This Privacy Statement describes the method of data collection and its usage by Ermes Department Stores Plc (the Company).
The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation (GDPR 2016/679), the applicable Cypriot legislation on the protection of personal data, any other potentially applicable national and European legislation for certain legal sectors, and for the Regulation of Electronic Communications and Postal Services (Law 112(I)/2004, as applicable).
1. WHAT IS PERSONAL DATA?
Personal data is information that identifies you directly or indirectly. Indirectly means in combination with other information, such as your name, postal address, email address, and phone number, or a unique device identification number.
2. GATHERING INFORMATION
The Company may collect the following information:
• information upon the registration of a person as a customer or as a member in a database,
• information upon the registration of a person to receive notifications via e-mail or sms or other commercial communication channels
• when placing an order on www.eshop.era.com.cy (the website),
• information for participation in contests that are held from time to time,
• information when logging on to the website through another platform (applications, IOS, android, Facebook, Google).
• information when communicating with the Company (e.g. by email, social media, telephone).
• information received during your interaction with advertisements and applications of the Company and/or third parties, where a link is contained to this Statement.
When filling out the order form on our website (www.eshop.era.com.cy),you will be asked to provide:
• Post code
• Credit card details
• Payment method of the order.
• Shipping and delivery details of an order,
• Pricing information or details about an offer you have requested.
• Other information required for the execution of an order.
• Information necessary for the provision of warranty services.
The Company may make use of your data:
• To contact you about (i) the delivery of an order, (ii) for confirmation and identification when required, (iii) for new or alternative products offered, (iv) special offers, (vi) receipt of gifts after a contest draw, (vii) receipt of personalized gifts,
• To comply with regulatory obligations, such as verifying your age and your status as a user of our products, where necessary,
• In the context of providing services to you regarding sales, such as to process your requests and answer any questions you may have, as well as to provide warranty services,
• In the context of selling our products to you, such as to process your orders and process your payments,
• To support all of the above, including managing your accounts, the ability to use contact points, to communicate with you, personalize your experience, and to manage and resolve any issues.
• We may need to use and retain your personal data for legal and compliance reasons, such as for the prevention, detection, or investigation of a crime, prevention of loss, fraud or any other misuse of our services and computer systems. We may also use your personal data for internal and external audit purposes, to secure information, or to protect or exercise our rights of, privacy, security, property or third persons.
3. ACCESS TO INFORMATION
By providing your personal data you consent that your data will be used by the Company's employees and partners for the reasons mentioned above.
Under no other circumstances may the Company share your personal information with others without your prior consent, unless required through any legal route. Please note that under certain conditions it is permitted, when required by law or on the basis of a court order, to collect, use and disclose of your personal data, which have been collected online without your prior consent (such as the case of a court order).
Your personal data will be used for the purposes described above. We collect and process as much personal data as is necessary to meet the required purpose. If we intend to use your personal data that we process with your consent, for purposes other than those disclosed in such consent, we will inform you in advance and, in cases where the processing is based on your consent, we will use your personal data for a different purpose only with your permission.
For existing customers, we may use the information we have received as part of our existing customer relationship to inform you for products or services related to similar products or services that you have previously requested, used, or may be of interest to you. You may, however, object to such use at any time either at the time that your data is collected or whenever you send a message. To stop receiving emails for marketing purposes, follow the instructions in the email you receive.
Please note that cookies are absolutely necessary in order for the website www.eshop.era.com.cy to function properly and seamlessly.
Cookies do not cause any damage to users' computers or to the files stored on them.
Cookies are divided into the following categories:
Necessary Cookies. They allow the execution of basic functions of the site, such as storing products in the shopping cart, adding products to the cart, online payments which are necessary for the smooth operation of the website, in addition their absence significantly limits your personal navigation experience and also underperforms the basic functions of e-commerce.
Functionality cookies. They remember your preferences when browsing our website, so we can recommend the right products based on your needs, helping you find what you are looking for easily.
