Privacy Policy

Website’s Privacy Policy

 

  1. About this Privacy Policy

This Privacy Policy applies to information that Another Circus may collect about any user (“User”, “you”, “your”) in connection with your access and use of the www.anothercircus.com website, including any individual pages, subdomains, and any functionalities, features, or services made available through it (“Website”), our social media pages, as well as through email messages that we send to you that link to this Privacy Policy, and other communications (for example, customer support requests, surveys, and SMS texts) in which you may provide personal information to Another Circus. The privacy of our Website Users is very important to us, and we are committed to safeguarding it. In line with the EU General Data Protection Regulation (Regulation 2016/679 – GDPR), the Greek applicable legislation and the decisions and guidelines of the competent authorities, this Privacy Policy explains what we will do with your personal information.

Those Privacy Policy provisions are part of our Terms of Use (“ToU”) and should be read in conjunction with them. Capitalized terms that are not defined in this Privacy Policy have the meanings given to them in the ToU.

If you do not agree with this Privacy Policy, please, do not access or use the Website.

 

  1. Controller of your data

Your data controller is “ANOTHER CIRCUS PRIVATE COMPANY”, a company incorporated under the laws of Greece, having its registered address at 5 Mesogeion Avenue, 115 26, Athens, Greece, with VAT No 997624630 and telephone number: +30 210 6105180 (“Another Circus”, “we”, “us”, “our”). 

 

  1. What personal information we collect

3.1 We collect the following personal information:

  1. Information about your computer, including but not limited to your Internet Protocol (IP) address, geographical location, browser type and version, operating system and devise characteristics.
  2. Information about your visits to and use of the Website including the referral source, length of visit, page views, and website navigation paths.
  3. Information that is generated while using the Website, including when, how often, and under what circumstances you use it.
  4. Information that you submit via links to social media networks, forums, blogs, message boards, chat rooms or similar functionality.
  5. Information that you provide to us for the purpose of subscribing to our email notifications and/or newsletters or text message alerts, such as email address and the information included in your email address, such as name and surname and context of your signature.
  6. Information that you enter when you send us messages via the Website’s message form.
  7. Information that you sent to us when you apply for a job, including but not limited to you C.V. and any other information shared for the job application. 
  8. Any other information you send to us through any means.

3.2 Social Media features and Widgets. Our Website may include Social Media features, such as the Facebook “Like” button, and Widgets, such as the “Share This” button or interactive mini-programs that run on our Website. These features may collect your IP address, which page you are visiting on our Website, and may set a cookie to enable the applicable feature or widget to function properly. Social Media Features and Widgets are either hosted by a third party or hosted directly on our Website. Your interactions with these features are governed by the privacy policy of the company providing the feature (whether Linkedin, Facebook, Instagram, or some other third party), and you must contact them with any requests you may have for access, modification or deletion of your personal information.

3.3 We do not knowingly collect personally identifiable information from anyone under the age of 18 (“Minor”) without his/her parent’s or guardian’s consent. If you are a parent or guardian of a Minor and you are aware that the Minor has provided us with personal data without your consent, please contact us. If we become aware that we have collected personal data from Minors without verification of parental or guardian consent, we take steps to remove that information from our servers.

3.4 In general, we do not process in any way any special categories of personal data under Article 9 of the GDPR. The concept of special categories of personal data includes personal data concerning racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, genetic or biometric data, data concerning the health, sexual life or finally, sexual orientation of an individual. In case we become recipients of any personal data as such, we will directly delete them or return them to their provider, asking him/her to refrain from any transfers of such personal data to us. 

 

  1. How the personal information is used

4.1 We use the personal information in order to:

  1. Storage in our company’s repositories and according to our data retention policy.
  2. Administer our Website and business.
  3. Improve and optimize the performance of the Website and personalize your experience on the Website by offering content tailored to your preferences.
  4. Respond to your inquiries and fulfil your requests, and to provide you with customer support when you ask for it.
  5. Send you updates, newsletters and other content that you have requested or subscribed to, as well as informational materials regarding our services (you can inform us at any time if you no longer wish to receive them).
  6. Only if you have consented and it is in compliance with applicable laws, send you marketing communications regarding products and services that we believe may be of interest to you. If you later decide that you no longer want to receive this type of marketing or promotional information, you may opt-out at any time by clicking the “Unsubscribe” button at the bottom of the marketing communication, or contacting us at the email or mailing address provided in this Privacy Policy.
  7. Send you non-marketing commercial communications.
  8. Send you email notifications that you have specifically requested.
  9. Provide third parties with statistical information about our Users (but those third parties will not be able to identify any individual User from that information).
  10. Deal with inquiries and complaints made by or about you relating to our Website.
  11. Keep our Website secure and prevent fraud.
  12. Verify compliance with the ToU governing the use of our Website (including monitoring messages sent through our Website’s message form).
  13.  As necessary for us to comply with applicable law, relevant industry standards, contractual obligations and our policies.
  14. Delete the personal data in case further processing is not required or upon request from the data subject.

