Privacy Policy

Privacy Policy

Your data is safe with us

At Hellas Direct group (“Hellas Direct”) we value privacy and data protection. We comply with all relevant Legislations, including Regulation (EU) 2016/679 of the General Data Protection Regulation (also known as «GDPR»), as might be amended from time to time; and which affects the protection of all personal data we have in our possession.

Hellas Direct group is made of different companies. We will let you know which Hellas Direct company is responsible for the processing of your personal data based on the product and/or service you choose.

  • HD Insurance Plc (HDI) : is an insurance company duly incorporated and existing under the Laws of the Republic of Cyprus, with Company Registration Number HE 289025, having its registered address at Dasoupoleos 8, 2015, Nicosia, Cyprus, and which operates through a Greek and Romanian branch, respectively. HDI is licensed and regulated by the Insurance Companies Control Service (ICCS in Cyprus), as well as the Bank of Greece (BoG) and the Financial Supervisory Authority (ASF in Romania) and a general insurance company;
  • HD 360: is a company duly incorporated and existing under the Laws of the Republic of Cyprus, with Company Registration Number HE 357242, having its registered address at Dasoupoleos 8, 2015, Nicosia, Cyprus, and which operates through a Greek branch, and is offering ancillary services and technical support;

Depending on the product and/or services you choose, you must agree to separate terms and conditions with those companies which will govern those product and/or services, as well as processing of your personal data by the respective company, as mentioned hereinbelow. We collect your personal data when you use our (i) website at www.hellasdirect.gr , (ii) any of our Hellas Direct apps and/or platforms (such as Superapp, HD Pro, HD Portal), and/or (iii) any of the products and/or services available to you through our website or apps. We may also collect your personal data from third parties or other companies. More details are provided herein below.

What is personal data?

The term Personal Data refers to any element or information that can identify a person’s identity or contact information. This also includes cases where one’s identity can be ascertained even indirectly by reference to a factor that is unique to the physical, physiological, genetic, psychological, economic, cultural or social identity of that individual.

What is the purpose of this Privacy Policy?

The purpose of this Privacy Policy is to inform you in detail about everything that concerns your personal data and Hellas Direct. Specific Hellas Direct products and/or services might have additional standalone privacy notices and relevant documentation. Such notices will be provided prior you start using the product and/or service, through the relevant Hellas Direct app and/or platform but can also be accessed through our website. If you have any follow up questions, please do not hesitate to contact us.

Our site uses Cookies. More details can be found in our Cookies Policy.

How do we collect your personal data?

Information you provide us directly:

  • When you visit our website, apps, platforms or social media pages;
  • When you provide us with your personal data (e.g. during a telephone conversation, email, request or query);
  • When you request an insurance quote either through our direct channel and/or through any of our trusted partners and/or insurance intermediaries and/or online aggregators;
  • When you request and/or conclude an insurance policy either through our direct channel and/or through any of our trusted partners and/or insurance intermediaries and/or online aggregators;
  • When you register and/or use any of our apps, platforms, portals, marketplace(s) etc;
  • When you create a Hellas Direct Customer Account (click here for more information);
  • When you visit and/or use our Marketplace;
  • When you use any ancillary services offered by other companies of the group (e.g. through HD360);
  • When you utilise any other products and/or services offered by other companies of the group;
  • When you participate in any marketing activity, survey or campaign of Hellas Direct and/or any of our trusted partners;
  • When you submit any query and/or complain through email, phone, social media pages and/or to any of our representatives and/or trusted partners and/or insurance intermediaries and/or online aggregators;
  • When you request any alteration, modification or access to your data;
  • When you submit a claim (relating to your insurance policy) to us directly and/or through our trusted partners and/or insurance intermediaries and/or aggregators.