Cookies Analytics. They constitute a subset of the functionality of Cookies and enable the website to evaluate the effectiveness of the various functions of our website, thus continuously improving the experience we offer to you www.eshop.era.com.cy may use Google Analytics features to display ads (e.g., remarketing, display reports in the Google Display Network, etc.).
Using Ad Settings, https://adssettings.google.com/authenticated visitors can opt out of Google Analytics for display ads and customize Google Display Network ads. Here are the available opt-out options - https://tools.google.com/dlpage/gaoptout of Google Analytics.
Performance cookies. They collect information about how visitors use the site and allow us to see which pages they visit most often, let us know if they have a problem navigating etc. Performance cookies collect aggregated information that is anonymous information and therefore do not collect information that identifies the visitor. Their use is limited only for the purpose of improving the functionality of www.eshop.era.com.cy.
Advertising Cookies. They provide ads related to your interests. They are also used to send advertisements or offers that are tailored to your needs, thus limiting unwanted and meaningless, promotional messages. They also help us measure the effectiveness of our advertising campaigns.
www.eshop.era.com.cy complies with the Interest-Based Advertising Policy https://support.google.com/adspolicy/answer/143465 of Google AdWords and its restrictions on sensitive categories and:
We reserve the right to change this Cookies policy at any time. Any changes to this Cookies policy will apply as soon as the revised Cookies policy is available on our website.
Third-party advertisers and other businesses we work with may use their own Cookies to collect information about your activities on our website. We do not control these Cookies.6. TRANSFER OF BUSINESS
The Company will not collect or process personal data of children under the age of 16 unless parental consent has been granted, in accordance with applicable local law. If we realize that a child's personal data was accidentally collected, we will delete that data without any delay.8. PROCESSING SENSITIVE DATA
In some cases, we may process specific categories of personal data about you ("sensitive data"). For example, we may process sensitive data that you have made public. We may also process sensitive data, where appropriate, to support, pursue or defend legal claims. We may also process your sensitive data if you have freely given your prior express and separate consent in a specific context for a specific purpose.9. TRANSACTION SECURITY
The Company is committed to ensuring the security and integrity of the data it collects, regarding the users of its website. The Company has adopted procedures that protect the personal data that users provide on its website or provide it by any other means (e.g. by telephone). These processes protect users' data from any unauthorized access or disclosure, loss or misuse and change or destruction. They also help to certify that these data are accurate and used correctly. Your connection to it is secure because it uses TLS technology with a size of 256bits. TLS technology relies on a key code to encrypt the data before being sent over the (TLS) connection.
The security check between the data and the Server is based on the unique key code ensuring secure communication. The Browsers, Internet Explorer, Mozilla Firefox, Safari support the TLS protocol and it is recommended to use them to connect to the www.eshop.era.com.cy's website.
We apply the appropriate level of security and have therefore implemented reasonable physical, electronic, and administrative procedures to safeguard the data we collect from accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data transmitted, stored or otherwise processed. Our information security policies and procedures are closely aligned with widely accepted international standards and are regularly reviewed and updated, where necessary, to meet our business needs, changes in technology, and regulatory requirements.
In the event of a data breach containing personal data, the Company will comply with applicable laws regarding the notification of the breach.10. YOUR LEGAL RIGHT
As a data subject you have specific legal rights relating to the personal data, we collect from you. The Company will respect your rights and will fully respond to any concerns you have as you address it.
The following list contains information about your legal rights arising from applicable data protection laws:
• Right to withdraw consent: Where the processing of personal data is based on your consent, you may withdraw such consent at any time.
• Right to correction: You can ask us to correct your personal data. We make reasonable efforts to retain your personal data that we control or have in our possession and are used on an ongoing basis, accurate, complete, and up to date, based on the latest information available to us. You can also check and correct your personal data by entering your personal account on www.eshop.era.com.cy
• Right to limitation: You may request from us to limit the processing of your personal data, if
- You question the accuracy of your personal data for the period when we will need to verify the accuracy,
- Processing is illegal and you request that we restrict the processing of your data instead of deleting your personal data
- We no longer need your personal data, but you need it to support, exercise or defend legal claims, or
- You have an objection to the processing of your data for the period when we verify whether our legitimate interests take precedence over yours.
