PRIVACY STATEMENT & PERSONAL DATA

This privacy statement (“Statement”) has been drafted by and applies to CeciliaStores.gr., a company registered in Greece with registered number 118109597, and their subsidiaries.

 

At CeciliaStores.gr, we value and respect your privacy and prove this through this Statement, which applies whether you visit our stores, use your mobile device or go online, and demonstrates CeciliaStores.gr compliance with the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as the “Regulation”) which is directly applicable in the European Economic Area from 25th May 2018, and has introduced new measures aiming to protect your personal data and thus your privacy.

 

In this Statement, we explain our practices regarding the collection and processing of your Personal Information, what kind of Personal Information we collect from you and when we collect them.


Collection of Personal Information

 

“Personal Information” is information that identifies you as an individual or relates to an identifiable individual i.e. through which you may be identified. It always has to do with living people. The Personal Information we collect is the following:

 

1.   First Name, Last Name;

2.   Your contact details: home address including billing and delivery address, telephone and/or mobile number and email address,

3.   Credit and debit card number, other card information and generally payment, billing and account information;

4.   Information provided on membership and account applications;

5.   Information related to the purchase, orders and receipt of goods or services;

6.   your reviews, comments, opinions and responses about our services and/or properties;

7.   any shopping preference or details to help us suggest items for you;

8.   your communication and marketing preferences;

9.   your correspondence and communications with us;

10.    Details of your interaction with our Customer Service;

11.   any other type of information which you may choose to provide to us or we may obtain about you through third parties with whom we do business

12.   your order history

13.   Loyalty card numbers from any brand of our group;

14.   your password(s);

15.   other publicly available personal data, including any which you have shared via a public platform (such as a Twitter feed or public Facebook page)

 

If you submit any Personal Information relating to other people to us, especially Personal Information of minors, in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Statement and/or the Card Application which is provided at the stores and/or properties which we operate and our websites.

We may collect Personal Information directly from you or indirectly through another source, whether these are provided in writing or through verbal communication in providing any part of our services, in ways such as the following:

 

1.    Through Our Online Services: We may collect Personal Information when you subscribe to our newsletters and/or promotions and/or apply online for a card and/or membership or otherwise purchase goods from us and/or buy and/or redeem vouchers through our websites and apps, when you communicate with us via online chat services and/or a social media service such as Facebook, and/or when you sign up for a newsletter or participate in a survey, contest, promotional and/or special offers and/or when you submit reviews or choose to complete surveys we have sent you, when you enter our online competitions, prize draws or promotions, complete an online form, such as for a transaction or employment purpose or for accident or incidents in stores or for other health and safety or security purposes.

2.    Through Our Offline Services: We may collect Personal Information from you offline. This may take place when you visit the reception desk and/or tills at our stores and/or properties and/or when you communicate with any member of our staff either in person and/or over the phone or via e-mail or when you contact customer services, when you purchase goods from us and/or buy or redeem vouchers and/or submit an application form for a card and/or membership, when you subscribe to our newsletters and/or promotions and/or when you submit reviews or choose to complete surveys we have sent you and/or when you enter our competitions, prize draws or promotions, and/or when you complete an online form, such as for a transaction or employment purpose or for accident or incidents in stores or for other health and safety or security purposes.

3.    From Other Sources: We may receive your Personal Information from other sources, such as public databases, joint marketing partners, and other third parties who have obtained your permission to share this information with us, or who need to share information with us in relation to goods and/or services you have purchased. This may include information from social media platforms (including from people with whom you are friends or otherwise connected). For example, if you elect to login to, connect with or link to, our Online Services using your social media account (e.g. Facebook or Twitter accounts etc.), then we also receive information from those accounts to the extent you've agreed to this as part of your settings and that third party's privacy policy. Thus, certain Personal Information from your social media account will be shared with us, which may include Personal Information that is part of your profile or your friends’ profiles.

