KHS Megastore takes Data protection very seriously and invests in resources to ensure that personal data is protected through processes that are by design targeted at keeping personal data safe. If the processing of personal data is necessary and there is no statutory basis for such processing, we generally obtain consent from the data subject.
The processing of personal data, such as the name, address, e-mail address, or telephone number of a data subject shall always be in line with the General Data Protection Regulation (GDPR). By means of this data protection declaration, our enterprise would like to inform the general public of the nature, scope, and purpose of the personal data we collect, use and process. Furthermore, data subjects are informed, by means of this data protection declaration, of the rights to which they are entitled.
As the controller, KHS Megastore has implemented numerous technical and organizational measures to ensure the most complete protection of personal data processed.
The Controller for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection is:
The Managing Director
54, Castaldi Street,
What data do we collect and why do we store and process your Personal Data?
KHS Megastore collects a series of general data and information when a data subject either becomes a client at one of our branches or through our Internet channels. This data and information is stored on our centralised server. Generally, when a data subject visits one of our branches we might require to collect the following: Name & Surname, Address, Telephone and Mobile numbers and email addresses.
When using our website we may collect the above personal details as well. Our web hosting provide also collects data through their server logs such as (1) the browser types and versions used, (2) the operating system used by the accessing system, (3) the website from which an accessing system reaches our website (referrer), (4) the date and time of access to the Internet site, (5) an Internet protocol address (IP address), (6) the Internet service provider of the accessing system, and (7) any other similar data and information that may be used in the event of attacks on our information technology systems.
The data collected is never used by KHS Megastore to draw any conclusions about the data subject. Rather, this information is needed to help us deliver the level of service that we feel our clients deserve. We use this data to be able to contact our clients and also to offer them new services and offers from time to time. Subscription to these offers and services will require separate consent from our clients. Offer may be sent to data subjects through various channels such as: Email Marketing, printed material by post.
KHS Megastore analyzes anonymously collected data and information statistically, with the aim of increasing the data protection and data security of our enterprise, and to ensure an optimal level of protection for the personal data we process. The anonymous data of the server log files are stored separately from all personal data provided by a data subject.
Who collects personal data?
Data is collected by
• By our employees through walk-ins at our retail establishment.
• Possibly through our website and social media pages.
• Through emails opened and actioned by our employees.
• Through phone calls and other messaging services.
We usually retain the personal data of our clients for the period during which they are considered as clients. As a policy, KHS Megastore retains all personal data for three years from the date of the last contact with the client. Where warranty agreements are over three years the data is retained throughout the warranty period. After this period, the data subject is no longer considered a client and their data is erased.
In the case of marketing communications we ask for specific permission from the data subject to retain their email address indefinitely. The data subject is reminded continuously in every mail shot that they may opt out whenever they like.
Who we share your data with
KHS Megastore uses third party partners to help in processing data for marketing purposes. We may share data with our ICT service providers, accounts, auditors or for logistics purposes. We are assured that these partner companies handle personal data under the strictest controls and in accordance with this policy. We also purposely share only the data that is required for the processing task rather than all the personal data about a data subject.
Subscription to our newsletter
On our website, users may be given the opportunity to subscribe to our newsletter. KHS Megastore may use this newsletter to inform its customers and business partners about its offers. The newsletter may only be received by the data subject if (1) the data subject has a valid e-mail address and (2) the data subject registers for the newsletter and (3) if the data subject is a client and gives KHS Megastore consent (Opts in). A confirmation e-mail will be sent to the e-mail address when a user subscribes. A double opt-in procedure is employed. This confirmation e-mail is used to prove whether the owner of the e-mail address as the data subject is authorized to receive the newsletter.
During the registration for the newsletter, we also store the IP address of the computer system assigned by the Internet service provider (ISP) and used by the data subject at the time of the registration, as well as the date and time of the registration. The collection of this data is necessary in order to understand the (possible) misuse of the e-mail address of a data subject at a later date, and it therefore serves the aim of the legal protection of the controller.
The personal data collected as part of a registration for the newsletter will only be used to send our newsletter.
How to contact us
You can contact us as follows :
54, Castaldi Street,
Tel : (+356) 2169 3446
Routine erasure and blocking of personal data
The data controller shall process and store the personal data of the data subject only for the period necessary to achieve the purpose of storage, or as far as this is granted by the European legislator or other legislators in laws or regulations to which the controller is subject to.
If the storage purpose is not applicable, or if a storage period prescribed by the European legislator or another competent legislator expires, the personal data is erased in accordance with legal requirements.
Your rights as a data subject
As a data subject GDPR provides you with extensive rights as follows:
• Right of confirmation
• Right of access
• Right to rectification
• Right to erasure (Right to be forgotten)
• Right of restriction of processing
• Right to data portability
• Right to object
• Automated individual decision-making, including profiling
• Right to withdraw data protection consent
• Data protection for applications and the application procedures
For more detailed information about your rights under GDPR, please see our GDPR Rights document.
Last revison 6th September 2018