PERSONAL DATA PROTECTION POLICY
If there are substantial changes to this Policy or our practices regarding your data change in the future, we will notify you by publishing the changes to our Website. However, if you wish any clarification or information regarding the changes, or you wish to raise a dispute, a reservation or a question about such changes, you may contact us at the address listed in the section below. Please note that any information/clarification provided to you in connection with any changes to this Policy does not constitute a replacement, substitution or modification of this Policy.
If you continue to navigate on our Website, or to use our Services and/or to make purchases through our Online Store, this means that you automatically and unreservedly accept the modified terms of this policy. If you do not agree with the modifications, you must not take any action or make any use of the Website or purchase, and you must not provide any personal data. However, you are entitled to terminate the contracts between us and ask for your Account and data to be deleted. In any case, for any information or clarification, you may contact us while retaining your rights with respect to your personal data as outlined and described in Section V below.
Information about your Personal Data Processing Officer as well as contact details of the Personal Data Protection Coordinator (DPC) for any issue that relates to your data;
The types of data we collect for you and the collection methods used;
The purpose of collecting and processing your personal data and the legitimate basis for processing them;
The security measures we take to protect your personal data;
The time period during which we keep your personal data;
Your rights and how you can access them, and your choices regarding the collection and processing of your data;
protection and storage of your data.
II. CONTROLLER & PERSONAL DATA PROTECTION COORDINATOR
1. Who is the Controller?
The Controller of your personal data is the company “That Gorilla Brand Private Company” and the trade name “That Gorilla Brand (Tax Reg. No 801057803, Tax Office: Kifisia, Registration no. 148058701000). The company's head office is located in Ekali, Kifisia on Eratous street, no. 2 Postcode 14578. (hereinafter referred to as the "Company").
Contact details of the Company’s Data Protection Coordinator
3. Questions and Feedback
You may contact us at the contact details listed above and provide us with your feedback, queries, comments or any complaints regarding this Policy and the collection and processing of your personal data, in general. You have the right to submit any complaint regarding your personal data that may arise from their processing by the Company to the Hellenic Data Protection Authority, which is the supervisory authority of Greece. For details, see the following link www.dpa.gr. However, we consider it our obligation and duty to handle any concerns you may have about your personal data we process, so please do not hesitate to contact us.
III. DATA COLLECTION AND PROCESSING
Personal data or personal information means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is one whose identity can be identified, directly or indirectly. Such data do not include data that are anonymous.
1. When you navigate to our Online Store or That Gorilla Brand Social Media, submitting an order, open your Account, sign up for our Newsletters or the That Gorilla Brand Loyalty Program, you take part in promotional activities such as contests, social media interaction (e.g., comments, Likes, etc.) or otherwise, we collect various types of personal data for you, either directly from you or from third parties, or which we collect or create by our own means (including through automated means).
Indicatively, we collect the following personal data for you:
Identity Data: (name, username, membership code, or other similar ID) that you provide to us when submitting your order or when registering as a That Gorilla Brand Member with the opening of an Account, your participation in contests, etc.
Contact Data: (fixed and/or mobile phone, e-mail address and other contact information) that you provide to us when submitting your order, opening an Account or as part of receiving a commercial communication from our Company or participating in various actions of our Company (e.g. contests, etc.).
Delivery Details: Postal address (street, number, PO, city, country)
Financial data: (bank account, transaction value, credit notes, refunds, debit or credit card information, billing address, etc.) that you provide to us when you pay by electronic means, in the case of refunds deducted from your purchases, etc. The card details, their confirmation, preapproval of payment and final charge are recorded in Eurobank secure environment (SSL). The website www.thatgorillabrand.com is by no means aware and does not handle or store your card details.
Transaction/Purchase Data: (type of purchase, transaction value, place of delivery, time of purchase, purchase history, complaints, payment method, details required in case of change or re-crediting of an account, such as a bank account, beneficiary name, IBAN, banking institution etc.) that we collect about your purchase and/or your Account.
Consumer Behavior Data: Consumer preferences while browsing the e-shop, i.e. the items you view, your shopping cart, Wishlist, your social media activity (e.g. what products you like), gifts redeemed, the frequency, way, time of purchase, the type of purchase, etc., by type of products, comments, or any replies to surveys we make.
