PROFARM PHARMAKAPOTHIKI S.A. (hereinafter referred to as PROFARM) respects your concerns about privacy and the protection of your personal data.
This data protection policy describes how PROFARM uses the information it collects, as well as what information is collected about you when you use any means of communication with PROFARM within the framework of your current or future collaboration with PROFARM.
The PROFARM website uses cookies that allow the identification of the origin and use of the browsing information collected through the cookies.
This data protection policy of PROFARM applies to all websites, applications, and services offered by PROFARM and its subsidiaries or companies acquired by it (referred to collectively as PROFARM in this policy), and is an addition to the “General Terms & Conditions of Use” of PROFARM.
Therefore, this data protection and cookies policy is important for you, who wish to have a positive experience in your cooperation with PROFARM and trust PROFARM, but also for us, as we want to respond accurately and thoroughly to your inquiries and consider your wishes within the scope of the law.
Modification of the policy
PROFARM may modify this data protection and cookies policy from time to time in order to improve it. In such cases, it will notify you by changing the date at the top of this document, and in some cases, it will issue additional notifications (for example, by adding a statement to the homepage of the PROFARM website or by sending you an email). We encourage you to read the data protection and cookies policy when interacting with PROFARM to stay informed about the practices followed by PROFARM for the protection of personal data, as well as the methods you can use to control the use of your personal data and protect your related rights.
DEFINITIONS
The following definitions that may be used in this document are contained in Article 4 of the GDPR:
- Personal Data: Any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one whose identity can be determined, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, psychological, economic, cultural, or social identity of that natural person.
- Special Category Personal Data: Personal data that, due to their nature, are particularly sensitive with respect to fundamental rights and freedoms and require special protection, as the context of their processing may pose significant risks to the fundamental rights and freedoms. These personal data include data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, membership in trade unions, genetic data, biometric data for the purpose of uniquely identifying a natural person, health data, or data concerning the gender or sexual orientation of a living natural person.
- Data Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by European Union or Member State law, the Data Controller or the specific criteria for its appointment may be provided for by European Union or Member State law.
- Data Processor: The natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
- Processing: Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, search for information, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
- Anonymization: The irreversible process of de-identifying personal data in such a way that the individual cannot be identified using reasonable time, cost, and technology, either by the Data Controller or by any other person, to identify the specific individual. Data protection principles do not apply to anonymous data, as they are no longer considered personal data.
- Pseudonymization: The processing of personal data in such a way that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separate and is subject to technical and organizational measures to ensure that it cannot be attributed to an identified or identifiable natural person.
- Cross-border Processing: (a) the processing of personal data that takes place within the operations of establishments in more than one Member State by the Data Controller or Data Processor in the EU, where the Data Controller or Data Processor is established in more than one Member State, or (b) the processing of personal data that takes place within the operations of a single establishment of the Data Controller or Data Processor in the EU but affects or may affect significantly data subjects in more than one Member State.
- Supervisory Authority: An independent public authority established by a Member State pursuant to Article 51 of the GDPR. Each National Supervisory Authority continues to oversee any local data processing affecting data subjects within its jurisdiction or carried out by a Data Controller or Data Processor from the EU or a third country, when the processing purposes target a data subject residing within the jurisdiction of the National Supervisory Authority. The duties and responsibilities of the National Supervisory Authority include conducting investigations, enforcing administrative measures and fines, raising public awareness about risks, rules, security, and rights regarding the processing of personal data, as well as access to all establishments of the Data Controller and Data Processor, including any equipment and means of processing data.
- Main Establishment: (a) when referring to a Data Controller with establishments in more than one Member State, the place of its central administration in the EU, unless decisions regarding the purposes and means of processing personal data are made in another establishment of the Data Controller in the EU, and that establishment has the authority to implement those decisions, in which case the main establishment is considered to be the one where such decisions were made. (b) when referring to a Data Processor with establishments in more than one Member State, the place of its central administration in the EU or, if the Data Processor does not have a central administration in the EU, the establishment of the Data Processor in the EU where the main processing activities take place in the context of the operations of the Data Processor’s establishment, insofar as the Data Processor is subject to specific obligations under this Regulation.
KEY PRINCIPLES OF PERSONAL DATA PROCESSING
Below are the key principles of personal data processing as derived from the GDPR, in relation to the responsibilities of organizations handling personal data. Article 5, paragraph 2 of the GDPR states that “The data controller is responsible for compliance with the principles and must be able to demonstrate compliance with them”.
