PERSONAL DATA STATEMENT
Statement of the Controller “Regarding the Protection of Personal Data”
The increasing economic and scientific collaborations as well as the mutual provision of data processing services result in the exchange of personal data, a trend that is reinforced by the ever-increasing use of modern telecommunications.
For these reasons, it is necessary to process data with care.
The Controller declares that compliance with the principles governing data protection for the processing thereof is its aim as it is committed to respecting individual rights and the privacy of individuals. The Controller handles personal data with special care and always in accordance with EU Regulation 2016/679, the applicable National Law and the applicable legislation.
For the purposes of this Directive, the following definitions shall apply:
Data Subject: any natural person whose personal data are processed by or on behalf of the Company
Personal Data: any information relating to an identified or identifiable natural person concerning his or her physical, physiological, psychological, emotional or economic situation, cultural or social identity.
Processing: processing of personal data (“processing”), any operation or set of operations which is performed on personal data, such as, but not limited to, collection, recording, storage, alteration, analysis, use, association, restriction (blocking), erasure or destruction.
1. Data Controller and DPO
The Data Controller is the Société Anonyme “SDOUKOS S.A.”, which is based in the Industrial Zone. Ioannina, Postal Code 45500, Ioannina, Tax ID 099803798 TAX OFFICE OF IOANNINON, E-mail info@sdoukos.eu ("Data Controller").
2.The Data We Process
With your consent, we process the following common and sensitive personal data that you provide when you interact with the Website (https://sdoukos.eu/) and use the services and functions it provides. These data include in particular your name and surname, contact details, address and the content of your specific requests, updates or reports as well as additional data that the Data Controller may obtain, including from third parties, in the context of carrying out its business activity ("Data").
In order to be able to fulfill the requests you submit through the contact form and/or to provide updates on adverse reactions, it is necessary for you to consent to the processing of the data marked with an asterisk (*).
Without this mandatory data or your consent, we cannot proceed further. On the contrary, the information requested in fields not marked with an asterisk and your consent to receive information material are optional and their failure to provide them has no consequence.
In any case, even without your prior consent, the Data Controller may process your data to comply with legal obligations arising from laws, regulations and EU law, to exercise rights in legal proceedings, to exercise its own legitimate interests and in all cases provided for, where applicable, in Articles 6 and 9 of the GDPR.
The processing is carried out both by computer and in paper form and always involves the application of the security measures provided for by applicable law.
3. Why and how we process your data
The data is processed for the following purposes:
(i) to handle the requests you submit using the ‘‘Form’’, to subsequently contact you or to provide you with information through it. The legal basis for the processing of personal data for this purpose is your consent (Article 6(1)(a) and Article 9(2)(a) of the GDPR) and the performance of the contract to which you are a party as a data subject;
(ii) to manage reports of adverse events submitted via the Website or the Forms. The legal basis for the processing for these purposes is your consent (Article 6(1)(a) and Article 9(2)(a) of the GDPR), as well as the pursuit of any public interest (Article 9(2)(i) of the GDPR) and legal obligations;
in addition, but only with your optional consent which constitutes the legal basis for the processing pursuant to Article 6(1)(a) of the GDPR:
(iii) to receive advertising material (direct marketing) from us
us.
By selecting the appropriate boxes you agree to the processing of your data for these purposes.
Your data may in any case be processed, even without your consent, for the purposes of compliance with laws, regulations, EU law (Article 6(1)(c) of the GDPR Regulation, to obtain statistics on the use of the Website and its proper functioning (Article 6(1)(f) of the Regulation).
Personal data are entered into the Controller's IT system in full compliance with data protection legislation, including security and confidentiality profiles and are based on principles of good practice, lawfulness and transparency regarding processing.
The data are stored for as long as is strictly necessary to achieve the purposes for which they were collected. In any case, the criterion used to determine this period is based on compliance with the deadlines set by law and on the principles of data minimization, storage limitation and rational file management.
All your data will be processed on paper or by automated means, ensuring in each case the appropriate level of security and confidentiality.
4. Principles applied during processing
We are permitted to process your personal data in order to provide personalized services, based on the law (article 6(1b) of Regulation (EU) 2016/679) and the relevant National Implementing Law. Your personal data will not be used for purposes other than those described in the Statement, unless we obtain your prior permission, or unless this is required or permitted by law.
Personal data shall be processed in a manner compatible with the purpose for which they were collected.
The principle of proportionality applies to the processing of personal data. Among other things, it creates the obligation not to collect personal data without reason.
Personal data used should be accurate and up-to-date.
Personal data used that are no longer accurate and complete should be rectified or erased.
Except in cases where there is a legal obligation to retain them for a longer period, personal data shall not be stored for longer than is necessary for the purposes for which they were collected or processed.
Personal data shall be processed in accordance with the principles of good faith. This means that data subjects can rely on the fact that processors will exercise due care in all matters relating to data processing.
Subjects whose personal data have been processed will be informed accordingly, upon request. In particular, they have the right to be informed of the purposes for which their data are processed, the type of data they concern, as well as the identity of the recipients of the data. Where necessary, data subjects also have the right to request the correction, non-transmission or deletion of their data.
The above rights may be limited only if such limitation is provided for by law. This applies, in particular, when conducting scientific research.
In particular, personal data are protected against unauthorized disclosure and any unlawful processing. The measures put in place ensure a level of security appropriate to the nature of the data to be protected and the risks that may arise from their processing.
The controller is responsible for compliance with and application of EU Regulation 2016/679 and the National Implementing Law.
Our employees involved in the processing of personal data are informed and trained accordingly. The procedures for the processing of personal data of third parties under agreement will be defined in writing, having ensured that the contracted third party processes personal data in a secure manner and that it complies with the principles set out in this Statement and the GDPREU. In the event that the third party is deemed unable to ensure a satisfactory level of security of personal data, we will terminate the cooperation.
5. Persons who have access to the data
The Data are processed by electronic and manual means in accordance with the procedures and practices related to the aforementioned purposes and are accessible to the personnel of the Controller who are authorized to process


