Privacy Policy
Privacy and data security are a top priority for Silphora Ltd when providing its services through the online store of personal care products, textiles and cosmetics. This Privacy Policy has been developed to provide clear, complete and easily understandable information about how we collect, use, store and protect customers' personal data. We are committed to processing all information in strict compliance with the principles of legality, transparency and data minimization, as defined in Regulation (EU) 2016/679 and the Personal Data Protection Act. In the following sections you will find a detailed description of the categories of data we process in relation to user profile registration, order fulfillment, product delivery, customer communication and marketing campaigns. The policy explains the legal basis for each processing, specific storage periods, applicable security measures and ways to exercise legal rights by data subjects. We encourage every user to carefully read the information provided and, should questions arise or further clarification be needed, the Administrator's team is always at your disposal through the stated communication channels. We believe that transparency and accountability in the processing of personal data are the basis for building trust and long-term relationships with customers.
Section I - Information about the administrator and the supervisory authority
Article 1. (1) This online store is managed and administered by:
Company Name: Silphora Ltd
VAT number: BG206511765
Registered office and administration address: Blvd. Bulgaria 4, Severen district, Plovdiv, 4003, Bulgaria
Postal address: Blvd. Bulgaria 4, Severen district, Plovdiv, 4003, Bulgaria
Phone: +30 699 815 4021
Email: support@silphora.gr
(2) Information about the supervisory authority:
Name: Commission for Personal Data Protection
Registered office and administration address: Blvd. Prof. Tsvetan Lazarov 2, Sofia 1592, Bulgaria
Postal address: Blvd. Prof. Tsvetan Lazarov 2, Sofia 1592, Bulgaria
Phone: 02 915 3 518;
Website: www.cpdp.bg
(3) Data subjects have the right to submit complaints to the competent authority of their country of residence:
Name: Hellenic Data Protection Authority
Address: Kifisias 1-3, P.O. Box 115 23, Athens
Phone: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr
Name: Office of the Commissioner for Personal Data Protection
Registered office and administration address: Kypranoros 15, 1061 Nicosia
Postal address: P.O. Box 23378, 1682 Nicosia
Phone: +357 22818456
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy
Section II - Definitions and terms
Article 2. The terms used in this Privacy Policy are interpreted according to the following meanings, unless the context dictates otherwise.
"Administrator" means Silphora Ltd, which, independently or in cooperation with other organizations, determines the purposes and methods of processing customers' personal data. The administrator bears full responsibility for the lawful collection, storage and use of information related to the operation of the online store.
"Personal data" is any information concerning a specific natural person through which that person can be identified directly or indirectly. Identification can be made through a single element or through a set of characteristics, such as name, address, phone number, email, location data, and others. For the purposes of the online store, personal data includes, for example: the customer's full name, delivery address, contact phone number for the courier, email address for order confirmation, as well as technical information about the device used when logging into the platform.
"Processing" includes any action or series of actions performed on personal data, regardless of whether they are automated or otherwise. Processing includes: collecting and recording data, classifying and storing them, modifying and updating them, using them for specific purposes, providing them to third parties, restricting access to them, as well as their final deletion or destruction. In the context of the online store, processing includes all activities necessary for receiving orders, organizing delivery, customer service, sending promotional messages, and maintaining platform security.
"Data Subject" is any natural person whose personal data is processed by the Administrator. For the purposes of this Policy, data subjects include both registered users with a permanent profile on the platform and visitors who make individual purchases, submit inquiries, or subscribe to newsletters.
"Recipient" is the person or organization to whom the Administrator provides personal data, regardless of whether this organization is an independent administrator or acts as a processor. Depending on the specific purpose of the provision, recipients may include courier companies, payment service providers, banking institutions, accounting firms, technical partners supporting the platform's functionality, as well as government authorities, if there is a legal obligation.
"Consent" means any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she signifies agreement to the processing of personal data relating to him or her for a specific purpose. Consent is given through a clear affirmative action, such as ticking a special box during registration, clicking a subscribe button, or activating a specific setting in the user profile.
"Personal data processor" is a person or organization that processes personal data on behalf of and according to the instructions of the Administrator based on a written agreement. The Processor is obliged to act exclusively in accordance with the documented instructions of the Administrator and to implement appropriate technical and organizational measures for data protection. Examples of personal data processors include cloud storage service providers, platform content management systems, newsletter sending platforms, or external specialists providing technical support.
"Supervisory authority" is an independent state authority that monitors the implementation of personal data protection rules and examines citizen complaints in case of violations. For the Republic of Bulgaria, the supervisory authority is the Commission for Personal Data Protection.
"Personal data breach" is an incident that leads to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data. In the event of such a breach, the Administrator takes measures to limit the consequences and informs the competent supervisory authority, as well as, where necessary, the affected data subjects.
"Profiling" means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements. For the purposes of the online store, profiling may only be applied when there is a valid legal basis and for the purpose of providing personalized content or product recommendations.
"Anonymization" is a process in which personal data is processed in a way that permanently excludes the possibility of linking it to a specific natural person. After anonymization is completed, the data ceases to be considered personal and does not fall within the scope of this Policy.
"Pseudonymisation" means the processing of personal data in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information. Such additional information is kept separately and is subject to technical and organisational measures to ensure that the personal data are not attributed to an identified or identifiable natural person.
