1. Information on the Processing of Personal Data
Mesogeios Digital S.A. is particularly committed to protecting the personal data of its customers, suppliers, business partners and staff. For this reason, the Company takes the appropriate technical and organisational measures to protect the personal data it processes and to ensure that such processing is carried out, both by the Company itself and by third parties who may process personal data on its behalf, always in accordance with the obligations set out in the applicable legal framework.
2. What is the General Data Protection Regulation (GDPR)?
The General Data Protection Regulation (GDPR) (EU) 2016/679 constitutes the European Union’s (EU) new regulatory framework in this area. The purpose of the Regulation is to lay down the conditions for the protection of natural persons with regard to the processing of personal data, to protect the rights and freedoms of natural persons, and to ensure the free movement of such data.
According to the definition set out in Article 4 of the GDPR, personal data is information that can be used by third parties to identify, contact and interact with a natural person (‘data subject’). Examples of such information include your full name, your postal address, your email address, your telephone number, your computer’s IP address, and other information when combined with your personal details.
3. Definitions
a. Personal data: This refers to information relating to a living natural person that identifies them directly or indirectly, such as – by way of example – their full name, tax identification number, contact details (addresses, telephone numbers), identity card number, location data, online identifiers, physical characteristics, age, etc. Information relating to legal entities does not constitute ‘personal data’ and is not protected by the Regulation. A subset of personal data is constituted by Special Categories of Personal Data, known as Sensitive Data, which relate to an individual’s intimate personal circumstances, such as, in particular, religious beliefs, political opinions, membership of trade unions, health, racial or ethnic origin, sex life or sexual orientation, administrative or criminal proceedings and convictions, etc. The natural persons to whom the personal data relate are referred to as ‘data subjects’.
b. Processing: Any operation or set of operations, carried out by any means, on personal data, such as storage, recording, organisation, alteration, retrieval, searching, transmission or dissemination to third parties by any means, alteration, erasure, etc.
c. Data Controller: The natural or legal person who determines the purposes and means of the processing of personal data, either alone or jointly with other persons (‘joint data controllers’).
d. Processor: The natural or legal person who processes personal data on behalf of the Data Controller.
e. Consent of the Data Subject: Any clear, free, specific, explicit and fully informed statement or other affirmative action by the data subject, by which they directly consent to the processing of their personal data, the existence of which the data controller must always be able to demonstrate.
4. Mesogeios Digital S.A. as Data Controller
Mesogeios Digital S.A., a public limited company trading under the name ‘MESOGEIOS DIGITAL DIGITAL APPLICATIONS – SOFTWARE DEVELOPMENT – TECHNOLOGY PRODUCTS S.A.’, which is based at 34A Averof Street, Nea Ionia, Attica, with Tax Identification Number 997264723, as the Data Controller of personal data, for the purposes of carrying out its business activities, collects and processes the personal data of its customers, suppliers, partners and staff, in accordance with applicable national legislation (Law 4624/2019) and the European Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation (GDPR)), as applicable. Consequently, Mesogeios Digital S.A. acts as the Data Controller in accordance with Article 4(7) of the GDPR.
5. Mesogeios Digital S.A. as a Data Processor
Mesogeios Digital S.A., within the scope of its activities relating to digital applications, the development of specialised software, and the design, development and manufacture of technology products in the field of environmental applications (liquids, solids, recycling) as well as in water resource management, acts as a Data Processor in accordance with Article 4(8) of the GDPR, whereby:
- it processes personal data solely on the basis of written instructions from the data controller,
- ensures that persons authorised to process personal data have undertaken to maintain confidentiality,
- takes the necessary technical and organisational security measures,
- does not engage a third party to carry out the processing (‘sub-processor’) unless authorised by the data controller, which authorisation may be general or specific (in the case of general authorisation, the ‘data controller’ is informed in the event that a replacement or addition of a subcontractor is required, so that the data controller has the opportunity to object to these changes),
- takes into account the nature of the processing and assists the data controller with appropriate technical and organisational measures to fulfil their obligation to respond to requests from the data subject,
- assists the controller in ensuring compliance with the obligations relating to the keeping of records of processing activities, security of processing, data breach notification and impact assessment (taking into account the nature of the processing and the information available to the processor),
- at the data controller’s discretion, erases or returns all personal data to the data controller upon completion of the provision of processing services and erases any existing copies,
- makes available to the data controller any information necessary to demonstrate compliance with the obligations laid down in this Article and allows for and facilitates audits.