 

In the event that we receive information from third parties, as opposed to directly from you, provided that they are lawfully entitled to share your data with us, we will use and share this information for the purposes described in this Statement. Also, in the event that your Personal Information is collected in this way, then we will bring to your attention the information included in this Statement along with the source from which the data originate, and if applicable, whether it came from publicly accessible sources. This information shall be provided to you within a reasonable period after obtaining the Personal Information, but at the latest within 1 month, except where the Personal Information are to be used for communication with you, in which case we will provide you with the above information at the latest at the time of the first communication with you. However, if the above information is envisaged to be disclosed to another recipient, then the above information shall be disclosed the latest when the Personal Information are first disclosed to the new recipient, despite the fact that none of the previous deadlines has passed. Of course, no such information would need to be provided:

 

1.    where you already have this information;

2.    where the provision of this information, for some reason, proves impossible or would involve disproportionate effort to obtain;

3.    obtaining or disclosure is expressly laid down by Union or Member State to which we are subject, and which provide measures to protect your legitimate interest, or

4.    In the event where the Personal Information must remain confidential subject to an obligation of professional secrecy.

 

Use of Personal Information

  We may use Personal Information in a variety of ways including:

 

1.    To provide the services you request from us, and to facilitate the purchase of our products both online and offline;

2.    To place and manage your orders and any issues during the order fulfilment and to check the status of your order, sending the order to you and manage returns.

3.    To reserve goods upon your request;

4.    to register you for our promotional and/or loyalty reward cards;

5.    To complete and fulfil your reservation and stay, for example, to process your payment, ensure that your room is available, and provide you with related customer service;

6.    To send you administrative information, direct marketing communications, newsletters, promotional and special offers, periodic customer satisfaction, market research or quality assurance surveys, and in order to respond to you requests and messages. This may be done in accordance to any communication preferences you have expressed. Such information may be provided through e-mail, postal mail, online advertising, social media, telephone, text messages, push notifications, in-app messaging, and other means including on –property messaging such as in-room television;

7.    To provide an e-Receipt for store and online purchases;

8.    To verify your identity when you access your account and/or to contact you to perform security checks and/or verify the identity of the loyalty reward card.

9.    To personalize the products and/or services you request and the promotional and/or special offers which we communicate to you and to tailor our website and/or online services to your needs and make them more user-friendly;

10. To allow you to participate in sweepstakes, contests and other promotions and to administer these activities. Some of these activities have additional rules, which could contain additional information about how we use and disclose your Personal Information. We suggest that you read any such rules carefully;

11. For our business purposes, such as data analysis, audits, security and fraud monitoring and prevention (including through the use of closed-circuit television and other security systems), developing new products, enhancing, improving or modifying our Services to ensure that our site, products, and services are of interest to you, identifying usage trends, determining the effectiveness of our promotional campaigns and operating and expanding our business activities;

12. to generate usage statistics of our website and analyse customer spend within our stores and online;

13. to generate statistics in relation to the types and volumes of products sold during the year;

14. To develop and test any changes or improvements to our websites, goods or services.

15. To ensure the safety and security of colleagues and customers and the prevention or detection of unlawful acts;

16. to comply with our legal and regulatory duties;

17. to manage customer service interactions with you;

18. to improve and personalise of our services to you during future purchases through the use of information that you provide in relation to your preferences and experiences. For this purpose, the creation of a profile is necessary.

 

In the event that we decide to further process your Personal Information for a purpose other than that for which the personal data were obtained, we shall provide you prior to that further processing with information on that other purpose and with any relevant further information which the General Data Protection Regulation requires.

 

 

Disclosure, Sharing and Transfer of Personal Information

 

To provide you with the best possible service in all our stores, your Personal Information may be shared with the below entities and/or people, which may involve cross-border transfer of information to third parties in countries outside the European Economic Area:

 

1.       To authorised personal at the applicable stores and/or offices in order to meet your purchase and/or order requests.

2.       To subsidiary and/or affiliate companies and/or business partners of our website for the purpose of meeting your preferences and in order to offer personalised services in all our properties.

3.       entities that help get your purchased products to you, such as payment service providers, warehouses, order packers, and delivery companies or as part of the standard customer journey for the purposes of taking payment, managing your order, monitoring site performance and stability, improving customer experience, tracking revenue, delivery and returns.

4.       Professional service providers, such as IT providers, marketing agencies, advertising partners and website hosts who help us run our business and deliver our marketing and advertising to you, including third party print companies for mailing purposes.

5.       Entities approved by you, such as social media sites (if you choose to link your accounts to us), and PayPal where you choose to use their payment service.

6.       To sponsors of Sweepstakes, Contests and other Promotions.

7.       to your friends associated with your social media account, to other website users and to your social media account provider, in connection with your social sharing activity, such as if you connect your social media account to your online Services account or log-into your online services account from your social media account. By connecting your online services account and your social media account, you authorize us to share information with your social media account provider, and you understand that the use of the information we share will be governed by the social media site’s privacy policy. If you do not want your Personal Information shared with other users or with your social media account provider, please do not connect your social media account with your online services account and do not participate in social sharing on the online services.

