PERSONAL DATA PROTECTION POLICY OF THE E-SHOP www.rootnaturecosmetics.com 
We at “ROOT NATURE COSMETICS” with headquarters in Riza, with Tax ID 302190994, GEMI 169120202000 , respect your privacy and we take appropriate measures to comply with the applicable national and European legislation in relation to the protection of your personal data. To this end, we have adopted this Privacy Policy (hereinafter referred to as the “Privacy Policy” or “Policy”) in order to inform visitors of our online shop (hereinafter referred to as “e-shop”, “online shop”), hosted on the website www.rootnaturecosmetics.com (the “Website”) about the processing of your data.
The Company’s privacy policy below is addressed to you when you:
– navigate our e-shop,
– create an account,
– purchase products from our e-shop,
– receive and/or use a Gift Card for your purchases,
– Receive updates from us through our promotional activities,
– communicate with us on issues concerning our Company and/or our Website
(hereinafter “You”).
This Policy should be read together with the Cookies Policy and the Terms & Conditions of our e-shop, as these texts are an integral part of this Policy, and govern the operation of the e-shop and the transactions (purchases) performed through it. By making any use of the e-shop you state that you have read this Policy (and the above texts), and you agree with the way we process your personal data; if you disagree or have reservations about part or all of it, please refrain from using the e-shop or accessing it, otherwise it is presumed that the use of the e-shop in accordance with the above is unconditional.
By continuing to navigate our e-shop and/or making your purchases, you automatically and unconditionally accept the terms of this Policy as amended from time to time. We invite you to consult this Policy from time to time in order to be informed of any changes. If you do not agree with the amendments, you must not perform any action on the e-shop (i.e. use the Website and/or purchase products).
1. Data Controller & Contact details
1.1. The Company with the details mentioned above is the Data Controller of your personal data.
1.2. Contact details: For any matter relating to this Privacy Policy and the processing of your personal data, you can contact us in the following ways:
– For telephone service, at 6938984015, Monday to Friday 9:00 am – 17:00 pm
– By email at rootnaturecosmetics@gmail.com
2. What is your personal data?
Your personal data includes any information that allows, either alone or in combination with others, your unique identification, in accordance with the provisions of the General Data Protection Regulation (GDPR 2016/679/EU – GDPR), the applicable Greek legislation and the decisions of the Hellenic Data Protection Authority as well as the directives and decisions of the competent European institutions. This information is collected either by you, when you enter it in specific fields of the Website, or following a specific action in our e-shop, or in an automated way during your navigation, such as, for example:
1. when you enter your personal data yourself electronically when creating and managing an Account in the e-shop
2. when you place an order or contact us to request assistance with your order
3. when you provide your data for us to conduct marketing activities towards you (when you subscribe to our Newsletter or other means of communication, e.g. Viber) or participate in the Company’s promotional activities (e.g. contests) or fill in some additional characteristics for the purposes of personalized commercial communication
4. when you provide us with your feedback in relation to the operation of the e-shop or we automatically process data in relation to the operation of our Website
5. when you use digital tools that are embedded in the e-shop and make use of some of our services (e.g. virtual try on)
6. when you submit a request for customer service
7. when you accept the use of tools such as cookies or other technical means to customize your browsing experience in the e-shop. For more information about the management of your personal data through cookies, you can also refer to our Cookies Policy.
3. What data do we collect?
Indicatively, we collect the following personal data for you, if you submit them to us:
Directly FROM YOU:
• Account log in data: name and surname, username – your e-mail or phone number
• ID & communication data: name and surname, postal addresses, e-mail, phone number
• Fiscal / Economic and Tax data: payment method, type of card, transaction value, outstanding balances, vouchers, Gift Cards, refunds, invoice or receipt data
• Transaction / Purchase Data: type of products purchased, transaction value, postal/shipping addresses, time of transaction/purchase, type of card used
• Account Data:
o History of Orders and activity logs on the e-shop and details for the facilitation of your orders
o Demographic data and information, e.g. date of birth, gender
o Additional features / specific characteristics (e.g. skin type, hair type, products and brands you prefer etc)
In addition, we may collect personal data about you from THIRD PARTIES when third parties provide us with your details (e.g. contact, identity) in order to issue and/or send you a Gift Card or send you a gift that they have picked out for you or when you use third party providers to connect to our Website and use our services (Facebook, Viber, Google), upon your notification and consent. In these cases, please consult the third parties’ updates/policies on the processing of your personal data, which are applicable.