Information lawfully obtained by third parties:

  • Through our trusted partners, suppliers, service providers, representatives, who process your personal data on our behalf;
  • Through any person and/or legal person that provide products and/or services directly to you on our behalf;
  • Directly from any individual and/or authorised representative on your behalf;
  • Through medical practitioners and/or medical facilities (as might be applicable);
  • Through your legal representatives;
  • Through other insurance companies;
  • When we process data for assesment of claim or compensation purposes, within the framework of the Direct Settlement Agreement (DSA)/ΣΑΠ, we may receive your data from other insurance companies participating in the Amicable Settlement/SAP system.
  • When we process data for assessment of claim or compensation purposes in an accident in which you were involved as a third party;
  • Through credit scoring and/or ID-verification and/or KYC companies;
  • Through companies that process card payments;
  • Through Public and/or Supervisory Authorities;
  • Through gov.gr, provided you choose to verify your data using gov.gr;
  • Through other Hellas Direct companies;

Other ways

  • Through publicly available sources such as:
  • Press and Media;
  • Internet search engines;
  • National registries and/or databases (such as gov.gr , National Cadastre etc);
  • Screening companies (such as LexisNexis used as part of KYC, AML and sanction screening).

Which categories of personal data do we use?

5.1 The category and type of personal data we collect and process depends on the product and/or service you select, the interaction and relationship you subsequently establish with Hellas Direct.

We generally collect and process personal data about:

  • Current or potential customers of Hellas Direct who enter into a contract with Hellas Direct for the provision of a product and/or service (insurance policy or ancillary services);
  • Beneficiaries and/or nominated representatives (as might be applicable);
  • Representatives of legal entities that enter into a contractual relationship with Hellas Direct;
  • Hellas Direct employees;
  • Representatives, trusted partners, service providers and/or any insurance intermediaries that Hellas Direct works with;
  • Any third parties involved in an accident;
  • Any persons/users of the website who participate in any marketing activity, survey or campaign of Hellas Direct and/or any of our trusted partners.

5.2 The main types of personal data that we use are:

Contact details: such as name, surname, home address, telephone number, email address.

Identification Details: such as your ID or Passport number, copy of ID or Passport, date of birth, TAX ID (AFM), IRC and copy of your residence permit (for non-EU nationals), driving license number, copy of your driving license, vehicle registration number, license number, vehicle type/model, KAEK number.

Biographical and Demographic Data: such as your date of birth, age, gender, marital status, occupation details, if you hold/held a prominent public function (PEP), authentication data (e.g. signature).

Financial Information: such as, annual income, source of income, proof of income, bank account number, account number details, tax residency and tac identification number, as well as details of the banking institution or your card details and billing information in order to process your payment and/or proceed with a payment (e.g. in case of a compensation or refund).

Information relevant to your product and/or service: such as history and status of current and past transactions (e.g. any previous insurance claims), number of products and/or services currently retained with Hellas Direct and cash value (if applicable).

Other Data: such as any photographic material, videos, supporting evidence and relevant reports (created by professional investigators and/or other experts), access to CCTV footage and recorded calls, legal documents and files (as might be applicable), sanction screenings, fraud risk scores, any information you provide us with to prove your eligibility for any of our products and/or services, information about other people which you might provide us with.

Details of your visit at our website, apps, platforms or other social media: such as your browsing data, IP address and placing cookies on your browser, to offer you a better online experience. More information is provided in our cookies policy.

Hellas Direct Customer Account: such as the details of your account log-in credentials (username, password) as well as your name, surname, email. Based on your preferences (i.e. whether you opt-in to marketing, profiling and cookie preferences) and the products and/or services you link to your account, we may process further personal data.

More information is provided in Hellas Direct Customer Account terms and conditions.

Surveys/Marketing Information: such as any questionnaire answer and/or feedback which you have agreed to provide regarding our products and/or services.

5.3 Special Categories of Personal Data

In some cases we may also processes sensitive personal data in relation to your health status, medical reports and medical history. We only collect and retain sensitive personal data with your explicit consent or other situations that are permissible under applicable legislation.

5.4 Personal Data of Minors

We do no provide online products and/or services to minors. We will not request or process minor’s personal data, except if necessary, to do so. For instance, if we are assessing a claim following a car accident, in which minors were involved, we will have to process their data for assessment and compensation purposes. This will be done based on the minor’s parent or legal guardian’s consent and always in compliance with the GDPR provisions.

Our website is not addressed to minors and should not be used by minors.

On what legal basis do we process personal data?

