Privacy Policy
This Privacy Policy describes how iasma collects, uses, stores and protects the personal data of visitors to the website www.iasma.gr and its customers, in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the applicable personal data protection legislation.
Data Controller
The controller of personal data collected and processed within the framework of the operation of iasma and the website www.iasma.gr is:
Name: Messinios Elias
VAT number:
Headquarters: Athens
Email: info@iasma.gr
Telephone: (+30) 210 4908810
(hereinafter referred to as “iasma”, “we” or “Data Controller”).
What data do we collect?
Depending on how you interact with iasma, we may collect and process the following categories of data:
-
Contact and booking data
When you contact us by phone, email or the website's contact form, we may collect:
-
full name,
-
telephone number,
-
email address,
-
information about your request,
-
the content of your communication,
-
details necessary for scheduling and managing your appointment.
-
Information provided during a session
During a session you may provide us with information about your personal, emotional or psychological state, as well as other information you consider relevant to your request.
Depending on their content, some of this information may fall within special categories of personal data, including data concerning health within the meaning of Article 9 of the GDPR.
iasma collects and processes only the information necessary to provide the specific service, and only to the extent that it is provided by the data subject themselves.
-
Transaction and invoicing data
To carry out and record transactions, we may collect the details necessary to issue the documents required by law and to comply with the related tax and accounting obligations.
-
Website usage data
When you visit the website, technical data may be collected, such as device data, browser, IP address and data about your use of the website, depending on the technologies and cookies that are active.
For more information about cookies, please see the iasma Cookie Policy.
For What Purposes Do We Process Data?
Your personal data may be processed for the following purposes:
for communication and response to your requests,
for scheduling, confirming and managing appointments,
for the provision of iasma services,
to personalize the counseling session and, where applicable, the flower remedy blend,
for the issuance and maintenance of the required tax and accounting documents,
for the security and proper functioning of the website,
to improve the functionality and user experience of the website, where the relevant processing is based on your consent,
for the exercise or support of legal claims and the protection of the legitimate interests of iasma, where necessary.
Legal Basis for Processing
Depending on the purpose of the processing, iasma bases the processing of personal data on one or more of the following legal bases of Article 6 of the GDPR:
Consent of the data subject (Article 6(1)(a)),
performance of a contract or taking measures at the request of the subject prior to the conclusion of a contract (Article 6, paragraph 1, letter b),
compliance with a legal obligation to which IASMA is subject (Article 6(1)(c)),
legitimate interests of IASMA or a third party, provided that the interests or fundamental rights and freedoms of the subject do not prevail (Article 6, paragraph 1, letter f).
When the processing concerns special categories of data pursuant to Article 9 of the GDPR, iasma applies the corresponding additional legal basis required by Article 9 of the GDPR.
Where processing is based on consent, it shall be freely given, specific, informed and unambiguous and may be withdrawn at any time. The withdrawal of consent shall not affect the lawfulness of processing carried out prior to it.
Confidentiality of Meetings
The information you provide during the session is treated as confidential and is used exclusively for the purposes for which it was collected.
We do not share the content of the sessions with third parties, unless required by applicable law, necessary to protect vital interests or rights, or with your prior consent.
Recipients and Processors
Your personal data may be disclosed or made accessible only to persons or providers who are necessary for the operation of iasma and the provision of its services, such as, but not limited to:
website hosting and technical support providers,
electronic communications service providers,
payment service providers, where applicable,
accountants or tax experts, to the extent required,
partners or providers acting as processors on behalf of iasma.
The iasma website is hosted and operated through the Wix.com Ltd. platform. Depending on the services and functions enabled on the website, Wix or other providers may process technical or other data on behalf of iasma or as independent data controllers, in accordance with their respective roles.
iasma does not sell, rent or trade your personal data.
Data Transfers Outside the EEA
In the event that personal data is transferred or made accessible outside the European Economic Area (EEA), iasma takes the appropriate measures provided for by the GDPR to lawfully carry out the transfer, such as, where applicable, the use of an adequacy decision, Standard Contractual Clauses or other safeguards provided for by law.
Data Retention Time
iasma retains personal data only for as long as is necessary to achieve the purposes for which they were collected or for as long as required by applicable law.
Data related to tax and accounting obligations are retained for the period required by the applicable tax and accounting legislation.
Contact and booking data is retained for as long as necessary to manage the request or relationship with the customer and, thereafter, for as long as necessary to fulfill any legal obligations or to exercise and defend legal claims.
Any special category data collected in the context of sessions are not retained for a period longer than is necessary for the specific purpose, unless there is a different legal basis that permits or requires their retention.
Your Rights
Under the conditions and limitations provided for by the GDPR, you have the right to:
access to personal data concerning you,
correction of inaccurate or incomplete data
deletion of your data,
restriction of processing,
objection to processing,
your data portability, where applicable,
withdraw your consent at any time, where the processing is based on consent.
These rights are not absolute and may be subject to restrictions provided for by the GDPR or other applicable legislation.
To exercise your rights, you can contact info@iasma.gr.
You also have the right to file a complaint with the Personal Data Protection Authority (PDPA), if you believe that the processing of your personal data violates the applicable personal data protection legislation.
Data Security
iasma takes appropriate technical and organizational measures to protect personal data from unauthorized access, loss, destruction, alteration, unlawful processing or disclosure.
Despite taking appropriate measures, no method of electronic storage or transmission of data over the internet can guarantee absolute security.
Automated Decision Making and Profiling
iasma does not make decisions that produce legal effects or significantly affect data subjects solely on the basis of automated processing, including profiling, unless we inform you in advance and there is a legal basis for doing so.
Privacy Policy Amendments
This Privacy Policy may be updated from time to time, especially in the event of changes to the services, technologies used or relevant legislation.
The currently applicable version is published on the website www.iasma.gr and indicates the date of the last update.