"Cookies" are small text files stored on the user's device when they visit the online store and are used to recognize the user on subsequent visits. Cookies allow preferences to be stored, behavior on the platform to be tracked, security to be ensured, and content to be personalized.
"Online store" or "Platform" is a distinct set of systematically connected web pages and other digital resources, accessible via a single internet address and operating through standardized network protocols. The platform includes textual content, images, multimedia files, scripts, and other software elements necessary for presenting personal care, textile, and cosmetic products, taking orders, and communicating with customers.
Section III - Principles of personal data processing
Article 3. (1) The administrator processes personal data lawfully, fairly and transparently towards the data subject, ensuring full information regarding the data collected, the purposes of processing and the rights of the data subjects.
(2) Processing is carried out only when there is a valid legal basis, as defined in applicable law, such as performance of a contract, compliance with a legal obligation, consent or the legitimate interest of the Administrator.
(3) Transparency is ensured through the provision of clear, easily accessible and understandable information about the processing, including through this Privacy Policy, notifications at specific data collection points, and the possibility of direct communication with the Administrator.
(4) The Administrator does not permit hidden, misleading or ambiguous practices in the collection and use of personal data, as all processing is based on pre-announced and documented purposes.
Article 4. (1) Personal data is collected for specific, explicitly defined and legitimate purposes related to the operation of the online store, such as the sale of personal care, textile and cosmetic products, order delivery, customer communication, accounting records and newsletter provision.
(2) The collected data is not further processed in a manner incompatible with the initially declared purposes, unless there is a new explicit consent of the data subject or a legal requirement for further processing.
(3) In the event that personal data needs to be processed for a purpose different from the original, the Administrator conducts a preliminary assessment of the compatibility between the new and old purpose, taking into account the nature of the data, the context of their collection, the expectations of the subjects and the potential impact on their rights. When the new purpose is not compatible with the original and is not provided for by law, the Administrator informs the data subjects and requests their explicit consent before starting the processing.
Article 5. (1) The Administrator processes only personal data that is adequate, relevant and limited to what is necessary for the achievement of the specific purpose of the processing.
(2) When designing registration, order, and newsletter subscription forms, the Administrator avoids collecting unnecessary information, distinguishing mandatory fields from optional ones and providing the option to complete basic processes without providing non-mandatory data.
(3) Before introducing new functionalities or processing changes, the Administrator evaluates the need for additional data, prioritizing alternative technical solutions that minimize the volume of collected information.
(4) A regular review of already collected data is carried out to identify and delete information that is no longer necessary for the original purpose or has become irrelevant due to the expiry of the storage period.
(5) Within the online store, the Administrator does not collect data related to health status, religious beliefs, political opinions or other special categories of personal data, as these are not necessary for the provision of services.
Article 6. (1) The Administrator takes reasonable measures to ensure the accuracy and timeliness of the personal data processed, correcting or deleting inaccurate or incomplete information in a timely manner.
(2) Data subjects have the ability at any time to update the information in their user profile, correct errors in delivery details, or inform the Administrator of changes through a rights exercise form or direct communication with the customer service team.
(3) In case of inaccuracy in personal data during the processing of an order, communication with a courier company or other action, the Administrator immediately contacts the relevant subject for confirmation or correction of the information.
Article 7. (1) Personal data is stored in a format that allows the identification of the data subject for a period not exceeding that necessary to achieve the purposes for which they are processed.
(2) Specific storage periods are determined according to the legal basis of the processing, the nature of the data, applicable legal requirements, and the legitimate interests of the Administrator, as detailed in Section VI of this Policy.
(3) After the expiry of the specified period, personal data is irreversibly deleted or processed in a way that does not allow subsequent identification of the subject, unless the law requires longer storage for accounting, tax or legal purposes.
Article 8. (1) The administrator implements appropriate technical and organizational measures to ensure an adequate level of security for personal data, including protection against unauthorized or unlawful processing, accidental loss, destruction or damage.
(2) Protection measures are determined taking into account modern technical developments, the cost of implementation, the nature and volume of data processed, the context and purposes of processing, as well as the degree of risk to the rights and freedoms of data subjects. A detailed description of the applied security measures is presented in Section X of this Policy.
Article 9. (1) The administrator clearly distinguishes between the processing of personal data necessary for the performance of the distance selling contract and the processing that is not mandatory for the provision of the basic service.
(2) For the execution of the contract, data such as identification and contact details, order and delivery data, payment and accounting information are processed, which are absolutely necessary for the acceptance, processing, delivery and invoicing of the order.
(3) Processing that is not necessary for the performance of the contract, such as sending promotional messages, analyzing consumer preferences through analytical tools and personalizing advertising content, is carried out only with valid consent or another applicable legal basis.
(4) Refusal or withdrawal of consent for non-mandatory processing does not restrict the ability to place orders, access the user profile, receive ordered products or mandatory communication related to the performance of the contract.
(5) The administrator does not allow the worsening of terms, service quality or the imposition of adverse consequences due to refusal to provide consent for non-mandatory processing of personal data.
Section IV - Categories of personal data and purposes of processing
Article 10. (1) The administrator collects and processes personal data only in connection with the provision of online store services, the sale and delivery of personal care products, textiles and cosmetics, the maintenance of user profiles, communication with customers and compliance with legal obligations.
(2) The volume of data collected is limited to the minimum necessary, in accordance with the principle of data minimisation, as only information directly related to a specific purpose and that cannot be replaced by less intrusive alternatives is processed.
