Before using our Website, please read this Data Protection and Privacy Policy (hereinafter referred to as “the Policy”) carefully. This Policy applies to all users of the Website, as well as to citizens regarding the collection and use of their personal data by the Municipality, in accordance with the provisions of the General Data Protection Regulation (EU) 2016/679 (“GDPR”).
As the Data Controller, the Municipality informs you about how it collects and processes information concerning you.
Personal Data means any information relating to an identified or identifiable natural person (hereinafter “Personal Data”).
The protection of your Personal Data is very important to the Municipality, which takes measures in this regard whenever it collects Personal Data from you. This Data Protection Policy (hereinafter “the Policy”) describes the type of information we may collect during our collaboration and informs you about how we use that information. When you voluntarily provide us with personal information, such as your name, address, or email address, either independently or in the context of submitting a request, we treat such information with absolute confidentiality. Unless otherwise specified in this Policy, no personal information will be rented, sold, publicly disclosed, or shared with other municipalities, companies, or organizations.
This Policy applies to all parties associated with the Municipality (citizens, partners, suppliers, etc.). It governs the collection and use of your personal information by the Municipality (e.g., information identifying a specific person such as full name or email address).
The EU Regulation 2016/679 on the Protection of Personal Data (GDPR) came into effect on Friday, 25 May 2018, and was revised on Monday, 1 January 2024.
A. Directly from you:
We collect Personal Data directly from you when you visit our Website, request information, submit a request, or contact any of the Municipality’s departments. Specifically, you provide your Personal Data in the following cases:
Procurement competitions or direct awards
Drafting contracts for the supply of goods/services, projects, etc.
Provision of social protection and solidarity services, sports, educational and lifelong learning programs, and other advisory actions
Submission of applications to various municipal departments for technical or other services
Submission of applications to Citizens’ Service Centers (K.E.P.) for the provision of services or issuance of certificates
Submission of job applications (when the application is made directly to the Municipality)
Submission of a request or inquiry via your account in the Municipality’s electronic request system or by email.
B. Automatically through Website use:
When you visit the Municipality’s Website, we may collect data from you based on your browsing and use of our services. Such data may include browsing history, IP address, screen resolution, browser type, operating system and settings, access times, and referring URLs, as well as data collected through cookies (see our Cookies Policy).
C. From third parties:
If you connect to the Municipality’s Website via a third-party service (e.g., Facebook, Instagram, Twitter, YouTube), that third party may send us information such as your registration details and profile information from that service. These details vary and are controlled or authorized by you through your privacy settings in the respective service.
The information collected from citizens includes Personal Data and details required by applicable law for the execution of a contract/provision of services between the Municipality and the citizen, or for the provision of any other public-interest services within the scope of social protection, education, and sports.
The information collected from our suppliers includes the data required by tax legislation for the provision and payment of supplies.
The information collected from our partners includes Personal Data and details required by applicable law for the execution of contracts between the Municipality and the partner, such as contact information, personal details, banking and financial data, etc.
When you visit the Municipality’s Website, we may collect the following Personal Data (which may vary depending on your use of the Website):
Name
Surname
Email address
Telephone number
Postal address
Any information included in your application text submitted through the Municipality’s electronic request system or your general communication with us
Browsing data such as IP address, screen resolution, browser used, operating system and settings, access times, URL, and cookie data.
The purpose of collecting/processing data is to provide citizens with information about the Municipality and its services, events, and initiatives; to communicate effectively with Website users and citizens; to support, promote, and organize actions related to citizens; and to ensure the security of transactions. Specifically, we use your data:
To allow you to access and use our Website and the services provided through it.
To respond to citizen service requests submitted through Citizens’ Service Centers (K.E.P.).
To issue certificates electronically through the Municipality’s online request system (e.g., marriage license, financial aid, etc.).
To send notifications about events or other municipal activities.
To resolve complaints or daily issues submitted electronically via the Citizen Service Office.
To detect and prevent fraud, misuse, security incidents, and other harmful activities.
To ensure compliance with legal obligations.
To improve our services and Website user experience by troubleshooting, enhancing functionality, and adapting our online presence to your needs.
The Municipality does not transfer Personal Data collected from you to countries outside the EU or the EEA.
The Municipality collects only the Personal Data necessary to fulfill its public duties and to serve citizens within its operational framework. Where additional optional information is requested, you will be informed at the time of collection.
According to Greek and EU law (including the GDPR), we process Personal Data only when we have a lawful basis to do so. Accordingly, we rely on one of the following legal grounds:
Contract performance: When processing is necessary to fulfill or comply with contractual obligations.