We collect AUTOMATICALLY certain Technical Data and data through cookies, such as: Internet Protocol (IP) address, operating system, statistical/pseudonym data, time zone and location, browser type and version, and any other technologies required to access the Website, the devices through which you visit the Website, data about the page from which you logged in or the page you went to when you left the Website, your preferences (duration and frequency at which you view certain products, the type of Newsletters you open or not, your Wishlist, the type of products you buy or place in your shopping cart), the products you have placed in your shopping cart and have not completed your purchase. More details on this can be obtained from our Cookies Policy.
It is clarified that during the payment process, we do not record or store the payment information during this transaction, e.g. credit card numbers etc. You provide this information directly to the respective payment service provider exclusively.
The e-shop and the services provided through it are addressed only to natural persons who have acquired sufficient legal capacity (over 18 years of age). We do not knowingly collect any information from any person under 18 years of age. If you are under 18 years of age, please do not use our Website and do not provide any information to us (i.e.: do not open an account in our e-shop, do not provide your e-mail address for subscription to our newsletter, do not make any purchase and do not provide any information about yourself to us).
4. Collection & Processing of personal data (purpose & legal basis for processing)
The following table aims to inform you about the purposes for which each processing activity (or series of activities) that the Company carries out (with or without the use of automated means) on personal data (or on sets of personal data), such as the collection, storage and transfer of data. It also indicates the legal basis on which each processing activity is based (i.e. the legal ground that allows us to process your personal data in the manner and for the purpose we have indicated).
Processing Purposes
1. Creation and Management of the Account on the e-shop
2. Order Submission and Performance (including after-sale service)
3. Marketing
4. Participation in commercial programs
5. Quality and customer satisfaction surveys
6. Security Measures for the access and use of the e-shop
7. Statistical Analysis for evaluation and optimization of the services of the e-shop and the Company as a business
8. Use of digital tools and services
9. Customer Service Requests management for Users of the Website
PROCESSING ACTIVITES DATA LEGAL BASIS FOR THE PROCESSING
Account Creation and Management (optional)
a) We collect the data you enter when you create an account and process them for the purpose of your registration in our online store and the management and maintenance of your Account. ID Data
Contact Data
Account Data
Log in Data a) The performance of our contractual relationship to create and maintain your Account, confirm your registration, facilitate your orders, track your order history, and manage your payments.
Order Submission and Performance (including after-sale service)
a) We collect your data for the management of your orders and process them for the invoicing and delivery of products, the management and processing of your payments, the issuing and sending of gift cards, the tracking of your order, informing you about its progress
(communication is performed to the means you indicate) a) ID Data
Contact Data
Transaction / Purchase Data
Fiscal Data a) the performance of our contractual relationship by virtue of the purchase and sale contract we have entered into upon your acceptance of the terms and conditions of the e-shop, to which you are a party, and which applies both at the pre-contractual stage, during the term of the contract and for your service after its expiry (especially if you contact us to manage issues relating to your order)
b) We collect and store your data that is necessary for the fulfilment of our tax obligations and for storing proof of our transactions b) Tax data (invoice/receipt data) b) compliance with our legal obligations for the management and maintenance of tax data that derive from the sale contract, and in the case of a legal claim raise by either party
c) We collect the data you share with us in order to assist you when you contact us for issues related to your order (cancellation, defects, returns, etc.)
