PRIVACY POLICY
1. INTRODUCTION
This policy concerns the company under the corporate name “NEA MITROPOLITIKI ATTIKI S.A. – LOCAL GOVERNMENT DEVELOPMENT ORGANIZATION” and the distinctive title “NEA MITROPOLITIKI S.A.”, hereinafter referred to as the “Company”. NEA MITROPOLITIKI ATTIKI is committed to protecting the personal information collected when you use our website and other services. This Privacy Policy sets out the Company’s commitment to protecting personal data and explains how this commitment applies to the collection, use, transfer, and retention of such data. The purpose of this policy is to inform you about the personal data we collect and process in the course of our operations and our general communication with you. This policy applies whenever we determine the purposes and means of processing, thus acting as the data controller.
Our full details are:
NEA MITROPOLITIKI ATTIKI S.A. - LOCAL GOVERNMENT DEVELOPMENT ORGANIZATION
Email Address: info@developattica.gr
Postal Address: 236 Syngrou Avenue, 176 72 Kallithea, Attica, Greece
Contact Tel.: 210 9213945 – 946
2. Concepts / Definitions of Personal Data
For the purposes of this policy, the following terms shall have the meanings set out below:
“Personal Data”: any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one whose identity can be established, directly or indirectly, in particular by reference to an identifier such as a name, identity number, location data, online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that natural person.
“Special Categories of Personal Data”: personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, as well as the processing of genetic data, biometric data for the purpose of uniquely identifying a person, data concerning health, or data concerning a natural person’s sex life or sexual orientation.
“Processing”: any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.
“Anonymization”: the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject.
“Pseudonymization”: the processing of personal data in such a manner that the data can no longer be attributed to a specific data subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organizational measures to ensure that it cannot be attributed to an identified or identifiable natural person.
“Controller”: the natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its designation may be provided for by Union or Member State law.
“Processor”: the natural or legal person, public authority, agency, or other body that processes personal data on behalf of the controller. “Consent” of the data subject means any freely given, specific, informed, and unambiguous indication of the data subject’s wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of personal data relating to them.
“Personal Data Breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
“Data Concerning Health”: personal data related to the physical or mental health of a natural person, including the provision of healthcare services, which reveal information about that person’s health status.
“Applicable Legislation”: The provisions of Greek, EU, or other legislation applicable to the COMPANY governing personal data protection matters, including but not limited to Law 2472/1997 on the protection of individuals with regard to the processing of personal data, Law 3471/2006 on personal data protection and privacy in electronic communications, Directive 95/46/EC, Directive 2002/58/EC, Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), and any implementing laws thereof.
3. General Principles for the Processing of Personal Data
When the Company processes personal data, it ensures that:
- Such data has been collected and is processed lawfully in accordance with applicable legislation and its requirements.
- Personal data is processed only for specified, explicit, and legitimate purposes.
- Appropriate technical and organizational measures are implemented to ensure a level of security appropriate to the processing of personal data, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage. The adequacy and effectiveness of these measures are periodically reviewed.
- Every reasonable effort is made to ensure that the personal data maintained and processed is accurate and up to date.
- Personal data is not retained for longer than necessary for the purposes for which it was collected and processed. However, it may be retained for a longer period where processing is necessary:
-
- for compliance with a legal obligation requiring processing under a statutory provision,
- for the performance of a task carried out in the public interest,
- within the framework of the COMPANY’S lawful activities, provided that the processing concerns employees or persons who have regular contact with it in relation to its purposes and that the personal data is not disclosed to third parties without the consent of the data subjects,
- for archiving purposes in the public interest, or for scientific or historical research purposes, or for statistical purposes,
- for the establishment, exercise, or defense of legal claims.
4. Purposes of Processing
Within the scope of its activities, the COMPANY may collect personal data relating to its employees, its collaborators in general, and natural persons with whom it interacts in the exercise of its responsibilities. These persons may include external associates, sole proprietors, legal or other representatives of legal entities, as well as their employees, third parties, and collaborators with whom the COMPANY conducts business. In principle, the COMPANY may collect and process personal data for the following purposes:
1. In order to fulfill the obligations imposed by legislation, as well as the provisions of its Articles of Association concerning its purposes and activities, such as:
- Scientific and advisory support to bodies and organizations, such as the Region of Attica, Local Government Authorities (OTAs), contracting authorities, and other public and private entities.