(3) The controller processes the data based on explicitly defined legal grounds in accordance with the requirements of Regulation (EU) 2016/679, and for each category of data and processing purpose, the corresponding legal ground is identified.
Article 11. (1) Depending on the role and interaction with the online store, the Controller collects and processes the following categories of personal data:
|
Category of personal data |
Purpose of processing |
Legal Basis |
Storage Duration |
|
Registration and user profile data (Name and surname, email, password (encrypted), profile creation date, login history) |
Creation and maintenance of a permanent user profile, facilitation of future orders, monitoring purchase history, managing communication preferences, providing access to platform functionalities |
Contract performance (Article 6, para. 1, letter "b" GDPR) |
Until the user profile is closed at the initiative of the data subject. In case of inactivity for a period of 2 years, the profile is automatically deactivated after prior notification. |
|
Order and delivery details (Recipient's name and surname, exact delivery address, phone number, information about ordered products, order number, delivery status) |
Receiving, processing, confirming, and executing orders; organising the delivery of products to the indicated address through partner courier companies; communication regarding delivery status; processing complaints, returns, and warranty claims. |
Contract performance (Article 6, para. 1, letter "b" GDPR) |
5 years from the date of contract execution, in accordance with applicable limitation periods for civil and commercial claims; in the case of warranty obligations - until the expiration of the warranty period plus the applicable limitation period. |
|
Payment and accounting information (Type of selected payment, transaction status, invoice details, transaction date and amount) |
Processing payments through the selected payment method. Issuance of invoices and other accounting documents. Fulfilment of obligations arising from tax and accounting legislation. Prevention of fraud and illegal transactions. |
Contract performance (Article 6, para. 1, letter "b" GDPR) and compliance with a legal obligation (Article 6, para. 1, letter "c" GDPR) |
10 years from the end of the respective financial year, in accordance with the requirements of the Accounting Act and tax legislation for accounting documentation, and 5 years for transaction data. |
|
Marketing and communication data (email, name, information about interest in specific product categories) |
Sending newsletters with news, offers, and special suggestions; providing personalized product recommendations based on expressed interest; conducting email marketing campaigns. |
Data subject's consent (Article 6, para. 1, letter "a" GDPR) |
Until the data subject withdraws consent. In case of no interaction (opening newsletters) for a period of 24 months, the subscription is automatically deactivated after prior notification. |
|
Technical data and platform usage data (IP address, type of device and operating system used, browser type and version, information about visited pages, session time and duration, traffic source) |
Ensuring the technical stability and security of the platform; preventing abuse, cyber attacks, and unauthorized access attempts; analyzing user behaviour to improve functionality and design; optimizing platform performance on various devices; diagnosing and resolving technical issues. |
Legitimate interest of the Controller (Article 6, para. 1, point "f" GDPR) - to ensure the smooth operation, protection, and continuity of services |
Up to 24 months from the last visit to the platform. In case of a security incident or dispute, data may be retained until the final resolution of the case. |
|
Data from reviews, ratings, and user content (author's name or pseudonym, review text, product rating, publication date, information about confirmed purchase (verified review)) |
Publishing product reviews and ratings on the platform to inform other users. Managing content to prevent spam, misleading or inappropriate information. Using reviews for marketing purposes (with explicit consent). Improving product and service quality based on feedback. |
Legitimate interest of the Controller (Article 6, paragraph 1, point "f" of the GDPR) for product quality promotion and consent (Article 6, paragraph 1, point "a" of the GDPR) for use in marketing materials outside the platform. |
Until the user profile is closed or until the specific review is requested to be deleted. In case of use for marketing purposes, until consent is withdrawn. |
|
Data from communication and customer service (Name and surname, email address or phone number, content of correspondence, order number or other information, date and time of communication) |
Answering questions and providing information about products and services; processing complaints, claims, and warranty claims; supporting technical issues or questions regarding platform usage; ensuring traceability and documentation of interactions for quality service. |
Contract performance (Article 6, para. 1, letter "b" GDPR) for order-related inquiries; legitimate interest (Article 6, para. 1, letter "f" GDPR) for general inquiries and service improvement |
Until the final resolution of the respective request, complaint, or claim plus 6 months for monitoring; in the case of warranty claims - until the expiration of the warranty period plus the applicable limitation period. |
(2) The publication of user reviews is not mandatory and is at the customer's discretion. When publishing, the customer can choose whether the review will be displayed with their real name, pseudonym, or anonymously, to the extent technically feasible. The customer has the right to request the modification or deletion of a published review at any time, when there is a legitimate reason for this, including the exercise of their rights under Regulation (EU) 2016/679 (GDPR), and the request is processed within the legally stipulated deadlines.
Article 12. (1) The controller does not collect and process special categories of personal data within the meaning of Article 9 of Regulation (EU) 2016/679, including data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, sex life or sexual orientation.
(2) Although the online store offers personal care products, textile and cosmetic products that may be related to specific skin conditions or allergies, the Controller does not request or collect information about the health status of customers, allergies or medical data of any kind.
(3) In the event that a data subject voluntarily provides information falling within the scope of paragraph 1, for example through free text in correspondence or a review, the Controller immediately informs the data subject that this information is not necessary for the provision of the services and takes measures to delete it without undue delay, unless there is explicit consent in accordance with Article 9, paragraph 2 of Regulation (EU) 2016/679.
