Overview
The respect for the protection of your personal data is a priority for us. Our company “ARCHEIOTHIKI S.A.” (hereinafter referred to as “Archeiothiki” or “the Company” or “we”) has established this Personal Data Protection Policy (hereinafter the “Data Protection Policy” or the “Policy”), in order to inform you, in a transparent and comprehensible manner, about the collection, use, storage and, in general, processing of your personal data for the purposes of this Policy (hereinafter “Personal Data”), in accordance with Regulation (EU) 2016/679 (hereinafter the “GDPR” or the “General Regulation”), the applicable Greek legislation on the protection of your personal data, as well as the decisions and guidelines of the competent European bodies (hereinafter the “applicable Personal Data Legislation”).
In addition, this Policy serves the purpose of Public Information regarding the processing of your Personal Data in accordance with Article 14(5) GDPR, as well as Article 32(2) of Law 4624/2019.
This Policy should be read in conjunction with the Archeiothiki Cookie Policy, as well as with the Social Media Policy, where applicable; together, these form a single document.
Content
1. Target audience of this Policy?
This Policy is addressed to you if you are:
- Users of our Website
- Prospective and former Customers of our Company
- Prospective, existing and former Suppliers of our Company
- Visitors to the Archeiothiki’s facilities (inspectors, partners, representatives of Customers / Suppliers, etc.)
- External users / guest users of Archeiothiki’s digital platforms who are not Clients or representatives of our Clients, but who have been invited by a Client or an authorized representative of a Client to gain access to a Virtual Data Room (VDR) or another digital platform, within the context of a project or collaboration
- Third parties, to whom this Policy relates
2. What is the role of Archeiothiki in the processing of personal data?
2.1 ARCHEIOTHIKI S.A., with registered headquarters in Nea Ionia, 86 Kapodistriou Avenue and Roumelis Street, P.C. 14235, telephone +30 2105570410, email: info@archeiothiki.gr, acts as Data Controller for the processing of your data for all processing purposes analysed in the table in section 5.
2.2 Archeiothiki has appointed a “Data Protection Officer”, whom you may contact at the details below for matters concerning this Policy as well as the processing of your Personal Data:
– by e-mail: dpo@archeiothiki.gr (for the attention of the DPO)
– by letter: Thesi Rykia, P.C. 193 00, Aspropyrgos – Greece (for the attention of the DPO).
2.3. There are also cases in which Archeiothiki acts as a Processor or Sub-processor, as well as other cases in which it acts as a Joint Controller; in such cases Archeiothiki enters into the appropriate data processing / joint controllership agreements, respectively.
2.4. Finally, where you are employees of our Customers or Suppliers, whose data we may process in the context of the provision of our services or the operation of Archeiothiki, we process your personal data as recipient thereof in the context of the performance of the contract with those Customers or Suppliers, while the latter are the Data Controllers of your personal data, from whom you may also obtain information regarding such processing.
2.5. For the processing of your personal data in the context of the operation of the notice-and-action mechanism, the internal complaint-handling systems, and, in general, its obligations under Regulation (EU) 2022/2065 (DSA), the Company acts as the Data Controller of your personal data.
Note: During the hosting and / or management of documents and other electronic files and, in general, the personal data and information included in Archival Material (physical or electronic), to which we must have access when providing our services to our Customers, we do not know, do not control, nor are we obliged to know or control the personal data included therein. As a rule, when we process data included in Archival Material or in customer systems/files on their behalf, Archeiothiki acts as a Processor (or Sub-processor) pursuant to Article 28 GDPR, while the corresponding Customer, who determines the purposes and legal basis of the processing, is the Data Controller. Archeiothiki processes the data exclusively on the Customer’s instructions and in accordance with our data processing agreement (DPA) and the appropriate security measures.
