Privacy Policy
Last updated: 9 August 2026. This Privacy Policy applies to Xermes PR ("Xermes", "we", "our" or "us"), a company carrying on the business of the collection, sorting, treatment and recycling of waste electrical and electronic equipment (WEEE) and other recoverable waste streams.
This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it and what rights you have. It is written to meet the requirements of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and of Law 4624/2019 on the Personal Data Protection Authority and measures implementing Regulation (EU) 2016/679.
1. Data controller
Xermes PR is the controller of the personal data described in this policy. You can contact us at:
Xermes PR
11th km Thessaloniki-Kilkis, Neochorouda, 54500 Thessaloniki, Greece
Company registration number: 800657706
Email: info@xermes.gr
Telephone: +30 2310 784400
Website: https://www.xermes.gr
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection enquiries should be sent to the address above and will be handled by our management.
2. Scope of this policy
This Privacy Policy applies to:
- Our website at https://www.xermes.gr and any related pages we operate.
- Our mobile applications (Sales, Management, Operations, Processing, Recycle and Ecommerce), published on the Google Play Store and the Apple App Store under the developer account "Theloyaltyapp.eu". Xermes PR is the company responsible for these applications and for the processing of personal data within them.
- Our services, platforms, customer and supplier accounts, and related business operations.
3. Categories of personal data
Depending on your relationship with us, we may process the following:
- Identity and contact data - name, job title, employer, email address, postal address and telephone number.
- Account data - username, password (stored in hashed form), user role, permissions and account preferences.
- Transaction data - orders, quotations, collections, deliveries, invoices, payment status and correspondence about them. We do not store full payment card numbers; card payments are handled by our payment providers.
- Operational data - records created as you use the applications, such as collection and processing records, asset and serial numbers, weights, photographs of items, checklists, inspection results and certificates.
- Device and usage data - device model and operating system, application version, IP address, log files, crash reports, timestamps and pages or screens viewed.
- Location data - see the section on location data below.
- Communications - messages you send us by email, contact form, helpdesk ticket or in-app messaging.
We do not seek to process special categories of personal data within the meaning of Article 9 GDPR. Where such data is unavoidably present in material handed to us for treatment, erasure or destruction, we process it only to the extent necessary to perform the service, under strict confidentiality, and destroy or erase it in accordance with the agreed service.
4. Location data
Our mobile applications may collect and process location data to support operational features. Location data is used for:
- Verifying attendance of field staff at assigned work locations;
- Planning, dispatching and evidencing collections, deliveries and on-site work;
- Giving managers visibility of field activity and supporting operational workflows and logistics;
- Geo-stamping operational records such as collection confirmations and proof of service.
Location data may be collected while the application is in use and, where it is required for work-related tracking, in the background. Users are informed before location access is enabled and are asked to grant permission, and you can review or withdraw that permission at any time in your device settings. Where location data relates to employees, processing is carried out in accordance with the guidance of the competent supervisory authority on monitoring in the workplace, is limited to working time and to what is necessary, and is not used to draw inferences about private life. We do not use location data for advertising and we do not sell it.
5. Purposes and legal bases
We process personal data on the following legal bases under Article 6(1) GDPR:
- Article 6(1)(b) - performance of a contract: creating and administering accounts, processing orders and collections, delivering goods and services, issuing certificates of recycling or destruction, invoicing and support.
- Article 6(1)(c) - legal obligation: accounting and tax records; waste, WEEE and environmental record-keeping and reporting; health and safety; responding to lawful requests from authorities.
- Article 6(1)(f) - legitimate interests: securing our systems and premises, preventing and investigating fraud, theft and misuse, evidencing performance of our services, managing and improving our operations, and administering our customer and supplier relationships. We balance these interests against your rights and you may object as described below.
- Article 6(1)(a) - consent: optional processing such as marketing emails and non-essential cookies. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing before it.
