TÜV ΗELLAS (TÜV NORD) SECURITY AND PERSONAL DATA PROTECTION POLICY
TÜV Hellas (TÜV NORD) S.A., as a distinguished and international certification and training body, attaches great importance to the lawful processing, security and protection of your personal data, regardless of the capacity in which you collaborate with or communicate with us (such as, for example, as prospective or existing customers, partners, Trainees, Suppliers, Employees, Private Individuals, website visitors or, more generally, third parties working with our Organisation).
Please read these terms and our Company’s relevant Security and Personal Data Protection Policy carefully. By using our websites and signing the relevant consent form, you unreservedly accept the practices described herein, the terms of which shall henceforth govern our contractual relationship and are incorporated into the terms of use of each of our services.
1. What is your personal data?
Your personal data includes any information, whether on paper or in electronic form, which may lead, either directly or in combination with other data, to your unique identification / or to your identification or location as a natural person. This category includes, where applicable, details such as your full name, tax identification number, National Social Security Number (AMKA), identity card number (ADT), your physical and email addresses, your landline and mobile telephone numbers, details of recipients of SMS/MMS messages, details of your bank cards, debit cards and prepaid cards, identification details of your equipment or devices – computer, smartphone, tablet – your web browsing history (log files, cookies, etc.), and any other information that enables your unique identification in accordance with the provisions of the General Data Protection Regulation (GDPR 2016/679), the applicable Greek legislation at any given time and the decisions of the Hellenic Data Protection Authority (HDPA).
2. What personal data do we collect from you
For example, we process and protect your personal data within the framework of lawful activities and in accordance with the relevant legislative and regulatory framework for Certification Bodies / Training, the collection of data from Certifications / Inspections / Audits / Training, as part of marketing activities, and in the context of communication / support / information provision to you, as well as in connection with any other activity of our Company.
3. Processing with your explicit consent
Our Company will use your information for the following lawful processing purposes, within the framework of our Contract or provided you have given us your explicit and specific consent, on a service-by-service basis (which you are free to withdraw at any time), namely:
§ To manage your data and details in connection with our Certification / Inspection / Auditing / Training services.
§ To provide you with support and information regarding our Company’s services and projects; to respond to your requests and enquiries; and to acknowledge and respond to your suggestions and comments regarding improvements to our services.
§ For the purposes of ‘internal’ quality assurance of our services.
§ To analyse website traffic and improve your experience, and to provide you with information relating to services, training programmes, general and technical updates, etc.
§ For internal operations and analysis, such as internal management, fraud prevention, and use by management information systems, invoicing, accounting, billing and auditing systems.
In any case, you can change your preferences at any time by using the unsubscribe link at the bottom of every email you receive from us.
4. What are the principles governing collection and processing?
The purpose of this Privacy Policy is to inform you of the terms governing the collection, processing and transfer of your personal data that we may collect in our capacity as Data Controllers or Data Processors.
Our Company and its trained staff apply the ten Principles of Processing set out in the GDPR 2016/679 (lawfulness, objectivity, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability).
Our Company protects and safeguards your eight rights regarding the use of your Personal Data (right to be informed, access, rectification, erasure, restriction of processing, data portability, objection and non-automated decision-making based on profiling, as specified in the GDPR and Greek legislation). The above applies without any discrimination and applies to all processing carried out and all services provided by our Company.
5. How we collect your personal data
Our Company collects your personal data with your consent and upon your acceptance of the terms of use for each of our services, such as:
§ when you call our numbers, send us an email or complete a form requesting information, a service quote or enrolment in a training programme
§ in the context of carrying out inspections, audits, certifications or training courses
§ when you provide us with a postal address for the issue or dispatch of an invoice or service receipt, as well as delivery details for a document (e.g. a certificate)
§ when you voluntarily register with printed or electronic directories in order to receive printed, electronically or via SMS, or other marketing material, or when you update these preferences
§ when you visit our websites, through which we collect, via cookies, the necessary information from your device and your browser.
6. Minimisation, storage and deletion of your data
Our Company will always request only the minimum personal data required by law to provide our Services and to serve you as best as possible.
Our Company retains your personal data only for as long as required by the contractual terms of each service, in conjunction with the legislation in force for Certification Bodies / Training Bodies, as well as the broader telecommunications, tax and other legislation and regulatory framework, based on the specific purpose of processing, after which it anonymises or destroys the data. You may contact us to find out what data we hold about you and to correct or delete it, unless their retention is required by law for tax, evidential or judicial purposes, or for the prosecution of unlawful acts.
7. Cookies Policy
In accordance with the relevant European E-Privacy Directive 2009/136/EC (which will soon be replaced by a Regulation), our website (www.tuv-nord.com/gr) uses “cookies”. Cookies are online ‘tools’ for collecting and analysing information from partner third-party websites or social media platforms, in order to measure traffic, improve the functionality, content and overall appearance of our website, and tailor it to the needs of our customers.
By using our website, you consent (opt-in) to the processing of your personal data collected by search engines or social networks, such as Google Analytics, Facebook social plug-ins, Google+, etc. (over which our Company has no involvement, influence or control on the part of our Company) and which are transferred either within or outside the European Economic Area (28 EU Member States plus Iceland, Liechtenstein and Norway), for which those third parties are solely responsible.
