NOTICE TO COUNTERPARTIES REGARDING THE PROCESSING OF PERSONAL DATA
- Introduction & Scope of this Notice
The company under the corporate name «ION SA COCOA & CHOCOLATE MANUFACTURERS», having its registered seat at Neo Faliro, Piraeus (address: Eleftheriou Venizelou str., no. 69, Postal Code: 18547), Greece (the “Company”), processes personal data in accordance with the General Data Protection Regulation 2016/679 (“GDPR”) and applicable local Personal Data legislation (together, the “Data Protection Legislation”).
This notice by the Company to its counterparties pursuant to Articles 13 and 14 of the GDPR (the “Notice”) describes how the Company collects, uses and generally processes Personal Data relating either to its counterparties (where they are natural persons) or to the legal representatives, members of management, beneficial owners and/or contact persons of its counterparties, where such counterparties are legal entities (“You”).
The Company acts as the controller of your Personal Data.
- Types of Personal Data collected – Sources
For the purposes of this Notice, Personal Data means any information relating to an identified or identifiable natural person, or that could be used to identify a natural person (“Personal Data”).
The Personal Data processed by the Company may include, as applicable:
- First name, surname, father’s name, address, telephone number, email address, products or services provided, as applicable.
- Where the counterparty is a natural person: Tax Identification Number (TIN) and tax office, ID card number, date of issue and issuing authority.
- Where the counterparty is a legal entity: job position / capacity with the counterparty.
In principle, your Personal Data is collected from you (where you are natural person) or from the counterparty of the Company (where you are legal representative, member of management, beneficial owner and/or contact person of that counterparty) who has provided it in the context of a contract or for the purpose of entering into such contract. In addition, we may obtain your Personal Data from other sources such as publicly available sources, credit rating agencies, etc.
- Personal Data of Third Parties
Where you provide Personal Data of third parties to the Company (e.g. legal representatives, staff), you must inform such individuals about the processing of their Personal Data by the Company and their relevant rights (for example, by providing them with this Notice).
Furthermore, where required by law, you must obtain the consent of such individuals for the transfer of their data to the Company and its subsequent processing. Where you provide Personal Data of third parties, the Company assumes that the relevant consent has been obtained following appropriate information.
- Why does the Company collect, use, disclose or retain Personal Data?
The Company collects, uses, discloses and retains Personal Data for the following purposes: (1) selection of counterparties, (2) entering into contracts, (3) performance of contracts, including payment management, (4) evaluation of cooperation, (5) safeguarding its legal rights, (6) compliance with our legal obligations, (7) internal audit, (8) ensuring compliance with our internal policies/procedures, (9) research (market research, satisfaction surveys, etc.), and (10) direct marketing
- Legal Basis for processing your Personal Data
The legal basis for the collection, use and processing of your Personal Data is set out in Article 6(1)(b), (c) and (f) of the GDPR. This means that we process your data: (i) for the performance of a contract to which you are a party or in order to take steps prior to entering into a contract, (ii) for compliance with legal obligations, (iii) for the purposes of the legitimate interests pursued by the Company or a third party, except where such interests are overridden by your interests or fundamental rights and freedoms (e.g. protection of legal interests, fraud prevention, internal investigations). Where the legal basis is your consent, it will be obtained separately, where required.
- Recipients of your Personal Data
The Company may from time to time disclose your Personal Data to third parties for any of the above purposes. Examples include:
- Third-party service providers (e.g. technical support services).
- Companies within the same group as the Company.
- Business advisors or auditors.
- Courts or judicial authorities, mediators, arbitrators, tax authorities, regulatory or governmental authorities.
- Public or national authorities, where required by law.
- Otherwise, where you have provided your consent for that disclosure.
- Overseas Transfers of Personal Data
Due to the nature of our business, we may disclose your Personal Data to third parties outside the European Economic Area (EEA). In such cases, except where the European Commission has recognised an adequate level of protection, we require recipients to implement appropriate safeguards for the protection of Personal Data.
- Retention of Personal Data
We will retain your Personal Data for as long as necessary to fulfil the purposes for which it was collected or to comply with legal, regulatory, accounting, audit or internal policy requirements. In determining the appropriate retention period, we consider applicable legislation, as well as the amount, nature and sensitivity of the Personal Data, the potential risk of harm from unauthorised use or disclosure, the purposes of processing and whether these can be achieved by other means.
- Your rights and obligations
(a) Your obligation to inform us of changes
It is important that the Personal Data we hold about you is accurate and up to date. Please inform us of any changes.
(b) Your rights regarding Personal Data
Under certain conditions, you have the right to:
- Request access to your Personal Data.
- Request correction of your Personal Data.
- Request erasure of your Personal Data.
- Object to processing (e.g. object to direct marketing by contacting us at the email address mentioned below).
- Request restriction of processing.
- Request your Personal Data in a structured format or request the transfer of your Personal Data to a third party (“data portability”).
- Withdraw your consent at any time (without affecting prior lawful processing).
- Request not to be subject to decisions based solely on automated processing, including profiling.
To exercise your rights or for any questions regarding this Notice, please contact us at privacy@ion.gr or by post at the above address.
You also have the right to lodge a complaint with the competent Data Protection Authority (for Greece: www.dpa.gr).
- Changes to this Notice
We reserve the right to amend this Notice at any time and will inform you accordingly by appropriate means.
