Privacy Policy
A. Scope of the Privacy Policy
The company under the name "HOMLI SINGLE MEMBER P.C." with its registered office in Athens, Attica, Tzaferi St., No. 16, with Tax Identification Number 801751483 (hereinafter referred to as the "Company" or "HOMLI") with this Privacy Policy (hereinafter referred to as the "Policy") in its capacity as Data Controller aims to inform the users of its website https://thehomli.com (hereinafter referred to as the "Website") about the purpose and the means by which their personal data is processed. HOMLI respects the privacy and personal data of all natural persons dealing with it. In this context, and for the purpose of providing transparent information to all interested parties, HOMLI posts on its Website this Policy in order to provide adequate information regarding the personal data it processes in the context of its legitimate activities.
This Policy has been drafted taking into account the current National and European legal framework for the protection of personal data and in particular the General Data Protection Regulation (EU) 2016/679 ("Regulation") and Law 4624/2019.
In particular, this Policy aims to explain and clarify the basic principles and rules of personal data processing that HOMLI complies with, as well as to inform data subjects in regards to the processing operations carried out, the legal basis of such operations and their legal rights.
Β. Definitions
For the purposes of this Policy, the following terms shall have the following meanings:
"Personal Data": any information relating to an identified or identifiable natural person ("data subject"); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
"Processing" means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
"Controller" means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law;
"Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller;
"Data Subject" means the natural person whose personal data are processed. In this particular case, the Data Subject is considered to be any user of our Website.
"Consent" of the data subject: any freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her;
"Personal data breach" means a a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored or otherwise processed;
"Existing legislation": the respective national and EU legislation on personal data protection and in particular the General Data Protection Regulation (EU) 2016/679, Law 4624/2019 "Personal Data Protection Authority, measures implementing Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and transposing into national law Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 and other provisions" as well as the Decisions, Directives and Opinions of the Hellenic Data Protection Authority.
C. General Principles for the Processing of Personal Data
When HOMLI processes personal data, it shall ensure that:
- To process such data lawfully, in accordance with the provisions of existing legislation and the conditions laid down therein, in a transparent manner in relation to the data subject (Principle of Legitimacy, Objectivity and Transparency).
- Personal data are processed only for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes (Principle of Purpose Limitation).
- Personal data are adequate, relevant and limited to what is necessary for the purposes for which they are processed (Principle of Data Minimisation).
- It takes appropriate technical and organizational measures so that personal data are processed in a way that ensures an adequate level for their protection and security, including protection against unauthorised or unlawful processing and accidental loss, destruction or damage. In addition, periodically review the adequacy and effectiveness of these measures (Integrity and Confidentiality Principle).
- It makes the necessary efforts to ensure that the personal data it holds and processes are always accurate and up-to-date and that all reasonable steps are taken to promptly delete or correct personal data that are inaccurate in relation to the purposes of the processing (Principle of Accuracy).
- It does not retain the personal data collected for a longer time period than the one required for the fulfillment of the purposes for which they were collected and processed. However, HOMLI may retain personal data for a longer time period if the processing of these data is considered necessary for one or more of the following reasons:
- to comply with a legal obligation that requires processing under a provision of law.
- for the performance of a task carried out in the public interest or in the exercise of official authority vested in HOMLI.
- for reasons of public interest.
- for archiving purposes in the public interest, or for scientific or historical research purposes, or for statistical purposes, after appropriate technical and organizational measures have been taken, including pseudonymisation, and only if these purposes cannot be served by anonymisation of the data.
- for the establishment, exercise or defence of legal claims (Storage Period Limitation Principle).
- It takes the necessary and appropriate measures to comply with the requirements of the Existing Legislation and is able to demonstrate at any time the aforementioned compliance (Principle of Accountability).
D. Personal Data We Collect and Process, Purpose and Lawfulness of Processing
Ι. Personal Data collected through the contact form.
Through the contact form, the user is able to contact HOMLI. In case the user wishes to use this service, he/she must fill in the relevant fields (a) his/her name, (b) his/her email, (c) his/her phone number, and (d) the reason of contact.