(communication is performed to the means you indicate) c) Data relating to your order (see a) above: ID, contact, transaction, fiscal)
Data provided for the management of your request c) compliance with our legal obligation for the adoption of tools/means to serve our customers after the sale, pursuant to the purchase and sale contract between us (e.g. to manage your requests, withdrawals, etc.)
Marketing
a) We collect your data for the purpose of directly promoting similar products via email, sms and viber, following the sale of our products to you (i.e. following an order placed by you) ID data
Contact Data
a) our legitimate interest in sending commercial communications to our customers following the submission and execution of the sale contract between us, which in this case is fairly balanced against your privacy and rights.
You can opt-out of receiving such emails by clicking on the unsubscribe button in the communication you receive.
b) We collect your contact information directly from you, if you enter it to subscribe to our newsletter mailing list on our website to send you promotional messages (news about our Company, offers, discounts, promotions, etc.) b) your consent, for the processing of your data for marketing purposes and for receiving relevant updates and promotional e-mails
You can withdraw your consent at any time by clicking the unsubscribe button in the communication you receive.
c) We collect the information you voluntarily provide to us through your Account and the o Additional features / specific characteristics you fill in, if you provide them to us, to send promotional messages for personalized beauty suggestions.  ID Data
Contact Data
Account Data (demographic information, additional features, if you provide them to us) c) you consent for the processing of your Account data, including the more specific characteristics and additional features that you fill in on your Account, if you provide them to us and subject to the activation of the relevant option, for marketing purposes
To withdraw your consent, you can edit your details in the relevant section in your Account and uncheck the options according to which you do not wish to receive commercial communications, or click the relevant button in order to not receive commercial communications based on your Account details at all.
d) We use the data that you have voluntarily disclosed to us through your Account in order to display our Company’s advertisements to you on third-party media and websites, using technologies based on the use of cookies. Account Data
(demographic information, additional features, if you provide them to us)
Cookies Data d) your consent to use your data for marketing purposes, if you have provided your consent to the installation and use of marketing cookies
You can change your cookie preferences from the button at the footer of the website or edit your cookie marketing preferences within your Account.
Participation in Commercial Programs
We collect the data you provide us in the context of specific commercial programs of our Company (e.g. contests) for the purpose of your participation in them and to inform you about their progress. ID Data
Contact Data
Data provided for participation at each commercial program The performance of the contract between us for your participation in the commercial program and for keeping you informed about its progress.
Quality surveys
We collect the data that we ask you to provide voluntarily to conduct quality surveys in relation to your satisfaction with the products and services of our Company and the e-shop. Data relating to each survey Your consent to participate in the quality survey and evaluation of the Company’s products and services and the e-shop
You can withdraw your consent at any time by contacting us at our Company’s contact details
Security measures for access and use of the e-shop
We collect your data to ensure the safe and lawful use of the e-shop Log in Data
Technical Data Our legitimate interest for the adoption of security measures and your identification when accessing the e-shop, your safe navigation and the lawful use of the services of the e-shop.
Statistical Analysis for evaluation and optimization of the services of the e-shop and the Company as a business
We further process the data we collect from your orders and purchases as aggregated and statistical data only, taking all necessary guarantees that do not allow for the identification of the data subjects, in order to perform statistical analysis for the improvement of our products and services. Transaction Data
Account Data
Fiscal Data
Survey Data
Data from participation in marketing activities
*All of the above in aggregate form The legitimate interest of our company for further compatible processing of aggregated data for statistical purposes (research and better understanding of e-shop customers’ needs, improvement of our products and services and development of new ones, adoption of new commercial partnerships, etc.). Our legitimate interest for this further purpose is fairly balanced against your privacy and your rights.
Use of digital tools and services
We collect personal data that you provide for the use of specific tools and services provided through the e-shop (e.g. virtual try-on) Specific data relating to each service / tool Your consent is the sole legal basis for the collection of your personal data when using these services, that only process your data instantaneously.
No personal data is stored when using this service.
