Privacy Policy

 

Notice on Personal Data Processing by finThesis

Notice on personal data processing by finThesis in compliance with Regulation (EU) 2016/679, Greek Law 4624/2019 and the relevant Greek and EU legislation.

finThesis Financing Solution Creators Single-Member SA, trading under “finThesis SINGLE-MEMBER SA” (hereinafter “finThesis”), in compliance with General Data Protection Regulation (ΕU) 2016/679 (hereinafter “GDPR”), Greek Law 4624/2019 on its implementation and all relevant provisions in the Greek and EU legislation on personal data protection, in its capacity as data controller, informs you about the processing of your personal data and your rights as a data subject.

1. Who this Notice concerns

This Notice is addressed to natural persons interested in the services provided by finThesis, as well as to any natural persons linked to these persons (e.g. family members, representatives, authorised attorneys at law, process agents, other authorised persons, employees, associates, legal representatives, shareholders and beneficial owners of finThesis transacting parties who are legal persons or entities etc.).

More information about the services provided by finThesis can be found here. finThesis is a credit brokerage company licensed by the Bank of Greece pursuant to article 28 of Law 4438/2016 and Bank of Greece Executive Committee Act 137/16.4.2018

2. Who this Notice concerns

The Controller of all your personal data is finThesis, registered in 15 25is Martiou Street, 17676, Tavros, General Commercial Register (GEMI) number 178570501000.

3. Which of your personal data are processed by finThesis and where does finThesis collect them from

Α) Categories of personal data processed by finThesis

The personal data collected and processed by finThesis may include the following:

  • Identification details: full name, copy or number of ID card or passport, tax number etc.
  • Contact details: postal address, email address, phone number (landline or mobile) etc.
  • Data from the use of finThesis online and/or digital services (e.g. cookies, IP addresses, location data or other online identification details), in accordance with their special terms.
  • Data on your financial, asset and marital status: occupation and time of occupation, remuneration, dependent members, if you are married, in civil partnership, widowed or not, tax returns (E1, E9 forms etc.), tax clearance certificates, insurance clearance certificates, mobile assets, real estate and other assets etc., which are provided in the context of processing requests relevant to credit intermediation services.
  • Data concerning your credit rating: such as obligations to credit or financial institutions stemming from any loans and credit etc. which are provided in the context of processing requests relevant to credit intermediation services.
  • Image data from the video surveillance systems used in finThesis spaces, which have the labels/notices required by law (detailed notice on personal data processing through the video surveillance system and upon entering finThesis facilities).
  • Data from documents and supporting documents you submit or send to finThesis in the context of your relationship with finThesis as well as data concerning or included in your requests when contacting finThesis or finThesis customer service or finThesis associates (including any data found in the contract or in other documents relevant to the property for which you have expressed interest and which is linked to your application for credit intermediation services).

Β) Sources from which finThesis collects your personal data

finThesis collects the aforementioned data from the following sources:

  • Directly from you or from third parties acting on your behalf (representatives, authorised attorneys at law etc.) or associated with you, when contacting finThesis, when browsing the finThesis website (https://www.finthesis.gr/), when logging into finThesis contact forms and platforms (including the estegastiko by finThesis platform).  finThesis is not responsible for any illegal processing of your personal data by third parties in accordance with the above.
  • From third-party service providers, finThesis suppliers and associates (including brokers).
  • From electronic devices or apps you are using or from service providers associated with finThesis.
  • From companies of the Group finThesis is part of.

In case you provide third-party personal data, you must first inform those parties in an appropriate manner about the fact that their personal data will be transferred and processed by finThesis, including by referring to this notice) and you must have obtained their consent, where such consent is necessary.

4. Why does finThesis collect and process your data

The processing of your personal data serves, among others, the following purposes:

A. To manage your registration in the estegastiko by finThesis platform and the requests you submit through this platform

If you decide to submit a request through the estegastiko by finThesis platform, you must first log into the platform to be recognised as a registered user and gain access to your account and the various functionalities and information available to you.

Β. To take measures following your request on a pre-contractual level, as well as in the contract signing and execution stage

In particular, this processing of your personal data serves purposes such as to identify you, verify your details, contact you and, in general, process your request for credit intermediation services.

