Personal Data Protection Policy
Valid From: 25 May 2018
This policy on Personal Data processing/protection (hereinafter “Policy”) informs about the collection, storage, processing and use of your Personal Data. The collection, use, and disclosure of your information is based on your consent and the provisions of General Data Protection Rule 679/2016 (hereinafter “GDPR”). Moreover it explains how we shield your information and data, ensuring reliability and confidentiality.
- Our Company
Our companyunder the corporate name“A. Magganiotis Car Rental GP” and distinctive title “Sixty Car” is committed and holds as its highest priority the protection of your Personal Data. We fully comprehend the importance of your Personal Data and we make every effort to carefully store and process the information you share with us.
This Policy describes all Personal Data, that our company collects for you, how we use and protect them, as well as all options you have about the way we use them. The Data Controller of Personal Data of the users / visitors of our website is our Company.
We acknowledge that protection of Personal Data is a constant responsibility and therefore we will update and amend this Policy from time to time. You are kindly requested to visit our website https:// www.sixtycar.gr / from time to time to make sure you are aware and satisfied with any amendments. In case of doubt regarding the terms of this Policy, you may contact us by e-mail at email@example.com .
- What is Personal Data?
“Personal Data” means any information relating to an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
- What is Personal Data Processing?
“Personal Data Processing” means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Data we collect
We make sure to collect only Data absolutely necessary to serve the purpose for which they were provided and such Data are used solely and exclusively for the purposes for which they were collected.
4.1.Personal Identity and Driver’s License Data, such as first name, last name, father’s name, date of birth, tax identification number, personal identification card number.
4.2. Contact Data, such as mailing address, email address, telephone number.
4.3. Payment details, such as credit/debit card number, PayPal account, bank account number.
- How we use your Data
Your Data are processed either by our authorized Company staff or by third parties who are bound by a contract with our Company, undertaking the contractual responsibility to ensure the confidentiality and protection of your Data, and process them solely and exclusively for the purposes for which they were provided.
As a general rule, your Data are processed with a view to providing you with services, including:
5.1.Price quotations: The Company processes your Data to enable it to offer you a price quotation for short- or long-term car rentals.
5.2.Car Purchase: The Company processes your Data to complete second-hand car sales.
5.3.Compliance with applicable Legislation: The Company processes your Data to enable it to meet its obligations under the law, in particular tax and insurance legislation or to provide insurance coverage for vehicles under active insurance agreements.
5.4.Information services from our Website: The Company provides information services to its clients
5.5.Contact: The Company uses Data to answer to requests/questions you make for instance through the Contact Center and contact forms.
5.6.Hiring: The Company processes your Data to assess your qualifications and skills relating to your job application as well as to contact you about it.
- The legal basis for the processing of your Data by the Company
Your Data are processed subject to:
- the terms of our contract with you
- your consent, where required
- the Company’s obligations under the Greek and European laws (e.g. tax, labor, insurance, etc. legislation)
- the Company’s legitimate interest
- How long do we keep your Personal Data?
We only keep your Data for as long as is required to fulfil the purpose for which you provided them, in compliance with applicable legislation.
Biographical data, which is submitted through email to apply for a job with the Company are kept for two (2) years, unless you have expressed your preference that we keep them for a shorter period of time or delete them.
- Guarantees for protection of your Personal Data
When you provide us with your Personal Data, we take all necessary steps to ensure that they are maintained secure. In order to protect your Personal Data, we take physical, technical and organizational protection measures. We update and control our security technology on a constant basis. We strictly limit access to your Personal Data only to our employees and network stores, who need to know this Data in order to provide our services to you. In addition we instruct our employees about the importance of confidentiality and of maintaining privacy and security of your Personal Data.
- When and how do we share your Personal Data?
In the context of our services, we may use third-party providers who provide services on our behalf. Thus, we may need to share your Personal Data with them only after we have informed you and we have received your explicit consent for this purpose. In any case, we only share with them only your Personal Data that is necessary for them to provide the services we ask for and we demand from them to protect your Personal Data and not to use it for other purposes.
Our company warranties that it will not transmit, disclose, assign, etc. your Data to third parties (save the recipients indicated in this Policy) for any purpose or use, unless it is mandatory under applicable legislation or required by public/judicial agencies/authorities.
Recipients of your Data may include but are not limited to:
1) Insurance companies working with our Company.
2) Third Parties working with our Company and offering repair, paintwork and maintenance services for vehicles rented to our clients.
3) Companies working with us to provide road assistance to drivers using our Company’s vehicles.
- Transfers of Personal Data to third countries or international organisations
The Personal Data we collect from you is not transmitted or processed outside the European Union. If this happens, you will be informed accordingly by updating this Policy.
- Your Rights
You have the following Rights:
11.1 Right of Transparent information, communication and modalities for the exercise of your Rights(§12 GDPR), i.e. the right to be informed about the way your Personal Data is used by our Company (as stipulated in detail in this Policy).
11.2. Right of information and access to your Personal Data (§13,14 GDPR). This right is dependent on whether your Personal Data has been collected by you or not.
11.3. Right of access (§15 GDPR) to your Personal Data we have collected.
11.4. Right of rectification (§16 GDPR) of your Personal Data we have collected.
11.5. Right of erasure (‘right to be forgotten’) (§17 GDPR) of your Personal Data we have collected.
11.6. Right of restriction of processing your Personal Data we have collected (§18 GDPR).
11.7. Right to be notified regarding rectification or erasure of your Personal Data or restriction of processing of them (§19 GDPR).
11.8. Right of data portability (§20 GDPR), i.e. your right to receive your Personal Data and transmit them to another Data Controller.
11.9. Right to object (§21 GDPR) to the processing of your Personal Data by us.
11.10. Right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. (§22 GDPR).
11.11. Right to withdraw your consent to us to process your Personal Data at any time (§7 GDPR). The lawfulness of processing your Personal Data is not affected by the withdrawal of your consent until the time you requested it.
11.12. Right to lodge a complaint with the Greek Personal Data Protection Authority (mailing address: 1-3 Kifissias Ave., Postal Code 115 23, Athens, Tel.: 210 6475600, email: firstname.lastname@example.org), if you believe that processing of your Personal Data by us is in violation of the applicable National and European legal and regulatory framework on Personal Data protection.
- How can you contact us?
You may contact us for any question about the processing of your Personal Data by us or to exercise your rights by using our online contact form or by sending an email to email@example.com.
We will reply to your Requests without any charge and delay, and in any case within (1) one month after we receive your request. However, if your request is complex or there are a large number of your requests, we will notify you within one month if we need to take another two (2) months extension, within which we will reply.
If your Requests are manifestly unfounded or exaggerated, in particular if they are repetitive, we may choose to charge you a reasonable fee in order to cover the administrative costs incurred in providing information or taking the action requested or refuse to take any further action with a Request.
- Applicable law to the processing of your Data by us
The applicable law is Greek law as shaped by the General Data Protection Regulation (Regulation (EU) 2016/679), and the applicable national and European legislative and regulatory framework on Personal Data protection.
The Courts of Athens have jurisdiction over disputes arising in connection with your Personal Data.
- Amendments and Updates
This Policy was last updated on 24/05/2018. We update this Policy whenever necessary. In case of major changes in the Policy or in the way we use your Personal Data, we will post an updated version of this Policy on our website and inform you by any appropriate means. We encourage you to refer regularly to this Policy to find out how your Data are protected.