3. What personal data do we process and how?
3.1 Personal Data: Your “Personal Data” includes any information relating to an identified or identifiable natural person (data subject), that is, a person whose identity can be established directly or indirectly, in particular by reference to an identifier (e.g. name, user identifier, location data, online identifier such as an IP address), in accordance with the applicable Personal Data Legislation.
3.2 Data Subjects: Archeiothiki mainly transacts with legal entities, the data of which do not in principle constitute Personal Data, with the exception of their electronic address (e.g. etaireia@…gr), pursuant to Law 3471/2006. However, where the information belongs to a legal entity that is either a sole proprietorship or a single-member EPE or a personal company (e.g. OE or IKE) and the name of an active partner/shareholder appears in the company name, such details may constitute Personal Data. In addition, if your name appears in your business e-mail address (e.g. onoma.eponymo@etaireia.gr), this is considered your Personal Data. Furthermore, if you are a member of a company’s Board of Directors or other administrative body of a legal entity, or a shareholder in a company, we may process your Personal Data in the context of providing our services.
4. How do we collect your personal data?
We collect your Personal Data from you, through automated means and/or from third parties.
From you when:
– you complete the Contact Form on our Website
– you give us your business card
– you contact us in order for us to send you a financial offer / cooperation proposal as our Customer
– you send us negotiation documents or your invoices, or we cooperate with you and you provide us with your details as our Supplier
– you have been invited by one of our Clients or by an authorized representative of one of our Clients to gain access to a Virtual Data Room or another digital platform of the Archeiothiki, in which case we may receive from the Client or their representative certain information that is necessary for the grant or management of access to such platform
– you contact the Point of Contact that we have designated in the context of Archeiothiki’s compliance with Regulation (EU) 2022/2065 (DSA)
By automated means when:
– you visit our Website through your browser
– cookies are installed on your computer through our Website (see more in the Cookie Policy)
– we collect image data through the closed-circuit CCTV system. You may obtain more information in the Second-Level Notice posted at central points in Archeiothiki’s premises
– you participate by answering questionnaires sent to you by Archeiothiki through platforms that we use as tools for our internal organisation
From third parties when:
– you are an employee of our Customers or Suppliers and we need to communicate in the context of the performance of our contract with them, or when providing IT support, accounting support or human resources management
– you interact with us on social media following your own action (see more in the Social Media Policy)
5. What is the purpose and legal basis of each processing?
5.1 The following table summarises the purposes of processing, the data that we collect and process per purpose, and the corresponding legal bases:
|
Processing Purpose |
Sub-purposes of Processing |
Personal Data |
Legal Basis of processing |
|
Website Users |
|||
|
Website users Technical operation / Communication |
(a) Technical operation and security of the website (prevention of malicious actions, troubleshooting, systems protection). |
|
(a) Legitimate interest Processing is based on Archeiothiki’s legitimate interest in the secure and uninterrupted operation of our systems while you browse our Website; this interest has been fairly balanced against the processing of your Personal Data in this context, without affecting your fundamental rights and freedoms. |
|
Website users Technical operation / Communication |
(b) Management of the contact request that you voluntarily submit through the contact form and response / communication with you. |
|
(b) Consent Processing is based on your consent to contact us by completing the contact form and for us to respond and manage contact requests. You may withdraw your consent at any time by sending an e-mail to dpo@archeiothiki.gr. Where we reply to your communication, the purpose for which we process your Personal Data has already been fulfilled. |
|
Website users Cookies / similar technologies |
Use of cookies / similar technologies for technical operation, preferences, statistical analysis, marketing (where applicable), in accordance with the Cookie Policy. |
Cookie identifiers, technical identifiers (e.g. IP / online identifiers), device / browser information, usage data (depending on the type of cookie) |
