PrivacyPolicy

Protecting your personal data is our priority. Read how we collect, use and protect your information in accordance with GDPR.

Last updated: January 2025
GDPR & Greek Law Compliance

General Overview

Basic principles of data protection

Law 4624/2019, GDPR 2016/679

This Privacy Policy has been drafted in accordance with the General Data Protection Regulation (GDPR - 2016/679) and Law 4624/2019 which incorporates Directive 2016/680.

It forms an integral part of the terms of use of our services and governs the collection, processing and protection of your personal data.

We are committed to transparency, security and compliance with the highest data protection standards required by Greek and European legislation.

Personal Data Collection

What data we collect and why

Articles 5, 6, 7 GDPR

We collect exclusively the personal data that is necessary for the provision of our renovation services:

Identity data: Full name, home/work address

Contact details: Phone, email, mailing address

Financial data: Tax number, payment details (when required)

Technical data: Space photos, measurements, technical specifications

Collection is done with your explicit consent and for specific, clear and lawful purposes.

We do not process sensitive data (Article 9 GDPR) without explicit consent.

Legal Basis and Purpose of Processing

Why and how we use your data

Article 6 GDPR, Law 4174/2013

The processing of your personal data is based on lawful bases according to Article 6 of the GDPR:

Contract performance: For the provision of renovation services we agreed upon

Legitimate interest: For service improvement and communication

Legal obligation: For compliance with tax and accounting obligations

Consent: For marketing and updates (with the possibility of withdrawal)

Processing purposes include:

- Cost estimation and quote provision

- Work coordination and communication

- Billing and financial management

- Warranty maintenance and after-sales support

Security and Protection Measures

How we protect your data

Articles 32, 33, 34 GDPR

We implement appropriate technical and organizational security measures according to Article 32 of the GDPR:

Data encryption in transmission and storage

Restricted access based on 'need to know' principle

Regular backups and data recovery plans

Staff training on data protection matters

Confidentiality agreements with partners

Regular risk assessments and security audits

In case of a data breach, we will notify the Data Protection Authority within 72 hours as required by law.

Data Retention and Deletion

How long we keep your data

Article 17 GDPR, Law 4174/2013

We retain personal data for specific periods in accordance with Greek legislation:

Customer data: 5 years from the last transaction (Law 4174/2013)

Financial data: 5 years for tax purposes (Tax Code)

Project technical data: 10 years for warranties and liabilities

Marketing data: Until consent withdrawal

After the deadlines expire, data is securely deleted.

You can request deletion of your data at any time (right to be forgotten).

Your Rights (GDPR)

Complete list of your rights

Articles 12-22 GDPR, Law 4624/2019

According to the GDPR and Law 4624/2019, you have the following rights:

Right to information (Articles 13-14): Complete information about processing

Right of access (Article 15): Copy of the data we process

Right to rectification (Article 16): Correction of inaccurate data

Right to erasure/be forgotten (Article 17): Data deletion under conditions

Right to restriction (Article 18): Processing restriction

Right to portability (Article 20): Receive data in structured format

Right to object (Article 21): Objection to processing

Right to withdraw consent: At any time for consent-based processing

To exercise your rights, please contact us in writing.

Cookies and Tracking Technologies

How we use cookies and analytics

ePrivacy Directive, Law 3471/2006

Our website uses cookies in accordance with the ePrivacy Directive and Law 3471/2006:

Essential cookies: For basic website functionality

Preference cookies: To store your settings

Statistical cookies: Google Analytics for anonymous traffic statistics

Marketing cookies: Only with your consent

You can manage cookie preferences:

- Through the consent banner on first visit

- From your browser settings

- Via the 'Cookie Settings' button in the footer

Rejecting certain cookies may affect functionality.

Sharing with Third Parties

When and with whom we share data

Articles 28, 44-49 GDPR

We do not sell, lease or trade your personal data. Sharing occurs only:

With partners/subcontractors: For work execution (with processing agreements)

With service providers: Cloud hosting, email, payments (with appropriate safeguards)

With public authorities: When there is a legal obligation (tax office, courts)

With your consent: For specific purposes you have approved

All third parties are contractually bound to protect data.

For international transfers (outside EU), we ensure adequate level of protection.

Important Notice

This privacy policy may be updated periodically to comply with legislative developments. Any significant changes will be communicated in advance.

Quick Contact

For data protection matters:

privacy@christosfeinaj.gr