Privacy Policy & Rights
Last date of update: 12/2023
“Tiresias S.A.” (hereinafter “Tiresias” or the “Company”) follows a strict policy to protect the privacy of the users of our websites «https://www.tiresias.gr», «https://tsek.teiresias.gr», «https://auth.teiresias.gr» («Websites»). With the present policy we offer you information on how we use cookies, each time you visit our Website. This cookie policy complements the Privacy Policies of our Websites.
Our Company reserves the right to amend and update this Cookie Policy, whenever it deems it necessary. The date the update took place will be indicated at the beginning of the Policy. Any changes thereof shall come in force and effect from the date the update took place as it appears at the beginning of the Policy. It is recommended that you check this page from time to time to make sure you are aware of any changes.
Tiresias’ websites
What are cookies and similar technologies?
Cookies are small text files with information, which are stored by the server of a website on the terminal device (computer, mobile phone, etc.) of a visitor/user while navigating on it. The website retrieves this information at each visit in order to offer the related services. A typical example of such information is the user's preferences on a website, as they are stated by the choices, he makes on it (e.g. selection of specific "buttons", searches, etc.).
According to Article 4 par. 5 of L.3471/2006, the storage or access to stored information in the user’s terminal equipment is allowed only if the specific user has given his consent upon clear and extensive information. An exception to the obligation of obtaining user’s consent, in accordance with the above paragraph, is the case of storage and access to information whose sole purpose is to "transmit a communication through an electronic communications network or is necessary to provide an information society service, that has been explicitly requested by the user or the subscriber". In essence, the user’s consent is not required for cookies which are considered strictly necessary for the realization of the connection to the website or for the provision of the requested internet service.
Cookies can be installed by the provider of the website, visited by the user, (first party cookies) or by other providers (third party cookies), through the provider of the website visited by the user.
Depending on their expiration dates, cookies are either “session” or “persistent” cookies. In particular, session cookies are automatically erased whenever you close your browser, whereas persistent cookies remain stored until their expiration date, unless manually deleted prior to that date.
Does our Company use cookies?
The websites «https://www.tiresias.gr», «https://tsek.teiresias.gr», «https://auth.teiresias.gr» use cookies for the purpose of its smooth and secure operation and the optimization of the navigation experience. In particular, we use certain strictly necessary cookies with the primary purpose to make our Websites more secure, functional and user – friendly.
Upon the visitors’/users’ consent, we will use additional optional cookies to measure and analyse traffic in order to improve the performance and content of the website (Statistical Analysis Cookies/Google Analytics).
What types of cookies do we use and for what purposes?
In the table below we describe the types of cookies that we use at each website and their purposes:
•For the website https://www.tiresias.grType | Description | Purpose |
---|---|---|
Strictly Necessary Cookies | These are cookies, which are absolutely necessary for the smooth and secure operation of our Website, such as cookies for the storage of data necessary for “reading” visual content, for the processing of applications between a group of servers, the authentication of registered users as well as to enable the connection to our website or to provide the internet service requested by the user. | Security and operation of our Website |
Statistical Analysis Cookies (Google Analytics) | These are optional cookies, which if you select them and give us your consent, we will use the Google Analytics service (provided by Google LLC) for the purpose of statistical analysis (web analytics) and in order to receive information about the use and website traffic through monitoring and analyzing the behavior and interaction of site users. For example, we will be able to know how users got to the site (i.e. which links each user followed to get to the site), which pages οf the site were viewed by users, how much time they spent on each of them, etc. Google Analytics will provide us with reports that describe and analyze the traffic of the site and the demographics of the site's users (e.g. where they get connected from, return rate to the site rate data, information about the browser they use), which will help us optimize its content and functionality. | Statistical Analysis (Web Analytics) on the use and traffic of the Website |
Which cookies do we use in specific and how long do we retain your data at the website https://www.tiresias.gr?
1. Strictly Necessary Cookies# | Cookie | Type | Purpose | Duration | Provider | Categories of Recipients |
---|---|---|---|---|---|---|
1 | .AspNetCore.Antiforgery.0sTSlXCRvc0 | 1st party | This cookie is used for the purpose of security in order to prevent forgery. | Session | Tiresias S.A. | Tiresias S.A. |
2 | .AspNetCore.Mvc.CookieTempDataProvider | 1st party | With this cookie, information or error messages in the website are stored. It is used for effective running of the website. Your personal data are not processed through this cookie. | 365 days | Tiresias S.A. | Tiresias S.A. |
3 | OptanonAlertBoxClosed | 1st party | This cookie is set by websites using certain versions of the cookie law compliance solution from OneTrust. It is set after visitors have seen a cookie information notice and in some cases only when they actively close the notice down. It enables the website not to show the message more than once to a user. The cookie has a normal lifespan of one year and contains no personal information. | 364 days | Tiresias S.A. | Tiresias S.A. |
4 | OptanonConsent | 1st party | This cookie is set by the cookie compliance solution from OneTrust. It stores information about the categories of cookies the site uses and whether visitors have given or withdrawn consent for the use of each category. This enables site owners to prevent cookies in each category from being set in the users browser, when consent is not given. The cookie has a normal lifespan of one year, so that returning visitors to the site will have their preferences remembered. It contains no information that can identify the site visitor. | 364 days | Tiresias S.A. | Tiresias S.A. |
Your choice for "I have been informed about cookies" can be stored locally (browser / localstorage).