Consent For the installation of cookies on your device, please consult our Website Cookie Policy. |
|
Prospective and Former Customers with specific reference to External / Guest Users of Digital Platforms |
|||
|
Prospective Customers Communication / sending cooperation proposals / pre-contractual documents / negotiations |
Communication and management of requests for information regarding our services, the content of a cooperation proposal, NDAs, Letters of Intent, draft contracts, and, in general, negotiation activities at the stage prior to the conclusion of a contract. |
|
Pre-contractual measures for the performance of a contract Where, at your request, you contact us and negotiate your cooperation with Archeiothiki, the processing is based on taking measures at the pre-contractual stage for entering into a contract. |
|
Prospective Customers – External / Guest Users of Digital Platforms
Commercial Communication – Newsletter |
Our communication with you for updates regarding Archeiothiki news and new services. |
|
Consent The processing of your Personal Data is based on your consent when you hand us your business card or when you have subscribed to our newsletter database by entering, on your own initiative, your e-mail address in the relevant field on Archeiothiki’s Website. You may withdraw your consent by selecting the unsubscribe button/link included in each of our communications. |
|
Former Customers Record keeping for tax compliance |
Record keeping for compliance with tax / accounting obligations and response to audits. |
|
Compliance with a legal obligation Processing for record keeping with such Personal Data as is necessary in order for Archeiothiki to comply with its legal obligations in the event of a tax audit. |
|
Suppliers (Prospective, Active and Former Suppliers) |
|||
|
Suppliers Prospective, Active and Former Suppliers Negotiation, Contract, payments, tax matters, systems security |
Prospective Suppliers Communication in order to receive information regarding your services, the content of a cooperation proposal, NDAs, Letters of Intent, draft contracts (i.e. documents at the negotiation stage), and, in general, negotiation activities prior to the conclusion of a contract with Archeiothiki. |
|
Pre-contractual measures for the performance of a contract The processing during the negotiation of our cooperation is necessary in order to take pre-contractual measures for the performance of a contract between us. |
|
Suppliers Prospective, Active and Former Suppliers Negotiation, Contract, payments, tax matters, systems security |
Active Suppliers (a) Conclusion/performance of the contract, communication, management of the cooperation, payments. |
|
(a) Performance of a contract The processing during the provision of your services, the communication in this context, the management of our cooperation and the payment of your remuneration is based on the performance of the contract between us. |
|
Suppliers Prospective, Active and Former Suppliers Negotiation, Contract, payments, tax matters, systems security |
Active Suppliers (b) Security of information systems and keeping of audit logs on digital platforms. |
|
(b) Legitimate interest Processing is based on Archeiothiki’s legitimate interest in adopting the appropriate security measures for the prevention of malicious actions, the handling and resolution of any issues (troubleshooting), and the evidence of actions. |
|
Suppliers Prospective, Active and Former Suppliers Negotiation, Contract, payments, tax matters, systems security |
Active Suppliers (c) Management of the supplier assessment process through digital platforms. |
|
(c) Legitimate interest Processing is based on Archeiothiki’s legitimate interest in the proper organisation, security, management and documentation of its supplier assessment process in accordance with applicable compliance standards, the monitoring of the quality of the services provided, and the improvement of the cooperation; this interest has been fairly balanced against your fundamental rights and freedoms, without affecting them. |
|
Suppliers Prospective, Active and Former Suppliers Negotiation, Contract, payments, tax matters, systems security |
Active and Former Suppliers Compliance with tax / accounting obligations and response to audits. |
|
Compliance with a legal obligation Processing is necessary for Archeiothiki’s compliance with its obligations under applicable tax legislation. |
|
Visitors to Premises |
|||
| Visitors to premises Visitor book |
For access control and the security of our premises, we process your Personal Data during your visit to our premises in order to record your details in the visitor books. |
|
Legitimate interest Processing is based on our Company’s legitimate interest in the security of our premises and the protection of persons, property and archival material of our Customers with high security requirements; this interest has been fairly balanced and does not affect your fundamental rights and freedoms. |
