Last updated: 28/05/2026
1. Data Controller
Sole Proprietorship — Panagiotis Kousidis (KOUSIDIS PANAGIOTIS TOU ANTONIOU)
VAT No.: 176210115 · G.E.MI.: 193229503000
Address: 92 Argous Street, Athens, 10441
Email: info@kousidisgallery.com
2. Data we collect
We collect the following personal data (Art. 13 GDPR):
- When you place an order: first name, surname, email, phone, shipping and billing address.
- When you pay: card details are not stored by us. They are passed directly to Viva.com.
- When you submit a custom order: the reference photo you upload and any comments.
- When you contact us: whatever you include in the contact form.
- Automatically: IP, browser, language, pages you visited (via cookies).
3. Purposes and Legal Basis
- Order fulfilment — Art. 6(1)(b) GDPR (performance of a contract).
- Communication and customer service — Art. 6(1)(b) GDPR.
- Marketing and newsletter — Art. 6(1)(a) GDPR (consent), only if you subscribe voluntarily.
- Legal obligations (invoicing, duties) — Art. 6(1)(c) GDPR.
4. Retention Period
- Order data: 10 years (tax obligation).
- Communication threads: 2 years from the last interaction.
- Newsletter subscription: until consent is withdrawn.
- Reference photos (custom orders): 1 year after delivery of the work, unless you request earlier deletion.
5. Recipients of the Data
Your data is shared with the following processors:
- Viva.com (card payment processing)
- ELTA Courier, DHL Express (parcel shipping)
- Brevo (sending transactional emails and the newsletter)
- Google Analytics (anonymised visit statistics)
- Other recipients where required by law (e.g. accountant, tax authorities)
6. Your Rights (Art. 15-22 GDPR)
You have the right to:
- Access (to know what data we store)
- Rectification
- Erasure (“right to be forgotten”)
- Restriction of processing
- Portability
- Objection to processing
- Withdrawal of consent at any time
- Lodging a complaint with the Hellenic Data Protection Authority (www.dpa.gr)
To exercise your rights, contact info@kousidisgallery.com — we respond within one month.
7. Security
We apply appropriate technical and organisational measures: SSL encryption, controlled access to data, regular backups, up-to-date passwords.
8. Changes to this policy
We reserve the right to update this policy. The date at the top shows the last revision.