Privacy Policy

Privacy Policy – Policy for the protection of personal data (the “Policy”)

Latest update: 12.9.2020

Content:

  1. Subject matter of the Policy
  2. Definitions
  3. Controller – Data Protection Officer
  4. Personal data processed
  5. Collection and processing of personal data
  6. Personal data of minors
  7. Data retention
  8. Sharing of Personal data
  9. Use of Cookies
  10. Your rights
  11. Links to third-party sites
  12. Amendments and updates to this Policy
  13. How to contact us

 

  1. Subject matter of the Policy

We fully respect the privacy of your personal data and make every effort to protect them, in accordance with applicable legislation, including the REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation - GDPR) and Statute No Ν. 4624/2019.

This Privacy Policy aims to inform the users of this website regarding the manner and purpose of the collection and processing of their personal data by Pharmaceutical Laboratories CANA SA (“Cana”), responsible for processing and owner of the website c-sept-antiseptics.myshopify.com, as well as explain their rights and choices regarding such data.

This Privacy Policy applies only to personal data that may be collected and processed on this website and does not apply to any other collection and processing of personal data that Cana may conduct.

WIN MEDICA SA may provide additional information about the confidentiality of the information to users of the site in individual sections of it as their personal data are collected on a case-by-case basis. These notices are supplemented in each case by this Privacy Policy.

By providing personal data to Cana, you consent to the collection and processing thereof by our company for the purposes of, and in accordance with the terms described in, this Privacy Policy. The provisions for the protection of personal data contained herein supplement the Terms of Use of our website.

 

  1. Definitions

Personal Data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Special Categories of Personal Data” means Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.

Data Concerning Health” means personal data relating to the inherited or acquired genetic characteristics of a natural person which give unique information about the physiology or the health of that natural person and which result, in particular, from an analysis of a biological sample from the natural person in question.

Processing”means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.

Processor” means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.

Data Protection Officer” means the natural person appointed by the Controller and the Processor for the purposes provided in the applicable legislation based on his/her professional qualifications and expertise in the field of data protection legislation and practices, with a primary role to be involved in all matters relating to the protection of personal data.

Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.

Applicable Legislation” means the provisions of Greek, EU or other legislation applicalbe upon Cana and determining data protection issues, including:

– Statute 2472/1997 for the protection of the individual from the processing of personal data,

– Statute 3471/2006 on the protection of personal data and privacy in the field of electronic communications,

– Directive 95/46/ΕC of 24.10.1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data,

– Directive 2002/58/ΕΚ of 12.7.2002, on the processing of personal data and the protection of privacy in the field of electronic communications, as amended,

– Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation),

Statute 4624/2019.

 

  1. Controller

Pharmaceutical Laboratories CANA S.A., 446 Irakliou Avenue, Iraklio – 14122 – Attica, Greece

Tel: +30 210 2883300

Email: info@cana.gr

Webpage: www.cana.gr

Data Protection Officer (DPO) 

Pharmaceutical Laboratories CANA S.A., 446 Irakliou Avenue, Iraklio – 14122 – Attica, Greece

Tel: +30 210 2883300

Email: regulatorydpt@cana.gr

 

  1. Personal data we process

When you visit the Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. Additionally, as you browse the Site, we collect information about the individual web pages or products that you view, what websites or search terms referred you to the Site, and information about how you interact with the Site. We refer to this automatically-collected information as “Device Information”. 
We collect Device Information using the following technologies: 
- “Cookies” are data files that are placed on your device or computer and often include an anonymous unique identifier. For more information about cookies, and how to disable cookies, visit http://www.allaboutcookies.org. 
- “Log files” track actions occurring on the Site, and collect data including your IP address, browser type, Internet service provider, referring/exit pages, and date/time stamps. 
- “Web beacons”, “tags”, and “pixels” are electronic files used to record information about how you browse the Site. 
Additionally when you make a purchase or attempt to make a purchase through the Site, we collect certain information from you, including your name, billing address, shipping address, payment information (including credit card numbers ), email address, and phone number. We refer to this information as “Order Information”. 
When we talk about “Personal Data” in this Privacy Policy, we are talking both about Device Information and Order Information. 