- Support for the development policy of the Region of Attica, including infrastructure projects and environmental initiatives.
- Promotion of sustainable development with emphasis on energy efficiency, environmental protection, and the utilization of Renewable Energy Sources (RES).
- Investment attraction initiatives for RES projects and energy-efficiency improvements.
- Development of sustainable urban mobility, including low-emission transport systems and applications of new technologies.
- Integrated Territorial Investments (ITI) and development policy strategies at local and regional level.
- Implementation of CLLD/LEADER programs and pursuit of funding from European and international programs.
- Implementation of projects aligned with the sustainable development goals of the UN Agenda 2030.
- Provision of digital convergence services and participation in programs promoting digital transformation.
- Support for tourism development and tourism marketing, promotion of cultural heritage, and development of alternative tourism.
- Execution and supervision of public works and provision of technical support to Local Government Authorities.
- Support for the agricultural economy, development of agrotourism initiatives, and promotion of local products.
- Scientific support for the utilization of public assets and assistance in the preparation of investment dossiers.
- Encouragement of sustainable entrepreneurship and support for innovative and outward-looking businesses.
- Design of social policy and social cohesion initiatives to support vulnerable groups and promote health and mental health.
- Development of infrastructure supporting entrepreneurship, including open-air trade and digitalization initiatives.
- Establishment of Portfolio Funds to utilize European financial instruments and support new businesses.
- Organization of cultural, sporting, and social events for the benefit of society.
- Carrying out any other related purpose consistent with applicable legislation and its Articles of Association.
2. In order to comply with legal obligations concerning its employees, suppliers, and external collaborators.
3. In order to recruit personnel and/or enter into agreements with external collaborators.
4. In order to ensure its smooth operation within the framework of its statutory purposes and applicable legislation.
5. In order to ensure the safety of its personnel, facilities, and equipment.
6. In order to lawfully conclude contracts and comply with the legal obligations arising therefrom.
7. In order to conduct research and studies within the framework of its statutory purposes.
5. Legal Basis for the Processing of Personal Data
The COMPANY processes your personal data transparently and in accordance with the principles of lawfulness, proportionality, confidentiality and integrity, purpose limitation and accuracy, storage limitation, and data minimization. Depending on the circumstances, the legal basis for processing your personal data may be:
(a) your consent,
(b) the necessity of processing your data for the performance of a contractual obligation,
(c) the necessity of processing your data for compliance with a legal obligation,
(d) the necessity of processing your data for the purposes of our legitimate interests.
6. What Data Is Processed
For the above purposes, the COMPANY may collect and process personal data including, indicatively, the following:
Employees and/or External Collaborators: full name, father’s name, mother’s name, year of birth, place of birth, gender, nationality, postal address, post office box, email address, contact telephone numbers, Identity Card Number, Tax Identification Number (TIN), Social Security Number (AMKA), bank account number (IBAN), information concerning family status, education and training, professional experience, and curriculum vitae (CV).
Purposes – Legal Basis for Processing:
- Management of the employment relationship. Processing is necessary for the performance of the employment contract.
- Fulfillment of the COMPANY’S employer obligations. Processing is necessary for compliance with a legal obligation.
- Management of payroll, insurance, tax, and pension obligations. Processing is necessary for compliance with a legal obligation.
- Communication with employees and collaborators for operational and administrative purposes. Processing is necessary for the performance of a contract and for the COMPANY’S legitimate interests.
- Protection of the COMPANY’S assets, facilities, information systems, and personnel. Processing is necessary for the purposes of the COMPANY’S legitimate interests.
Job Applicants: full name, father’s name, mother’s name, contact details, education and qualifications, professional experience, curriculum vitae (CV), cover letter, references, certifications, language skills, digital skills, and any other information voluntarily provided by the applicant during the recruitment process.
