FREEBYTES PRIVACY NOTICE

This Privacy Notice explains how FREEBYTES collects, uses, discloses, stores and protects personal data in connection with operation of the online store, order fulfilment, communication with customers and visitors, technical support, management of withdrawals and returns and compliance with the business's legal obligations.

Processing is carried out in accordance with Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019, Greek Law 3471/2006 and any other applicable provisions. This notice does not mean that the business collects every possible category of data; it describes categories of processing connected with the actual operation of the online store and applies only to the extent that the relevant data are in fact collected or used.

1. Data controller

The controller of the personal data described in this Privacy Notice is Ioannis Kontarinis, a sole trader trading as FREEBYTES. In that capacity, and except where the law or the factual relationship provides otherwise, the controller determines the purposes and essential means of the processing carried out for operation of the online store and administration of customer transactions.

Ioannis Kontarinis - sole trader trading as FREEBYTES
78 Boreiou Ipirou Street, Kolonos, 10444 Athens, Greece
G.E.MI. No.: 1557801000
VAT No.: EL043747758
WEEE Producer Register No. (ΑΜΠ ΑΗΗΕ): 3969
Tel.: +30 210 5132673 / +30 210 5150527
Email: infofree@freebytes.com

For privacy questions or to exercise a right, you may use the email address above or our Contact Us page. No special wording is required, provided that the right or issue concerned is sufficiently clear.

2. Core processing principles

We process only data that are adequate, relevant and limited to what is necessary for the relevant purpose. Data are used for specific lawful purposes, retained for as long as required and protected through appropriate technical and organisational measures.

We do not sell personal data to advertisers or other third parties. Disclosure to a service provider takes place only where necessary for a specific purpose such as payment, delivery, technical support, accounting or tax compliance, system security or fulfilment of a legal obligation.

3. Account data

When an account is created, we may collect name, address, postal code, city, country, email address, telephone number and information necessary to identify and operate the account. Certain information is mandatory for account operation or order fulfilment.

The password is used for authentication according to the technical architecture of the system and is not used for commercial analysis or another unrelated purpose.

4. Order and purchase data

When an order is submitted and fulfilled, we process customer and recipient details, billing and shipping addresses, contact information, products and quantities, prices, dates, shipping method, payment method, order status, order number and other information necessary to perform and document the transaction.

These data are used for order fulfilment, delivery, invoicing, after-sales support, returns, withdrawals, non-conformity requests and compliance with accounting, tax and other legal obligations.

5. Billing information

Where an invoice is requested or specific tax details are required, we may process a legal or trading name, business activity, registered address, VAT number, competent tax authority and other information necessary for lawful issuance and transmission of the document.

These data are not used for credit scoring or financial profiling unless such a process is introduced in the future with separate, clear and lawful information.

6. Payment data

Card payments are handled through the environment of the cooperating payment-services provider or banking institution. The online store may receive or retain information such as payment method, approval or rejection status, amount and transaction reference so that the payment can be reconciled with the order.

The FREEBYTES customer and order database is not intended to store the full card number or CVV/CVC. Full card credentials, where required, are processed through the relevant payment provider's environment.

7. Shipping and delivery

For delivery, we disclose to the selected carrier the information necessary for shipment, normally recipient name, address, postal code, city, telephone number and, where required, email address or cash-on-delivery information.

We may also receive from the carrier a shipment reference, delivery status, failed delivery attempt, parcel return or other information necessary to manage the order.

8. Communications and technical support

When you contact us by email, telephone or contact form, we process your contact details and the content of the request to the extent necessary to respond, identify a related order, provide technical or commercial support, manage a complaint or document resolution.

For a technical issue, we may ask for photographs, video, serial number, symptom description, firmware version or other technical information only to the extent reasonably useful.

9. Electronic withdrawal data

The Electronic Withdrawal Function processes data necessary to exercise and evidence the withdrawal right, such as order number, name, order email address, products concerned, declaration text, unique reference, submission date and time, case status and technical indicators concerning dispatch of acknowledgements.

These data are used to record the declaration, send an acknowledgement, organise return of goods and reimbursement and evidence the time and content of the withdrawal. The dedicated function is designed with data minimisation in mind and does not itself require storage of the user's IP address in the dedicated withdrawal table.

10. Returns, guarantees and repairs

For a return, repair or replacement we may process order and contact details, serial number, technical problem description, diagnostic findings, shipping information and communications with the customer, supplier, manufacturer or authorised service centre.

Disclosure to a manufacturer, supplier or service centre is limited to information necessary for the specific case.

11. Technical data and logs

The web server, security software or other technical infrastructure may record IP address, access date and time, requested page, browser type, device information, server response codes, session identifiers and other events necessary for operation, troubleshooting, security and prevention of abuse.

Technical logs are not used to create a commercial or credit profile. They may be examined to investigate a technical problem, unauthorised access, abuse, fraud or a security incident.

12. Cookies and similar technologies

The online store uses cookies or similar technologies where necessary for functions such as user session, shopping cart, security, language selection and other functions requested by the user. Strictly necessary cookies are subject to the applicable legal exemption from consent.

For non-essential cookies or trackers, for example analytics, advertising or tracking technologies, the information and consent mechanism required by Greek Law 3471/2006 is applied. The actual cookie-banner configuration must remain consistent with the plugins and trackers that are active.

13. Transactional and marketing email

Messages necessary for an account or transaction, such as order confirmation, shipping updates, withdrawal acknowledgement or a support response, are not advertising messages.

