Personal Data Protection Statement
The société anonyme under the name “Goody’s Société Anonyme of Catering Services” (hereinafter referred to as “the Company”), as the Controller, is subject to all obligations and commitments arising from the personal data protection legislation, including the General Data Protection Regulation (EU) 679/2016 and Law No 4624/2019 (hereinafter referred to as the “Legislation on PD”). For the Company, respect for and protection of your personal data is a commitment. We understand and take seriously into consideration that you are aware of and interested in your personal data.
This Privacy Statement describes the type of personal data, which is being collected by the Company on your behalf, how we use and protect your personal data and your options regarding the way we use these data. Its purpose is to inform you of the Company's policy regarding your personal data, which you provide to us, so that you are aware of the purpose of our processing, of the categories of people, to whom these data may be disclosed, and the procedures you can follow i order to exercise your legal rights.
The Company, recognising its ongoing responsibility for the protection of your personal data, since they are being processed by the company as a Controller, has taken all technical and organisational measures particularly based on the principles of proportionality, purpose limitation and processing time limitation and data minimisation, solely for the purpose of processing, for which they have been collected, and solely for the time period of the purpose of processing, so that your personal data is absolutely secure.
We recognize that the protection of personal data is a constant responsibility and therefore we will update and modify this statement from time to time in order to be fully in compliance with the legislation. Please visit our website https://www.goodys.com frequently to make sure you are aware of and satisfied with any changes. In case of doubt regarding any term of the present privacy statement, you may contact us by e-mail at email@example.com
We would also like to assure you that the Company does not process personal data which belongs to minors under the age of 18.
The Company has designated the company under the name “NetBull IT Services Ltd.” as the Data Protection Officer.
Who we are
The Company is active on the mass catering market and is the largest catering chain in Greece, with shops and a presence abroad. Our objective is to provide our services to consumers either through our network of stores, which operate under a franchise system, or/and through our website goodys.com, or through the mobile application “Goody’s app” or through in-store applications.
What type of personal data is collected for you?
Under no circumstances shall the provision of the following personal data to the Company be obligatory, however the non-provision of certain data, which are explicitly detailed below, will not allow us to provide our catering services to you, as well as your participation in the “ALL STAR CLUB” Loyalty and Rewards Program . This means that you voluntarily provide us at least with the personal data needed in order for the Company to properly and effectively provide the services you wish to receive by the Company, mainly regarding the fulfilment of your orders for our products, and your participation in the “ALL STAR CLUB” Loyalty and Rewards Program. Under no circumstances shall the non-provision of the non-mandatory personal data, which is detailed below as well, affect the unimpeded provision of our services.
- In order to use the Delivery/Take away services either through our stores and/or online via our website goodys.com or through the Goody’s app or through in-store applications, we process the following personal data:
- Full name: We collect your full name for the preparation of your order of the Goody’s price list products through our network of stores
- Postal address: We collect the residence or legal address of our customers in order to deliver and complete your order
- E-mail address: We collect the e-mail address of our customers to confirm their order. The e-mail address of the Guests of the Website is collected exclusively for sending the receipt of the order placed through it.
- Phone numbers: We collect the phone number of our customers to provide our services better and faster, up to the completion of the order, including the confirmation of their order.
- Invoicing information: We collect our customers’ data required for the invoicing of our services, such as the T.I.N. and the Tax Office, the occupation, the address etc., as long as they request an invoice to be issued and sent to them (concerning sole proprietorships)
- Facebook ID/Gmail: In case the customer chooses to log in to the online ordering service (goodys.com, goodys app.) through his Facebook account. The user’s e-mail address is the necessary information we collect from his social media and Gmail.
- History Preferences - Information: Only after your prior written consent, we collect information regarding your purchases in our stores through goodys.com as well as the deals received in order to facilitate your future orders.