Technical data such as for example channel - source of origin, Internet Protocol (IP) address, time zone and location, login details, browser type and version, operating system and platform, and other technology on the Devices that you use to access our Website, etc.
Login Data to connect to your Account or to the account of a member of the fidelity program, i.e. your username (which corresponds to your email or mobile phone number) and password.
Profile Data as part of your participation in That Gorilla Brand’s loyalty program, we collect data about your interests and consumer preferences, collecting and redeeming your reward points, participating in contests or events, and all your interactions with That Gorilla Brand in general.
Demographic data: age, sex, place of residence, which are collected directly from the data subject, as the case may be, or deduced from the transactions of the subjects in our Online Store, etc.
Data collected through Cookies: Browser, IP address, products you have placed in the shopping cart but not purchased yet, the country of origin of your order, the products you are looking at in the Online Store, Wishlist with your favorites, other websites from which you were directed to us.
Marketing data: which include your preferences in receiving promotional material from us and third parties and your preferences concerning your communication with us, whether we have your consent or you have subscribed to the That Gorilla Brand loyalty program, your opinion on the products you have purchased from us.
We do not knowingly collect any information from anyone under the age of 15. Our services are aimed exclusively at people who are at least 15 years of age or older. In case you are under 15.
Your obligation to let us know about changes to your personal information.
2. It is important that personal information we keep for you is up-to-date and accurate. Please let us know as soon as possible about any changes to your personal information throughout our relationship with you.
We collect directly by you the following personal information:
At the time of submission of the order whether electronically or by telephone, you must give us your full name, product shipping address, email address, mobile phone number and payment details (credit / debit card, etc.). The card details, their confirmation, preapproval of payment and final charge are recorded in Eurobank secure environment (SSL). The website www.thatgorillabrand.com is by no means aware and does not handle or store your card details.
When registering at the That Gorilla Brand Rewards Program or when you open an Account, either through our website or through our stores, through the relevant form you fill out, you must provide us with your mobile phone number, your full name, date of birth, and a password. Optionally and if you wish, you can also provide to us your email, the date of your name day and your home address.
To sign up to the list of recipients of our Company’s Newsletters, you must provide to us your email.
To sign up for the contests which our Company organises from time to time, you must provide to us your personal information as determined on a case by case basis.
When communicating with us in the Company’s social media (Facebook, Instagram, etc.) and with the customer service department (except to place a telephone order), you must provide to us your personal information, such as ID, contact, or transaction details, which we will use on a case-by-case basis only to process your request.
We collect with automatic means the following data and information about you.
By using cookies and other related technologies, we collect and/or generate data about your preferences, such as the products you view, the time and frequency of your views, the type of newsletters you open or not, their content and your communication with us after every newsletter, your Wishlist, the type of products you buy, the search terms you enter, or the links you click on in the Online Store, the products you place in the cart without completing their purchase, country of origin, language etc.
From your Account we create the history of your orders and purchases, from which we infer your preferences, the frequency of your purchases by type, the value of the products you buy or are interested in, the time you buy, the area your stay etc.
Data about the devices through which you visit our Website, for example the Internet Protocol (IP) address, login information, browser type and version, operating system and platform and other technology on the devices used to access our Website, etc.
Data about the page from which you signed up and the page that you visited when you left,
We collect from third parties the following data and information about you:
We may receive your personal information, such as your full name and e-mail address, from a friend of yours who entered your details for you to receive a voucher from us or for us to send you a gift that he has selected for you.
If you sign up for our service through a social networking platform, we may collect the above personal data directly from the information you have provided to the platform (as long as the social networking platform is entitled to share your personal data with us).
Your personal data may be shared with us by third independent organizations when there is a legal basis for processing and they are entitled to do so. In such cases, you must be informed about the processing of your personal data from the relevant Data Protection Notice of these third parties. These organizations may include social media such as Facebook, Instagram, Viber, Twitter.
