Privacy Policy
Our Company conducts its business activities in accordance with privacy principles, applying ethical and responsible practices.
The applicable legislation defines our standards for the management and protection of your Personal Data, so that you are provided with the maximum possible security.
These principles ensuring protection of your personal information apply to all types of our activities involving the collection and processing of information about individuals, including but not limited to research, production, commercial activities, corporate support and data transfers.
Indicatively, this Policy applies to:
- Promotional and commercial activities: evaluation of markets regarding our products/advertising, marketing, sales, distribution and delivery of our products/communication with our customers and other end users of our services/sponsorship and event organization
- Corporate support: recruitment, management and compensation of employees/conducting performance and talent evaluations of employees/provision of training/management of issues related to ethics and privacy/management and safeguarding of our assets and infrastructure/procurement and payment for products and services/fulfillment of our commitments regarding environment, health and safety/communication with the media.
These Policy applies to all natural persons whose data we process including customers, candidates and partners.
Accordingly, every employee of the Company, and third parties who process data for our company, are responsible for understanding and complying with their obligations under this Policy and the applicable laws.
The privacy principles described below summarize the standards and basic requirements for the collection and processing of personal data by our company.
Personal data:
- are processed lawfully and fairly in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”),
- are collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (“purpose limitation”),
- are adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”),
- are accurate and, where necessary, kept up to date (“accuracy”),
- are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of the processing of personal data (“storage limitation”),
- are kept in a form which permits identification of data subjects for no longer than is necessary for the purposes of the processing of personal data (“storage limitation”),
1. Necessity - data minimization
- Before collecting, using or distributing Personal Data, we determine and record the specific, lawful business purpose being served.
- We determine and record the time period for which Personal Data is used for defined business purposes, which is set per case depending on the nature and type of activity.
- We do not collect, use or share more Personal Data than necessary and we do not retain Personal Data in identifiable form for longer than necessary for the defined business purposes.
- We anonymize data when business or legal requirements make this necessary, as well as when information related to the activity or process must be retained for a longer period.
- We ensure that these necessary requirements are embedded in supporting technologies and that third parties supporting the activity or processing are informed.
2. Lawfulness, Fairness and Transparency
- We do not process Personal Data in ways that are unfair to individuals to whom the data relates.
- We determine whether the proposed collection, use or other processing of Personal Data poses a risk of actual or potential harm to individuals, always aiming to prevent it.
- If the nature of the data, the types of people or the activity involve an inherent risk of actual or potential harm, we ensure that this risk does not outweigh the corresponding benefits for those individuals.
- Where processing of special categories (“sensitive”) Personal Data is necessary, it is carried out only with the explicit consent of individuals or as required or explicitly permitted by applicable laws.
- We record risk analysis and design any required mechanisms for obtaining and documenting consent in supporting technologies. We do not process Personal Data in ways or for purposes that are not transparent.
- All individuals whose Personal Data is processed under this Policy shall have the right to a copy of this Policy, published online. The Data Protection Officer will provide digital and/or physical copies of this Policy upon request at the addresses listed below.
- When Personal Data is collected directly from individuals, we inform them through a clear and easily accessible privacy notice or similar means, providing them with the following information:
- the identity and contact details of the data controller
- the purposes of processing
- if processing is based on legitimate interests of the controller, what those interests are
- the recipients of the personal data
- any data transfers
- the retention period of the data
- the existence of the right to request access, rectification or deletion of personal data or restriction of processing
- where processing is based on consent, the right to withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal
- the right to lodge a complaint with the Data Protection Authority
- the legal nature of the provision
- the possibility of automated decision-making
- If new reasonable business purposes are identified for already collected Personal Data, we ensure that either the new business purpose (including a substantially similar purpose) is compatible with the purpose described in the privacy notice or other transparency mechanism previously provided to the individual, or we obtain the individual’s consent for the new use of their Personal Data.
- We are responsible for maintaining the privacy and security of Personal Data when transferred from or to other organizations.
- We transfer Personal Data or allow it to be processed by third parties only if the following conditions are met, for which we are responsible.
- If the role of the third party is to process Personal Data on behalf of or to safeguard the company’s vital interests, before the third party receives the Personal Data, we:
- complete legal due diligence to assess privacy practices and risks related to those third parties,
- obtain written contractual assurances from those third parties that they will process Personal Data in accordance with our company’s instructions and this Policy.
- ensure that they will notify us in a timely manner of any Security Incident and agree to cooperate when necessary.
- if the role of the third party is to provide Personal Data to our company, before obtaining the Personal Data from the third party, we ensure that transparency requirements for collecting Personal Data from other sources are met and obtain written contractual assurances from the third party that it does not violate any Law or third-party rights by providing Personal Data to our company.
- if the role of the third party is to receive data from our company for processing not specifically under our company’s supervision, before providing the data to the third party, we ensure that the third party will use the data only for the defined business purposes specified in the agreement and in accordance with applicable law.
3. Data Quality, Integrity and Confidentiality
We maintain Personal Data accurate, complete and up to date, and in accordance with its intended use.
- We ensure that periodic data review mechanisms are embedded in supporting technologies to validate data accuracy.