C. To comply with finThesis legal obligations

finThesis will process your personal data to the extent necessary to comply with the following legal and supervisory obligations it is subject to and which result from Law 4438/2016 and the relevant Executive Committee Acts of the Bank of Greece, as in effect from time to time:

i. the legal and regulatory framework for money laundering and terrorist financing, as in effect from time to time (in particular, Law 4557/2018, Bank of Greece’s Banking and Credit Committee Decision 281/5/17.3.2009, Directive 2005/60/ΕU, Directive 2015/849/ΕU, recommendations of the Financial Action Task Force, as well as all relevant acts, decisions and executive circulars of any competent authority),

ii. Bank of Greece’s Executive Committee Act no. 157/02.04.2019, as in effect from time to time, which imposes, among others, notice obligations and transparency of transaction conditions in general, including the management of debtor requests and complaints,

iii. the submission of supervisory reports to the Bank of Greece and the conduct of audits by the Bank of Greece,

iv. finThesis’ compliance with the obligations arising from the legal, regulatory and supervisory framework in effect from time to time, as well as the decisions of any competent authorities (public, supervisory, independent, prosecution etc.) or courts (including arbitration courts).


D. For finThesis or third-party legitimate interest purposes (Group companies, associated companies etc.)

The processing of your personal data also serves purposes such as to establish, exercise and defend legal claims, comply with finThesis policies, comply with finThesis contractual terms with third parties, meet finThesis corporate objectives, secure information systems and assets in general of finThesis and/or third parties, keep historical records, safeguard fame, prevent criminal acts or fraud against finThesis or third parties, manage complaints, assess and optimise functionalities, processes, security and IT system procedures, upgrade services provided etc.

Ε. Provided you have given your consent

Provided you have been asked and given your consent, the processing of your personal data will be based on this consent.

In these cases, you have the right to withdraw your consent at any time, without affecting the lawfulness of the processing on which it was based, until its withdrawal.

5. Who are the recipients of your personal data  

In the context of processing your personal data, finThesis may transfer them to the following recipients:

  • The respective credit institutions (data controllers) in the context of processing your relevant requests.
  • The competent employees and the management of finThesis in the context of their duties, and companies of the Group finThesis is part of.
  •  Service providers relevant to storage, archiving, file and data management and destruction, IT applications and maintenance, electronic communication, cloud services, information society services, accounting/tax and postal services.
  • Supervisory, independent, judicial, police, tax, public and/or other authorities, to the extent necessary.
  • Brokers, notaries, engineers, lawyers, to the extent necessary.

6. Personal data transfer to countries outside the European Economic Area

finThesis does not directly transfer your personal data to third countries or international organisations unless such transfer is required by the applicable regulatory or legislative framework.
If applicable, finThesis may transfer your personal data to third countries provided that:

  • A sufficient level of protection is ensured, in accordance with the European Commission, by the third country, a territory or one or more specific sectors in said third country or by the international institution.
    or
  • Appropriate guarantees have been provided for their processing by the recipient, based on national and/or EU legislation.

 If none of the aforementioned conditions apply, your personal data may be transferred:

  • If you have given finThesis explicit consent to do so.
    or
  • The transfer is required to execute your contract with finThesis, e.g. to execute your orders.
    or
  • The transfer is necessary to establish or exercise finThesis legal claims or defend finThesis rights.
    or
  • finThesis is otherwise obliged by law or transnational agreements.

To meet this obligation, finThesis may transfer your personal data to competent national authorities so that they forward them to the respective third-country authorities.

7. How long your personal data will be retained for

Your personal data will be retained throughout the time the user account on the estegastiko by finThesis platform remains active and/or throughout your business relationship with finThesis.

In case of litigation against finThesis or relevant administrative dispute, the time your personal data will be retained is extended until a final court judgement has been handed down.

finThesis will retain records of all the complaints it has received, including the documents relevant to each case, for a minimum of five (5) years in accordance with Bank of Greece’s Executive Committee Act no. 157/02.04.2019. Furthermore, finThesis will retain every document required for the purposes of prevention, identification and investigation of money laundering and terrorist financing in accordance with Law 4557/2018 for ten (10) years after your business relationship with finThesis has ended.