 

  1. Collection and processing of personal data

By simply visiting this website, the Internet Service Provider may automatically collect information (eg IP address, operating system used to connect to the website, date and browser type, the language and settings, the external links that you follow on the website and your activity on it) to enable the technical operation of the website itself and the best provision of information to you depending on your device. This information is recorded as statistical files or log files. The Browsing Data is usually deleted after processing anonymously, but may be stored and used by our company to identify and identify the perpetrators of any computer crimes committed against or via this website. Without prejudice to this feature and the provisions of the Cookies Policy, the browsing data described above are only temporarily stored, in accordance with the law.

Otherwise, your personal data may be used for the purpose of communicating with you or for the purposes that are communicated to you each time before their collection. Cana has taken the appropriate technical and organizational measures to keep your data secure and protected from unauthorized access. However, you should be aware that no organization can guarantee the absolute security of information, especially information transmitted via the Internet.

With your consent, we may process your personal data to ensure that you can take advantage of the available services and functions provided on this website, collect statistics on its use, manage requests, queries and reports received through the site from you as well as your registration in any areas of it.

With your consent, we may use your Personal Information to provide you with targeted advertisements or marketing communications we believe may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work. 
You can opt out of targeted advertising by using the links below: 
- Facebook: https://www.facebook.com/settings/?tab=ads 
- Google: https://www.google.com/settings/ads/anonymous 
- Bing: https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads 
Additionally, you can opt out of some of these services by visiting the Digital Advertising Alliance’s opt-out portal at: http://optout.aboutads.info/. 

We may also process your personal data for the fulfillment of our legal obligations under the Applicable Legislation. We may also use your Personal Data:

  • if we are asked to do so because of an applicable law, or a request from public and state authorities (including court orders, subpoenas or government regulations), even outside your country of residence;
  • if we need to enforce our Terms of Service;
  • when we believe in good faith that the processing of Personal Data is necessary to protect the legal rights, security or integrity of this website;
  • to protect your safety or the safety of others;
  • as part of any criminal or other legal investigation or proceedings in your country or in other countries; or
  • to the extent reasonably necessary for the development or continuation of the negotiation or completion of a corporate or commercial transaction.

The collection and processing of personal data by our company is effected in accordance with existing legislation, in full compliance with the GDPR and with full respect for the principles of the law governing the processing, in order to ensure security and confidentiality

 

  1. Personal data of minors

Use of this website is not intended for children under 16 years of age. In any case, our policy is not to knowingly process any kind of personal data processing of a person under 16 years of age. By using the website you confirm that you are over sixteen (16) years old. If you are under sixteen (16) years old you have the obligation to refrain from any use of the website as well as from any provision of your personal data without the approval of your parent or legal guardian.

If you do not comply with the above obligations, you must immediately notify our company. In any case, by using the website you acknowledge that our company is not responsible for the breach of the above obligations by you to the extent that it is not able, even if it makes reasonable efforts, to verify your age or consent of your parent or legal guardian.

 

  1. Data Retention

Your personal data is stored by Cana only for as long as is required to fulfill the purpose for which they were collected, as described in this Privacy Policy, based on their nature, any contractual relationship governing their storage and the relevant legal obligations of our company. This data is deleted (or anonymized) when the purpose of their processing ceases to exist, in accordance with existing legislation.

When you place an order through the Site, we will maintain your Order Information for our records unless and until you ask us to delete this information.

 

  1. Sharing of Personal data

Your Personal Data may be transferred to third parties acting on our behalf.