| Visitors to premises CCTV – Security of premises |
The processing of your Personal Data is necessary when you approach or visit our premises for the protection of persons and property and for the prevention and investigation of security incidents on our premises. |
|
Legitimate interest Processing is based on our Company’s legitimate interest in the protection of persons and property and the security of premises, assets and archival material of our Customers with high security requirements. You may obtain more information in the Second-Level Notice posted at central points in Archeiothiki’s premises. |
|
External / Guest Users of Digital Platforms |
|||
|
Prospective Customers – External / Guest Users of Digital Platforms
Access to and participation in VDR / digital platforms |
For the grant and management of access to a Virtual Data Room (VDR) or another digital platform, following an invitation by one of our Clients or by an authorized representative of one of our Clients, for your participation therein. |
|
Legitimate interest The processing is based on our Company’s legitimate interest in ensuring secure, controlled, and documented access to the platform, the operation of the VDR, the prevention of unauthorized access, the resolution of technical issues, and the ability to demonstrate actions performed. This legitimate interest has been balanced against your rights and freedoms, taking into account that the processing is limited to the data strictly necessary for the specific use of the platform. |
|
Prospective Customers – External / Guest Users of Digital Platforms
Commercial Communication – Newsletter |
For sending operational or technical notifications directly related to the use, security, access, operation, changes, or necessary usage instructions of the VDR or other digital platforms, as applicable. These communications do not constitute marketing communications or newsletters. |
|
Legitimate interest The processing is based on our Company’s legitimate interest in informing platform users of matters that are necessary or directly related to the secure and proper use of the platform, as well as on the corresponding interest of users and Clients to be informed of issues affecting access to, operation, or security of the VDR or other digital platforms, as applicable.. |
5.2 Archeiothiki may process your Personal Data in the context of the exercise or defence of its lawful claims on the basis of its overriding legitimate interest.
5.3 Certain of your Personal Data may be processed on the basis of our legitimate interest and Archeiothiki’s compliance with a legal obligation for other purposes, such as, for example, when we receive documents, requests, orders, pleadings, warrants, etc. from lawful third-party authorities or bodies, such as supervisory, prosecutorial, judicial or tax authorities, for the investigation of crimes and your protection against fraud or the combating of every form of criminality and infringement of legal interests.
5.4 During the investigation of a personal data breach incident and the notification of data subjects affected by each incident, as well as the recording of the incident in the relevant internal register/file of the company, Archeiothiki processes your Personal Data on the basis of its compliance with a legal obligation arising from the applicable Personal Data Protection Legislation.
5.5 Where the legal basis for the processing of your Personal Data is the legitimate interest of our company, you may object to the processing by contacting us at dpo@archeiothiki.gr.
5.6 Where the legal basis for the processing of your Personal Data is consent, if you withdraw your consent, such withdrawal applies for the future, in which case your Personal Data are deleted. The processing of your Personal Data based on your consent, up to the point of withdrawal of your consent, is carried out lawfully.
5.7. Archeiothiki will process your Personal Data during the exercise and implementation of your rights on the basis of compliance with a legal obligation in accordance with the applicable Personal Data Legislation.
5.8. In the context of our compliance with Regulation (EU) 2022/2065 (Digital Services Act – DSA), we process your Personal Data for Archeiothiki’s compliance with the legal obligations arising from that Regulation. More specifically, such data are processed, indicatively, when you communicate with the Point of Contact we have designated, in order for us to communicate with you in the context of the operation of the notice-and-action mechanism, for your identification when you participate as an involved party in that mechanism, and in order to disclose your details to the reported person, where this is necessary.