In addition, your personal data will be retained for any time required by the applicable legal and regulatory framework.

8. Your personal data protection rights vis-à-vis finThesis

According to GDPR, you have the following rights:

i. The right of access to personal data relating to you, which we retain and process, as well as to information relevant to their processing (data origination source, processing purposes, recipient categories, data retention period).

ii. The right to correct your personal data, in case of any inaccurate details or to supplement incomplete data, by submitting any necessary document requiring to correct or supplement data.

iii. The right to object processing of your personal data, in case the processing has been assigned to finThesis to fulfil a duty in the public interest or when exercising public power or pursuing finThesis legitimate interests, including profiling.

iv. The right to limit processing of your personal data, where either the accuracy of such data is contested or the processing is unlawful, or finThesis does not require your personal data for the purposes of processing, or you have exercised your right to object and it has not been verified yet whether finThesis’ legal grounds prevail over yours.

v. The right to erase your personal data from the records we keep.

vi. The right to portability of your personal data to another controller, provided that processing is based on your consent or a contract and is done using automated means.

Please note the following with regard to the aforementioned rights:

  • finThesis has in any case the right to refuse your request to limit processing of or erase your personal data, if the processing or retention is necessary to exercise your rights or meet finThesis obligations vis-à-vis you, as well as to establish, exercise or defend finThesis rights or to comply with legal obligations.
  • In addition, finThesis has in any case the right to refuse to erase your personal data, given that some of these data cannot be erased for the purposes of keeping historical records.
  • Exercising the right to portability of your personal data (see vi above) does not imply the erasure of your data from finThesis records; said erasure is subject to the previous paragraph.
  • The aforementioned rights can be exercised in a forward-looking manner and cannot apply to personal data processing that has already been conducted.

9. How to exercise your rights at finThesis

To exercise your rights under the previous section, you can contact finThesis in writing at 15 25is Martiou Street, 17676, Tavros, Greece, or at dpo@finthesis.gr.

finThesis will make every possible effort to respond to your request within one month after submission. This deadline can be extended for two (2) additional months, if finThesis reasonably deems it necessary, taking into account the complexity of the request and the number of requests. finThesis will notify you if the one-month deadline has been extended.

The above service is provided by finThesis free of charge. In case, however, submitted requests are clearly unfounded, excessive or repetitive, finThesis may either impose a reasonable fee to the requester notifying them accordingly, or refuse to respond to their request(s).

10.finThesis Data Protection Officer

You can contact finThesis’ Data Protection Officer on matters relating to the processing of your personal data at 15 25is Martiou Street, 17676 Tavros, Attica, Greece or at dpo@finthesis.gr.

11. Right to lodge a complaint with the competent Data Protection Authority

You have the right to lodge a complaint with the competent Data Protection Authority for matters relating to the processing of your personal data. You can find detailed information about the Authority’s remit as well as about how to lodge a complaint on its website (www.dpa.gr – Individuals – Complaint to the Hellenic DPA).https://dpa.gr

12. Security of your personal data

finThesis implements appropriate technical and organisational measures for lawful collection and processing, as well as for the effective protection of your personal data against unauthorised or unlawful processing, loss, alteration, accidental or unlawful destruction or damage, prohibited transmission or third-party access, and any other form of unlawful processing.

13. Updates and amendments to this Notice on personal data processing

Based on its data protection policy in force from time to time and in the context of the legislative and regulatory framework in force from time to time, finThesis may revise or amend this Notice, which will always be available on www.finthesis.gr.

Latest update of this Notice: November 2024

 

Notice on personal data processing of finThesis suppliers, service providers and associates

Notice on personal data processing of finThesis suppliers, service providers and associates in compliance with Regulation (EU) 2016/679 and the relevant Greek legislation.

finThesis Financing Solution Creators Single-Member SA, trading under “finThesis SINGLE-MEMBER SA” (hereinafter “finThesis”), in compliance with General Data Protection Regulation (ΕU) 2016/679 (hereinafter “GDPR”), Law 4624/2019 on its implementation and all relevant provisions in the Greek and EU legislation on personal data protection, in its capacity as data controller, informs you about the processing of your personal data and your rights as a data subject.