- Credit or debit card information: It is necessary for Goody’s to collect the data and information of the Users’ and Guests’ credit or debit cards, in case they choose to prepay (before the delivery of the order through the Website or the Application) the price of the transaction using their credit or debit card, or to pay at the time of the delivery the price of the transaction using their credit or debit card. Credit/debit card details will be requested upon completion of the order, as long as they choose the relevant payment method, and will be used solely for their electronic transmission through the secure Viva Wallet environment to complete the payment. Goody’s does not store any credit/debit card information in its electronic systems or in physical files. The verification of the cardholder may require the transfer of the User's card details to a third party collaborating with Viva Wallet, which completes the card payment process.
In order to participate in the “ALL STAR CLUB” Loyalty and Rewards Program, we collect and process the following personal data:
- In order for our customers to register and participate in the “ALL STAR CLUB” Loyalty and Rewards Program, we collect their full name, mobile phone, e-mail address, gender and date of birth, as well as information about their purchases made in our stores. By using the “ALL STAR CLUB” membership number, information is collected regarding the purchases made by you in our stores, and/or online via our website goodys.com or through the Goody’s app or through the in-store applications, in order to collect points and receive the benefits and vouchers arising from the aforementioned program.
- By registering in the “ALL STAR CLUB” Program, users give their consent to have their profile analysed (profiling) by the Company and be classified into segments (custom audiences). Within this framework, users are asked during their first login to the Website or/and the Application to fill out a personal data questionnaire (date of birth, gender) in order to earn stars/points and to declare their preferences in order to receive personalized news and offers, as detailed more specifically in par. 5.2.3. regarding the purposes for which we process your personal data.
How personal data is collected:
Your personal data is being collected when showing your interest in our services, when making purchases through our e-shop or when we provide our services to you directly in our stores, or when entering your data online while visiting our website or the Goody's app or when subscribing to our newsletter.
With regard to the registration and participation of our customers in the “ALL STAR CLUB” Loyalty and Rewards Program, we collect your personal data when signing up for the “ALL STAR CLUB” Loyalty and Rewards Program and entering your data for that purpose.
Who else is the recipient of your personal data?
We do not transfer your personal data to third parties, except to those with whom we cooperate and who are necessary or facilitate the provision of our services, yet always under conditions fully ensuring that your personal data is not subject to any unlawful processing, that is any processing having a purpose other than that of the transmission as described above. Within the framework of our activities, we use third parties, such as the companies Right On S.A., TELECROFT S.A. etc., which provide services on our behalf. For example, we reserve the right as for the following (No. 5) purposes to transfer your personal data to credit card providers for the processing of a payment on your behalf following an order from our e-shop, to third parties - natural or legal persons - who may provide promotion and marketing services for both our business and our products or our services on our behalf. We inform you that these categories of recipients of your personal data are processors on our behalf and therefore do not process your data beyond the above purposes of transfer. In any case, the Company shall not make available for sale or transmit otherwise or publish the personal data of the guests/users of its website to third parties, except those mentioned above, without the guest’s/user’s consent, excluding the application of relevant legal orders and towards competent authorities only.
Access may also be given to:
- external partners of the Company, who provide accounting or legal services, consulting services in general, IT services, computerisation services, website services, security technician/occupational physician services etc
- external partners of the Company, who provide survey or/and advertising services, provided that you have given your consent,
- lawyers, bailiffs or other people necessary for the judicial or out-of-court settlement of the claims of the Company,
- public services, administrative and judicial authorities, supervisory and regulatory authorities, if required by law, court decision or any other act binding on the Company, in the context of compliance with its general obligations under the law.
These Third Parties process your data strictly and solely for the purpose, for which they have been collected, and take all appropriate security measures to prevent any unlawful processing. In any case, the Company shall not make available for sale or transmit otherwise or publish the personal data of the guests of the Website and its customers’ personal data in general to third parties, except those mentioned above, without the guest’s/customer’s consent, excluding the application of relevant legal orders and towards competent authorities only.
In any case, the access of unauthorised persons, including our employees, to your personal data is prohibited.
Why do we use (process) your personal data?
