Privacy Policy

«BOOKSCANNER SINGLE MEMBER S.A. – INFORMATION TECHNOLOGY DESIGN & DEVELOPMENT SERVICES», operating under the distinctive title «BookScanner», with registered office at 2 Thermopylon St., P.C. 67131, Xanthi, Greece, VAT No. 800496710, tel. +30 25410 24450, e-mail: info@bookscanner.gr (hereinafter the «Company»), in its capacity as Data Controller, collects and further processes your personal data, only where strictly necessary, for clear and lawful purposes, pursuant to Regulation (EU) 2016/679, Law 4624/2019 and Law 3471/2006, as in force, in the course of operating the website https://www.bookscanner.gr (hereinafter the «Website») and its online store.



Definitions


For the purposes of this information notice, the following terms have the meanings set out below:


  • «Personal Data»: any information relating to an identified or identifiable natural person («data subject»); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
  • «Special categories of personal data»: data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic or biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a person’s sex life or sexual orientation.
  • «Processing»: any operation or set of operations performed on personal data, whether or not by automated means, such as collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, dissemination, restriction, erasure or destruction.
  • «Controller»: the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing. For the purposes hereof, the Company acts as Data Controller.
  • «Processor»: the natural or legal person which processes personal data on behalf of the Controller.
  • «Consent»: any freely given, specific, informed and unambiguous indication of the data subject’s wishes by which he or she signifies agreement to the processing of personal data relating to him or her.
  • «Applicable Legislation»: the national and EU personal data protection legislation in force from time to time and, in particular, the General Data Protection Regulation (EU) 2016/679 («GDPR»), Law 4624/2019, Law 3471/2006, the case law of the CJEU, as well as the Decisions, Directives and Opinions of the European Data Protection Board («EDPB») and of the Hellenic Data Protection Authority («HDPA»).


Personal data we process in the context of communication


Categories of personal data Purpose Legal basis Retention period Recipients
Identification data (first name, surname), contact data (e-mail, telephone), data included in contact forms or appointment booking requests Interactive communication with the user, responding to requests and providing quotations Article 6(1)(f) GDPR – Legitimate interest of the Company in promoting its activities 5 years or 20 years pursuant to Articles 250 and 249 of the Greek Civil Code respectively Processors: IT systems support service providers, hosting and cloud service providers


Personal data we process in the context of orders and purchases


Categories of personal data Purpose Legal basis Retention period Recipients
Identification data (full name), contact data (address, e-mail, telephone), shipping and billing data, order history Performance of the contract of sale, processing and shipping of the order, after-sales service Article 6(1)(b) GDPR – Performance of a contract 5 years or 20 years pursuant to Articles 250 and 249 of the Greek Civil Code respectively Processors (hosting/cloud and IT service providers), courier/transport companies, payment service providers
Transaction details / accounting documents Fulfilment of tax and accounting obligations Article 6(1)(c) GDPR – Compliance with a legal obligation As provided for by tax legislation Financial institutions and competent authorities, to the extent required

Card details are processed directly by a certified payment service provider in a secure environment; the Company neither collects nor stores full card details.



Personal data in the context of supplier records (natural persons)


Categories of personal data Purpose Legal basis Retention period Recipients
Identification data, contact data, transaction history (accounting documents, declarations) Supply of products/services to the Company and fulfilment of tax obligations Article 6(1)(b) & (c) GDPR – Performance of a contract / Compliance with a legal obligation 5 years or 20 years pursuant to Articles 250 and 249 of the Greek Civil Code respectively Processors, financial institutions to the extent required for the execution of payments


Personal data for information / newsletter purposes


Categories of personal data Purpose Legal basis Retention period Recipients
Contact data (e-mail) Direct marketing of products and services by electronic means Article 6(1)(a) GDPR & Article 11 of Law 3471/2006 (consent), or legitimate interest in respect of existing customers (Article 11(3) of Law 3471/2006) Until consent is withdrawn or you object Marketing / newsletter distribution service providers

No automated decision-making, including profiling, is carried out.



Data we collect automatically


When you use our Website, we also automatically collect certain information, part of which may constitute personal data. This includes, indicatively, language settings, IP address, approximate location, device settings and operating system, browser version, time of use, referral URL, browsing history and the type of content you viewed. We may also collect data through cookies. For information regarding the use of cookies, please refer to the Company’s Cookies Notice.



Transfer of Personal Data outside the EEA


As a rule, the Company does not transfer your personal data to third countries and/or International Organisations. The hosting infrastructure it uses is located within the European Economic Area (EEA). In the event of a transfer of personal data to a country outside the EEA or to an International Organisation, the Company first ensures that one of the legal bases of Article 6 GDPR is met, in combination with one of the conditions of Chapter V GDPR.



Rights of Data Subjects


The Company takes care to respond promptly to data subjects’ requests for the exercise of their rights in accordance with the Applicable Legislation. In particular, every data subject has the right:


  • Of access to the data concerning them
  • Of rectification of inaccurate or incomplete data
  • Of erasure («right to be forgotten»)
  • Of restriction of processing
  • Of data portability
  • To object to processing activities based on the Company’s legitimate interest

In addition, for processing activities for which you have provided your consent, you may withdraw it at any time, without affecting the lawfulness of processing based on consent before its withdrawal.


You may exercise any of the above rights by sending a relevant request to info@bookscanner.gr, and the Company will respond promptly, in any event within thirty (30) days of submission of the request, informing you in writing of the progress made in satisfying it.


For any complaint regarding this information notice or personal data protection matters, if we do not satisfy your request, you may address the Hellenic Data Protection Authority (www.dpa.gr).



Disclaimer for Third-Party Websites – Social Media Buttons


The Website may contain social media widgets (e.g. Facebook, LinkedIn); through their use, and provided the user is logged in to the relevant social network, a digital footprint of the user is created, in respect of which both the Company and the social network act as joint controllers. The purpose of the processing is to improve the functionality of the Website and to analyse its traffic, on the legal basis of legitimate interest (Article 6(1)(f) GDPR).


The Company neither controls nor is liable for any subsequent processing carried out by the joint controllers. For further information regarding the data processing policies and the settings options of these networks, you may visit the respective privacy policies of Facebook (facebook.com/privacy/policy) and LinkedIn (linkedin.com/legal/privacy-policy).