3. All of your above personal data, which as mentioned above, which are provided to us by you either on a mandatory or on a voluntary basis, or which we collect from third parties or are generated by automated means, are used for the following legitimate purposes. Please note that if Community or national law restricts or prohibits certain actions of the Company for which we use your data, we will discontinue the use of your information for these purposes.
In particular, your personal data are used by us for the following purposes:
To receive your orders, process them, and ship products to you.
To communicate with you about issues relating to the sale of our products to you.
To manage, handle and process your payments, including the security of our financial transaction.
To help you, as a That Gorilla Brand member, in opening your Account with us.
To create, keep and maintain a database with our client base and to analyse it.
To send to you commercial communication via Newsletter, SMS, or other media (VIBER) regarding our Company's news, products, promotions and offers.
To analyze your behavior and identify your preferences.
To understand and analyze the results of our ads and promotions.
To handle your requests, such as withdrawal, product replacement, etc.,
To satisfy your rights with respect to your personal data.
To ensure security of transactions.
For business analyzes and enhancements, such as placing our products on the market and optimizing our products, optimizing your experience and service from us within our Online Store, managing Loyalty programs, as well as adapting your experiences to our Online Store.
To carry out market research, statistical analyzes, marketing strategy development and marketing campaign management and inform you or our partners of any possible opportunities to participate in That Gorilla Brand 's marketing or promotional initiatives.
For other purposes for which we will notify you or will be identified on a case-by-case basis at the place where your information is originally collected
4. The Legal basis on which we make use of your information is either one of the following
- Performance of a contract to which you are a party.
- Any legitimate business interest against which your data protection interests do not prevail.
- To comply with a legal obligation with which we our bound,
- If none of the above apply, your consent (which you will always be requested to provide before we process any information).
Your free and informed consent is the legal basis for using your email and/or mobile phone for us to send you direct mail in the Newsletter form to your emails, or for you to receive updates on That Gorilla Brand news and offers through SMS/VIBER on your mobile phone, when you are not for example our client or as appropriate.
Your e-mail or mobile phone for the purpose of commercial communication via information email, SMS, VIBER etc. within the framework of our customer relationship, if you buy from us, for the development of our business activity, the optimization of commercial and technical systems, statistical analysis to improve products, optimized customer service,
Purpose of Processing Data we process for this purpose Legitimate Processing Basis
Member Registration - Creation of Account - Account Management at That Gorilla Brand
We process your data for the following purposes:
- To identify you each time you request access to your Account.
- To provide you access to the functions and services of the Member Account.
- View the history of your orders and purchases.
- To allow you to use the services/functions of your Wishlist, favorites, address management, etc.
A) Identity Data that you provide to us for creating a That Gorilla Brand account:
- Name - Surname
- Contact phone (mobile)
- Date of birth
- Physical address
- Name day
B) Transaction Data (type of purchase, value, date of purchase, place of delivery, etc.)
C) Data about cookies for your Wishlist
The legal basis for treatment of your personal data is:
a) our legitimate interest for security of your account and your identification, wherever required, also for the purpose of protecting you against fraud or security incidents.
Download, manage and execute your order via That Gorilla Brand’s e-shop or by phone:
- submission of orders by customers
- registration of orders
- product pricing
- management of payments, fees and charges
- delivery of products to customers
- withdrawals or returning a product for another reason
- order processing and handling, in general
- Contact with customers for updates, notifications regarding the order
- Initiating mechanisms to prevent fraud against you or against us.
- To ensure the use of your gift vouchers, etc. A) Identity Data
- First name
- Last name
B) Delivery Data
- Postal address of product delivery (street, number, PO, city, country)
C) Communication Data,
- Mobile phone
In case the call is recorded, you will be notified beforehand by a relevant audio message.
D) Financial Data:
- payment and card details
E) Transaction / Market Data
The legal basis for treatment of your personal data is:
(a) performance of the contractual obligations which the Company undertakes to perform to you under the sale contract.
(b) compliance with its legal obligations.
(c) legitimate interest,
d) consent in cases of data provided by you on a voluntarily basis.
