Data privacy policy – Communications & marketing
PURPOSE
STOP ΑΕΒΕ respects the confidentiality and protects your personal data.
The Privacy Policy for Data Protection describes how we collect and use your personal data for informing you on issues of personal protective equipment and the improvement of the services we offer according to the General Data Protection Regulation (GDPR) 2016/679 of the European Union and the relevant provisions of the existing Greek legislation on the protection of personal data. There is always the possibility of you opt-out from receiving any informational material.
We are obliged by law to update you on the content of this policy.
This policy is not part of any contract of employment or contract of service.
This policy may change content or be modified at any time.
It is recommended that you read this policy carefully describing the collection and processing of your personal data for you to know how and why we use this information.
DESCRIPTION
DATA PROTECITON OFFICER
We have appointed a Data Protection Officer (DPO) to oversee the compliance with this privacy notice. If you have any questions about this privacy statement or how we handle your personal information, please contact us using the following ways:
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
You have also the right to submit a complain about data protection issues at any time to the supervisory Authority for the Protection of Personal Data in Greece (Kifisias 1-3, P.C. 115 23, Athens, Call Center: + 302106475600, Fax + 302106475628, email [email protected]).
DATA PROTECTION PRINCIPLES
Our principles are based on the principles set out in this European legislation. Personal data shall be:
- Processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’).
- Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’).
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’).
- Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’).
- Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organizational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’).
- Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (‘integrity and confidentiality’).
DATA WE HOLD
Personal data or personal information means any information relating to a person where on the basis of this information, can be identified and/or detected. It does not include data where the identity has been removed (anonymous data).
On cases and for the purpose of communicating with you, we can collect, store and use the following personal data:
- Customer Name and Surname
- Customer’s Email
- Answers given (e.g. In cases of sending Customer Satisfaction Survey questionnaires)
HOW WE COLLECT OR WILL COLLECT YOUR PERSONAL DATA
STOP ΑΕΒΕ collects or will collect your personal data with your consent on the case and for the purpose of business communication. This information may be derived by third parties if you have given your prior consent.
If you do not wish to collect your personal data, please refer to further details in a next paragraph.
RECIPIENTS OF YOUR PERSONAL DATA
We limit access to your personal information to those employees and other third parties who have a business reason to know and who will process your personal information in accordance with our instructions as well as the obligation for confidentiality.
Recipients of your data are employees and personnel in managerial positions of our Company, both parent and subsidiary and members of the group who are responsible for:
- A) The management of relevant Information received throughout our customer relationship. And
- B) The management and supervision of information systems and applications.
In addition, it may be a member of our Board of Directors that has any legal right to know about the Information and data on customer’s satisfaction in order to safeguard the company’s legitimate interest and defend the company’s name against third parties.
DATA SECURITY
We have put in place measures to protect the security of your information.
We have put in place appropriate security measures to prevent accidental loss, use or access to your personal information in an unauthorized manner, alteration or disclosure.
We have put in place procedures to deal with any suspicion of data security breach and will notify you promptly and any public entity responsible for investigating a suspected breach, as we are legally and morally obliged to do so.
Every third party as mentioned above is required to respect data protection and comply with the relevant legislation. It is also required to take all necessary measures to protect your personal data according to the existing legislation and in connection with our policies and procedures. They are not allowed to use your data for their own purposes other than for the specific purposes referred to in this policy. The same terms will apply if we need to transfer your data outside European Union members. If we do this, we assure you that we will demand the same degree of protection of your personal data.
Details of these measures are available on request to the Data Protection Officer.
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
DATA RETENTION
Our company maintains your personal data fulfilling the objectives set out so far and far beyond this for every auditing purpose. We retain your personal data for 1 year unless you have subscribed to our newsletter where the retention period lasts until you unsubscribe.
Your personal data is stored electronically in the company’s web space and in printed form in storage lockers.
Our company after the aforementioned period will safely destroy your personal information.
RIGHT OF ACCESS, RECTIFICATION, ERASURE AND RESTRICTION OF PROCESSING YOUR PERSONAL DATA
Under certain circumstances by law you have the right to access, modify or delete your personal information. More specifically:
- Right to Access: You have the right to access your personal information in order to receive a copy of the personal information we have kept about you and check that we are processing it legally.
We will provide the information for free and within one month, except where the request is unfounded, excessive or repetitive, so we reserve the right to charge management fees or alternatively may refuse compliance under these conditions.
- Right to Rectification: It is your duty to inform us of changes in the personal information we hold about you so that is accurate and current. By this, inaccuracies or deficiencies will be corrected without delay and in a period of one week.
- Right to Erasure: You can request to erase or remove specific personal information. You have also the right to ask us to delete or remove your personal data where you have exercised your legal right to object to the processing (see below).
- Right to Restriction of Processing: In particular cases where the processing of your personal information for specific purpose is not necessary under the Legislation and policies of our company, you are entitled to object to at any time.
- Right to Data Portability: You retain every right to transfer your personal data to a third party after written communication to our company giving consent to this operation.
