FREE SHIPPING FOR ORDERS IN GREECE

                                 PERSONAL DATA PROTECTION POLICY
                                                  (PRIVACY POLICY)

Last Updated: 24.09.2026

The sole proprietorship of  ELISAVET ZOI, operating under the trade name “LITTLE GREEK DRESS”, with its registered office at 39B Kimonos Voga Street, Thessaloniki, Greece, Tax Identification Number (TIN) 055029402, Tax Office: E' Tax Office of Thessaloniki, contact telephone number +30 2310 845378, and email address for personal data protection matters littlegreekdress@yahoo.com (hereinafter referred to as the “Data Controller”), recognizes the importance of protecting the personal data of its visitors and customers and is committed to processing personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), Law 4624/2019, and all applicable national and European Union legislation.

This Privacy Policy describes the manner in which the Business collects, uses, stores, transfers, and protects personal data received through the website www.littlegreekdress.com and the services provided through it.

DATA CONTROLLER

The Data Controller of your personal data is:

Business Name (Sole Proprietorship): Elisavet Ζοι

Trade Name: LITTLE GREEK DRESS

Registered Office: 39B Kimonos Voga Street, Thessaloniki, Greece

Tax Identification Number (TIN): 055029402

Tax Office: 5th Tax Office of Thessaloniki

Telephone: 2310 845378

Email Address: littlegreekdress@yahoo.com

For any matter concerning the processing of your personal data or the exercise of your rights, you may contact us using the above email address.

2. SCOPE OF THIS PRIVACY POLICY

This Privacy Policy applies to every natural person who:

  • visits our website

  • creates a user account

  • makes purchases through our online store

  • subscribes to our newsletter

  • contacts us via the contact form or by email

  • participates in promotional activities or competitions

  • interacts with our services in any other way.

3. CATEGORIES OF PERSONAL DATA

We may collect and process the following categories of personal data:

a) Identification Data:

  • full name

  • invoicing/billing details

  • business details (where required)

b) Contact Information:

  • residential or delivery address

  • email address

  • telephone number

c) Order Information:

  • products ordered

  • purchase history

  • date and time of the order

  • order status

  • details relating to returns or exchanges

d) User Account Information:

  • username

  • encrypted login credentials

  • account preferences

e) Communication Data:

  • content of messages

  • customer service requests

f) Newsletter and Marketing Communication Data:

  • email address.

  • consent records

  • information regarding the receipt of and interaction with newsletters and other marketing communications.

g) Technical Data:

  • IP address

  • device type

  • browser type

  • operating system

  • log file data

  • cookie identifiers and similar tracking technologies

h) Payment Data:

  • payment method

  • payment status

  • transaction details

  • proof of bank transfer, where payment is made via bank account transfer.

The Business does not collect or store complete credit or debit card details. The processing of card payment information is carried out exclusively by the respective payment service providers.

4. SPECIAL CATEGORIES OF PERSONAL DATA

The Business does not seek or require the collection of special categories of personal data within the meaning of Article 9 of the GDPR (such as health data, biometric data, religious beliefs, or political opinions).

You are kindly requested not to disclose such data to us through our website or communication channels.

5. PURPOSES AND LEGAL BASES OF PROCESSING

Personal data is processed solely for lawful, specific, and explicit purposes.

In particular, we process your personal data for the following purposes:

a) Performance of the sales contract and fulfillment of your orders.

Legal Basis: Article 6(1)(b) GDPR (performance of a contract).

b) Processing payments, returns, and refunds.

Legal Basis: Article 6(1)(b) and Article 6(1)(c) GDPR (performance of a contract and compliance with a legal obligation).

c) Shipping products and monitoring their delivery.

Legal Basis: Article 6(1)(b) GDPR (performance of a contract).

d) Providing customer support and responding to communication requests.

Legal Basis: Article 6(1)(b) and Article 6(1)(f) GDPR (performance of a contract and legitimate interests pursued by the Data Controller).

e) Compliance with the Business’s tax, accounting, and other legal obligations.

Legal Basis: Article 6(1)(c) GDPR (compliance with a legal obligation).

f) Sending newsletters and marketing communications.

Legal Basis: Article 6(1)(a) GDPR (consent) or, where permitted, the legitimate interests of the Business pursuant to Article 6(1)(f) GDPR and Article 11 of Greek Law 3471/2006.

g) Ensuring website security, preventing fraud, and protecting the legitimate interests of the Business.

Legal Basis: Article 6(1)(f) GDPR (legitimate interests).

h) Analysing purchasing behaviour and improving our services.

Legal Basis: Article 6(1)(f) GDPR (legitimate interests) or consent, where required.

i) Sending personalised marketing communications, offers, or updates.

Legal Basis: The user's consent or the legitimate interests of the Business, where permitted under applicable law.

6. RECIPIENTS AND DATA PROCESSORS

The Business may disclose personal data to third-party service providers acting either as independent data controllers or as data processors on its behalf, solely for the purposes described in this Privacy Policy and provided that they offer adequate safeguards for the protection of personal data.