We process personal data in accordance with the relevant laws and regulations. To have a lawful process we must always have a legal basis as per Art.6 of GDPR in order to process your personal data. We will process your personal data only if:

  • you have consented to processing for one or more purposes;
  • processing is necessary for the proper implementation of a contract to which you are a party or for actions that need to be taken at your request prior to the conclusion of a contract;
  • processing is necessary to comply with a legal obligation we may have;
  • processing is necessary to safeguard your vital interest or someone else’s;
  • processing is necessary for the performance of a duty performed for the public interest or in the exercise of public authority entrusted to us;
  • processing is necessary for the purposes of the [respective] company’s legitimate interests, except in cases where your fundamental rights and freedoms override those interests - in such cases, the protection of your personal data will supersede the company’s legitimate interests.

Special Categories of Data:

In case of special categories of personal data, additional legal basis as per Art. 9 and Art. 10 of GDPR will be required before we proceed with such processing.

We will lawfully process any sensitive personal data (such as medical data) if:

  • upon having your explicit consent and/or
  • processing is necessary for the establishment, exercise or defence of legal claims.

You can withdraw such consent at any time, but this might materially impact our ability to provide you with our products and/or services (such as processing your insurance claim).

Why do we collect and use your personal data?

7.1 We only ask what is necessary – without these, we cannot evaluate your eligibility for use of our products and/or services nor can we properly serve you during the course of our relationship (e.g. process any claims and/or compensate you).

Provision of Products and/or Services

We use your personal data to provide, operate, and manage our services, including:

  • Providing insurance services, including quotes, underwriting, policy issuance, and claims handling;
  • Enabling the Superapp functionality, including access to multiple services, personalization, and loyalty schemes;
  • Operating the used car marketplace, including listings, saved preferences (e.g. wishlists, searches), and communication between users.

Hellas Direct Customer Account Creation & Management

Your Hellas Direct Customer Account acts as the central point through which you can access all of Hellas Direct’s group products and/or services from the supporting channels. Personal data is collected and used for:

  • Creating and maintaining your Hellas Direct Customer Account
  • Authentication and identity management
  • Managing your preferences (including marketing consent and consent to profiling)

Creating a Hellas Direct Customer Account enables you to have access across multiple services offered by the group (e.g. Insurance, Superapp, Marketplace).

The necessary personal data we collect and process for this purpose include your: name. surname, email, phone. Upon creation of your account you can choose which services and/or products you wish to access through your customer account and manage your settings. With your explicit consent, further types of personal data might be processed.

Contractual and Operational Purposes

We process your data to fulfil our contractual obligations and ensure proper service delivery, including:

  • Verifying your identity and eligibility;
  • Processing payments and managing billing;
  • Providing customer support and handling requests or complaints;
  • Managing relationships with partners, sellers, and service providers;
  • Ensuring service continuity, performance, and reliability.

Legal and Regulatory Compliance

We process your data where necessary to comply with legal and regulatory obligations, including:

  • Compliance with insurance and financial services regulations;
  • Anti-money laundering (AML) and fraud prevention requirements;
  • Tax, accounting, audit, and reporting obligations;
  • Reporting vehicle insurance details (tax number, registration number) to regulatory authorities (HIC) and insurance industry bodies (Greek Insurance Union) as required by law.
  • Providing information to public authorities, courts, regulators, and parties involved in legal proceedings (and their professional advisors) as necessary or appropriate.

Risk Management and Fraud Prevention

We use your personal data to detect, prevent, and investigate fraud, abuse, and unlawful activities, including:

  • Monitoring transactions and behaviour across our products and services;
  • Verifying information provided in insurance and marketplace activities;
  • Protecting the integrity and security of our platforms.

Improvement of Services

We use your data to analyse, improve, and develop our products and services, including:

  • Understanding how users interact with our platforms (including the Superapp and marketplace);
  • Enhancing features, usability, and performance;
  • Developing new products and services;
  • Conducting internal analytics and research.

Personalization and Loyalty Programs (where applicable)

Where permitted by law and/or based on your consent, we use your data to:

  • Personalize your experience within the Superapp and marketplace;
  • Provide loyalty schemes, rewards, and benefits;
  • Recommend relevant services and products across our group (e.g. insurance, mobility-related services).

Personalization may involve combining data from different products and services within our group, provided your explicit consent has been acquired.