Article 13. (1) The online store is intended for individuals over 18 years of age and is not intended to collect personal data from minors.
(2) When creating a user profile or placing an order, the data subject declares that they have reached the age of 18, and the Controller reserves the right to request additional verification in case of reasonable doubt.
(3) In the event that personal data of an individual under 18 years of age is found to have been collected without valid parental or legal representative consent, the Controller immediately takes measures to delete such data and deactivate any created profile.
(4) Parents and legal representatives of minors have the right to contact the Controller to inform them about unlawfully collected data of individuals under their parental care.
Article 14. (1) The Controller does not apply automated decision-making, including profiling, within the meaning of Article 22 of Regulation (EU) 2016/679, which has legal effects on the data subject or significantly affects them.
(2) For the purpose of improving user experience and providing relevant recommendations, the Controller may conduct limited analysis of user behaviour based on order history, viewed products, and expressed preferences, which does not lead to automated decisions with legal or significant consequences.
(3) The analysis referred to in paragraph 2 is carried out only if there is valid consent or other applicable legal basis and is based on aggregated data regarding interaction with the platform, without affecting access to the basic functionalities of the online store.
(4) The data subject has the right to object at any time to processing for analysis and recommendation purposes, without this limiting their ability to place orders or use the platform's services.
(5) In the event of future introduction of automated decision-making or profiling with legal or significant consequences, the Controller will update this Policy, provide detailed information about the logic, significance, and envisaged consequences of such processing, and ensure the possibility of human intervention, expressing an opinion, and challenging the decision.
Article 15. (1) Every processing of personal data by the Controller is based on at least one of the valid legal bases defined in Article 6, para. 1 of Regulation (EU) 2016/679, while the specific basis for each category of data and processing purpose is indicated in the table in Article 11.
(2) When processing is based on a legitimate interest of the Controller, a balancing test has been conducted, which confirms that the pursued interest does not override the rights and freedoms of the data subjects, and appropriate measures have been taken to minimize the impact on privacy.
(3) In cases where processing is based on the data subject's consent, such consent is freely given, specific, informed and unambiguous, through a clear affirmative action, and the data subject retains the right to withdraw their consent at any time without negative consequences for access to basic services.
Section V - Personal Data Storage Periods
Article 16. (1) The controller stores personal data for the period objectively necessary to achieve the purposes for which the data were collected and processed, taking into account the legal basis for processing, the nature of the data, applicable legal requirements, and the legitimate interests of the parties.
(2) After the expiry of the specified storage period, personal data are irreversibly deleted through secure erasure from all systems and backups or processed in a way that does not allow subsequent identification of the data subject.
(3) In cases where legislation requires longer retention of certain data categories for accounting, tax, or legal purposes, the Controller adheres to the mandatory minimum deadlines, even when the original purpose of processing has already been achieved.
(4) The determination of specific deadlines is carried out depending on the category of data, taking into account the following factors: purpose of processing, type of legal basis, degree of data sensitivity, limitation periods for exercising legal claims, requirements of accounting and tax legislation, existence of current legal or contractual relations with the data subject.
Article 17.
The specific deadlines for the storage of various categories of personal data are as follows:
|
Category of personal data |
Storage Duration |
Initial Reference Point |
Criterion for Determination |
Action after Expiry |
|
User profile data |
Until the user closes the account. Inactivity - 2 years from the last login. |
Profile creation date; date of last activity |
Duration of the contractual relationship; need to maintain the profile for future orders; protection of legal claims |
Automatic deletion of the profile after sending a warning notification 30 days before deactivation. |
|
Order and delivery details |
5 years |
Order execution date (receipt by customer or return in case of failed delivery) |
Five-year limitation period for civil and commercial claims under the Law of Obligations and Contracts; warranty obligations and possibility to file complaints. |
Complete deletion of data after the expiration of the period. In case of an active dispute, data is retained until its final resolution. |
|
Payment information (transactions) |
5 years |
Date of transaction |
Ability to dispute transactions; limitation periods for financial claims; requirements of payment service providers |
Deletion of transaction data; information in accounting documents is retained according to applicable accounting periods. |
|
Accounting and tax documents |
10 years |
End of the financial year to which the documents refer |
Requirements of the Tax and Social Insurance Procedure Code |
Archiving in a protected environment with restricted access. After the expiration of the period, destruction in accordance with the procedures for processing archival documents. |
|
Marketing data (newsletter) |
Until consent is withdrawn. In case of no interaction - 24 months |
Date of consent; date of last newsletter opening or link click |
Actively expressed will of the data subject; relevance of interest in promotional messages |
Immediate deletion from marketing lists (up to 30 days); retention of a record of consent withdrawal for evidentiary purposes (minimum data volume) |
|
Technical data (IP addresses, logs) |
24 months |
Date of data collection (platform visit) |
Need for traceability in case of incidents; technical support period; log rotation |
Automatic deletion of old logs; anonymization of IP addresses for statistical purposes |
|
Data from cookies |
Depending on the type of cookie: temporary - until browser closure; permanent - from 30 days to 12 months |
Moment of cookie placement |
Technological necessity; validity period of consent |
Automatic deletion upon expiration; manual deletion via browser settings |
|
Data from reviews and ratings |
Until account closure or until deletion is requested. In case of use for marketing purposes outside the platform, until consent is withdrawn. |
Date of review publication |
Informational value for other users; contractual terms for publishing user content |
Deletion of the review and related personal data. Anonymization of content while retaining the rating for statistical purposes (at discretion). |
|
Data from customer communication |
Until final resolution of the request, complaint, or grievance + 6 months |
Date of completion of communication or resolution of the case |
Service traceability; possibility for subsequent inquiries about the same case; protection in case of legal claims |
Archiving of correspondence for the duration of storage; then - complete deletion |
|
Data in case of consent withdrawal |
1 year |
Date of consent withdrawal |
Proof of legality of processing in case of inspection by a supervisory authority; protection in case of disputes |
Deletion after the expiration of the evidentiary period; only minimal information is stored |
Article 18. (1) In the event of an ongoing legal dispute, proceedings before a court or administrative body, investigation, or proceedings for the establishment, exercise or defense of legal claims, the Controller shall temporarily suspend the automatic deletion of personal data related to the proceedings until the final conclusion of the case.