Customer Service Requests management for Users of the Website
We collect the personal data you provide us when you contact us in writing (via the contact form, live chat or by phone, if the call is recorded) and process it for the management of complaints and requests you submit to us. ID Data
Contact Data
Transaction Data
Information you provide in relation to your request Depending on the case you consider that you need to be assisted in relation to our Website, processing is carried out on the following legal bases:
a) compliance with our legal obligation to adopt tools / means to service the users of our Website
b) (where applicable) your consent, to receive communication from the Company in relation to your request, following your request in that regard.
You can withdraw your consent at any time by sending an e-mail to the contact details above.
In addition, we may process the above personal data on the basis of our legitimate interest or our Company’s compliance with its legal obligation when we receive documents, requests, orders, legal documents, warrants, etc. from legal authorities or bodies, such as supervisory, prosecutorial, judicial, tax authorities, for the investigation of crimes and your protection against fraud or the fight against all forms of crime and offences.
In addition, we collect data through cookies for various purposes (technical, quality and performance control of our Website and e-shop operation, advertising). More information in relation to how we process the data we collect through cookies can be found in our Cookies Policy.
In the event that we process any of your data that has been provided to us by a third party for the use of services and products from the e-shop, we assume that the third party has received them and provides them to us in the context of and for purposes of private use (e.g. providing a gift, gift card); otherwise, and if so required, we assume that they have received your permission to provide your personal data to us.
5. For how long do we keep your data?
We will retain your personal data for as long as you continue to interact with us and as long as it is necessary to fulfil the processing purposes described above. The data will remain in the e-shop database until you request its deletion (e.g. in the event of a request to delete your account), unless retention is required under a legal obligation (e.g. for tax purposes) or to support a legitimate claim of our Company. In any case, data is deleted immediately after the purposes for which it is retained have been fulfilled, while some data (e.g. any order data) is kept anonymised or pseudonymised for statistical analysis purposes. By way of example, you can see below the retention periods for your data that we process:
5.1. Account Data in the e-shop: We keep your data until your Account is deleted or up to 5 years after your last login.
5.2. Order Data: When you purchase products we will process your data for the period of time required to manage the order, including any returns, withdrawals or claims related to the purchase of the specific product or service. We may retain certain data from your transactions for as long as necessary to comply with our legal obligations (e.g. for tax and accounting purposes, for evidential purposes, etc.).
5.3. Customer and Website Visitors service: The information you provide when submitting your service request (regardless of whether you are our customer or not) is recorded in our systems and kept for as long as required according to the nature of the request submitted, and in any case for at least 6 months from the submission of the latest information you have provided to us in relation to it.
5.4. Marketing: If we do not receive any response to our communication to you for a long period of time, then we will stop sending you promotional communications and delete your history of relevant responses, considering that you prefer not to receive updates. In particular, we will retain your data for marketing purposes until you withdraw your consent or object to us sending you marketing communications, or for up to 3 years from the last time you interacted with us in the relevant means (e.g. opened a newsletter, viber message etc.), whichever comes first.
5.5. Commercial Program: We will retain your data for as long as necessary to complete the program in question.
5.6. Statistical Analysis: We will process your data during a relevant activity (e.g. assessing the marketability of e-shop products) and until we anonymise your data, at which point your data will no longer be held in a way that cannot personally identify you. we reserve the right to keep data that we collect in aggregate form, for an indefinite period of time.
5.7. Use of Digital Tools: The data that you enter in the e-shop for the use of the digital tools and services offered, are not stored by us and are subject to instantaneous processing only.
6. What are your rights and how can you exercise them?
6.1. Τα δικαιώματά σας μπορείτε να τα ασκήσετε στα στοιχεία επικοινωνίας της Εταιρείας μας ανωτέρω. Προς διευκόλυνσή σας, παραθέτουμε κατωτέρω αναλυτικό πίνακα με τα δικαιώματά σας και την σχετική επεξήγηση:
RIGHT EXPLANATION
Access You can ask us to:
– confirm that our Company processes your personal data
– Provide you with access to any personal data that you do not already have in your possession
– obtain relevant information about their processing, such as: what data our Company holds, why it uses it, who it transfers it to, whether it transfers it to third countries, how it protects it, where the Company collected it from if it did not collect it from you, how long it keeps it, what rights you have, how you can lodge a complaint, etc.
