EU & Hellenic Legal Compliance (GDPR & Law 4624/2019)

Privacy Policy

Chris Bacco Laboratory (Cosmetic Research, Manufacturing & E-Commerce Store) is committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR 2016/679), Greek Law 4624/2019, Law 3471/2006, and EU Consumer Protection Directives.

1. Data Controller Information

The Data Controller for the processing of your personal data collected through this website and online store is:

  • Entity: Chris Bacco Laboratory (Laboratory for Cosmetic Research & Manufacturing)
  • Address: Agiou Vlassiou 56, P.C. 204 00 Xylokastro, Corinthia, Greece
  • Contact Email: info@chrisbacco.com
  • Regulatory Supervision: Hellenic National Organization for Medicines (EOF) & Ministry of Development

2. Categories of Personal Data We Collect

We process data depending on your interaction with our laboratory services and e-commerce store:

🛒 E-Commerce & Online Store Purchases

  • Full Name, Shipping Address, Billing Address
  • Email Address & Phone Number for Delivery Updates
  • VAT Number (AFM) & Tax Office (DOY) for Invoices
  • Order History, Cart Items, and Transaction IDs

🔬 B2B Laboratory & R&D Consultations

  • Professional Title, Company/Brand Name
  • Formulation Specifications & Project Technical Scope
  • Product Information File (PIF) & Regulatory Compliance Data
  • Cosmetovigilance & Adverse Reaction Reports (EC 1223/2009)

3. Legal Basis & Purposes of Processing

Your personal data is processed under the following lawful bases pursuant to Article 6(1) GDPR:

  • Contract Execution (Art. 6(1)(b) GDPR): Processing e-shop orders, processing payments, delivering products, and fulfilling formulation contracts.
  • Legal Obligation Compliance (Art. 6(1)(c) GDPR): Tax and accounting compliance under Greek Tax Legislation (Law 4308/2014 - AADE), invoice issuance, and Cosmetovigilance safety reporting under EU Cosmetics Regulation (EC 1223/2009).
  • Legitimate Interest (Art. 6(1)(f) GDPR): Ensuring website security, fraud prevention in online transactions, and improving R&D services.
  • Consent (Art. 6(1)(a) GDPR): Sending newsletters, promotional material, or analytical cookies (with explicit prior opt-in).

4. Payment Security & Data Recipients

We strictly limit data sharing to authorized third-party service providers required for fulfilling e-commerce orders and lab operations under strict Data Processing Agreements (DPAs):

  • Payment Processors (PCI-DSS Certified): Online payments are processed directly by encrypted, certified payment gateways (e.g. Viva Wallet, Stripe, PayPal, or Bank Transfer). Chris Bacco Laboratory NEVER stores credit or debit card numbers on its servers.
  • Couriers & Logistics: Recipient delivery details are transferred to courier partners (e.g. ACS Courier, Geniki Taxydromiki, DHL) solely for shipping products.
  • Accounting & Tax Authorities: Transaction data is transmitted securely to our certified accounting partners and the Hellenic Independent Authority for Public Revenue (AADE / myDATA).

5. Data Retention Period

  • E-Commerce Tax & Transaction Records: Retained for 10 years as required by Greek Tax Law (AADE).
  • B2B R&D & Product Information Files (PIF): Retained for 10 years following the placement of the last product batch on the market (EU 1223/2009).
  • Customer Account & Inquiry Data: Retained until account deletion or request for erasure, unless statutory obligations apply.

6. Your Rights Under GDPR

As a data subject in the European Union, you hold the following rights:

• Right of Access (Art. 15): Request a copy of your personal data.
• Right to Rectification (Art. 16): Correct inaccurate data.
• Right to Erasure (Art. 17): Delete data ("Right to be Forgotten").
• Right to Restriction (Art. 18): Limit data processing.
• Right to Data Portability (Art. 20): Receive data in a structured format.
• Right to Object (Art. 21): Object to direct marketing or processing.

To exercise any of your rights, contact our Data Protection Lead at info@chrisbacco.com. You also maintain the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) at www.dpa.gr.