Lawfulness, Fairness, and Transparency
Personal data must be processed lawfully, fairly, and transparently in relation to the data subject.
Purpose Limitation
Personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Data Minimization
Personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which they are processed. The Data Controller or Data Processor should apply anonymization or pseudonymization to personal data, where possible, to reduce risks to data subjects.
Accuracy
Personal data must be accurate and, where necessary, kept up to date. Appropriate measures must be taken to ensure that inaccurate personal data, considering the purposes for which it is processed, is erased or corrected in a timely manner.
Limitation of retention period
Personal data must be kept for no longer than is necessary for the purposes for which the data is processed.
Integrity and Confidentiality
Taking into account the state of the technology and other available security measures, the cost of implementation, and the likelihood and severity of risks to personal data breaches, the Data Controller uses appropriate technical or organizational measures to process personal data in a manner that ensures the security of personal data, including protection against accidental or unlawful destruction, loss, alteration, unauthorized access or disclosure.
Responsibility
The Data Controller bears the burden of responsibility and proof for compliance with the principles described above.
Key Points of the Data Protection and Cookies Policy
- PROFARM collects information and data about you when you visit its website, interact with it, or make purchases of pharmaceutical or para-pharmaceutical products traded by PROFARM.
- Based on the information and data you typically provide during the order placement stage or when starting your contractual relationship with PROFARM, a personalized account is created for you in the PROFARM system, where all the necessary data is stored in the context of serving your contractual relationship with PROFARM.
- The information and data you provide to PROFARM allow it to get to know you better and use your preferences to offer you personalized offers for products traded by PROFARM and its business partners.
- The use of cookies allows PROFARM to improve the specifications of its website and display advertisements on its website.
- The information and data you provide to PROFARM are kept by PROFARM and may be transferred to PROFARM’s systems (?) as part of the management of the specialized ERP program used by PROFARM, when required to provide you with the product you requested. Some of this information (excluding your purchase history and your profile in PROFARM’s ERP program) may, depending on your sharing options, be transferred to PROFARM’s business partners for better and faster processing of your orders.
- PROFARM does not transfer data outside the European Union.
- If you have any questions or complaints regarding this data protection and cookies policy, you can contact PROFARM:
- In writing to PROFARM PHARMAKAPOTHIKI S.A., 51-53, Agamemnonos Street, Kallithea 17675, Athens, Greece. – For the attention of DPO
- By phone, Monday to Friday from 09:00 to 15:00 at 216 0007 200. For quality control purposes, your call will be recorded.
- Electronically by email: dpo@profarm.com.gr
PROFARM collects and processes your data as the Data Controller. Furthermore, PROFARM determines the strategic directions regarding profile creation and direct marketing for PROFARM. As a result, it is the recipient of information about customers and the expectations of all legal entities in which PROFARM is a shareholder or strategic investor, as well as browsing information from users of PROFARM’s website.
WHAT DATA DOES PROFARM COLLECT?
PROFARM collects various types of personal data:
It collects information that you provide directly when using PROFARM’s website or contact details with the aim to:
- Establish a commercial relationship with PROFARM either online or by phone
- Subscribe to receive electronic newsletters or promotional emails
- Participate in a lottery, competition, offer, or survey
- Contact us by using social media
- Contact us in the context of customer service
- Contact us in any other way
Providing your data to PROFARM is voluntary. However, if you do not provide PROFARM with all the necessary or requested data, it may not be able to provide you with some of the products it trades.
The categories of information that PROFARM collects include:
- Identity and contact details (such as first and last name, professional and mailing address, contact information) required to identify you within the framework of your contractual relationship with PROFARM.
- Transaction data necessary to process your order (selected details, delivery and billing address, Tax Identification Number, telephone number, e-mail address, payment method, as well as the name of the payment card holder).
- Historical data about your orders (such as your preferences for the quantity and quality of products).
- Historical data of your communication with us (the history of your commercial relationship with PROFARM when you contact customer service or when you place an order).
WHAT INFORMATION DOES PROFARM AUTOMATICALLY PROCESS?
PROFARM automatically processes certain information about you when you access or use the PROFARM website. Specifically, processing may occur on:
- Login Data: Information about the device you use to browse and use the PROFARM website (such as the operating system, browser type, whether you are using a proxy server, the recommended location of your IP address to identify your computer, visit duration, pages you visited, and the link that led you to our website).
- Browsing Information (whether logged in or not): Cookies and other technologies may be used to collect information about you when interacting with the PROFARM website or emails sent by PROFARM. This information allows PROFARM to determine your preferences for certain products. These details are collected whether you are logged in or not and may be cross-checked across devices that you use.
