ΕΓΓΕΓΡΑΜΜΕΝΑ ΜΕΛΗ 2023-2024
.
ΕΓΓΕΓΡΑΜΜΕΝΟΙ ΦΙΛΑΘΛΟΙ 2023-2024
.

Πολιτική απορρήτου

 

PRIVACY POLICY

 

Privacy Notice

 

"OLYMPIACOS SFP" – [Olympic Club of Fans of Piraeus] takes due account of its members’ right to privacy and goes to great lengths to ensure that they consistently abide by the applicable national and European legal and regulatory framework concerning the protection of personal data.

 

1.           Scope

 

This Privacy Notice describes our procedures regarding the processing of personal data,  such as collection, registration, organization, structure, storage, adaptation or alteration, retrieval, search, use, disclosure by transmission, dissemination or any other form of making available, association or combination, restriction, deletion or destruction of your personal data.

 

"OLYMPIACOS SFP" reserves the right to amend and/or update this Privacy Notice at its discretion and at any time. Any changes shall take effect upon their notification to you, either by e-mail or by posting them on the Internet or by any other means the Club deems appropriate.

 

In the event that the terms of your cooperation with "OLYMPIACOS SFP" are defined by more specific terms regarding the protection of personal data, these terms shall apply in conjunction with the present ones. In case of conflict, the special terms of use that apply to each service shall prevail.

 

 

 

2.           Personal Data collected

 

Upon registering with the CLUB, the following information may be collected about you:

 

·                      Name

 

·                      Age

 

·                      Contact information

 

·                      Other identification details (ID card №)

 

Please note that some of the information mentioned above is necessary for the fulfilment of our contractual obligations towards you, while other information is required in order to meet our legal obligations. For example, your social security number is required by law. Other information may be required in order for the smooth operation of the contractual relationship and/or the legitimate interests of "OLYMPIACOS SFP". Should you refuse to provide us with the personal data needed to fulfil our contractual obligations or ensure the smooth operation of our cooperation, it may be difficult or impossible for us to do so, depending on the nature of personal data involved and the legal basis upon which we rely for processing it.

 

3.           Data collection sources

 

Your personal data is mainly collected:

 

From you

 

In order to register you or to carry out its contractual obligations to you and/or to third parties, "OLYMPIACOS SFP" needs to be aware of specific information about you under the terms of our contract. Such information may be provided in a variety of ways, such as:

 

·                      By filling out various corporate forms

 

·                      By telephone

 

·                      Through documents sent to the Club

 

·                      Via electronic communications (email, website)

 

4.           Purposes of processing

 

"OLYMPIACOS SFP" collects and processes your personal data listed above for the following purposes:

 

·       fulfilling its contractual obligations and ensuring that the operation of the contractual relationship runs smoothly

 

·       tax purposes, invoicing and proof of services rendered.

 

"OLYMPIACOS SFP" collects and uses the personal information of its members solely for the aforementioned purposes and only to the extent absolutely necessary to carry out those purposes.

 

5.           Legal basis

 

There are several ways in which "OLYMPIACOS SFP" legally processes your personal data and each processing action performed by the Club is in accordance with at least one of the following legal bases.

 

Processing is necessary if "OLYMPIACOS SFP" is to fulfill its contractual obligations.

 

The legal basis on which the Club lawfully processes the data of its associates is Article 6, §1(b) of GDPR, which provides that "OLYMPIACOS SFP" may process data if "processing is necessary for the performance of a contract to which the data subject is party". This allows "OLYMPIACOS SFP" to process data in order to be able to fulfill its contractual obligations towards you and monitor the fulfilment of the contractual obligations of its associates.

 

Apart from its contractual obligations, the Club has also to comply with several obligations stemming from the current legislative framework. According to Article 6, §1 (c) of GDPR, the Club may process personal data when processing “is necessary for compliance with a legal obligation”.

 

Processing is necessary for the purposes of the legitimate interests pursued by the Club, in accordance with the provisions of Article 6, §1 (f) of GDPR. The Club may process personal data when such processing “is necessary for the purposes of the legitimate interests pursued by the Club, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data”.

 

Personal Data Processing is based on your consent

 

In extremely rare instances, we may ask for your express opt-in consent before we carry out certain processing of your data. For example, we might ask for your permission before sending you any informational or promotional material or before sharing your personal data in corporate publications or other media for purposes of promotion.

 

6.           Subscriptions for fans & members

 

The subscription holder accepts the following terms for the financial support of "OLYMPIACOS SFP":

 

·       Payment for Member Cards, Junior Cards, and Fan Cards can be made in cash or by debit/credit card at the Members & Fans Department, as well as online at http://www.olympiacossfp.gr.

 

·       If a member/junior/fan ID number has been assigned, the financial support fee shall be non-refundable.

 

·       If the online transaction through the website was successful but the holder did not receive a member/junior/ fan ID number, he/she may contact the competent department at 211-1007060 or via email at members@osfp.gr so that a check be carried out and a member/junior/fan ID number be assigned. Only in such case, the member/fan may request a refund by emailing proof of payment to members@osfp.gr. The requested amount of financial support shall then be transferred to the member's personal account/ IBAN.

 

·       The sports club is not permitted to cancel or contest an electronic transaction made through the affiliated financial institution where financial support payments are made.

 

7.           Time of personal data retention

 

Personal data shall be retained by the Club in accordance with the applicable provisions of the law and only for the time required to fulfill the purposes laid out in sections 4 & 5, or for as long as required by law or to defend the Club against possible judicial actions to pursue claim.

