1. Collection and processing of personal data
At operation of the website and the online store www.vardavasoptics.gr of the VARDAVAS OPTICS (Akadimias 18, 10671, Athens) we collect and process personal data. The collection and processing of personal data is done in accordance with the General Regulation for Data Protection (EU) 2016/679 (GDPR), law 4624/2019 and law 2472/1997. Please read our policy regarding the collection and processing of your personal data carefully.

2. How we collect data
You can browse the website without giving any personal information, but we may collect data.
We collect data that you share with us when you place an order, when you create a user account, subscribe to our newsletter or when you send us an email.

3. What data we collect and why

BROWSING THE WEBSITE
Data we collect: Geolocation, IP address, device and connection you use, browser, operating system, access provider, URL
Purpose of processing: The smooth operation and use of the website
Legal basis: Securing company interests
How long we keep the data: The duration of the browsing

PLACING AN ORDER
Data we collect: Name, address, telephone, email, VAT number, Tax Office (in case of invoice issuance)
Purpose of processing: Execution of order
Legal basis: The processing of your data is necessary for the execution of the contract and for our compliance with the applicable tax laws
How long we keep the data: The data are kept for as long as it is necessary to achieve the purposes of their collection and processing, and for five (5) years after its completion, subject to our compliance with a provision that makes it mandatory to maintain them for a longer period.

PLACING AN ORDER
Data we collect: Ophthalmological measurements, prescription from an ophthalmologist
Purpose of processing: Execution of order
Legal basis: The consent you provide to us for the processing of your data and the fact that the processing of your data is necessary for the execution of your order
How long we keep the data: The data are kept for as long as it is necessary to achieve the purposes of their collection and processing, and for five (5) years after its completion, subject to our compliance with a provision that makes it mandatory to maintain them for a longer period.

SUBSCRIPTION TO NEWSLETTER
Data we collect: Name, email
Purpose of processing: Personalized communication, marketing
Legal basis: The consent you provide to us for the processing of your data in order to contact you regarding your order and for any other purpose, safeguarding the interests of the company or third parties, advertising purposes
How long we keep the data: Until the withdrawal of the consent or until the anonymization of the data

CREATE A USER ACCOUNT
Data we collect: Email, creating username and password
Purpose of processing: Personalized communication, marketing, prevention of electronic fraud 
Legal basis: The consent you provide to us for the processing of your data, the fact that processing is necessary to safeguard the legal interests of the company and our customers, on the one hand to prevent any attempts at electronic fraud and on the other hand for the advertising purposes of our company.
How long we keep the data: Until the withdrawal of the consent (deletion of account)

CREATE A USER ACCOUNT THROUGH SOCIAL MEDIA
Data we collect: Name, Email, Date of Birth, Gender and any other details you have declared as public
Purpose of processing: Personalized communication with you, marketing, prevention of electronic fraud
Legal basis: We collect the above data for the purposes of our personalized communication with you and marketing
How long we keep the data: Until the withdrawal of the consent

IN CASE YOU SEND US YOUR CV
Data we collect: Name, date of birth, residence, education and previous service data
Purpose of processing: Examination of the possibility of cooperation 
Legal basis: The consent you provide to us for the processing of your data, the safeguarding of company interests
How long we keep the data: Until the withdrawal of the consent, otherwise up to three (3) years

Additionally, credit card details are collected on our behalf by the online payment service company EveryPay.

4. Disclosure of personal data to third parties
For the purposes of the execution of your orders, as well as for the purposes described in this privacy policy, it is necessary to disclose your information to our staff, as well as to third parties, natural or legal persons, with whom we cooperate for the following:
- to transport companies, for the execution of your order.
- to banks and online payment service providers, to ensure the validity and security of payment.
- to persons or companies who provide us with technology and information services.
- to persons or companies that provide us with legal and accounting services.
- to providers of marketing and advertising services of our products, social networking sites.
We may also disclose your information to third parties, in case we are required to do so by law or court order.

5. Data security
All appropriate and specific measures shall be taken to safeguard the interests of the data subject.
All data is stored on network servers, which operate under a high level of security and which are protected from improper use and are not accessible by unauthorized persons.
In particular, all data are kept encrypted and are not accessed by unauthorized persons. Only the persons necessary to execute your order have access to the health data.

6. Cookies
We use cookies in order to facilitate your browsing of the website and your purchases. Cookies are used to store products in your cart, to monitor the progress of your order, etc.
Cookies are small text files that are stored on your computer or mobile device while browsing the web. They are used to store the preferences and the data you enter (eg language preferences, data entered in forms, etc.) for a short period of time, so that you do not have to re-enter this information the next time you visit the website.
Activation of cookies is not mandatory for the operation of the website and the e-shop. You can choose not to install cookies through the browser you use. In this case, some of the features of the website may not work satisfactorily.

