Subject matter of this Data Protection Privacy Policy:
The sole proprietorship under the trade name "STAUROS ANDREA KOIS" and the distinctive title "OPTIKO KENTRO KYKLADON STAUROS A. KOIS" (hereinafter "Kois Optics"), headquartered at 16 Thymaton Spercheiou Street, acts as the Controller with regard to the personal data it handles for the purpose of providing its services.
Kois Optics safeguards the integrity of personal information by applying appropriate technical and organizational measures, complying with the applicable national and Union framework-primarily Regulation (EU) 2016/679 and Law 4624/2019 – and with the Decisions, Guidelines and Opinions of the competent Greek supervisory authority.
Kois Optics consists of the main store at 16 Thymaton Spercheiou Street and a branch at 3 Eleftheriou Venizelou Street, both in Ermoupoli Syros.
This Privacy Policy covers all premises, applications and digital infrastructures belonging to Kois Optics and related to its activity, including www.kois-optics.gr.
Contact details of the Data Controller:
Corporate name: OPTIKO KENTRO KYKLADON STAUROS A. KOIS
Address: 16 Thymaton Spercheiou Street, P.C. 84100, Ermoupoli Syros
Email address: info@koisoptics.gr
Phone number: 22810 83810
Website: https://kois-optics.gr
Definitions:
For the purposes of this Policy, the following terms have the following meaning:
"Personal data": any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one whose identity can be verified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
"Special categories of personal data": personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or tradeunion membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person's sex life or sexual orientation.
"Processing": any operation or set of operations which is performed with or without automated means on personal data or on sets of personal data, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
"Controller": the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or MemberState law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
"Processor": the natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
"Data subject": the natural person whose personal data are processed, for example customers, employees, etc.
"Recipient": the natural or legal person, public authority, agency or other body to which personal data are disclosed, whether a third party or not; however, public authorities that may receive personal data in the framework of a specific inquiry under Union or MemberState law shall not be regarded as recipients; the processing of those data by those public authorities is in compliance with the applicable dataprotection rules according to the purposes of the processing.
"Third party": any natural or legal person, public authority, agency or body other than the data subject, the controller, the processor and persons who, under the direct authority of the controller or the processor, are authorised to process personal data.
"Consent" of the data subject: any freely given, specific, explicit and informed indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data concerning him or her.
"Personal data breach": a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
"Anonymisation": the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject.
"Pseudonymisation": the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures to ensure that it is not attributed to an identified or identifiable natural person.
"Data concerning health": personal data related to the physical or mental health of a natural person, including the provision of services for filling prescriptions for eyeglasses, sunglasses and contact lenses, and revealing information about that person's health status.
"Applicable legislation": the national and Union data protection legislation in force, namely General Data Protection Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019, as amended, as well as the Decisions, Guidelines and Opinions of the Hellenic Data Protection Authority.
General principles of personal data processing
Kois Optics collects and processes your personal data in accordance with the following processing principles:
- Lawfulness, fairness, transparency: Kois Optics collects and processes your personal data lawfully, fairly and in a transparent manner.
- Purpose limitation: Kois Optics processes your personal data only for specified, explicit and legitimate purposes.
- Data minimization: Kois Optics takes appropriate technical and organizational measures so that the personal data it processes are adequate, relevant and limited to what is necessary for the purposes for which they are processed.
- Accuracy: Kois Optics ensures that the personal data it holds and processes are always accurate and up to date.
- Storage purpose limitation: Kois Optics does not keep personal data for longer than the period required by the purposes for which they were collected and processed; however, Kois Optics may retain them for longer period if processing is necessary:
- i) to comply with a legal obligation that requires processing by law,
- ii) for the performance of a task carried out in the public interest,
- iii) for reasons of public interest,
- iv) for archiving purposes in the public interest or for scientific or historical research purposes or statistical purposes, after appropriate technical and organisational measures, including pseudonymisation, have been taken and only when those purposes cannot be served by anonymising the data,
- v) for the establishment, exercise or defence of legal claims.
- Integrity and confidentiality: Kois Optics sees to it that the collection and processing of your personal data are carried out securely, using appropriate technical and organisational means, so that they are protected from any unauthorised or unlawful processing and accidental loss, destruction or damage.