Pre-Sale or After-Sales Customer Service and Handling including:
- Communication by the client using the Company’s communication means (contractual media, email or call center, or multimedia communication eg viber or other media eg Social Media)
- Communication by the Company at customer's request to the details provided by the customer.
- Customer service in general for issues related to the company, e-shop, products, services, ordering, its Account, or any contests implemented at any time, any guarantees it provides, the social media of the company.
- Complaints or clarifications
- Exercise of rights
- Managing and optimizing the experience and service of the user in the e-shop
Processing for this purpose includes
(a) the absolutely necessary details you give us when submitting your request, that is
- Identity Data
- Communication Data
/ Transaction Data
- Information that you provide to us related to your request
(b) data that we develop for you.
In case the call is recorded, you will be notified beforehand by a relevant audio message
The legal basis for treatment of your personal data is:
(a) compliance with the Company's legal obligation to adopt pre/post-sale customer service tools/means to respond to your queries related to the exercise of your rights.
(b) the legitimate interest of the company to respond to your requests through various communication channels, optimize customer service and management, and provide our customers with the ability to communicate with them and address any of their issues in the best possible way based on their needs and always to the benefit of the subject and which is reasonably expected by the subjects.
Any user may opt-out at any time by accessing his/her personal information for that purpose, such as for the data kept in the relevant purchase file, by stating so to the customer service staff or otherwise or by contacting the Company by any means for any of the above.
(c) performance of a contract if you contact us specifically to raise any issues related to your order
(d) customer's consent to receive communication from the Company for this purpose when they ask the Company to contact them.
Advertising & Marketing
For the purpose of advertising & marketing, the company may process:
Transaction / Purchase Data
and/or any combination of the above.
For this purpose, our Company shall process your email and mobile phone depending on the products you have viewed in our store or left in your cart,
The legal basis for treatment of your personal data is:
(a) a legitimate interest of the Company to process customer data that were provided to us in a purchase or other transaction with us for the purpose of direct commercial communication for related products or purposes.
(b) consent if you voluntarily give us your data, you authorize us to send you our newsletters via email, sms, viber and other media, when you agree to receiving push notifications, when accepting both Remarketing Cookies and receiving emails/sms/viber messages about the products you viewed during your visit to our store or left in your cart.
5. In the context of the operation of our e-shop, the fulfillment of our contractual obligations and your best service, our Company reserves the right to cooperate with third-party service providers that provide us with support and access only to your data that are absolutely needed by us (e.g. for registering you in the e-shop and managing your account, for executing the contract between us and providing any of our services to you, in general, for the functional and IT handling of our website www.thatgorillabrand.com, for optimizing our products and services, etc.). These third service providers are contractually bound not to use your information in any way other than to help us provide you with the products and services we agree to.
We reserve the right to disclose your personal data to a third party which we reserve the right to choose to transfer all or part of our business. In addition, in the event of a merger or redemption, or other change in our business, new owners, shareholders, administrators etc. have the right to use your personal data in the same way as this privacy statement.
Your retained data may be communicated to the competent judicial, police and other administrative authorities upon their request and in accordance with the applicable laws. Furthermore, in the case of a statutory provision, a service order or a formal preliminary examination, the Company has the right to place the relevant information at the disposal of the respective service.
6. The Company generally maintains your personal data within the European Economic Area. In the event that data are to be transmitted to third countries outside the European Economic Area for which there is no European Commission decision or to International Organizations, all the appropriate safeguards provided for in the applicable data protection legislation on the transfers to third countries will be taken and the relevant information will be posted on the company’s website at www.thatgorillabrand.com.
What happens if you do not provide us with the personal data we request or if you request us to stop processing your personal data.
In order to register or continue to enjoy the privileges of the That Gorilla Brand Rewards program, we need to keep at least your mobile phone number, your full name and date of birth. However, if you voluntarily provide us with more personal data, we will be able to provide you with improved services and to serve you better. As noted above for your participation in the loyalty program, we collect information about your transactions with us.
If you request us to stop processing your personal data, then we will not be able to provide you with the benefits of the That Gorilla Brand Rewards program.
