EU GDPR (2016/679), Greek Law 4624/2019 & Law 3471/2006 Compliance

Privacy Policy

Chris Bacco Laboratory (Cosmetic Research, Manufacturing & E-Commerce Store) is committed to protecting your personal data in strict compliance with the European Union General Data Protection Regulation (GDPR 2016/679), Greek Law 4624/2019, Greek Law 3471/2006, the EU ePrivacy Directive (2002/58/EC), and EU Cosmetic Regulation (EC 1223/2009).

1. Data Controller Information

The Data Controller responsible for collecting and processing your personal data through this website, R&D portal, and online store is:

🏢 Chris Bacco Laboratory

Entity: Laboratory for Cosmetic Research, Formulation & Manufacturing

Facility Address: Agiou Vlassiou 56, P.C. 204 00 Xylokastro, Corinthia, Greece

Data Protection Lead Email: info@chrisbacco.com

Regulatory Supervision: Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) & Hellenic National Organization for Medicines (EOF).

2. Age of Consent (Greek Law 4624/2019 Article 21)

Pursuant to Article 21 of Greek Law 4624/2019, the minimum age of valid consent for information society services (including accepting cookies, submitting contact forms, or creating e-commerce accounts) is set at 15 years old.

If you are under 15 years of age, you must obtain prior verifiable consent or authorization from your parent or legal guardian before providing any personal data on this website.

3. Categories of Personal Data We Collect

We process data depending on your interaction with our laboratory services and e-commerce store:

🛒 E-Commerce & Online Store Purchases

  • Full Name, Shipping Address, Billing Address
  • Email Address & Phone Number for Delivery & Order Tracking
  • VAT Number (AFM) & Tax Office (DOY) for Commercial Invoices
  • Order History, Cart Items, Transaction Reference IDs

🔬 B2B Laboratory & R&D Consultations

  • Professional Title, Company/Brand Name
  • Formulation Specifications & Technical Project Scope
  • Product Information File (PIF) & Regulatory Dossier Data
  • Cosmetovigilance Safety & Adverse Reaction Reports (EC 1223/2009)

4. Legal Bases & Statutory / Contractual Requirements (GDPR Art. 13)

We process your personal data under the following lawful bases pursuant to Article 6(1) GDPR:

A. Contractual Requirement (Art. 6(1)(b) GDPR)

Processing is necessary for executing e-commerce purchase orders or delivering B2B formulation research contracts. Providing your identity, contact, delivery, and payment details is a contractual requirement. Failure to provide this data will make it impossible for us to fulfill your order, process payment, or issue safety certificates.

B. Statutory & Legal Obligations (Art. 6(1)(c) GDPR)

Processing is required by law under Greek Tax Code (Law 4308/2014 - AADE / myDATA) for invoice issuance, and under EU Cosmetics Regulation (EC 1223/2009) for safety record retention and Cosmetovigilance reporting. Mandatory under Greek tax law; without required tax details (AFM), commercial invoices cannot be legally issued.

C. Legitimate Interest (Art. 6(1)(f) GDPR)

Ensuring IT security, preventing fraudulent e-commerce transactions, and defending against legal claims.

D. Consent (Art. 6(1)(a) GDPR)

Submitting contact inquiries or activating analytical cookies (Google Analytics). You have the explicit right to withdraw consent at any time without affecting prior lawful processing.

5. International Data Transfers to the United States (GDPR Art. 44–50)

Some third-party technical services we utilize (e.g. Google Analytics `G-D0T6X9DCSH`, Web3Forms contact submission API, US cloud providers) process and store data on servers located in the United States. Under GDPR Chapter V, these constitute restricted international data transfers outside the European Economic Area (EEA).

1. EU-US Data Privacy Framework (DPF) Adequacy Decision

For certified US entities (such as Google LLC), transfers rely on the European Commission's DPF Adequacy Decision pursuant to Article 45 GDPR, confirming that certified US companies maintain adequate privacy protections equivalent to EU standards.