Categories of data we process
- i) Kois Optics gathers only the data that are strictly necessary for the proper provision of its services and the fulfillment of its contractual or legal obligations. Indicatively, it collects:
- i) Identification details and demographic referral data (full name, father's name, mother's name, date of birth, age, gender, AMKA, AFM, occupation or employing company/organisation, etc.),
- ii) Contact details (postal address, landline and mobile phone, email) for communication, for sending your optometry results or for sending you newsletters of Kois Optics regarding provided services, news and offers,
- iii) Insurance details (insured person's code, insurance fund or company, insurance relationship, group or individual policy number, coverage code, policy inception or renewal date, coverage expiration date, policy anniversary date, dispatch record date, policy status (active or void), covered members, etc.),
- iv) Data concerning health and in particular data related to the optometry services provided by Kois Optics, which concern diagnostic and clinical examinations, doctors' referrals, clinical symptoms, medical staff or/and family or/and previous medical history, medication and eye treatment, medical opinions and findings, any surgical details such
as recorded endoscopic surgical acts, previous healthcare, case code, etc.,
- v) Data concerning health collected in the context of our optometry services from medical services not provided by Kois Optics but communicated or transmitted by you or by an accompanying person and absolutely necessary for assessing the health status of your eyes and providing optometry services, browsing data on our website, such as the IP address of your device while browsing our site www.koisoptics.gr, the type of browser you use, etc.,
- vi) Third party data such as your relatives' details (name, surname, father's name, ID number, etc.) for receiving your optometry results or for granting authorisation for receiving your optometry results when you are objectively unable,
- vii) Image and video data from CCTV and security cameras as set out in the "INFORMATION ON THE PROCESSING OF PERSONAL DATA THROUGH CLOSED CIRCUIT TELEVISION SYSTEM (CCTV)" of Kois Optics,
- viii) Data related to requests you have submitted for exercising your rights or complaints,
- ix) Candidate employee data contained in attached CVs or relevant forms (name, surname, contact details, education, work experience, etc.),
- x) Employee data at Kois Optics (name, surname, father's name, mother's name, gender, date of birth, home address, landline/mobile phone, email (corporate/personal), nationality, marital status, number of children, civil registry acts or family certificates, ID details, AFM, Tax Office, IBAN, degrees, professional certifications, military service certificates, training, previous experience, hiring date, payroll details, allowances, internal evaluation reports, etc.),
- xi) Supplier and partner data of Kois Optics (name, surname, father's name, gender, date of birth, phone, fax, home address, post code, email (corporate/personal), ID, passport number, AFM, Tax Office, IBAN, business sector, transaction details, information regarding shareholding status, professional certificates, degrees, information on any sanctions, and any further details required by national law).
The above categories may be updated when required in order to meet new legal or operational needs, always observing the principle of data minimisation.
Method of collecting personal data:
Personal data are collected both by physical and electronic means, as the case may be, indicatively:
- i) at Kois Optics stores during your optometry, when completing various forms or during electronic communication, when using our website to schedule optometry or obtain another service and when submitting online orders,
- ii) when you state your wish to use your insurance contract for executing your referrals,
- iii) when you apply to work at Kois Optics,
- iv) when you are hired as an employee at Kois Optics,
- v) when you contract as a partner/supplier with Kois Optics,
- vi) when you submit a request to receive a newsletter,
- vii) when you enter the store and branch of Kois Optics that are monitored by CCTV and security cameras.
Purposes of processing and legal bases of processing:
Kois Optics processes personal data exclusively when an appropriate legal basis exists under the Applicable Legislation, which are used for the following purposes of processing:
- i) For providing optometry services,
- ii) for sending/delivering to you the results of your optometric analysis, etc. Regarding processing of specialcategory data, namely sensitive data (data concerning health), processing is necessary for providing our services, i.e. executing referrals for manufacturing prescription eyeglasses, sunglasses and ordering contact lenses.
Legal basis for processing these data is:
- a) the necessity of processing your data for executing your referrals or under a contract with a healthcare professional, and
- b) the necessity of processing to perform obligations and exercise specific rights of ours or yours in employment and socialsecurity law or for the fulfilment of a task carried out in the public interest, and
- c) the necessity of processing to ensure high standards of quality and safety in executing referrals as provided by law. We will never process your personal data without one of the above legal bases or without your explicit consent after first informing you of the purpose of processing. When you use a public insurance fund/body, certain personal data will be processed on the legal basis of executing referrals and the necessity of processing your personal data to perform obligations and exercise specific rights in social security and social protection law.