2. Statistical Analysis CookiesIf you choose and give us your consent, we will use the Google Analytics 4 service (provided by Google LLC) for the purpose of statistical analysis (web analytics) and in order to receive information about the use and traffic of our website, through monitoring and analyzing the behavior and interaction of site users.
# | Cookie | Type | Purpose | Duration | Provider | Categories of Recipients |
---|---|---|---|---|---|---|
1 | _ga | 1st party | This cookie name is associated with Google Universal Analytics - which is a significant update to Google's more commonly used analytics service. This cookie is used to distinguish unique users by assigning a randomly generated number as a client identifier. It is included in each page request in a site and used to calculate visitor, session and campaign data for the sites analytics reports. By default it is set to expire after 2 years, although this is customisable by website owners. | 729 days | Google LLC | Tiresias S.A Google subcontractors who provide support services for the Google Analytics service, e.g. customer support, technical support services, management of IT facilities. Detailed information on these subcontractors is available here and here (section "Access to data"). |
2 | _ga_xxxxxxxxxx | 1st party | Performance Cookies. | 729 ημέρες | Google LLC | Tiresias S.A Google subcontractors who provide support services for the Google Analytics service, e.g. customer support, technical support services, management of IT facilities. Detailed information on these subcontractors is available here and here (section "Access to data"). |
Type | Description | Purpose |
---|---|---|
Strictly Necessary Cookies | These are cookies, which are absolutely necessary for the smooth and secure operation of our Website, such as cookies for the storage of data necessary for “reading” visual content, for the processing of applications between a group of servers, the authentication of registered users as well as to enable the connection to our website or to provide the internet service requested by the user. | Security and operation of our Website |
Statistical Analysis Cookies (Google Analytics) | These are optional cookies, which if you select them and give us your consent, we will use the Google Analytics service (provided by Google LLC) for the purpose of statistical analysis (web analytics) and in order to receive information about the use and website traffic through monitoring and analyzing the behavior and interaction of site users. For example, we will be able to know how users reached our site (i.e. which links each user followed to get to the site), which pages οf the site were viewed by users, how much time they spent on each of them, etc. Google Analytics will provide us with reports that describe and analyze the traffic of the site and the demographics of the site's users (e.g. where they get connected from, return rate to the site rate data, information about the browser they use), which will help us optimize its content and functionality. | Statistical Analysis (Web Analytics) on the use and traffic of the Website |
Which cookies do we use in specific and how long do we retain your data at the website https://tsek.teiresias.gr?
1. Strictly Necessary Cookies# | Cookie | Type | Purpose | Duration | Provider | Categories of Recipients |
---|---|---|---|---|---|---|
1 | TRITES_SessionId | 1st party | It is used to uniquely identify the session while browsing the website and is essential for the seamless operation of the site. | session | Tiresias S.A. | Tiresias S.A. |
2 | TRITES___RequestVerificationToken | 1st party | For the safe and seamless operation of the site, the absolutely necessary cookie to authenticate users registered in the services is used | session | Tiresias S.A. | Tiresias S.A. |
3 | OptanonAlertBoxClosed | 1st party | This cookie is set by the cookie compliance solution from CookiePro. It is set after visitors have seen a cookie information notice and in some cases only when they actively close the notice down. It enables the website not to show the message more than once to a user. | 365 days | Tiresias S.A. | Tiresias S.A. |
4 | OptanonConsent | 1st party | This cookie is set by the cookie compliance solution from CookiePro | 365 days | Tiresias S.A. | Tiresias S.A. |
If you choose to give us your consent, we will use the Google Analytics 4 service (provided by Google LLC) for the purpose of statistical analysis (web analytics) and in order to receive information about the use and traffic of our website, through monitoring and analyzing the behavior and interaction of site users.
