We treat the protection of your personal data with responsibility and believe that your data should only be collected and processed when absolutely necessary. That's why all our company systems, but also the website it is designed with the appropriate operational and internal systems and complies with the applicable European legislation regarding data protection {General Regulation EU 679/2016 for the protection of natural persons against the processing of personal data (GDPR)}.

This Policy has been adopted by the company under the brand name " TOTAL LOOK EE » and the distinctive title "Achilleas Accessories" , based in Athens, 1 Souliou Street, (VAT 801013148 - D.O.Y A'THINON), with VAT number 146956101000, tel. 210-9888649, which is the controller of the personal data you provide us. Our company is responsible for protecting you whenever you provide us with your information when you purchase products in our physical stores, as well as when you use either as a simple visitor, or as a consumer-buyer, or as a registered member and to inform you of all the information you need, in accordance with articles 12, 13 and 14 of the new GDPR applicable from May 25, 2018 at the European level.

1. What is personal data?

Personal Data is any information that refers to you, or can be attributed to you. Such data are, for example, first name, last name, patronymic, address, postal code, city, country, telephone, as well as e-mail, username, password, etc. In addition, personal data also constitute some technical data concerning you, such as your IP address or the websites from which you entered our site, etc.

2. Personal data collected by ACHILLEAS ACCESSORIES and purposes of their processing

The collection and processing of this information is carried out on the one hand for purposes directly related to the services you request from us and we offer you and/or for the purposes for which you have granted us your consent and always in accordance with the applicable laws and regulations regarding the protection of personal data. We retain your personal data for as long as necessary to provide you with our products and services, but also for our compliance with our legal obligations.

As part of our normal operation, we do not receive personal data of special categories, in accordance with the applicable Regulation, such as data related to your state of health or the alleged commission or conviction of criminal offences. In the event that we become aware of such data, we will process it only if you give your express consent or based on our legal obligation, in any case in accordance with the relevant provisions of the Regulation.

In addition, like most websites, this one, by browsing the , your registration as a Member in our Online Store, your registration in the Newsletter Service, or the submission of a purchase order in our Online Store, collects and processes personal data and information concerning you, either through cookies or directly from you who grant it to us.

In particular, Achilleas Accessories collects and processes personal data and information in accordance with the following:

2.1 Browsing the Website – Cookies

2.1.1. For your navigation on the Website/Online Store, your registration is not required, in which case the direct provision by you to us of your personal data or other information concerning you is not required. However, the Company, during your navigation on the Achilleas Accessories site and your transaction with us through our services, collects personal data and other information about you through our own Cookies (First Party Cookies) or third parties with whom we collaborate (Third Party Cookies).

Cookies are small text files that are installed on your computer or electronic device temporarily and transmitted to our server when you visit Achilleas Accessories, through the browser you use. No Cookie file collects information and does not gain knowledge of any document or file from your computer.

The information collected by Cookies for the above purposes may include the type of browser you use, the type of computer, its operating system, Internet service providers, the sites you visit and about the links to third-party websites you may choose through our Website, the products and advertisements you see, your device's IP address, User Name & Password, general demographic information about you such as gender, age, place of residence and other shopping habits and online behaviors.

Our Company uses Cookies to connect you to your Account without requiring the opening of a new account every time you want to make a purchase in our store, to remember the products stored in your cart, to verify any problems on our server, etc.

In addition, they are used by us for advertising and promotion purposes, statistical purposes, for market research purposes in order to optimize our products and services, profiling, to measure the effectiveness of the website, to improve and upgrade its content, to adapt it to the demand and needs of Users, as well as to measure the effectiveness of the presentation and promotion of Achilleas Accessories on third-party websites.

By browsing the Website and making purchases through our Online Store, you consent to the processing by Achilleas Accessories of the information it collects from you through the use of Cookies. You can, however, edit your preferences through the special settings of our site for Cookies.

2.1.2. We also use Google Analytics (GA) and Google Tag Manager, as well as Adaplo, Facebook, Adwords, Moosend to track user activity. We use this data to determine the number of people using our website, to better understand how they find and use our website, and to see their journey through the website.

