1. Introductory Note
PHARMACY CHRISTIANA KARI (“we”, “our”, “us”) respects your privacy. We understand that how your personal data is used and shared online matters to you, and we take the privacy of those who visit our website (“the website”) very seriously.
PHARMACY CHRISTIANA KARI of ANTREA AVRAAMIDI 50, STROVOLOS, is the Controller of the processing of personal data, and it is processing personal data in accordance with the provisions of General Data Protection Regulation (EU/2016/679) and the national data protection law 125(i)/2018.
2. What data do we collect and how we use your data
When you use our website and the services, we provide via the website we will collect your personal data. We will collect your name, surname, contact details including email address, phone numbers etc., billing and delivery information and order information.
We only process your personal data for the following purposes:
• to process, administer and fulfil your orders,
• to register your account and maintain it,
• to deliver your order,
• to communicate you with about your order or about your account or about any queries you raised or to respond to any complaints you file,
• to send you information about any specific product upon your request,
• to send you marketing communication,
• to comply with any applicable laws and or regulations
Also, our site automatically collects usage data when you visit the website. The usage data may include your IP address, geographical location, browser type and version, operating system, length of visit, page views and website navigation paths, as well as information about the timing, frequency and pattern of your service use.
3. Legal basis of processing
We collect and process your personal data for the purposes outlined above, on the basis of the following legal grounds:
• For the performance of the contract between us in relations to the sale of goods,
• With your consent, for example when you consented to receive marketing communication from us,
• To comply with any applicable to us legal obligations, for example to comply with Tax and VAT legal requirements,
• On the basis of our legitimate interests, when such interests override your interests, rights and freedoms, for example our interest to ensure the security and integrity of our IT systems or our interest to market and/or advertise our products to our customers.
We don’t have access to any financial information you provide during the checkout process because such information is securely transferred directly to our Payment Service Providers.
4. Sharing your personal data
We will not sell your personal data with anyone at any time. In certain cases we may share the necessary data with our subcontractors such as Couriers in order to deliver to you the products you ordered and purchased form us or to Payment Service Providers to complete the payment process. In both cases, our subcontractors are processing your personal data on our instructions. We take all possible and appropriate measures to ensure that such third parties are taking all necessary technical and organisational measures to ensure security and protection of your personal data. Where it is necessary for us to share your personal data with any other third party we will inform you prior to such sharing. Also, we may be obliged to share your personal data with third parties to either comply with a legal obligation or to enforce or defend legal claims including debt collection. If we will share your personal data, we will take appropriate measures to ensure the security and the protection of such sharing.
5. Retention period of personal data
We only retain your personal data for as long as it is necessary to achieve the above purposes. All details that are linked with your account, such us personal data that you provided when you register with us and order, communication history will be processed until the date that you closed your account. Any other personal data will be retained in our systems only for the period necessary to achieve the purposes for which it was collected.
Knowing our responsibility when processing your personal data, we implement appropriate policies, rules, and technical security measures to ensure a high level of security and protection of your personal data from unauthorized access, inappropriate use or disclosure, unauthorized modification, accidental loss, destruction or damage.
8. Your rights
In addition to the above, we inform you that you have the following rights in relation to your personal data that you can exercise at any time. You have the right to:
a) Request access to your personal data.
b) Ask for rectification of the personal data we hold for you.
c) Ask for the deletion of your personal data.
d) Object to the processing of your personal data where we rely on a legitimate interest and there is something about your particular situation that makes you want to object to the processing on this basis.
e) Object to the automated decision-making including profiling.
f) Ask to restrict the processing of your personal information.
g) Require the transfer of your personal data in a structured and commonly used and machine-readable format to you or to another person (commonly known as the "data portability" right).
h) Withdrawal of consent.
i) Submit a complaint to the Supervisory Authority. If you are concerned about any aspect of our privacy practices, including how we handle your personal information, you can report it to the appropriate Supervisory Authority.
Please bear in mind that some of the above rights may not be applicable in all cases.
If you wish to exercise any of the above rights, please contact us by e-mail at firstname.lastname@example.org
9. Contact Information
If you do not receive a satisfactory response from us or in any case you can immediately file your complaint with the Data Protection Commissioner using the following link http://www.dataprotection.gov.cy.