Personal Data Statement
Where Every Mile is a Smile
Statement of the Controller “Regarding the Protection of Personal Data”
The increasing economic and scientific collaborations as well as the mutual provision of data processing services result in the exchange of personal data, a trend that is reinforced by the ever-increasing use of modern telecommunications.
For these reasons, it is necessary to process data with care.
The Controller declares that compliance with the principles governing data protection for the processing thereof is its aim as it is committed to respecting individual rights and the privacy of individuals. The Controller handles personal data with special care and always in accordance with EU Regulation 2016/679, the applicable National Law and the applicable legislation.
For the purposes of this Directive, the following definitions shall apply:
Data Subject: any natural person whose personal data are processed by or on behalf of the Company
Personal Data: any information relating to an identified or identifiable natural person concerning his or her physical, physiological, psychological, emotional or economic situation, cultural or social identity.
Processing: processing of personal data (“processing”), any operation or set of operations which is performed on personal data, such as, but not limited to, collection, recording, storage, alteration, analysis, use, association, restriction (blocking), erasure or destruction.
1.Data Controller and DPO
The Data Controller is DIMITRA TZAMPAZI, with registered office in Alexandroupoli, Dimokratias Ave. no. 123, Postal Code 68132, Tax Identification Number 168243797 Tax Office of Alexandroupolis, and e-mail: info@pickndrive.gr (“Data Controller”).
2.The Data We Process
With your consent, we process the following common and sensitive personal data that you provide when you interact with the Website ( https://pickndrive.gr/), and use the services and functions it provides. These data include in particular your name and surname, contact details, address and the content of your specific requests, updates or reports as well as additional data that the Data Controller may obtain, including from third parties, in the context of carrying out its business activity (“Data”). In order to be able to fulfill the requests you submit through the contact form and/or to provide updates on adverse reactions, it is necessary for you to consent to the processing of the data marked with an asterisk (*).
Without this mandatory data or your consent, we cannot proceed further. On the contrary, the information requested in fields not marked with an asterisk and your consent to receive information material are optional and their failure to provide them has no consequence.
In any case, even without your prior consent, the Data Controller may process your data to comply with legal obligations arising from laws, regulations and EU law, to exercise rights in legal proceedings, to exercise its own legitimate interests and in all cases provided for, where applicable, in Articles 6 and 9 of the GDPR.
Processing is carried out both using computers and in printed form and always involves the implementation of security measures provided for by applicable legislation.
- Why and how we process your data
The data is processed for the following purposes:
- to handle the requests you submit via the ‘‘Form’’, to contact you subsequently or to provide you with information via The legal basis for processing personal data for this purpose is your consent (Article 6(1)(a) and Article 9(2)(a) of the GDPR) and the performance of the contract to which you are a party as a data subject;
- to handle reports of adverse events submitted via the Website or the Forms. The legal basis for processing for these purposes is your consent (Article 6(1)(a) and Article 9(2)(a) GDPR), as well as the pursuit of any public interest (Article 9(2)(i) GDPR) and legal obligations;
in addition, but only with your optional consent which constitutes the legal basis for processing pursuant to Article 6(1)(a) GDPR:
- to receive advertising material (direct marketing) from us.
By checking the appropriate boxes you agree to the processing of your data for these purposes.
Your data may in any case be processed, even without your consent, for the purposes of compliance with laws, regulations, EU law (Article 6(1)(c) of the GDPR Regulation, to obtain statistics on the use of the Website and its proper functioning (Article 6(1)(f) of the Regulation).
Personal data are entered into the Controller’s IT system in full compliance with data protection legislation, including security and confidentiality profiles and are based on principles of good practice, lawfulness and transparency regarding processing.
The data are stored for as long as is strictly necessary to achieve the purposes for which they were collected. In any case, the criterion used to determine this period is based on compliance with the deadlines set by law and on the principles of data minimization, storage limitation and rational file management.
All your data will be processed on paper or by automated means, ensuring in each case the appropriate level of security and confidentiality.
- Principles applied during processing
We are allowed to process your personal data in order to provide personalized services, based on the law (Article 6(1b) of Regulation (EU) 2016/679) and the relevant National Implementing Law. Your personal data are not used for other purposes, other than those described in the Statement, unless we obtain your prior permission, or unless this is required or permitted by law.
Personal data are processed in a manner compatible with the purpose for which they have been collected.
The principle of proportionality applies when processing personal data. Among other things, it creates the obligation not to collect personal data without reason.
Personal data used should be accurate and up-to-date.
Personal data used that are no longer accurate and complete should be corrected or deleted.
Except where there is a legal obligation to retain them for a longer period, personal data shall not be stored for longer than is necessary for the purposes for which they were collected or processed.
The processing of personal data shall be carried out in accordance with the principles of good faith. This means that data subjects may rely on the processors to exercise due care in all matters relating to data processing.
Data subjects whose personal data have been processed shall be informed accordingly, upon request. In particular, they shall have the right to be informed of the purposes for which their data are processed, the type of data they concern, and the identity of the recipients of the data. Where necessary, data subjects shall also have the right to request the rectification, non-transmission or erasure of their data.