• Right to access: You may ask us for information about personal data that we store for you, including information about the categories of personal data we own or control, for what purpose they are used, from what source they were collected, if not by you directly, and to whom they have been shared, in each case. You can obtain from us free of charge a copy of the personal data we keep for you. We reserve the right to charge a reasonable fee for any further copy you may request.
• Right to transfer: At your request, we will transfer your data to another controller, where technically feasible, provided that the processing is based on your consent or is necessary for the procedure of a contract. Instead of receiving a copy of your personal data, you may ask us to transfer the data to another controller, that you will indicate to us, directly.
• Right to erasure: You may ask us to delete your personal data, where - personal data is no longer necessary in relation to the purposes for which they were collected or processed - you have the right to object to further processing of your personal data and you exercise this right - the processing is based on your consent, you withdraw your consent and there is no other legal basis for processing - your personal data have been processed illegally, except where the processing is necessary - to comply with a legal obligation, which requires processing by us – especially for a legal duty-fulfilling obligation - to support, pursue or defend legal claims
• Right to object: You may object - at any time - to the processing of your personal data due to your particular situation, provided that the processing is not based on your consent but on our legitimate interest or on a legitimate interest of third parties. In this case we will no longer process your personal data unless we can demonstrate compelling legitimate reasons and an overriding interest in processing or supporting, exercising or defending legal claims. If you object to the processing, please specify whether you wish to delete your personal data or restrict our processing.
• Right to lodge a complaint: In the event of an alleged breach of the applicable privacy law, you may lodge a complaint with the data protection supervisory authority in the country where you live or where the alleged infringement occurred.
• Time period: We will try to satisfy your request within 30 days. However, the time limit may be extended for specific reasons relating to that legal right or the complexity of your request.
• Restricting access: In some cases we may not be able to provide access to all or some of your personal data under legal provisions. If we refuse your request for access, we will inform you of the reason for this refusal.
• Non-recognition: In some cases, we may not be able to search for your personal data because of the identifiers you provide in your application. Two examples of personal data that we cannot look for when you provide your name and email address are: - data collected through browser cookies, - data collected from social networks if you have posted a comment under an alias not known to us.
In such cases, where we cannot identify you as a data subject, we are unable to comply with your request to enforce your legal rights as described in this article, unless you provide us with additional information that allows you to be identified11. MANAGEMENT OF CURRICULUM VITAE
By submitting your CV through our Website or via any other means, your personal data is being processed by the companies of the Group for employment evaluation purposes only.
We provide you with the option to choose, should you wish to do so, to keep your CV for an additional period of time after the completion of the hiring process for the particular vacancy you have applied for, or for consideration for future potential vacancies, by filling in your details in the online form of our Website and clicking on the available tick-box, available for that purpose. If you do not do this, your CV will be deleted immediately after the vacancy is filled. Additionally, you have the right to retract your consent, as noted below.
Within the same framework, we process all other data you may provide to us or that we may obtain during the evaluation process, such as psychometric tests, which, if the necessary consent is not given, are also deleted immediately after the filling of the specific vacancy along with your other data.12. RETENTION OF YOUR PERSONAL DATA
In general, we will delete the personal data that we collect from you if they are no longer necessary to achieve the purposes for which they were originally collected. However, we may be asked to store your personal data for a longer period of time due to legislation.
In addition, we will not delete all of your personal data, if you have asked us not to contact you in the future. For this purpose, the Company maintains records containing information about people who do not wish to be contacted in the future (e.g. through group e-mail messages). We categorize your requests as consent for the storage of your personal data for the purposes of maintaining that file, unless you give us different instructions.
Please address any questions on the issue of data protection and any requests to exercise your legal rights to the data controller at email@example.com
You can also contact the Office of the Commissioner for Personal Data Protection in Cyprus at firstname.lastname@example.org
If you use the website www.eshop.era.com.cy you accept and consent to this Privacy Statement, as well as the terms and conditions of use of the website announced through it.
Release Date 24th March 2021