LEGAL
Privacy Policy
How we collect, use and protect your personal data.
This Privacy Policy explains how BRON S.A. collects, uses and protects the personal data of visitors to bron.gr, in accordance with the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019.
1. Data Controller
The Data Controller of your personal data is:
- BRON S.A. (ΜΠΡΟΝ Α.Ε.)
- 16 Plateia Argentinis, Athens 114 72, Greece
- Tax number (ΑΦΜ) 801459195 · General Commercial Registry (ΓΕΜΗ) 157314601000
- Telephone: +30 210 6424646
- Email: info@bron.gr
The company is not required to appoint a Data Protection Officer. For any matter concerning your data, please use the contact details above.
2. What data we collect
2.1 Data you give us
When you complete the contact form we ask for your name, email address, telephone number, the area of work that interests you and your message. Only the fields marked as required are necessary for us to reply. The same applies if you contact us directly by email or by telephone.
2.2 Data collected automatically
The hosting server records, as any server does, the IP address, the date and time of the request, the page requested and the browser type. These logs serve only the security and technical operation of the site.
We do not build visitor profiles, we do not track your browsing on other websites, and we take no automated decisions producing legal effects concerning you.
3. Purposes and legal bases
- Responding to your enquiry and preparing for a possible engagement. Legal basis: steps taken at your request prior to entering into a contract (Article 6(1)(b) GDPR).
- Security and proper operation of the website. Legal basis: our legitimate interest in protecting our systems from misuse (Article 6(1)(f) GDPR).
- Loading the map and any other optional third-party service. Legal basis: your consent (Article 6(1)(a) GDPR), which you may withdraw at any time.
- Compliance with tax and other legal obligations, where the enquiry develops into an engagement. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).
4. Recipients of the data
We do not sell or trade personal data. Access is limited to:
- the company’s staff and associates, to the extent needed to answer your enquiry;
- the website hosting provider and the email provider, acting as Data Processors;
- the provider of technical support and maintenance for the website, acting as a Data Processor;
- where the enquiry develops into an engagement, the external legal, accounting and technical advisers involved in that particular matter;
- public authorities, where required by law.
A contract under Article 28 GDPR is in place with each Data Processor.
5. Transfers outside the European Economic Area
Your data is stored on servers within the European Economic Area. Should a transfer to a third country become necessary, it will take place only where an adequacy decision of the European Commission applies or Standard Contractual Clauses are in force, together with appropriate supplementary safeguards.
6. Retention periods
- Enquiries that do not lead to an engagement: retained for twelve (12) months from the last contact, then deleted.
- Client data: for the duration of the engagement and, after it ends, for as long as the company’s tax and accounting obligations require, or for the establishment and exercise of legal claims.
- Server logs: for a short period, in line with the hosting provider’s policy.
7. Security
Communication with the website is encrypted (SSL/TLS). We apply access control, regular software updates and backups. No method of transmission or storage is entirely secure, but we maintain appropriate technical and organisational measures under Article 32 GDPR.
8. Your rights
You have the right of access to your data, and the rights to rectification, erasure, restriction of processing, data portability, and objection to processing based on our legitimate interest. Where processing rests on your consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
To exercise your rights, write to info@bron.gr. We respond within one (1) month; that period may be extended by a further two months where the request is complex, in which case we will inform you.
If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifissias Avenue, 115 23 Athens, www.dpa.gr).
9. Cookies
The website uses a limited number of cookies. Full details are set out in the Cookies Policy.
10. Minors
The website is addressed to adults and we do not knowingly collect data relating to minors. Should we find that we have received such data, we delete it.
11. Changes to this policy
We may update this policy when our services or the legal framework change. The version in force is published on this page, with the date it was last updated.