4.2 Any information which is aggregated or anonymized so that it is no longer reasonably associated or trackable to an identifiable natural person, shall no longer be considered as personal information and Another Circus may use it for any legitimate and lawful business purpose.

 

  1. Legal basis for processing

5.1 A general rule in data processing is that, in principle, it is unlawful unless the conditions set forth in Articles 6 and 9 of the Regulation are met, which provide the necessary legal framework which defines the lawfulness of the processing operations on personal data.

5.2 The legal bases for the processing of your personal information is either your consent which you have granted to us, or the fulfilment of our pre-contractual or contractual or legal obligations, or the purpose of serving our legitimate interests.

5.3 We may need to disclose your personal information to government or law enforcement officials, regulatory agencies or other third parties (such as attorneys or regulatory service providers), as necessary, in order to (i) comply with applicable laws or regulations, (ii) cooperate with governmental or law enforcement investigations, (iii) respond to legal claims or processes, (iv) protect the safety and legal rights of the public or any individual, (v) detect, prevent or remedy any suspected fraud, market manipulation or illegal, tortious or wrongful activity or (vi) enforce applicable agreements or other contracts to which you have agreed.

 

  1. Recipients of your personal information (data processors)

6.1 We may share your personal information with the employees, administration members and affiliated companies of Another Circus, within our corporate family, as well as with trusted third-party service providers in order for them to perform certain tasks on our behalf. We guarantee that the data processors we engage with implement the appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including, as appropriate, the measures referred to in Article 32(1) of the GDPR.

6.2 Our processors’ actions may include the following:

  1. Delivering content and communications to you (such as email).
  2. Analysing Website usage and customer demographics
  3. Serving advertisements.
  4. Conducting surveys or contests.
  5. Managing customer relationships.
  6. Providing IT and technical support.
  7. Providing accounting services
  8. Providing cloud storage services.

We only share what is needed for the third party to perform the tasks on our behalf. These third parties are prohibited from using, sharing, or keeping your personal information for any other purpose, and are bound to strict personal data processing terms and conditions.

 

  1. Data transfers to non-affiliated to our company entities

7.1 As a rule, we will not transfer your personal data to any third parties without the need of such processing operation to take place and additionally, your prior explicit consent. Respecting the principle of confidentiality, we ensure that the personal data processed will be not disclosed to unauthorized individuals, taking necessary measures accordingly.  

7.2 In any case, we categorically state that we will not transfer your personal data to any third parties for their direct use for promotional purposes (marketing) or any other purposes not related to the provision of our services or an applicable legal obligation. 

 

  1. Security and protection of your personal information

8.1 The secure processing of your personal data is of utmost importance to us and as a result, we implement all the appropriate organizational and technical measures on a case-by-case basis, both primarily preparatory and during processing, to ensure the confidentiality, integrity, and availability of the personal data collected under this Policy, according to the risk-based approach of the GDPR.

8.2 Some of the relevant measures and procedures implemented are the following:

  1. We apply an internal framework of policies and minimum standards across all our business to keep your personal information safe. These policies and standards are periodically updated to keep them up to date with regulations and market developments. More specifically and in accordance with the law, we take appropriate technical and organizational measures (policies and procedures, IT security etc.) to prevent the loss, misuse, or alteration of your personal information as well as to ensure the confidentiality and integrity of your personal information and the way it’s processed.
  2. We store all the personal information you provide on secure (password- and firewall-protected) servers.
  3. We make sure that all data processing takes place within the European Economic Area (EEA) and we take all the appropriate technical and organizational measures to comply with the principles of GDPR regarding safe data transfer to third countries. If we need to transfer your data to a location outside the EEA, we will implement appropriate measures to ensure that your personal information remains protected and secure in accordance with applicable data protection legislation. 
  4. Our employees are subject to confidentiality and may not disclose your personal data unlawfully or unnecessarily.

You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet.

 

  1. Period for which your personal information will be retained

Your personal information will be stored only for the time which is absolutely necessary for the purposes of its collection and processing as described in this Privacy Policy, always respecting the data minimization principle. The information is securely erased after its processing unless the legal framework in force foresees the continuance of its retention or in case there are ongoing legal actions with Another Circus that directly or indirectly concern you or in case its retention is necessary to establish, exercise, or defend our legal rights. Indicatively, we may keep your data for a maximum period of 5 or 20 years, depending on each case, to cover the possibility of exercising or oppose any legal claim.

