privacy policy

Privacy Policy Statement

Introduction

Our COMPANY created this website with the sole purpose of serving its customers. Our website www.ohmyhat.gr is simple and friendly to use, while it has been designed to meet the specific needs of each user. In our effort to best serve you, you will need to provide us with certain information in the processing of your order, which will be secured by us.

This Privacy Policy statement and the attached terms and conditions of use of this website describe the method of data collection from the website, the use of this data by us and the terms and conditions of use of this website. This Statement refers exclusively to your personal data, which you provide to us during your orders on this website.

In compliance with the current legislative framework, our COMPANY has taken all the necessary actions, applying the appropriate technical and organizational measures for the legalization, processing and safe keeping of your personal data files, committing to ensure and protect them in every way  from loss or leakage, alteration, transmission or in any other way of improperly processing it.

General note

The information voluntarily provided by the users of the mentioned website is used by our company, in order for the users to have direct and meaningful communication with the store, to provide them with answers to specific questions they ask and finally to serve and execute their orders. The information collected by our company through the website is intended to measure its traffic numbers, determine customer requirements for more products and facilitate transactions with the company. The company does not distribute the e-mail addresses, or any other information concerning its users and customers, to any other organization or partner that is not connected to it.

Collection of information

www.ohmyhat.gr designed its website so that its users can visit it without having to reveal their identity unless they wish to. Visitors to our website are only asked to provide us with personal data if they want to order product(s), register on our website and/or send us an email.

The website mainly collects two types of information about its users: (1) information that the user gives us when registering as a customer, (2) information that the user gives us in order to fulfill his order.
These items may include:

Personal data such as name, address, email address, telephone number and other contact details.
Account information, such as username and other identifiers or credentials used to access our online services.
Device information
IP address
Cookies

Processing information

a. Basic processing

In order to complete an online order, the user/customer declares his personal data as a visitor: In this case the personal data of the visitor/customer will be kept in the COMPANY’s files until the completion and delivery of his specific order, with the exception only the transaction data for tax purposes and their processing will only concern the execution of the sales contract. The user/customer can at any time change or correct their data by logging into their account at www.ohmyhat.gr (with their username and password).

The use of a credit card, for the charge of which identification documents of the legal owner are required, is guaranteed in every case.

The purpose of the basic processing of the data is the execution of the contract and the completion of the specific order, the communication with the user/customer and the sending of informative messages concerning the stages of the processing of the order, the provision of clarifications related to the order and the delivery of the order in the area of ​​choice of the user/customer. The visitor is informed that the provision of the above mandatory personal data as well as the details of his transactions are necessary and are a prerequisite for the proper execution of the order and delivery contract for products and services. For this reason, the consent of the user-client is not required for this specific processing.

Every user-customer who uses www.ohmyhat.gr is informed that his personal data concerning the receipt, execution and delivery of an order will be processed for the purpose of serving users/customers both by the competent employees of OhMyHat and by the third party recipients and/or processors on its behalf in the context of the execution of an order. These third party recipients are transport companies and internet service providers with whom the COMPANY cooperates.

No other processing or transmission of user/customer data will be done by our COMPANY and our online store (www.ohmyhat.gr)

Cookies

This website uses cookies to collect information. Cookies are small data files, which are placed on the user’s/customer’s computer or other devices (smartphones, tablets) while browsing the website, allowing the website to function smoothly and without technical anomalies, to collect multiple user options, to recognize frequent users, to facilitate their access to it, and to collect data to improve the content of the website. They are also used to customize the products and services offered and advertised to the user, both on the website and on social media. The activation of cookies requires the user’s consent.

Data subject rights

  Each registered user/customer, as a data subject, may at any time exercise his rights, as provided for in the General Regulation on the Protection of Personal Data 679/2016 EU. and in particular articles 12 to 23 thereof and national legislation and in particular:
Right of access:You have the right to be aware of and verify the lawfulness of the processing. You have the right to access the data and receive additional information about its processing.
Right to rectification: You have the right to correct, update or amend your personal data.
Right to erasure: You have the right to request the erasure of your personal data when it is processed based on your consent or in order to protect your legitimate interests. In all other cases (obligation to process personal data imposed by law), this right is subject to specific restrictions or does not apply depending on the case.
Right to restriction of processing:You have the right to request restriction of processing of your personal data in the following cases: (a) when you dispute the accuracy of your personal data and until verification is made, (b) when you object to the deletion of personal data and request deletion instead the limitation of their use, (c) when the personal data are not needed for the purposes of processing, but are nevertheless necessary for the establishment, exercise, support of legal claims.
Right to object to processing: You have the right to object at any time to the processing of your personal data in the cases where, as described above, it is necessary for the purposes of legitimate interests.
Right to portability: You have the right to receive your personal data free of charge in a form that will allow you to access it, use it and process it by commonly used processing methods. You also have the right to request, if technically possible, that your data be transmitted directly to another controller. This right of yours exists for the data you have provided and their processing is carried out by automated means based on your consent or in execution of a relevant contract.

In case of exercise of one of the above-mentioned rights of the registered user/customer, the will take all possible measures to satisfy the request within (1) one month from its submission. In this case, the registered user/customer is informed that the minimum necessary of his personal data will be kept, to safeguard the legal interests of the company.

In any case, every user/customer has the right to contact the competent Authority for the Protection of Personal Data (www.dpa.gr) and/or to bring legal action.

Data storage time

The user/customer’s data will be kept and processed by the COMPANY until the completion of his specific order. The data of the registered user/customer will be kept and processed until the user/customer requests the deletion of his account or, for any processing of his data based on his consent, until he declares the withdrawal of his consent for the purposes of providing the COMPANY services. Nevertheless, some necessary personal data concerning his transactional relations with the COMPANY as well as the member’s information, consent and withdrawal of consent for the processing of his data will remain as information for the user/customer to ensure the proof of the legality of the processing of his data from the COMPANY and the safeguarding of the legal claims of the parties.
Also, personal data is kept for as long as tax legislation requires.

Secured Transactions

The SSL (Secure Sockets Layer) protocol is today the global standard on the internet for certifying websites to web users and for encrypting data between web users and web servers. An encrypted SSL communication requires that all information sent between a client and a server be encrypted by the sending software and decrypted by the receiving software, thus protecting personal information in transit. In addition, all information sent with the SSL protocol is protected by a mechanism that automatically checks if the data has been changed in transit.