Purposes – Legal Basis for Processing:
- Evaluation of qualifications and suitability for employment or collaboration. Processing is necessary in order to take steps at the request of the data subject prior to entering into a contract.
- Maintenance of applicant records for future employment opportunities, where applicable. Processing is based on the applicant’s consent or on the COMPANY’S legitimate interest, depending on the circumstances.
Suppliers, Contractors, and Representatives of Legal Entities: full name, position, business address, contact details, Tax Identification Number (TIN), financial and banking information, identity details, and any information necessary for the conclusion and execution of contracts.
Purposes – Legal Basis for Processing:
- Conclusion, execution, and monitoring of contracts. Processing is necessary for the performance of a contract.
- Compliance with accounting, tax, and other legal obligations. Processing is necessary for compliance with a legal obligation.
- Communication and business cooperation. Processing is necessary for the COMPANY’S legitimate interests.
Website Users and Communication Recipients: identification data, contact details, electronic communication data, and any information provided through contact forms, email correspondence, or participation in events, programs, consultations, and other activities.
Purposes – Legal Basis for Processing:
- Responding to requests, inquiries, and communications. Processing is necessary for the COMPANY’S legitimate interests and, where applicable, for the performance of a contract.
- Informing interested parties about actions, programs, and initiatives relevant to the COMPANY’S statutory purposes. Processing is based on consent where required by law or on the COMPANY’S legitimate interests.
The COMPANY does not intentionally collect or process special categories of personal data unless this is required by law, necessary for the exercise of rights and obligations in the field of employment and social security law, necessary for reasons of substantial public interest, or based on the explicit consent of the data subject, where applicable.
7. Recipients of Personal Data
Access to personal data is granted only to authorized personnel of the COMPANY who require such access in order to perform their duties. The COMPANY may disclose personal data to third parties only when this is necessary for the fulfillment of the processing purposes described above and always in compliance with applicable legislation.
Recipients may include, indicatively:
- Public authorities, independent authorities, supervisory bodies, courts, and law enforcement authorities where disclosure is required by law.
- Insurance funds, tax authorities, labor authorities, and other competent public bodies.
- External consultants, auditors, lawyers, accountants, and technical advisors bound by confidentiality obligations.
- Information technology service providers, cloud service providers, hosting providers, and system support providers acting as processors on behalf of the COMPANY.
- Financial institutions and banking organizations where required for the execution of payments and financial transactions.
- Partners and organizations participating in programs, projects, actions, and initiatives implemented by the COMPANY, where such disclosure is necessary.
In all cases, the COMPANY ensures that recipients process personal data only to the extent necessary and under appropriate contractual, technical, and organizational safeguards.
8. Rights of Data Subjects
Subject to the conditions and exceptions provided by applicable legislation, every data subject has the following rights:
- Right of Access: the right to obtain confirmation as to whether personal data concerning them is being processed and, where that is the case, access to such data and related information.
- Right to Rectification: the right to request the correction of inaccurate personal data and the completion of incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): the right to request the deletion of personal data where the conditions provided by law are met.
- Right to Restriction of Processing: the right to request restriction of processing in the cases provided by applicable legislation.
- Right to Data Portability: the right to receive personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller, where applicable.
- Right to Object: the right to object, on grounds relating to the data subject’s particular situation, to processing carried out on the basis of the COMPANY’S legitimate interests or for the performance of a task carried out in the public interest.
- Right to Withdraw Consent: where processing is based on consent, the data subject has the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
Every request by the person/data subject shall be submitted to the COMPANY at the email address: dpo@developattica.gr.
In the event of exercising any of the above-mentioned rights, the COMPANY shall take every possible measure to satisfy your request within a reasonable period, and no later than one (1) month from the submission and identification of the request. This period may be extended by an additional two months, where necessary, if the request is complex or if there is a large number of requests.
In such a case, the COMPANY is obliged, within one month of identifying the request, to inform you of the delay and the reasons for it. Within the above period, the COMPANY must also inform you of any refusal to satisfy the submitted request, in whole or in part, and the reasons for such refusal.