6. The personal data processed by Mesogeios Digital S.A.
Mesogeios Digital S.A. processes personal data only for lawful purposes, provided that one of the conditions set out in Article 6(1) of the GDPR is met. The website https://mesogeos-digital.com has been designed so that users can visit it without revealing their identity or providing their personal data. In the course of the Company’s activities, certain personal data may be processed in order to provide specific services to meet the needs of its business operations and its customers. Specifically:
6.a. Customers’ Personal Data
Mesogeios Digital S.A. collects and processes its customers’ personal data, such as full names, fathers’ names, contact telephone numbers, email addresses, postal addresses, and contact details belonging to project teams, for the purpose of carrying out its activities in the sector in which it operates, in both the public and private sectors.
The legal basis for the above processing is the performance of its contractual obligations (Article 6(1)(b) of the GDPR) as well as the legitimate interests of Mesogeios Digital S.A. (Article 6(1)(f) of the GDPR).
6.b. Personal Data of Staff and Job Applicants
- The staff of Mesogeios Digital S.A. are trained and aware of their obligations regarding the protection of personal data, as well as regarding the professional confidentiality of clients, suppliers, business partners and the staff themselves. There is always a contractual relationship between Mesogeios Digital S.A. and its employees, with the necessary confidentiality undertakings and the implementation of appropriate organisational and technical measures to protect personal data.
- When a new vacancy arises, Mesogeios Digital S.A. collects CVs from prospective employees. At this stage, the Company collects and processes candidates’ personal data, such as full name, identity/passport details, age, marital status, address, telephone number, email address, CV details, degrees, qualifications, previous employment, position applied for, etc. CVs from prospective employees are collected either by sending an electronic file to the company’s email address or in hard copy via the company’s staff. CVs are processed and assessed only by individuals duly authorised for this procedure, thereby ensuring confidentiality during the assessment of CVs, in accordance with a fundamental principle of the General Data Protection Regulation (GDPR).
- Mesogeios Digital S.A. ensures that each candidate’s personal data is kept intact and secure for one (1) year from the date the CV is received, so that it may be considered for future employment opportunities.
- When Mesogeios Digital S.A. decides to recruit a candidate, it collects and processes personal data such as full name, passport/ID details, age, marital status, address, telephone number, email address, CV, degrees, qualifications, previous employment, job title, medical certificates, sick leave, Tax Identification Number (AFM), Social Security Number (AMKA), Social Security Registration Number (AM IKA), IBAN, employment contract, payroll details, training records and staff attendance records. This data is necessary for the fulfilment of the Company’s contractual and legal obligations.
The legal basis for the above processing is the performance of the contract (Article 6(1)(b) of the GDPR), the fulfilment of its legal obligations, e.g. compliance with tax, social security and labour obligations laid down by law (Article 6(1)(c) of the GDPR), and the legitimate interests of Mesogeios Digital S.A. (Article 6(1)(f) of the GDPR), as well as the consent of job applicants to the submission of their CVs (Article 6(1)(a) of the GDPR).
6.c. Personal Data of Third-Party Partners/Suppliers
Mesogeios Digital S.A. collects and processes personal data relating to its partners and suppliers (e.g. including, but not limited to, website hosting providers, IT support staff, building security staff, accountants/tax advisers, legal advisers, business consultants, safety technicians, occupational health doctors, etc.) such as full name, email address, telephone number, address, tax identification number, ID card number, social security number, IBAN, business cards, invoices, supporting documents, contracts, etc. It also maintains a record of meetings, a filing system for categorising, evaluating and monitoring the progress of partners and suppliers, as well as audit reports. This information is necessary to enable the Company to communicate with, direct and supervise its partners, always with a view to ensuring effective collaboration and customer satisfaction.
The legal basis for the above processing is the performance of the contract (Article 6(1)(b) of the GDPR), the fulfilment of its legal obligations, e.g. compliance with tax, social security and labour obligations laid down by law (Article 6(1)(c) of the GDPR), and the legitimate interests of Mesogeios Digital S.A. (Article 6(1)(f) of the GDPR).