Your Personal Data may also be disclosed to third parties if we are required to do so by applicable law, court order or government act (including summons or government regulation), even outside your country of residence, if required to enforce our Terms o Service, when we believe in good faith that the disclosure of Personal Data is necessary to protect the legal rights, security or integrity of this website, in order to protect your security or the safety of others, in the course of any criminal or other legal investigation or proceedings in your home country or abroad, or to suppliers, consultants and other legal entities, to the extent reasonably necessary for the development or continuation of the negotiation or completion of a corporate or commercial transaction.

The above third parties have a contractual or legal obligation to use your Personal Data solely for the agreed purpose, not to disclose it to third parties, unless required by applicable laws or regulations or otherwise stated in this Privacy Policy.

We also share your Personal Information with third parties to help us use your Personal Information, as described above. For example, we use Shopify to power our online store--you can read more about how Shopify uses your Personal Information here: https://www.shopify.com/legal/privacy. We also use Google Analytics to help us understand how our customers use the Site -- you can read more about how Google uses your Personal Information here: https://www.google.com/intl/en/policies/privacy/. You can also opt-out of Google Analytics here: https://tools.google.com/dlpage/gaoptout

 

  1. Use of Cookies

Cookies are small text files that a website stores on your computer or mobile device when you visit that website. This way, the site remembers your actions and preferences for a period of time, so you do not have to enter those preferences every time you visit the site or browse its pages. Cookies do not collect information individually, but when read by a server through a web browser they can provide information to provide a more user-friendly service. In order to learn more about cookies (what are cookies, which cookies are used on our website, what information is collected and how you can control it, please refer to the Cookies Policy.

 

  1. Your rights

Under the current legislation on the protection of personal data, you have the following rights, for which in any case you can contact our company using the contact details found below:

  1. To request confirmation as to whether or not personal data concerning yourself are being processed and the categories of personal data concerned;
  2. To be granted access to such data or request a copy thereof;
  3. To request rectification or completion thereof if you believe they are inaccurate or incomplete;
  4. To request erasure thereof. In this case, we shall erase them, unless there exists a legal reason on the basis of which we are entitled to keep them;
  5. To request restriction of processing thereof;
  6. To revoke your consent to the collection and processing of your personal data;
  7. To submit a complaint to the competent supervisory authority, in this case to the Personal Data Protection Authority (Website: www.dpa.gr, Postal Address: 1-3 Kifissias Avenue, PC 23 23, Athens, Call Center: +30 210 6475600, Fax: +30 210 6475628, E-mail: contact@dpa.gr).

We shall respond to your request within one (1) month. In case the request is complex or there is a large number of requests, we shall inform you if an extension of another two (2) months will be required. If the requests are manifestly unfounded or excessive, in particular because of their repetitive nature, we may refuse to follow up on the request, giving the reasons for our such reply.

 

  1. Links to third-party sites

This website may contain links to third-party websites. If you follow these links, you will leave this website and, therefore, the scope of this Privacy Policy. Under no circumstances are we responsible for the privacy practices or policies of third-party websites as we can not guarantee the security of your browsing on them. In this context, we encourage you to read the privacy statements of each and every website that collects personally identifiable information. This privacy statement only applies to information collected from our site.

 

  1. Amendments and updates to this Policy

We reserve the right to modify and / or update this Privacy Policy at any time. Please check our Privacy Policy regularly. In case of updating and / or substantial changes to this Privacy Policy, a relevant publication will take place on this website and the "update date" will be modified accordingly. You may also be informed in other ways, via email or other contact information provided by you through this website.

 

  1. How to contact us

You may contact us for any questions, comments, complaints regarding this Privacy Policy, to exercise any of the above rights, to submit a request or to request access to and / or correction of your personal information.

Contact information:

C-Sept Antiseptics

Pharmaceutical Laboratories CANA S.A.

446 Irakliou Avenue, 14122 Iraklio, Attica, Greece

Tel.: +30 210 2883300

Email: regulatorydpt@cana.gr