Although GA records data such as your geographic location, device, web browser and operating system, none of this information makes you personally identifiable to us. GA also records your computer's IP address, which could be used to identify you, but Google does not give us access to this information.

2.2. Member Registration - Account Opening

During the Member registration process in our Online Store, Achilleas Accessories collects the personal data that you voluntarily declare, namely your first name, last name, e-mail and password. Your above personal data is used by our Company in order to open a Member Account for you, through which you can see the history of your transactions, while at the same time you give your consent by providing these details to the Company to keep the password, in order to allow you to access your Account every time you connect with your password. If you are under 16 years of age, you MUST have your parents' consent before signing up for .

At the same time, there is cooperation with the Mailchimp platform for sending "procedural" emails (for creating a new account, registering a new order, modifying an order, changing the password on the individual account, etc.).

2.3. Subscribe to the Newsletters service

We will not send you any Newsletter, for any purpose of advertising or promoting our products, if you do not choose to subscribe to our Newsletter service. If you register, Achilleas Accessories will collect your e-mail address and send you informational material regarding the products of our Online or physical Stores, any offers on products, gift vouchers and points, advertisements regarding products, commercial partnerships, etc.

If you choose to participate in our Newsletters service, the email address you submit to us will be forwarded to Moosend who provide us with marketing services. The email address you submit, if you are not a Member of our e-shop, will not be stored in a database within the site or in any of our computer systems. Your e-mail will remain in Moosend's database for as long as we continue to use the services or until you explicitly request to be removed from the relevant list.

In case you do not wish to receive Achilleas Accessories Newsletters and advertising material in general, you can at any time request to be removed from the recipient list, either by following the relevant link at the end of each e-mail you receive from us, or by sending the relevant request to . From the e-mails that our Company sends you as part of the Newsletters service, cookies record the opening rates of messages you receive from us and the number of clicks, along with the content of the e-mails when you click.

If you are under 16, you MUST have your parents' consent before subscribing to our email newsletter.

2.4 Purchase of Products from the Achilleas Accessories Online Store

In our e-shop, it is possible to make purchases either from ordinary visitors, or from visitors who are registered members, through their individual account. For the completion of each online order, its processing and execution, it is necessary to provide, collect and process certain necessary personal information. Our Company uses this data for the execution of the contract between us, i.e. for the execution of your order, with the sale of the products and their delivery to the address you give us, as well as for making the payment on your behalf. Specifically, whether you are a Member or not, your e-mail, first name, last name, address, region, prefecture, postal code, country and telephone number are collected to complete your purchases.

We will send to your e-mail the notification of receipt and execution of the order by the transport company, or we will use both your e-mail and your phone to send you a message in case we encounter a problem in the execution of your order or for the employee of the transport company who will deliver the products to you in case of need and for any other communication with you or notification in accordance with the Terms of Use (wrong price, delay in shipment) to contact you etc.).

2.5. Payment by credit card

If you choose credit card to pay for the product(s) you purchase from Achilleas Accessories, you will automatically be transferred to a secure banking transaction environment. There, you will have to provide for the purpose of payment the type and number of the card, its expiry date, CCV, filling in all the necessary fields in the (secure) order form. Transactions are protected by top online RSA Encryption security systems, which guarantee a secure trading environment in most of the world's largest businesses. Our Company does not learn or keep any personal data related to the payment details, except for the successful or non-completion of the transaction, for obvious purposes of service and execution of the order.

2.6. Login and Order with your Facebook, Google+ account details

You can register in our e-shop or complete an order through your Facebook or Google+ account. In this case, Achilleas Accessories will ask you to give us your permission to access any information that you have made public on Facebook or Google +. By choosing to grant this permission, you consent to Achilleas Accessories accessing these details of your Account, for the purpose of creating a profile for you, for the purposes of targeted advertising of its products based on your profile, and for statistical purposes.

2.7. Purchase of products in the physical stores – points of sale maintained by the company.

The Company maintains physical stores in various points of sale in Greece and abroad. In them, and only if our customers so wish, data such as name, surname, telephone and e-mail may be collected, which they themselves provide to our partners, in order to register them as Members in the Company's online store or to send informative messages.