6.d. Personal data from video surveillance
The security cameras and closed-circuit CCTV systems operated by Mesogeios Digital S.A. are primarily intended to deter crime and, subsequently, to maintain records that assist the Company in drawing reliable conclusions, in order to gain a comprehensive understanding of the risks from which it must protect both human life and its own property. The Company ensures that the locations where cameras are installed and the method of data collection are determined in such a way that the data collected does not exceed what is strictly necessary to fulfil the purpose of the processing and that the fundamental rights of its customers, partners, suppliers and staff are not infringed. Furthermore, Mesogeios Digital S.A. ensures that data subjects are informed, before entering the area covered by the video surveillance system, in a clear and comprehensible manner (via a sign), that they are about to enter an area under video surveillance. The video surveillance system is not used for the purpose of monitoring employees within the workplace, but only at entry and exit points to and from the workplace. Personal data resulting from the use of monitoring and surveillance methods will not be used to the detriment of customers, business partners, suppliers and the Company’s staff unless they have been previously informed of the introduction of these monitoring and surveillance methods and of the use of such data. The maximum retention period for video surveillance recordings is 7 days.
The legal basis for the above processing is the legitimate interest of Mesogeios Digital S.A. (Article 6(1)(f) of the GDPR).
7. Purposes of personal data processing
- Digital applications, the development of specialised software, and the design, development and manufacture of technology products in the field of environmental applications (liquids, solids, recycling), as well as water resource management, for the customers of Mesogeios Digital S.A.
- Communication with the clients, suppliers and partners of Mesogeios Digital S.A.
- The recruitment and payroll of employees, and all the Company’s general obligations towards its employees, as well as the processing of employees’ personal data for tax and social security purposes and as required by law (e.g. notifying their recruitment to the ERGANI information system, granting statutory leave, etc.).
- The collection of CVs from job applicants, who submit their CVs voluntarily either electronically or on paper, and which are accessed and assessed solely by company staff who are competent and authorised for this specific process.
- The management and training of human resources, within the framework of the legitimate interest in the sound and effective management of the Company, as well as in the continuous improvement of its operations and efficiency.
- Video surveillance of the entrances and exits to the Company’s offices for the purposes of protecting and ensuring the safety of human life and the Company’s property.
- The management of the Company’s judicial and/or extrajudicial disputes, in accordance with its relevant obligations arising from the law.
- The Company will not carry out any other processing of personal data relating to the data subjects mentioned above, apart from that referred to above, unless prior notification has been given or where necessary.
8. Basic Principles of Personal Data Processing
- The processing of personal data is carried out in a lawful, fair and transparent manner.
- Personal data is collected only for specified, explicit and legitimate purposes.
- The period for which personal data is stored and retained is limited and is only for the fulfilment of the specific purpose of the processing.
- Personal data must be accurate and kept up to date.
- Personal data that is inaccurate is either rectified or erased.
- Personal data is processed with the appropriate security and confidentiality.
- Personal data shall remain confidential and be stored securely.
- Personal data is not disclosed to third parties, unless this is necessary in order to provide services in accordance with an agreement.
9. Disclosure of personal data
Mesogeios Digital S.A. may transfer personal data provided by individuals to third parties in the following circumstances and for specific purposes.
9.a. To its employees or external partners
These are professionals who are fully informed of their obligations regarding the confidentiality of the personal data of customers, partners, suppliers and employees. The employees and external partners of Mesogeios Digital S.A. have access only to the personal data of customers, partners, suppliers and employees that is deemed strictly necessary for the performance of their duties. Between the Company and its employees and external partners, there is always a contractual relationship incorporating the necessary confidentiality obligations and the implementation of appropriate organisational and technical measures to protect the personal data of customers, partners and suppliers.
9.b. To other third parties in accordance with legislation
Mesogeios Digital S.A. may disclose the necessary and essential personal data to social security bodies, the Ministry of Labour, the competent tax authorities, as well as to any administrative, judicial or other public authority, as provided for by applicable legislation or a court order, in order to comply with applicable legislation or to respond to a mandatory legal procedure (e.g. for tax purposes) or to protect the rights or security of the Company.
9.c. To other third parties with consent
Apart from the disclosures described in this Privacy and Personal Data Protection Policy, Mesogeios Digital S.A. may transfer information relating to you to third parties, provided that it has obtained your free and explicit consent.