- Location Data: When you connect to the PROFARM website via a mobile device and have activated the relevant option on your device, information about your location is collected.
- Call Recording for Customer Service: Additionally, if you contact a PROFARM representative, your conversations may be recorded to improve the quality of customer service regarding your product order. You will be notified of this recording via an automated voice message before speaking to the PROFARM representative. If you do not wish for your call to be recorded, other methods of communication with PROFARM are available.
WHICH INFORMATION IS PROCESSED THROUGH PROFARM’S PARTNERS?
PROFARM may also receive information about you from other partners and link it with data received directly from you, such as:
- Information from local postal service databases in order to verify and update shipping addresses.
- Data shared by partners: This refers to information shared by PROFARM’s partners with whom you have interacted and permitted to disclose your personal data to third parties, including PROFARM, for direct marketing or advertising purposes.
- Data shared via social networks: This refers to information shared with PROFARM through the social media channels of PROFARM that you have used.
- Data minimization: PROFARM collects the minimum amount of personal data necessary. If personal data is collected from third parties, PROFARM ensures that your personal data is collected lawfully.
- Use, retention, and disposal: The purposes, methods, storage limitation and retention period, of personal data are in accordance with the information contained in PROFARM’s statement. PROFARM ensures the accuracy, integrity, confidentiality, and relevance of personal data in accordance with the purpose of processing. PROFARM implements sufficient security mechanisms to protect personal data from theft, misuse, and to prevent data breaches. PROFARM is responsible for ensuring compliance with the requirements outlined in this section.
- Disclosure to third parties: Whenever PROFARM uses a third-party Data Processor to process personal data on its behalf, PROFARM and the head of the IT department ensure that the third-party Data Processor provides adequate security measures to address related risks and safeguard personal data. For this purpose, a specific questionnaire, such as the Data Processing Compliance Questionnaire, is used. PROFARM requires the third-party data processor to provide the same level of personal data protection as PROFARM does. The Data Processor processes personal data only to fulfill its contractual obligations to PROFARM, based on PROFARM’s instructions and directions, and not for other purposes. When PROFARM processes personal data jointly with a processor, PROFARM specifies the respective responsibilities of the processor in a related contract or any other legally binding document between PROFARM and the Data Processor.
- PROFARM does not make cross-border transfers of personal data either within or outside the EU. The law stipulates that if such a cross-border transfer of personal data is made, adequate safeguards must be used before transferring personal data from the European Economic Area (EEA), including the signing of a data transfer agreement, as required by the EU. If necessary, permission must be obtained from the competent supervisory authority (Data Protection Authority). The legal or natural person to whom the personal data is transferred must comply with the principles of personal data processing as outlined in the cross-border data transfer procedure.
GUIDELINES FOR PROPER DATA PROCESSING
- Notifications to data subjects: When collecting personal data for any processing activities, including but not limited to the sale of products, services, or marketing activities, PROFARM is bears the responsibility for providing appropriate, complete, and clear information to the data subjects about the processing methods, processing techniques, the rights of data subjects, the retention period of data, any potential international or other data transfers, the transfer of data to third parties, and the security measures implemented by PROFARM to protect personal data. If PROFARM has multiple data processing activities, it is required to create separate notifications based on the processing activity and the categories of personal data being collected (e.g., one notification for mail shipments and another for transport purposes). When personal data is transferred to third parties, PROFARM must inform the data subject—before the transfer to the third party—and ensure that prior consent is obtained from the data subject for the transfer of their data. Furthermore, PROFARM ensures that the recipients of the data have committed to using appropriate technical or organizational measures to process personal data in a manner that ensures the security of the data, including protection from accidental or unlawful destruction, loss, transfer, unauthorized access, or disclosure.
- Obtaining consent: Whenever personal data processing is based on the consent of the data subject or other lawful grounds, PROFARM is required to always maintain the written consent of the data subject.
- Rectification, modification, or destruction of records containing personal data: When requests for the rectification, modification, or destruction of records containing personal data are made, PROFARM ensures that such requests are processed within a reasonable timeframe, provided the appropriate conditions are met. PROFARM keeps a record of these requests and maintains a related log.