In addition, when you elect to post information on message boards, chat, profile pages and blogs and other services to which you are able to post information and materials (including, without limitation, our Social Media Pages) any such information you post or disclose through these services will become public and may be available to other users and the general public. We urge you to be very careful when deciding to disclose any information on the Online Services.

8.       In the event of any reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of our business, assets or stock (including in connection with any bankruptcy or similar proceedings), we may share your Personal Information to a third party for the purposes of the aforementioned event.

9.       Other circumstances in which the sharing of your Personal Information may take place are in order to:

 

1)    comply with applicable laws,

2)    respond to governmental inquiries or requests from public authorities,

3)    comply with valid legal process,

4)    protect the rights, privacy, safety or property of CeciliaStore.gr, site visitors, guests, employees, those of any of our affiliates or the public,

5)    permit us to pursue available remedies or limit the damages that we may sustain,

6)    enforce our websites' terms and conditions, and

7)    respond to an emergency

8)    to allow us to pursue available remedies or limit the damages that we may sustain.

 

 

 

Legal grounds for collection and processing of Personal Information

We would like to inform you that the legal grounds for receiving and handling your personal data are:

1.    that processing is necessary for the provision and sale of our products to you (Regulation, Art. 1(b));

2.    to the extent that the collection and processing is not covered by a) then the legal ground will be your explicit consent to the processing of your personal data for the above specific purposes (Regulation, Art. 1(a)). You may withdraw your consent at any time by sending us written notice of your wish to withdraw. This may be done in any written format including e-mail and fax;

3.    that processing is necessary for compliance with our legal obligations (Regulation, Art. 1(c));

4.    that processing is necessary in order to protect your vital interests or those of another individual (Regulation, Art. 1(d)).

5.    that processing is necessary for the legitimate interests pursued by us except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child (Regulation, Art. 1(d)). Legitimate interests include processing for direct marketing purposes. In carrying out this balancing exercise between our legitimate interests to carry out direct marketing and your interests and rights, we believe that because, as you can see below, you are able to effortlessly object to the use of your Personal Information and thus terminate any direct marketing, since you might be better off knowing about our special and/or promotional offers, because all offers which are made through direct marketing are sent to all our guests and there is no discrimination in terms of the guests that receive them, and because the variety of services that we offer are all inherently connected to each other, we believe that your fundamental rights and interests do not prohibit us from carrying out direct marketing, even though we will always strive to first obtain your consent before carrying out such actions.

 

Your rights

 

Under the Regulation, you have the following rights:

 

a.    to check whether and what kind of Personal Information we hold about you and to access or to request copies of such data;

b.    to be explained clearly and simply the information contained in this Statement;

c.    to request correction, supplementation or deletion of Personal Information about you that is inaccurate or processed in non-compliance with applicable legal requirements;

d.    to instruct the erasure of your Personal Information from our archives where:

1)    it is no longer necessary for the purposes mentioned in this Statement;

2)    where you withdraw your consent on which the processing is based and where there is no other legal ground for the processing;

3)    where you object at any time to the processing of your Personal Information in accordance to point (f) and (g) below;

4)    your Personal Information has been unlawfully processed;

5)    your Personal Information have to be erased in order to comply with our legal obligations.

 

e.    to obtain a restriction to the collection, processing or use of Personal Information about you where the accuracy of your data is contested by you to allow us to verify the accuracy of your Personal Information, the processing is unlawful but you do not wish us to erase your Personal Information from our archives, we no longer need your data for the purposes of processing, but they are required by you for the establishment, exercise or defense of legal claims or you object to the processing of your information which is based on your consent, subject to limited exceptions such as the establishment, exercise or defense of legal claims;

f.     to object to processing of your data on ground relating to your personal situation which have been obtained based on the necessity for the legitimate interests pursued by us, and to have us no longer process your personal data unless either we demonstrate to you compelling legitimate grounds for the processing which override your interest, right and freedoms, or the Personal Information is needed for the establishment, exercise or defense of legal claims;

g.    to object at any time to processing or your data for direct marketing;

h.    to the extent that your data is processed on the legal ground of your consent or the processing is carried out by automated means, to receive the data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller without hindrance from our part;

i.      to know the identities of third parties to which your personal data are transferred;

j.      to provide instructions on how your data must be handled after your death when relevant;

k.    to lodge a complaint with the competent data protection authority;

l.      to withdraw your consent at any time. If, following the provision of your consent, you then no longer wish to receive marketing-related communications from us on a going-forward basis, you may opt-out by email us info@ceciliastore.gr or following the instructions in any such email you receive from us or by sending us a fax at +(30) 2241 021219