# | Cookie | Type | Purpose | Duration | Provider | Categories of Recipients |
---|---|---|---|---|---|---|
1 | _ga | 3rd party | This cookie is used in the context of the Google Analytics 4 service to distinguish users. | 2 years | Google LLC |
Tiresias S.A. Google subcontractors who provide support services for the Google Analytics service, e.g. customer support, technical support services, management of IT facilities. Detailed information on these subcontractors is available here and here (section "Access to data"). |
2 | _ga_xxxxxxxxxx | 3rd party | This cookie is used as part of the Google Analytics 4 service to maintain the user's session status. | 2 years | Google LLC |
Tiresias S.A. Google subcontractors who provide support services for the Google Analytics service, e.g. customer support, technical support services, management of IT facilities. Detailed information on these subcontractors is available here and here (section "Access to data"). |
Type | Description | Purpose |
---|---|---|
Strictly Necessary Cookies | These are cookies, which are absolutely necessary for the smooth and secure operation of our Website, such as cookies for the storage of data necessary for “reading” visual content, for the processing of applications between a group of servers, the authentication of registered users as well as to enable the connection to our website or to provide the internet service requested by the user. | Security and operation of our Website |
Which cookies do we use in specific and how long do we retain your data at the website https://auth.teiresias.gr?
Strictly Necessary Cookies# | Cookie | Type | Purpose | Duration | Provider | Categories of Recipients |
---|---|---|---|---|---|---|
1 | TeiresiasAuthServerSession | 1st party | It is used to uniquely identify the session while browsing the website and is essential for the seamless operation of the site. | session | Tiresias S.A. | Tiresias S.A. |
2 | TeiresiasAuthConsent | 1st party | It is used for the safe storage of the user's choice regarding the information of the use of the strictly necessary Cookies | session | Tiresias S.A. | Tiresias S.A. |
3 | TeiresiasAntiforgery | 1st party | It is used to prevent Cross-Site Request Forgery (CSRF) attacks on the login and password reset screen. | 30 minutes | Tiresias S.A. | Tiresias S.A. |
4 | TeiresiasIdentity | 1st party | It is created with the successful login of the user and constitutes his identity. It allows the user to reconnect, without requiring the entry of access data, until the end of its life. | Session or 14 days (if the user chooses to stay logged in) | Tiresias S.A. | Tiresias S.A.. |
What kind of data do we collect by our use of cookies?
By using strictly necessary cookies, we collect and process the following categories of data:
- End user device data (mobile phone, tablet, laptop).
- User’s identification data (in case of account).
- Users’ IP address.
- Information on users’ browser.
For the operation of the Google Analytics 4 service, it is necessary to install the cookies, of the above table, by Google, on the device of the user who visits our website, which entails the processing of personal data of that user by Google as data processor, and in particular:
- IP address,
- Demographic data and geographical location of the user,
- Technology of the user's device (e.g. iOS, Android, etc.),
- Type of user device (mobile, computer, tablet),
- Average duration of the session/the sessions and,
- How the user interacts with the site.
Internet Protocol (IP) addresses are retained for twenty-six (26) months while the aforementioned user attribute data is retained for two (2) years.
Tiresias will not transmit any further data to Google LLC for the purpose of correlating with other data collected from user accounts in other Google services in order to optimize its other services and products. For the purposes of providing Google Analytics service, such user data will be transmitted by Google LLC (as data processor) outside the European Union too, including among other countries the USA (whereby, under conditions, access to the data may be granted to US competent state/federal agencies). The transfer is secured and conducted upon the appropriate Standard Contractual Clauses. More details on the Google Subcontractors’ location can be found here. Please note that in the context of the operation of the Google Analytics service, we use, as a technical measure of data protection (privacy by design), the "_anonymizeIp ()" function of Google, in order to hide the Internet Protocol (IP) addresses of the site users, whose behavior is analyzed (more information can be read here). It is clarified that, even with the use of the "_anonymizeIp ()" function, the processed data in general are still considered personal data (i.e. they do not become completely anonymous). The maximum retention period of the user-level and event-level data, stored by Google Analytics and will be automatically deleted from Google Analytics servers, is 2 years. To provide the service, the basic aggregate report of Google Analytics is stored, which does not contain personal data.
Consent Provision and Management for the use of Cookies
By entering our Website, you will find a short notice in a pop-up window placed in a prominent position of our home-page, which informs you about the use of cookies by us and refers to this Cookie policy. In this notice you will find important information about the description and purposes of the different cookies categories. You will also be able to accept the use of all Cookies (Strictly Necessary Cookies and Statistical Analysis) or to reject the use of non-strictly necessary Cookies (Statistical Analysis Cookies). For the use of strictly necessary cookies the user's consent is not required and they are always activated. In addition, there is the option "Cookies Settings", where you can find more detailed information about the cookies we use and set your preferences regarding the use of cookies.
In particular:
- By selecting "ACCEPT ALL COOKIES" you acknowledge the use of strictly necessary cookies and provide your consent to the use of all of the above non-necessary cookies [including Google Analytics cookies].
- By selecting "ACCEPT ONLY ESSENTIAL COOKIES" you acknowledge the use of strictly necessary cookies and reject any other cookie category.