2. Contact Form Processing (Web3Forms) & SCCs

Contact form submissions (name, email, technical project brief) are encrypted in transit via HTTPS JSON API to Web3Forms, acting as a data processor. Web3Forms forwards messages securely to info@chrisbacco.com. For US processing services not covered by DPF, data transfers rely on standard contractual clauses (SCCs) adopted by the European Commission pursuant to Article 46(2)(c) GDPR.

3. US CLOUD Act & Technical Safeguards

We recognize that US service providers may be subject to foreign law enforcement access requests under the US CLOUD Act. To safeguard your data against unauthorized access, we implement strict technical measures including TLS 1.3 transport encryption, AES-256 storage encryption, IP anonymization, and pseudonymization.

6. Independent Data Controllers vs Processors

We clearly distinguish between third-party service processors operating under a Data Processing Agreement (DPA) and independent data controllers:

  • Independent Data Controllers (Payment Gateways): Payment service providers (such as Stripe Inc., PayPal Europe S.à r.l., Viva Wallet S.A., Alpha Bank, Piraeus Bank, Eurobank, NBG) act as Independent Data Controllers under PCI-DSS regulations for financial verification, fraud monitoring, and banking compliance. They process your financial data under their own independent privacy policies.
  • Data Processors (Web3Forms, Logistics & Cloud): Form processing services (Web3Forms), courier partners (ACS, Geniki Taxydromiki, DHL), and technical cloud hosts act as data processors bound strictly by privacy terms to process your contact and shipping data solely on our instructions.

7. Google Analytics & Google Consent Mode v2

We use Google Analytics (`G-D0T6X9DCSH`) to evaluate aggregate, anonymized website usage metrics.

  • Google Consent Mode v2: Analytical storage (`analytics_storage`) and advertising storage (`ad_storage`) default to `denied` until you provide explicit opt-in consent via our banner.
  • IP Anonymization: IP addresses are truncated and anonymized before storage.
  • Opt-Out Mechanism: You can revoke consent at any time via our Cookie Policy page or using the Google Analytics Opt-Out Browser Add-on.

8. Automated Decision-Making & Profiling (Art. 22 GDPR)

Chris Bacco Laboratory does NOT use automated decision-making or profiling algorithms that produce legal effects or significantly affect users under Article 22 GDPR.

9. Data Retention Schedule

  • Tax & Invoicing Records: Retained for 10 years as required by Greek Tax Legislation (AADE).
  • Cosmetic PIF & Safety Records: Retained for 10 years following the placement of the last product batch on the market (EC 1223/2009).
  • User Inquiries & Account Data: Retained until request for erasure or account deletion, unless statutory obligations apply.

10. Your GDPR Rights & Right to Withdraw Consent

Under Articles 15–22 of the GDPR, you maintain the following fundamental rights:

• Right of Access (Art. 15): Request a copy of processed personal data.
• Right to Rectification (Art. 16): Correct inaccurate or incomplete data.
• Right to Erasure (Art. 17): Request data deletion ("Right to be Forgotten").
• Right to Restriction (Art. 18): Restrict processing under legal conditions.
• Right to Data Portability (Art. 20): Receive your data in a structured format.
• Right to Object (Art. 21): Object to processing or direct marketing.
🔄 Explicit Right to Withdraw Consent (Art. 13(2)(c) GDPR)You have the absolute right to withdraw your consent at any time for consent-based processing (marketing, analytical cookies) without affecting the lawfulness of processing carried out prior to withdrawal.

To exercise any of your rights or submit a privacy inquiry, contact our Data Protection Lead at info@chrisbacco.com. You also maintain the statutory right to lodge a complaint with the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ):

  • Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
  • 1-3 Kifissias Ave., P.C. 115 23, Athens, Greece
  • Website: www.dpa.gr | Email: contact@dpa.gr