 

 

How you can access, change, suppress or delete your Personal Information:

If you would like to review, correct, update, suppress or delete Personal Information

that you have previously provided to us, you may contact us at e-mail:

info@ceciliastore.gr , or:

   

5 NIKOLAOU PLASTIRA ,

RHODES, 85131

Tel:  +(30) 2241 021219

 

For your protection, we may only implement requests with respect to the Personal Information associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.

 

Security

Reasonable organisational, technical and administrative measures are in place to protect your Personal Information from unauthorized access, disclosure, alteration or destruction, while the Personal Information is stored in our archives. Among the things used to ensure the protection of your data are:

 

1.    the use of a data protection officer, who audits the processing of the Personal Information and advises us in terms of compliance;

2.    the minimisation of people who have access to the electronic archives where the Personal Information are stored;

3.    Passwords are used on the computers that the data are stored.

4.    Data are stored in locked safe boxes with keys only accessible to the employee that are qualified to have access.

 

 

We also carry out check to ensure that our affiliates and service providers with whom we share personal information, have reasonable measures in place to provide an adequate level of data protection and to maintain the confidentiality of your Personal Information.

 

We will not contact you by mobile/text messaging or email to ask for your confidential personal information or payment card details. If you receive this type of request, you should not respond to it. We will only ask for payment card details by telephone when you are booking a reservation or promotional package. We also ask that you please notify us at e-mail:  info@ceciliastore.gr

 

If you have reason to believe that your interaction with us is no longer secure (for example, if you feel that the security of your account has been compromised), please immediately notify us in accordance with the “Contacting Us” section below.

 

 

Special category of Personal Information 

“Special Category of Personal information” amount to such information the processing of which reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.

 

We do not generally collect Special Category information unless it is volunteered by you. Despite that, we ask that, unless there is a serious and/or legal need for you or another customer or third party, you do not to send us, and you do not disclose, any Special Category Personal Information to us.

 

Minors

We do not knowingly collect personal information from individuals who are under 18 years of age. As a parent or legal guardian, please do not allow your children to submit personal information without your permission. By providing us with the personal information of your children, you represent that authority has been given by both parents for the provision of this information.

 

Retention Period: 

Unless we hear otherwise from you or a longer retention period is required or permitted by the applicable law, your Personal Information will be subject to our 3-year retention policy. This retention period is in our opinion necessary to fulfil the purposes outlined in this Statement.

 

Your Personal Information shall be destroyed as early as practicable, from both our short-term system and our back-ups so that restoration and/or reconstruction of the data is no longer possible. This also involves the secure destruction of any printed paper through methods such as cross-shredding or incinerating the paper documents.

 

Updates to this Privacy Statement

Where the need arises for the further protection of your Personal Information and for the purposes of your information, we may change and/or modify this Privacy Statement from time to time. Where we make material changes to this Statement, we will post a link to the revised Statement at the homepage www.ceciliastore.gr and where you have consented to the processing of your Personal Information based on a previous version of this Statement you may also be informed through a communication channel that you have provided. It is possible to recognise when this Statement has been last updated by looking at the date at the top of the Statement Any changes become effective from the date on which they were posted on the website www.ceciliastore.gr Use of the website, any of our products and services, and/or providing consent to the updated Statement following such changes constitutes your acceptance of the revised Statement then in effect.

 

 

Contact Us

In the event that you have any questions about this Privacy Statement or you want to exercise any of your rights regarding your Personal Information please contact us at e-mail:

info@ceciliastore.gr , or:

 

5 NIKOLAOU PLASTIRA ,

RHODES, 85131

Tel:  +(30) 2241 021219

 Because email communication is not always secure, please do not include credit card or other sensitive information in your emails to us.

 

Keep Connected

Get updates by subscribe our weekly newsletter

Free Shipping

Orders over 100

Free Return

Withthin 30 Days

100% SECURE

Online Shopping

Best Price

Guaranteed

close
Your Cart is Empty
close
close
close