Marketing & Transactional Communications

Operational and

Transactional Communications

With your explicit consent, we use your personal data to:

  • Send you promotional communications about products and services across our group;
  • Inform you about offers, campaigns, and updates;
  • Deliver personalized marketing and advertising.

We may also send you service-related communications (e.g. account updates, transaction notifications) where necessary for the provision of our services. These are considered transactional communications (regardless of your marketing-consent preferences).

Security and System/Platform Integrity

We process your data to ensure the security and proper functioning of our systems, including:

  • Preventing unauthorized access and misuse;
  • Monitoring systems and responding to incidents;
  • Ensuring data integrity and protection.

Internal Group Operations& Data Sharing

Your personal data is primarily processed by the company providing the relevant product and/or service.

However, your Hellas Direct Customer Account enables certain data to be shared across our group, in a controlled manner, for:

  • Account creation, authentication, and identity management;
  • Management of your marketing preferences and consents;
  • Personalization and loyalty services within the Superapp, where you have provided explicit consent;

Other than above-mentioned cases, your data remains separated between group companies, unless required by law or otherwise permitted.

Intra-group policies and agreements are maintained to ensure the integrity, lawfulness and protection of your personal data.

Exercise and Defense of Legal Claims

We may process your personal data where necessary to establish, exercise, or defend legal claims or rights.

More specifically, we will process your personal data in order to:

Insurance

Calculation of Quote

/Cost of your Insurance

To be able to either insure you or calculate the cost of your insurance, we evaluate the data and personal data you give us. This data is necessary to be able to determine the insurance risk we undertake and, consequently, to be able to calculate the costs effectively. For example, for home insurance, it is important to know your place of residence because in some areas the risk of theft is higher than others.

For the conclusion of your insurance policy and/or for assessment of a claim, additional categories of personal data may be processed, for instance, photographic material as well as sensitive data in relation to your health status, medical reports and medical history.

Conclusion of your Insurance Policy

If you decide to purchase insurance from us we will need to obtain more categories of personal data from you, to be able to provide you with the required insurance cover.

The necessary personal data we collect and process are: name, address, email, telephone (landline and mobile), TAX number, call recording and collection of written communications to and from Hellas Direct, number of contracts, photographs, and number of visits to the site, account details, and other financial information. Where necessary, we may process medical and legal data.

This kind of personal data will also be obtained upon the renewal or amendment of your insurance or when you submit a claim for payment under your insurance contract.

Communication Purposes

In addition, we need your personal information so that we can communicate with you when necessary. We will contact you:

  • to remind you of the expiry of your insurance contract;
  • in case you file a complaint or a claim we will have to contact you to obtain all the relevant information to enable us to assess your complaint or claim;
  • after your obtain a quote through our website we will send you up to three (3) emails to remind you about the quote we provided you with;
  • if you have purchased insurance from us which has lapsed, we may contact you within a period of eighteen (18) months from the date the insurance contract elapses;
  • if you have applied for financing through Wallet+, we may contact you within a period of eighteen (18) months.

Assessing a Claim /Compensating

To be able to properly assess any claim (following a car accident which you were a part of and/or any damage to your insured vehicle and/or property) and proceed with any compensation.

Provision of Information to Public Authorities

Additionally, for motor insurance, we will ask for your TAX number to inform the authorities that your vehicle is insured. The information we ask for is essential for the proper assessment of the insurance risk and for the calculation of a fair premium that meets your specific needs.

Complying with Legal & Regulatory Obligations

We will process your personal data as deemed required, in order to comply with our legal and regulatory obligations (e.g. timely submission of information to supervisory authorities and/or providing information to any authority requesting data from us, provided this is justified and required.

Legitimate Purposes

Cases of data processing for the purposes of legitimate interests include, but are not limited to, processing for the prevention and assessment of criminal or illegal and malicious actions to Hellas Direct. For example, when we have reasonable grounds to suspect that a claim is fraudulent.

Do we make any Automated Decisions?

In some cases, we use automated processes for decision-making, in line with applicable legislation. This means that we have systems that automatically collect, organize and evaluate the data you give us. Automated processing allows us to assess your eligibility for use of our products and/or services (in real time) so that you do not have to wait for it. Automated processes may be used, among others, in order to (i) ensure the security and reliability of our products and/or services, (ii) to monitor and prevent fraud and/or money laundering, (iii) where such processing is necessary for entering into or performing a contract, (iv)for profiling purposes (provided the relevant consent for profiling is provided).

