Privacy Policy

Last Updated: 30 June 2026

Privacy Policy

SYCHEM S.A. is strictly committed to safeguarding and protecting your privacy. When processing your personal data, SYCHEM S.A. complies fully and strictly with the General Data Protection Regulation (EU) 2016/679 (GDPR) and all applicable national and European data protection laws. This Policy clearly defines the legal framework for the collection, use, and protection of your information.

  1. Data Controller

The Data Controller of your personal data under this Privacy Policy is:

  • Company Name: SYCHEM S.A.
  • Headquarters: 486 Mesogeion Avenue, Postal Code 153 42, Agia Paraskevi, Athens, Greece
  • Contact Phone Number: +30 214 6874 800
  • Contact Email Address / GDPR: v.stamogiannis@sychem.gr

 

  1. Description and Method of Collecting Data

By strictly adhering to the principle of data minimization, we process only the data that is absolutely necessary. We collect this data in the following ways:

  • Through a declaration by the data subject themselves (e.g., by filling out a contact form on the website, submitting a job application, or sending a resume)
  • Through other publicly available sources, which we use to keep the contact information we already lawfully hold accurate and up-to-date.
  • Automatically, through the website’s technology (cookies) as the data subject navigates the site, subject to the strict condition of the data subject’s explicit consent.

 

The personal data we process is limited to the following:

  • Basic identification information: Full name, the company you work for, and your title or position.
  • Contact information: Mailing address, email address, and phone number(s).
  • Employment information (for job applicants): Data, documents, and information included in your resume (CV) when you apply for a job.
  • Technical information: Data from your visits to our website (e.g., data via Google Analytics) or related to the materials we send you.
  • Other information: Any other information about you that you may voluntarily provide to us. The Company reserves the right to immediately delete any unsolicited sensitive personal data.

 

Personal Data of Minors: The SYCHEM S.A. website and services are intended strictly for adults (individuals over the age of 18). The Company does not knowingly collect or process the personal data of minors. If it is determined that personal data of a person under the age of 18 has been collected without the verifiable consent of the parent or legal guardian, the Company will immediately and permanently delete such data from its systems.

 

  1. Purposes and Legal Basis for Processing (Article 6 of the GDPR)

SYCHEM S.A. collects and processes personal information exclusively within a clear and documented legal framework:

  • Performance of a Contract: To provide you with the information or services you have requested, to enter into an agreement, to manage our relationship (registering you as a customer/partner), and for billing purposes.
  • Legal Obligation: To comply with the applicable legal and regulatory obligations to which our Company is subject.
  • Legitimate Interest: To establish, exercise, or defend our legal rights before judicial authorities; to ensure the smooth and secure operation of the company and the website; and to protect our systems and prevent and detect malicious activities.
  • Labor Law Obligations: For the purposes of hiring, evaluating candidates, and fulfilling employment or social security contracts.
  • Consent: To provide newsletters, company news, and invitations to events (you have the right to unsubscribe at any time), as well as where required by law (e.g., for optional statistical cookies).

Automated Decision-Making & Profiling: SYCHEM S.A. expressly states that it does not engage in any form of automated decision-making, including profiling, that produces legal effects concerning you or significantly affects you. All decisions related to hiring, entering into contracts, or providing services are made exclusively through human intervention.

 

  1. Data Security & Zero-DB Policy

We use a rigorous set of technical and organizational measures to protect your personal data from unauthorized access, use, disclosure, alteration, or destruction. All of our employees and the third parties we engage are required by law and their contracts to strictly respect the confidentiality of your information.

 

Important Note (Zero-DB Policy) : To ensure your maximum security, our website implements a data minimization policy (Privacy by Design). All data entered by users in contact forms or resume submission forms is immediately encrypted and transmitted exclusively via email to the secure corporate systems of our authorized departments. The website does not maintain any central database whatsoever, thereby eliminating the risk of mass data breaches via the online platform. Nevertheless, transmitting information over the internet is never completely secure and is done at your own risk.