2.8. Data of our employees

Our Company collects personal information from jobseekers, including private contact information, professional qualifications and previous work experience, in order to enable us to make informed hiring decisions. After hiring, we collect information about our employees within the framework of our contractual relationship and for purposes related to it, such as to evaluate their performance, to run their payroll or for tax purposes. This information of our employees is collected and stored in a corporate database in accordance with our standard business practices. We may also process similar information about freelancers, consultants and other third parties who work with our company to provide products or services to it.

3. Lawful basis for processing your data

As can be seen from what we have already described, we never process your data without this processing being necessary and based either 1) on the execution of a sales contract between our company and you as a customer, or 2) on our legal interests to maintain our relationship with you as our customers, or 3) on your consent, mainly for advertising purposes regarding the activity and products of our Company.

More specifically, our Company will in no case receive more personal data from you than is necessary for each purpose for which it collects it, nor will it disclose your data to third parties, unless this is absolutely necessary for the performance on our part of a service, the provision of which you have requested and is related to the sales contract between us, (e.g. product delivery) or the processing by a third party is necessary for the purposes of our legal interests (e.g. conducting a credit check) or if you have previously given your consent , and/or when the law requires it (eg to execute a court decision, prosecutor's order, etc.).

Also, our Company does not sell, rent or transfer your personal data to third parties, with the exception of the application of relevant legal dictates, and does not collect and process personal data of minor children, unless it has the express consent of their parents.

4. Retention Period

We do not retain your data for longer than is necessary to fulfill the purposes for which it was collected or as required by applicable laws.

The information you provide to us may be archived or stored periodically, in accordance with our relevant security procedures, and will only be kept for as long as is necessary for each purpose for which it was collected, unless the law requires us to keep it for a longer period (eg in relation to sales tax documents to you), or to delete it sooner, or unless you exercise your right to have your data deleted or restricted (whenever this is permitted ).

For example, we will keep the resumes we receive, without ultimately hiring the interested party, for a period of twelve (12) months. For example, finally, according to Directive 1/2011 of the National Authority for the Protection of Personal Data, the recording files from security cameras that are legally installed in our offices or stores should be kept for a specific period of time, according to the purpose for which they are processed. Unless otherwise required by law or necessary in cases where a breach has been observed, these records are destroyed every 15 business days.

5. Recipients of your data

We do not sell, rent or trade your personal information, nor will we do so at any time in the future. We may disclose (share, send, or otherwise make available) the personal data we collect about you in accordance with the terms herein to third parties, but always under conditions that fully ensure that there is no illegal processing, i.e. other than the purpose of transmission.

In addition, your data may be transferred to countries within the European Economic Area, where all security requirements are met. As a rule, we do not transfer data outside the EU or EEA, and in case this is necessary (e.g. to Google), the transfer will only be made in accordance with international security requirements and with a view to maximum protection of your data.

The data kept in our file may be communicated to the competent judicial, police and other administrative authorities upon their legal request and in accordance with the applicable legislative provisions.

In any case, Achilleas Accessories employees who have access to your personal data and information are specific and properly trained, while unauthorized access to your data is prohibited.

In particular, we may transfer your data in accordance with the following:

  • To Google, in accordance with what we have already mentioned above, in particular for the use of the Google Analytics and Tag Manager services.
  • To Mailchimp, in accordance with what we have already mentioned above, in particular for the provision of Newsletter services.

    Both of these agencies are based in the US and are compliant with the interstate agreement known as EU-US Privacy Shield.

    • To advertising companies and advertising service providers in general. Achilleas Accessories does not disclose personal data without your consent, however, it may share with third-party advertising service providers statistical information regarding the products purchased, demographic information, information regarding the technical characteristics of the mobile devices used to access the visitors to our e-shop, etc., from which you cannot be identified.
    • To third parties who provide Achilleas Accessories with services related to the operation of the Online Store, such as developers, data analysts, suppliers, data security service providers and subject information, strictly for the purpose of processing their services to us.
    • To service providers for the hosting of our customers' database, its technical support and management.
    • To data security service providers.
    • To courier companies, for the delivery of your orders.
    • To credit institutions or other providers of electronic transaction facilitation, to complete your online purchases, as we have already described.
    • To other companies that are members of our group.
    • •To designated successors: In the event Achilleas Accessories undergoes a business change, such as a merger, acquisition by another company, or sale of all or part of its assets, it may transfer all information and data it holds, including personal information, to the successor organization. If there are significant changes to Achilleas Accessories' privacy practices as a result of the business transition, the Company will notify you prior to the transfer of your personal information.

