Privacy Policy
Effective Date: October 29, 2025
Website: www.yperos.gr
Contact Email: yperosbio@gmail.com
Registered Address: Μεσημέρι, Θεσσαλονίκης, Greece
1. Introduction
At Yperos (“we,” “us,” or “our”), your privacy is important to us.
This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit www.yperos.gr, purchase our products, or interact with us through any other channels.
We are committed to processing personal data in accordance with:
-
EU General Data Protection Regulation (GDPR) (EU 2016/679)
-
Greek Law 4624/2019 implementing the GDPR in Greece
-
Applicable e-Privacy and consumer protection regulations.
By using our website, you acknowledge that you have read and understood this Privacy Policy.
2. Data Controller
The Data Controller responsible for your personal information is:
Yperos
Μεσημέρι, Θεσσαλονίκης, Greece
yperosbio@gmail.com
If you have any questions about this Privacy Policy or your data rights, please contact us at the above email address.
3. What Personal Data We Collect
We collect the following types of personal data when you visit our website, create an account, or make a purchase:
a. Information You Provide Directly
-
Full name
-
Email address
-
Billing and shipping addresses
-
Telephone number
-
Payment information (processed securely by third-party payment gateways)
-
Order details and purchase history
-
Account login credentials (if you create an account)
-
Any communication sent to us (emails, contact forms, reviews, etc.)
b. Information Collected Automatically
When you browse our website, we may collect:
-
IP address and device identifiers
-
Browser type and version
-
Operating system and device type
-
Pages visited, time spent, and referring websites
-
Cookies and similar tracking technologies (see Section 10)
c. Information from Third Parties
We may receive data from:
-
Payment processors (e.g., PayPal, card networks)
-
Delivery partners (for shipment tracking)
-
Social media platforms (if you interact with our profiles)
4. Legal Basis for Processing
We process your personal data only when we have a valid legal basis under Article 6 of the GDPR:
| Purpose | Legal Basis |
|---|---|
| To process and fulfill your orders | Performance of a contract (Art. 6(1)(b)) |
| To provide customer support | Performance of a contract / Legitimate interest |
| To send order confirmations and service messages | Performance of a contract |
| To send marketing emails (with consent) | Consent (Art. 6(1)(a)) |
| To improve our website and services | Legitimate interest (Art. 6(1)(f)) |
| To comply with tax and accounting obligations | Legal obligation (Art. 6(1)(c)) |
5. How We Use Your Data
We use your personal information to:
-
Process and deliver your orders;
-
Communicate with you about purchases, returns, and support;
-
Provide account access and maintain your order history;
-
Improve website functionality and user experience;
-
Send marketing and promotional communications (only with your consent);
-
Comply with legal and regulatory requirements.
We will never sell or rent your personal data to third parties.
6. Sharing and Disclosure of Data
We may share limited personal data with trusted partners who assist us in providing our services, including:
-
Payment processors (for secure transactions)
-
Delivery and logistics partners (to deliver your orders)
-
IT and hosting providers (for website functionality and security)
-
Professional advisors (accountants, auditors, legal counsel when required)
All third parties are bound by data processing agreements and are required to process your data only as instructed by Yperos, in full compliance with GDPR.
We may also disclose information:
-
If required by law or legal process;
-
To protect our rights, customers, or the public.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes collected, including:
-
Order and payment records: retained for 6–10 years (for tax/legal compliance)
-
Customer accounts: retained until you delete your account
-
Marketing communications: retained until you withdraw consent
-
Cookies and analytics data: typically retained 12–24 months (see Section 10)
After the retention period, data is securely deleted or anonymized.
8. Data Security
We take appropriate technical and organizational measures to protect your data from unauthorized access, loss, alteration, or destruction, including:
-
SSL encryption on all website traffic;
-
Secure, GDPR-compliant hosting servers;
-
Restricted access to personal data;
-
Regular security updates and backups.
However, no online transmission is completely secure. You use the Service at your own risk.
9. Your Rights Under GDPR
You have the following rights under the EU GDPR:
-
Right of Access – Request a copy of your personal data we hold.
-
Right to Rectification – Correct inaccurate or incomplete data.
-
Right to Erasure (“Right to be Forgotten”) – Request deletion of your data under certain conditions.
-
Right to Restrict Processing – Ask us to limit how we use your data.
-
Right to Data Portability – Request a copy of your data in a structured format.
-
Right to Object – Object to processing for legitimate interests or direct marketing.
-
Right to Withdraw Consent – Withdraw consent at any time for processing based on consent.
-
Right to Lodge a Complaint – With the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.
To exercise any of these rights, please contact us at yperosbio@gmail.com.
10. Cookies and Tracking Technologies
We use cookies and similar technologies to:
-
Enable essential website functions;
-
Analyze site traffic and usage;
-
Improve your browsing experience;
-
Remember your preferences;
-
Display personalized offers (if applicable).
You can manage or disable cookies through your browser settings.
For detailed information, please see our Cookie Policy (available separately on our website).
11. International Data Transfers
We generally store and process your data within the European Economic Area (EEA).
If data is transferred outside the EEA (e.g., to hosting or service providers), such transfers occur under:
-
Adequacy decisions by the European Commission, or
-
Standard Contractual Clauses (SCCs) approved under GDPR.
12. Minors
Our website and services are not directed at children under 18.
We do not knowingly collect personal data from minors.
If we become aware that data from a minor has been collected, we will promptly delete it.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our practices.
Updated versions will be posted on www.yperos.gr with a revised Effective Date.
We encourage you to review this page periodically.
14. Contact Information
If you have any questions, concerns, or requests about this Privacy Policy or your personal data, please contact us at:
Yperos
Μεσημέρι, Θεσσαλονίκης, Greece
yperosbio@gmail.com