- iii) For the compliance of Kois Optics with its legal obligations, such as tax and insurancelaw compliance. Legal basis in this case is the compliance of Kois Optics with its legal obligations.
- iv) For safeguarding and protecting legitimate interests of both natural persons (patients, visitors) and Kois Optics. For example, we use CCTV and security cameras in order to protect the safety of natural persons, property and facilities, in accordance with the specific conditions provided for the installation of cameras in our stores.
Legal basis in this case is the legitimate interest of Kois Optics.
- viii) For sending newsletters on Kois Optics news so that you are informed about innovations, products and offers of Kois Optics.
Legal basis in this case is your prior explicit consent.
- ix) For our communication after prior identification and the management of your requests, whether related to dataprotection issues or the quality of your service.
Legal basis in this case is the legitimate interest of Kois Optics or/and the compliance of Kois Optics with its legal obligations under the Applicable Legislation.
- x) For extracting statistical data after anonymisation of your data.
Legal basis in this case is the necessity for extracting statistical data.
- xi) For the lawful conclusion and performance of contracts concluded by Kois Optics with third parties.
Legal basis in this case is the necessity of processing your data in the context of fulfilling a contractual obligation or at the precontractual stage.
- v) For Kois Optics to hire staff and also contract with external partners (salespersons, technicians, nurses, etc.).
Legal basis in this case is:
- a. the necessity of processing these data in the context of fulfilling a contractual obligation or at the precontractual stage, and
- b. the necessity of processing to perform obligations and exercise specific rights of ours or yours in employment and socialsecurity law or for the fulfilment of a task carried out in the public interest.
- vi) For Kois Optics to select suitable Suppliers/Partners, conclude assignment contracts and monitor their implementation, check the creditworthiness of counterparties to secure financial transactions in the context of undertaken business activities and comply with legal obligations of Kois Optics.
Legal basis in this case is
- a) the performance of the contract concluded with the Suppliers/Partners of the Company,
- b) compliance with legal obligations (for example tax law),
- c) the establishment, exercise or defence of legal claims or when courts act in their judicial capacity,
- d) the safeguarding of our legitimate interests (for example ensuring commercial credit, fraud protection, credit and market risk management, unlawful transactions under the applicable legal and regulatory framework on financial sanctions) and compliance with our legal obligations.
Where processing is based on the legitimate interest of Kois Optics, we conduct a balance test of the rights of data subjects to ensure that your interests or fundamental rights and freedoms are taken into account in balancing our legitimate interest.
Your consent is freely given, specific, explicit and informed and may be withdrawn at any time without affecting the lawfulness of processing based on consent before its withdrawal. Specifically, consent is given freely, can be withdrawn at any time without affecting the lawfulness of prior processing and is not a condition of service provision unless processing is necessary for providing our services, for safeguarding our legitimate interest or when required by law.
Third parties personal data sharing:
Kois Optics may, when necessary, disclose personal data to specific recipients, always respecting the principles of lawfulness, necessity and minimisation and only where a legitimate purpose exists.
Processors – Kois Optics partner network:
We may assign specific tasks requiring access to a limited set of personal data to third party companies or professionals (e.g ophthalmologists, optometric laboratories, centers for ophthalmological checks). Each partner is contractually bound to confidentiality, to apply appropriate security measures and to process data solely on our behalf and according to our written instructions and orders.
i) Public social security organisations
When you use a public insurance body, we process the necessary data to handle reimbursement or coverage of your expense under the institutional insurance framework.
ii) Private insurance or employer companies.
In cases of private insurance we transmit, after your explicit prior consent, only the strictly necessary sensitive health data for recognizing and paying the cost of our services. Medical referral data are not disclosed to the employer or insurance company without your prior consent.
iii) Financial institutions and credit rating companies
To secure transactions and check credit risk in contracts with suppliers or partners, we may transmit economic data to banks or specialised organisations after relevant notification.
iv) Judicial, prosecutorial and other public authorities:
Where required by law, we disclose data to competent authorities (courts, prosecutors, tax services) either ex officio or following a request by a third party invoking legitimate interest, always following the prescribed legal procedures.
