Privacy Policy
D GROUP is committed to ensuring full compliance with applicable Personal Data Protection legislation within its field of activity. The present Policy establishes the fundamental principles under which D GROUP processes the personal data of clients, employees, suppliers, partners, and other individuals. This Policy applies to D GROUP and its directly or indirectly controlled subsidiaries based in Greece. All employees, whether on permanent or fixed-term contracts, as well as all subcontractors working on behalf of D GROUP, are bound by this Policy.
Below are the key definitions of the terms used in this document, as set out in Article 4 of the General Data Protection Regulation (GDPR), in order to familiarize the data subject with the terminology of the Regulation:
Personal Data: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special categories of Personal Data: Personal data which are, by nature, particularly sensitive in relation to fundamental rights and freedoms require specific protection, as the context of their processing could create significant risks to the fundamental rights and freedoms. These personal data include personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union participation, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation.
Data Controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Processor: a natural or legal person, public authority, agency or other body which processes personal data on behalf of the data controller.
Processing: any operation or set of operations, which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Authority: The Hellenic Data Protection Authority (HDPA).
D GROUP, as a data controller, strictly adheres to the data protection principles set out in Article 5 of the General Data Protection Regulation.
3.1. Lawfulness, Fairness and Transparency
D GROUP processes personal data lawfully, fairly and in a transparent manner in relation to the data subjects.
3.2. Purpose Limitation
Personal data are collected only for specified, explicit and legitimate purposes and are not further processed for any other purpose.
3.3. Data Minimisation
D GROUP maintains accurate personal data of data subjects and ensures that their retention is limited to what is necessary in relation to the purposes for which they are processed. At the same time, it applies appropriate technical measures to achieve the above objectives.
3.4. Accuracy
The personal data maintained by D GROUP are accurate and kept up to date. Measures are taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified within a reasonable timeframe.
3.5. Storage Limitation
Personal data are kept for no longer than is necessary for the purposes for which D GROUP processes them.
3.6. Integrity and Confidentiality
Taking into account the state of the art and other available security measures, the cost of implementation, as well as the likelihood and severity of the risks for personal data, D GROUP implements appropriate technical or organizational measures for processing Personal Data in a manner that ensures appropriate security of the personal data, including protection against accidental destruction, loss, damage, unauthorized or unlawful processing.
3.7. Accountability
D GROUP bears responsibility for and is able to demonstrate compliance with the General Data Protection Regulation to the competent Data Protection Authority.
4.1. Notice to Data Subjects
Prior to or at the time of collecting personal data for any processing activity undertaken by D GROUP, including but not limited to the sale of products, provision of services or marketing activities, D GROUP is responsible for providing appropriate information to the data subjects. Specifically, this includes information regarding the types of personal data collected, the purposes of processing, the processing methods, the rights of data subjects in relation to their personal data, the retention period, any international data transfers, whether personal data are disclosed to third parties in the context of cooperation, as well as D GROUP’s security measures for the protection of personal data. This information is provided by means of the Privacy Notice.
4.2. Consent – Free Withdrawal
Where the collection of personal data relies on consent of the data subject as its legal basis, D GROUP is responsible for ensuring that data subjects grant their consent freely, by a positive action, explicitly and in full awareness of the content of the text to which they consent. D GROUP provides data subjects with the option to withdraw their consent at any time. Where collection of personal data of children under 16 years of age takes place, D GROUP ensures that parental consent has been given prior to collection. Processing of personal data must take place solely for the purpose for which they were originally collected. In the event that D GROUP wishes to process collected personal data for another purpose, it must seek the consent of data subjects in an explicit and specific written manner. Any such request must contain the original purpose for which the data were collected, as well as the new or additional purpose(s).
4.3. Collection
D GROUP makes every effort to ensure that the amount of personal data collected is kept to the minimum necessary. If personal data are collected from a third party, D GROUP ensures that such data are collected lawfully.
4.4. Relationship of D GROUP with Third Parties
In cases where D GROUP uses a third-party supplier or commercial partner to whom it assigns the processing of personal data on its behalf, it ensures that the processor provides appropriate security and protection measures for personal data in order to address potential related risks.
D GROUP makes every effort to ensure that its suppliers or commercial partners process personal data solely for the performance of their contractual obligations towards D GROUP, strictly in accordance with its instructions and for no other purpose.
4.5. Access Rights of Data Subjects
D GROUP, as Data Controller, is responsible for providing data subjects with an access mechanism to their personal data, which additionally enables them to review, rectify, erase or transfer such data.
4.6. Data Portability
Data subjects have the right to receive, upon request, a copy of the data they have provided to D GROUP in a structured format and to transmit those data to another controller. D GROUP is responsible for ensuring that these requests are processed within one month, provided that such requests are not manifestly unfounded. In exercising the right to data portability, the data subject has the right to have the personal data transmitted directly from one controller to another, where technically feasible.
4.7. Right to Erasure
Upon request, data subjects have the right to request from D GROUP the erasure of their personal data. D GROUP will promptly take the necessary actions (including technical measures) to satisfy the request and will ensure the same from any third parties that use or process personal data on its behalf.
4.8. Right to Object
The data subject has the right to object, at any time, to the processing of personal data concerning them, including profiling.
4.9. Right to Restriction of Processing
Upon request, data subjects have the right to request from D GROUP the restriction of processing of their data in accordance with Article 18(1)(a)–(d) of the General Data Protection Regulation (EU) 2016/679.
4.10. Exercise of Data Subject Rights and Withdrawal of Consent
The data subject may exercise their rights as well as withdraw their consent by submitting a written request to D GROUP. The data subject may freely withdraw their consent at any time without affecting the lawfulness of processing based on consent before its withdrawal, by sending a written request/letter or email to: info@dgroup.edu.gr
The Data Controller for the personal data of the data subject is D GROUP, headquartered in Athens, 98-100 Akadimias Str., 106 77.
Furthermore, the data subject may address the Data Protection Authority using the following contact details: www.dpa.gr, email: contact@dpa.gr, telephone number: +30 210 6475600, Address: 1-3 Kifissias Ave., P.C. 115 23, Athens.
When D GROUP becomes aware of a potential or actual personal data breach, it will immediately conduct an internal investigation and take appropriate remedial measures within a reasonable timeframe, in accordance with the Personal Data Breach Policy. When there is a risk to the rights and freedoms of data subjects, D GROUP is obliged to notify the breach incident to the Data Protection Authority without delay and, in any event, not later than 72 hours.
If you have any further questions or require any clarification regarding the processing of your personal data by D GROUP, you may contact us and our Group will be pleased to assist you promptly.