Rectification You may request that our Company corrects your inaccurate or untrue data or update it. In this context, our Company reserves the right to verify the accuracy of the data before making the correction and is obliged to inform the recipient to whom the personal data was disclosed, unless this proves to be impracticable or involves a disproportionate effort.
Deletion You can request that your data be deleted if:
– you have withdrawn the consent on which the processing was based
– they are no longer necessary for the purposes for which they were collected
– you find that they are otherwise or unlawfully processed
– you object to the processing
Our Company reserves the right to refuse to allow the exercise of the above right if the processing of the data is necessary (a) for the purpose for which it was collected, (b) to comply with a legal obligation, (c) to establish, exercise or defend legal claims. When you terminate the contracts between us you may request the deletion of your Account and your data. The deletion, will be fulfilled when the above conditions are met.
Restriction of processing You can ask the Company to restrict the processing of youer personal data, i.e. to retain but not use your personal data, when:
– their accuracy is disputed, so that you can verify their accuracy
– the processing is unlawful, but you do not wish to have it erased
– the processing of the data is no longer necessary for the purposes for which it was collected, but our Company still needs it to establish, exercise or defend legal claims
– you object to the processing and are awaiting verification of its effect, i.e. whether our Company’s legitimate grounds prevail over your own legitimate claims
Right to Data Portability You have the right to ask our Company to provide you with your personal data in a structured form or you can request that it be transferred directly to another controller. The conditions for exercising this right are (a) that the data has been provided upon consent or in the context of the performance of the contract and (b) that the data is held by automated means and not on paper (c) that it has been provided by you and that it is not data that has been inferred by our Company on the basis of data provided by you.
Opt-out You may object at any time to any processing of your personal data that is based on (a) legitimate interest, (b) the performance of a duty, (c) profiling. If you exercise this right, our Company may invoke compelling legitimate grounds which, if any, override your rights and freedoms or which pertain to the establishment, exercise, or maintenance of legal claims for the continuation of such processing.
Withdrawal of consent You have the right to withdraw your consent where consent is the basis for processing. You can freely withdraw your consent at any time by requesting it to our Company’s contact details. Any withdrawal is valid for the future and any processing carried out by the Company up to the point of withdrawal is lawful.
Right to human intervention In cases where our Company informs you that it uses certain technical means for the automated processing of your data in order to send you commercial communications without human intervention, you have the right to request human intervention in decision-making through automated processing and to express your opinion on the decision.
Supervisory Authority
Alternative Dispute Resolution You have the right to submit your complaints or a formal grievance to your local supervisory authority about our processing of your personal data. In Greece, the supervisory authority for data protection is the Hellenic Data Protection Authority (www.dpa.gr /) . As the protection of your privacy is a priority for our Company, you can contact us at any time and with any issue or complaint regarding the processing of your personal data.
In addition, our Company suggests that you choose alternative dispute resolution – mediation as a more flexible means of resolving disputes between you and our Company.
6.2. Procedure to exercise your rights
Identity verification: Our aim is to maintain a high level of confidentiality of all records held by the Company that contain personal data, therefore we reserve the right to ask you for certain information to verify your identity if you make a request to exercise your rights in relation to such records.
Timeframes: The timeframe whithin which we aim to respond to your valid and accurate requests is one (1) month of receipt, unless the request you submit to us is particularly complex or you have submitted several requests. If we need more time to respond to your request for the aforementioned reasons, we will notify you accordingly within the month.
Specific requests: In any case, you must provide specific and true information and/or facts so that we can respond and/or accurately meet your request, otherwise we reserve the right to make any errors that are beyond our control. Our Company reserves the right to reject requests that are unfounded, excessive, abusive or illegal.
