“We” are NACARO FOODS Private Company, trading as NACARO FOODS, headquartered in Hersonisos, Crete, with general commercial registration no. 142730627000 and VAT no. 800842727, Local Tax Office of Heraklion, Crete. “Our Website” is https://yiayiaandfriends.com, including our online shop (e-shop); our email is firstname.lastname@example.org.
Regarding your personal data, we act as “Data Controller”, pursuant to GDPR Article 4(7).
“You” are any person accessing or using our website or contacting us by any other means, and you are a “Data Subject” pursuant to GDPR Article 4 (1).
Data processing principles
As Data Controller, our company shall be responsible to demonstrate compliance with the following personal data processing principles stipulated by the GDPR.
In particular, your personal data shall be:
a) processed lawfully, fairly and in a transparent manner to you (“lawfulness, fairness and transparency”),
b) collected for specified, explicit and legitimate purposes and not submitted to further processing in ways incompatible with those purposes (“purpose limitation”),
c) adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed (“data minimization”),
d) accurate and, where necessary, kept up to date (“accuracy”),
e) kept in a format that permits the identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed (“storage limitation”),
f) processed in a manner that ensures appropriate security of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organizational measures (“integrity and confidentiality”).
Lawfulness of processing
We may collect and process your personal data subject to at least one the following legal bases and associated purposes:
a) you have explicitly provided us with consent to process your personal data for one or more specific purposes, such as to create a user account on our website, to order a product through our e-shop, to participate in a contest or for other specific purposes,
b) processing is necessary for the preparation or execution of a contract between us, as when you enter and save your details prior to confirming you order or when you actually buy a product through our e-shop,
c) processing is necessary for compliance with a legal obligation that we are subject to, such as our obligation to record your contact details on our receipt or invoice for tax compliance purposes,
d) processing is necessary to protect a vital interest, yours or of another natural person, such as for example protecting the integrity and security of your personal account and your stored personal data,
e) processing is necessary to fulfill a duty towards the public good, or in the execution of a public power vested in the Data Controller,
f) processing is necessary for the purposes of our own or any third party’s legitimate interests. Such legitimate interests are the smooth and secure operation of our website, direct marketing, after-sales customer support and the improvement of products and services.
In any case, we shall keep the personal data that we request at the minimum possible level. Depending on the purpose of data processing, your refusal to provide requested personal data may prevent us from fulfilling a statutory, pre-contractual or contractual obligation.
Personal data processing
We shall collect and process your personal data only after you provide us with your explicit consent while using our website and e-shop or when you are contacting us for any other reason. We will ask you for your personal data in the following cases:
- When you register and open a user account on our website, we collect your email address.
- When you register on our website with your social media profile (e.g., Facebook, Google, etc.), you provide us with access to your social media profile’s username and email address.
- When you place an order through our e-shop or by any other means, we will ask you for your full name, delivery address, email, and a telephone number. Additional data may be required by applicable tax legislation.
- When you contact us for information on our products, or about your order, we may ask you for your full name and contact details.
- When you are registering to receive our newsletter, we will ask you for your email address.
- Depending on your chosen Cookies preferences and according to our Cookies Policy, we may collect information on your browsing activity, your preferences and your purchase orders. Such information is collected and stored anonymously.
- With your consent, our website may also store credit/debit card information in the user’s account, so that it does not need to be re-entered for repeat orders.
Duration of personal data storage
We will retain your personal data for the period required to fulfill the processing purposes mentioned above, or until you explicitly request from us to delete your personal data from our database, subject to the limitations prescribed in Article 17 of the GDPR. In the case where personal data processing is based on your consent, the data shall be retained until we receive your withdrawal from such consent and there is no other legal base or statutory limitation preventing us from deleting your data. Certain data (e.g., order data) may be kept anonymously or pseudonymized for the purposes of statistical analysis.
Note that we may retain your personal data until the end of a claim limitation period or until any disputed claims are resolved before mediation panels or courts. We may also retain your personal data for as long as this may be required by tax or other applicable legislation.
According to Articles 15 to 22 of the GDPR and Articles 33 to 35 of applicable Greek Law 4624/2019, you have certain rights as a data subject. You have the right to withdraw your consent for personal data processing anytime. You have the rights to request from us access to and rectification or erasure of your personal data. You have the right to request from us to restrict processing concerning yourself as a data subject, the right to object to your personal data being processed for the purposes of legitimate interests pursued by us or by a third party, including profiling, as well as the right to data portability, where possible. You also have the right not to be subject to a decision based solely on automated processing, including profiling, if it produces legal effects on you or affects you significantly in a similar way. These rights can be exercised subject to limitations prescribed in the legal provisions mentioned above.
Furthermore, you have the right to lodge a complaint with the competent data protection authority. Our supervisory authority is the Hellenic Data Protection Authority www.dpa.gr.
Personal data transfers
to provide sufficient guarantees to implement appropriate technical and organizational measures in such a manner that processing will meet the requirements of GDPR and will ensure the protection of your personal data rights.
Your personal data are stored on hosting servers located in countries which ensure an adequate level of data protection, as defined in Article 45 of the GDPR.
We do not assume or accept any responsibility whatsoever for processing of any personal data you may provide to third parties through links provided on our website. Such parties are independent Data Controllers and so we strongly advise you to study their Privacy Policies prior to granting them with access to any of your personal data.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risks involved for your personal data, in accordance with GDPR requirements.
Your information is processed only by authorized and qualified staff and associates which are bound by confidentiality and data protection agreements with us.
Your user account is personal and non-transferable. It is your duty to safeguard and not to disclose your user login credentials to anyone else.
Cookies are small text files stored on your computer when you visit a digital platform. They are used as a means of identifying your computer. The cookies placed by the owner of the digital platform are called “first-party cookies”. Cookies placed by others are called “third-party cookies”. Third-party cookies allow third-party features (such as analytics, ads, and videos) to be provided on or through a website. Parties installing third-party cookies can recognize your device when you visit our e-shop and also when you visit other websites.
With the exception of absolutely necessary cookies, cookies are installed only if you accept them upon visiting the website. By accepting the cookies when entering the website, you explicitly declare that you have read and understood the specific terms and conditions regarding the installation, function and purposes served by the cookies and that you grant your consent for their use. Alternatively, you may not accept installation of cookies. In this case we will only install cookies deemed necessary for the smooth operation of our website and e-shop.
You may choose which of the cookie categories you accept to install or to opt not to install any cookies not deemed necessary.
Cookies fall under the following categories:
- Strictly Necessary Cookies: These are necessary for the smooth operation of our website. They include, for example, cookies that enable you to log into secure areas of our website.
- Analytical/Performance Cookies: These allow us to recognize and count the number of users of our website and see how such users navigate through it. This allows us to improve functionality of our website.
- Functionality Cookies: These improve the functional performance of our website and make it easier for you to use. These cookies allow the website to remember our visitors’ options such as username and region in order to provide improved and personalized features.
- Targeting Cookies: These record your visit to our website, the pages you have visited and the links you have followed. These cookies are used to serve personalized content based on the users’ interests. We will use this information to make advertising more relevant to your interests.
You have the option to accept or decline cookies by modifying the settings in your browser.
Please bear in mind that you may not be able to use all of our website features if cookies are disabled.
We may update our cookies policy anytime and at our sole discretion. The updated policy will be displayed on this web page.