Privacy Policy
Protecting your personal data and maintaining the confidentiality and trust of our clients, visitors and business partners.
1. Introduction and Scope
Tsegas Law Firm – Konstantinos Tsegas & Associates (“we”, “us” or “our”) is committed to protecting your personal data and to the professional secrecy that lies at the heart of our relationship with our clients.
This Privacy Policy explains how we collect, use, store and protect personal data when you visit our website, communicate with us, instruct us to act for you or otherwise interact with our firm.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), Greek Law 4624/2019 and the professional obligations applicable to us as a law firm.
This Policy sets out what information we collect, why we process it, how we protect it, how long we retain it and what rights you have in relation to your personal data. We encourage you to read it carefully.
2. Information We Collect
We collect the categories of personal data necessary for the provision of legal services. Depending on the circumstances, these include:
- Identification data — first name, surname, identity card number and tax identification number.
- Contact data — postal address, email address and telephone number.
- Financial data — billing details and bank account details.
- Case data — the information, documents and history relating to your legal matter. Depending on the nature of the matter, this may include special categories of personal data within the meaning of Article 9 of the GDPR, such as health records, or personal data relating to criminal convictions and offences within the meaning of Article 10.
- Technical data — IP address, browser type and similar information collected automatically when you visit our website through cookies and analytics tools.
We do not collect personal data that is not necessary for the purpose of the processing. Where we receive personal data from third parties, we process it in accordance with the GDPR and applicable law.
3. How We Use Your Personal Data
We process personal data only where there is a lawful basis for doing so, and only for the following purposes:
- to provide legal advice and to represent you before the courts and public authorities;
- to perform our contractual obligations to you, including the drafting of pleadings and the preparation of contracts;
- to invoice our services and maintain our accounting records;
- to comply with our legal and professional obligations, including anti-money-laundering legislation and the rules of the Greek Advocates’ Code;
- to establish, exercise or defend legal claims; and
- to improve our website and the quality of the services we provide.
The lawful basis for the processing is ordinarily the performance of a contract, compliance with a legal obligation to which our firm is subject, or our legitimate interests, provided that those interests are not overridden by your fundamental rights and freedoms. Where processing is based on your consent, you may withdraw that consent at any time; withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
4. Data Protection and Security
We apply strict technical and organisational measures to protect personal data against unauthorised access, loss, destruction, alteration, disclosure or other unlawful processing.
These measures include encryption in transit using current SSL/TLS protocols, access controls over our electronic files, secure server environments, and the storage of physical case files in controlled premises with restricted access.
Access to personal data is limited to those who require it for legitimate professional or operational purposes. All members of our staff and our associates are bound by strict confidentiality undertakings and by legal professional privilege, which ensures that your matter remains strictly private, subject to applicable law and professional obligations.
5. Your Rights Under the GDPR
As a data subject, you have the following rights in relation to your personal data:
- Right of access — to obtain confirmation as to whether we process your personal data and, where we do, a copy of that data together with information about its processing.
- Right to rectification — to have inaccurate or incomplete personal data corrected.
- Right to erasure — the “right to be forgotten”, subject to our legal and professional obligations to retain records.
- Right to restriction of processing — to have the processing of your personal data restricted in the circumstances set out in the GDPR.
- Right to data portability — to receive the personal data you have provided to us in a structured, commonly used and machine-readable format and, where technically feasible, to have it transmitted to another controller.
- Right to object — to object to processing carried out on the basis of our legitimate interests, where the conditions in the GDPR are met.
- Right to withdraw consent — where the processing is based on your consent.
These rights are not absolute and are subject to the conditions and exceptions provided for in the GDPR. To exercise them, please contact us in writing using the details in Section 9 below.
6. Cookies
Our website uses cookies, which are small text files stored on your device.
We use strictly necessary cookies for the basic operation of the website, together with analytics cookies (including Google Analytics) which help us understand how visitors interact with the site. These statistics are collected in aggregate and are used to improve our content and navigation.
Where consent is required, non-essential cookies are set only in accordance with your choices. You can manage or disable non-essential cookies at any time through the cookie settings available on our website, or through your browser settings. Disabling certain cookies may affect your experience of the website.
Our contact page loads the embedded map only when you click to load it, so that no third-party cookies are set for that purpose unless you ask for them.
7. Third-Party Services and Data Recipients
Legal professional privilege is fundamental to our practice. We do not sell, rent or otherwise commercially disclose your personal data.
Personal data is disclosed only where necessary and under strict conditions, namely: to courts and public authorities in the course of representing you; to notaries, bailiffs, accountants, technical experts and other professionals instructed in connection with your matter, always subject to confidentiality; and to IT service providers, including our website hosting provider, which act as data processors on our behalf under written data processing agreements as required by Article 28 of the GDPR.
Personal data may also be disclosed where we are required to do so by law or by a competent authority, or where disclosure is necessary for the establishment, exercise or defence of legal claims.
Where personal data is transferred outside the European Economic Area, we ensure that appropriate safeguards under Chapter V of the GDPR are in place.
8. Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, taking into account our legal, regulatory and professional obligations.
As a general rule, the physical and electronic file relating to your matter is retained for a period of five (5) to twenty (20) years following the closure of the matter, in order to comply with tax obligations and with the limitation periods applicable to potential legal claims, in accordance with the Greek Advocates’ Code.
Once these periods have elapsed, your personal data is securely deleted or destroyed.
9. Contact Details
If you have any questions, concerns or complaints regarding this Privacy Policy, or if you wish to exercise your rights under the GDPR, please contact us.
Tsegas Law Firm – Konstantinos Tsegas & Associates
16 Plateia Argentinis Dimokratias
114 72 Athens, Greece
Telephone: +30 210 6424646
Email: info@tsegalaw.gr
If you consider that the processing of your personal data infringes data protection law, you also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).