Privacy Policy
1. Introduction
This Personal Data Protection Policy (hereinafter the “Data Policy” or “PDPP”) governs access to and use of the website onesalonica.com
Onesalonica.com is the “Website” of a shopping centre managed and maintained by the company under the corporate name “ONE OUTLET SOCIETE ANONYME FOR THE MANAGEMENT AND OPERATION OF OUTLET CENTRES”, having its registered office in Alimos, Attica (77 Poseidonos Avenue, P.C. 174 55), Greece (Tax ID No.: 800596468 / Tax Office: KEFODE of Attica) (hereinafter the “Company”), which belongs to the group of companies of “FAIS HOLDINGS SOCIETE ANONYME” (registered office: 77 Poseidonos Avenue, Alimos, Attica, P.C. 174 55, Tax ID No.: 800907275, General Commercial Registry (G.E.MI.) No.: 144651701000, Tax Office: KEFODE of Attica) within the meaning of Article 31 of Law 4308/2014 (hereinafter referred to as the “Group”, the parent entity being referred to as “FAIS HOLDINGS S.A.”).
This Policy is issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (GDPR), in order to inform you, in clear and plain language, of the Company’s policy regarding your personal data, the purpose of their processing, their legal basis, the categories of recipients, the retention period, and the procedures you may follow in order to exercise your statutory rights.
For certain processing operations, in particular those relating to Group-wide actions/infrastructures (indicatively: unified commercial communications/campaigns at Group level and/or shared customer management infrastructures), the Company and “FAIS HOLDINGS SOCIETE ANONYME” act as joint controllers within the meaning of Article 26 of Regulation (EU) 2016/679 (GDPR).
Any natural person who visits the pages of the Website or makes use of its services is referred to herein, for brevity, as the “Personal Data Subject” or the “Data Subject”.
The management and protection of your personal data are governed by the terms of this Policy and the relevant provisions of Greek, EU and international law on the protection of individuals with regard to the processing of personal data, in particular Regulation (EU) 2016/679 (GDPR), Law 4624/2019, Law 3471/2006 (ePrivacy), as well as the Decisions and guidelines of the Hellenic Data Protection Authority (HDPA) and the European Data Protection Board (EDPB). Any future amendment of the above regulatory framework will be incorporated into this Policy.
This Policy constitutes an integral part of the Terms and Conditions of onesalonica.com and forms a single whole with them. The Company may amend this Policy from time to time, without prior notice, by posting the amended version on the Website. For any question or request regarding the processing of your personal data, you may contact the Data Protection Officer (DPO) at: dpo@faisgroup.gr or by post at the address of the Company’s registered office.
The services of the Website are not addressed to minors under 15 years of age, and the Company does not knowingly collect data of minors without the required parental consent.
The Company does not take decisions producing legal or similarly significant effects based solely on automated processing. Automated fraud prevention tools may be used for transaction security purposes.
Personal Data Controller(s) — as applicable
A. Independent Controller (operation of onesalonica.com, newsletters, communication)
“ONE OUTLET SOCIETE ANONYME FOR THE MANAGEMENT AND OPERATION OF OUTLET CENTRES”
77 Poseidonos Avenue, Alimos, Attica, P.C. 174 55, Greece
Tax ID No.: 800596468 / Tax Office: KEFODE of Attica
DPO E-mail: dpo@faisgroup.gr
B. Joint Controllers (Art. 26 GDPR)
For processing operations carried out jointly (unified Group campaigns, shared CRM/marketing infrastructures):
(i) FAIS HOLDINGS SOCIETE ANONYME, 77 Poseidonos Avenue, P.C. 174 55, Alimos, Attica — Email: info@faisgroup.gr, DPO Email: dpo@faisgroup.com
(ii) “ONE OUTLET SOCIETE ANONYME FOR THE MANAGEMENT AND OPERATION OF OUTLET CENTRES”, 77 Poseidonos Avenue, P.C. 174 55, Alimos, Attica — DPO Email: dpo@faisgroup.gr
The two companies have entered into a specific Joint Controllers Agreement pursuant to Art. 26 GDPR, the essence of which is available to data subjects upon request. FAIS HOLDINGS S.A. (dpo@faisgroup.com) has been designated as the central contact point for the above joint processing operations, without prejudice to your right to also contact the Company.