1. Controller details

The Controller of all your personal data is finThesis, registered in 15 25is Martiou Street, 17676, Tavros, General Commercial Register (GEMI) number 178570501000.

2. Who this Notice concerns

This Notice is addressed to finThesis suppliers, service providers and associates, as well as to natural persons connected with them, e.g. staff, associates, representatives, managers, subcontractors, agents etc., whose personal data are subject to processing for the purposes mentioned herein.

Note that, in case the supplier and/or service provider and/or associate is a legal person or entity, this Notice is addressed to the managers, representatives, employees, partners and management bodies of said person or entity, whose personal data are subject to processing by finThesis in the context and for the purposes of the respective agreement with finThesis.

This Notice may be complemented with special finThesis notices and policies, e.g. the Notice on personal data processing by finThesis.

3. Which of your personal data are processed by finThesis and where does finThesis collect them from

Α. Categories of personal data processed by finThesis

The personal data collected and processed by finThesis may include the following:

  1. Identification details: full name, father’s name, mother’s name, ID card/passport number, tax registration number, tax office, social security number (AMKA), date and place of birth, nationality, gender, photograph, electronic identification details, such as username, signature details etc.
  2. Contact details: postal address, email address, phone number (landline or mobile) etc.
  3. Occupation and professional skill details: e.g. information contained in submitted CVs and/or quotes, in submitted documents and supporting documents, such as professional certifications, recommendations and/or contact details for third-party recommendations and confirmations, as well as professional experience or activity details, details on your professional card etc.
  4. Financial behaviour data, in special cases where finThesis recognises high fraud risk depending on the nature of the contract and the services provided, in accordance with the applicable legal and regulatory framework.
  5. Financial information and pricing data, including your bank account.
  6. Financial status and insurance clearance data: e.g. in case of legal representatives of general partnerships or sole proprietorships, income tax returns, tax and insurance clearance certificates, certificates of no previous bankruptcy, no filing for bankruptcy, no declaration of cessation of payments, debt information etc., in accordance with the applicable legal and regulatory framework and finThesis policies.
  7. Data derived throughout your relationship with finThesis: e.g. communications/correspondence with finThesis or third parties in the context of your duties/responsibilities, data on provisions/expenses, access data for physical locations, systems, files, as well as any other relevant electronic equipment of finThesis etc.
  8. Data collected through the finThesis CCTV, as well as access data for physical locations, systems, files and any other relevant electronic equipment (e.g. portable storage devices) of finThesis or other companies of the Group finThesis is part of.

Β. Sources from which finThesis collects your personal data

finThesis collects the aforementioned data from the following sources:

  1. Directly from you or third parties acting on your behalf (representatives, proxies etc.) or connected with you. finThesis is not responsible for any illegal processing of your personal data by third parties in accordance with the above.
  2. Our employees, as well as third-party service providers, suppliers and finThesis associates.
  3. Publicly accessible sources.

Note that the aforementioned data may also be collected or verified by companies of the Group finThesis is part of or by third parties working for you.

According to the GDPR, personal data must be updated and accurate. Therefore, you are obliged to notify finThesis about any change in the personal data you have submitted.

In case you provide third-party personal data, you must first inform those parties in an appropriate manner about the fact that their personal data will be transferred and processed by finThesis, including by referring to this notice, and you must have obtained their consent, where such consent is necessary.

4. Why does finThesis collect and process your data

finThesis processes your personal data in the context and for the purposes of the agreement we have signed. Specifically, finThesis processes your data for the following purposes:

Α. To execute a contract and take measures following your request prior to signing a contract

The processing of your personal data serves, among others, the following purposes:

i. To identify you, verify your details and communicate with you, including both the pre-contractual and the contractual stage of your relationship.

ii. To manage your contract with finThesis, as well as to prepare with you, execute and manage a contract with finThesis and meet the obligations of all parties.

B. To comply with finThesis legal obligations

finThesis shall process your personal data to the extent necessary, to comply with the obligations of the applicable legal, regulatory and supervisory framework, as well as the decisions of authorities (public, supervisory, independent, judicial etc.) or courts (regular or arbitration), as well as to protect persons and goods.