 

  1. Your data protection rights

10.1 With the current Privacy Policy, our aim is to provide the necessary information to the Users about the terms of collection and in general processing of their personal data by our company, as Data Controllers. We acknowledge our responsibility to fully adhere to the principles governing the processing of personal data as provided in the GDPR, namely the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability. 

10.2 Additionally, we respect, protect, and ensure the exercise of the data subjects’ rights provided in the GDPR, including:  

  1. “Right to be informed” regarding anything that is related to the processing of personal data (arts. 12-14 GDPR),
  2. “Right of access” to the personal data and any other information related to the data processing activities (art. 15 GDPR),
  • “Right to rectification” of inaccurate personal data or completion of incomplete personal data (art. 16 GDPR),
  1. “Right to erasure” (“right to be forgotten”), according to which the data subject could achieve the deletion of his/her personal data under certain conditions (art. 17 GDPR),
  2. “Right to restriction of processing” of the personal data under certain conditions (art.18 GDPR),
  3. “Right to data portability”, according to which the data subject can receive the personal data concerning him/her, which had been provided to a controller, in a structured, commonly used and machine-readable format and transmit them to another controller without hindrance from the controller to which the personal data had been previously provided (art. 20 GDPR),
  • “Right to object” at any time to processing of personal data concerning him/her (art. 21 GDPR),
  • “Right to object to the automated individual decision-making, including profiling” (art. 22 GDPR),
  1. “Right to withdraw from the provided consent” freely, at any time, in case the processing of your personal data is based on consent and
  2. “Right to file a claimbefore the responsible data protection regulatory authority, in particular, before the Greek Authority for the Protection of Personal Data: https://www.dpa.gr/index.php/el/polites/katagelia_stin_arxi                                                                                                                                              
  3. Exercising your rights

11.1 If you want to exercise your rights or submit a complaint or simply have any questions, you may contact Another Circus in writing at its mailing address (5 Mesogeion Avenue, 115 26, Athens, Greece) or via e-mail at the e-mail address info@anothercircus.com or you can even call at the telephone number +30 210 6105180.

11.2 In the case of a relevant request, we are obliged to respond to it without undue delay and in any event within one month of receipt of the request and provide information to you in a concise, transparent, intelligible and easily accessible form, using clear and plain language. You will not have to pay a fee to exercise any of the aforementioned rights. However, we may charge a reasonable fee or refuse to comply with your request in case the latter is clearly unfounded, repetitive or excessive.

 

  1. Actions in case of a data breach event

12.1 Despite our efforts to ensure the integrity and security of your personal data, the rapid development of technology may lead to the emergence of new, unforeseen methods that could result in malicious loss, misuse, alteration, or destruction of the personal data. While we cannot absolutely guarantee the security of the personal data in every unforeseen situation, we do guarantee vigilance and effective management of potential risks, always in collaboration with the competent authorities, beyond the security measures already taken.  

12.2 According to Article 33 of the GDPR, we shall notify, without undue delay and, if feasible, within 72 hours of becoming aware of the personal data breach, the supervisory authority as per Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. When notification to the supervisory authority is not made within 72 hours, it shall be accompanied by a justification for the delay. If it is not possible to provide the information simultaneously, it may be provided gradually without unjustified delay.  

12.3 Additionally, according to Article 34 of the GDPR, if the personal data held in our records are breached in a manner that may pose a high risk to your freedoms and rights, we have the corresponding obligation to inform you without undue delay, as provided for in the applicable General Data Protection Regulation (GDPR).

 

  1. Links to third party websites

Any interconnection between this Website and any other third-party website via special links (links, hyperlinks or banners) does not mean that Another Circus accepts any responsibility for the policies applied by those websites regarding the handling and protection of personal information.

You must make sure you are informed about the protection and management of your personal information by those third-party websites.

 

  1. Changes to the Privacy Policy 

We may amend the information contained in this Privacy Policy when we consider this appropriate. Should we do so, we will notify you by various procedures through the Website (for example, through a banner, a pop-up or a push notification), or we may even send you a notice to your e-mail address when the change in question is relevant to your privacy, for you to be able to review the changes, assess them and, as the case may be, object or unsubscribe from ay service or functionality. In any case, we suggest you to review this Privacy Policy from time to time in case minor changes are made or we make any interactive improvement, taking the opportunity that you will always find it as a permanent point of information on our Website.

 

  1. Information on cookies 

We use cookies to facilitate your browsing in the Website, understand how you interact with us and, in certain cases, to be able to show you advertisements in accordance with your browsing habits. Please read our Cookie Policy to understand with greater detail the cookies and similar devices that we use, their purpose and other information of interest.

 

For any question regarding this Privacy Policy, please contact us at info@anothercircus.com.

 

Last updated: 13/01/2026