Kois Optics may transmit the above personal data to third parties to which it has assigned processing on its behalf. Kois Optics may transmit your personal data to partners within its network who act on its behalf, contractually bound to Kois Optics for providing independent services (for example partner ophthalmologists for diagnostic purposes or clinical checks after informing you and obtaining your consent, partner ophthalmological centres, partner ophthalmological clinics and ophthalmological laboratories) or to third partner companies within the Kois Optics network that process your personal data on behalf of Kois Optics.
Employees working within Kois Optics stores may have access to the optometry history records that Kois Optics maintains for you where necessary for assessing and evaluating the appropriate eyeglass, sunglass or contact lens prescription during the provision of our optical services and, among other things, for executing your referrals.
In every case, third parties to which data subjects' data may be disclosed are contractually bound to Kois Optics to ensure the obligation of confidentiality and all obligations provided by the Applicable Legislation.
Kois Optics specifies the processing details, signs special contracts with the third parties to which it assigns specific processing activities and ensures that processing is carried out in accordance with the Applicable Legislation. The said third parties are contractually bound to Kois Optics to process your personal data only for the specific and contractually defined purposes and not to transmit or disclose them to third parties unless required by law.
Kois Optics may transmit your sensitive personal optometry data (health data) to contracting third party companies for assuming the cost of the optical services provided to you or to partner private insurance companies within the European Union and the EEA for your insurance coverage only on condition that your prior explicit consent has been given before such transmission.
We do not perform transfers of data outside the European Economic Area. If an international transfer becomes necessary in the future, we will apply the appropriate safeguarding mechanisms and inform the data subjects in good time.
Retention period:
The personal data collected by Kois Optics are retained only for as long as necessary in relation to each processing purpose. After the expiry of the relevant period the data are deleted or destroyed securely unless the applicable law imposes or allows a different retention period. The period is determined indicatively as follows:
i) Data are retained obligatorily for the entire period required by the processing purpose or the Applicable Legislation. After the processing purpose has lapsed, personal data are retained only as long as necessary to protect the legitimate interests of Kois Optics before judicial or administrative authorities. Job application CVs are retained for two (2) years and then destroyed according to the Secure Destruction Protocol of Kois Optics.
ii) When processing is imposed by the Applicable Legislation, data are stored at least for the minimum period provided by the specific provisions. iii) In every other case where processing is based on your consent, your personal data are retained until you withdraw your consent without affecting the legality of processing based on consent before its withdrawal. To withdraw consent you must submit a request to the Data Protection Officer of Kois Optics (see contact details below). Alternatively, for the promotion of Kois Optics products and services you may also use the unsubscribe options by clicking on the corresponding link in our electronic communications. For as long as your email address remains in our database you will periodically receive informational emails from us. iv) The physical file with the optometry results of your optometry and generally the files you receive is retained for sixty (60) days from the date of optometry at Kois Optics stores where we provide services if you do not choose to have them sent to your email or via courier to your postal address. The digital files with your electronic signature in which you indicate, for example, the method of receiving your optometry examinations other than personal collection by you or a third person you designate and any granting of consent for receiving newsletters, informational material and offers of Kois Optics, granting of consent for any disclosure, are retained for as long as required to fulfil each purpose and after fulfilment for five (5) years. They are also recorded and kept in electronic form while the physical file after the above sixty day period is destroyed securely according to the Secure Destruction Protocol of Kois Optics. v) Data we collect when you submit a request and the related file in which they are recorded are retained for twenty (20) years from the date of collection.
Security of personal data:
Taking into account the state of the art, implementation cost, nature, scope, context and purposes of processing, as well as the likelihood and severity of risk to the rights and freedoms of natural persons, Kois Optics applies appropriate technical and organisational measures to ensure the protection of personal data.
- i) Technical measures: firewalls, antivirus/antimalware, encryption mechanisms where required, controlled system access, regular security updates and backups.
- ii) Physical security: alarm system, controlled access to facilities and CCTV to prevent unauthorised access to areas where files are kept.
- iii) Organisational measures: information security policies, staff training in data protection issues, periodic compliance audits, incident management procedures and processing activity logs.