For each request you can contact the Data Protection Officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
RIGHT TO WITHDRAW CONSENT
In limited cases where your consent to the collection, processing and retention of your personal information for specific purpose is not necessary under the Legislation and policies of our company, you have the right to object to at any time.
To withdraw your consent, please contact the Data Protection Officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
Once we receive the notice that you have withdrawn your consent, we will no longer process your information for the purpose or purposes that you initially agreed, unless we have another legal basis to do so by law.
CHANGE OF SCOPE
We will use your personal data only for the purposes for which we have collected, unless we reasonably believe that we should use them for another reason and this reason is compatible with the original purpose.
If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so.
Please note that we may process your personal information without your knowledge or consent in accordance with the above rules, where required or permitted by law.
CHANGES TO THIS PRIVACY POLICY
We reserve the right to update this privacy statement at any time and we will provide you with a new privacy notice when we make important updates. We may also notify you in other ways from time to time regarding the processing of your personal information.
If you have any questions about this Privacy statement, please contact the Data protection officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
If you do not agree with the content of this policy or have any objection, please let us know at [email protected]
The Management
Data privacy policy – Candidates
PURPOSE
STOP AEBE respects the confidentiality and protects your personal data.
The Candidate Data Protection Policy describes how we collect and use your personal Data during the process of sourcing and selecting candidates in order to fill a vacancy in our company in accordance with the General Data Protection Regulation (GDPR) 2016/679 of the European Union and the relevant provisions of the existing Greek legislation on the protection of personal data.
This policy applies to Candidates wishing to join STOP AEBE.
This policy is not part of any contract of employment or contract of service.
This policy may change content or be modified at any time.
It is recommended that you read this policy carefully and any other policy of our company that describes the collection and processing of your personal data so that you know how and why we use this information.
DESCRIPTION
DATA PROTECTΙON OFFICER
We have appointed a Data Protection Officer (DPO) to oversee the compliance with this privacy notice. If you have any questions about this privacy statement or how we handle your personal information, please contact us using the following means:
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
You have also the right to submit a complain about data protection issues at any time to the supervisory Authority for the Protection of Personal Data in Greece (Kifisias 1-3, P.C. 115 23, Athens, Call Center: + 302106475600, Fax + 302106475628, email [email protected]).
DATA PROTECTION PRINCIPLES
Our principles are based on the principles set out in this European legislation. Personal data shall be:
- Processed lawfully, fairly and in a transparent manner in relation to the data subject (‘lawfulness, fairness and transparency’).
- Collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes. Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (‘purpose limitation’).
- Adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (‘data minimization’).
- Accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (‘accuracy’).
- Kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods insofar as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organizational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (‘storage limitation’).
- Processed in a manner that ensures appropriate security of the personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organizational measures (‘integrity and confidentiality’).
DATA WE HOLD
Personal data or personal information means any information relating to a person where on the basis of this information, can be identified and/or detected. It does not include data where the identity has been removed (anonymous data).
During the recruitment process, we collect, store and use the following personal data which are sent after candidate’s consent:
- Personal Data that are mentioned in the curriculum vitae and/or the cover letter which the candidate has provided to our company, such as:
- Name, surname, residence address, telephone number fixed and/or mobile telephony, E-mail address, date of birth, marital status, photograph, studies, work experience, computer knowledge, knowledge of foreign languages, thesis, publications, projects, contact information for referees giving recommendations (Name, surname, fixed and/or mobile telephone number, e-mail address).
- Sensitive Personal Data mentioned in the curriculum vitae and/or the cover letter that the candidate has provided to our company, including:
- Sex, nationality, political opinions, religious or philosophical beliefs, participation in a trade union, health status, sex orientation, criminal prosecutions and convictions.
- Personal data collected during the evaluation of the candidate in the stage of personal interviews, tests and any other means of evaluation chosen by our company including:
- Name, surname, evaluation score as well as comments.
- Personal data collected during the process of checking references, such as:
- First name, surname, telephone numbers of fixed and/or mobile telephony, E-mail address, job title and name of the company where the referees chosen are working.
- Sensitive personal data collected for the candidate selected to cover a certain position as written in the Criminal Record which the Candidate is responsible for submitting to the company along with the other hiring documents, including:
- First name, surname, date and country of birth, Father’s name, Mother’s name, identity card number/Passport/residence permit/identity card for expatriates as well as the public authority and year of issuance, place (full address) of residence, criminal prosecutions and convictions.
HOW YOUR PERSONAL INFORMATION IS COLLECTED
We collect your personal data during the process of sourcing and evaluating candidates directly from the candidate or by recruitment consultants or by websites providing recruitment services.
We may collect information from third parties during evaluation through your named referees.
RECIPIENTS OF PERSONAL DATA
Recipients of your personal data are the employees of our company who are responsible for evaluating your Curriculum Vitae or application, your recommendation letter, the test and the information collected through the reference check.
They can also be employees of our company who are not responsible but to whom you have voluntarily contacted to send your CV or to submit your application to our company.
