PRIVACY POLICY

Updated: May 25, 2018

Costarellos, company number 998872425, with registered office at 55, Vasilissis Sofias Avenue, 11521, Athens Greece, take your data protection rights and our legal obligations seriously. This Privacy Policy ("Policy") describes how we use your personal data collected via costarellos.com ("Website") or transmitted to us by XXXXXXXX.

Please read this Policy carefully.

The personal data that you provide may be regarded as controlled by Costarellos Ltd.

1. Personal Data We May Collect About You
We will collect various types of personal data about you for the purposes described in this Policy, including:

  • - Contact information (such as your name, birthday, nationality, email address, postal address, telephone number and any other personal data) that you provide by completing forms on the Website, including if you subscribe to our newsletter and register and create an account on the Website
  • - Personal data that may be contained in communications you send to us, for example to report a problem or to submit queries, concerns or comments regarding the Website or its content
  • - Information from surveys that we may, from time to time, conduct on the Website for research purposes, if you choose to respond to, or participate in, them
  • - Personal information collected from third parties, such as data that you agree to share with us on publicly accessible social networks (e.g., Facebook, Instagram, etc.) and/or that we may collect from other publicly accessible databases.

You are under no obligation to provide any such information. Providing your personal data to us  (in particular, your personal details, your email, your address and your telephone number) is necessary for supplying other services provided on the Website upon your request, or when your personal data is needed to fulfil obligations required by law or regulations. The refusal to provide us  with any personal data necessary for performing the above purposes may consequently prevent us from including you in various promotional and informational activities (events, sales etc.) or fulfilling obligations required by law and other regulations.

Disclosure of further personal data to us other than that required for fulfilling legal or contractual obligations and to properly browse our services with necessary traffic data is, on the contrary, optional and does not have any effect on the use of the Website and of its services. We will inform you at every step whether disclosing your personal data to us is required or optional by marking with an appropriate symbol (*) the information that is required or data needed for the purchase of products and/or for the provision of requested services on the Website.

 

2. Minimum Age
Protecting the safety and privacy of children is very important to us. We will not knowingly collect or use personal data from anyone under the age of sixteen (16) years, or any other age limit set out by the law of his/her country of residence. By registering on the Website, you confirm that you have reached the age of majority in your country of residence.

 

3. Use Made of Your Personal Data
Whenever we process your personal data, we do so on the basis of a lawful "justification" (or legal basis) for processing. In the majority of cases, the processing of your personal data will be justified on one of the following bases:

  • - processing is necessary to perform a contract with you or take steps that you have requested in order to enter into a contract (e.g., sale contract)
  • - processing is necessary for us to comply with a legal obligation
  • - processing is in our legitimate interests as a business, and our interests are not overridden by your interests, fundamental rights or freedoms. Our legitimate interests may include our interest in using customer and Website user personal data to conduct and develop our business activities (including by carrying out standard marketing activities) ,with current and potential customers and Website users; and in establishing, exercising or defending legal claims, or
  • - processing is based on your prior explicit consent, such as segmented and customized marketing activities.

 

4. Disclosure of Your Personal Data
We may disclose your personal data to any of our affiliate companies, or to our service providers who assist us in providing the services we offer, processing transactions, fulfilling requests for information, receiving and sending communications, updating marketing lists, analysing data, providing support services or in performing other tasks, from time to time.

For the avoidance of doubt, we will get your express opt-in consent before we share your personal data with any third party company other than Costarellos Ltd for marketing and promotional purposes.

Your personal data will be accessible by authorized personnel of Costarellos and affiliated companies, and service providers acting on our behalf on a need-to-know basis.

We may also share your personal data with third parties in connection with potential or actual sale or restructuring of our company or any of our assets, or those of any associated company, in which case personal data held by us about our users may be one of the transferred assets.

We will also respond to requests for personal data where required to do so by law, or when we believe that disclosure is necessary to protect our rights and/or comply with a judicial proceeding, court order, request from a regulator or any other legal process served on us.

 

5. Security
We place great importance on the security of all personal data associated with our users. We have adopted security measures to protect personal data against accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access. For the best possible protection of your personal data outside the limits of our control, your device should be protected (such as by updated antivirus systems) and your internet service provider should take appropriate measures for the security of network data transmission (such as, for example, firewalls and anti-spam filtering).

While we take reasonable steps to protect your personal data, we cannot guarantee that the personal data you disclose to us will be 100% secure, nor that any data breach will not occur.

You accept the inherent security implications of dealing on-line over the Internet and will not hold Costarellos' or their processors responsible for any data breach unless it is due to our negligence.

 

6. Retention of Your Personal Data
Our general approach is to retain your personal data only for as long as required to fulfil the purposes for which it was collected. We generally retain your personal data for three years from the end of our relationship or from the last contact from you, unless local law requires otherwise. However, in some circumstances we may retain personal data for longer periods of time, for instance where we are required to do so in accordance with legal, tax and accounting requirements.

In specific circumstances we may also retain your personal data for longer periods of time corresponding to the applicable statute of limitations so that we have an accurate record of your dealings with us in the event of any complaints or challenges.

 

7. Your Rights
You have the following rights with respect to your personal data:

Right to withdraw consent - where applicable, you have the right to withdraw your consent at any time. For example, if you wish to opt-out of receiving electronic marketing communications, you can change your settings in your account on the Website, use the 'unsubscribe' link provided in our emails or otherwise contact us directly and we will stop sending you communications.
Right of access, rectification and erasure - you have the right to request access to and obtain a copy of any of your personal data that we may hold, to request correction of any inaccurate data relating to you and to request the deletion of your personal data under certain circumstances. You can see and update most of this data yourself online, or by contacting directly info@costarellos.com.
Right of data portability - Under certain conditions, you have the right to receive all such personal data which you have provided to us in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
Right to restriction of processing - you have the right to restrict our processing of your personal data where:
- you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
- the processing is unlawful but you do not want us to erase the data;
- we no longer need your personal data for the purposes of the processing, but you require such data for the establishment, exercise or defence of legal claims; or
- you have objected to processing justified on legitimate interest grounds (see below) pending verification as to whether we have overriding compelling legitimate grounds to continue processing.

Where personal data is subject to restriction in this way, we will only process it with your consent or for the establishment, exercise or defence of legal claims, in accordance with local legislation.
Right to object to processing justified on legitimate interest grounds - where we are relying upon legitimate interest to process personal data, then you have the right to object to that processing. If you object, we must stop that processing unless we can either demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where we need to process the data for the establishment, exercise or defence of legal claims. Where we rely upon legitimate interest as a justification for processing we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
Right to object to processing for marketing purposes - where we process personal data for direct marketing purposes, then you have the right to object to that processing at any time.

You also have the right to lodge a complaint with a supervisory authority if you consider that the processing of your personal data infringes applicable law.

For further information regarding your rights, to exercise any of your rights, or if you have any complaints or questions regarding the processing of your personal data please contact info@costarellos.com.

Please note that we may request proof of identity, and we reserve the right to charge a fee where permitted by law, for instance if your request is manifestly unfounded or excessive. We will endeavour to respond to your request as soon as possible and in any case within the applicable timeframes.

 

8. Changes to this Policy
We may occasionally change this Policy, for example, to comply with new requirements imposed by the applicable laws or technical requirements. We will post the updated Policy on the Website. We may also notify you in case of material changes and seek your consent to those changes, where required by applicable law. You are thus encouraged to periodically review this page.