What cookies do we use and why?
Some cookies are necessary to allow you to browse our website, use its features, and access secure areas in it. The use of these cookies is crucial for the function of the website. For example, we use user-input cookies for the duration of a session to keep track of a user’s input when filling in forms that span several pages.
We also use functional cookies to remember choices you’ve made or information you’ve provided (such as username, language, or the region you are in), so we can adjust your website experience specifically to your preferences. For example, authentication cookies are functional cookies that are used for the duration of a session (or persistent, if you use the “remember me” function) to allow users to authenticate themselves on subsequent visits or to gain access to authorized content. The functional cookies we use include:
User-centric security cookies to detect authentication abuses for a limited duration (for example) repeated failed login attempts. These cookies are set for the specific task of increasing the security of the service.
Multimedia content player session cookies (flash cookies) are used for the duration of a session to store technical data needed to play back video or audio content (e.g. image quality, network link speed, and buffering parameters).
Load balancing session cookies are used for the duration of the session to identify the same server in the pool so that the load balancer can redirect user requests appropriately.
User interface customization persistent cookies are used to store a user’s preference regarding a service across web pages.
We use reporting and analytics cookies to collect information about how you use our website or our merchants’ storefronts, and how often, in order to improve our website. These cookies only gather information for statistical purposes and only use pseudonymous cookie identifiers. The performance cookies we use include:
First party analytics cookies - We use these cookies to estimate the number of unique visitors, to improve our website, and to detect the most searched for words in search engines that lead to a webpage. These cookies are not used to target you with online marketing. 
Third party analytics cookies - We also use Google Analytics and other third-party analytics providers listed below to help measure how users interact with our website content. 
Advertising cookies are used on our website to adjuct marketing to you and your interests. These cookies remember your visit on our website and we may share this information with third-parties, such as advertisers. Although these cookies can track your device’s visits to our website and other sites, they typically cannot personally identify you. Without these cookies, the advertisements that you see may be less relevant and interesting to you. 
Finally, Social and Content cookies are placed by many social media plugins (for example the Facebook ’like’ button), and other tools meant to provide or improve the content on a website (for example services that allow the playing of video files, or that create comments sections). We integrate these modules into our platform to improve the experience of browsing and interacting with our websites. Please note that some of these third party services place cookies that are also used for things like behavioural advertising, analytics, and/or market research.

These are the third party cookies that are used:
Shopify
https://www.shopify.com/legal/cookies
Facebook & Instagram
https://www.facebook.com/policy/cookies/
https://help.instagram.com/1896641480634370?ref=ig
Google Analytics
https://policies.google.com/privacy
Google Ads
https://policies.google.com/privacy

7. Website user rights in relation to personal data
You have the following rights regarding the collection and processing of your personal data:

 • Right of access
You have the right to access your personal data that we collect and to receive information about their processing.

• Right to receive a copy
You have the right to request and receive a copy of your personal data that we collect.

• Right tο rectification
You have the right to request the rectification of any inaccurate data concerning you, as well as the completion of incomplete data, by sending a relevant email to the email address info@vardavasoptics.gr.

• Right to erasure
 You have the right to request the erasure of personal data concerning you. 

 • Right to restriction of processing
You have the right to obtain restriction of processing of your personal data under certain circumstances.

 • Right to data portability 
You have the right to receive the personal data concerning you in order to be transferred to another party.

• Right to object to the processing
You have the right to object at any time to the processing of your personal data in cases where the processing is done for the purpose of marketing and protection of our interests. 

 • Right to withdraw consent
You have the right to revoke your consent to the processing of your data at any time. In this case, please send an email to the email address: info@vardavasoptics.gr.

• Right of complaint to the Hellenic Data Protection Authority.
You have the right to submit a complaint to the Hellenic Data Protection Authority (www.dpa.gr),  1-3 Kifissias Av., PO 115 23, Athens, Telephone Nr.: +30 210 6475600, E-mail: contact@dpa.gr

8. Modifications to the Privacy Policy
We reserve the right to modify the Privacy Policy at any time. In that case, we will inform you by publishing a relevant notice and / or in any other way.

9. Data protection officer
Data protection officer: A. ΚΑΤΡΙΤSI AND CO L.P. (distinctive title: VARDAVAS OPTICS)
Adress: 18,  Αkadimias str., Αthens, 10671
Τel. Nr.: +30 2103611211 
Email:  info@vardavasoptics.gr