Data subjects may exercise their rights against either of the joint controllers (Art. 26 para. 3 GDPR).
1. Definition of Personal Data
“Personal Data” means any information relating to an identified or identifiable natural person (Art. 4 para. 1 GDPR). Indicatively: name, address, date of birth, mobile number, email, username, password, IP address.
2. Summary Table of Processing Operations
The following table summarises the main processing operations carried out by the Company, the categories of data, the purpose, the legal basis under the GDPR, the retention period and the Controller. A detailed description of each processing operation follows in Section 2.3.

3. Collection and Processing of Personal Data
No personal data is required for simple browsing of the Website. However, the Company collects browsing data through cookies. For details, please refer to the Cookies Policy. The categories of personal data that the Company collects and processes (through stores, websites, social media) are the following:
3.1. Newsletter & Commercial Communications
Legal basis: Art. 6 para. 1 point (a) GDPR (consent) & Art. 11 of Law 3471/2006.
If you tick the relevant checkbox, we collect your email and/or mobile number in order to send Newsletters, SMS, Viber and push notifications. Processing for email marketing purposes is carried out by the processor GRAMMEDIA LTD, on the basis of a data processing agreement. Your address is retained in the database until you withdraw your consent or request deletion via the unsubscribe link.
3.2 Social Media
Legal basis: Art. 6 para. 1 point (f) GDPR (legitimate interest — customer service via social media).
We may process data you provide via Facebook, Instagram or other social media platforms solely in order to respond to your requests. These platforms act as independent controllers — please refer to their own privacy policies. In certain cases the Company and the social media providers may act as joint controllers for page visit statistics. To exercise your GDPR rights, do not use social media — contact the DPO directly
3.3 Fraud Prevention
Legal basis: Art. 6 para. 1 point (f) GDPR (legitimate interest — fraud prevention) & Art. 6 para. 1 point (c) GDPR (legal obligation).
Where there are reasonable indications of fraud or unlawful use, onesalonica.com may collect and process the data necessary to detect and address fraudulent activities.
3.4 Statistics & Analytics
Legal basis: Art. 6 para. 1 point (f) GDPR (legitimate interest — service improvement) or Art. 6 para. 1 point (a) GDPR (consent) where required by the Cookies Policy.
We use pseudonymised and technical browsing data for statistical analyses aimed at improving the Website and our services.
3.6 Targeted Advertising (Retargeting)
Legal basis: Art. 6 para. 1 point (a) GDPR (consent — Cookies Policy).
Personalised advertisements on third-party platforms (e.g. Facebook Ads, Google Ads) are displayed exclusively upon your explicit consent given through cookies or similar technologies.
4. DATA RETENTION PERIOD
The Company applies the following retention periods:
• Newsletter / commercial communications: Until withdrawal of consent or deletion request
• Customer service: 6 months from closure of the request
• Fraud prevention: 3 years from the identified suspicious transaction
• Cookies / Analytics: As per the Cookies Policy (up to 13 months for analytics cookies)
• Legal claims: Until expiry of the limitation period (general 5-year period — Art. 250 of the Greek Civil Code, or special period where applicable)
5. DATA RECIPIENTS AND TRANSFERS
The Company may transfer your personal data to the following recipients:
•GRAMMEDIA LTD (processor): For email marketing services — on the basis of a data processing agreement under Art. 28 GDPR
•Third-party marketing / CRM / analytics / technical support providers: As processors on the basis of an Art. 28 GDPR agreement
•FAIS HOLDINGS S.A.: As joint controller for joint marketing/CRM activities (Art. 26 GDPR)
•Judicial / Supervisory / Administrative authorities: Legal basis: Art. 6 para. 1 point (c) GDPR (legal obligation) or Art. 6 para. 1 point (f) GDPR (establishment/defence of legal claims) —
The Company does not sell, lease or otherwise transfer personal data to third parties for commercial exploitation.
6. LEGAL BASES OF PROCESSING
The Company processes your personal data on the basis of the following GDPR legal bases:
•Art. 6 para. 1 point (a) — Consent: For newsletters, marketing, retargeting ads, satisfaction surveys, non-essential cookies. Consent is given through an explicit action (opt-in) and may be withdrawn at any time.
•Art. 6 para. 1 point (f) — Legitimate interest: For fraud prevention, customer service, analytics, social media interaction, exercise of legal claims. The legitimate interest has been balanced following an assessment that the fundamental rights and freedoms of the data subjects do not override it.
