Privacy Policy

Who we are

Last Updated: July 2026]

Introduction and Data Controller

Suggested text: When visitors leave comments on the site we collect the data shown in the comments form, and also the visitor’s IP address and browser user agent string to help spam detection.

This Privacy Policy determines how [Insert Legal Business Name / Company Name] (referred to as “the Lab”, “we”, “us”, or “our”), operating a laboratory for cosmetic checks, measurements, and chemical/microbiological analysis based in Greece, collects, uses, processes, and protects your personal data.

We act as the Data Controller for the personal data processed through our website [Insert Website URL] and during the provision of our professional testing services.

  • Company Name: [Insert Full Official Name & Legal Form, e.g., XYZ Cosmetics Lab Single Member P.C.]
  • Registered Office: [Insert Full Physical Address, Greece]
  • GEMI Number (General Commercial Registry): [Insert GEMI Number]
  • Email Contact: [Insert Privacy/General Email]
  • Phone: [Insert Phone Number]
  • Data Protection Officer (DPO): [Insert DPO Name & Contact Info, or state: "Inquiries can be directed to our privacy team at [Email]"]

Categories of Personal Data We Collect

We only process data that is strictly necessary to optimize website functionality, execute testing contracts, and fulfill statutory obligations. We collect:

A. Client and Business Partner Data

To conduct makeup analysis, stability testing, microbiological checks, and safety assessments, we process:

  • Identity Data: First name, last name, professional title/role of clients, brand representatives, or designated formulation chemists.
  • Contact Data: Corporate email address, physical business address, telephone number.
  • Financial & Billing Data: Tax Identification Number (AFM), competent DOY (Tax Office), bank account details, and payment histories.
  • Technical Product Documentation Data: Formula technical sheets or Safety Data Sheets (SDS) which may contain personal data if tied to individual creators, safety assessors, or chemical experts as required by EU Regulation 1223/2009.

B. Website Visitors (Automated Collection)

  • Technical Data: IP address, browser type and version, time zone setting, operating system, and platform.
  • Usage Data: Information about how you use our website, pages viewed, and response times.
  • Cookies: Detailed explicitly in Section 9.

Purposes and Legal Bases for Processing

Under GDPR Article 6, we process your data under the following legal frameworks:

Purpose of ProcessingCategory of DataLegal Basis (GDPR Art. 6)
Executing analysis requests: Managing orders, performing chemical/microbiological tests, issuing certificates of analysis.Identity, Contact, Technical Product DataContractual Necessity: Art. 6(1)(b) – Necessary to fulfill our testing agreement with you.
Regulatory Compliance: Documenting safety assessments, maintaining records for national/EU health authorities (EOF, European Commission).Identity, Financial, Technical Product DataLegal Obligation: Art. 6(1)(c) – Compliance with EU Cosmetics Regulation 1223/2009 and Greek tax laws.
Financial Management: Issuing invoices, managing payments, and recovering debts.Identity, Contact, Financial DataContractual & Legal Obligation: Art. 6(1)(b) & (c).
Customer Support: Responding to inquiries submitted via contact forms or emails.Identity, Contact, Inquiry DetailsLegitimate Interest: Art. 6(1)(f) – Efficient business operations and customer relationship management.
Website Security & Optimization: Monitoring for cyber threats, troubleshooting, and improving interface performance.Technical Data, Usage DataLegitimate Interest: Art. 6(1)(f) – Protecting network security and intellectual property.

Data Retention Periods

We do not store personal data longer than necessary for the purposes it was collected:

  • Contractual and Analytical Records: Raw measurement data, client identities, and certificates of analysis are stored for [Insert period, e.g., 10 years] following contract termination to satisfy liability timelines and EU Cosmetics Regulation audit tracking.
  • Tax and Billing Data: Retained for 10 years (or the period strictly mandated by current Greek tax legislation).
  • Inquiries/Contact Forms: Retained for [Insert period, e.g., 12 months] from resolution, unless they lead to a contractual partnership.

Data Sharing and Recipients

Your data is treated with strict confidentiality. It is never sold. We share data only with trusted third parties under binding Data Processing Agreements (DPAs) that enforce GDPR compliance:

Public Authorities: Regulatory frameworks like the National Organization for Medicines (EOF) or judicial authorities, strictly upon lawful request.

Subcontracted Specialists: External specialized laboratories or certified safety assessors if a specific measurement requires external validation (disclosed explicitly to the client beforehand).

IT & Cloud Providers: Entities hosting our laboratory information management systems (LIMS), website servers, or email infrastructure.

Professional Advisors: External accountants, auditors, and legal counsel.

International Transfers

All primary data processing and storage occur within the European Economic Area (EEA). If any cloud provider routes technical data outside the EEA, we enforce EU Standard Contractual Clauses (SCCs) to guarantee equivalent protection levels.

Data Security Measures

We implement rigorous technical and organizational measures to prevent unauthorized access, alteration, disclosure, or destruction of your data:

  • Use of secure Laboratory Information Management Systems (LIMS) with strict role-based access control.
  • Data minimization principles regarding raw cosmetics formulations.
  • HTTPS/SSL encryption for all data transmitted via our website.
  • Regular vulnerability assessments of our digital infrastructure.

Your Rights Under the GDPR

As a data subject, you hold the following rights under Articles 15-22 of the GDPR:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to be Forgotten”): Request deletion of your data, provided processing is no longer required by law or contract.
  • Right to Restrict Processing: Request limitation of data processing under specific conditions (e.g., while disputing data accuracy).
  • Right to Data Portability: Obtain your data in a structured, commonly used, machine-readable format.
  • Right to Object: Object to data processing based on our legitimate interests.

To exercise any of these rights, contact us directly at [Insert Privacy Email, e.g., privacy@yourlab.gr]. We will respond free of charge within thirty (30) days.

Right to Complain to the Supervisory Authority

If you believe our processing of your data violates the GDPR, you have the right to lodge a formal complaint with the Greek national supervisory authority:

Website / Portal: www.dpa.gr

Authority: Hellenic Data Protection Authority (HDPA)

Postal Address: 1-3 Kifissias Avenue, 115 23, Athens, Greece

Phone: +30 210 6475600

Cookies Policy

Our website uses cookies to distinguish you from other users and monitor traffic.

  • Essential Cookies: Necessary for basic site security and navigation. These do not require consent.
  • Analytical/Performance Cookies: (e.g., Google Analytics). These track how visitors move around the site. These are disabled by default and only activate if you explicitly opt-in via our cookie banner.

You can modify or withdraw your cookie consent choice at any time via the settings link on our website footer.

Amendments to this Policy

We reserve the right to update this Privacy Policy to reflect changing laboratory operations, technical infrastructure, or European legal updates. Any changes will be published directly on this page with an updated “Last Updated” timestamp.