C. For finThesis or third-party legitimate interest purposes (Group companies, associated companies etc.)

The processing of your personal data also serves, among others, the following purposes:

  • to establish, exercise and defend legal claims;
  • to comply with finThesis policies;
  • to comply with finThesis contractual terms with third parties;
  • to safeguard the security of information systems and assets in general of finThesis and/or third parties;
  • to keep historical records;
  • to safeguard fame;
  • to prevent criminal acts or fraud against finThesis or third parties etc.

Before this processing it is ascertained that your interests, fundamental rights and freedoms that impose the protection of your data do not prevail over the legal interests of finThesis or the respective body.

5. Who the recipients of your personal data are

In the context of processing your personal data, finThesis may transfer them to the following recipients:

  1. The competent employees and the management/committees of finThesis in the context of their duties, and companies of the Group finThesis is part of.
  2. Attorneys at law, law firms, bailiffs, notaries public, experts, chartered accountants/auditors and consultants etc.
  3. Service providers relevant to the storage, archiving, file and data management and destruction, IT applications and maintenance, teleconference services, electronic communication, cloud services, information society services and postal services.
  4. Supervisory, independent, judicial, police, tax, public and/or other authorities or bodies, accredited mediators and mediation service centres, arbitration courts and alternative out-of-court dispute resolution entities.

6. Personal data transfer to countries outside the European Economic Area

finThesis does not directly transfer your personal data to third countries or international organisations unless such transfer is required by the applicable regulatory or legislative framework.

If applicable, finThesis may transfer your personal data to third countries provided that:

i. A sufficient level of protection is ensured, in accordance with the European Commission, by the third country, a territory or one or more specific sectors in said third country or by the international institution, or

ii. Appropriate guarantees have been provided for their processing by the recipient, based on national and/or EU legislation.

If none of the aforementioned conditions apply, your personal data may be transferred provided that:

i. You have given finThesis explicit consent to do so, or

ii. The transfer is required to execute your contract with finThesis, e.g. to execute your orders, or

iii. The transfer is necessary to establish or exercise finThesis legal claims or defend finThesis rights, or

iv. finThesis is otherwise obliged by law or transnational agreements.

To meet this obligation, finThesis may transfer your personal data to competent national authorities so that they may forward them to the respective third-country authorities.

7. How long your personal data will be retained for

Your personal data will be retained throughout your contractual relationship and collaboration with finThesis, and for as long it is required by the applicable legal and regulatory framework and, in any case, until the statute of limitations has passed, i.e. up to twenty (20) years from the termination of your collaboration with finThesis.

In particular, in case of litigation against finThesis, the time your personal data will be retained is extended until a final court judgement has been handed down.

Furthermore, a few necessary data (e.g. identification details, data contained in the minutes of finThesis management bodies etc.) may become part of finThesis’ historical record and, therefore, be kept for as long as said record exists.

8. Your personal data protection rights vis-à-vis finThesis

According to GDPR, you have the following rights:

i. The right of access to personal data relating to you, which we retain and process, as well as to information relevant to their processing (data origination source, processing purposes, recipient categories, data retention period).

ii. The right to correct your personal data, in case of any inaccurate details or to supplement incomplete data, by submitting any necessary document requiring to correct or supplement data.

iii. The right to object on grounds relating to your particular situation in the case where the processing is required for the purposes of the legitimate interests pursued by the Company or a third party.

iv. The right to limit processing of your personal data, where either the accuracy of such data is contested or the processing is unlawful, or finThesis does not require your personal data for the purposes of processing, or you have exercised your right to object and it has not been verified yet whether finThesis’ legal grounds prevail over yours.

v. The right to erase your personal data from the records we keep.

Please note the following with regard to the aforementioned rights:

  • finThesis has in any case the right to refuse your request to limit processing of or erase your personal data, if the processing or retention is necessary to exercise your rights or meet finThesis obligations vis-à-vis you, as well as to establish, exercise or defend finThesis rights or to comply with legal obligations.
  • finThesis has in any case the right to refuse to erase your personal data, given that some of these data cannot be erased for the purposes of keeping historical records or if, due to the special nature of data storage, it is not possible to erase them or it is only possible to erase them after disproportionate effort.
  • The aforementioned rights can be exercised in a forward-looking manner and cannot apply to personal data processing that has already been conducted.