- By selecting "COOKIES SETTINGS" you can be informed in detail about the cookies we use and set (or change) your preferences regarding the use of statistical analysis (with the exception of the strictly necessary cookies, which are always enabled).
We use cookies for statistical purposes only under the condition of your prior, informed and explicit consent. The Cookies of this category are used to obtain statistics on the website traffic solely for the purpose of improving its performance and content, on the condition that the visitor /user has already consented. Your consent may be given through the relevant option in the pop-up window mentioned above and it can be withdrawn at any time, without retroactive effect, through the option ‘Cookies Settings’.
We also remind you that as data subjects you have the right to request and receive access, information, and request a copy of your personal data, which Tiresias collects and processes. We further inform you that, at any time, you may exercise your rights regarding the correction, deletion and portability of your personal data as well as restriction and opposition to its processing. Finally, you have the right to lodge a complaint with the Personal Data Protection Authority or another competent supervisory authority.
Contact Us
For any further information or request or for the exercise of your rights regarding this cookie policy you may contact us at the following address : dpo@tiresias.gr
To exercise your rights, the company's Customer Service Office operates on working days from 08:30 to 14:00 (Alamanas 1, 151 25 Marousi). On working days from 09:00 to 16:00 a call center operates on the telephone number 210 36 76 700. In addition, you can address a relevant request in writing to the above address of the Company or electronically to the e-mail address ‘tiresias@tiresias.gr’, while useful information for exercising the above rights is provided on the TIRESIAS’s websites «https://www.tiresias.gr», «https://tsek.teiresias.gr», «https://auth.teiresias.gr».
Last date of update: 28/11/2023
Data Controller
The company "Banking Information Systems S.A." with the distinctive title "Tiresias S.A." (hereinafter referred to as the Company), having its registered office in Maroussi, Attica, at 2, Alamanas Str., 151 25, tel. 210 36 76 700, e-mail cust_support@tiresias.gr processes personal data of its partners - suppliers - customers and website visitors.
This policy sets out the principles governing the collection, storage and use of your personal information by the Company when you visit, sign up or use the online TSEK platform (tsek.teiresias.gr).
tsek.teiresias.gr is the website of the Company's TSEK platform (Tiresias Risk Checking System), and the Company acts as Controller and owns the website.
When do we collect your personal data
- When you navigate the above website
- When you sign up as a user to our services (creating a user account) (A la carte Service)
- When you purchase a subscription package to access the TSEK file as well as when you access it.
- When you submit a contact form
- When you provide us with your consent to contact you for advertising and sales promotion/ marketing purposes
Categories of personal data we collect
A) When you visit and navigate our website, we collect your data using cookies. To learn about the type of data we collect using cookies and the lawfulness of such processing, please visit our Cookies Policy.
B) When you sign up as a user to the TSEK platform, a customer tab (user account) is created in which you enter, and then we store, the following information about you:
- Full Name or Company Name and Distinctive Title
- Country, Business Activity & Company Legal Form
- VAT No., General Electronic Commercial Registry (GEMI) No. & Tax Office
- full address of headquarters, invoice and mailing address (Address, Number, City, Zip code, company and accounting dept. telephone number),
- details of the Company’s legal representative (First Name, Last Name, Company e-mail) and the WebOfficer of the TSEK platform service, if other than the legal representative. (First Name, Last Name, ID card no., business telephone and mobile phone number, e-mail/ password and possibly job title).
C) When you purchase a subscription package (access to the TSEK file), or purchase individual services (A la carte Service) and when we provide services to you, we collect data concerning transactions between us (purchases, invoice data, payment information, dues) as well as data regarding communication between us in the context of the provision of such service (customer service, subscription package change requests, troubleshooting requests), as well as data concerning your access to the TSEK file.
D) During the process of first activation of the user account, it is mandatory to declare a mobile phone number at your possession that we will use it to send you an One-time code via SMS in order to identify you as a user (it is not obligatory to provide your personal mobile phone number). The mobile phone number is stored for future multiple identification process by sending an One-time code, when retrieving / changing the user's password. However, in the above cases, the user has the option to use his email address instead of his mobile phone number.
E) When you submit a contact request using the contact form of the TSEK platform, you enter, and consequently we store until the end of such communication, your following data: Full Name, E-mail, Telephone, Company
F) In order to contact you by telephone, sms, viber, e-mail, social media for advertising and marketing purposes (sending newsletters/information material about our news and services, promotional activities, questionnaires), we collect your e-mail address and/or your mobile phone number as appropriate in each case- unless you have initially objected to contacting you. If you are a visitor to the TSEK platform, we will ask for your explicit consent before contacting you for advertising and marketing purposes.
