1.Who collects your personal data?
The Greek company NORMA FASHION ALLEY is responsible for the processing of personal data provided to us and is responsible for the security of your data under the Personal Data Protection Act.
2.Why do we use your personal data?
We use your personal data:
- to manage your online purchase, that is to process your orders and returns through our online services and to send you notifications about the delivery status or in case of any problems during the delivery of your items.
- to process your payments.
- to manage complaints about our products.
- to offer you different alternative payments.
- to identify you and verify that you are over 16 years old.
- to improve your shopping experience and our services.
- to send promotional emails about new products, special offers, our news or other information that we think may be useful to you, using the email addresses you have given us.
3.What personal data do we collect?
- Contact details such as name, surname, address, e-mail address, telephone number, postal code.
- Account information such as name, surname, address, email address, telephone number, postcode, date of birth, gender, city, country, and username.
- Information and payment history
- Order information
- Purchase history
- Delivery history
- Activity recording information
- IP address
4.What is the legal basis for processing your data?
We process your personal data because it is essential for:
- the execution of the contract of sale of goods
- our compliance with our legal obligations
- pursuing our legitimate interests
In general, we rely on your consent as a legal basis only for the processing related to the sending of direct marketing messages via e-mail. You have the right to withdraw your consent at any time. Where your consent is the sole legal basis for processing, we will stop processing your data after it is revoked.
5.How long do we keep your data?
We do not retain your data for longer than is necessary for the purposes set out in this Policy. Different retention periods apply to different types of data, however the longest time we keep your personal data is 10 years.
6.Who has access to your personal data?
In order to provide you with certain services, we need to share your personal information with some of our partners. These include delivery, payment and marketing service providers. We will never transfer, sell, rent or exchange our customers’ data to other organizations for marketing purposes. We may share your data with government agencies, regulators, law enforcement agencies, courts, banking institutions and insurers, in cases where we have to do so:
- to comply with our legal obligations.
- to exercise our legal rights.
- to prevent, locate, investigate crimes, or prosecute offenders.
- to protect our employees and customers.
7.Do we forward your data outside the European Union?
In order to provide you with our products and services, it is sometimes necessary to transfer your data outside the European Union. This usually happens when the partner service providers are outside the European Union or if you are outside the Union. These transmissions are subject to special rules under the Data Protection Act. If this happens, we ensure that the transmission complies with the data protection legislation and that all your personal data will be secure. Our usual practice is to use “standard data protection clauses” which have been approved by the European Commission for such transfers.
8.How do we protect your data?
We implement appropriate technical and organizational measures to ensure that your personal data is always protected and secure. Our security measures include data encryption, regular cybersecurity assessments by all service providers that may handle your personal data, security checks that protect our entire technology infrastructure from external attack and unauthorized access, and internal policies that determine how to ensure the protection of your data and the training of our employees.
9.What are your rights?
- Right of access: you have the right to request information about personal data that we process at any time. You can contact us and we are willing to let you know your personal information via email.
- Right to correction: You have the right to request the correction of your personal data if it is incorrect.
- Right to delete (“right to be forgotten”): You have the right to request the deletion of personal data processed by our company at any time, unless an order is pending which has not yet been shipped or you have any debt to us.
- Right to restrict processing: You have the right to ask us to restrict processing when there is a specific reason for it (e.g. if you have objections to our legal interest or if your personal data is incorrect or if you think the processing is illegal or if we no longer need them).
- Right to portability: Every time our company processes your personal data, you have the right to get a copy of them in a structured, commonly used and machine readable format, as well as request that they be transferred elsewhere. This only includes the personal data you provided to us.
- Right to object against processing based on legal interest: You have the right to object to the processing of your personal data based on our legal interest. We will not continue to process your personal data unless we can prove legitimate grounds for processing that are in your best interests or have legitimate claims.
- Right to oppose direct commercial promotion: You have the right to object to direct commercial promotion, including the preparation of profiles made for direct commercial purposes. You have the option to opt out of direct marketing.
10.How can you exercise your rights?
If you wish to exercise any of the above rights, contact us using our contact details or go to your personal account where you can change your data or delete it. If you believe that our company is processing your personal data incorrectly, please contact us.
If you have any questions about how we use your personal data that have not been answered here or if you wish to exercise your rights regarding your personal data, send us an e-mail to firstname.lastname@example.org.
1.What are cookies?
2.What kind of cookies do we use and for what purpose?
We use necessary first – party cookies (such as session, permanent and traffic log cookies). These cookies collect information about your browsing and shopping behavior when you access this website through your computer or other device. The information collected is related to the pages you saw, your favorite products or products you purchased, and your navigation on our website. In addition to first-party cookies, we use third-party cookies to collect user statistics and data, in aggregate and individual form, through analysis tools to optimize our website and provide you with relevant promotional material.
3.What personal data do cookies record?
- Cookie ID
- The IP address
- The browsing history
- Buying behavior
- If you have an account, we can also link your cookie ID to the personal data you submitted to us when you created your account.
4.How long do we store your personal data?
We do not retain your data more than is necessary for the purposes set out in this Policy. The data recorded by the first – party cookies are kept for only 30 days. In addition, data from third-party cookies is stored for 26 months.
5.Who has access to your personal data?
Data transmitted to third parties (such as Google Analytics) is only used to provide the above services and to collect statistical data through analysis tools to optimize our website and provide you with relevant promotional material.
7.How can you disable cookies?
You can easily disable cookies using your browser. If you want to manage and delete cookies, see the “help” and “support” section of your browser. You can choose to disable cookies or receive a notification every time a new cookie is sent to your computer. Please note that by deleting cookies or disabling future cookies you may not have access to specific areas or functions of our website.