6. How long do we retain your personal data?
6.1 We will retain your Personal Data for as long as you continue to interact with us and for as long as those data are necessary for the fulfilment of the processing purposes described herein. In order to determine the retention period of your data, we take into account the nature of the data, the quantity, the purpose of processing, and their security, in accordance with the principle of data minimisation, provided that Archeiothiki’s legitimate interests are not adversely affected and/or there is no legal obligation to retain them as described above. Indicatively, according to the role you have when you interact with us, cooperate with us, or when we process your data in the context of fulfilling our contractual obligations:
– If you are a Website User and have submitted a request through the contact form, we retain the relevant data for up to 1 year from the last communication, unless a longer period is required due to the management of claims / disputes
– If you are a Prospective Customer or Prospective Supplier (e.g. exchange of business card / communication for cooperation), we retain the data for up to 5 years from the last substantive communication, unless there are active negotiations or another documented need
– If you are a Former Customer or Former Supplier, we retain the data required for tax/accounting purposes for the period provided by applicable legislation (indicatively up to 10 years, depending on the case) and for legal protection purposes until any claims become time-barred and/or any related disputes are completed
– If you are a Visitor to our premises (visitor book), we retain the visit data for up to 5 years, unless a security incident / investigation / audit arises, in which case the data are retained until the completion of the relevant purpose.
– CCTV: image data are retained for a short and proportionate period of 7 days, with exceptions in incident cases (see the Second-Level Notice for more information)
– If you are an external / guest user of one of our digital platforms, we retain account, access, usage data and related logs for as long as necessary for the maintenance and management of access to the platform, the provision of support, system security, documentation of actions, and the fulfillment of contractual or legal obligations. After the completion of the relevant purpose, the data are deleted or anonymized, unless longer retention is required for reasons of security, audit, compliance, or the establishment, exercise, or defense of legal claims.
6.2 Furthermore, we retain your Personal Data for our legal protection in the event of a dispute in the context of the use of the Website (e.g. your message), as well as for the management by Archeiothiki of any lawful claims and the processing activities covered by this Policy (e.g. out-of-court dispute, dispute before courts and/or prosecutorial or other authorities), for the period during which liability could arise from the processing, in accordance with the applicable legislation in force from time to time.
6.3 In any event, for as long as we retain your data, they are stored securely, also in accordance with the security measures of section 10 below.
7. Who are the third recipients of your data?
7.1 Where it is necessary for Archeiothiki to cooperate with third parties in order to provide its services in the best possible manner and to operate as a commercial enterprise, our Company selects persons or third-party partners with corresponding professional qualifications who provide adequate guarantees in terms of technical knowledge and personal integrity for maintaining confidentiality and the security and protection of data against accidental or unlawful destruction, loss, alteration or dissemination. Through the corresponding contractual commitments with shareholders, members of management staff, as well as external partners and processors or joint controllers, our Company takes all those necessary contractual, technical and organisational security measures for the protection and safeguarding of the secrecy, confidentiality and integrity of Personal Data.
7.2 In addition, our Company, as Data Controller, works with third parties acting as Processors, with whom it has signed the required data processing agreements (DPAs) and for whom it has ensured that they provide safeguards for the secure processing of Personal Data in accordance with the applicable Personal Data Legislation. Moreover, Archeiothiki may disclose Personal Data to third-party recipients acting as separate Data Controllers, either where this is mandatory by law (e.g. public services or lawful authorities), or in the context of the performance of its contractual obligations towards its Customers, or on the basis of its legitimate interest in the proper administration and operation of its business.
7.3 For the smooth and uninterrupted operation of the Website, Archeiothiki cooperates with third-party companies, which obtain access only to such of your data as are absolutely necessary for the operational and IT organisation of our Website, the optimisation of the User experience, the submission of your messages through the contact form, etc. Indicatively, the companies with which we cooperate include the company hosting and technically supporting the Website, etc.
7.4 Your Personal Data may be communicated to the following categories of recipients:
– Public services (e.g. the Tax Authority, etc.) or State Authorities
– Third parties who provide services to us, such as IT companies, database hosting companies, companies for system development, support and maintenance, telecommunications companies, courier companies, providers of specialised software, lawyers, etc.