6. Recipients
- Companies within our group involved in providing the service;
- Processors acting on our documented instructions under Article 28 GDPR - hosting and cloud providers, software suppliers, payment service providers, couriers and logistics partners, and professional advisers;
- Downstream treatment, recovery and recycling facilities, and compliance schemes, where this is necessary to perform the service or to meet our reporting duties;
- Competent authorities, regulators and courts, where disclosure is required by law;
- A purchaser or successor in the event of a sale, merger or reorganisation.
We do not sell personal data.
7. Transfers outside the European Economic Area
We host and process personal data within the EEA wherever possible. Where a provider processes personal data outside the EEA, we transfer it only under Chapter V GDPR - that is, to a country covered by a European Commission adequacy decision, or under appropriate safeguards such as the Commission's Standard Contractual Clauses together with a transfer risk assessment and any supplementary measures required. You may request a copy of the safeguards we rely on by writing to us.
8. Retention
We keep personal data only as long as necessary for the purposes described above, and then for as long as required by law. Accounting and tax records are retained for the statutory period applicable in Greece. Waste, WEEE and environmental records are retained for the period required by the applicable environmental legislation and permits. Account data is retained for the life of the account and for a reasonable period afterwards for queries and legal claims, subject to the limitation periods for bringing them. When data is no longer needed we delete it or irreversibly anonymise it.
9. Security
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR, including:
- Encryption of data in transit using TLS;
- Role-based access control, so that staff and contractors can reach only the data they need for their role;
- Individual named accounts and password policies;
- Logging of administrative activity;
- Regular backups, and physical and environmental controls at our hosting provider;
- Contractual confidentiality and data protection obligations on our staff and suppliers.
Where a personal data breach occurs, we will notify Hellenic Data Protection Authority within 72 hours where the breach is likely to result in a risk to individuals, and will inform affected individuals where the breach is likely to result in a high risk to them, in accordance with Articles 33 and 34 GDPR.
10. Your rights
Under the GDPR you have the right to:
- Access your personal data and obtain a copy (Article 15);
- Have inaccurate data corrected and incomplete data completed (Article 16);
- Have your data erased in the circumstances set out in Article 17;
- Restrict processing in the circumstances set out in Article 18;
- Receive the data you provided in a structured, commonly used, machine-readable format and have it transmitted to another controller (Article 20);
- Object at any time to processing based on our legitimate interests, and to object absolutely to direct marketing (Article 21);
- Not be subject to a decision based solely on automated processing which produces legal effects concerning you or similarly significantly affects you (Article 22). We do not carry out such automated decision-making;
- Withdraw consent at any time where processing is based on consent (Article 7(3)).
To exercise any right, email info@xermes.gr. We will respond within one month of receiving your request, which may be extended by a further two months for complex requests, in which case we will tell you within the first month (Article 12(3)). There is normally no charge. If you are an employee or contractor of one of our customers, your employer may be the controller deciding how your data is used in our applications; where that is the case we will pass your request to them.
11. Complaints
Please contact us first at info@xermes.gr so that we can try to resolve any concern. You also have the right under Article 77 GDPR to lodge a complaint with the supervisory authority in the Member State of your habitual residence, place of work or the place of the alleged infringement. The supervisory authority for Greece is:
Hellenic Data Protection Authority
1-3 Kifissias Avenue, 115 23 Athens, Greece
Email: contact@dpa.gr
12. Children
Our website, applications and services are intended for business users and adults and are not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Cookies and similar technologies
Our website uses cookies that are strictly necessary for it to function, which do not require consent. Any analytics or other non-essential cookies or similar technologies are set only with your prior consent, as required by Law 3471/2006 on the protection of personal data and privacy in electronic communications, and you can withdraw or change your choice at any time. Most browsers also allow you to block or delete cookies, although parts of the site may then not work correctly.
14. Changes to this policy
We may update this Privacy Policy from time to time. The version published on this page is the current one and the date at the top shows when it was last changed. Where a change is significant we will take reasonable steps to bring it to your attention.
15. Contact us
Xermes PR
11th km Thessaloniki-Kilkis, Neochorouda, 54500 Thessaloniki, Greece
Company registration number: 800657706
Email: info@xermes.gr
Telephone: +30 2310 784400
Website: https://www.xermes.gr