PERSONAL DATA PROTECTION POLICY
1. Data Controller
The website tokrimini.gr (hereinafter the “Website”) operates as a Data Controller of personal data in accordance with:
-
Regulation (EU) 2016/679 (GDPR)
-
Greek Law 4624/2019
-
Any other applicable Greek and European legislation.
The Website constitutes a private, controlled digital community for genealogical and historical documentation, with the following purposes:
-
preservation of cultural heritage
-
preservation of family memory
-
historical and research documentation.
2. Nature and Access to the Service
-
Access is granted exclusively to approved users.
-
Self-registration is not available.
-
Each registration request is evaluated and approved by an Administrator.
-
Each new entry or modification of data is temporarily stored and becomes visible only after administrative approval.
-
The content is not publicly accessible and is not indexed by search engines.
3. Categories of Data
3.1 User Data
-
Full name
-
Parents’ details
-
Date of birth
-
Username
-
Email address
-
Password (stored in encrypted form)
3.2 Genealogical and Historical Data
-
Identifying information of natural persons
-
Family relationships
-
Dates of birth and death
-
Historical information and archival data
The data may concern both deceased persons and, where applicable, living persons.
4. Purposes and Legal Basis of Processing
Processing is carried out for the following purposes:
-
Management of user accounts (Article 6(1)(b) GDPR)
-
Operation of the genealogical database (Article 6(1)(b))
-
Preservation of historical and cultural documentation (Article 89 GDPR)
-
Ensuring system integrity and security (Article 6(1)(f) – legitimate interest)
5. Submission of Third-Party Data
Users may submit information relating to third natural persons.
The process includes:
-
Temporary storage of the submitted entry
-
Review by an Administrator
-
Approval or rejection before the information becomes visible
The user declares that the information submitted is lawful and accurate.
The Website reserves the right to restrict or remove data that may violate the rights of third parties.
6. Special Categories of Data – Historical Context
Historical information that may fall under special categories of data may be recorded.
Such processing:
-
is limited to purposes of historical and archival documentation
-
does not aim at modern evaluation or discrimination of living persons
-
is subject to administrative review
-
may be restricted or removed upon request or after evaluation
Particular attention is given to data relating to living persons.
Where data concern living persons, special care is taken to limit the scope and visibility of the information, in order to protect privacy and dignity.
7. Access and Data Transfers
-
Access is granted exclusively to approved users.
-
No sale or commercial exploitation of data takes place.
-
Data are not transferred to third countries.
Access may be granted to research or cultural institutions, following evaluation and approval, under the same conditions that apply to registered users.
8. Provision of Structured Data Exports
Upon specific request, limited and targeted data exports may be provided for historical or research purposes under the following conditions:
-
The export concerns only data relating to deceased persons or data that may lawfully be transferred.
-
A specific data use agreement must be signed.
-
Commercial exploitation is prohibited.
-
Uncontrolled republication or transfer to third parties is prohibited.
-
Appropriate security measures must be implemented by the recipient.
The Website reserves the right to refuse any data export request.
9. Data Retention Period
Data are retained:
-
for as long as the user account remains active,
-
or for purposes of historical documentation,
-
unless lawful deletion is requested or otherwise required by applicable legislation.
10. Rights of Data Subjects
Each data subject has the right to:
-
access
-
rectification
-
erasure
-
restriction of processing
-
objection
-
data portability
-
withdrawal of consent (where applicable)
A complaint may be submitted to the Hellenic Data Protection Authority.
Requests for the exercise of rights must be submitted through the Website’s contact form.
The Website makes every reasonable effort to respond within the time limits established by law.
11. Security
Appropriate technical and organizational measures are implemented, including:
-
password encryption
-
restricted administrator access
-
administrative review of entries
-
regular backups
12. Amendments
This Policy may be amended.
Any changes are published on the Website and take effect from the date of publication.
13. Automated Decision-Making
No automated decision-making or profiling is carried out.