The COMPANY may refuse to satisfy, in whole or in part, a relevant request received from the data subject only where such possibility is provided for under the General Data Protection Regulation (EU 2016/679). If the COMPANY processes personal data as a processor, it shall forward the relevant requests to the controller, who is responsible for examining and satisfying them.
9. Personal Data Breach
Personal Data Breach
A “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, communication of, or access to personal data collected, stored, or otherwise processed by the COMPANY. In the event that any employee or collaborator of the COMPANY becomes aware of or suspects that a personal data breach may have occurred, they shall inform the COMPANY at the email address: dpo@developattica.gr. Where the COMPANY processes data as a processor, it shall notify the controller without undue delay and shall not make any notifications on its own.
10. Data Retention Period
Your personal data is retained for a limited period of time, depending on the purpose of processing, after the completion of which the personal data is deleted from our records, unless a different retention period is required or permitted under applicable legislation. For additional information regarding the retention period and deletion period, please send a message to the email address: dpo@developattica.gr.
11. Training
The COMPANY ensures that personnel involved in the collection and processing of personal data are adequately informed and trained, taking into account the available methods of training and awareness in order to select those most appropriate to each circumstance.
12. Updates to the Personal Data Protection Policy
The COMPANY may amend this Policy from time to time for reasons of compliance with regulatory changes and for operational purposes. Updated versions of this policy will be posted on its website with a date indication so that you are aware of the most recently updated version.
This policy was updated on 30-05-2025.
13. Contact
If you have any concerns or complaints regarding this policy, please contact us at: dpo@developattica.gr.
PRIVACY STATEMENT
The protection of personal data is a primary concern of NEA MITROPOLITIKI ATTIKI, hereinafter referred to as the “COMPANY”. Within the framework of the General Data Protection Regulation (EU) 2016/679 (GDPR), this document provides information regarding the processing of personal data and the rights of data subjects, in accordance with Article 13 of the above Regulation. This statement describes the personal data protection practices and policies followed by the Company as Data Controller, in accordance with the General Data Protection Regulation (GDPR).
By collecting this information, we act as data controllers and, by law, we are required to provide you with information about us, the reasons and manner in which we use your data, and the rights you have over it.
We invite you to read this statement carefully so that you are adequately informed about the type of data we process.
1. PURPOSE OF THE PRIVACY STATEMENT
This statement applies to transactions between natural persons – data subjects and NEA MITROPOLITIKI ATTIKI. In particular, this statement applies in the case of:
- current, prospective and former customers, suppliers, consultants, and external collaborators
- employees,
- other natural persons with whom the COMPANY has a business relationship
This statement does not apply to the policies and practices of companies that are not related in any way to the COMPANY, and the COMPANY bears no responsibility for the privacy policies and practices of other companies.
2. Method of Collection of Personal Data
The COMPANY collects personal data if one of the following conditions applies:
- For the execution of the Company’s operations, which cannot be carried out without collecting personal data.
- The collection takes place in emergency situations for the protection of the vital interests of the data subject or for the prevention of serious harm or injury to another natural person.
3. Disclosure of Personal Data – Categories of Recipients
The COMPANY does not disclose the personal data it collects and processes to third parties unless such disclosure is required for the lawful fulfillment of our professional and business needs, in order to meet our contractual obligations to suppliers and partners, or is imposed or permitted by law.
The data of suppliers, partners, and citizens who come into contact with the COMPANY is processed within the framework set out in this statement by departments and employees of our company who are responsible for carrying out the relevant functions. The data may also be processed by cooperating third parties, on behalf of and under the instructions of the COMPANY, in cases where company functions are outsourced, such as external technical services, accounting services, etc. There are no permanent such assignments and therefore it is not possible to name any future partners within the context of this statement. In all cases, our company ensures that it assigns processing activities to third parties only if they meet high standards of security and confidentiality, provide sufficient guarantees and commitments regarding data protection, and undertake the contractual obligations required by law.