- We ensure that Sensitive Data is validated as accurate and current before use, evaluation, analysis, reporting or other processing which carries a risk of unfairness if inaccurate or outdated data is used.
- In case of changes to personal data, the data subject is responsible for informing our company so that necessary updates can be made.
We implement safeguards to protect Personal Data and Sensitive Data.
- We have implemented a comprehensive information security program and security controls based on the sensitivity of information and the level of risk of the activity, using best practices of modern technology. Policies for protection against loss, misuse, unauthorized access, disclosure or destruction include but are not limited to business continuity and disaster recovery standards, identity and access management, information classification, information security incident management, network access control, physical security and risk management.
4. Rights of Access, Rectification, Erasure, Portability, Restriction of Processing and Objection to Processing
You have the right to access your personal data.
This means you have the right to be informed by us whether we process your Data. If we process your Data, you may request information about the purpose of processing, the type of Data we hold, to whom we disclose it, how long we store it, whether automated decision-making is used, as well as your other rights such as rectification, erasure, restriction of processing and lodging a complaint with the Data Protection Authority.
You have the right to rectification of inaccurate personal data.
If you find that there is an error in your Data, you may request us to correct it (e.g. name correction or address update).
You have the right to erasure / right to be forgotten.
You may request that we delete your data if it is no longer necessary for the above-mentioned processing purposes
You have the right to data portability.
You may request to receive your Data in a readable format or request that we transfer it to another controller
You have the right to restriction of processing
You may request that we restrict the processing of your Data for as long as the examination of your objections is pending.
You have the right to object to the processing of your Data.
You may object to the processing of your Data or withdraw your consent and we will stop processing your Data, unless there are other overriding legitimate grounds.
To exercise your rights you may send us a relevant request describing the right you wish to exercise either to the postal address of the Company "K.P SUPER WASH LTD" marked “Exercise of right of access/rectification/erasure/restriction/objection”, or to the email address: info@superwash.com.cy with subject “Exercise of right of access/rectification/erasure/restriction/objection”, describing your request and we will ensure it is reviewed and answered as soon as possible
We respond to your requests free of charge without delay and in any case within one (1) month from receipt. However, if your request is complex or there is a large number of requests, we will inform you within one month if an extension of two (2) additional months is required.
If your requests are manifestly unfounded or excessive, in particular due to their repetitive nature, the Company may charge a reasonable fee or refuse to act on the request, taking into account administrative costs. You have the right to lodge a complaint with the Data Protection Authority (postal address Kifisias 1-3, Athens/www.dpa.gr), if you believe that the processing of your Personal Data violates the applicable national and regulatory framework for data protection.
Terms you should know:
Anonymization. The alteration, removal or transformation of Personal Data so that it can no longer be used to identify, locate or contact an individual.
Legislation. All laws, rules, regulations and legally binding opinions.
Personal Data. Any data relating to an identified or identifiable individual, including data that identifies the person or could be used to locate, track or contact them. Personal Data includes direct identifiers such as name, ID number or job title, as well as indirect identifiers such as date of birth, phone number and coded data.
Privacy Incident. A breach or violation of this Policy or a privacy/data protection law. Determination of whether a privacy incident has occurred will be made by the Data Protection Officer and Legal/Compliance Department.
Processing. Any operation or set of operations performed on data relating to individuals, whether or not by automated means, including but not limited to collection, recording, organization, storage, access, adaptation, alteration, retrieval, use, analysis, reporting, dissemination, disclosure, transmission, alignment, restriction, erasure or destruction.
Security Incident. Unauthorized access to Personal Data or disclosure to an unauthorized person, or reasonable suspicion thereof. Access by or on behalf of the company without intent to violate this Policy does not constitute a Security Incident, provided the data is subsequently used and disclosed only as permitted.
Sensitive Data. Any type of data relating to individuals that carries an inherent risk of harm, including legally defined sensitive data such as health, genetics, race, ethnic origin, religion, political or philosophical beliefs, criminal record, precise geolocation, financial account numbers, government-issued identifiers, minors, sexual life, trade union membership, social security and other employment or state benefits.
Third Party. Any legal entity, organization or individual that does not belong to our company or is not controlled by it. Unless otherwise specified, no part of the company is required to comply with third-party requirements under this Policy, as all subsidiaries and departments must process data in accordance with this Policy.
Changes to this Policy
This Policy may be revised from time to time in accordance with applicable law. Whenever it is materially changed, a notice will be posted on our website.
Dispute Resolution
You are informed that in case any dispute arises from our transaction and cannot be resolved amicably, you may use the Online Dispute Resolution platform at webgate.ec.europa.eu/odr/ which is connected to the competent independent authority “Consumer Ombudsman” www.synigoroskatanaloti.gr You may submit a request for dispute resolution and our company may then be contacted by the competent Authority at the email: info@superwash.com.cy
We also inform you that our Company recognizes in good faith the advisory nature of the Authority’s decisions and is not bound by their enforceability. In any case of non-amicable resolution through the ODR platform, the competent courts shall have jurisdiction.
You may read the Electronic Commerce Consumer Code of Conduct as published in the Government Gazette