Purpose of processing your personal data
We collect your Data as above specifically for:
A) acceptance of the connection terms and/or conclusion and performance of the service agreement between us and/or the TSEK file data agreement (access to the TSEK file, provision of services to you via the TSEK platform, communication and provision of information to you regarding the platform and services provided, payment and management of your dues to the company, renewal, extension or any cancellation of a purchase, etc.),
B) identifying the users via a method of strong authentication in order to access our services effortlessly, swiftly, remotely and securely.
C) our compliance with the obligations imposed by the legislation in force each time, e.g. issuance of legal tax documents,
D) the protection of the company’s legitimate interests (safeguarding legitimate claims),
E) Contacting you for advertising and marketing purposes related to the TSEK platform and including market & customer satisfaction surveys, information and promotional material for the company's products and services, as well as newsletters.
Legal bases of processing
Your data will be processed under the following legal bases:
1) by virtue of the agreement for the provision of TSEK file data and/or the acceptance of the connection terms when you sign up to the TSEK platform and/or other services (conclusion, performance, termination) to which you are a party [for data categories under B,C, D and F];
2) by virtue of the company's legal obligations (tax legislation) [for data categories under B and C];
3) by virtue of the provisions of the e-privacy legislation (art. 11 par. 3 of Law 3471/2006) [regarding the conduct of market & customer satisfaction surveys under E and F]; and
4) by virtue of your prior consent [for other data categories under A, E and F], except if you are already a customer of ours and you had not initially expressed your disagreement. In any case, you can state that you wish us to stop contacting you and/or that you wish to stop receiving communications from Tiresias (TSEK Platform) and generally communications for marketing purposes, using the unsubscribe option in any message you receive or the relevant option in your TSEK platform profile.
Data collected using cookies are necessary for the provision of our services. Please visit our Cookies Policy for more information.
Who we share your personal data with – where it is stored
Recipients of the Data include staff of the Company with a need to know, which is bound by confidentiality agreements, and our partner companies that process your Data as Processors on our behalf and per our instructions, such as advertising companies, public relations companies, automated e-mail distribution companies, market research companies, etc. We may share or disclose your Data when you have explicitly requested it or when required by law.
We do not send your Data outside the European Union. Your Personal Data are only stored and processed within the European Union.
Processing principles and protection measures
Our Company, inter alia:
- processes only your personal data that is necessary for the above purposes and only for those purposes;
- takes appropriate technical and organizational measures for the security of personal data (ensuring confidentiality, integrity and availability) by design and by default;
- has and applies procedures and systems to ensure the confidentiality of personal data processing, as well as its protection against accidental or unlawful destruction, accidental loss, alteration, unauthorised dissemination or access and any other form of unlawful processing (e.g. use of tools for access controls and data loss prevention);
- has informed the data subjects (citizens and employees), in accordance with Regulation (EU) 2016/679 (GDPR);
- complies with the principle of personal data minimization;
- ensures that data subjects’ rights are exercised and fulfilled;
- has prepared documents, policies and procedures demonstrating its compliance in accordance with the principle of accountability (privacy policy, cookies policy, recording the type, categories and flows of personal data, compilation of processing records, impact assessment, etc.) as referred to in the GDPR;
- has appointed a Data Protection Officer and set up a personal data protection team;
- provides training and awareness-raising to employees regarding personal data protection;
- has amended its partnership agreements with data processors, in accordance with the provisions of Article 28 GDPR for the purpose of full compliance of the latter ones.
For how long we keep your personal information
We delete your Personal Data (personal data that you have entered in your user account, as well as any additional data we process for the conclusion and performance of the agreement between us), in accordance with the following:
- regarding our approved clients: 20 years from expiry of the agreement;
- regarding the history of the Alarm service: 5 years from expiry of the subscription;
- regarding Alarm files sent to us: 5 years from expiry of the subscription.
Our updates regarding the processing of your clients' personal data when accessing the TSEK file are kept by you, as data processor, for 5 years from expiry of your agreement with said client.
In relation to communication for marketing purposes (newsletters and promotional material, market or customer satisfaction surveys, etc. via email, SMS, Viber, social media and telephone communication), we delete your email and/or your mobile phone from our list of recipients as soon as you state your disagreement, by selecting the relevant link that appears in each e-communication for service promotion sent to you, or using the relevant option in your TSEK profile, or following a communication with a representative of the TSEK team or in any other appropriate way (with the contact form, via email, etc.).
Data collected via Cookies is deleted in accordance with our Cookies Policy.
Is your Data safe?
We are committed to safeguarding your Personal Data. We have taken appropriate organizational and technical measures to secure and protect your Data from any form of accidental or unlawful processing.
We use an Electronic Security Certificate (SSL - Secure Socket Layer) to ensure the secure data exchange between the website and your browser.