(2) The extension of the period under paragraph 1 applies only to data directly related to the specific legal case, while other data of the same data subject continue to be processed according to the usual retention periods.
(3) The data subject shall be informed of the extension of the retention period by providing them with information regarding the legal basis, the nature of the legal case (without disclosing confidential details), and the expected duration of the extension.
Article 19. (1) The Controller shall maintain an internal register of data categories and applicable retention periods, which shall be regularly updated in case of changes in legislation, business processes, or technical infrastructure.
(2) The process of data deletion or anonymization shall be carried out automatically through technical mechanisms, where possible, or through periodic manual checks and actions by authorized personnel.
(3) When personal data is deleted from the primary systems, it shall be ensured that the same data is also deleted from all backups during the next update of the archives, with the maximum period for complete deletion not exceeding 90 days from the initial deletion.
Article 20. The data subject has the right to request at any time information regarding the applicable retention period for their specific personal data, and the Controller shall provide a response within 30 days of receiving the request, which includes details regarding the data category, the legal basis, the initial recording date, and the expected deletion date.
Section VI - Rights of Data Subjects
Article 21. (1) Each data subject has specific rights regarding their personal data, which they can exercise at any time by submitting a request to the Controller.
(2) The exercise of rights is free of charge, except in cases of manifestly unfounded or excessive requests, in which the Controller may impose a reasonable fee or refuse to take action.
(3) Requests shall be submitted via email to the address specified in Section I, through the contact form on the platform, or via written correspondence to the Controller's physical address.
(4) When submitting a request, the Controller may ask for additional information necessary to confirm the data subject's identity, when there are reasonable doubts or when the nature of the request requires additional verification.
Article 22. The data subject has the right to obtain confirmation as to whether the Controller is processing their personal data and, if so, to access it along with information about the purposes of processing, data categories, recipients, retention period, data source, and existing rights. A copy of the data is provided free of charge in electronic format, and an administrative fee may be charged for repeated copies.
Article 23. (1) The data subject has the right to request the rectification of inaccurate personal data without undue delay, with the controller updating the information within a reasonable timeframe.
(2) The data subject can also request the completion of incomplete data by submitting an additional statement, which is particularly important for the accuracy of delivery or communication data in future orders.
(3) Users with a registered profile can update most of their data themselves through the profile settings, without the need for submitting a formal request.
Article 24. (1) The data subject may request the deletion of their personal data when the data is no longer necessary for the purposes for which it was collected, when consent for processing has been withdrawn, when the data has been unlawfully processed, or when there is a legal obligation to delete it.
(2) The controller shall delete the data within 30 days of receiving the request, unless there is a legitimate reason to retain it, such as obligations under accounting and tax legislation, the need for protection in case of legal claims, or other legal requirements.
(3) In case of refusal to delete, the Controller shall provide a detailed explanation of the legal reason why the data must be retained, along with information on the expected period of additional storage.
Article 25. The data subject may request a restriction of processing, during which the data is stored but not actively used, in the following cases: when the accuracy of the data is contested during verification; when the processing is unlawful but deletion is not desired; when the Controller no longer needs the data, but it is required by the data subject for legal claims; when an objection to processing has been lodged until it is clarified whether the Controller's grounds override those of the data subject.
Article 26. (1) The data subject has the right to receive the personal data they have provided to the Controller in a structured, commonly used and machine-readable format, such as CSV, JSON or XML.
(2) If technologically feasible, the Controller may transfer the data directly to another controller, according to the data subject's instructions.
(3) The right to data portability applies only to data processed based on consent or a contract, and only when the processing is carried out by automated means, without including data extracted or generated by the Controller's system.
Article 27. (1) The data subject may object to the processing of personal data based on the Controller's legitimate interest, in which case the processing shall cease, unless compelling legitimate grounds are demonstrated which override the interests and rights of the data subject.
(2) In case of an objection to processing for direct marketing purposes, the Controller shall immediately and unconditionally cease all use of the data for marketing purposes, including the sending of newsletters and promotional messages.
(3) The objection does not affect the processing of data necessary for fulfilling contractual obligations or complying with legal requirements.
Article 28. (1) When processing is based entirely on consent, the data subject may withdraw it at any time with the same ease with which it was given.
(2) Withdrawal can be done via an unsubscribe link in the newsletter, in the user profile settings, via email, or through any other available communication channel.
