Privacy Policy / GDPR

Last updated: July 2026

This Privacy Policy explains how our company collects, uses, stores and protects your personal data when you use the Piato365 platform (the piato365.gr website and PWA application), in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.

1. Data Controller

The controller of your data is the single-member company Kazepi (kazepi.gr), VAT No. 802252145, legally represented by Maria Kazepi. Piato365 is a service/trademark of the group.

2. What data we collect

  • Identification & contact details: full name, mobile phone number, email (optional).
  • Delivery details: postal code, address (only for home delivery).
  • Order details: order history, products, dates, amounts, payment/collection method.
  • Payment data: card payments are processed by the payment provider Viva Wallet. We do not store card details — we receive only confirmation of the transaction.
  • Technical data: IP address, device/browser type, cookies (see §8), for security and service improvement.
  • Marketing consent: your preferences for receiving offers via SMS/email.

3. Purposes & legal basis for processing

  • Performance of the order (conclusion/performance of a contract, Art. 6(1)(b) GDPR): collection, preparation, delivery, customer service, order confirmations/notifications (transactional SMS/email).
  • Legal obligations (Art. 6(1)(c)): tax/accounting records.
  • Legitimate interest (Art. 6(1)(f)): platform security, fraud prevention, service improvement.
  • Consent (Art. 6(1)(a)): sending advertising/promotional messages (which you may withdraw at any time).

4. Recipients of the data

We disclose data only to the extent necessary to perform the order, to:

  • The partner producer/catering business (for preparation — receiving only the strictly necessary information, without payment details).
  • The collection point/courier (for delivery — name, phone number, and address where required).
  • The payment provider Viva Wallet (for card payments).
  • SMS/email providers (for order notifications).

We do not sell or rent your personal data to third parties.

5. Retention period

We retain your data for as long as your account remains active and for as long as required by law (e.g. tax records for 5 years). Upon a deletion request, the account is deactivated immediately and the data is permanently anonymised after a 30-day grace period (except for data that must be retained for legal reasons).

6. Your rights (GDPR)

At any time, you have the following rights:

  • Access — to find out what data we hold about you.
  • Rectification — to correct inaccurate details (including via "My Account").
  • Erasure ("right to be forgotten") — to request the deletion of your account and data.
  • Restriction of processing.
  • Portability — to receive your data in a structured format.
  • Objection to processing.
  • Withdrawal of consent to marketing, at any time, without retroactive effect.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).

7. How to exercise your rights

You can manage your details and preferences from the "My Account" page, or contact us with any request concerning your rights. We respond within one (1) month.

✉ Contact us about your rights

8. Cookies

We use essential cookies for the operation of the cart and login, as well as optional statistics/marketing cookies (only with your consent through the relevant banner). You can manage your choices from your browser.

9. Security

We take technical and organisational measures (HTTPS encrypted connection, secure password storage with hashing, access restriction) to protect your data from unauthorised access, loss or leakage.

10. Minors

The service is intended for adults. We do not knowingly collect data from minors under the age of 16.

11. Amendments

We may update this Policy. The version in force at any given time is posted on this page together with the date of the update.