9. How to exercise your rights at finThesis

To exercise your rights under the previous section, you can contact finThesis in writing at 15 25is Martiou Street, 17676, Tavros, Greece, or at dpo@finthesis.gr.

finThesis will make every possible effort to respond to your request within one month after submission. This deadline can be extended for two (2) additional months, if finThesis reasonably deems it necessary, taking into account the complexity of the request and the number of requests. finThesis will notify you if the one-month deadline has been extended.

The above service is provided by finThesis free of charge. In case, however, submitted requests are clearly unfounded, excessive or repetitive, finThesis may either impose a reasonable fee to the requester notifying them accordingly, or refuse to respond to their request(s).

10. finThesis Data Protection Officer

You can contact finThesis’ Data Protection Officer on matters relating to the processing of your personal data at 15 25is Martiou Street, 17676 Tavros, Attica, Greece or at: dpo@finthesis.gr.

11. Right to lodge a complaint with the competent Data Protection Authority

You have the right to lodge a complaint with the competent Data Protection Authority for matters relating to the processing of your personal data.

In relation to the Authority’s competencies and procedures for lodging complaints, you may visit the website of the Hellenic Data Protection Authority: www.dpa.gr > Rights of individuals > Complaint to the Hellenic DPA, where detailed instructions are available.

12. Security of your personal data

finThesis is implementing appropriate technical and organisational measures for lawful collection and processing, as well as for the effective protection of your personal data against unauthorised or unlawful processing, loss, alteration, accidental or unlawful destruction or damage, prohibited transmission or third-party access, and any other form of unlawful processing.

13. Updates and amendments to this Notice on personal data processing

Based on its data protection policy in force from time to time and in the context of the legislative and regulatory framework in force from time to time, finThesis may revise or amend this Notice, which will always be posted on www.finthesis.gr.

Latest update of this Notice: November 2024

Privacy Notice on the Processing of Personal Data by finThesis

Privacy Notice on the processing of personal data of finThesis in accordance with the European Regulation (EU) 2016/679, Greek Law 4624/2019 and relevant applicable Greek and European legislation

“finThesis Financing Solution Creators Single Member Société Anonyme”, with distinctive title finThesis Single Member S.A. (hereinafter “finThesis”) informs you pursuant to the General Data Protection Regulation (EU) 2016/679 (hereinafter referred to as “GDPR”), Greek law 4624/2019 for the implementation thereof and the relevant applicable Greek and European legislation on the protection of personal data, under its capacity as a controller with regard to the collection and further processing of your personal data as well as your rights as data subject.

1. Who this Notice concerns

This Notice is addressed to the persons that show interest, for the services provided by finThesis as well as to any related parties to the aforesaid persons, (indicatively family members, attorneys-infact, agents, counterparties, other authorized persons, employees, partners, legal representatives, shareholders and beneficial owners of persons dealing with finThesis who are legal persons or entities, etc.).

For the insurance intermediation services provided by finThesis, further information is available here. finThesis is registered as an insurance agent in the Special Register of the Athens Chamber of Commerce and Industry under Special Register number EBEA/10396. This information may also be verified through the Single Information Point for insurance intermediaries at: http://insuranceregistry.uhc.gr

2. Details of the controller of your personal data

The data controller of your personal data is finThesis headquartered in 15 25th March street, 17676, Tavros, Greece, with GEMI no. 178570501000..

More information about finThesis, www.finthesis.gr .

3. What personal data finThesis processes and which sources it collects such data from

Α) Categories of personal data processed by finThesis.

The personal data collected and processed by finThesis include, indicatively, the following, which may not all apply to you:

  • Identification data: name, surname, father’s name, tax identification number (TIN), date of birth etc.
  • Communication data: Postal address, e-mail address, telephone number (landline or mobile), etc.
  • General Infromation: Job position.
  • Image data collected from the video surveillance systems at the premises of finThesis, where relevant notification signs have been placed pursuant to the law (analytical information for the processing of the personal data through the video
    surveillance system at your entrance in the premises of finThesis).
  • Data resulting from documents and supporting documents that you provide or send to finThesis in the context of your relationship with finThesis as well as data concerning or contained in your requests when you contact finThesis or the staff of the customer service department or the finThesis partner network (including any data included in any document
    you submitted).