The TSEK platform has been designed to provide a high level of security. In summary, the security measures applied to the functioning of the TSEK service are summarized below:
1. Use of Secure Network Infrastructure
The TSEK platform is protected by the most advanced network security infrastructure designed to detect and prevent malicious attacks as well as to fully control incoming and outgoing data.
2. Encrypted Data Transfer
For data transfers from the Tiresias S.A. systems to users we apply appropriate protocols so such data and the whole communication in general remains encrypted until received by the user. Thus, the service is offered through a secure connection (https://tsek.teiresias.gr in the Browser).
3. Keeping a Data File
The TSEK file is a file of Tiresias S.A. kept separately form the Default File and the Mortgages and Prenotations File. These two systems are interconnected exclusively within the internal network of Tiresias S.A. using specialized protocols, without intervention of any external communication line or third party provider.
4. Controlled Access
Access to the platform’s services is granted only after review and validation of the legalisation documents required by Tiresias S.A. Users can only access the platform by entering their Username & Password. Tiresias S.A. will never ask you for your password. Only you know the credentials you have entered and the answers to the security questions, and only you can change your password.
5. Security Policies
Tiresias S.A. adheres to very strict security procedures and policies, which are part of the ISO 9001:2015 quality assurance standard, according to which the company has been certified; compliance with the standard is constantly monitored both internally and via regular external audits.
6. Secure Payments
Payments are made automatically and transparently, either by credit card, or by wire transfer using DIAS Credit Transfer (DCT) or IRIS Online Payments. Tiresias S.A. does not in any way keep a record of credit or debit cards used to purchase subscription packages or individual services (A la carte Service).
The above measures are reviewed and amended when deemed necessary.
What are your rights and how can you exercise them?
You have the following rights:
a) To know what personal data we keep and process, their origin, the purposes of processing, as well as the retention period (right of access).
b) To request that your personal data is rectified and/or completed so that it is complete and accurate (right of rectification). You should provide any required document evidencing the need for rectification or completion.
c) To request the restriction of processing of your data (right to restriction of processing).
d) To refuse and/or object to any further processing of your personal data that we keep (right to object) or withdraw your consent at any time if the processing is based on such consent (withdrawal of consent).
e) To request that we transfer your personal data that we keep to any other controller of your choice (right to data portability).
f) To request the erasure of your personal data from the records we keep (right to be forgotten).
In relation exercising your above rights, note the following:
- The Company has in any case the right to refuse to meet your request for restriction of processing or erasure of your personal data or your objection to processing, if the processing or retention of the data is necessary for the establishment, exercise or support of its legal rights or the fulfilment of its obligations.
- The exercise of the right to portability does not imply the erasure of your data from our files, which is subject to the terms of the preceding paragraph and the conditions of the Regulation.
- Exercising the above rights applies to the future and does not affect data processing that has already taken place.
g) To lodge a complaint to the Hellenic Data Protection Authority (www.dpa.gr), if you feel that your rights are infringed in any way (right to lodge a complaint with the Authority).
To exercise the above rights, you may send a letter to the Company's address (2, Alamanas str., Maroussi 151 25), or an e-mail to the e-mail address cust_support@teiresias.gr or via the Company's website www.tiresias.gr or the website tsek.teiresias.gr,indicating "Exercise of the right of access/ rectification/ erasure/ restriction/ objection", or call 210 3676700, and in any case you may also contact the Company's Data Protection Officer at dpo@tiresias.gr.
When do we respond to your Requests?
We respond to your Requests free of charge as soon as possible, and in any case not later than one (1) month of receiving your request. However, if your Request is complex or there are many pending Requests, we will inform you within the one-month deadline if we need an extension of another two (2) months to respond.
If your Requests are manifestly unfounded or excessive, in particular due to their repetitive nature, the company may charge a reasonable fee, considering the administrative costs for providing the information or performing the requested action, or refuse to follow up on the Request.
Do we use automated decision making/ including profiling when processing your Data?
We do not make decisions or make profiling based on automated processing of your Data.
What is the applicable law when we process your Data?
We process your Data in accordance with the General Data Protection Regulation 2016/679/EU, and in general the applicable national and European legislative and regulatory framework on the protection of personal data (Law 4624/2019, Law 3471/2006).
Data Protection Officer (DPO)
The Company has appointed a Data Protection Officer in accordance with art. 37 of the General Data Protection Regulation (Tel. 210 36 76 700, dpo@tiresias.gr, 2, Alamanas Str., 151 25 Maroussi, Athens, Greece).
Last date of update: 09/2021
Controller
The company under the corporate name "Banking Information Systems SA" and the distinctive title "TIRESIAS SA" (hereinafter the Company), which has its registered office in Maroussi, Attica, 2, Alamanas Street, 151 25, P.C. 210 63.82.200 processes its partners’ - suppliers’ - customers’ personal data.