Purpose of Processing and Legal Basis.
The purpose for the collection and processing of the aforementioned personal data is the provision of services by HOMLI and in particular the provision of specialized real estate services, the direct contact of the user with HOMLI and the optimal response of HOMLI to the user. The legal basis for processing the personal data of the users is the legitimate interest of HOMLI to provide high quality services to its clients and users of its Website (GDPR art. 6, par, 1, subpar. f).
II. Personal data collected through the use of cookies.
When you browse the Website, certain information related to the traffic of the Website may be collected, such as the user’s Internet Protocol (IP) address, the user’s type of browser etc. For more information about the use of cookies on the Website, please refer to the Cookies Policy.
Purpose of Processing and Legal Basis.
The purpose of the collection and processing of this data is to improve the functionality of the Website and the services provided, as well as to analyze its traffic. The legal basis for processing personal data is the user's consent (GDPR art. 6, par. 1, subpar. a), which is provided by accepting these cookies, with the exception of the absolutely necessary cookies which are permanently installed and are absolutely necessary for the operation of the Website, for which the legal basis for processing is the legitimate interest of the Company (GDPR article 6, par. 1, subpar. f). It is noted that we use targeting and retargeting services of various providers for the optimization of our websites, while we use Google Analytics of Google LLC and Hotjar of Hotjar Limited to conduct statistical analyses. The retention period of the information generated by cookies varies depending on the type of cookies.
For detailed information on the types of cookies we use, please
visit our Cookies Policy.E. Personal Data of Minors
HOMLI is not aimed or intended to be used by minors and as such it does not wish to collect and process personal data of minors (i.e. persons under the age of 18). However, since it is impossible to cross-check and verify the age of the users of the Website, HOMLI asks the parents/guardians of minors, in case they become aware of any unauthorized data disclosure on behalf of minors, to immediately notify HOMLI, so that HOMLI can take the necessary protective measures (e.g. immediate deletion of their data). If HOMLI becomes aware that it has collected the personal data of a minor, it will undertake to immediately delete them and take all necessary measures to protect such data.
F. Data Protection Impact Assessment (DPIA)
Where a type of processing is likely to present a high risk to the rights and freedoms of natural persons, HOMLI shall carry out, prior to the processing, an assessment of the impact of the envisaged processing operations on the protection of personal data ("Data Protection Impact Assessment -DPIA"). A DPIA, is a process designed to describe the processing, assess its necessity and proportionality and assist in risk management by evaluating and defining measures to address the risks. A DPIA is not required for every form of processing, but only in cases where a form of processing is considered to pose a high risk for the rights and freedoms of the data subjects. In the context of the impact assessment, the nature, scope, overall context and purposes of the processing are taken into account in order to assess whether a risk is likely to occur, as well as its seriousness for the rights and freedoms of the data subjects.
G. How do we ensure that Processors respect your Personal Data?
Our partner companies that act as data processors and/or sub-processors on our behalf have agreed and are contractually bound to:
- maintain privacy and ensure data confidentiality,
- process the data only for a specific purpose and for no other purpose
- not to transmit data to third parties,
- take appropriate organizational and technical security measures to ensure data protection,
- comply with the legal framework for the protection of personal data and in particular the Regulation and Law 4624/2019.
H. Transmission to third parties
Users' personal data may be transmitted to public authorities, independent authorities etc. during the exercise of their powers or at the request of a third party claiming a legitimate interest, following all legal procedures and in compliance with the appropriate safeguards to ensure the protection of personal data. HOMLI, reserves the right to disclose and/or transfer personal data to a third party to whom it may transfer or merge parts of its business or assets. In the event of a change in our business, the new owners will have the right to use your personal data in the same way as set out in this Policy.
Ι. Transfer of Personal Data outside the EU
- The European Commission has issued an adequacy decision for the third country to which the transfer will take place.
- The appropriate safeguards in accordance with the Regulation are complied with for the transfer of such data.