Furthermore, data may, to the extent necessary for the fulfillment of processing purposes or other obligations, be transmitted to third parties. In every case where data transfer becomes necessary, our company ensures that personal data is transferred only to parties that meet high standards of security and confidentiality and provide adequate guarantees and commitments regarding data protection.
Finally, the company may disclose data to public authorities of any kind (public services, tax authorities, social insurance organizations, etc.) or to judicial, independent, prosecutorial, or investigative authorities, where this is provided for or required by law, or deemed absolutely necessary for the protection of our legitimate rights or for compliance purposes.
To ensure the protection of personal data, the COMPANY’S Privacy Policy is applied.
4. Information Security
The COMPANY uses organizational, technical, and administrative measures to protect personal data, personal information, and other information.
5. Rights of the Data Subject
You may access, receive, and transfer your personal data, correct, delete, or restrict its processing, object to processing, and withdraw your consent where processing is based on consent. Subject to any exception under the GDPR, you have the following rights:
According to applicable legislation and subject to the restrictions provided therein, data subjects have the following rights regarding their personal data:
- Right to information and access: You have the right to be informed about the processing of your personal data and for this reason you are provided with this Privacy and Personal Data Protection Statement. You also have the right to access personal data concerning you upon request.
- Right to rectification: You have the right to request the correction of inaccurate personal data maintained within the framework of this statement or the completion of incomplete data.
- Right to erasure: You have the right to request the deletion of your data. Please note that this right is not absolute and is subject to legal limitations. We may have lawful grounds for not complying with such a request.
- Right to restriction of processing: You have the right to request restriction of the processing of your data, meaning that you may request the cessation of further processing and only the retention of your data by our company. The exercise of this right is subject to the conditions provided by applicable legislation. If the legal requirements are not met, the company may not be obliged to satisfy your request.
- Right to data portability: You have the right to receive your data in a specific format and request its transfer to another controller, where provided by law for the relevant processing activity.
- Right to object: You have the right to object at any time to the processing of your data, within the limitations provided by applicable legislation. Likewise, this right is not absolute and the company may have legitimate grounds for refusing such a request.
- Right to withdraw your consent: Where the processing of your personal data is based on your consent, you have the right to withdraw your consent immediately, easily, and free of charge at any time for the continuation of such processing. Withdrawal of consent does not affect the lawfulness of processing carried out before its withdrawal.
- Right to lodge a complaint with the Hellenic Data Protection Authority: We also inform you that under applicable legislation you have the right, if you believe that data protection legislation has been violated, to submit a complaint to the competent Data Protection Authority (for Greece: Hellenic Data Protection Authority – HDPA, 1 Kifisias Avenue, 115 23 Athens, Tel. +30 210 6475600, www.dpa.gr).
6. Retention Period of Personal Data
The COMPANY retains your personal data for as long as required for the purpose for which it was collected, for a longer period where necessary, or for as long as permitted by law. When personal data is no longer necessary for its original purpose, it is deleted in accordance with the COMPANY’S policies and procedures.
7. On What Legal Basis Does NEA MITROPOLITIKI ATTIKI Process Personal Data?
The COMPANY processes your personal data transparently and in accordance with the principles of lawfulness, proportionality, confidentiality and integrity, purpose limitation and accuracy, storage limitation, and data minimization.
The legal basis for processing your personal data may, depending on the case, be:
(α) the provision of services that you assign to us and wish to receive from us, such as information regarding our activities, and consequently the fulfillment of our contractual obligations in this context.
(β) the safeguarding and protection of legitimate interests, both yours and ours.
(γ) compliance with a legal obligation imposed by law, such as regulatory compliance for tax purposes.
(δ) the consent you provide under the specific conditions set by the legal framework, in order to receive updates regarding the activities, services, etc. of both the COMPANY and cooperating third-party companies that process personal data in accordance with the applicable legal framework.
8. Contact
General: The COMPANY is responsible for the collection, use, and disclosure of your personal information in accordance with this Privacy Statement. If you have any questions regarding this statement or our privacy practices, or if you would like to access your information, please contact us at dpo@developattica.gr. You also have the right to lodge a complaint with the competent supervisory authority (Data Protection Authority).