This policy sets out the principles applied by the Company during the processing of the aforementioned data (categories, legal basis, purpose, protection measures, rights, etc.) and aims to inform the data subjects about the processing. It is posted on our Company websites (http://www.tiresias.gr/PersonalDataProcessing.html & https://tsek.teiresias.gr/el/Home/PrivacyPolicy and when necessary it is modified or updated.
We assure you that all information we collect about you is confidential, used only for the legitimate purposes and protected by high level security systems.
When we collect your personal data?
- During your participation in procurement procedures conducted by our Company.
- When signing a contract with our Company and during its life cycle and its execution, when the contractual terms change and at the end of the contract.
- When you contact us in writing on a contract related matter (in writing or electronically) or to submit an application.
- During your presence at the Company's premises that are monitored by CCTV camera surveillance system.
What categories of personal data do we collect?
We process the following categories of personal data (in whole or in part, depending on the type of cooperation / contract and the physical presence or not of data at our Company's premises) of our partners-suppliers-customers:
- in the case of single-membered companies / traders: Basic identification data (name, father's name, address, telephone numbers, e-mail addresses, VAT number, Tax Office, ID number), distinctive title / type of business, registered office address, bank accounts,
- basic identification data of legal representatives, representatives, project managers, board members, etc. (name, father's name, address, telephone numbers, e-mail addresses), tax and social security clearance),
- financial data (e.g. payments, invoices, etc.),
- your image as well as your movement to the extent that you move in areas of the Company where video recording (CCTV) takes place in accordance with the relevant procedure for reasons of protection of persons and goods (http://www.tiresias.gr/docs/NotificationAboutPersonalDataProcessingThroughACCTV.pdf).
- When you enter the premises of our offices and for the purpose of protecting people and goods, incoming data is recorded in a relevant book kept by the private security company.
Measures to prevent the spread of the pandemic due to Covid 19 and protect employees
In the context of prevention and protection, every incoming person undergoes a temperature measurement (http://www.tiresias.gr/docs/NotificationAboutBodyTemperatureMeasurement.pdf, while at the same time there is a case-by-case obligation to conduct a self-test, in accordance with the relevant procedure of the Company.
Purposes for which we process your personal data
We process your personal data for the purpose of participating in procurement procedures, the preparation, execution, operation and termination of the contract between us and in general the management of the business relationship between us (contracts, invoices, payments, etc.), but also for Company’s compliance with its legal obligations and for establishment of our legal claims or defence against claims brought before the Courts, Authorities etc. Personal data relating to your image and movement to the extent that you move to the Company's premises where video recording takes place for reasons of protection of persons and goods, is collected to protect persons and goods of the Company.
Legal Grounds for Processing Data
Legal grounds for processing data are, depending on the case: (a) The legitimate interest we pursue (the operation of our company as well as the protection of persons and goods in relation to the CCTV surveillance system) (b) Our compliance with obligations arising from the law, (c) The execution (drafting, operation, termination) of the contract between us), (d) your consent.
To whom we disclose your personal data and where data is stored
The Company does not disclose your personal data to third parties but is processed only by the Company’s authorized staff under strict confidentiality. Exceptionally, your personal data may be shared:
(a) with Public authorities for the purposes of the Company's compliance with its legal obligations,
(b) with third parties who provide services to the Company, such as human resources companies, lawyers/law firms (in case of extrajudicial or judicial actions regarding legal claims of the Company or against it). These persons, who act as processors on behalf of our Company, are bound by the applicable legislation (European and National) on personal data, and
(c) before the courts for the exercise and defence of the Company's rights. Your data is kept within Greece under conditions of organizational and technical security measures.
Principles of processing and protection measures
Our Company, indicatively and not restrictively:
- processes only your personal data that is necessary for the above purposes and only for these purposes,
- implements appropriate technical and organizational measures for the security of personal data (ensuring confidentiality, integrity and availability) by design and by default,
- implements procedures and systems for the confidentiality of the processing of personal data, as well as for their protection from accidental or unlawful destruction, accidental loss, alteration, prohibited dissemination or access and any other form of unlawful processing (e.g. use of tools for access controls and data loss prevention),
- informs the data subjects (citizens and employees), in accordance with the Regulation (EU) 2016/679 (GDPR),
- respects the principle of personal data minimisation,
- ensures the exercise and satisfaction of the rights of the subjects,
- has drawn up documents, policies and procedures that prove its compliance with the principle of accountability (privacy policy, cookies policy, recording of the type, categories and flows of personal data, compilation of processing records, impact assessment, etc.) as they are mentioned in the GDPR;
- has appointed a Data Protection Officer and set up a group for the protection of personal data;
- educates and raises awareness among its employees regarding the protection of personal data;
- amends its cooperation agreements with processors on its behalf, in accordance with Article 28 of the GDPR, ensuring that processors are fully GDPR compliant as well.