Finally, recipients of your personal data may be employees of Recruitment Companies or websites providing search services and you have addressed or registered your curriculum vitae and/or the reference letter.
HOW YOUR PERSONAL DATA ARE USED
We will use your personal data we have collected to:
- Evaluate skills, competencies and your suitability for the role.
- Carry out background and reference check, where applicable.
- Contact you during the process of sourcing and selecting candidates.
- Keep records related to our hiring process.
- Comply with legal requirements.
Our company evaluates the candidates based on objective criteria related to the profile of the job and on principles of equality and diversity that govern our operations.
We will also use information concerning your health status only to adapt and facilitate the selection process (e.g. If you are experiencing a health problem, we will adjust the test).
Finally, we will process the information provided in your Criminal Record for possible convictions only if this is relevant to the job role. We will only ask you for this information when we would like to offer you the role and after we have concluded with the stage of the reference check and other requirements.
CHANGE OF SCOPE
We will use your personal information only for the purposes for which we have collected them, unless we reasonably believe that we should use them for another reason and this reason is compatible with the original purpose.
If we need to use your personal information for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so.
Please note that we may process your personal information without your knowledge or consent in accordance with the above rules, where required or permitted by law.
DATA SECURITY
We have implemented measures to protect the security of your information. Details of these measures are available on request.
Third parties (employees of recruitment companies or websites that provide candidates recruitment services and you have addressed or registered your CV and/or the recommendation letter) will process your personal information only in accordance with our instructions and if they have agreed to handle the information confidentially and keep it safe.
We have implemented appropriate security measures to prevent accidental loss, use or access to your personal information in an unauthorised manner, alteration or disclosure.
In addition, we limit access to your personal information to those employees and other third parties who have a business reason to know. They will only process your personal information in accordance with our instructions and are subject to a confidentiality obligation. Details of these measures can be obtained by the Data Protection Officer:
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 80
We have put in place procedures to deal with any suspected data security breach and will notify you on time as well as any public authority responsible for investigating a suspected breach, where we are legally and morally obliged to do so.
DATA RETENTION
We will retain your personal information for a period of 2 months after we have communicated to you our decision about whether to appoint you for the role.
Data of successful candidates (such as curriculum vitae, reference letter, test/Exercises, Interview Assessment form, Consent Form for Recommendation, Recommendations Results, Copy of Criminal Record), will be kept in their employment record. This will be limited to the information necessary for the employment relationship and, where appropriate, required by law. This information in both hard copy and electronic format, is transferred and handled by the Human Resources Department.
In case you are not selected for that vacancy, the reason we keep your personal data during that period, is to prove in the event of a legal claim, that we have not committed discrimination against candidates for prohibited reasons and that we have conducted recruitment in a fair and transparent manner. After this period, we will safely destroy your personal information in accordance with our data retention policy. If we wish to keep your personal data beyond this period, we will inform you and will ask you for your written consent.
RIGHT OF ACCESS, RECTIFICATION, ERASURE AND RESTRICTION OF PROCESSING YOUR PERSONAL DATA
Under certain circumstances by law you have the right to access, modify or delete your personal information. More specifically:
- Right to Access: You have the right to access your personal information in order to receive a copy of the personal information we have kept about you and checked that we are processing it legally.
We will provide the information for free and within one month, except where the request is unfounded, excessive or repetitive, so we reserve the right to charge management fees or alternatively we may refuse compliance under these conditions.
- Right to Rectification: It is your duty to inform us of changes in the personal information we hold about you so that is accurate and current. By this, inaccuracies or deficiencies will be corrected without delay and in a period of one week.
- Right to Erasure: You can request to erase or remove specific personal information. You have also the right to ask us to delete or remove your personal data where you have exercised your legal right to object to the processing (see below).
- Right to Restriction of Processing: In particular cases where the processing of your personal information for specific purpose is not necessary under the Legislation and policies of our company, you are entitled to withdraw at any time.
- Right to Data Portability: You retain every right to transfer your personal data to a third party after written communication to our company giving consent to this operation.
For each request you can contact the Data Protection Officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
RIGHT TO WITHDRAW CONSENT
In limited cases where your consent to the collection, processing and retention of your personal information for specific purpose is not necessary under the Legislation and policies of our company, you have the right to object to at any time.
To withdraw your consent, please contact the Data Protection Officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
Once we receive the notice that you have withdrawn your consent, we will no longer process your information for the purpose or purposes that you initially agreed, unless we have another legal basis to do so by law.
CHANGES TO THIS PRIVACY POLICY
We reserve the right to update this privacy statement at any time and we will provide you with a new privacy notice when we make important updates. We may also notify you in other ways from time to time regarding the processing of your personal information.
If you have any questions about this Privacy statement, please contact the Data protection officer
Email: [email protected]
Address: Agiou Dimitriou 39 and Anapafseos 2-4, 18546, Piraeus, Greece
Phone Number: 0030 210 46 26 800
If you do not agree with the content of this policy or have any objection, please let us know at [email protected]
The Management