Legal obligation: When processing is necessary for compliance with legal requirements (e.g., tax, insurance, or accounting obligations).
Public interest: When processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority, such as public safety, employment promotion, or support of vulnerable social groups.
Consent: When we request your specific consent to process certain Personal Data. You may withdraw your consent at any time by contacting the Municipality’s Data Protection Officer, at info@nafpaktos.gr.
We use your Personal Data to provide our services and perform all lawful actions required for that purpose.
Your Personal Data may be shared with third parties for financial/tax purposes, legal compliance, or service provision on your behalf. Specifically, recipients may include:
Municipality employees
External partners providing accounting, auditing, internet, or technical support services
Public authorities such as EOPYY, various Ministries (Justice, Health, etc.), Tax Offices, ERGANI, insurance funds, DIAVGEIA, judicial authorities, OAED, and others.
Additionally, through our Website, the Municipality provides access to the following third-party platforms:
Health KEP: In this case, the Municipality acts as a Joint Data Controller with the “National Intermunicipal Network of Healthy Cities – Health Promotion (EDDYPPY).” Since EDDYPPY remains responsible for operating the “Health KEP” platform and processing Personal Data submitted upon registration, the Municipality advises users to consult EDDYPPY’s Privacy Policy before accessing the service.
Gov.gr: For your convenience, you may connect directly to the gov.gr platform of the Ministry of Digital Governance. The Municipality bears no responsibility for the collection or processing of Personal Data by that platform and advises users to review its Privacy Policy at https://www.gov.gr/info/politiki-aporritou before submitting their information.
Our data centers, where Personal Data are stored, are located in Greece, at the Municipality’s headquarters.
The retention period of Personal Data is determined by applicable legal or tax obligations (e.g., contract duration). Depending on the processing purpose, retention is defined as follows:
Requests or applications submitted via the Municipality’s electronic system are retained for as long as necessary to serve and resolve your request. Newsletter data are retained until you unsubscribe.
Data related to beneficiaries of municipal social, educational, or sports programs are deleted when:
Consent is withdrawn,
The individual ceases to be a participant or beneficiary, or
Data are no longer current,
unless retention is required by law (e.g., tax, labor, social security, or medical regulations).
Employee and external collaborator data are deleted after the statutory retention period following contract termination.
Supplier data are retained for the duration of the contract and as legally required thereafter.
Citizen service applications and their accompanying documents are deleted after processing unless legal grounds require otherwise.
We may also retain Personal Data:
To comply with ongoing or potential legal proceedings, or
To protect and defend our legal rights or user/public safety.
After the applicable retention period expires, your Personal Data are permanently deleted.
The Municipality maintains official accounts on Facebook, Instagram, YouTube, and Twitter. Our Website includes social media plug-ins inviting users to follow, like, or comment. When using these platforms, certain Personal Data (e.g., profile data) may be collected.
According to the jurisprudence of the European Court of Justice, the Municipality is considered a Joint Controller with the respective social media platform. The Municipality takes appropriate technical and organizational measures to ensure the secure processing of data (e.g., limiting administrative access).
The purpose of processing is to promote the Municipality’s image and activities, provide updates, and communicate with users.
The legal basis is your consent, expressed by clicking “like” or “follow.” You may withdraw consent at any time by selecting “unlike” or “unfollow.”
The Municipality is not responsible for how each social media platform processes your data. Please consult the privacy policies of Facebook, Instagram, YouTube, and Twitter for details.
You have the right to:
Access your stored Personal Data free of charge at any time.
Request correction or updating of your data.
Request deletion of your data (unless retention is legally required).
Request cessation or restriction of processing (where feasible).
Request transfer of your data to another entity.
File a complaint with the Hellenic Data Protection Authority if you believe your data have been unlawfully processed.
To exercise your rights or ask questions about this Policy, contact the Municipality’s Data Protection Officer at info@nafpaktos.gr.
The Municipality, its employees, contractors, and representatives are committed to implementing appropriate technical and organizational measures to ensure optimal protection of Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
The Municipality also requires all service providers and partners to handle Personal Data confidentially and in compliance with GDPR obligations.
These measures ensure that processing is carried out in accordance with the GDPR, considering the nature, scope, context, and purposes of processing, as well as potential risks to individuals’ rights and freedoms.
The Municipality may amend this Policy. Please check the Effective Date at the top of this Policy to see when it was last revised. Any revision takes effect upon publication.
If material changes are made that expand our right to use your previously collected Personal Data, we will notify you and provide the opportunity to choose whether to allow such future use.