 

8.           Data Security

 

The procedure of personal data processing by the Club shall be carried out in a way that ensures its confidentiality. More specifically, data is processed exclusively by specially authorized personnel of the Club, while all appropriate technical and organizational measures shall be applied to ensure the appropriate level of security of your data against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access or any unauthorised form of processing.

 

9.           Disclosure/ Transmission to Third Parties

 

The Club shall not share or transfer its members' personal data in any way, nor will it interlink its files for financial or other consideration with any third-party private companies, natural or legal persons, public authorities or services, or other organizations.

 

The Club may provide access or disclose/transfer the personal data of its associates to:

 

Third-party service providers performing various tasks or actions on behalf of the Club, as well as external consultants, associates, lawyers, accountants, auditors, technical and support service providers, and IT consultants.

 

Financial institutions: We may share information with financial organizations/institutions where you have a bank account in order to process payments.

 

Processing of your personal data by our above-mentioned affiliates (data processors) shall be carried out under our supervision and only pursuant to our instructions, and shall be subject to the same privacy policy or a policy of at least the same level of protection.

 

Furthermore, as part of its regulatory obligations, the Club shall disclose/ transfer your data to:

 

Tax, Audit and other Public Authorities when we consider in good faith that we are required by law or any other regulatory act to grant access or forward such data.

 

10.         Rights of the data subject

 

One of the basic principles of GDPR is to protect the rights of individuals with regard to the processing of their personal data. Within the above context, you have a set of rights with respect to your personal data processed by the Club. Specifically:

 

            Right to object: This right allows you to oppose to the processing of your personal data, especially when the processing is carried out for purposes of a legitimate interest of the Club. Where processing is conducted to serve its legitimate interests, the Club shall respect your objection and stop the processing in question unless the Club demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or the processing in question is for the establishment, exercise or defense of legal claims of the Club.

 

           Right to withdraw consent: If data processing is based on prior consent, you have the right to revoke your consent at any time and the Club shall cease the specific activity you previously consented to, unless there is an alternative legal basis justifying the continuation of your data processing for that purpose, a case in which you shall be informed.

 

            Rights of access, rectification and erasure (“right to be forgotten”): You may request at any time to be informed about your personal data retained by the Club and request amendment, rectification, updating or erasure of such information. You may be asked to provide additional information so that we process your request. Nevertheless, since we grant access to the information we have on file for you, this access shall be provided free of charge, unless your claim is "clearly unfounded or illegitimate". Since we have the legal right to turn down your request, we shall inform you on the specific reasons for such denial.

 

·                Right to limitation of data processing: In some circumstances, you have the right to "opt out" or revoke further use of your personal data.  In practice, this means that we may store your data, but we shall not be able to process it further, unless such processing is carried out with your consent, or such processing is necessary either to establish, exercise or support legal claims of the Club, or to protect the rights of a third person or for reasons of public interest. We maintain lists of people who have requested that further use of their data “be restricted” to ensure that this restriction shall be complied with in the future.

 

 

 

·                Right to data portability: You have the right to transfer your personal data to other controllers. In practice, this means that you have the ability to transfer the information retained to any third party. In order to implement this right, we shall provide you with the data in a structured, commonly used and machine readable format so that you can transfer your data to another controller. Alternatively, we can send the data directly for you. The right to portability applies to (a) data we process automatically (i.e. with no human intervention), (b) personal data provided by you, and (c) personal data processed as a result of your consent, or if processing is necessary for enforcing a contract.

 

·                Right to lodge a complaint with a supervisory authority: You have the right to lodge a complaint with the competent supervisory authority, namely the Hellenic Data Protection Authority.

 

You can contact the Data Protection Authority in the following ways:

 

Postal Address: Hellenic Data Protection Authority, Registered offices: 1-3 Kifissias Avenue, P.C. 115 23, Athens.

 

Call center: +30-210 6475600

 

Fax: +30-210 6475628

 

e-mail: contact@dpa.gr

 

11.         Details of the club

 

Name: “"OLYMPIACOS SFP" – [Olympic Club of Fans of Piraeus]

 

VAT Reg. №: 090035555

 

Registered Offices: ALEXANDRAS SQUARE, PIRAEUS

 

Legal representative: MICHAIL KOUNTOURIS & DIMITRIOS NAKOS

 

Tel./e-mail: 210 4190902 / info@osfp.gr

 

Do you have any queries? Contact us

 

Should you have any questions about this Notice, please do not hesitate to contact us by phone at +302111007060 or via e-mail at members@osfp.gr.

 

 

 

Definitions

 

“General Data Protection Regulation ("GDPR")” - a European Union regulation aimed at harmonizing European legislation on data protection. It entered into force on May 25, 2018, and any reference to it should be interpreted to include national implementing legislation.

 

“Personal Data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

 

“Processing”: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

 

“Sensitive personal data”: personal data which contain information on racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, physical and mental health, genetic and biometric data, data relating to sexual life or sexual orientation, and information on criminal convictions and offenses. Due to the nature of sensitive personal data, the legislation is much more rigorous about how these data should be processed. The Club processes sensitive personal data only in accordance with the law.

 

“Personal data breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data transmitted, stored or otherwise processed.

 

“Restriction of processing”: the marking of stored personal data with the aim of limiting their processing in the future.

 

“Associates”: Natural persons with whom the Club may maintain any business relationship or contractual relationship or partnership.

 

“Data Controller”: the natural or legal person, public authority, agency or any other body which alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by the Union or Member State law, the data controller or the specific criteria for their nomination may be provided for by the Union or Member State law.

 

 

 

 

 

English