7. CONSENT
Your consent is requested only where it is the applicable legal basis (e.g. marketing, non-essential cookies) and is given through an explicit action (checkbox opt-in). No consent is required for processing based on contract or legal obligation.
7.1 Marketing Activities
By subscribing to the Newsletter and commercial communications service you give your explicit consent (opt-in) to receive email, SMS, Viber and push notifications. You may withdraw your consent at any time by sending an email to dpo@faisgroup.gr or via the unsubscribe link in the messages you receive.
7.2 Disclosure to Authorities
The Company discloses data to competent authorities exclusively where this is required by the applicable legal framework (Art. 6 para. 1 point (c) GDPR) or for the establishment, exercise or defence of legal claims (Art. 6 para. 1 point (f) GDPR).
8. DATA TRANSFER AND SECURITY
Data transfer between the Website and your browser is encrypted (HTTPS/TLS). Data are stored on secure servers within the EU/EEA.
Where a processor outside the EU/EEA is used, the transfer takes place subject to appropriate safeguards (Standard Contractual Clauses — SCCs under Art. 46 para. 2 point (c) GDPR, or another lawful mechanism). The Company implements appropriate technical and organisational security measures, such as role-based access restriction, access controls, security event logging and incident management procedures
9. DATA SUBJECTS’ RIGHTS
Upon verification of your identity, you have the following rights:
Right to information & access (Arts. 13-15 GDPR)
The right to be informed about the processing and to receive a copy of your data.
Right to rectification (Art. 16 GDPR)
The right to have inaccurate data rectified and incomplete data completed.
Right to erasure (Art. 17 GDPR)
The right to have data erased where they are no longer necessary, where you withdraw your consent or where the processing is unlawful. Exceptions: legal obligation or establishment of legal claims.
Right to restriction (Art. 18 GDPR)
The right to restrict processing where accuracy is contested, where processing is unlawful or where the data are necessary for legal claims.
Right to object (Art. 21 GDPR)
The right to object to processing based on legitimate interest or carried out for direct marketing purposes. In the latter case, the objection is immediately binding.
Right to data portability (Art. 20 GDPR)
The right to receive your data in a structured, commonly used and machine-readable format, where the processing is based on consent or contract and is carried out by automated means.
Right to human intervention (Art. 22 GDPR)
The right not to be subject to a decision based solely on automated processing (including profiling) which produces legal or similarly significant effects.
Right to withdraw consent (Art. 7 para. 3 GDPR)
The right to withdraw consent at any time, without affecting the lawfulness of prior processing.
Right to lodge a complaint (Art. 77 GDPR)
The right to lodge a complaint with the supervisory authority. In Greece: Hellenic Data Protection Authority (HDPA), 1-3 Kifissias Avenue, 115 23 Athens, www.dpa.gr, complaints@dpa.gr.
The exercise of these rights is subject to any data retention obligations of the Company
10. SUBMISSION OF REQUESTS — CONTACT
To exercise your rights, please contact:
“ONE OUTLET SOCIETE ANONYME FOR THE MANAGEMENT AND OPERATION OF OUTLET CENTRES”
77 Poseidonos Avenue, Alimos, Attica, P.C. 174 55, Greece
DPO E-mail: dpo@faisgroup.gr
For joint processing operations (Art. 26 GDPR), you may also contact FAIS HOLDINGS S.A.: dpo@faisgroup.com
We respond free of charge within 1 month of receipt of the request. In cases of complexity or multiple requests, the deadline may be extended by 2 additional months, in which case you will be informed within the first month (Art. 12 para. 3 GDPR). Manifestly unfounded or repetitive requests may be subject to a reasonable fee or refusal (Art. 12 para. 5 GDPR).
11. LEGAL FRAMEWORK
Data processing is governed by:
•Regulation (EU) 2016/679 (GDPR)
•Law 4624/2019 (implementation of the GDPR in Greece)
•Law 3471/2006 (electronic communications and privacy — ePrivacy)
•Decisions and guidelines of the HDPA & EDPB
This document is subject to periodic review. In the event of material changes, you will be notified by appropriate means (email or announcement on the Website).
EU General Data Protection Regulation 2016/679 (GDPR)
Last updated 24.07.2026