Data Protection Impact Assessment (DPIA):
When processing is likely to entail a high risk to the rights and freedoms of natural persons, Kois Optics conducts, before processing, an assessment of the impact of the envisaged processing operations on the protection of personal data ("impact assessment"). The impact assessment is a process designed to describe the processing, assess its necessity and proportionality and assist in risk management by defining measures to address them. It is not required for every form of processing but only when a form of processing is considered high risk. The nature, scope, context and purposes of processing are assessed to evaluate the likelihood and severity of risk to the rights and freedoms of data subjects.
Kois Optics may decide to conduct an impact assessment even if it is not mandatory under the Applicable Legislation. Furthermore, it is not mandatory to draw up a separate impact assessment for every form of processing; a set of similar processing operations involving similar high risks may be included in one impact assessment.
Impact assessment is mandatory in all cases where processing "is likely to result in a high risk to the rights and freedoms of natural persons." Such cases include indicatively:
- i) Systematic and extensive evaluation of personal aspects relating to natural persons, based on automated processing (including profiling) and on which decisions producing legal effects concerning or imilarly significantly affecting the data subject are based.
- ii) Large scale processing of special category data (sensitive data).
- iii) Systematic processing of personal data.
Personal Data breach:
In the event of a data breach, Kois Optics immediately activates the approved response plan. The plan includes identifying and isolating the incident, investigating its causes and scope, applying corrective actions and restoring operations securely. The enterprise keeps an internal incident log (Breach Register) and assesses the severity of each breach, especially regarding the risk to the rights and freedoms of data subjects.
When the breach is likely to result in a high risk, Kois Optics notifies without undue delay the competent Greek supervisory authority and, where required, the data subjects, describing the nature of the breach, possible consequences and measures taken or proposed to mitigate its effects. If you notice or suspect that your personal data have been breached, please contact the Data Protection Officer immediately at info@kois-optics.gr so that the incident management procedure can be activated.
Rights of data subjects:
Kois Optics ensures that it responds promptly to requests to exercise your rights in accordance with the applicable legislation. Your rights are the following:
i) Right to withdraw consent
If processing is based solely on your consent (for example for promotional purposes), you are entitled to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
ii) Right of access and information
You may be informed whether we keep data concerning you, obtain a copy and be informed about how and why they are processed.
iii) Right to rectification
You are entitled to request the completion or rectification of inaccurate or incomplete personal data.
iv) Right to erasure
You may request the deletion of data when no lawful reason for retention exists. Data required for compliance with legal obligations or for the establishment, exercise or defence of legal claims are excluded.
v) Right to restriction of processing
You may request restriction when you contest accuracy, when processing is unlawful and you prefer restriction to deletion, when data are no longer necessary for us but you need them for legal claims, or when you have objected to processing pending verification of overriding legitimate grounds.
vi) Right to object
You may object at any time to processing based on legitimate interest. Kois Optics does not apply automated decision making.
vii) Right to data portability
You are entitled to receive your data in a structured, commonly used and machine readable format or request their transfer to another controller, when technically feasible.
All requests are fulfilled without undue delay and in any case within one (1) month of receipt and identification. The deadline may be extended by two (2) additional months considering complexity and number of requests; you will be informed in good time of any delay. If a request is manifestly unfounded or excessive, Kois Optics may charge a reasonable fee or refuse to comply.
Data Protection Officer (DPO) contact details:
To exercise the above rights and for any issue regarding the processing of your personal data, you may contact the Data Protection Officer of Kois Optics at info@kois-optics.gr.
Disclaimer for third party websites:
If our websites include links redirecting you to third party sites, Kois Optics does not control or bear responsibility for their content, their privacy policies or their data processing practices. Access to such sites is solely at your own responsibility.
Right to lodge a complaint with the Hellenic Data Protection Authority:
For any complaint regarding this policy or personal data issues, if we do not satisfy your request you may contact the Hellenic Data Protection Authority via www.dpa.gr at 13 Kifisias Avenue, P.C. 115 23, Athens, +30 210 6475600, +30 210 6475628, contact@dpa.gr.
Updates of the Personal Data Protection Policy:
This Personal Data Protection Policy may be modified/revised in the future for regulatory compliance and for optimising and upgrading our website services. We therefore recommend that you consult the updated version each time for adequate information.
Last updated: July 2026