It is noted that that, we do not rely solely on automated decisions. Human intervention and/or revision of decisions is performed by the relevant departments, as deemed appropriate in each case. You reserve the right to request us to review an automated decision which might significantly impact you.

Credit Checks

To assess your eligibility to use some of our products and/or services and to properly evaluate your application we may conduct a credit check through some of our trusted partners, in order to verify your identity, prevent fraud and comply with regulatory requirements, if any. .

The outcome of this credit check may affect your eligibility.

What will we do if you give us false information?

If you give us inaccurate, incomplete or false information, we may cancel and/or suspend and/or terminate the use of our products and/or services and/or your contract with us.

  • Obligation to Provide us with Personal Data / Consequences of Non-Provision

We need all the necessary personal information in order to proceed with the purposes mentioned in this Privacy Policy and to properly serve you. We also need some of this personal data to comply with our legal obligations (such as KYC, AML and Tax legislation) and any reporting obligations to Supervisory and/or Regulatory bodies and authorities.

If you do not provide us with the required personal data, we might not be allowed to commence, continue or renew our commercial relationship with you.

Will your data be used for commercial purposes?

According to the GDPR, for us to be able to send you any promotional material, you must first give us your explicit consent. Without it, we cannot send you updates about new services or new products and/or partnerships with affiliated companies. Also, we will not be able to send you the company news or news of the market (e.g., news about uninsured cars, news regarding the road taxes, news about loyalty promotions, news and offers about used cars/Marketplace, etc.).

If you opt in to these communications, you have the right to withdraw your consent at any time. Just let us know by emailing us at dpo@hellasdirect.gr or simply «unsubscribe» from the next email you receive. We will immediately stop processing your data for commercial and promotional purposes.

How do you use my personal data for marketing?

Marketing

With your explicit consent, we will use some of your details for marketing and market research purposes. We will use your details to send you informational material, as well as any information we believe may be of interest to you and our offers for any products and/or services we may make available. Any kind of information (emails/sms/viber/whatsapp/push notifications) sent to you will provide you with the option to stop receiving such notifications if you ever wish to cease such communication. You can also contact as dpo@hellasdirect.gr in order to stop such processing.

Remarketing

With your explicit consent, we will use some of your personal data for remarketing purposes, to display our advertisements relevant to your interests through our trusted partners. In this way we may use your data to provide you with targeted and personalised advertisements.

Profiling

We may use your personal data to inform you about our products and/or services and/or offers that may be of interest to you. For this purposes, personal data provided by you and/or collected and/or inferred form the use of our products and/or services may be used (e.g. information on your insurance policy transactions). We review and/or analyse these data in order to form a view of what you may need and/or tailor the content we provide you with (targeted marketing information on products based on your personal aspects). We can only proceed with such processing to promote our products and/or services with your explicit consent and/or in certain cases, based on legitimate interests.

You have the right to object to and/or withdraw consent to this processing of your personal data for marketing purposes, including profiling, at any time.

Who has access to your personal data?

At Hellas Direct we take confidentiality and protection of your personal data seriously and we make every effort to comply with applicable GDPR requirements and relevant legislation. Access to your personal data is only available to those requires to have access, with the purpose of serving you. To this end, any recipients and/or persons processing your personal data on behalf of Hellas Direct, are subject to obligations of confidentiality and processing your data in accordance with applicable GDPR and Legal Framework. Personal data is disclosed only to those absolutely necessary in order to achieve the purposes mentioned in this Privacy Policy and/or as otherwise disclosed to you at the time of collecting your personal data.

Recipients of your data may include:

  • Internally: within relevant departments of Hellas Direct (limited to those required to access in order to perform their day-to-day tasks and/or the purposes mentioned herein)
  • Externally: with our trusted partners, service providers, other companies and Public and/or Supervisory Authorities.

For any recipients outside EU or EEA, the appropriate safeguards are taken into consideration, prior to such processing, as per term 16 herein below.

Aside from Hellas Direct who else has access to your personal data?