 

Handling Data Breaches (Articles 33 & 34 of the GDPR) : In the event that the Company becomes aware of any personal data breach that is likely to pose a high risk to your rights and freedoms, it undertakes to notify, without undue delay and, if possible, within 72 hours, the Hellenic Data Protection Authority (HDPA), as well as the affected data subjects, in full compliance with the provisions of the General Data Protection Regulation.

 

  1. Data Retention

Your personal data is not retained indefinitely. It will be retained strictly and only for the period necessary to fulfill the purpose for which it was collected, taking into account legal and regulatory requirements and the statute of limitations for legal claims. Specifically:

  • Invoicing and contract data are retained for as long as required by applicable tax and commercial laws.
  • The data and documents included in resumes (CVs) are retained for the duration of the Human Resources department’s evaluation period, which does not exceed one (1) year from the date of receipt, unless you provide us with your explicit consent for further retention.

 

  1. Disclosure to Third Parties and Cross-Border Transfers (Article 28 of the GDPR)

We do not disclose or sell your personal data outside of SYCHEM S.A., unless you have given us your explicit consent, with the following strict exceptions:

  • To third parties that provide services exclusively to us or on our behalf, in their capacity as Data Processors (e.g., external IT support partners), who are contractually bound (Data Processing Agreements) to the exact same data protection obligations.
  • In cases where we are required to do so by law.
  •  In cases where it is absolutely necessary in the context of legal proceedings or in order to exercise and defend our legal rights.

 

We will primarily transfer your data within the European Economic Area (EEA). If we transfer your data to a location outside the EEA (e.g., through the use of Google Analytics), we implement appropriate legal safeguards (e.g., EU Standard Contractual Clauses) to ensure that your personal information remains fully protected in accordance with European law.

 

  1. Your Rights (Data Subject Rights)

The General Data Protection Regulation (GDPR) grants you the following non-negotiable rights:

  • Right of Access: To request and receive a copy of the information we hold about you.
  • Right to Rectification: To request the correction of inaccurate or incomplete data.
  • Right to Erasure (“Right to Be Forgotten”): To request the permanent deletion of your personal data.
  • Right to Restriction & Objection: To request that processing be restricted or to object to it entirely.
  • Right to Data Portability: To request that your personal information be transferred to another organization in a structured format.
  • Right to Withdraw Consent: If you have given your consent, you have the right to withdraw it at any time. The withdrawal is effective for the future and does not affect the lawfulness of the processing that took place prior to the withdrawal. Please note that objecting or withdrawing consent may mean that we are unable to take the necessary steps to provide our services, while the Company may lawfully continue processing to the extent permitted by law (e.g., to defend its legal rights).

 

To exercise your rights, please contact us exclusively and directly at the following email address: v.stamogiannis@sychem.gr

SYCHEM S.A. is committed to processing and responding to any legitimate request you submit within one (1) month of its confirmed receipt, unless this conflicts with our overriding legal obligations. In cases of exceptional complexity, this deadline may be extended by two (2) additional months, of which you will be notified in a timely manner.

You also have the right to file a formal complaint regarding the processing of your personal data with the national supervisory authority: Hellenic Data Protection Authority (1-3 Kifissias Ave., P.O. Box 115 23, Athens, www.dpa.gr).

 

  1. Cookies

Our website uses cookies to distinguish you from other users and to collect anonymous information about behavior patterns (e.g., through Google Analytics) in order to obtain traffic statistics. For a complete breakdown of cookie categories, how they work, and how to manage and block trackers, please refer to our website’s dedicated [Cookie Policy]

 

  1. Changes to the Policy

SYCHEM S.A. reserves the right to update and amend this Privacy Policy from time to time in order to meet the needs of the company, our customers, or changes in the legal framework. In the event of material changes to how your data is processed, a clear notice will be posted on the website before the revised policy takes effect. We encourage you to check this page periodically to stay fully informed.