CY • BG • BOX NOW SHIPPING
Privacy policy
1. Data Controller
The Data Controller of the personal data is the sole proprietorship of PSYLLOU ELEFTHERIA, with the trade name hellonna enjoy nature, located at 15 Kleious St., P.C. 17778, Tavros (Municipality of Moschato – Tavros), with the contact email info@hellonna.gr. The Company collects and processes personal data in strict compliance with the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR), as well as relevant Greek legislation.
2. Categories of Data Collected
The Company collects and processes specific categories of User/Customer data for the smooth operation of the e-shop and the execution of orders. These include:
- Identification Data: First and last name.
- Contact Details: Billing address, email, and telephone number.
- Delivery Information: Shipping address and necessary information for transport services.
- Payment Information: Transactions are processed via Stripe and Klarna. The Company does not store or have access to card details.
- Transaction Data: Order history and purchase details.
- Technical Data: IP address, cookies, browser and device information.
- Communication Data: Any information provided by the User via email or contact forms.
3. Purposes of Processing and Legal Basis
The Company processes personal data based on specific legal grounds and for clearly defined purposes:
- Performance of a Contract: Managing and processing orders, payments, and product shipments.
- Compliance with a Legal Obligation: Maintaining necessary tax and accounting records as required by law.
- Legitimate Interest: Improving services, ensuring system security, and preventing fraud.
- Consent: Processing for newsletter subscriptions, participation in promotional activities, or the use of marketing cookies is conducted exclusively upon the User's explicit consent.
4. Data Recipients
User/Customer personal data may be transferred to third-party partners exclusively for the fulfillment of the defined purposes. These include:
- Shopify (e-commerce platform provider).
- Partner Courier Services for product delivery.
- Payment Providers (Stripe and Klarna).
- Partner Accounting and Tax Services.
- Email Marketing Providers and technical associates responsible for hosting, security, and e-shop system support.
- Advertising Platforms: The Company may use Meta Platforms (Facebook, Instagram) tools for advertising and analytics. Meta may receive data via cookies or pixels according to its own privacy policies, subject to the User’s prior explicit consent.
5. Data Transfer Outside the EU
Some of the Company’s partners, such as Shopify, Stripe, and Klarna, may transfer and store data in countries outside the European Economic Area (EEA). In such cases, the transfer is conducted in full compliance with the GDPR and is based on appropriate safeguards, such as Standard Contractual Clauses (SCCs) approved by the European Commission, and the implementation of adequate technical and organizational measures by the providers.
6. Data Retention Period
Personal data is retained for as long as necessary to fulfill the contract and for the period required by tax legislation, which is set at a minimum of five (5) years. Data collected based on consent for newsletters is retained until such consent is withdrawn by the User. The Company also retains necessary data for a reasonable period for system security and fraud prevention. Upon expiry of these periods, data is permanently deleted or securely anonymized.
7. Cookies and Tracking Technologies
The Company uses cookies to ensure technical functionality, analyze traffic, improve the user experience, and for advertising purposes upon consent. Users can manage their preferences and choose which categories of cookies to enable via the cookie banner that appears upon entering the e-shop.
8. Rights of the Data Subject
The User possesses a series of rights regarding their personal data, including:
- Right of Access to their data.
- Right to Rectification of inaccurate information.
- Right to Erasure (“right to be forgotten”).
- Right to Restriction of Processing.
- Right to Data Portability.
- Right to Object or Withdraw Consent at any time. To exercise these rights, requests must be submitted in writing to: info@hellonna.gr.
9. Data Security
The Company implements appropriate technical and organizational measures to protect personal data against accidental loss, unauthorized access, alteration, or any form of unlawful processing. These measures are reviewed and updated as necessary to ensure a high level of protection.
10. Changes to the Privacy Policy
The Company reserves the right to modify this Privacy Policy whenever deemed necessary. Any changes will be published on the e-shop and will take effect immediately upon posting.
11. Contact Information
For any issues or clarifications regarding the protection of your personal data and the exercise of your rights, you may contact us directly at: info@hellonna.gr.