9.d. Transfer of Personal Data outside the EEA
Mesogeios Digital S.A. does not transfer personal data to third countries outside the European Economic Area (European Union, Iceland, Liechtenstein and Norway). Should such a situation arise, the Company will transfer personal data only to third countries that provide an adequate level of personal data protection and for which an adequacy decision has been issued by the European Commission. Otherwise, the Company may transfer personal data only if the data subject has given their explicit consent to the transfer or if the transfer is subject to appropriate safeguards, as set out in Articles 46 et seq. of the General Data Protection Regulation (e.g. Standard Contractual Clauses, Binding Corporate Rules). Furthermore, the Company will inform data subjects of this matter and, in particular, will explicitly state the third countries to which personal data will be transferred, as well as the aforementioned mechanisms permitting such transfer in accordance with the General Data Protection Regulation (e.g. an adequacy decision by the European Commission, Standard Contractual Clauses, Binding Corporate Rules, etc.). For the avoidance of doubt, in the event that the United Kingdom is no longer part of the EEA, references in this paragraph to the EEA shall mean the EEA and the United Kingdom.
10. Retention Period for Personal Data
The period for which personal data is stored and retained is determined on the basis of the following specific criteria, as applicable:
- Where processing is required by provisions of the applicable legal framework, the personal data of customers, partners and suppliers will be stored for as long as required by the relevant provisions.
- Where processing is carried out on the basis of a contract, the personal data of customers, partners and suppliers are stored for as long as is necessary for the performance of the contract and for the establishment, exercise and/or defence of legal claims arising from the contract.
- CVs of job applicants are retained for up to one (1) year from the date of receipt. After this period, they are deleted without further notice.
- The CVs of employees at Mesogeios Digital S.A. are stored in the Company’s IT systems and in a physical archive until the end of their contract, for administrative purposes (e.g. participation in tenders, grant schemes).
- As regards the personal data of customers and employees of Mesogeios Digital S.A., this is retained for twenty (20) years from the expiry of their contractual relationship, in the event that the data subjects in question wish to bring claims, which are subject to a 20-year limitation period.
11. Data Security
Mesogeios Digital S.A. implements appropriate technical and organisational measures to ensure the secure processing of personal data and to prevent accidental loss or destruction, as well as unauthorised and/or unlawful access to such data, use, alteration or disclosure of such data. These technical and organisational measures are taken both during the design of the processing systems (e.g. encryption of data on the company’s servers and computers, etc.), as well as by design, so that only the personal data necessary for the specific purpose of the processing is processed (the principle of data minimisation). However, the Company does not rest on the technical security measures it has implemented to date, but is constantly seeking new and up-to-date methods to safeguard the personal data it collects and processes. In any event, however, the nature of the internet and the fact that it is freely accessible to anyone means that the Company cannot guarantee that unauthorised third parties will never be able to circumvent the technical and organisational measures in place, gaining access to and possibly using personal data for unauthorised and/or unlawful purposes.
12. Actions to be taken in the event of a personal data breach
A personal data breach is defined as a breach of security measures resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access to personal data that has been transmitted, stored or otherwise processed. Any person who becomes aware of a personal data breach must take appropriate measures to protect the personal data from any further adverse impact and shall report the breach without delay to the Company’s DPO, who shall record the breaches identified and assess their causes.
In the event that a breach of data subjects’ personal data is identified and such a breach is likely to pose a risk to their rights and freedoms, Mesogeios Digital S.A. undertakes to notify the Hellenic Data Protection Authority (HDPA) without delay, and in any event within 72 hours of becoming aware of the breach.
Furthermore, if the personal data breach is likely to result in a high risk to the rights and freedoms of the data subject, the data subject must be informed by the Company without delay.
13. The Rights of Data Subjects
Any natural person whose personal data is processed by Mesogeios Digital S.A. has the following rights:
- Right to information: You have the right to be informed of the identity and contact details of our Company or our representatives, the purposes of the processing for which the personal data are intended, as well as the legal basis for the processing, the recipients or categories of recipients of the personal data. In accordance with the principle of transparency that governs our Company’s operations, you may contact the Company to request further information on how your personal data is processed and how to exercise your rights, by submitting the relevant requests. We will respond to your requests without undue delay and, in any event, within one month of receiving the request. This time limit may be extended by a further two months, if necessary, taking into account the complexity of the request and the number of requests.