The Company collects, maintains and processes only the personal data, which are at least and absolutely necessary to achieve the purpose of the processing.
- We use your personal data for the following purposes:
- For your full access to the services provided through our Website (Contact Form/newsletters) and especially for the preparation of the order of the Company's price list products, namely for the provision of our products and services.
- For the preparation of the order of Goody’s price list products, namely for the provision of our products and services, which is based on the conclusion and execution of an agreement or - upon your explicit request - on preparatory actions for the conclusion and execution of an agreement.
- Upon your prior explicit consent, for the purposes of direct marketing or/and promotional activities, such as the participation in competitions or e-mails sent from time to time to those who have subscribed to our newsletter, thus accepting the relevant processing of their personal data. Every newsletter gives the recipient the opportunity to state that he does not wish to receive other newsletters either through e-mail or firstname.lastname@example.org. This may also be done by sending a relevant request to email@example.com and by changing the relevant settings in the account.
- For creating profiles with your consent in order to personalise our services and products.
- For analysis through statistical procedures aiming at the creation and provision of personalised offers.
- For cases where the processing of your personal data is necessary for the purposes of our legal interests or for the purposes of our compliance with the national or/and European legislation.
- Regarding your participation in the “ALL STAR CLUB” Loyalty and Rewards Program we use mainly your personal data for the following purposes:
- Acquisition and redemption of points.
- For the purposes of direct marketing or/and promotional activities, such as the participation in competitions/draws etc., and the sending of informative messages about new products and offers in general.
- For the creation of profiles and statistical analysis in order to personalise our services and products and send special personalised offers exclusively applicable to the members of the “ALL STAR CLUB” Program by subscribing to it. More specifically, through the aforementioned process described in par. 2.2. of filling in the personal data questionnaire (date of birth, gender) and declaring preferences, which is indicated as a mission and is optional, the members of the Program may earn stars/points and receive personalized offers (via e-mail, SMS, social media (e.g. Facebook)). These campaigns may be automated and triggered by the user's actions (e.g. second order, inactive for a period of time etc.).
How long do we keep your personal data?
6.1.1. When the processing is imposed as an obligation by provisions of the law (e.g. Tax, market regulations), your personal data is retained for as long as the relevant provisions require.
6.1.2. In order to prepare the order of our products, we shall retain your personal data for as long as it is absolutely necessary to meet this purpose and where necessary upon your request to issue and send the relevant invoices (concerning sole proprietorships) and secondly to fully satisfy your requests and any complaints regarding the order as well as to establish, exercise or/and support the legal claims based thereon.
6.1.3. For promotional/advertising activities (marketing activities), your personal data is retained until the revocation of your consent and in any case up to 2 years, after which we will ask again for your consent for the aforementioned purpose. You may exercise your aforementioned right of revocation of your consent for the aforementioned purpose at any time, without affecting the provision of our services to you or the preparation of your orders. Revoking your consent does not affect the legality of the processing based on your consent during the period prior to its revocation.
6.2. Regarding your participation in the “ALL STAR CLUB” Loyalty and Rewards program, the Company retains and processes your data for as long as you participate and are a member of the said Program.
6.2.1 In case you wish to unsubscribe from the aforementioned Program, please visit the Website www.goodys.com and log in to your account. Then, after going to “My Account” and choosing to be deleted from the “Personal Data” section by clicking the delete button, the Company will delete your personal data. If you are not participating in the program for five (5) years, the Company will delete your personal data, unless it is required to retain your personal data for a longer period of time, if this is necessary to protect its legitimate interests in relation to possible liability related to the provision of its Services. More specifically, in case any legal claim of customer arises against the Company, his data shall be retained until this claim becomes final.
6.3. The Company may retain your personal data for a longer period of time if this is necessary to protect its legitimate interests in relation possible liability related to the provision of its Services. More specifically, in case any legal claim of customer arises against the Company, his data shall be retained until this claim becomes final.