- Limitation of the purpose of processing: Personal data should only be processed for the purpose for which it was collected. If PROFARM wishes to process the collected personal data for another purpose, it must seek the consent of the data subject before proceeding with the new purpose and must clearly and concisely inform the data subject about the new purpose. Any such request will include the original purpose for which the personal data was collected, as well as the new or additional purpose(s) for which PROFARM seeks consent. PROFARM informs the data subject of the reason for the change in the processing purpose(s). PROFARM ensures that the methods of data collection and processing are compliant and consistent with best practices.
WHAT IS THE LEGAL BASIS AND USE OF THE INFORMATION AND DATA PROCESSED BY PROFARM?
PROFARM processes personal data only when there is a legal basis for doing so. The processing of personal data described below occurs only because it is:
1. Necessary so that PROFARM provides you with the products in execution of the orders you have placed.
PROFARM uses your data in the context of fulfilling its contractual obligations related to the sale of pharmaceutical or parapharmaceutical products. Specifically, PROFARM uses your data for:
- Providing the products you requested through any provided transaction method, processing transactions and charges, ensuring delivery, including payments management.
- Managing your personalized account in PROFARM’s ERP system.
- Managing your reviews related to the products sold by PROFARM.
2. Necessary for our legitimate interests
In this case, PROFARM considers the potential impact that this collection and processing of data may have on you.
PROFARM manages its relationship with you by maintaining a database in its ERP system that includes existing and potential customers. PROFARM may also combine data about you that has been collected online and offline with any available data from your account in our ERP system.
PROFARM also uses information collected for studies and statistics, after anonymizing or processing the data to prevent identification of natural persons.
In addition to these cases, your data may also be collected based on your prior written consent, for example, when you complete a satisfaction survey, submit a contact form, place an order with PROFARM, subscribe to an electronic newsletter, or post a comment or when this consent is also required by law (for example in cases such as sending you partner offers via email or text message, or using cookies for targeted advertising).
PROFARM may also record telephone calls to manage orders, and, as a proof of the content of the order. It uses your data to communicate with you, manage your subscriptions to newsletters, respond to your inquiries, and handle your orders (customer service).
PROFARM processes your personal data to pursue its legitimate interest in managing its dynamic relationship with you, in the context of the contractual sale of pharmaceutical and parapharmaceutical products, to enhance its corporate image, and to promote the products it trades, including on a rotational basis, purposes of using your data in the context of ongoing consumer studies and market research on pharmaceutical and parapharmaceutical products. Additionally, PROFARM uses your data to tailor product offers that it trades based on the capabilities of the product manufacturers.
3. Necessary for compliance with PROFARM’s legal obligations.
Some of your data may also be disclosed in the context of PROFARM’s compliance with legal obligations before any relevant Authority that may request the data and is required to process it within a specifically outlined legal procedure.
FOR HOW LONG ARE YOUR DATA RETAINED?
Your data are retained for the entire duration of the transactional relationship between you and PROFARM under a sales, employment, or project contract.
In general, your personal data are retained for the duration of your relationship with PROFARM and for six years after the end of this relationship for the possibility of retroactive tax audits by PROFARM, at which point they are archived. PROFARM keeps your personal data after the termination of the contractual relationship with you to fulfill its legal obligations towards Authorities and as proof of the transactional relationship with you. PROFARM may also anonymize your data for research and statistical purposes.
In certain cases, due to legal obligations, PROFARM may retain some of your personal data even if you delete your account or if there is an issue with your account (e.g., a negative balance or an outstanding financial claim or dispute, whether judicial or not). In such cases, the data necessary to resolve the issue or dispute will be retained during the dispute within the limits of the rules regarding prescription. Other data may be retained for research and statistical purposes once they have been processed to prevent association and identification of data subjects.
WITH WHOM DOES PROFARM SHARE YOUR DATA?
PROFARM shares your data whenever it is necessary to manage either its website or the processing of your order for the purchase of a product. In the context of fulfilling your order, some of your data are disclosed to competent personnel of PROFARM or its partners who provide relevant support services necessary for executing the order for the purpose of purchasing a product. Additionally, financial or personal data related to your transactional relationship with PROFARM may be disclosed to financial institutions for the completion of financial transactions related to the sale of PROFARM products. In the context of legitimate interest, corporate and/or regulatory compliance, and protection obligations, PROFARM may acquire, with your prior information and consent, information on your financial behavior and data related to aggregation of grants, mortgages, and pre-notices, as well as data contributing to prevent fraud in banking transactions, which is provided through TEIRESIAS S.A.
With your consent, certain data (contact details, profile, etc.) may be disclosed to PROFARM partners for sending you personalized product offers.