(3) The withdrawal of consent does not affect the lawfulness of processing carried out up to the time of withdrawal, nor the processing of data for another legal basis, such as the performance of a contract or a legal obligation.
(4) After the withdrawal of consent for promotional messages, the data subject continues to have full access to all platform functions and the ability to place orders without restrictions.
Article 29. (1) The controller examines the requests and provides information on the actions taken within one month of their receipt.
(2) If necessary, the deadline may be extended by two further months, taking into account the complexity and number of requests, for which the data subject shall be informed within the first month, along with the reasons for the delay.
(3) In case of refusal to take action on the request, the controller shall inform the data subject of the reasons within the same one-month period, explaining the possibility of lodging a complaint with the supervisory authority and seeking judicial protection.
Article 30. (1) The data subject has the right to lodge a complaint with the Commission for Personal Data Protection if they consider that the processing of their personal data violates applicable law.
(2) The complaint can be submitted in writing to the address of the Commission for Personal Data Protection, as specified in Section I, or electronically through the official website of the Commission.
(3) The exercise of the right to complain to the supervisory authority does not in any way limit the data subject's access to the platform's services and does not lead to adverse treatment or discrimination by the Controller.
(4) The data subject also retains the right to seek judicial protection, regardless of lodging a complaint with the CPDP.
Section VII - Recipients of personal data (third parties)
Article 31. (1) The Controller provides personal data to third parties only when this is necessary for fulfilling contractual obligations, complying with legal requirements, or ensuring the smooth operation of the platform.
(2) All recipients who process data on behalf of the Controller act as personal data processors based on written agreements that guarantee the implementation of appropriate technical and organizational measures for data protection.
(3) Recipients do not have the right to use personal data for their own purposes, except for those explicitly authorized by the Controller, and are obliged to process it only in accordance with documented instructions.
Article 32. The controller provides personal data to the following categories of recipients in connection with the stated purposes:
-
Courier and logistics services (ELTA Courier, Geniki, BoxNow for deliveries in Greece, Kronos Express for deliveries in Cyprus) - receive name, delivery address, and contact phone number for the purpose of physical delivery of ordered products to the customer.
-
Payment service providers (Stripe) - process transaction data for the purpose of verifying and executing credit and debit card payments, while the Controller does not store full credit card data.
-
Technology partners (hosting, platform, content management system providers) - have access to technical data and logs to ensure the stability, security, and smooth operation of the platform.
-
Accounting and auditing services - receive invoice data and transaction information for the purpose of fulfilling the Administrator's obligations under accounting and tax legislation.
-
Marketing and analytics platforms (Google Analytics, Meta Pixel) - collect technical data and information about platform behavior for the purpose of analyzing user interaction and conducting advertising campaigns, with processing based on consent obtained through the cookie management mechanism.
-
Legal advisors and law firms - receive data when legal protection, advice, or proceedings related to complaints, contractual disputes, or the exercise of rights are required.
-
State and regulatory authorities (Personal Data Protection Commission, National Revenue Agency, courts) - receive data only when there is a legal obligation, an official request based on an act of a competent authority, or within the framework of proceedings before an administrative or judicial authority.
Article 33. (1) The administrator selects partners who have taken the necessary measures to protect personal data and who demonstrate compliance with the requirements of the applicable data protection legislation.
(2) When selecting personal data processors, their technical capabilities, organizational measures, experience in the relevant field, and reputation regarding compliance with security and confidentiality standards are taken into account.
Section VIII - International data transfers
Article 34. (1) During the provision of services, personal data may be transferred to recipients located outside the European Union and the European Economic Area, which occurs when using specific technological platforms and tools.
(2) Every data transfer to a third country is carried out in strict compliance with the requirements of Chapter V of Regulation (EU) 2016/679, ensuring that the level of protection is not degraded compared to that of the European Union.
(3) The controller does not transfer data to third countries for which there are no appropriate legal mechanisms and additional technical measures ensuring adequate protection.
(4) In the event of a transfer of personal data to providers or recipients established outside the European Union or the European Economic Area, the controller implements appropriate safeguards in accordance with Regulation (EU) 2016/679, including Standard Contractual Clauses (SCCs) approved by the European Commission or other valid protection mechanisms provided for in Chapter V of the GDPR, with the aim of ensuring an adequate level of personal data protection.
Article 35. The transfer of personal data outside the EU/EEA is carried out to the following recipients with the indicated safeguards:
-
Stripe (payment service provider with servers in the United States and the European Union) - the transfer is based on standard contractual clauses approved by the European Commission, supplemented by technical measures of data encryption and limited access to sensitive information.
-
Google LLC (Google Analytics for web analytics with servers in the United States) - the transfer is based on standard contractual clauses and compliance with the EU-US Data Privacy Framework, having performed a risk assessment and implemented additional measures for IP address pseudonymization.
-
Meta Platforms, Inc. (Meta Pixel for marketing purposes with servers in the United States) - the transfer is based on standard contractual clauses and compliance with the EU-US Data Privacy Framework, with processing carried out only with explicit consent obtained through the cookie management mechanism.
Article 36. (1) Before each data transfer to a third country, the administrator assesses the legal framework of the recipient country, analyzing legislation regarding public authorities' access to data, the existence of legal protection mechanisms, and practical implementation.
(2) Based on the assessment in the preceding paragraph, additional technical and organizational measures are implemented, including data encryption during transfer and storage, limiting the volume of transferred data to the absolute minimum necessary, access control based on the principle of least privilege, and contractual clauses prohibiting access by public bodies without a legal basis.
