PERSONAL DATA PROTECTION 
 



1.Object

The management and protection of your personal data during the use of our Website are governed by the present terms and the relevant provisions of both Greek Law and the Directives of the European Parliament. According to the EU Regulation 2016/679 of the European Parliament of April 27, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter referred to as GDPR) and the national legislation Law 4624/2019.
The Controller is the HELLENIC FOOTBALL FEDERATION ("H.F.F./E.P.O."), which is a Legal Entity under Private Law and namely a third-tier sports association.
H.F.F. takes into consideration and fully understands the importance of maintaining the privacy of your personal data and other information processed. It is therefore committed, in fulfilling its purposes and in compliance with applicable data protection laws, to ensure the confidentiality, integrity and availability of your personal data.


2.Security Measures
Appropriate organizational and technical measures are implemented using advanced security technologies and procedures in order to safeguard the security, confidentiality and integrity of personal data against all kinds of risks, in particular accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access thereof and in general against any other form of illegal or improper processing ("Data Security Breach"). These measures are reviewed and amended when deemed necessary. However, we would like to point out that in any case, the transmission of information over the Internet is not completely secure. Although we do our best to most efficiently protect your personal data, we cannot absolutely guarantee its security when they are transmitted over the Internet.


3.Data Categories

In order to provide the aforementioned services in the Terms and Conditions to users, as well as to serve other legal purposes (e.g. for tax purposes, for invoicing purposes etc.), the Hellenic Football Federation collects and processes the necessary personal data, which the user has provided. For example, the following data might be requested:
Last name
Name
Gender
Date of birth
Mobile phone
Landline phone
E-mail
Country
Province
Municipality/Area
City
Postal Code
Address
Tax Office
VAT number
Social Security Number
Identity/Passport and Date of Issuance


4.Legal Basis
H.F.F. processes your personal data legally and for each processing performed there is at least one of the following legal bases.

  • Processing is necessary for the performance of contractual obligations.

In order to be able to perform the contractual obligations of the Federation towards you and also to monitor the fulfillment of the contractual obligations of its partners, the legal basis in the context of which the data of the subjects are legally processed is article 6, par.1 (b) of the GDPR.

  • Processing is necessary to comply with legal obligations.

Beyond its contractual obligations, H.F.F. must also comply with its various obligations stemming from the current legislative framework, in accordance with what is provided for in article 6, par.1 (c) of the GDPR.

  • Processing is necessary to serve legitimate interests.

In accordance with the provisions of article 6, par. 1 (f) of the GDPR, H.F.F. may process personal data when such processing is "necessary for the purposes of the legitimate interests it pursues, unless these interests are overridden by the interest or the fundamental rights and freedoms of the data subjects which require protection of personal data".

  • You give us your consent to process your personal data.

In limited cases, we may seek your opt-in consent before carrying out certain processing of your data. For example, we may ask for your consent to send you informational or promotional material.


5.Data Recipients
The Federation does not in any way transfer the personal data of the users for financial or other motives to any third-party private companies, natural or legal persons or other organizations.
The recipients of the data for the promotion, support and servicing of the transactional relationship may be the Financial Institutions through which the fees of each user are paid.
In addition, the H.F.F. may transmit the above data to authorized partners (e.g. Ticket Issuing Company) for the fulfillment of the aforementioned purposes, who will act as Processors on behalf of the Federation. These partners must implement appropriate technical and organizational measures, in such a way that the processing meets the requirements of the Regulation and the protection of the rights of the data subject is ensured.
In special cases, either for the defense of the rights of the H.F.F., or when provided for by of the law or judicial decisions or decisions of the Authority, recipients may be the Police and Judicial Authorities, the Hellenic Data Protection Authority or other Independent Authorities.


6.Retention period

The data shall be stored for the minimum possible period, i.e. 6 (six) years, for the fulfillment of the obligations provided for in the tax legislation that fall on the Federation. If the law or regulatory acts oblige H.F.F. in keeping the personal data for a period longer than the aforementioned, the retention periods will be extended accordingly.


7.Users’ Rights
Please note that as users you have the following rights:

  • You have the right to know which personal data concerning you are held and processed.
  • You have the right to request their rectification and/or completion, so that they are complete and accurate.
  • You have the right to request the restriction of the processing of the data or to refuse any further processing thereof, however, the satisfaction of such requests is made upon request of the subject of the processing of the personal data.
  • You have the right to object to the processing of personal data, especially when the processing is carried out for purposes of legitimate interest. Therefore, as long as the processing takes place to serve the above-mentioned purpose, the Federation will comply with your objection and stop the specific processing, unless it can demonstrate compelling and legitimate reasons for the processing that override the interests, rights and freedoms of you or the said processing is for or for the establishment, exercise or support of legal claims of the Federation.
  • You have the right to request the erasure of data concerning you (“right to be forgotten”), as long as the above-mentioned retention period has expired (unless the law or regulations specify specific retention periods.)
  • You also have the right to file a complaint with the Hellenic Data Protection Authority (www.dpa.gr), if you believe that you and/or your rights are being violated in any way.


8.How to communicate with us
For any issue regarding the processing of your data, you can contact the Data Protection Officer of the Hellenic Football Federation, at the following e-mail address: dpo@epo.gr.
Other information:
Hellenic Football Federation (“H.F.F./E.P.O.”)
www.epo.gr
Ticket Department
ticketing@epo.gr
Tel. (+30) 210 9306000

*********************************************************************************

ELECTRONIC MAGAZINE/ NEWSLETTER
In addition, the user may, separately, consent to the processing of his/her data (the data provided in the context of the transaction) by sponsor companies cooperating with H.F.F. in order to receive exclusive promotional material related to the National Teams, and information on the possibility of participating in competitions, trips with the National Teams, gifts and other benefits, and the receipt of the official electronic magazine/newsletter with exclusive news on the National Teams. In any case, he reserves the right to withdraw his consent at any time, also retaining the right to erase his data (the processing operations carried out prior to the withdrawal are not affected).