Β) Sources from which finThesis collects your personal data

finThesis collects the above-mentioned personal data either directly from you or from third parties acting on your behalf (such as representatives, authorised agents, lawyers, etc.). finThesis shall not be liable for any unlawful processing of your personal data by such third parties, as referred to above.

In the event that you provide finThesis with personal data relating to third parties, you must have duly informed such individuals in advance of the transfer and processing of their personal data by finThesis, including by referring them to this Privacy Notice, and you must have obtained their consent, where such consent is required.

4. Why finThesis collects your data and for which purposes it processes them

In particular, finThesis processes your data for the following purposes:

A. The identification of your insurance requirements and needs, for the purpose of providing insurance intermediation services.

If you decide to submit a request for obtaining an insurance product, finThesis, in its capacity as an insurance agent, will process your personal data for the purpose of providing advice in relation to the insurance products marketed by finThesis.

Β. For the execution of the agreement and the measures taken following your request prior to the conclusion of the agreement

Such processing of your personal data serves, in particular, purposes such as your identification, the verification of your details, communication with you, and, in general, the processing of your request relating to insurance intermediation services.

C. For the compliance of finThesis with its legal obligations

finThesis shall process your personal data to the extent necessary in order to comply with the legal and regulatory obligations to which it is subject, including Law 4583/2018, as well as with decisions of any competent authorities (public, supervisory, independent, prosecutorial, etc.) or courts (including arbitrary)

D. For legitimate interest purposes pursued by finThesis or third parties (indicatively, companies of the Group, affiliates etc.)

The processing of your personal data also serves purposes such as, indicatively, the establishment, exercise and defense of legal claims, the compliance with the policies of finThesis, the compliance with terms of contracts of finThesis with third parties, the achievement of finThesis’ corporate objectives, the security of IT systems and, in general, assets of finThesis and/or a third party, the preservation of reputation, record keeping, the prevention and deterrence of criminal acts or fraud against finThesis or a third party, the management of your complaints, the assessment and optimization of operations, processes, security procedures and information systems, upgrading of services provided, etc.

E. Provided that you have given your consent

Where your consent has been requested and obtained, the processing of your personal data is based on that consent.

In such cases, you have the right to withdraw your consent at any time without prejudice to the lawfulness of the processing based on your consent prior to its withdrawal.

5. Who are the recipients of your personal data

In the context of processing your personal data, finThesis may transmit those data to the following recipients:

  • To insurance undertakings, reinsurers, insurance intermediaries or agents cooperating with finThesis.
  • To the authorised employees, members of management/committees of finThesis in the context of their duties and to the companies of the Group where finThesis belongs.
  • To service providers for storage, archiving, management and destruction of files and data, providers of IT and maintenance services, providers of teleconference services, providers of electronic communications services, cloud computing, information society, accounting/taxation and postal services.
  • To supervisory, independent, judicial, prosecutorial, police, tax, public and/or other authorities or bodies.
  • To lawyers and/or other consultants to the extent required.

6. Transfer of your personal data outside the European Economic Area

finThesis does not transfer your personal data to third countries or international organizations unless such transfer is required by the applicable regulatory or legal framework.

If applicable, finThesis may transfer your personal data to third countries under the following circumstances:

  • Where the European Commission has decided that the third country, a territory or one or more specified sectors within that third country or international organization ensure an adequate level of protection.
    or
  • If appropriate safeguards have been provided from the recipient, in accordance with the national and European legislation.

If none of the above conditions apply, the transmission may be completed:

  • If you have provided your express consent to finThesis,
    or
  • If the transfer is necessary for the performance of a contract between you and finThesis, such as for the execution of your orders,
    or
  • If the transfer is necessary for the establishment or exercise or defense of legal claims and rights of finThesis,
    or
  • If there is a relevant obligation arising from a legal provision or an international convention to which finThesis is subject. In order to fulfill such obligation, finThesis may transfer your personal data to competent national authorities so that such data are delivered through them to the respective authorities of third countries.