The above rights may only be restricted if such restriction is provided for by law. This applies, in particular, when conducting scientific research.
In particular, personal data are protected against unauthorized disclosure and any unlawful processing. The measures implemented ensure a level of security appropriate to the nature of the data to be protected and the risks that may arise from their processing.
The controller is responsible for compliance with and implementation of EU Regulation 2016/679 and the National Implementing Law.
Our employees involved in the processing of personal data are informed and trained accordingly. The procedures for the processing of personal data of third parties following an agreement will be defined in writing, having ensured that the contracted third party processes personal data in a secure manner and that it complies with the principles set out in this Statement and the GDPR EU. In the event that the third party is deemed unable to ensure a satisfactory level of security of personal data, we will terminate the cooperation.
- Persons who have access to the data
The Data are processed by electronic and manual means in accordance with the procedures and practices related to the aforementioned purposes and are accessible by the Controller’s staff authorized to process the Personal Data and supervisors and in particular employees belonging to the following categories: technical staff, Information and Network Security staff and administrative staff as well as other staff members who need to process the data for the performance of their duties.
The Data may also be communicated to countries outside the European Union (“Third Countries”): i) to institutions, authorities, public bodies for institutional purposes; ii) to professionals, independent consultants – whether working individually or collectively – and other third parties and providers who provide the Data Controller with commercial, professional or technical services required for the operation of the Website (e.g. provision of IT and Cloud Computing services) for the purposes mentioned above and to support the Data Controller in providing the services you have requested; iii) to third parties in the event of mergers, acquisitions, transfers of businesses or their branches, audits or other extraordinary operations;
The aforementioned recipients receive only the data necessary for their respective functions and duly process them only for the purposes mentioned above and in accordance with data protection laws. The Data may also be communicated to other lawful recipients specified from time to time by applicable laws.
Except as above, the Data will not be communicated to third parties, natural or legal persons, who do not perform commercial, professional or technical tasks for the Controller and will not be disseminated. The persons receiving the data will process them, as the case may be, as Data Controllers, Processors or persons authorized to process personal data for the purposes mentioned above and in accordance with applicable data protection legislation.
Regarding the transfer of data outside the EU, even to countries whose laws do not guarantee the same level of protection of personal data privacy as that provided by EU law, the Controller informs that the transfer will in any case be carried out in accordance with the methods permitted by the GDPR, such as for example based on the user’s consent, based on the standard contractual clauses approved by the European Commission, by choosing parties that participate in international programs for the free movement of data (e.g. EU-US Privacy Shield) or that are implemented in countries considered safe by the European Commission.
- Your rights
If you wish, you may request at any time to exercise the rights of articles 15-22 of the GDPR Regulation, to be informed about your personal data held by us, their recipients, the purpose of their holding and processing as well as their modification, correction or deletion, by sending a relevant email to the addresses shown above, from the contact email address you have stated, by completing the application that the Data Controller may provide you with, attaching a copy of your ID card. You also have the right to review the personal data we hold and generally to exercise any right provided for by the legislation on the protection of personal data.
The personal data that you disclose to the Data Controller through the website https://pickndrive.gr/ either during your registration or at a later stage, are collected and used and processed in accordance with the applicable provisions on the protection of personal data of the new European General Data Protection Regulation (EU) 2016/679.
You retain the following rights in detail:
- Right to information about your personal data: Upon your request, we will provide you with information about the personal data we hold about
- Right to correction and completion of your personal data: If you notify us, we will correct any inaccurate personal data concerning We will complete incomplete data if you notify us, provided that such data is necessary for the purposes of processing your data.
- Right to erasure of your personal data: Upon your request, we will erase the personal data we hold about However, some data will only be erased after a specified retention period, for example because in certain cases we are legally obliged to retain the data, or because the data is required to fulfil our contractual obligations towards you.
- Right to block your personal data: In certain cases provided for by law, we will block your data if you ask us to do Further processing of blocked data will only take place to a very limited extent.
- Right to withdraw your consent: You can withdraw your consent to the processing of your personal data at any time with effect for the The lawfulness of the processing of your data remains unaffected by this action, up to the point of withdrawal of your consent.
- Security of Personal Data
The Controller applies specific technical and organizational security procedures in order to protect personal data and information from loss, misuse, alteration or destruction. Our partners who support us in the operation of this website also comply with these provisions.
The Controller makes every reasonable effort to keep the personal data collected only for the period for which it needs these data for the purpose for which they were collected or until their deletion is requested (if this occurs earlier), unless it continues to keep them as provided for in applicable law.
- Revisions to the Statement
We reserve the right to modify or revise this Statement periodically, at its sole discretion. In the event of changes, the Controller will record the date of modification or revision in this Statement and the updated Statement will apply to you from that date.
We encourage you to periodically review this Statement in order to review whether there are any changes to the way we manage your personal data.
This is a Declaration of Compliance with the provisions of EU Regulation 2016/679 and the National Implementing Law.
April 2025