– Third parties that carry out audits on us in the context of our regulatory obligations, customer relationships, or obligations arising from applicable legislation or from standards with which our Company complies
– Persons / entities as required under Regulation (EU) 2022/2065
– Law enforcement authorities, in order for us to comply with a legal obligation or court order
7.5 If, through our Website, you are redirected to third-party websites, whether or not they are partners of Archeiothiki, you are requested to consult the relevant privacy policy on each website you visit.
8. Transfer of data to third countries
8.1 As a rule, Archeiothiki keeps personal data within the European Economic Area (EEA). However, in the context of its operation and the use of infrastructures or IT services, in certain cases data may be transferred and/or remotely accessed from countries outside the EEA (“third countries”).
8.2 Transfer or access outside the EEA may take place only to countries for which an adequacy decision exists, or to countries whose entities have joined the U.S. Data Privacy Framework list, and only to the extent necessary for purposes such as:
– hosting and technical support of information systems,
– systems security and business continuity (e.g. back-ups),
– use of communication or organisational support tools,
– and / or provision of services to customers, in accordance with our contractual commitments
8.3 In any case of transfer or access to personal data in third countries that do not have an adequacy decision, Archeiothiki ensures that appropriate safeguards are implemented (e.g. execution of Standard Contractual Clauses – SCCs, carrying out a Transfer Impact Assessment – TIA where required, and implementation of additional technical and organisational security measures, depending on the nature of the transfer).
8.4 By way of exception, and only if the GDPR conditions are met, a transfer may take place without an adequacy decision or appropriate safeguards, such as, indicatively, where the transfer is necessary for the establishment, exercise or defence of legal claims.
8.5 Information regarding transfers of personal data to third countries and the safeguards applied is updated in this Policy where required. In addition, you may request further information regarding the transfer mechanisms applied and the main safeguards by contacting the Data Protection Officer at the details referred to in section 2.2, subject to any limitations arising from confidentiality obligations or the protection of business secrets.
9. What are your rights and what are the procedures for exercising them?
9.1 You can exercise your rights by submitting a specific request using the DPO contact email. The table below sets out your rights as well as the relevant explanation and the conditions for exercising them:
|
RIGHT |
WHAT IS IT? |
|
Access |
You have the right to request that you: – confirm that Archeiothiki processes your Personal Data – gain access to the data we process about you – receive information about their processing, such as: what data we hold, why we use them, to whom we transfer them, whether we transfer them to third countries and how we protect them, how long we keep them, what rights you have, how you can lodge a complaint, and from where your data originate where we did not collect them directly from you. |
|
Rectification |
You have the right to request that our company rectify false or inaccurate data about you or update them. If you exercise this right, Archeiothiki reserves the right to verify the accuracy of your data before proceeding with their rectification and is obliged to inform the recipient to whom your personal data were disclosed, unless this proves impossible or involves disproportionate effort. |
|
Erasure |
You have the right to request that your data be erased when: (a) you have withdrawn the consent on which the processing is based; (b) they are no longer needed for the purposes for which they were collected; (c) you establish that they are otherwise or unlawfully processed; (d) you object to the processing. Archeiothiki reserves the right to refuse the exercise of the above right if the processing of the data is necessary: (a) for the purpose for which they have been collected; (b) for compliance with a legal obligation; (c) for the establishment, exercise or defence of legal claims. Erasure, where the above conditions are met, will be total and complete. |
|
Restriction |
You have the right to request that Archeiothiki exercise the right to restriction of processing, that is, to retain but not use your Personal Data when: (a) their accuracy is contested so that it can verify their accuracy; (b) the processing is unlawful but you do not wish their erasure; (c) the processing is no longer necessary for the purposes for which the data were collected, but Archeiothiki still needs them for the establishment, exercise, defence or rebuttal of legal claims; (d) you object to their processing and verification of the outcome of the balancing test with Archeiothiki’s legitimate interest is pending, i.e. whether our legitimate grounds override your own lawful claims. |
|
Portability |
