In light of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Hellenic American Union (Massalias Str., no. 22, Postal Code 10680, Athens) (the “HAU”) would like to inform you of the following:
- What data is processed by the HAU belonging to which natural persons: The HAU, in its capacity as data controller, processes personal data of minors who participate or are willing to participate in its events and which are being represented by holders of parental responsibility or guardianship (jointly and, as the case may be, the “data subjects”). Data processed by the HAU may include: (a) personal information (e.g. full name and e-mail address); (b) financial data relating to the payment of fees due to the HAU, such as bank card information, bank account numbers and billing and payment data, if fees are charged for participating in the event; (c) voice data (voice) of the participants in the event, when despite the alternative means to participate (e.g. by submitting questions through chat) the holders of the parental responsibility or guardianship have provided their consent for the minor to speak during the event in full knowledge of the fact that material from the event may be uploaded to the internet. The disclosure of the data in clauses (a) and (b), above, is a legal or contractual obligation of the data subject or a requirement to fulfil a contract. Where the data subject does not provide the above data or part thereof, he or she will not be able to participate in the HAU event.
- Source of data: The source of the data, as the case may be, is the data subject himself/ herself disclosing his/ her data to the HAU or the holders of the parental responsibility or the guardianship of the data subject.
- Purpose and legal basis of processing data: Depending on the case, it may process personal data: (a) to register, provide services to and in general manage the participants in the event. The legal basis for such data processing is to execute the relevant contract and comply with a legal obligation the HAU has, while for data that relates to voice (voice) of the participants in the event (as specified in clause 1 (c) above), the legal basis is the consent the holders of the parental responsibility or guardianship have given for the minor to speak during the event in full knowledge of the fact that material from the event may be uploaded to the internet. (b) To safeguard the interests of the HAU. The legal basis for such data processing is that processing is necessary to safeguard the HAU’s legitimate interests (e.g. for the establishment, exercise or support of legal claims). (c) To send marketing material via electronic mail. Note that the HAU is entitled to use the data subjects’ email address, as it has been lawfully obtained as part of the services or transaction it has provided or to promote similar services or pursue similar purposes, even when the holders of parental responsibility or guardianship have not given their prior consent, provided that they are given, when these contact details are collected, as well with every subsequent message, a clear, transparent, cost-free and easy-to-use option to object to the collection and use of their electronic data. The legal basis for such data processing is that processing is necessary to serve the prevailing legitimate interests pursued of the HAU (i.e. the legitimate interests relating to the promotion of its services). For all of the above purposes, the HAU does not proceed with automated decision-making, including profiling of the data subjects.
- Recipients of data: Depending on the case and purpose of processing, personal data may be transmitted to authorized employees of the HAU, as well as to companies associated with the HAU with which the HAU has a relevant contract and which processes the data on its behalf (e.g. IT companies, IT service providers, etc.), within their competencies and subject to the obligation of confidentiality, secrecy and compliance with the data protection legislation. In addition, the HAU may transmit personal data to third parties where so required by law, or for the purposes of, or in connection with legal proceedings in which it participates, or otherwise for the purposes of supporting, exercising or defending its rights, or to third parties that are law enforcement authorities and have submitted a lawful transmission request, or where it considers that transmission is necessary in connection with an investigation into the suspicion or existence of illegal activity. Personal data will not be transmitted outside the European Economic Area.
- Data retention time: The above data will be retained for a period time as required or allowed by the legislation/regulatory framework in force each time, taking into account the applicable prescription period, which may extend to up to 20 years. Specifically: (a) where processing is carried out under a relevant contract, the personal data shall be stored for as long as necessary for the performance of the contract and for the establishment, exercise and/or support of any legal claims of the HAU arising from that contract; and (b) where the processing is imposed as an obligation by provisions stemming from the applicable legal framework, personal data shall be stored for as long as the relevant provisions so require.
- Data subjects’ rights: The data subject has the following rights under GDPR: (a) to receive a copy of the personal data held by the HAU, together with other information on how data is processed; (b) to request that personal data concerning him or her be rectified and, under conditions, to request the deletion or restriction of processing, or to object to the processing of personal data; (c) to receive a copy or to request the transmission of a copy of his or her personal data to a third party in a structured, commonly used and machine-readable format (right to data portability). Where the processing of the data subject’s data is based on the consent of the holders of parental responsibility or guardianship of the minor, these persons have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal. If the data subject wishes to receive further information about the processing of his or her personal data or to exercise any of his or her above rights, he or she must email the HAU Data Protection Officer exclusively at: firstname.lastname@example.org, or send a letter to the mailing address mentioned above. Finally, the data subject has the right to file a complaint with the competent supervisory authority about how the HAU handles his or her data (www.dpa.gr).