  • Other Hellas Direct and/or affiliated companies;
  • Other insurance companies and reinsurers. We will disclose your details to the Insurance Statistics Agency, and to other insurance companies if this is deemed necessary by our reinsurers;
  • Other insurance companies within the framework of the Direct Settlement Agreement (DSA)/ΣΑΠ, for examination of the claim for compensation and completion of the procedure. In such a case, we will notify you accordingly regarding the transmission of your data to another insurance company within the framework of the Direct Settlement Agreement (DSA)/ΣΑΠ, with a clear reference to specific insurance company and its status as a new data controller.
  • To our trusted partners (including external service providers) with whom Hellas Direct has entered into an agreement with. Such partners/service providers have been evaluated and approved by Hellas Direct and the necessary agreements are in place, in accordance with the applicable legislation (including the required documents and agreements that clearly define the roles/responsibilities between each service provider and Hellas Direct, in the context of processing personal data and the general cooperation between the parties);

Such trusted partners may assist us in providing the products and/or services you have purchased. These include but are not limited to: underwriting experts, repair services, technicians that provide emergency services and take on repairs in the insured house, insurance appraisers, as well as doctors, external lawyers and legal counsellors, investigators, financial and business advisors, actuaries, internal and external auditors, accountants, reinsurers, brokers, experts, banks and financial institutions, and others.

  • Identity Verification and KYC service providers, credit scoring companies, fraud scoring companies, fraud preventing agencies or private investigators, debt collectors, communication service providers, analytics and search information providers ,file storage companies, marketing companies and/or market research companies and others;
  • Public or governmental bodies such as courts, regulatory bodies, law enforcement agencies, tax authorities, criminal intelligence services, third-party tribunals and their accountants, auditors, lawyers and others consultants and their representatives, as we think is necessary or appropriate. These include the relevant body which identifies uninsured vehicles, as well as any relevant authority requesting data from us;
  • Public and/or Supervisory and/or other Regulatory Public Authorities if an obligation to disclose data exists.

Transfers outside EEA

Some of the recipients of your personal data may be located in third countries, i.e. country outside the European Union (EU) and/or the European Economic Area (EEA) and/or some of our trusted partners and/or service providers may retain their headquarters, parent companies or data centres in a third country. In such case, all relevant applicable measures are taken into account prior to such transfers and/or prior to entering into a commercial relationship with such partners and/or service providers. Hellas Direct ensures that all data processors who process personal data on behalf of Hellas Direct are obligated to comply with applicable GDPR standards and to provide appropriate safeguards in relation to the transfer of your personal data in accordance with GDPR and Legal Framework, respectively.

Is your personal data safe?

Absolutely! We use all appropriate technical and organizational measures to ensure the security of your personal data. We have chosen to keep only the data which is absolutely necessary, all of which is encrypted and/or anonymized, either in part or in whole. The security of your data is extremely important to us. Hellas Direct has internal policies and procedures to ensure proper compliance with GDPR requirements and the adequate protection of your personal data.

How long will we keep your personal data for?

We will maintain and process your personal data for as long as it is necessary to achieve the purpose for which you originally provided the data, in line with applicable legislation as might be amended from time to time.

To comply with our legal obligations with respect to KYC, AML, insurance, banking and tax legislation, we are required to retain some personal data for specified periods. As a general rule, we will keep your personal data for up to 10 years upon lapse and/or termination of your contractual and/or business relationship with Hellas Direct.

In some cases, we might keep your personal data for longer period (e.g. potential and/or ongoing litigation and/or any case and/or claim against us).

Some examples of our retention periods include:

Insurance (HD Insurance)

  • Insurance quote (no policy purchased): up to eighteen (18) months from the date of the quote.
  • Active insurance policy: for the duration of your contract and service provision.
  • Upon lapse/termination/cancellation: up to ten (10) years upon lapse and/or termination and/or cancellation of your contractual relationship with us, or as otherwise required by applicable laws and regulations.

Mobile App (HD360)

  • Hellas Direct Customer Account data, including personalization and loyalty features: for as long as your Hellas Direct Customer Account remains active.
  • Upon account deletion, suspension, or opt-out from specific products and/or services: data will be deleted or anonymized where possible, or will otherwise be retained for up to ten (10) years.