Guaranties taken for personal data protection
When you provide us with your personal data, we take measures to ensure that it is kept and managed securely. We take adequate physical, technical and organisational measures to protect your personal data. We update and check the security technology we use on an ongoing basis. We give access to your personal data only to those employees and stores of the GOODY’S network, who need to know these data in order to provide you with the services you desire. In addition, we educate all employees on the importance of confidentiality and the privacy and security of your personal data. Among other things, we have taken the following technical and organisational measures and procedures to protect your personal data from any loss, alteration, illegal processing or change:
- access to your personal data is given only to the number of authorised persons for specific purposes
- IT systems used for data processing are accessed only by authorised persons
- access to these IT systems is monitored to detect and prevent unauthorised access immediately
- use of information systems and programs for computers installed in such a way as to minimize the use of personal data or/and the user’s identification data;
- adoption of individual procedures for the protection of personal data and their secure deletion/destruction;
- periodic audit (every 2 years) and deactivation of inactive accounts
You may exercise the following rights in accordance with the terms and more specific provisions of Regulation (EU) 2016/679:
8.1.1. The right to access to your personal data, which we process, as well as to information regarding their processing.
8.1.2. The right to correct your personal data, namely the right to correct any inaccurate information.
8.1.3. The right to object to the processing of your personal data when there is a legitimate interest, including your right to object to the automated processing of your data and their processing for marketing purposes.
8.1.4. The right of restriction of the processing of your personal data, which means to request the suspension of such processing, if you question the accuracy of the data, if you have objections to their processing or if there is any other reason provided for in the relevant Greek or European legislation on the Protection of Personal Data.
8.1.5. The right to receive your personal data, provided to us with your consent, to use it anywhere else.
8.1.6. The right to delete your personal data without undue delay upon your relevant request under the conditions set out in the relevant Greek and European legislation on the Protection of Personal Data in force.
8.1.7. The right to withdraw consent. In cases, where we process your personal data based on your consent, you also have the right to withdraw your consent at any time or change the degree of consent you have given without affecting the lawfulness of the processing for the period prior to the withdrawal of your consent.
8.1.8. The right to be informed about violations.
08/01/2010. The right to lodge a complaint to the competent Greek independent authority, which is the Personal Data Protection Authority, in the event of unlawful processing of your data (http://www.dpa.gr/).
Transfer of personal data outside the EU
Your personal data collected by us are not transferred or processed outside the European Union.
The Company allows only Google Analytics to install the Cookies we use. If you access third party websites or connect to social media (Τwitter, Facebook, YouTube) via our website, you should be aware that these third party websites or entities may install cookies immediately after you click the relevant link, which is beyond our control. Thus, they are governed by the respective individual cookies policy of each of them who installs them.
Please find out more about our Cookies Policy at the following link www.goodys.com/cookies
How to contact us?
In case the Company does not adequately satisfy your request, without sufficiently justifying its refusal, or generally in breach of its obligations under the Legislation on PD, you are entitled to file a Complaint or other complaints to the Personal Data Protection Authority (www.dpa.gr), telephone:2106475600, fax:2106475628, e-mail: firstname.lastname@example.org.
You may contact the Data Protection Officer by sending an email to email@example.com
Version Information - Changes and Updates
The present Statement was last updated on 22-5-2018.
We reserve the right to amend and update the present Statement, either in whole or part of it, at our sole discretion at any time. Any amendments to the present shall apply as soon as the amended Statement is posted on the Website. There will also be an indication on the website indicating the change. In any case, as long as you continue using the Website and its services, the E-Shop and the Google App, after amendments have been applied, as described above, you will be deemed to have accepted these amendments. If you do not agree with the terms of the present Statement as it may be amended, either in whole or part of it, you must cease using our Website and E-shop services. We may periodically send e-mails to remind you of the changes and updates to the present Statement, but you should check our website frequently to stay informed of the current and applicable Personal Data Protection Statement.
Any changes to the present Statement shall be immediately posted here.