7. How long your personal data are retained

The personal data we collect are retained for the entire duration of your cooperation and transactional relationship with finThesis and for no longer than is necessary for the fulfilment of each respective processing purpose and for finThesis’s compliance with any record-keeping obligations, as provided for by applicable law.

In particular, in the event of judicial proceedings between you and finThesis or of a related administrative dispute, the retention period of your personal data shall be extended until the issuance of a final and irrevocable court decision.

8. Your rights towards finThesis with regard to the protection of your personal data

According to GDPR’s provisions, you have the following rights:

i. Right of access to your personal data that are retained and processed by us, as well as to information concerning the processing thereof (origin of the data, purposes of processing, categories of recipients, storage period).
ii. Right to rectification of your personal data, in the event of inaccurate data or for the purposes of completing incomplete personal data by providing any necessary document justifying the need for rectification or supplementation.
iii. Right to object the processing of your personal data, where the processing has been entrusted to finThesis for the performance of a task carried out in the public interest or in the exercise of public authority or the legitimate interest pursued by finThesis, including profiling.
iv. Right to restrict processing of your personal data where the accuracy of the personal data is contested by you or the processing is unlawful or finThesis no longer needs your personal data for the purposes of processing, or you have objected to the processing and the verification whether the legitimate grounds of finThesis override yours, is pending.
v. Right to erase your personal data from finThesis’ records.
vi. Right to portability of your personal data to any other data collector provided that the processing is based on your consent or on a contract and is carried out by automated means.

Please note indicatively the following in relation with your above rights:

  • finThesis has in any case the right to refuse the satisfaction of your request for the limitation of the processing or the erasure of your personal data if their processing or their maintenance is necessary for the exercise of your rights or the fulfillment of the obligations of finThesis towards you as well as the establishment, exercise or defense of legal claims of finThesis or the compliance of finThesis with its legal obligations.
  • finThesis also has in any case the right to refuse the erasure of your personal data, provided that some of them are not erased for filing purposes.
  • The exercise of the right to portability (above under vi) does not lead to the deletion of data from the archives of finThesis, which (deletion) is subject to the conditions set out in the immediately preceding paragraph.
  • The exercise of the above rights acts for the future and does not concern already executed processing of data.

9. How can you exercise your rights towards finThesis 

In order to exercise the rights of the above section, you may address your relevant requests in writing to 15 25th March street 17676, Tavros, or by sending an e-mail at the address dpo@finthesis.gr.

finThesis shall use its best endeavors to address your request within one month from its submission. The abovementioned period may be extended by two (2) further months, if deemed necessary at reasonable discretion of finThesis, taking into account the complexity and number of requests.
finThesis shall inform you in case of such extension within one month from the receipt of the request. The abovementioned service is provided by finThesis free of charge. However, where requests are manifestly unfounded, excessive or repetitive, finThesis may, after informing the debtor, either charge a reasonable fee or refuse to act on the request/requests.

10. Data Protection Officer of finThesis

You can contact finThesis Data Protection Officer for any matter regarding the processing of your personal data in writing at the address of 15 25th March, street, 17776, Tavros, Greece, or by sending an e-mail at the address dpo@finthesis.gr.

11. Right to appeal before the Hellenic Data Protection Authority

You have the right to lodge a complaint before the Hellenic Data Protection Authority for any matter regarding the processing of your personal data. For the respective competence of the Authority and the procedure to be followed for filing a complaint, you may visit the Hellenic Data Protection Authority website (www.dpa.gr – Individuals – Rights of Individuals – Complaint to the Hellenic DPA), where detailed information is available.

12. Security of your personal data

inThesis implements appropriate technical and organizational measures to ensure the lawful protection and processing, as well as the effective protection of your personal data from unauthorized access to, disclosure of, processing, loss, alteration, accidental or unlawful destruction or corruption, prohibited transmission by third parties as well as any other form of unlawful processing.

13. Updating and modifying this Information Notice on the processing of personal data

finThesis, may in accordance with its applicable policy on the protection of personal data and pursuant to the applicable legal and regulatory framework, modify or amend this Notice, the updated version of which will always be posted on the website at www.finthesis.gr.

Last update of the Privacy Notice : February 2026