Used Car Marketplace (HD 360)

  • Marketplace account sepadata (including profiles, wishlists, saved searches, and messages): for as long as your account remains active.
  • Upon account deletion, suspension, or opt-out: data will be deleted or anonymized where possible, or will otherwise be retained for up to ten (10) years.

General principles

  • If you opt out of a specific product and/or service but retain a broader Hellas Direct Customer Account, we will stop processing data for that product and/or service and retain only what is necessary to comply with legal and regulatory obligations.
  • Retention periods may be extended where required by law and/or to establish, exercise, or defend legal claims (e.g. for ongoing cases data may be retained for longer periods and/or until a final decision is held).

Hellas Direct has detailed internal policies and procedures to ensure proper compliance with GDPR requirements and the adequate protection of your personal data. Upon expiration of the applicable retention periods Hellas Direct will proceed with destruction and/or deletion and/or anonymisation of your personal data in accordance with appropriate methods and practices.

What kind of changes do we make?

At times, we may make changes to our Privacy Policy for the purpose of improving customer service and to comply with relevant legislation. We urge you to visit our site from time to time to keep up-to-date with any changes. However, if we make substantial changes to this Privacy Policy, we will notify you via email to give you the opportunity to review the new terms and conditions in order to decide whether or not you agree with them.

What are your rights?

Τhe right to information: to clearly be informed by Hellas Direct as to how we collect, use, and store your personal data. This is done via our Privacy Policy.

The right to access: to request a copy of your personal data and an explanation in order to understand how these are processed. This can be exercised through a Data Subject Access Request (DSAR) via the details mentioned below. We cannot provide you with any personal data relating to any third party or an ongoing criminal or fraud investigation.

The right of rectification: you can request for inaccurate, incomplete or outdated data to be corrected. Before we update your personal data, we might request to check the accuracy of the updated personal data you provide us with.

The right to restrict processing: you can request to limit how Hellas Direct uses your personal data, especially in case you contest its accuracy or lawfulness.

The right of erasure (right to be forgotten): you can request to be deleted from our database in some cases, especially if there is no longer a need for us to have your data or your consent is withdrawn. It is noted that this is not an absolute right and in some case we might not be able to fully satisfy your request – we will inform you accordingly in each case.

The right of portability: you can request to receive your personal data in a structured, commonly used, machine-readable format in order to transfer it to another partner or other company.

The right of objection: you can object to the processing of your personal data for specific purposes, such as for direct marketing or profiling. However, since some of these data are necessary for us to provide you with some of our products and/or services (such as insurance), the objection may affect and/or lead to the termination of the respective product and/or service.

The right to not be subjected to automated decision-making: you can request a manual intervention or review of an automated decision that significantly affects you since you have the right not to be subject to decisions taken solely on the basis of automated processing, including profiling.

The right to withdraw the consent you have given us for the use of your data for commercial purposes. You can withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of any processing based on your consent prior to such withdrawal.

In order to exercise any of your above mentioned rights, you must send us your request by email at dpo@hellasdirect.gr , by calling us at 212 222 9999, or by filling in GDPR Request Form. We will evaluate your request and revert in writing, as soon as possible and in any case within thirty (30) days from the receipt of your request, as per applicable legislation. In case of more complex requests we might revert within (60) days from the receipt of your request but we will inform you accordingly of the extended period required. If there are objective reasons that do not allow us to meet your request and/or in case your request can be partly-satisfied, we will inform you accordingly including the relevant justifications. You can exercise these rights at no cost. In case of repeated requests, Hellas Direct reserves the right to apply a reasonable management fee.

You can contact us for more details about our DSR Policy.

How can you complain about the way your personal data is being processed?

If you disagree with the way we have processed your personal data, you can email the Data Protection Officer at dpo@hellasdirect.gr. Alternatively, call us 212 222 9999.

You can also contact the Personal Data Protection Authority. The applicable Personal Dara Protection Authorities based on the countries in which we are currently operating are:

For Cyprus: the Office of the Commissioner for Personal Data Protection, available at https://www.dataprotection.gov.cy/

For Greece: Data Protection Authority, available at https://www.dpa.gr/

For Romania: The National Supervisory Authority For Personal Data Processing, available at https://www.dataprotection.ro

Chat with us