- Right of access: You have the right to be informed of and verify the lawfulness of the processing, as well as to request from the Company copies of the personal data being processed. You therefore have the right to access the data and to receive further information regarding its processing. You also have the right to access more specific information regarding the content and the manner in which you may exercise your individual rights.
- Right to rectification: You have the right to review your personal data, request the rectification of inaccurate or incomplete data, and update or amend your personal data.
- Right to erasure: You have the right to request the erasure of your personal data where the Company processes it on the basis of your consent or in order to protect its legitimate interests. In all other cases (such as, for example, where there is a contract, a legal obligation to process personal data, or a public interest), this right is subject to specific restrictions or may not apply, depending on the circumstances (e.g. the Company is entitled to refuse to erase your personal data for the purpose of establishing, exercising or defending legal claims).
- Right to restriction of processing: You have the right to request the restriction of the processing of your personal data in the following circumstances: (a) where you contest the accuracy of the personal data and until such data has been verified, (b) where you object to the erasure of personal data and request, instead of erasure, that its use be restricted, (c) where the personal data are no longer necessary for the purposes of processing, but are nevertheless necessary for you to establish, exercise or defend legal claims, and (d) where you object to the processing and until it is established that there are legitimate grounds for continuing the processing which are relevant to us and which override the grounds on which you object to the processing.
- Right to object to processing: You have the right to object at any time to the processing of your personal data in cases where, as described above, such processing is necessary for the purposes of the legitimate interests pursued by the Company as the Data Controller, as well as to processing for direct marketing purposes. In particular, you have the right to object to any decision taken solely on the basis of automated processing, including profiling, which produces legal effects concerning you or significantly affects you. However, you may not object to automated decision-making concerning you where such a decision is either necessary for the conclusion or performance of the contract you have entered into with the Company or is based on your explicit and freely given consent.
- Right to data portability: You have the right to receive your personal data free of charge in a format that allows you to access, use and process it using commonly used processing methods. You also have the right to request that the Company, where technically feasible, transfers the data directly to another data controller. This right applies to data that you have provided to the Company and which is processed by automated means on the basis of your consent or in performance of a relevant contract.
- Right to withdraw consent: You have the right to withdraw your consent freely, where processing is based on your explicit and freely given consent, without this affecting the lawfulness of the processing carried out on the basis of your consent prior to its withdrawal.
To withdraw your consent, you may contact the Data Protection Officer (DPO) of Mesogeios Digital S.A.
Right to lodge a complaint with the Hellenic Data Protection Authority: In the event of a breach of your personal data, you have the right to lodge a complaint with the Hellenic Data Protection Authority, www.dpa.gr, Call Centre: +30 210 6475600, Email: contact@dpa.gr.
14. Third-party websites
The Mesogeios Digital S.A. website may provide links to other websites that are not owned or controlled by the Company, but which may be useful or of interest to visitors to our Company’s website. In such cases, Mesogeios Digital S.A. is not responsible for the privacy policies applied on third-party websites, nor for the accuracy of their content, nor for the collection of information by the parties that own and control such websites, nor for their use of cookies. Consequently, the Company is not liable for any loss or problem incurred by any of its users who access such an external website, but it is solely up to each user to decide whether or not to use a link to another website provided on the Company’s website, particularly if the user does not fully trust that website.
15. Changes to the Privacy and Personal Data Protection Policy
Mesogeios Digital S.A. may make changes or amendments to this Privacy Policy in order to comply with the evolving legal environment or the Company’s needs. The Company, in accordance with the provisions of the applicable legislation, reserves the right to amend this Policy from time to time without prior notice. You are responsible for reviewing this Privacy Policy when you visit the Website, so that you are aware of any changes or updates to this Policy. All amended terms come into effect from the date on which the updated Privacy Policy is posted on the Company’s Website.
16. Contact details of the Data Protection Officer (DPO)
For any enquiries regarding the processing of personal data, please contact the Data Protection Department of Mesogeios Digital S.A. using the following contact details:
- Email: dpo@mes-digital.com
- Address: 34 Averof Street, Postcode 14232, Nea Ionia, Attica, Greece
- Telephone: +30 211 118 77 76
- Website: www.mesogeos-digital.com
The Company’s Representative
Date: 01.02.2024
Signature: NIKOLAOS PAPASARAFIANOS