In particular, your personal data may be disclosed to the following categories of recipients:

a) Website Hosting and E-commerce Platform Provider

The Business’s website and online store operate through the platform Shopify Inc. Shopify provides hosting services, order management services, customer data processing, and technical support.

Further information regarding Shopify’s processing of personal data is available in its Privacy Policy at: https://www.shopify.com/legal/privacy

Shopify may process customer data, order data, payment-related information, technical data, and website usage data in accordance with its terms and privacy policy.

b) Newsletter and Marketing Services

For the management of newsletter subscriptions and the sending of informational and promotional communications, the Business cooperates with:

These providers process data such as email addresses, consent records, and information relating to users’ interaction with the communications sent.

c) Website Translation Service

The website uses the Weglot application to automatically translate its content into multiple languages.

The use of this service may involve limited processing of technical data related to the display of website content

c1) Cookie Consent Management Platform (CMP)

The website uses the NOVA application, which operates as a Consent Management Platform (cookie consent banner), enabling users to choose whether they accept or reject the use of non-essential cookies.

In this context, technical data may be processed, including the user's IP address, information relating to the device and browser used, as well as records of users' consent choices, solely for the purpose of complying with applicable data protection and electronic communications legislation. 

c2) Currency Conversion Service

The website uses the MLV application, which enables the display and conversion of product prices into different currencies in order to facilitate purchases by users located outside Greece.

For the provision of this service, limited technical data may be processed, including the user's IP address, information relating to the user's country or region, currency preferences, and data concerning the user's interaction with the currency conversion functionality.

d) Shipping and Delivery Service Providers

For the execution and completion of your orders, strictly necessary personal data may be disclosed to our cooperating shipping and delivery service providers, such as:

  • GENIKI TAXYDROMIKIDHL SA

  • BOX NOW S.A.

  •  DHL International GmbH and its local affiliates and partners. 

The personal data disclosed to such providers is limited, as applicable, to:

  • full name

  • delivery address

  • telephone number

  • email address

  • order details necessary for the delivery of the products

e) Payment Service Providers

Payments made through the online store may be processed by third-party payment service providers, which act as independent data controllers.

In particular:

  • Shopify Payments (where used)

  • PayPal

  • other payment service providers integrated through Shopify.

The Business does not store or have access to the complete credit or debit card details of its customers.

f) Banking Institutions

  • Where payment is made by bank transfer, we may process personal data contained in the relevant proof of payment documents and in the transaction records of the Business’s professional bank account held with EUROBANK.

g) Professional Advisors and Public Authorities

The Business may disclose personal data to:

  • Accountants

  • legal advisors

  • tax advisors

  • auditors

  • public, judicial, or administrative authorities,

where such disclosure is required by applicable law or is necessary for the protection of the legitimate interests of the Business.

7. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES

Some of the service providers referred to above may be established in, or process personal data outside, the European Economic Area (EEA), particularly in the United States of America.

In such cases, the Business takes reasonable measures to ensure that any transfer of personal data is carried out in accordance with Articles 44 et seq. of the GDPR and is based, where applicable, on:

  • an adequacy decision issued by the European Commission

  • the participation of the relevant service provider in the EU–US Data Privacy Framework, provided that such provider is duly certified at the time of the transfer;

  • the Standard Contractual Clauses (SCCs) adopted by the European Commission;

  • or any other lawful transfer mechanism provided for under applicable data protection legislation.

8. AUTOMATED PROCESSING AND MARKETING COMMUNICATIONS

The Business may use e-commerce and marketing tools, such as Shopify, Privy, and Mailchimp, to manage communications with customers and users, send newsletters, provide information about products, offers, and updates, and improve the overall shopping experience.

In this context, basic user categorisation or segmentation may take place, for example based on previous purchases, interest in products, newsletter subscriptions, or interaction with promotional emails.

The Business does not make decisions that produce legal effects concerning the user or similarly significantly affect the user solely on the basis of automated processing.

Users may withdraw their consent to receive marketing communications at any time, either by using the unsubscribe link included in each email or by contacting the Business directly. 

9. DATA RETENTION PERIOD

The Business retains personal data only for as long as is necessary to fulfil the purposes for which it was collected or for as long as required under applicable law.

For example:

a) Order data, invoices, and other tax-related records are retained for a minimum period of five (5) years, or for a longer period where required by applicable tax, accounting, or other legal obligations.

b) User account data is retained until the account is deleted or until a reasonable period of inactivity has elapsed.

c) Communication data is retained for as long as necessary to manage and respond to the relevant request.

d) Newsletter data is retained until the user withdraws their consent or exercises their right to object to such processing.

Upon expiration of the above retention periods, personal data is securely deleted or anonymised, unless its further retention is required for the establishment, exercise, or defence of legal claims.