Costs: You will not have to pay to exercise your rights in relation to personal data unless otherwise provided by law or in cases where the request is unfounded or excessive. In that case, we may charge a reasonable fee. We will inform you for any possible charge before we carry out your request.
7. Third party recipients of your data
7.1. In the context of the proper operation of the e-shop and for the fulfillment of its contractual obligations, our Company cooperates with third party entities that gain access only to as much data as is absolutely necessary for the performance of the tasks with which they have been entrusted so that we are able to provide you with our services and products.
7.2. Indicatively, our Company cooperates with third party entities for the following purposes:
1. Hosting and management of the Website and the e-shop (hosting of databases, administration of the Website), supply and support of information systems
2. Processing of your orders (courier services, shipping, receipt and delivery of products, withdrawal, returns) and collection of money on behalf of the Company (in case of cash on delivery)
3. Advertising and marketing (e.g. to send newsletter)
4. Data analysis, market and customer service surveys
5. Accounting and legal services
6. Financial organizations for the receipt of payments for purchases and institutions for fraud detection and prevention
7. In addition, physical stores with which you interact may receive your data from us in the context of the purchase of products through the e-shop, e.g. in the case of returns of products to the address of a physical store indicated in the withdrawal form, etc.
7.3. All our partners are contractually bound to maintain the confidentiality of the personal data transmitted to them by us, as well as to take all technical and organisational measures for secure processing and not to use your information in any way other than to help us provide you with the products and services we have agreed.
7.4. We reserve the right to disclose your personal data to a third party to whom we choose to transfer all or part of our business. In addition, in the event of a merger or acquisition, or other change in our business, the new owners, shareholder managers etc., have the right to use your personal data in the same way as set out in this Policy.
7.5. When transmitting your personal data, we continuously ensure the highest possible level of security. The Company generally keeps your personal data within the European Economic Area (EEA). In the event that data is to be transferred to third countries outside the European Economic Area for which there is no adequacy decision of the European Commission, or to International Organisations, all appropriate safeguards provided for in applicable legislation and in the decisions and directives of the competent European institutions for the protection of personal data concerning transfers to third countries will be taken and the relevant information will be posted on the Website.
7.6. Your personal data may be disclosed to the competent judicial, police and other administrative authorities upon their legitimate request and in accordance with the applicable legal provisions. In addition, in the event of a legal provision, governmental order or official preliminary investigation, the Company shall have the right to make the relevant data available to the relevant authority without any prior actions.
8. Data Security
8.1. The Company takes all necessary technical and organizational security measures to protect and ensure the privacy of your personal data (e.g. Firewalls, Antivirus, Access rights control, PCI Security Standards, Service Organization Control (SOC), special software to counter malicious actions and reCAPTCHA, to certify that access to specific fields of the Website is not performed by a bot).
8.2. For the performance of the processing activities, the Company selects persons with appropriate professional qualifications that provide sufficient guarantees in terms of technical knowledge and personal integrity to ensure confidentiality. The Company, through its respective contractual commitments and its partners, undertakes all necessary security measures to protect and ensure the privacy, confidentiality and integrity of personal data. In any case, the security of such data in the website environment is subject to events beyond the Company’s sphere of influence, as well as errors due to technical or other network deficiencies beyond the Company’s control, or reasons of force majeure or fortuitous events.
8.3. You must not disclose the access details to your Account and ensure that no unauthorised access is performed to it by third parties.
9. Changes to this Policy
We reserve the right to modify this Policy, for instance, in order to comply with new requirements imposed by applicable laws, directives, or technical requirements, or in the event of a revision of our procedures or practices. We will notify you of any revision to our Privacy Policy by posting it on our Website. We therefore encourage you to check this page regularly. Should you require any clarification or information regarding the changes, or have any disagreement, reservation or query relating to them (changes), you may contact us at the details listed above. Please note that any information or clarification provided to you in accordance with the above does not constitute a replacement, substitution or any amendment to this Policy.

Get 10% OFF in Your First Order

    By subscribing, you agree to our Terms of Use and Privacy Policy.

    Call now