Privacy Policy
Last updated: 20 September 2026
The Mikrolab microbiology laboratory (hereinafter the “Company”) attaches particular importance to the protection of your personal data. This Personal Data Protection Policy (hereinafter the “Policy”) sets out the conditions under which our Company, with registered offices at 15A Theodorou Kolokotroni St, Chalandri 152 33, tel.: 210 6855799, email: mikrolabchristou@gmail.com, collects, stores and uses personal information. The Company also operates a second laboratory at 10 Korytsas St, Agia Paraskevi 153 43, tel.: 210 6006456.
About us
The Company is responsible for the website https://mikrolab.gr/, which is the Company’s online presence (hereinafter the “site”). The personal data you provide to us when visiting our website or contacting us are processed and kept in a file under the responsibility of our Company.
This Policy may be updated from time to time; for this reason you should check its content regularly for any changes.
This Policy concerns the website. Information on the processing of your data as a person tested at our laboratories (e.g. referrals, test results) is provided by the laboratory staff.
1. Definition of personal data
The term “personal data”, as used in this Policy, refers to information about data subjects, i.e. natural persons, whether private individuals or professionals, such as full name, postal address, email address, contact telephone number and the like, which can be used to identify a customer or visitor of the website.
2. Definition of processing of personal data
Processing of personal data means the collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure to third parties, dissemination, alignment, combination, restriction, erasure and destruction of the personal data of natural persons.
3. How personal data are collected
We collect information about you, among other cases, in the following situations:
- when you contact us directly, by telephone or email, to request information,
- when you visit the website,
- when you fill in the contact form on our website.
The website has no member registration or user accounts, and no online payments are made through it.
If you provide personal data on behalf of a third party, you must ensure that this third party has first been informed of this Policy. If you are under 16, you must not provide us with any information about yourself unless you have the consent of the person who holds parental responsibility for you. Please help us keep your information up to date by informing us of any changes to your data.
4. Which personal data we collect
The following categories of data about you may be collected and further processed:
- Contact form data: full name, telephone number, email address, the subject you are interested in and your message.
- Information about the reasons for contacting us: information concerning your interest, requests for our services, including complaints and claims.
- Technical website usage data: IP address and browsing details, as recorded in the logs of the server hosting the website, for security and proper operation.
Please do not send test results, medical reports or other health data through the contact form or by email. For such matters, please contact the laboratory by telephone.
We collect the above information from you, which you provide voluntarily. For cookies and the third-party content embedded in the website (Google Maps, Google reviews), please see the Cookie Policy.
5. Processing of personal data
We do not make decisions or carry out profiling based on automated processing of your data.
6. Legal basis for processing personal data
For data relating to the actions described above, the lawfulness of processing is based on your consent, which you give before sending the contact form.
7. Purpose of processing personal data
The personal data you provide on our website are intended exclusively for purposes relating to the provision of our services and communication with you, so that we can respond to your request.
They may not be used by any unauthorised third party without compliance with the provisions of the General Data Protection Regulation (EU) 2016/679, national legislation and the relevant acts of the Hellenic Data Protection Authority, Law 3471/2006 and the ePrivacy Directive (2002/58/EC, as amended by 2009/136/EC), as in force.
The Company operates in accordance with applicable Greek and EU legislation and keeps your personal data secure. In short, we ask only for as much information as we need to serve you and communicate with you.
8. Recipients of the data
The recipients of the data are only the strictly necessary staff and associates of the Company, who are bound by confidentiality. We may share or disclose your data when you have expressly requested it or when required by law.
9. Processors
For the operation of the website, the Company works with hosting, email and technical support providers. The processors of personal data have agreed and committed to the Company:
- to maintain confidentiality,
- not to send data to third parties without the Company’s permission,
- to take appropriate security measures,
- to comply with the legal framework for the protection of personal data, and in particular the GDPR.
10. Processing and storage period – deletion
The data you provide are kept by us only for as long as is necessary to fulfil the purpose for which you have shared them with us, and in compliance with the applicable legal provisions.
In particular, contact form messages are sent to the Company’s email address and recorded in the website’s database. They are kept from the time your consent is obtained until you withdraw it, by sending a request to the Company’s email address, or until they are no longer necessary for the above purposes.
We restrict access to your data to the authorised persons who need to use them for the specific purpose.
11. Data security
We are committed to safeguarding your personal data. We have taken appropriate organisational and technical measures to secure and protect your data against any form of accidental or unlawful processing. The site has an SSL certificate installed for the encryption and secure handling of your personal and browsing data.
These measures are reviewed and amended whenever necessary. Any processing of your data is permitted only by persons authorised by us, our employees and associates, exclusively for the purposes stated above.
12. Your rights as a data subject
- Right of access. You have the right to be informed by us whether and which of your data we process, the purpose of the processing, the type of data we keep, to whom we disclose them, how long we store them and whether automated decision-making takes place.
- Right to rectification. If you find an error in the personal data we hold about you, you may ask us to correct it.
- Right to erasure (“right to be forgotten”). You may ask us to delete your data if they are no longer necessary for the above processing purposes or if you wish to withdraw your consent, where consent is the only legal basis.
- Right to data portability. You may ask to receive the data you have provided in a readable format, or to have them transmitted to another controller.
- Right to restriction of processing. You may ask us to restrict the processing of your data while your objections to the processing are being examined.
- Right to object. You may object to the processing of your data or withdraw your consent, and we will stop processing unless there are other compelling legitimate grounds that override your right.
13. How to exercise your rights
Any request should be addressed in writing to the Company at mikrolabchristou@gmail.com. For any question, suggestion or statement relating to these matters, contact us by email or through the contact form. You may contact us in the same ways for information on the progress of your requests.
14. Handling of requests
We respond to your requests free of charge and without delay, and in any case within one (1) month of receiving your request. If your request is complex or there is a large number of requests, we will inform you within that month whether an extension of a further two (2) months is needed, within which we will respond.
If your requests are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee, taking into account the administrative costs, or refuse to act on the request.
15. Applicable law
We process your data in accordance with the General Data Protection Regulation (EU) 2016/679 and, in general, the applicable national and European legislative and regulatory framework for the protection of personal data.
16. Right to lodge a complaint
You have the right to lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifissias Ave, 115 23 Athens, tel. +30 210 6475600, email: contact@dpa.gr, www.dpa.gr) if you believe that the processing of your personal data violates the applicable legal framework for the protection of personal data.
17. Amendments to this Policy
We will update this Policy whenever necessary. If there are significant changes to the Policy or to the way we use your personal data, we will notify you by posting a notice in a prominent place before the changes take effect, or by any other appropriate means. We encourage you to read this Policy at regular intervals.
The Company is the Controller of the data it processes. See also the website’s Terms of Use and Cookie Policy.