General Data Protection Regulation (GDPR)
ATHEXGROUP PRIVACY STATEMENT FOR WEBSITE USERS
Please read this notice in order to be informed in detail about the terms of processing your data.
1. Data Controller
The Companies act as independent data controllers, pursuant to General Data Protection Regulation (EE) 2016/679 ("GDPR") and national law 4624/2019, for the processing of your personal data, which is carried out when you use the Website. The registered seat of the Companies is in Athens, at 110 Athinon Ave., postal code 104 42, contact telephone number: +30 210 33 66 800 e-mail: protocol@athexgroup.gr.
2. Collection of personal data
3. Purpose of the processing
- to communicate with you in case you send a message or wish to apply for the use of the Group's services by sending an e-mail to the e-mail addresses listed on the Website or
- to manage your request to participate in training seminars; or
- to send information and press releases regarding the services provided, actions, educational activities and certifications of the Group,
- to ensure the best operation of the Website and the improvement of your navigation, with the use of cookies. Learn more about our Cookies Policy here.
4. Legal basis for the processing of personal data
5. Who has access to your personal data
Access to your personal data is granted exclusively to the necessary, in each case, personnel of the Group, who have been duly informed about the secure processing of your personal data.
In addition, your data may be received by associated natural and legal persons offering their services to the Companies of the Group, such as providers of technological and information security services and providers of educational services. These persons, acting as processors of personal data, have been informed and have committed in advance to respecting the confidentiality of your data, are aware of and follow the Group's instructions regarding the processing of personal data and take all appropriate measures for the protection of the aforementioned.
Official governmental and supervisory bodies (e.g. law enforcement and prosecution authorities, supervisory authorities, etc.) may also have access to your personal data when the Group is required to comply with the law, when the transfer is deemed necessary for important public interest reasons, and for the establishment, exercise or defense of legal claims.
6. Transfer of personal data outside the EEA
7. Automated decision-making/ profiling
Within the context of the use of the Website, profiling and automated decision-making is not carried out.
8. Data retention period
9. Interaction with third party websites
Any interconnection of the Website with other third party websites through special links, hyperlinks, banners, etc. does not imply that the Group assumes any responsibility for the content of this website, the quality and completeness of any products or services presented on this website or the policy followed on this website regarding the protection and processing of personal data. The natural person should ensure that he or she is informed about the protection and processing of his or her data by the aforementioned websites and that he or she has read their respective personal data policies.
10. Security of personal data
The Companies implement an information security management system, in order to ensure secrecy, security of data processing and protection of personal data from any accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, as well as from all inappropriate forms of processing. The Companies have implemented all appropriate organizational and technical measures in order to safeguard the processing of data against any form of accidental or unlawful processing. In this respect, the authorised personnel of the Companies that processes your personal data, has received the appropriate training and guidance. The measures taken by the Companies are reviewed and amended regularly or when deemed necessary based on new needs and technological developments.
11. Your rights
- Right to access your personal data.
- Right to correct and/or update your data.
- Right to deletion / right to be forgotten.
- Right to restrict processing.
- Right to data portability.
- Right to object to the processing of your personal data.
- Right to withdraw your consent.
12. Exercise of rights
If you wish to receive further information about the processing of your personal data or exercise any of your rights, you can contact the Companies either in writing at: Athens Stock Exchange Group, 110 Athinon Ave., 104 42 Athens, for the attention of: Data Protection Officer (DPO), or by e-mail addressed to the Data Protection Officer (DPO) of the Group at: dataprotectionofficer@athexgroup.gr.The Companies shall reply to your request within one (1) month of its receipt and at no cost to you. This time limit may be extended for a period of two (2) more months, due to the complexity or number of requests. In this case, you will be notified regarding the extension and the reasons for it at the earliest and no later than one month after receiving the request.
13. Right to lodge a complaint
If you believe that any request submitted by you has not been adequately and legally satisfied, or your right to personal data protection is being breached by any processing that is carried out by the Companies, you have the right to lodge a complaint with the Hellenic Data Protection Authority (postal address: 1-3 Kifissias Ave., 115 23, Athens, https://www.dpa.gr/, tel. 210 6475600, e-mail: contact@dpa.gr).