purpose of marketing and selling wine and other products from our own production. Some data can be used for purposes of information and commercial promotion of the services of the company Emmanouil Michalakis AVEGTKE, always after relevant consent.
Legal bases for data processing may be on a case-by-case basis:
- The execution of the contract between the company Emmanouil Michalakis AVEGTKE and its customers, in order to receive its services.
- The compliance of the company Emmanouil Michalakis AVEGEKE with its legal and regulatory obligations, arising from the current legal framework regarding the business activities of the Company.
- The promotion, preservation and protection of the legal interests of both the company Emmanouil Michalakis AVEGTKE and its customers, in case we need to support legal claims or to defend our rights and interests before the courts. Legal interests include, among others, the development and improvement of the services provided by the Company, as well as its smooth and constantly improving operation.
- The consent that can be given to us in order for our customers (existing or potential) to receive information about the services of the company Emmanouil Michalakis AVEGTKE, its business actions and activities etc.
7. WITH WHOM DO WE SHARE THE INFORMATION WE GATHER?
Your data are first accessed by the authorized employees of the company Emmanouil Michalakis AVEGTKE, in the context of the execution of their duties from their position (the absolutely necessary staff of the Company). Our staff is committed to confidentiality as well as our partner companies or third-party service providers, who process your data as Processors on our behalf and in accordance with our orders.
Your personal data can be transferred to third parties of the Company, always subject to confidentiality, integrity, and availability in any case. For example (indicatively mentioned) to a cooperating accountant, to a trading partner company, to credit card and payment processing companies, transfers and deliveries, hosting, management and maintenance of our data, email distribution, research and analysis, brand promotion management and products, Google, Facebook, and managing certain services and components. When we use third party service providers we enter into agreements that oblige them to implement appropriate technical and organizational measures to protect your personal data.
In addition, the data may be disclosed – as required and / or permitted by applicable law – to state authorities or public bodies, in order for the company Emmanouil Michalakis AVEGTKE to comply with its legal (legislative, regulatory, court decisions) or contractual obligations.
The policy we apply to those with whom we share your data in accordance with the above includes (indicative):
- Provide only the information needed to perform their specific services.
- License to use your data only for the exact purposes we specify in our contract with them.
- Ensuring the protection of your privacy.
- By stopping using their services, any of the data they hold will be deleted or anonymized.
Notification from you
When you use certain social media items on our sites, you can create a public profile that includes information such as username, profile picture and city. You can also share content with your friends or the general public, including information about your interaction with the Company. We encourage you to use the tools we provide to manage the Company’s social media sharing in order to control the information you make available through the Company’s social media components.
8. HOW LONG DO WE RETAIN YOUR DATA?
First, we store the data for at least as long as it takes to fulfill the processing purposes for which they were collected.
Some examples of customer data retention periods:
Orders:
When you place an order, we will retain the personal data you provided to us for 5 years, so that we can comply with our legal and contractual obligations.
Newsletter:
Your statement of consent for sending a newsletter is kept for as long as a newsletter is sent to you by the Company and in any case not more than 6 months from the cessation of sending it.
Finally, we keep the data for the period required by the legal framework that defines the business operation of the Company.
If the processing is based on your consent, the personal data will be kept until that consent is revoked. It is clarified that the withdrawal of consent does not affect the legality of the processing based on the consent before its withdrawal.
In any case, the company Emmanouil Michalakis AVEGTKE implements all appropriate technical and organizational measures to ensure the protection of personal data that it processes and constantly takes care to prevent any unauthorized access to this data.
9. YOUR RIGHTS AS A DATA SUBJECT
Regarding the processing of your personal data, you can exercise the following rights:
- Right of access
You have the right to know what data we hold and process, why and other additional information about them, as well as to request a copy of them.
- Right to rectification
You have the right to request the correction, modification and completion of your personal data.
- Right to erasure (“right to be forgotten”)
You have the right to request the deletion of your personal data when it is processed with your consent. In cases where the processing is based on another legal basis (such as the execution of a contract, a legal obligation, or the protection of the legal interests of the Company, etc.) this right may be subject to restrictions or may not exist.
- Right to restriction of processing
You have the right to request a restriction on the processing of your personal data:
- when their accuracy is questioned and until the relevant verification is done
- alternatively, instead of deleting them
- when they are no longer necessary for the processing purposes for which we collected them, but are necessary for the establishment, exercise, or support of legal claims by you
- when you have objections to their processing and until it is verified that there are legal reasons for this processing by the Company.
- Right to object to the processing and revocation of consent to the processing of your data
You have the right to object to the processing of your personal data when it is done on the basis of a legitimate interest, as well as for the purposes of direct marketing and profiling. Your right to object to editing includes automated decision making and profiling. If you have given your consent to the collection, processing and use of your personal data, you may revoke your consent at any time with future effect.
- Right to data portability
You have the right to request and receive your personal data in a form that allows you to access, use and process it using commonly used processing methods. In addition, for your data which we process with automated means and based on your consent or for the execution of a contract, you can ask us to transfer it directly to another controller, if this is technically possible.
- Right to withdraw consent
If the processing of your data is based on your consent, you have the right to revoke it at any time. Revoking your consent does not affect the legality of the processing based on the consent before revoking it.
For the exercise of your above rights and for any question, complaint, or other information regarding the processing of your personal data you can contact us at dpo@michalakis.gr .
We respond to your requests free of charge without delay, and in any case within (1) one month from the time we receive your request. However, if your request is complex or there is a large number of your requests, we will inform you within the month if we need to receive an extension of another (2) two months within which we will respond to you.
If your requests are manifestly unfounded or excessive, in particular due to their recurring nature, the Company may impose a reasonable fee, taking into account the administrative costs of providing the information or performing the requested action, or refusing to comply with the request.
10. RIGHTS OF COMPLAINT TO THE HELLENIC DATA PROTECTION AUTHORITY
If you think that your rights are being violated, you have the right to submit a complaint to the Hellenic Data Protection Authority
Address: 1-3 Kifissias, GR-11523 Athens
Call Center: +30210-6475600
Email: complaints@dpa.gr
Applicable Law is the Greek Law, as formulated in accordance with the General Regulation for the Protection of Personal Data 2016/679 / EU (GDPR), and in general the current national and European legal and regulatory framework for the protection of personal data.
The Courts of Heraklion are competent for any disputes arising related to your data.