Automated individual decision making, including profiling
We use software to track your consumer behavior if you are registered as a member of the That Gorilla Brand loyalty program, when you navigate to our online store or for purchases you make in our network’s stores. This technology helps us create your profile based on your preferences on our products. Your client profile helps us send you targeted offers and gifts according to your previous transactions. If you do not agree with the characteristics of your profile, you can always exercise your rights and oppose or restrict automated processing (For more information see below).
The legal basis on which we are based to make automated individual decisions, including profiling, is the legitimate interests of the company, taking into account whether your fundamental rights and freedoms are being infringed by such processing. For more information on the legal bases of processing, see above.
VI. SAFETY of your personal data
7. We apply appropriate technical and organizational measures to protect the personal information we keep from unauthorized disclosure, use, conversion or destruction. Where appropriate, we use encryption and other technologies that can help safeguard the information you provide. We also ask our service providers to comply with stringent privacy and data protection requirements.
8. Time of Retention of your personal data
We will retain your personal data for as long as you continue to interact with us (e.g. you maintain an account with That Gorilla Brand, you are registered to receive commercial communication from us, make a purchase from our online store, contact our customer service points, take part in a contest, etc.). At the same time, we shall keep your personal data for purposes of our legitimate interests in the event of a dispute regarding the sale contract, the maintenance of your Account, our trade policy or any other transaction between us, for the time period during which that processing could arise, in accordance with applicable law. Your financial data may be kept by our Company as part of its tax obligations. We may keep any other data until you ask us to delete them or those we maintain and process as part of your consent until you withdraw it or until you oppose to their processing by us on which we rely on our legitimate interest.
To determine the retention time of your personal data, we take into account the nature of your data, their quantity, purpose, security, etc. You have the right to ask us to delete your data. To exercise your right, please visit the relevant section in this Policy.
We reserve the right in some cases, to anonymize your data for research or statistical purposes, so that they will be no longer associated with an identifiable person, therefore we reserve the right to use this information for an indefinite period of time. In any case, your data will be stored securely.
Purpose of processing Retention time
Member Registration /
Managing your Account Until your Member Account is deleted, or up to since you last entered it. If you attempt to create an Account but have not completed the process, the data you have submitted shall not be kept.
Purchases - Receipt of order, processing of order If you buy products, we will retain your transaction details for as long as we need to complete the sale and comply with any legal obligations (for example, for tax and accounting purposes). We will process your data for the time needed to process orders for purchased products, including any refunds, withdrawals, complaints or claims relating to the purchase of the particular product or service.
V. With respect to your personal data we have and process, you have the following rights:
- to request us to access them to confirm that we process them in accordance with law and/or your request and preferences,
- to request us to correct any incomplete or inaccurate data we keep about you. We also have the right to request you to update your information at regular intervals.
- to request us to delete them, as long as the law does not oblige us to the contrary.
- to request us to limit their use, under certain circumstances,
- to oppose to their use, under certain circumstances,
- to withdraw your consent with respect to their use,
- you have the right to data portability, under certain circumstances,
- to submit a complaint to the country’s supervisory authority.
- not to be bound by a decision made solely on the basis of automated processing, including profiling, under certain circumstances.
Some mobile apps we offer may also send you unsolicited messages about, for example, new products or services. You can disable these messages through the settings of your phone or app.
For your information security, we may ask you for certain information about your identification. Your right is exercised free of charge, however, when your right is used abusively, we may claim a fee, in accordance with the conditions laid down by law. In any case, we shall respond to your requests within one month of the date of receipt of the request, except in exceptional cases where our response time to a request may be longer.
Changes to the Data Protection Policy
In order to ensure that you are always aware of how we process your personal data, we will update this Policy so that it includes new services or products and the processing of your data associated with them as well as changes to the existing processing of your personal data. In addition, we may modify this change as a consequence of changes in the legal and regulatory framework and in order to comply with the relevant requirements. You undertake to visit our website for any changes to this notice that may apply to you. In any case, if you continue to use our Website and its services and our e-shop services after any modifications made in accordance with the above, you will be deemed to accept these modifications. If you do not agree to the terms of this Policy as may be modified, either in whole or in part, you must cease to use our services we provide to you.
Any changes to this Policy will be immediately posted here.