Privacy and Personal Data Protection Policy
General Information on the Processing of Your Personal Data by MAZI SOU MAMA A.M.K.E. (Privacy Policy – Data Privacy Notice)
The protection of your privacy and personal data is our priority.
At MAZI SOU MAMA A.M.K.E., we fully understand how important the safeguarding of your personal data is. This document outlines the terms and conditions under which the non-profit civil company under the name “MAZI SOU MAMA NON-PROFIT CIVIL COMPANY”, with the distinctive title “MAZI SOU MAMA A.M.K.E.”, headquartered in Athens, 6 Grivogiorgou Street, TIN: 996608089, G.E.MI. Number: 171477301000 (hereinafter referred to as the “Company”), processes the personal data of users and beneficiaries of the Company.
This notice applies to all beneficiaries of the Company’s programs and their families. For this reason, we take all necessary measures to ensure the security and proper handling of your data.
Section 1
What personal data do we process?
The term personal data refers to any information that relates to you and through which you can be identified. This identification may occur either through specific information or through a possible combination of information that we have at our disposal.
As a provider of services and support in line with its non-profit objectives (as described in Section 3: “For what purposes do we process your personal data?”), the Company processes the following categories of personal data:
Basic Personal Data
A) Data collected prior to or during your participation in the Company’s programs and activities/events (hereinafter referred to as Participation Data), such as your full name, ID card number, passport number or other identification document, Tax Identification Number (TIN), residential or mailing address, date of birth, occupation, nationality, and contact information (e.g., telephone number, email address, Social Security Number – AMKA).
Please note that in cases where support and services are provided through specific programs (e.g., programs intended for Persons with Special Needs), we may process, in a very limited manner, special categories of personal data (e.g., disability certificates), in order to make these programs as accessible as possible with minimal restrictions.
Regarding the data processed for the purpose of beneficiary verification, please refer to Section 3.3.7 “For the purpose of conducting creditworthiness checks, in order to safeguard our legitimate interests and the interests of prospective beneficiaries of the program.”
B) Customer Support Data. This includes information related to communications between you and the Company (hereinafter referred to as Support Data), such as the history of your communications with the Company and, in particular, any recorded conversations with the Customer Support Department for the purpose of verifying communication and consent, or for other similar legitimate business purpose This also includes requests or complaints submitted to the Beneficiary Support Department, or any other form of communication you had with us (e.g., via email, chat, Company representative), as well as the timing and method of resolving your complaints.
C) Service Usage Data (hereinafter referred to as Usage Data) – This refers to data related to your overall use of the Company’s services, such as aggregated data displayed in your personal profile or account record.
D) Survey Participation Data (hereinafter referred to as Survey Data) – This includes information regarding surveys you have received or participated in, and your responses to those surveys.
D) Benefits & Gifts Data (hereinafter referred to as Benefits Data) – This includes information about any gifts or benefits you have received, related communications you have received from the Company, and the date/time of delivery or receipt.
The processing of your personal data is governed by the General Data Protection Regulation (GDPR) and Greek Law 4624/2019.
Section 2
What is the processing of personal data?
The processing of personal data refers to any operation or series of operations performed on your personal data or on sets of personal data. These operations may include, for example: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
Rest assured that any information you entrust to us is secure, because:
- We retain only the personal data that is strictly necessary, depending on the purpose of the processing.
- We process the data in a manner that ensures its security and protection from unauthorized or unlawful access and processing, as well as from accidental loss, destruction, or damage, by employing appropriate technical and organizational measures.
Please note that this document serves as the general notice provided by the Company regarding the processing of personal data during the provision of our services.
Section 3
For what purposes do we process your personal data?
To facilitate your participation in the Company’s programs and activities, we process the data referred to in Section 1 (“What personal data do we process?”) for the following purposes: submitting your application to participate in the Company’s programs and activities, and providing the Company’s services to participating beneficiaries.
To process your participation, we will request the information necessary for the submission and approval of your application, such as your full name, Tax Identification Number (TIN), ID or passport number, address, and contact details (phone number and/or email). We may also request proof of identity, such as an ID card or passport.
For the purpose of handling your requests through the Company’s support channels (e.g., call center, email, Company representatives), we process your data to verify your identity and respond to your inquiries. These requests may include, but are not limited to, requests for information, exercising your rights, complaints, or reports.
We process your personal data based on your consent.
In some cases, the Company may process your data based on additional legal bases, but consent remains a key foundation for processing.
