Privacy Policy

Since 25-5-2018, new Regulation (EU) 2016/679, on the protection of personal data, has been implemented, aiming at strengthening this protection in all EU Member States.

A. ABOUT US

The protection of personal data is a basic principle in our company and a factor of trust for our employees, customers and suppliers.

GENERAL COMMERCIAL & INDUSTRIAL S.A. is active in the field of industrial and hydraulic equipment, being the most important supplier for Greece and the countries of Eastern Europe.

Our company's goal is to ensure the best solution for our customers by providing them with high quality products and services.

Our company, respecting the new Regulation and your personal data, is immediately implementing it.

This privacy policy shall apply to all information (i) related to clients within the framework of its business activity or business development, (ii) that relates to personal data obtained through its business relationship or provision of services with suppliers or to the market evaluation process (iii) pertaining to candidate employee data collected during the recruitment process iv) pertaining to visitors and clients of our corporate website v) related to customer data obtained during the customer care process vi) related to visitor data collected at the premises.

The Company is bound to protect the privacy of visitors’/clients’/suppliers’/candidate employees’/employees’ and of other data subjects and to adhere to the local and European Data Protection legislation currently in effect, implementing the key principles of the GDPR (lawfulness, fairness and transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality and accountability). The above apply without discrimination and apply to all processing we perform.

B. CATEGORIES OF COLLECTED DATA

As part of the CV evaluation process, personnel management, business activity with customers, suppliers and partners, communication with website users and visitor control at our facilities, we collect and process personal data with the aim of better organizing our relationship, serving and informing you. Information-Data that we collect are indicatively name, surname, patronymic, job title, gender, VAT number, ID number, date and place of birth, e-mail, telephone, browsing data, etc.

C. DATA TRANSFER TO THIRD PARTIES

Data subjects’ data will be transferred to the Company’s departments that are competent for the smooth and trouble-free provision of our services.

Your data may be transmitted and become accessible by legal entities (suppliers, subcontractors, etc.) with which we have entered into contractual agreements for the purpose of fulfilling our company’s statutory purpose. Our Company selects reliable providers, and we try to set contractual restrictions on third parties who receive your personal data, to ensure their lawful use. However, we cannot guarantee that they will not use or disclose this data without your permission. For this reason, we recommend that you carefully review the privacy practices of any third-party providers / products whose products or services you purchase through our websites.

In addition, our website may contain links that lead to other websites of third parties, independent entities, such as content providers, payment service providers, etc. which are operated and maintained solely by them, and which we do not control and therefore bear absolutely no responsibility for their content, actions or policies. Please read the respective privacy policies on the websites you visit carefully, as they may differ significantly from ours.

Personal data related to the invoicing processes may be transmitted and become accessed by bank institutions with which we cooperate to process our employees and suppliers’ payments, as well as to the competent state authorities in compliance with legal obligations. Such third parties may be official state and supervisory bodies (e.g. prosecutors, Cybercrime Division, Data Protection Authority, Hellenic Telecommunications and Post Commission, Independent Authority for Public Revenue etc.), in case we are called upon to comply with the law and prevent harm illegal actions against us and our customers.

Data subject’s personal data may be disclosed to cloud hosting providers for the purpose of storing and safeguarding the data with the appropriate technical and security measures.

During all data transfers, we always take all appropriate measures to ensure that the transmitted data is the minimum required for the intended processing purpose and that the conditions for legitimate and lawful processing will always be met.

D. DATA RETENTION PERIOD

The data retention period depends on the lawful basis of processing, as set out in detail below:

•   In case the lawful basis for processing is the exercise of legitimate interest, the processing of personal data is carried out if it is considered necessary for the achievement of the intended statutory purpose of the Company and until such time the limitation period of any related claims has expired.

•   In case the personal data are provided under the subjects’ own consent, we shall retain their data until the granted consent by the data subject has been withdrawn. In case the consent is withdrawn for any valid reason, we shall retain them for as long as it is required until the limitation period of any related claims expires.

•   In case the lawful basis for processing is the performance of the contract, we shall retain your data for as long as you retain the contractual relationship with us or we shall retain it for as long as it is required until the limitation period of any related claims expires.

•   In case where the processing of the personal data is based on a legal obligation (Article 6 of GDPR), the data retention period is set in accordance with the pertinent legislation and the limitation period for any inspections that may be performed by competent authorities.
Additional information in relation to the exact data retention periods may be provided by submitting your relevant request to our company.

Additional information in relation to the exact data retention periods may be provided by submitting your relevant request to our company.

E. DATA SECURITY MEASURES

The Company applies throughout the data processing procedure, the appropriate technical, physical, and administrative security measures for the protection and security of the personal data from loss, misuse, damage or modification, unauthorized access and disclosure, in compliance with article 32 of the GDPR 679/2016, to ensure the appropriate security level against those risks. Those include, among others, as the case may be: a) application of encryption protocols b) the ability to ensure confidentiality (article 32 GDPR 679/2016), integrity, availability, and resilience of processing systems and services on an ongoing basis, c) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident, d) a process for regularly testing, assessing and evaluating the effectiveness of technical and organizational measures for ensuring the security of the processing.

Moreover, the Company shall take measures to ensure that any natural person acting under the authority of the data controller, who has access to personal data, shall not process that data except on instructions from the data controller and limit access to your personal information to authorized employees.

F. RIGHTS OF THE DATA SUBJECTS

Under the new Regulation, extended rights are granted for and established as far as your personal data are concerned.

1. Right to be informed: You have the right to know accurately and clearly about the collection and use of your personal data.
2. Right of access: You have the right to get informed about the collection and processing of your personal data by our company, as well as the right to receive a copy thereof.
3. Right to rectification: You have the right to update and correct potential mistakes about your personal data.
4. Right to erasure: You can request the removal of your data from our company. Exceptionally, we may deny erasure in accordance with applicable law.
5. Right to restriction: You have the right to request a limitation in your personal data processing by our company.
6. Right to portability: You have the right to receive, in a structured, widely used and mechanically readable form, your personal data you have provided to us.
7. Right to object: You have the right to oppose the processing of your data for specific purposes, e.g. advertising.

For any information regarding our company's privacy policy and for the exercise of the above-mentioned rights, you may contact our Personal Data Protection Officer, Mr. Apostolos Vlachos, through an online form at our company web sites www.geb.gr or through emailing at dpo@prostasiadedomenon.gr or by calling at 2155050115.

These rights shall be exercised free of charge for you. In case however the rights are exercised excessively and without good cause thus causing us administrative burden, we may charge you with the cost related to the exercise of the respective right.

In case you exercise any of your rights, we will take all appropriate measures available for the satisfaction of your request within thirty (30) days following the receipt of the relevant request. We may either inform you of the acceptance of your request or on any objective grounds that hinder the processing of your request.

In any case, you may file a complaint with the Hellenic Data Protection Authority if you believe that the collection and processing of your data is in violation of applicable legislation.

G. AMENDMENTS

This policy may be renewed from time to time, due to amendments to the related legislation or change to the corporate structure. Therefore, we encourage you to periodically visit this site to be informed regarding recent information on privacy practices. In any case, you may be informed via e-mail or of a notice on our website regarding any amendments to this policy.