If you do not wish third parties, such as Google, Facebook, Twitter, etc., to receive information from your browser, when you visit the Company’s websites, you may opt out by selecting the relevant option as provided in the respective Terms of Use available on each such third party’s website.
Although most web browsers automatically accept the use of cookies, you can always change the settings on your computer to choose not to accept cookies, or to be asked to accept each one individually. However, you should be aware that doing so will limit the range of browsing options available to you on each website.
8. Transfer of your data to third parties
As a general rule, our Company does not transfer your personal data to third parties unless clearly required to do so by legislation / regulatory framework, or when we act as ‘intermediaries’ and to the extent that this is necessary to fulfil one of our services and to respond to requests relating to the services we provide.
Such third parties may include official supervisory or government bodies (e.g. ESYD, APDPCH, etc.) and/or the TÜV NORD Group, when we are required to comply with legislation or regulations governing certification bodies and/or Training Bodies and/or to prevent unlawful acts (e.g. fraud, abuse, defamation, etc.) to our detriment and that of our Clients.
At the Company, we select reliable partners and endeavour to impose contractual restrictions on third parties who may receive your personal data, so as to ensure, as far as possible, that they use it in accordance with this Policy and the data protection laws in force in Europe and internationally.
In order to process your data, we may need to transfer your information to other countries, including countries generally within and, in exceptional cases, outside the European Economic Area (EEA) on the basis of EU adequacy decisions, corporate binding rules, standard contractual clauses and approved codes of conduct.
9. Security of your personal data
In all cases, we take appropriate technical and organisational measures to ensure that your personal information is transferred, stored and processed, in accordance with appropriate security standards and procedures, and in accordance with the terms of this Policy and the applicable data protection laws in force at any given time.
At the Company, we have trained and responsible staff and a Data Protection Officer (Data Protection Officer, DPO), and we recognise the importance of protecting your privacy and all your personal information. To this end, we have appropriate security policies in place and use the appropriate technical and organisational measures, such as anonymisation, pseudonymisation, data encryption, the use of firewalls, the establishment of access levels, authorised staff, staff training and periodic audits), as well as compliance with international security and business continuity standards.
Any of our partners who have access to the above information use it solely for the purposes set out above. We share the information you provide to us exclusively in the ways described in this Policy and in accordance with your explicit and specific consent for each type of processing, which you may freelyby contacting us.
10. Display of targeted adverts
We may use your personal data together with other information we have collected (basic contact details such as Name / Company / Telephone / Address / email), following manual intervention by our Sales Department or other members of our management team, in order to provide you with better information / information, relevant marketing campaigns (emails, newsletters, etc.).
However, we do not use automated tools to identify and analyse your consumer profile and general preferences using other personal information (such as your email address) to display adverts or send you personalised offers. Furthermore, we do not share your personal data with third parties so that they can send you relevant adverts, unless you have explicitly consented to this.
If you would like us to stop sending you updates or offers, you can use the unsubscribe link at the bottom of the email you received from us.
11. Links to third-party websites
Our Company’s websites may contain links to other websites operated by third parties, such as, for example, companies providing consultancy or similar services, which are operated and maintained exclusively by them, and over which we have no control, as mentioned above. Consequently, we accept no liability whatsoever for the content, actions or policies of these websites. Please read the relevant data protection policies on the various websites you visit carefully, as they may differ significantly from our own.
12. Unsolicited commercial communications
Our Company does not permit the use of our website or our services for the transmission of bulk or unsolicited commercial emails (spam). Furthermore, we do not permit the sending of messages to or from our Customers that use or contain invalid or forged headers, invalid or non-existent domain names, techniques to conceal the origin of any message, false or misleading information, or which breach the terms of use of websites.
We do not, under any circumstances, permit the collection of email addresses or general information about our customers and subscribers via our website or our services. We do not permit or authorise any attempt to use our services in a way that could harm, disable or overload any part of our services, or prevent anyone from using our services.
If we believe that any of our services are being used in an unauthorised or inappropriate manner, we may, without notice and at our sole discretion, take appropriate measures to block messages from a specific domain, an email server, or an IP address. We reserve the right to immediately terminate any account using our services which, at our sole discretion, transmits or is associated with the transmission of any messages that breach this policy.
13. Contact details and address of the TÜV NORD Greece DPO
If you have any questions or comments regarding this security and personal data protection policy, or if you believe that we have not adhered to the principles set out herein, please email us at tuvhellasdpo@tuv-nord.com.
[DPO at TÜV NORD Hellas]: Mr Michalis Alexiou (IT Systems Engineer)
[Address] 282 Mesogeion Avenue, Cholargos 155 62
[Telephone] +30 215 215 7449
[Email] malexiou@tuv-nord.com
14. Validity of the Security and Personal Data Protection Policy
This Policy was published by our Company on 25 May 2018 and is subject to periodic improvement and revision.
Any changes to this Policy will apply to information collected from the date the revised version is published, as well as to existing information held by us. By continuing to use the website after changes have been published, you are deemed to have accepted those changes.
1 September 2023
Savvas Peltekis Vasiliki Kazazi