This Privacy Policy describes the policies of the company “Coffee Republic S.A.” (Tax ID: 099555196, Tax Office: KEFODE, Business Registry No.: 3596501000), headquartered in Greece, at 25 Oikonomidou Street, 12132, Peristeri (hereinafter referred to as “the Company”), regarding the collection, use, and disclosure of your information that is collected when you use the website (https://cafeistas.com) (hereinafter referred to as “the Service”). By accessing or using the Service, you consent to the collection, use, and disclosure of your information in accordance with this Privacy Policy.
Our top priority is the protection of your personal data, which we process in compliance with the applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR) and any other relevant applicable legislation. Please read this Privacy and Personal Data Protection Policy carefully to be informed, as the use of our website and registration to our services implies your unconditional acceptance, consent, approval, and agreement to the Terms of Use and this Privacy and Personal Data Protection Policy, as detailed herein.
If you have any questions regarding this Privacy Policy, please contact us at: mail@coffeerepublic.gr.
We may modify this Privacy Policy at any time without prior notice, and we will post the revised policy on the Service. We recommend that you review this page periodically.
Information We Collect
We collect and process the following personal information about you: full name, address, email, telephone number, and payment details.
How We Use Your Personal Data (Legal Bases for Processing Your Personal Data)
a. To process your orders, payments, and requests, to perform purchase contracts for products or services, to fulfill purchase orders and deliver products you have ordered through our website, and to provide any other services you may request, including your participation in contests and notification about product availability. For these purposes (collectively referred to as “Provision of Services”), your consent is not required for the processing of your personal data, as such processing is necessary for the provision of the services you have requested and, consequently, for the performance of the contract to which you are a party or to take steps at your request prior to entering into a contract (GDPR Article 6(1)(b)).
b. To respond to your questions, comments, requests, or complaints, and to take any other actions necessary to manage your inquiry.
c. To contact you, provide you with promotional information, and send you email newsletters. You receive newsletters only by giving us your consent when you enter your email address in the relevant subscription form. You may withdraw your consent at any time by selecting the unsubscribe option included in every email you receive. Processing for these purposes is based on your consent (GDPR Article 6(1)(a)).
d. To comply with applicable laws, such as consumer protection legislation, which requires the Company to collect and/or further process certain categories of personal data. When you provide any personal data to the Company, it must process it in accordance with applicable law, which may include retaining and disclosing your personal data to official authorities in compliance with tax, customs, or other legal obligations. Consent is not required for this type of processing (hereinafter “Compliance”), as such processing is necessary to comply with a legal obligation of the Company (GDPR Article 6(1)(c)).
e. To protect and defend the security of the Company’s systems and property, including preventing and detecting any misuse of the Website or fraudulent activities carried out through it, as well as to defend the Company’s legal interests before competent Courts and Authorities. Processing for this purpose (hereinafter “Security/Legitimate Interests”) is necessary for the pursuit of the Company’s legitimate interests (GDPR Article 6(1)(f)).
Recipients of Your Data
For the fulfillment of the purposes described herein, it is necessary to grant access to your personal data to our staff, associates, and third-party service providers responsible for transportation and delivery, as well as partner companies that operate and provide technical support for our website. Any third party who has access to your personal data is contractually bound to protect the confidentiality and security of your personal data. We may also disclose your personal information in the following cases:
To comply with applicable laws, regulations, court orders, or other legal procedures;
To enforce your agreements with us, including this Privacy Policy; or
To respond to claims that the use of the Service violates the rights of third parties.
Retention of Your Information
The Company will process your personal data for as long as necessary to fulfill the above purposes and its legal obligations — for example, in relation to the purchase of products or services you have obtained from us, any returns, complaints, requests, or comments you may have submitted. If you withdraw your consent regarding the collection and processing of your personal data, we will delete your personal data from our records, unless their retention is required by applicable law (such as tax or commercial legislation) or necessary for the establishment, exercise, or defense of our legal claims before judicial authorities.
Your Rights
You have the right to exercise the following rights:
Right of access and information – to obtain confirmation from us as to whether or not we process your personal data and to receive information regarding the type of data we process, the purpose of processing, the storage period, and the recipients of such data.
Right to rectification – to correct any incomplete or inaccurate personal data, should you identify any errors.
Right to erasure (“right to be forgotten”) – to request the deletion of your personal data when it is no longer necessary for the purposes mentioned above or for the defense of our interests before the courts.
Right to restriction of processing – to request that the processing of your data be limited in certain circumstances.
Right to data portability – to receive your personal data in a structured, commonly used, and machine-readable format and to transmit those data to another controller.
Right to object – to object to the processing of your personal data when such processing is based on legitimate interests or relates to direct marketing purposes.
To exercise any of these rights, you may contact us at mail@coffeerepublic.gr, and we will respond in accordance with the applicable legislation.
Please note that if you do not allow us to collect or process the necessary personal information, or if you withdraw your consent, you may not be able to use certain services that require such information.
Supervisory Authority
You have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA), located at 1–3 Kifisias Avenue, 11523 Athens, Greece, or via their website: www.dpa.gr.
Payment Processing (EPAY)
During the payment process via EPAY, your payment details are submitted directly to EPAY, which acts as an independent data controller in accordance with its own privacy policy.
Security
The security of your information is important to us, and we employ reasonable security measures to prevent the loss, misuse, or unauthorized alteration of your data under our control. However, due to the inherent risks of the internet, we cannot guarantee absolute security and therefore cannot ensure or warrant the security of any information you transmit to us — you do so at your own risk.
Cookies Information
We use cookies to enhance your browsing experience on our website. To learn more about the use of cookies and your options regarding these tracking technologies, please refer to our Cookies Policy.
Third-Party Links and Use of Your Information
Our Service may contain links to other websites that are not operated or controlled by us. This Privacy Policy does not cover the privacy policies or practices of third parties, including websites or services that may be linked to our Service.
We strongly recommend that you read the privacy policy of every website you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party websites or services.