How long we keep your personal data
We keep your personal data in line with the requirements set by law for a period during which Tax Authorities, National Social Security Fund and other Authorities, have the right to audit our Company. If there is no shorter period of time set by law, the above data is kept for twenty (20) years, i.e. equal to the general limitation period. In the event that there is a relevant pending trial, we will keep your data for five (5) years from the issuance of an irrevocable court decision. Insurance and tax clearance certificates are destroyed one (1) year after their receipt, unless they are incorporated in tax documents, in which case they are destroyed along with them.
When the processing of your personal data is no longer necessary, your data will be destroyed in a secure and proven manner. Video surveillance data is stored for a period of 14 days.
Is your Data safe?
We are committed to safeguarding your Personal Data. We have taken appropriate organizational and technical measures for the security and protection of your Data from any form of accidental or unlawful processing.
Tiresias S.A. follows strict procedures and safety policies, which are part of the ISO 9001:2015 quality assurance standard, according to which the company has been certified, while its compliance is constantly regularly both by internal and by external inspections.
Those measures shall be reviewed and amended when necessary.
What are your rights? How to you exercise them?
You have the following rights:
- Be informed when we collect and process your personal data, data sources, the purposes of processing it, its retention period and request a copy of any personal data we hold that concerns you (right of access).
- Request the correction and/or completion of your personal data in order to be complete and accurate (right of rectification). You should provide us with any necessary document substantiating the need to rectify the inaccurate or incomplete data.
- Request the restriction of processing your personal data (right to restrict processing).
- Refuse and/or object to the processing of your personal data that we keep (right to object).
- Request the transfer of your personal data that we keep to any other controller of your choice in a safe and secure way, without affecting its usability (right to data portability).
-
Request the deletion of your personal data from the files we keep for example when your data is no longer necessary or unlawfully processed or no longer meets one of the abovementioned lawful grounds (right to be forgotten).
With regards to the exercise of your above rights, please note that:
- The Company has in any case the right to refuse the satisfaction of your request to limit the processing or erasure of your personal data or your objection to the processing, if the processing or retention of the data is necessary for the establishment, exercise or defence of its legal rights or the fulfilment of its obligations.
- The exercise of the right to portability does not imply the deletion of your data from our records, which is subject to the terms of the immediately preceding paragraph and the conditions of the Rules of Procedure.
- The results from the exercise of these rights have effect for the future and does not concern data processing already carried out.
- Lodge a complaint with the Hellenic Data Protection Authority www.dpa.gr if you consider that your rights are being violated in any way (right to complain to the Authority).
For the exercise of the above rights you may address in writing to the Company's address (Alamanas 2 Maroussi 151 25), or electronically to the e-mail address apanopoul@tiresias.gr or by phone at 210 63 82 252, and in any case you can also contact the Company's Data Protection Officer at dpo@tiresias.gr address.
When do we respond to your Requests?
We respond to your Requests free of charge without any delay, and in any case within one (1) month from the time we receive your request. However, if your Request is complex or there is a large number of your Requests, we will inform you within the month if we need to receive an extension of another two (2) months within which we will respond to you.
If your Requests are manifestly unfounded or excessive, in particular due to their repetitive nature, the company may impose a reasonable fee, taking into account the administrative costs for the provision of the information or the execution of the requested action, or refuse to act on the Request.
Who can you contact for the progress of your Requests?
For more information you can call during working days and hours at +302103676700 (Customer Service Phone Line).
Do we make use of automated decision-making, including profiling when processing your Data?
We do not make decisions or profiling based on automated processing of your Data.
What is the applicable law we processing your Data?
We process your Data in accordance with the General Regulation on the Protection of Personal Data 2016/679/EU, and in general, with the applicable national and European legislative and regulatory framework for the protection of personal data (Law 4624/2019, Law 3471/2006).
Data Protection Officer (DPO)
The Company has appointed a Data Protection Officer in accordance with Art. 37 of the General Data Protection Regulation (tel. +30 210 36.76.700, dpo@tiresias.gr, Alamanas 2 151-25 Amarousion)
Right of Access and Objection
In accordance with Article 12 of L. 2472/97 any individual can have access to Tiresias's Database in order to be informed of any kind of personal data stored in the system. Legal persons enjoy the same access right as well.
Also any entity (individual or legal person) who does not wish its data (stored in the Default Financial Obligations System (DFO) & Mortgages and Prenotations to Mortgages System (MPS)) to appear, can submit an application to Tiresias. After the request has been fulfilled the indication “does not wish the transmission of its data” is displayed. This information is evaluated at will, taking into account all possible consequences. Exceptionally, company data from the Government Gazette and the General Electronic Commercial Registry will still be transmitted. Revocation of this request can be submitted at any time, exclusively to Tiresias.