(3) The administrator regularly reviews the risk assessment in case of changes in the legislation of the recipient countries or in case new circumstances arise that could affect the level of protection of the transferred data.
Article 37. Data subjects have the right to receive information about the specific countries to which their data is transferred, as well as a copy of the protection mechanisms, by submitting a request in accordance with Section VI of this Policy.
Section IX - Security Measures
Article 38. (1) The administrator implements a set of technical and organizational measures to ensure an appropriate level of personal data security, depending on the nature, volume, and purposes of processing, as well as the degree of risk to the rights and freedoms of data subjects.
(2) Protection measures are regularly reviewed and updated, taking into account modern technological developments, new cyber threats, and changes in the categories of data processed.
(3) When determining appropriate measures, the data controller takes into account the cost of implementation, technological capabilities, and the balance between effectiveness and practical feasibility.
Article 39. The administrator implements the following technical measures for the protection of personal data:
-
Encryption of communications - all communications between the user's browser and the platform's servers take place via encrypted SSL/TLS connections (HTTPS protocol), which prevents data interception during their transmission.
-
Password protection - user passwords are stored in encrypted form using hashing algorithms, which makes it impossible to retrieve the original password, even in the event of unauthorized access to the database.
-
Access control - access to personal data is restricted through a system of unique identifiers and authorization levels, as only employees with specific duties are allowed to view or process the relevant data.
-
Firewalls and threat detection systems - the platform is protected by firewalls and monitoring systems that detect and block suspicious activity, unauthorized access attempts, DDoS attacks, and other cyber threats.
-
Backups and recovery - data backups are regularly created and stored in a protected and isolated environment, allowing for quick recovery in case of technical failure, hardware malfunction, or security incident.
-
Software updates - the platform's management system (Shopify and the applications used) and all related applications are kept up to date through the timely installation of security patches and updates.
Article 40. The administrator implements the following organizational measures for the protection of personal data:
-
Principle of least privilege - each employee or external collaborator has access only to that part of personal data that is absolutely necessary for the performance of their specific task, without the ability to view or process irrelevant information.
-
Staff training - employees who have access to personal data are required to undergo training on data protection legislation requirements, internal security policies and procedures, and best practices for incident prevention.
-
Confidentiality agreements - all employees and external collaborators sign confidentiality agreements, which oblige them to keep confidential the information they access during the performance of their duties.
-
Internal policies and procedures - documented procedures have been developed and implemented for data processing, incident management, access approval, archiving, and deletion of information.
-
Physical security - the technical infrastructure of hosting partners is located in protected data centers with controlled access, video surveillance, air conditioning, and fire detection systems.
Article 41. (1) The administrator conducts periodic audits and evaluations of the effectiveness of the implemented security measures through internal controls, vulnerability tests, and analysis of incidents that have occurred.
(2) In case of identification of new risks or weaknesses in protection, corrective measures are immediately taken, including technical improvements, updating of procedures, or additional staff training.
Article 42. (1) In the event of a personal data security breach that may endanger the rights and freedoms of data subjects, the Administrator informs the Personal Data Protection Commission no later than 72 hours after the incident is identified.
(2) The notification includes a description of the nature of the breach, the categories and approximate number of affected data subjects and data records, the likely consequences, the measures taken or planned to mitigate the effects, and the Administrator's contact details.
(3) When the breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the breach to the affected data subjects without undue delay by individual email or public announcement, depending on the circumstances.
(4) The notification to the data subjects includes a description of the incident, specific recommendations for protection (password change, monitoring of bank transactions), contact details of the Administrator for further questions, and information about the right to lodge a complaint with the supervisory authority.
(5) The Administrator keeps a record of all security breaches, regardless of whether they have been reported to the PDPC, which includes a timeline of the incident, an analysis of the causes, an assessment of the consequences, and a list of corrective measures taken.
Section X - Use of cookies and tracking technologies
Article 43. (1) To ensure an optimal user experience, technical stability, and personalized content, the platform uses cookies and similar tracking technologies.
(2) Cookies are small text files stored on the user's device when they visit the platform and serve to recognize them on subsequent visits, remember preferences, ensure security, and analyze interaction with the online store.
(3) Detailed information about the types of cookies used, their specific purposes, storage times, providers, and management mechanisms is available in the platform's separate Cookie Policy.
Article 44. (1) Upon first accessing the platform, the user sees an interactive consent management mechanism (cookie banner), which requires active action before any cookies are activated, with the exception of those strictly necessary for the operation of basic services.
(2) The user has the option to choose between the following options:
-
Accept all cookies - provides consent for the full functionality of the platform, including analytical and marketing tools.
-
Reject non-essential cookies - the platform operates only with the strictly necessary technical elements for order fulfillment and basic navigation.
-
Customized settings - access to a detailed control panel for individual selection by cookie category.
(3) The recorded consent remains valid for a period of 12 months, after which, upon the next visit, the system requires new confirmation.
(4) Marketing and analytics cookies, including, but not limited to, Google Analytics and Meta (Facebook) Pixel, are not activated or used before valid, explicit, and informed consent is obtained from the user, provided through a cookie management mechanism.
Article 45. (1) The user can change their consent or revoke permission to use specific cookie categories at any time through the control panel located at the bottom of each platform page.