J. Data Retention Period
K. Security of Personal Data
All officers and employees of HOMLI are responsible for ensuring that personal data held and processed by HOMLI are kept securely and are not disclosed or transferred to any third party unless the third party is authorized by HOMLI to receive and process such information in the context of (a) HOMLI's lawful activities and where HOMLI has entered into a corresponding confidentiality agreement or (b) there is a legal obligation to do so by law or court order.
HOMLI undertakes all appropriate technical and organizational measures to ensure the security of the personal data it collects and processes. Although no method of transmission via the Internet or method of electronic storage is completely secure, HOMLI takes all necessary digital data security measures (firewall, encryption etc.).
HOMLI implements, both at the time of determining the means of processing and at the time of processing, appropriate technical and organizational measures designed to apply data protection principles and incorporate the necessary safeguards in the processing in such a way that the requirements of the GDPR are met and the rights of data subjects are protected (data protection by design).
HOMLI applies appropriate technical and organizational measures to ensure that, by default, only personal data that are necessary for the purpose of the processing are processed (data protection by default).
HOMLI shall ensure that the staff involved in the collection and processing of personal data are adequately informed and trained.
In the event of a personal data breach, HOMLI shall inform the Hellenic Data Protection Authority without delay, unless the breach is unlikely to cause a risk to the rights and freedoms of natural persons, providing all the necessary information and documentation. If the breach is likely to pose a high risk to the rights and freedoms of natural persons, HOMLI shall promptly communicate that breach to the data subjects, unless such communication would involve a disproportionate effort, or in the meantime HOMLI has implemented appropriate technical and organizational protection measures on the data affected by the breach that render it incomprehensible to unauthorised users, or in the meantime HOMLI has taken measures to ensure that a high risk to the rights and freedoms of natural persons is no longer likely to arise.
L. Rights of Data Subjects
HOMLI will ensure that it is able to respond promptly to users' requests to exercise their rights under the Existing Legislation.
In particular, each data subject has the following rights:
- Right of Access to his/her Data: To request information on the processing of his/her personal data by HOMLI. To request access to his personal data held by HOMLI. In particular, he may request to receive a copy of his personal data held and to check the lawfulness of the processing.
- Right to Rectification of Inaccurate Data: to request the rectification of his/her personal data in case that these data are incorrect or incomplete.
- Right to Erasure: To request the erasure of his/her personal data if their retention is not based on any legitimate basis or legitimate interest.
- Right to Restriction of Processing: To request the restriction of the processing of his/her personal data, subject to specific conditions.
- Right to Data Portability: to request the portability/transmission of his/her personal data either to himself/herself or to third parties.
- Right of Withdrawal/Objection: to withdraw at any time the consent given to the processing of his/her personal data, without this withdrawal affecting the lawfulness of the processing carried out until then, to object to the processing of his/her personal data by HOMLI, to object to a decision concerning him/her taken solely on the basis of automated processing, including profiling.
To exercise your rights, you may contact HOMLI at data@thehomli.com by submitting a request: a) for the rectification or deletion of the personal data you have entered or in any other manner provided us with or we have collected through our Website, b) for the restriction of the processing of the personal data you have entered or in any other manner provided us with or we have collected through our Website, c) for objection to the processing of the personal data you have entered or in any other manner provided us with or we have collected through our Website, d) for access and portability of the personal data you have entered or in any other manner provided us with or we have collected through our Website, and e) for the revocation of your consent to the processing of your personal data. In case of exercise of any of the above rights, HOMLI will provide the data subject with information on the processing operations upon request submitted within one (1) month from the receipt of the request and the identification of the data subject. This time limit may be extended by two (2) additional months, if necessary, in case that the request is complex or there is a large number of requests. In this case, HOMLI is obliged, within one (1) month of receipt of the request, to inform the user of the expected delay and the reasons why it is necessary.
HOMLI may refuse to comply in whole or in part with a request received from the data subject, only where such refusal is not prohibited by the Regulation or the national legislation.
If a request from the data subject is manifestly unfounded or excessive, in particular because of its repetitive nature, HOMLI may opt to charge a reasonable fee taking into account the administrative costs required to fulfill such request or refuse to respond to the request.


Ελλάδα
España
Italia
Belgium 