Personal Data Protection Policy


Dear customer,

1. Introduction

The Military Service under the name Hellenic Military Geographical Service (GYS), based in Athens, at Pedion Areos, Evripidou Street No. 4, PC: 11362, email: hmgs@gys.gr, is committed to protecting your personal data. Through this Policy, we inform you about how your personal data is collected, used, and protected when using our website.

2. Definitions

2.1. For the interpretation of the Data Protection Policy, the following definitions apply:

“GDPR”: General Data Protection Regulation. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.

“Law 4624/2019”: Law 4624/2019 titled “Hellenic Data Protection Authority, implementation measures of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and incorporation into national legislation of Directive (EU) 2016/680 and other provisions”.

“Authority”: The Hellenic Data Protection Authority, which according to Article 9 of Law 4624/2019 serves as the supervisory authority of the GDPR and related national provisions. It is an independent public authority based in Athens.

“Policy”: This personal data processing policy, which defines the terms and conditions for the protection of your personal data as users of the GYS website.

“Cookie Policy”: The policy defining the terms under which our Service processes your personal data as website users through the use of cookies.

“Data Controller”: The Ministry of National Defence through the Hellenic Army General Staff / GYS.

“Website”: The Service’s website accessible at the domain names www.hmgs.gr or www.gys.gr

“Users” or “You”: The users of the GYS website.

2.2. In all other respects, the definitions of Article 4 of the GDPR and Article 4 of Law 4624/2019 apply.

3. What data/information we collect

When using our Website and services, we may collect the following categories of data:

  • Identification Data: Full name, username, tax identification number.

  • Contact Data: Email address, telephone number, shipping and billing address.

  • Transaction Data: Information related to your purchases (we do not store card details; payments are processed via banking gateways).

  • Technical Data: IP address, browser type, cookies.

For detailed information regarding the use of cookies, please refer to the Website’s Cookie Policy.

4. Purposes and Legal Bases of Processing

We use your personal data for the following purposes:

  • Execution and processing of your orders.

  • Communication with you regarding your transactions.

  • Sending updates, if you have given your consent.

  • Compliance with legal obligations.

  • Improvement of website functionality and services.

The processing of your data is carried out, depending on the purpose, under the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR).

  • Compliance with a legal obligation (Art. 6(1)(c) GDPR).

  • Performance of a task carried out in the public interest (Art. 6(1)(e) GDPR).

  • Consent (Art. 6(1)(a) GDPR).

Providing data is necessary for the execution of the website’s services. If not provided, it may not be possible to complete your transaction or provide services. Automated processing, including profiling, may be performed to implement and improve services. No automated decision-making producing legal effects or similarly significant impact is carried out (Article 22 GDPR).

5. Data Retention Period

We retain your data only for as long as necessary. Transaction data is kept for up to five (5) years, user account data until deletion, and communication data for as long as needed to handle the request. In some cases, data may be retained longer if required by law or for legal claims.

6. Data Disclosure to Third Parties

Your data is disclosed only to necessary partners:

  • Courier companies: For product delivery.

  • Payment providers: For transaction processing. For issuing invoices, the mytimologisi application is used (https://mytimologisi.gr/privacy.php), which is subject to data protection regulations. Invoices and receipts are transmitted to the Greek tax authority (AADE) in accordance with applicable legislation (Government Gazette 3131/B/19 July 2021).

No data is transferred outside the European Economic Area.

7. Your Rights

Under GDPR, you have the following rights:

  • Right to information

  • Right of access

  • Right to rectification

  • Right to erasure

  • Right to restriction of processing

  • Right to data portability

  • Right to object

8. Right to Lodge a Complaint

If you believe that the processing of your personal data violates applicable law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA). Detailed information is available at www.dpa.gr. Prior to filing a complaint, you are encouraged to contact the Data Protection Officer.

9. Data Security

We apply appropriate technical and organizational measures (such as SSL encryption) to protect your data from loss, alteration, or unauthorized access. These measures are regularly reviewed and updated.

10. Contact

You may contact the Data Protection Officer of the Hellenic National Defence General Staff via email (dpo@hndgs.mil.gr) or telephone (210-6574904) for any information or assistance regarding your rights and data protection matters.

11. Changes to This Policy

This Policy may be updated when necessary. Significant changes will be communicated through appropriate means.

icon

Copyright © 2026 Hellenic Military Geographical Service