Privacy policy
How we use and protect your personal data
This policy explains what personal data the wonlex.gr online shop collects, why, how long it keeps it and what rights you have, under the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.
1. Data controller
The controller of your data is GPSCOM, which operates wonlex.gr:
- Company name: GPSCOM
- VAT number (ΑΦΜ): [pending]
- Registered address: [pending]
- Email: info@wonlex.gr
- Phone: +30 2310 944433
For any question about your data, write to us at info@wonlex.gr.
2. What data we collect and why
Orders
Name, delivery and billing address, phone, email, the products you bought, the payment method and, if you ask for an invoice, your business details. We use them to fulfil and deliver your order, issue a receipt or invoice and handle returns and warranty claims. We do not see or store your full card details. Legal basis: performance of the contract (GDPR Art. 6(1)(b)) and compliance with tax law (Art. 6(1)(c)).
Customer account
If you create an account: email, password (stored only in encrypted form), delivery details and order history. Legal basis: performance of the contract.
Newsletter and offers
Your email address, only if you subscribe. You can unsubscribe at any time from the link in every email. Legal basis: consent (Art. 6(1)(a)).
Contacting us
Name, email, phone and the content of your message when you write to us through the contact form, by email, by phone or on Viber. Legal basis: answering your request and our legitimate interest in serving our customers (Art. 6(1)(b) and (f)).
Warranty registration
Name, email, phone, order number, model, the device’s IMEI or serial number, purchase date and whatever you tell us about the problem. We use them only to identify the device and handle the warranty. Legal basis: performance of the contract and legal obligation (legal guarantee).
Reviews
If you leave a product review, we publish the name you choose and your text. You can ask us to remove it at any time. Legal basis: consent.
Browsing, cookies and analytics
Strictly necessary cookies (cart, language, login, consent choices) work without consent. Analytics (Google Analytics 4) and advertising (Google Ads, Meta) are switched on only if you consent. For security, technical data such as your IP address and browser type are also logged. Details are in our Cookie policy.
3. Children and the watch’s data
The shop is meant for adults. Kids’ watches are bought by parents or guardians, and we process only the buyer’s data. We do not knowingly collect personal data from children under 15, the age of digital consent in Greece (Law 4624/2019, Art. 21). If you find that a child has given us data, write to info@wonlex.gr and we will delete it.
The data the watch produces does not come to us. Location, calls, voice messages, photos and video calls pass through the companion app (e.g. SeTracker) and its provider’s servers. The shop has no access to this data and does not store it.
That data is covered by the app provider’s terms and privacy policy, which we recommend you read before activating the watch. Controller and storage location of the app’s data: [pending].
Tips for parents
- Use a strong, unique password for the app account and do not share it.
- Add only people you trust to the watch’s contacts and, if your model supports it, allow calls only from them.
- Give access to your child’s location only to the parents or guardians who need it, and regularly check which accounts are linked to the watch.
- Explain to your child what the watch does and when you use it, and respect their privacy as they grow older.
- Tell the school about the watch and turn on class mode if your model has it.
- Before you sell, give away or return a watch, unlink it from the app and do a factory reset.
The same applies to watches for older people: set them up with the knowledge and agreement of the person who will wear them.
4. Who we share data with
We do not sell your data. We share it only as far as needed, with partners who process it on our behalf under contract and with appropriate security measures:
- Payment providers (e.g. Viva, Stripe, PayPal, banks for IRIS), depending on how you pay, for payment and fraud prevention.
- Courier companies, for delivery (name, address, phone). Partner couriers: [pending].
- Email delivery provider: [pending].
- Hosting provider for the website and database: [pending].
- Accountant and e-invoicing provider, for our tax obligations (myDATA).
- Google and Meta, only if you consent to analytics or advertising cookies.
- Public authorities, where the law requires it.
Transfers outside the EEA
Some providers (e.g. Google, Meta, Stripe) may process data outside the European Economic Area, mainly in the USA. In those cases the transfer relies on the EU-US Data Privacy Framework or the European Commission’s standard contractual clauses.
5. How long we keep it
- Orders and receipts/invoices: as long as tax law requires (as a rule at least 5 years from the end of the financial year) and, for warranty matters, for as long as the warranty lasts.
- Warranty registration: for as long as the warranty lasts and until related claims are time-barred.
- Account: until you ask us to delete it.
- Newsletter: until you unsubscribe.
- Messages: as long as needed to handle your request and then for [pending].
- Cookies: as described in our Cookie policy.
6. Your rights
You can ask at any time for:
- access to your data and a copy of it;
- rectification of inaccurate or incomplete data;
- erasure, unless the law requires us to keep it (e.g. receipts and invoices);
- restriction of processing;
- portability, i.e. to receive your data in a machine-readable format;
- objection to processing based on legitimate interest and, at any time, to direct marketing;
- withdrawal of your consent, without affecting the lawfulness of processing before the withdrawal.
Send your request to info@wonlex.gr. We will reply within one month. If needed, we may ask for information to confirm the request comes from you.
7. Complaint to the Data Protection Authority
If you believe the processing of your data breaks the law, you can lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifisias Ave, 115 23 Athens). We would appreciate it, though, if you contacted us first so we can try to resolve the issue.
8. Security
The website runs over an encrypted connection (HTTPS). Only people who need the data for their work can access it, and account passwords are stored only in encrypted form.
9. Changes to this policy
We may update this policy when the way the shop works or the law changes. The date of the last update is shown at the top of this page.