10. RIGHTS OF DATA SUBJECTS

In accordance with the General Data Protection Regulation (Regulation (EU) 2016/679), every natural person whose personal data is processed by the Business is entitled, subject to the conditions and limitations set out in applicable legislation, to exercise the following rights:

a) Right to Information and Transparency: The right to receive clear, transparent, and easily understandable information regarding the manner in which their personal data is processed. 

b) Right of Access (Article 15 GDPR): The right to obtain confirmation as to whether the Business processes personal data concerning the individual and, where that is the case, to access such personal data and receive information regarding its processing. 

c) Right to Rectification (Article 16 GDPR): The right to request the correction of inaccurate personal data and the completion of incomplete personal data. 

d) Right to Erasure ("Right to be Forgotten") (Article 17 GDPR): The right to request the deletion of personal data, provided that the legal requirements for such deletion are met and provided that the retention of the data is not required by applicable law or for the establishment, exercise, or defence of legal claims. 

e) Right to Restriction of Processing (Article 18 GDPR): The right to request the restriction of the processing of personal data in the circumstances provided for by the GDPR. 

f) Right to Data Portability (Article 20 GDPR): The right to receive the personal data that has been provided to the Business in a structured, commonly used, and machine-readable format and to request the transmission of such data to another data controller, where technically feasible. 

g) Right to Object (Article 21 GDPR): The right to object, at any time, to the processing of personal data based on the legitimate interests of the Business, including processing for direct marketing purposes. 

h) Right to Withdraw Consent: Where the processing of personal data is based on the data subject’s consent, the data subject has the right to withdraw such consent at any time, without affecting the lawfulness of the processing carried out prior to the withdrawal. 

11. EXERCISING YOUR RIGHTS

To exercise any of the rights described above, you may contact the Business at:

Email: littlegreekdress@yahoo.com

The Business will respond to requests without undue delay and, in any event, within one (1) month of receipt of the request. This period may be extended by an additional two (2) months where the request is particularly complex or where a large number of requests have been received. In such cases, you will be informed accordingly.

The Business reserves the right to request additional information necessary to verify the identity of the individual submitting the request, where such verification is required. 

12. SECURITY MEASURES

The Business implements appropriate technical and organisational security measures, taking into account the nature, scope, context, and purposes of the processing, as well as the risks to the rights and freedoms of natural persons.

Such measures include, without limitation:

-restricted access to personal data, limited solely to authorised personnel

-the use of passwords and authentication procedures

-protection of information systems against unauthorised access

-the implementation of backup procedures where necessary

-data breach management and incident response procedures

-cooperation exclusively with service providers that provide adequate guarantees of compliance with the GDPR.

Despite these measures, no method of data transmission over the Internet or method of electronic storage can be considered completely secure. Therefore, the Business cannot guarantee the absolute security of personal data. 

13. COOKIES AND SIMILAR TECHNOLOGIES

The website uses cookies and similar technologies to ensure its proper operation, enhance the user experience, analyse website traffic, and, where applicable, display personalised content or advertisements.

Detailed information regarding the cookies used, their purposes, retention periods, and the available options for managing them is provided in the website's separate Cookie Policy.

Strictly necessary cookies are used without prior consent, as they are essential for the operation of the website and the provision of the service requested by the user.

Non-essential cookies, including, by way of example, analytics, statistical, advertising, or personalisation cookies, are installed only after the user has provided prior consent through an appropriate consent management mechanism.

The management of consent preferences is carried out through the NOVA application, which records and retains users' preferences regarding the use of non-essential cookies in order to demonstrate whether the required consent has been obtained, in accordance with the GDPR, Greek Law 3471/2006, and the guidelines issued by the Hellenic Data Protection Authority (HDPA). 

14. MINORS

The website and the services provided by the Business are not intended for persons under the age of fifteen (15) years without the consent or authorisation of the person exercising parental responsibility, in accordance with applicable Greek legislation.

If the Business becomes aware that it has collected personal data relating to a minor in violation of the above provisions, it will delete such data without undue delay.

14A. RIGHT TO SUBMIT A REQUEST TO THE BUSINESS

Before submitting a complaint to the competent supervisory authority, the data subject may contact the Business in order to resolve any issue relating to the processing of their personal data, using the contact email address provided in this Privacy Policy.

15. RIGHT TO LODGE A COMPLAINT

If you believe that the processing of your personal data violates applicable data protection legislation, you have the right to lodge a complaint with the competent supervisory authority.

In Greece, the competent supervisory authority is the:

Hellenic Data Protection Authority (HDPA)

1–3 Kifisias Avenue, 115 23 Athens, Greece

Telephone: +30 210 6475600

Website: www.dpa.gr 

16. CHANGES TO THIS PRIVACY POLICY

The Business reserves the right to amend or update this Privacy Policy at any time in order to reflect changes in applicable legislation, business practices, or technological developments.

The current version of this Privacy Policy will be published on the website and will indicate the date of its latest update. Users are encouraged to review its contents regularly.

17. LANGUAGE OF THE PRIVACY POLICY

This Privacy Policy has been drafted in the Greek language. In the event that it is translated into any other language, the Greek version shall prevail in the case of any inconsistency, ambiguity, or difference in interpretation.

18. FINAL PROVISIONS

This Privacy Policy shall be governed by and construed in accordance with Greek law and the applicable European Union legislation on the protection of personal data.

Should any provision of this Privacy Policy be held to be invalid, unlawful, or unenforceable, such invalidity, unlawfulness, or unenforceability shall not affect the validity and enforceability of the remaining provisions, which shall remain in full force and effect.
















Availability