Privacy Policy
Last updated: 7 September 2026 · Version: 1.0
1. Introduction
PHARMACHIM Single Member S.A. respects your privacy and is committed to protecting your personal data. This Policy explains what data we collect through the website pharmachim.gr (the “Website”), why we collect it, how we use it, with whom we share it and what rights you have.
Processing is carried out in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Greek Law 4624/2019, Greek Law 3471/2006 and all other applicable provisions.
This Policy constitutes the information notice required by Articles 13 and 14 GDPR.
2. Controller and contact details
| Data controller | PHARMACHIM Single Member S.A. |
| Registered office | 7A Vasilissis Sofias Avenue, 106 71 Athens, Greece |
| G.E.MI. No. | 191655801000 |
| VAT No. | 803188792 |
| Telephone | +30 210 3303985 |
| General contact | info@pharmachim.gr |
| Data Protection Officer (DPO) | dpo@pharmachim.gr |
The Company has designated a Data Protection Officer (DPO) under Article 37 GDPR, whose duties are performed by an external adviser. You may contact the DPO on any matter relating to the processing of your data and the exercise of your rights, at dpo@pharmachim.gr or by post to the address above, marked “For the attention of the Data Protection Officer”.
3. What data we collect
3.1 Data you provide to us
Contact form / email: full name, email address, telephone number (if you provide it), company name and role (if you provide them), the content of your message and any attachments, and the date and time of submission.
Business enquiries: contact details and professional information you share with us in the context of a business relationship, a scientific enquiry or a job application.
3.2 Data collected automatically
Technical data and server log files: IP address (anonymised or truncated where technically feasible), browser type and version, operating system, device type, language, pages visited, date and time of access, referrer page and error data.
Cookies and similar technologies: as described in detail in our Cookie Policy.
3.3 Special categories of data
The Website is not designed to collect special categories of data (Article 9 GDPR), such as health data. Please do not send such data through the contact form or by unencrypted email.
Exceptionally, if you voluntarily provide us with information constituting an adverse event report or a quality complaint concerning a medicinal product, we are legally obliged to process it — see section 4.4.
Source of data not obtained from you (Article 14 GDPR). In the pharmacovigilance context we may receive patient data (for example initials, age, sex, medical history, the adverse reaction) that does not come from the patient but from the reporter — a healthcare professional, a relative or a third party — or from the marketing authorisation holder and the competent authorities. Such data is kept to the minimum necessary and pseudonymised where feasible.
3.4 Minors
The Website is not directed at minors and we do not knowingly collect data of persons under 15, the age threshold set by Article 21 of Greek Law 4624/2019. If we become aware of such collection, the data is deleted without delay.
4. Purposes and legal bases of processing
| # | Purpose | Data categories | Legal basis (GDPR) |
|---|---|---|---|
| 4.1 | Responding to enquiries and requests submitted through the form or by email | Identification and contact details, message content | Article 6(1)(b) (steps prior to entering into a contract) or Article 6(1)(f) (our legitimate interest in responding to enquiries and managing our correspondence) |
| 4.2 | Managing business relationships and communication with partners, suppliers and healthcare professionals | Professional contact details | Article 6(1)(b) or 6(1)(f) (legitimate interest in conducting our business) |
| 4.3 | Assessing unsolicited job applications / CVs | Applicant details, employment history | Article 6(1)(b) or 6(1)(a) (consent to retain your CV in a candidate pool) |
| 4.4 | Pharmacovigilance and product safety: recording, assessing and transmitting adverse event reports and quality complaints | Reporter details, patient details, health data | Article 6(1)(c) (compliance with a legal obligation) in conjunction with Article 9(2)(i) (public interest in the area of public health, ensuring high standards of quality and safety of medicinal products) |
| 4.5 | Network and information security, prevention and investigation of misuse, ensuring proper operation of the Website | Technical data, log files | Article 6(1)(f) (legitimate interest in system security) |
| 4.6 | Statistical analysis of traffic and improvement of the Website | Usage data via analytics cookies | Article 6(1)(a) (consent), read with Article 4(5) of Greek Law 3471/2006 |
| 4.7 | Operation of strictly necessary cookies | Technical identifiers | Article 6(1)(f) · exempt from the consent requirement under Article 4(5) of Greek Law 3471/2006 |
| 4.8 | Compliance with legal, regulatory and tax obligations and responses to requests from authorities | As applicable | Article 6(1)(c) |
| 4.9 | Establishment, exercise or defence of legal claims | As applicable | Article 6(1)(f) · Article 9(2)(f) where special categories are involved |
Legitimate interest. Where we rely on Article 6(1)(f), we have balanced our interest against your rights and freedoms. You may request information about that balancing test at dpo@pharmachim.gr.
Provision of data. Completing the fields marked as mandatory in the contact form is necessary for us to answer your request; without them we cannot respond. Providing any other information is optional.