(2) Revoking consent for analytical or advertising cookies does not restrict access to the basic functions of the online store, the ability to place orders, or the use of the user profile.
(3) Regardless of the platform settings, the user can block or delete cookies directly through the settings of the browser used, taking into account that disabling all cookies may lead to limited functionality of certain sections.
Article 46. Some cookies are placed by external service providers, such as Google Analytics and Meta Pixel, who may transfer data outside the European Union in accordance with the terms described in Section VIII, with processing carried out only with your explicit consent obtained through the cookie management mechanism.
Section XI - Changes to the Privacy Policy
Article 47. (1) The administrator reserves the right to update this Privacy Policy periodically to reflect changes in data processing practices, the introduction of new features, technological improvements, or compliance with changes in applicable legislation.
(2) Each update is carried out in strict compliance with the principles of transparency and good faith, ensuring that data subjects are informed in a timely manner of the changes and their consequences.
(3) The updated version of the Policy includes a clear reference to the date of the last modification at the beginning or end of the document, while the Administrator maintains a record of previous versions, which is available upon request.
Article 48. (1) When introducing changes affecting the rights of data subjects, the categories of processed data, the purposes of processing, the recipients or protection mechanisms, the Controller informs users in the following ways:
-
Sending an individual email to registered users at least 14 days before the changes come into effect.
-
Publishing a clear and conspicuous systemic notification upon first login to the platform after the update, informing about the changes and providing a direct link to the new version of the Policy.
-
Publishing a message on the homepage of the e-shop for a period of at least 30 days.
(2) When changes impose a new legal basis for processing, such as, for example, transitioning from legitimate interest to a requirement for consent, the Controller discontinues the corresponding processing until explicit confirmation is received from the data subject.
(3) Minor technical corrections, spelling error corrections or updates to contact details do not require prior notification, but are indicated by the date of the last change.
Article 49. (1) Changes come into effect from the date of their publication on the platform, unless the changes themselves specify a different, later effective date.
(2) Continued use of the platform after the publication of the updated Policy is considered as acceptance of the changes by the data subject, provided that they have been duly informed in accordance with the provisions of the preceding article.
(3) If the user does not wish to accept the material changes to the Policy, they have the right to discontinue the use of the services, delete their user profile, and request the deletion of their personal data in accordance with the terms of Section VI, which right may be exercised within the 14-day notice period.
Section XII - Final Provisions
Article 50. (1) This Privacy Policy comes into effect on 02.01.2026 and applies to all personal data collected and processed through the e-shop, regardless of whether they were collected before or after this date.
(2) The Policy is an integral part of the relationship between the Controller and the platform users and applies together with the General Terms of Use of the e-shop.
(3) In case of a conflict between the provisions of this Policy and the General Terms regarding matters concerning the protection of personal data, the clauses of the Privacy Policy prevail as a specific document on this matter.
Article 51. In addition to this general Privacy Policy, upon request, the Controller provides privacy notices at specific data collection moments, such as during profile registration, order completion, newsletter subscription, or request submission.
Article 52. (1) This Policy is governed by and interpreted in accordance with Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data, the Law on Personal Data Protection of the Republic of Bulgaria, and the applicable Bulgarian and European legislation.
(2) All disputes arising in connection with the processing of personal data or the application of this Policy shall be resolved primarily through negotiations and mediation between the parties with the aim of reaching a mutually acceptable solution.
(3) If an agreement cannot be reached peacefully, the dispute shall be referred for resolution to the competent Bulgarian court in accordance with the procedural rules for determining jurisdiction.
(4) Data subjects retain their right to lodge a complaint with the Commission for Personal Data Protection, regardless of negotiations or court proceedings.
(5) The provisions of this article regarding the applicable Bulgarian law and the competent Bulgarian court do not limit or prejudice the rights of data subjects under Regulation (EU) 2016/679 to exercise their rights and seek protection from the competent supervisory authority or the competent court of the Member State in which they have their habitual residence, including the Republic of Greece or Cyprus, where applicable under European law.
Article 53. (1) Should any provision of this Policy be found invalid, ineffective, or unenforceable by a competent authority, this shall not affect the validity and enforceability of the remaining clauses.
(2) The invalid or unenforceable provision shall be replaced by a valid clause that reflects to the maximum extent the original purpose and economic logic, without violating the requirements of applicable law.
(3) The controller is obliged to immediately update the Policy if a clause is found to be invalid, informing data subjects of the change in accordance with the procedure set out in Section XI.
Article 54. (1) When interpreting the provisions of this Policy, the purpose of each clause, the ordinary meaning of the words and expressions used, the systematic position of the provision in the structure of the document, as well as the general principles of personal data protection, shall be taken into account.
(2) In case of doubt or ambiguity in the application of a specific provision, the interpretation shall be made in favor of the broader protection of the rights and freedoms of data subjects.
(3) The headings of sections and articles serve only to facilitate navigation and do not affect the interpretation of the content of the respective clauses.
Article 55. (1) This Privacy Policy was originally drafted in Bulgarian.
(2) For users with habitual residence in the territory of the Republic of Greece and the Republic of Cyprus, the Policy may also be provided in Greek.
(3) In case of discrepancies between the language versions, the mandatory provisions for the protection of personal data according to European Union law and the law of the country of habitual residence of the data subject shall apply.
EFFECTIVE DATE: 02.01.2026
LAST UPDATED: 02.01.2026