With your explicit consent, we may also combine personal data collected through the services we provide in order to create your individual beneficiary profile, based on your preferences and particular needs.
Profiling is a form of automated processing of your personal data through which we may assess certain preferences—such as predicting products or services that might interest or benefit you—and send you relevant updates tailored to your interests.
Please read the document where the relevant consent is provided here.
We process your personal data based on the legitimate interest of the Company or our subscribers
The Company also processes your personal data based on its legitimate interests, while always taking into account your own rights and interests as a beneficiary. These types of processing activities, based on our legitimate interest, are carried out only after a careful assessment of our interests against the need to protect your personal data. Such processing is limited to what is strictly necessary and expected, and compatible with our service relationship.
Specifically, we process your data:
- For the direct provision of our services and the support of beneficiaries.
We process a limited set of your personal data, strictly for the purpose of providing our services in accordance with your needs. Our communication with you will take place via the contact information you provided during your application to participate in the Company’s programs. - For handling customer service matters, such as questions, complaints, reports of harassment, and requests related to our services, in order to offer prompt and effective support.
- After the end of your participation in the Company’s programs or activities, for any reason, and after resolving any outstanding matters between us—and once the data retention period, as defined by the applicable legal and regulatory framework, has passed—the Company will retain only your full name, and only with your consent. No other type of personal data will be kept. This allows us to identify you as a former beneficiary in case of any future communication with you.
For sending satisfaction or evaluation surveys regarding the products, services, or customer support we provide. We process a limited scope of your personal data—specifically Participation Data, Support Data, and Benefits Data—for the purpose of sending satisfaction or evaluation surveys related to the services or support we provide to you. These surveys are in the form of questionnaires and may be sent to you via SMS, email, or conducted through outbound phone calls. In some cases, the surveys may be carried out by partner companies on our behalf. If you choose to participate in a survey, we will analyze your responses and may contact you based on your feedback.
- We process your personal data to comply with our legal obligations
The Company processes personal data in order to comply with applicable legal and regulatory requirements.
For the transfer of data to competent authorities
The Company may process your personal data in order to transmit it to the competent police, prosecutorial/judicial, or regulatory authorities, upon receiving a valid legal request, and for the purpose of complying with applicable laws and regulations.
For compliance with the applicable corporate governance regulatory framework
As part of our compliance with the applicable corporate governance framework (Laws 4548/2018 and 4706/2020), we process personal data necessary for the functioning of the Company. For example, we process personal data for the issuance and auditing of the Company’s financial statements, as well as for the implementation of internal audit and regulatory compliance procedures.
We process your personal data for the purpose of protecting your vital interests or the interests of other natural persons
This includes, for example, the provision of information to the competent authorities responsible for responding to emergency situations, to ensure the protection and safety of individuals.
We further use your personal data for the following purposes:
To improve the services provided, the level of customer care, and beneficiary support
The Company is committed to the continuous improvement of the services we offer you, as well as to ensuring a high standard of support and customer service. For this purpose, we additionally process:
- Basic Personal Data, in order to draw conclusions about the use of our services and the level of support offered.
For example, we may process your Participation Data and Support Data to generate statistical insights—such as the average response time of our Beneficiary Support Team to incoming requests. - Basic Personal Data, to better understand how our services and activities are used. These insights help us improve existing services, design new ones, develop support mechanisms, and make informed business decisions.
- Participation Data, to assess the effectiveness of our advertising campaigns and to enhance the planning of future campaigns.
To promote scientific research through the use of anonymized data
As part of its participation in European research programs, the Company may share anonymized data with partner organizations. These data sets may include Participation Data and are used to generate useful statistical insights relevant to their research objectives.
The Company also uses anonymized data internally to extract meaningful insights and to improve its internal processes.
These activities constitute compatible further processing of personal data. In evaluating their legitimacy, the Company has considered several key factors, such as: the relationship between the original and further processing purposes, the reasonable expectations of our beneficiaries, the nature of the personal data, the potential impact of further processing, and the safeguards implemented by the Company to protect the data.
Section 4
Who will process your personal data?
In addition to the Company itself, your personal data may also be processed by our partners or third-party companies. However, the Company remains solely responsible for the security of your personal data and takes all necessary measures to ensure it, including:
- Selecting partners based on the high technological and organizational security standards they offer.
- Establishing contractual agreements with each company before any collaboration involving the processing of personal data, to guarantee a high level of protection for your personal data.
