This Privacy Policy is intended to inform you about the information collected from you when you visit this website, how it may be used, how you can control the use and disclosure of your information, and the measures taken to protect that information. This Policy is an integral part of the Terms of Use, which are incorporated by reference.
The website of the Institute of Systemic Therapy of Thessaloniki ISTT (hereinafter referred to as the “Institute”) with the electronic address https://istt.gr/ (hereinafter referred to as the “Website”) is the Institute’s informational website. The Institute, as the controller of your personal data, informs you, as the person to whom the personal data relates (hereinafter referred to as the “Data Subject”), that when you visit or use the Website, the processing of your personal data is governed by applicable European and national legislation on the protection of personal data, including Law 4624/2019, Regulation (EU) 2016/679 of the European Parliament and of the Council, adopted on April 27, 2016, and effective as of May 25, 2018 (hereinafter referred to as the “GDPR”), as well as the decisions, directives, and regulatory acts of the Hellenic Data Protection Authority.
- Personal Data Collected and Processed by the Website
The Website ensures the fair and lawful collection and processing of personal data. Personal data are information that directly or indirectly identify the Data Subject, in particular by reference to an identifier such as full name, contact telephone number, and email address, as well as special categories of data. The personal data collected are strictly necessary for the fulfillment of the action requested by the Data Subject.
The Data Subject ensures that the personal data provided are correct and accurate and undertakes to notify the Institute of any change or modification thereof. Any loss or damage caused to the Website or to any third party through the disclosure of incorrect, inaccurate, or incomplete information via the contact form shall be the sole responsibility of the Data Subject.
- Use of the Website by Minors
In accordance with the provisions of Article 8(1)(a) of the GDPR in conjunction with Article 21 of the Law, minors under the age of fifteen (15) are prohibited from disclosing their personal data through the Website without the prior consent of their parent or legal guardian.
- Purpose of Data Processing
The purpose of the collection and processing of personal data by the Website is to enable communication between the Institute and the Data Subject for the optimal handling of the request submitted via email and/or through the contact form, as well as for the evaluation of the Data Subject’s application for participation in an educational program and the relevant communication.
Furthermore, the Website collects personal data necessary for its basic functions, such as navigation and access to secure areas of the Website (strictly necessary cookies). When the Data Subject accesses the Website, the Institute may, following the Data Subject’s explicit consent, also collect browsing data for analytical purposes (e.g. traffic monitoring) and for statistical purposes (Browser type, Operating System, Internet Protocol (IP) addresses), in order to understand how the Data Subject interacts with the Website and to improve it accordingly.
More information regarding this category of personal data can be found in the Website’s Cookie Policy.
The Institute collects and processes personal data solely for the above-mentioned purposes and only to the extent strictly necessary to effectively serve such purposes. Such data are relevant, appropriate, and not excessive in relation to the purposes, are accurate, and, where necessary, kept up to date.
- Data Retention Period
The personal data and special categories of data collected are retained and stored in a secure environment solely for the purposes of their collection and processing (see paragraph 3) and only for the period required to achieve those purposes, subject to the specific provisions of applicable legislation. After the expiration of this period, the data are securely deleted or destroyed, unless their retention is required by law, such as in cases of civil disputes, investigation of criminal offenses, tax audits, etc.
- Data Security
The processing of personal data by the Institute is carried out in a manner that ensures confidentiality. The Institute takes all appropriate organizational and technical measures to safeguard data and protect them from accidental or unlawful destruction, accidental loss, alteration, unauthorized disclosure or access, and any other form of unlawful processing.
- Data Breaches
The Institute undertakes that, in the event of a breach of its database, it will notify the Data Subjects and the Hellenic Data Protection Authority within 72 hours of becoming aware of the breach.
- Recipients of the Data
Recipients of the personal data are the Institute and the data processors acting on its behalf. The Institute guarantees that it will not transfer, disclose, or make available the Data Subject’s personal data to third parties for any purpose or use. However, it reserves the right to disclose information relating to the Data Subject where such disclosure is required by law or by a court decision, prosecutorial order, or order or decision of another person or administrative authority legally entitled to demand such disclosure.
- Data Processors Acting on Behalf of the Institute
The Institute uses third-party service providers (accountant, web hosting provider, and lawyer) to manage one or more aspects of its activities, including the processing of personal information. When the Institute uses an external company or partner, it employs contractual commitments and other appropriate means to ensure that the Data Subject’s personal data are processed in accordance with applicable legislation and this Policy.
- Use of Cookies
The Website uses cookies that are necessary for its basic functions. Additionally, it may use cookies to analyze visitor behavior, track preferences, and collect information about the Data Subject. Cookies are used to manage sessions and provide personalized web pages, so that the Website reflects the specific needs and interests of each Data Subject.
In this way, the Website remembers the Data Subject’s actions and preferences (such as display preferences, language, etc.) for a certain period of time, so that the Data Subject does not have to re-enter these preferences each time they visit the Website, unless they wish to do so.
For more detailed information about the cookies collected by the Website, please refer to the Cookie Policy.