5. Automated decision-making and profiling
We do not take decisions concerning you based solely on automated processing, nor do we carry out profiling within the meaning of Article 22 GDPR.
6. Recipients of the data
We do not sell or rent personal data. We may share it, strictly to the extent necessary, with:
- Authorised staff of the Company, on a need-to-know basis;
- Processors acting on our behalf under Article 28 GDPR contracts: the Website’s hosting provider, our development and maintenance provider, email and IT infrastructure providers, analytics providers (where you have consented);
- Marketing authorisation holders and principals we represent, in the context of pharmacovigilance, quality and regulatory compliance obligations;
- Competent authorities: EOF, the European Medicines Agency (EMA), and other supervisory, tax, judicial or law enforcement authorities where required by law;
- External advisers (legal, audit, accounting), bound by confidentiality;
- Third parties in the context of a corporate transaction (merger, acquisition, business transfer), subject to appropriate safeguards.
7. Transfers outside the EEA
As a rule your data is kept within the European Economic Area. Where a transfer to a third country is required — for example where an IT service provider or a marketing authorisation holder is established outside the EEA — it takes place only where one of the following applies:
- an adequacy decision of the European Commission (Article 45 GDPR); or
- appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses, accompanied by a transfer impact assessment and any supplementary measures (Article 46 GDPR); or
- a specific derogation under Article 49 GDPR.
A copy of the safeguards is available on request at dpo@pharmachim.gr.
8. Retention periods
| Category | Retention period |
|---|---|
| Contact form messages and related correspondence | Up to 24 months from final handling of the request, unless it develops into a contractual or other relationship |
| Business contact and partner data | For the duration of the relationship and 5 years after it ends (the general twenty-year limitation period of Article 249 of the Greek Civil Code applied only where required) |
| Unsolicited CVs | 12 months from receipt, or longer with your consent |
| Pharmacovigilance data | For as long as the product is authorised and at least 10 years after the marketing authorisation has ceased to exist (Article 12 of Commission Implementing Regulation (EU) 520/2012 and GVP Module I) |
| Server log files | Up to 12 months |
| Cookies | For the lifetime of each cookie as stated in the Cookie Policy; consent is re-requested at the latest every 6 months |
| Invoices and accounting records | As required by tax legislation (as a rule 5 years) |
| Data relating to legal claims | Until final resolution of the dispute and expiry of applicable limitation periods |
After those periods, data is securely deleted or irreversibly anonymised.
9. Data security
We apply appropriate technical and organisational measures (Article 32 GDPR), including: encryption of Website traffic via TLS/HTTPS, access control and role-based permissions, application of the need-to-know principle, regular backups, software patching and maintenance, staff confidentiality undertakings and data processing agreements with our providers.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we notify the Hellenic Data Protection Authority within 72 hours and, where required, you directly, in accordance with Articles 33-34 GDPR.
10. Your rights
As a data subject you have the following rights:
- Access (Article 15): to be told whether we process your data and to obtain a copy.
- Rectification (Article 16): to have inaccurate data corrected or incomplete data completed.
- Erasure / “right to be forgotten” (Article 17): subject to the conditions set out in law.
- Restriction of processing (Article 18).
- Data portability (Article 20): for data processed by automated means on the basis of consent or a contract.
- Objection (Article 21): to object at any time to processing based on legitimate interest, on grounds relating to your particular situation, and unconditionally to processing for direct marketing purposes.
- Withdrawal of consent (Article 7(3)): at any time, without affecting the lawfulness of processing carried out on the basis of consent before withdrawal.
How to exercise your rights: by request to dpo@pharmachim.gr or by post to the address in section 2. We respond without undue delay and in any event within one (1) month of receipt; this may be extended by a further two months where the request is complex, in which case we will inform you. Exercising your rights is free of charge; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act, giving reasons. We may ask for additional information to verify your identity.
Limitations. Certain rights may be restricted where processing is required by a legal obligation — in particular in pharmacovigilance, where safety data cannot be erased before the statutory retention periods have expired.
11. Right to lodge a complaint
If you believe that the processing of your data infringes the law, you have the right to lodge a complaint with the supervisory authority:
Hellenic Data Protection Authority (HDPA) 1-3 Kifissias Avenue, 115 23 Athens, Greece · Tel. +30 210 6475600 · contact@dpa.gr · www.dpa.gr
We would appreciate the opportunity to address your concerns first, at dpo@pharmachim.gr.
12. Third-party links
The Website may contain links to third-party websites. This Policy does not cover their processing of data. We recommend that you read their privacy policies.
13. Changes to this Policy
We may update this Policy to reflect legal, technical or organisational developments. The version in force at any time is published on the Website with an updated date. Where changes are material, we will provide specific notice where required.
14. Contact
PHARMACHIM Single Member S.A. · 7A Vasilissis Sofias Avenue, 106 71 Athens, Greece · Tel. +30 210 3303985 · dpo@pharmachim.gr