Your data is primarily processed within Greece and the European Union (EU). If we collaborate with companies outside the EU, your data will only be processed under our instruction and only if:
- There is an adequacy decision by the European Commission regarding the respective country, or
- Appropriate contractual clauses are in place to ensure a high level of data protection during processing.
We mainly collaborate with companies or independent professionals operating in the fields of research, IT, and consulting services.
Section 5
How long will we retain your personal data?
Your personal data will be retained for as long as necessary to fulfill the purpose for which it was collected, or, in cases where the retention period is defined by applicable legislation, for the legally required duration. Once this retention period has expired, your personal data will either be deleted in a manner that makes recovery technically impossible or will be anonymized.
If you have given your consent for the creation of a profile and/or the retention of profile-related data after the end of your participation, the specific retention periods outlined below will apply.
In particular, Participation Data and Support Data will be retained for as long as you are an active beneficiary of the Company’s programs. After the termination of your participation—regardless of the reason—your personal data will be kept in our beneficiary support systems for a period of fourteen (14) months from the date of termination.
Section 6
What measures do we take to protect your data?
At the Company, we integrate appropriate technical and organizational measures into our corporate procedures and apply them across the IT systems and platforms used to collect, process, or use personal data.
These measures include, but are not limited to:
- Access control measures to prevent unauthorized individuals from accessing data processing systems (physical access control).
- System access control to ensure that data processing systems cannot be used by unauthorized persons (logical access control).
- Data access control, ensuring that authorized users of data processing systems have access only to the data they are authorized to handle, and that personal data cannot be transferred, copied, altered, or deleted by unauthorized persons during processing, use, or after being stored.
- Data transmission control, to ensure that personal data cannot be transmitted, copied, altered, or removed by unauthorized persons during electronic transmission, transport, or storage. These measures also allow for verification and identification of the individuals or systems to which personal data has been transmitted via data transmission equipment.
- Data entry control, to ensure that it is possible to retrospectively examine and verify whether and by whom personal data was entered into, modified, or deleted from data processing systems.
- Processor control, to ensure that personal data processed by third-party processors or contractors is handled solely in accordance with our instructions.
- Separation control, to ensure that data collected for different purposes can be processed separately (purpose limitation and data segregation principle).
Section 7
What are your rights regarding your personal data?
As a beneficiary, you have the following rights regarding your personal data:
Right of access: You have the right to be informed about the personal data we process about you (e.g., the purposes of processing, the types of data, the recipients to whom the data is disclosed, and the retention period) and to request and receive a copy of this data.
Right to rectification: You have the right to request the correction of your personal data (e.g., updating your address, contact details, or ID number).
Right to erasure (“right to be forgotten”): You have the right to request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected or if you withdraw the consent based on which the data was collected and processed.
Right to restrict processing: You have the right to request that the processing of your personal data be restricted for a specific purpose.
Right to data portability: You have the right to receive the personal data you have provided to the Company in a structured, commonly used, and machine-readable format (e.g., receiving data stored on a cloud platform).
Right to object to processing: You have the right to object to the processing of your personal data if you no longer wish for your data to be processed.
For any request or information regarding the protection of your personal data, you can send an email to: info@mazisoumama.com To exercise your rights, you may: Send an email to info@mazisoumama.com, or Send a letter to the following address:
Beneficiary Support Department, 6 Grivogiorgou Street, Athens, GR-11528.
Please include “Exercise of Data Subject Rights” in the subject line, and clearly state your full name, Tax Identification Number (TIN), and the address where you wish to receive a response.
If you believe that your request has not been satisfactorily addressed, or that your personal data has been infringed in any way, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) via its online complaint portal.
Contact details of the Authority:
1-3 Kifisias Ave., Athens GR-115 23 | Tel: +30 210 6475600
Detailed instructions for submitting a complaint are available on the Authority’s website.
The Company will respond to your request free of charge and within one (1) month of its receipt. In exceptional cases, this deadline may be extended by up to two (2) additional months, if necessary due to the complexity of your request. In all cases, you will be informed of any such extension and the reason for the delay.
If we determine that your request is manifestly unfounded or excessive, we reserve the right to request the payment of a reasonable fee to process it—taking into account the administrative costs involved—or even to refuse to act on the request altogether.
This Privacy Policy is updated whenever necessary.
If there are significant changes to our Policy, we will update the relevant text accordingly before the changes take effect and will make every reasonable effort to notify you by all appropriate means.
This Policy was last updated on February 3, 2025.