Electronic direct marketing is governed by the GDPR and the specialised electronic-communications rules. Where consent is required it is requested separately and, in all cases, the legally required method of objecting to or stopping marketing communication is provided.

14. Legal bases for processing

Contract performance - Article 6(1)(b) GDPR: for receiving and fulfilling an order, payment, delivery, account operation and support directly connected with the contract.

Legal obligation - Article 6(1)(c) GDPR: for tax, accounting, commercial, consumer-protection or other mandatory compliance and lawful requests from authorities.

Legitimate interests - Article 6(1)(f) GDPR: for security, fraud prevention, system protection, transaction documentation, legal claims and improvement of technical operation, provided that the data subject's rights do not override those interests.

Consent - Article 6(1)(a) GDPR: where required, such as for certain non-essential cookies or forms of electronic marketing. Consent may be withdrawn for the future.

15. Recipients of personal data and third-party roles

Personal data may be disclosed only to persons or organisations that need the relevant information for a lawful and defined purpose. A third party is not classified as a processor, independent controller or, in a specific case, joint controller simply because of the type of business it operates. The role depends on the actual function performed in the relevant processing and on who determines the purposes and essential means of that processing.

A processor processes personal data on behalf of and under documented instructions from the controller. Where a FREEBYTES service provider acts in this capacity, the requirements of Article 28 GDPR apply.

An independent controller determines its own purposes and essential means of processing for its lawful activities and is responsible for its own transparency and GDPR compliance obligations.

Depending on the service and contractual relationship, recipients may include hosting/server/email, backup, technical-support and security providers; banks and payment-services providers; Greek Post, courier companies and other carriers; accountants, tax advisers, electronic-invoicing providers and tax systems; manufacturers, suppliers and authorised service centres; legal and other professional advisers; and public authorities or courts where disclosure is required or lawfully requested.

Hosting, server, email, backup and technical-support providers will normally act as processors where they handle data solely on behalf of FREEBYTES. Banks, payment providers, carriers, accountants/tax advisers, manufacturers or service centres may, depending on the particular processing and their own legal or professional obligations, act as independent controllers or, for certain limited functions, as processors.

FREEBYTES does not automatically classify every external service provider as a processor. The role is determined by the actual allocation of decision-making and responsibility in the relevant processing activity.

16. Transfers outside the EEA

If a particular technical or other provider involves transfer of personal data outside the European Economic Area, the transfer is made only through a lawful mechanism such as an adequacy decision, appropriate contractual safeguards, Standard Contractual Clauses or another mechanism permitted by the GDPR.

Where required, supplementary safeguards are also considered. Further information about a specific transfer may be requested at infofree@freebytes.com.

17. Retention periods

There is no single retention period for all data. Information is kept for as long as necessary for the relevant purpose and is then deleted, anonymised or restricted unless further retention is required by law or for legal claims.

Orders, invoices and tax records are retained for the legally applicable tax, accounting and commercial periods. Deleting an account does not require deletion of records that the business remains legally required to retain.

Withdrawal declarations and acknowledgements are retained for as long as necessary for compliance, completion of returns and possible claims. Technical/security logs are retained for a limited period proportionate to their purpose unless a security incident requires longer retention.

18. Security

We use technical and organisational measures proportionate to risk, such as encrypted HTTPS/TLS transmission, controlled access, user permissions, server and application security measures, security updates, event logging and backups where applicable.

No system can guarantee absolute security. In the event of a personal-data breach, the applicable duties of assessment, documentation and, where required, notification to the supervisory authority and communication to affected persons are followed.

19. Automated decisions

The normal operation of the online store does not rely on solely automated decision-making that produces legal effects or similarly significantly affects the customer within the meaning of Article 22 GDPR. If such processing is introduced in the future, the specific information required by law will be provided.

20. Your rights

Depending on the processing and the conditions of the GDPR, you may have rights to information, access, rectification, erasure, restriction, portability, objection, withdrawal of consent and rights concerning automated decisions.

The right to erasure is not absolute where retention is required by law or for another lawful reason. For direct marketing, you may object at any time to use of your data for that purpose.

21. Exercising your rights

You may send a request to infofree@freebytes.com or use our Contact Us page. To protect data from unauthorised disclosure, reasonable additional identification information may be requested where necessary.

Requests are handled without undue delay and within GDPR time limits. Exercising a right is generally free of charge, subject to the legal exceptions for manifestly unfounded or excessive requests.

22. Complaint to the supervisory authority

If you believe that processing infringes applicable law, you may lodge a complaint with the Hellenic Data Protection Authority or another competent supervisory authority. Information and complaint procedures are available at www.dpa.gr.

The right to complain does not restrict any right to judicial remedy or compensation where the statutory conditions are met.

23. Third-party links and services

The website may contain links to manufacturers, payment providers, carriers, social networks or other independent services. When a user moves to an independent third party, that entity's processing is governed by its own privacy information and FREEBYTES does not determine the third party's independent processing activities.

24. Changes to this notice

This notice may be updated where legislation, technical infrastructure, providers, online-store functions or actual processing purposes change. The new version is published on this page.

A later change does not retroactively create a new legal basis. Where a new activity requires consent or specific information, that procedure is completed before the processing to the extent required by law.

25. Related pages

For contractual terms see the Conditions of Use. For shipping, returns, withdrawal and statutory conformity information see Shipping & Returns. To exercise withdrawal electronically use the Electronic Withdrawal Function.

Last revised: 12 September 2026 - version 7.1. This notice should remain technically consistent with the systems, cookies, plugins, payment providers, delivery services and other integrations that are actually active.

Manufacturers