You have the right to request that Archeiothiki provide your Personal Data to you in a structured format, or you may request that they be transferred directly to another controller (e.g. another employer). A condition is that the data have been provided on the basis of consent or in the context of performance of the contract between us and that the data are kept by automated means and not in paper form. An additional condition is that the data have been provided by you. |
|
Objection |
You have the right to object at any time to any processing of your Personal Data the lawful basis of which is: (a) legitimate interest; (b) performance of a task; (c) profiling. If you exercise this right, our Company must demonstrate compelling and lawful grounds that override your rights and freedoms, or it must demonstrate that it needs to continue processing your data for the establishment, exercise or support of legal claims. |
|
Withdrawal of consent |
You have the right to withdraw your consent where consent is provided as the basis for processing. Your consent may be withdrawn freely and at any time upon your request to the DPO’s contact details or in any other way of which you were informed when your consent was obtained. The withdrawal of consent applies for the future. |
|
Right to human intervention |
Our Company does not make decisions by technical means through which personal aspects concerning you are evaluated and which are based solely on automated processing and produce legal effects concerning you or similarly significantly affect you. Nor does it profile you through automated processing of personal data. Archeiothiki informs you hereby that this right is also available to you. |
|
Supervisory Authority / Alternative dispute resolution |
If you consider that we did not satisfy a request that you submitted to Archeiothiki under this Policy, you have the right to submit your complaints or lodge a complaint with the local supervisory authority regarding the processing of your personal data. In Greece, the supervisory authority for data protection is the Hellenic Data Protection Authority – www.dpa.gr/. However, since the protection of your privacy is a priority for us, we encourage you to contact us regarding any issue or complaint about the processing of your personal data, as well as anything else relating to this Policy, at the contact details set out above and with the DPO appointed by our company. Additionally, we suggest that you consider Alternative Dispute Resolution – Mediation as a more flexible means of resolving disputes between us. |
9.2 We respect the confidentiality of all files containing Personal Data and reserve the right to ask you for proof of your identity if you submit a request to exercise your rights in relation to such files.
9.3 We will not charge you for exercising your rights in relation to your Personal Data, unless, as provided by law, your request for access to information is unfounded or excessive, in which case we have the right to charge a reasonable fee under the specific circumstances. In any case, we will inform you of any charges before we complete your request.
9.4 Our aim is to respond to any valid requests no later than within one (1) month from receipt, unless the request is particularly complex or you have submitted a large number of requests, in which case we may extend this period to three (3) months. We will inform you if we are going to need more than one (1) month for the reasons set out above.
10. The security of your data
10.1 Archeiothiki takes all the necessary technical and organisational security measures for the protection and security of your Personal Data against loss of their confidentiality, integrity and availability (accidental or unlawful destruction / loss / alteration, prohibited dissemination or access and any other form of unlawful processing).
10.2 The management of the Personal Data that you disclose to Archeiothiki is carried out exclusively by specially authorised personnel of Archeiothiki, who are under the Company’s control and only on its instructions, and by the recipients, where this is necessary. For the conduct of the processing, Archeiothiki selects persons with corresponding professional qualifications who provide adequate guarantees in terms of technical knowledge and personal integrity for maintaining confidentiality. Through the corresponding contractual commitments and its partners, Archeiothiki takes all those necessary security measures for the protection and safeguarding of the secrecy, confidentiality and integrity of personal data. In any case, the security of such data in the Website environment is subject to reasons beyond Archeiothiki’s sphere of influence, as well as reasons due to a technical or other failure of the network not controlled by Archeiothiki, or due to force majeure or fortuitous events.
11. Amendments to this Policy
We reserve the right to amend this Policy, for example in order to comply with new requirements imposed by applicable laws, directives or technical requirements, or in the event of a review of our procedures or practices. We will inform you of any revision to our Privacy Policy by publishing it on our Website. For this reason, we encourage you to check this page periodically.
Last updated: 09/05/2026