      6. Your Rights

      We are committed to providing you with the opportunity to exercise all of your rights, under the GDPR, in relation to your data that we hold and process, such as the right to access and correct, withdraw your consent, delete or restrict the processing of your data, restrict or stop direct marketing and provide a copy of your data that we hold in digital format (e.g. pdf) to you or another service provider that you may indicate to us. You also have the right to file a complaint with the competent authority.

      For example, at your request, we will:

      • we grant you access to copies of your personal data within a reasonable time
      • we correct personal information when it is inaccurate
      • withdraw your prior consent to the processing of personal information, etc.

        In case you wish to exercise any of your rights regarding any of your personal data held by us, you can write to our company at the email . You can request us to access your data free of charge, however depending on the amount of data our company holds about you, we may ask you to cover some of our costs.

        7. Security of your Data

        We are committed to safeguarding and protecting your personal data. We constantly implement appropriate technical and organizational measures to ensure a level of security suitable to prevent accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access of your personal data collected, stored or otherwise processed.

        Our Company has implemented security procedures and measures in physical and electronic records in order to protect the personal information we hold. We regularly review security measures and will endeavor to protect your personal data as if it were our own. However, we are not responsible for the actions of third parties or their security measures with respect to information that third parties may collect or process through their websites, services or otherwise. We will destroy or delete your personal data when we no longer need it to provide our contractual services or as otherwise required by law.

        More specifically:

        General Control Procedures: Regular and systematic checks are implemented at workplaces, such as automatic computer locking, frequent hardware and software upgrades and configuration, in order to minimize the possibility of unauthorized access and exploitation of critical data stored in our archive. The company's equipment is connected to an uninterruptible power supply (UPS) system, so that its operation is not interrupted in the event of a system failure, while in the event of a prolonged power outage, our servers are safely shut down.

        Saving Files in Physical Form: Our company may keep records in physical, paper form, which contain your personal data (such as contracts, invoices, etc.). We keep these records in secure areas protected by security locks and to which only our employees or partners have access, for purposes described in their employment contract. We use a shredder to destroy physical files to prevent anyone from accessing them without our authorization.

        Online Storage: Some of your personal data will be stored in the website database that we maintain. We have implemented graded access to files containing personal data on our network, which is protected by a VPN (Virtual Private Network). Based on this graded access, special codes are required which are only provided to those employees or partners of ours who are required to access these files. Our network is additionally protected by antivirus protection and a firewall, which separates the local network and prevents unauthorized access. Finally, we ensure the security of your data by creating backup copies (back-up) of our system files.

        File Transfer: All internet traffic (file transfer) between this website and your browser is encrypted and transferred via 128-bit SSL protocol. Encryption is essentially a way of encoding information until it reaches its intended recipient, who will be able to decode it using the appropriate key.

        Card Details: In addition, as we mentioned, we do not store the details of your cards that you use online. Your card details are not visible on Achilleas Accessories because you are automatically transferred to a secure banking environment to complete your order. At the same time, you must also take every possible measure to prevent third parties from gaining access to your account, such as not disclosing your password.

        E-mail: Data sent to us via e-mail is protected via SMTP (Simple Mail Transfer Protocol). Our SMTP servers are protected by TLS (sometimes known as SSL) security protocol, which means that email is encrypted using 256-bit SHA-2 encryption before it is sent over the Internet. Email content is decrypted by local computers and devices.

        8. Contact us

        In case you want any clarification or information regarding the terms of this Policy, or you have any disagreement, reservation or question, you can contact our Company at tel. 2109888649 or by sending an e-mail message to sales .

        9. Changes to Privacy Policy

        This privacy policy may change from time to time in accordance with legislation or industry developments, without prior notice. That's why we invite you to check this page regularly.