Under the applicable law, PROFARM may disclose your data to third parties, within the scope of executing an order or managing overdue debts, to those responsible for judicially pursuing the satisfaction of your financial debts or for the collection of information about you related to the pursuit of satisfying your financial debts, combating fraud, or financial crimes against PROFARM.
Additionally, data that you have provided to PROFARM through social media may be disclosed to third parties in the context of the operation of PROFARM’s social media account. When you use PROFARM’s social media account, the data you enter regarding your identity or other information may be disclosed to third parties at the discretion of the social media account administrator. The use of a social media account is governed by the terms and conditions of the respective social network, which PROFARM encourages you to read before using the social media platform.
HOW IS THE SECURITY OF YOUR PERSONAL DATA GUARANTEED?
Your personal data is protected by the technical and organizational measures used by PROFARM, in compliance with Greek and European legal and regulatory requirements that ensure their integrity and confidentiality. Specifically, PROFARM employs technological protection measures to safeguard the integrity and confidentiality of your data, particularly the data entered into its ERP system. Additionally, PROFARM requires its software providers, whom it collaborates with, to commit in writing that the software products supplied to PROFARM meet the technical specifications required by the GDPR (Regulation 2016/679/EU) to ensure the protection of data subjects’ rights regarding their personal data.
WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA UNDER THE GDPR?
As a data subject, you have the following rights under the specific provisions of the new GDPR:
- Right to be informed and access your data.
- Right to rectification of your data.
- Right to restrict the processing of your data.
- Right to object to the processing of your data.
- Right to erasure of your data – Right to be forgotten.
- Right to portability of your data.
HOW CAN YOU ACCESS YOUR DATA?
You have the right to access the personal data collected and processed by PROFARM. To exercise your right of access, you must contact PROFARM using the contact details provided above in this data protection and cookies policy. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request regarding access to your personal data as soon as possible.
HOW CAN YOU RECTIFY YOUR DATA?
You have the right to request the rectification of your personal data collected and processed by PROFARM. To exercise your right of rectification, you must contact PROFARM using the contact details provided above in this data protection and cookies policy and request the rectification of inaccurate data or the completion of incomplete data concerning you. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request for rectification of your personal data as soon as possible and within the time limits set by law.
HOW CAN YOU RESTRICT THE PROCESSING OF YOUR DATA?
You have the right to request the restriction of the processing of your personal data collected and processed by PROFARM under specific conditions that you will explicitly mention. To exercise your right to restrict the processing of your data, you must contact PROFARM using the contact details provided above in this data protection and cookies policy and request the restriction of your data processing for specific, clearly stated reasons. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request regarding the right to restrict the processing of your personal data as soon as possible and within the time limits set by law.
HOW CAN YOU OBJECT TO THE PROCESSING OF YOUR DATA?
You have the right to object to the processing of your personal data collected and processed by PROFARM under specific conditions that you will explicitly mention, particularly when it concerns profiling or for the purpose of direct marketing of products. To exercise your right to object to the processing of your data, you must contact PROFARM using the contact details provided above in this data protection and cookies policy and state your objection to the processing of your data for specific, clearly stated reasons. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request regarding the right to object to the processing of your personal data as soon as possible and within the time limits set by law.
HOW CAN YOU REQUEST THE DELETION OF YOUR DATA?
You have the right to request that your personal data, which has been collected and processed by PROFARM, be deleted, under the condition that the data is not held for any specific lawful and declared purpose. To exercise your right to erasure (right to be forgotten), you must contact PROFARM using the contact details provided above in this data protection and cookies policy and request that you no longer wish for your data to be processed or retained, and that you wish for its deletion. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request regarding the right to erasure of your personal data as soon as possible and within the time limits set by law.
HOW CAN YOU REQUEST THE PORTABILITY OF YOUR DATA?
You have the right to request the portability of your data in a machine-readable format from PROFARM to another data controller under specific conditions. To exercise your right to data portability, you must contact PROFARM using the contact details provided above in this data protection and cookies policy and request the portability of your data collected and processed by PROFARM to the new data controller you specify. PROFARM shall respond to your request after verifying your identity. You may be asked for additional information to address your request. PROFARM shall respond to your request regarding the right to data portability as soon as possible and within the time limits set by law.
If you find that your rights as described above are not respected or that your data is not being protected, you have the right to file a complaint regarding the processing of your data with the Hellenic Data Protection Authority (DPA) at: Data Protection Authority (DPA), 1-3, Kifisias Avenue, 115 23 Athens, Greece, Phone: +30 210 6475600, Email: contact@dpa.gr

