Privacy Policy
Last updated: [EFFECTIVE DATE]
1. Introduction
This Privacy Policy explains how [LEGAL ENTITY NAME] ("Agenor", "we", "us", "our") collects, uses, discloses and protects personal data when you visit agenor.bi (the "Website"), contact us, or use our business analytics and web development services (the "Services").
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), Greek Law 4624/2019, and, in respect of electronic communications and cookies, Law 3471/2006.
2. Controller vs processor — the two roles we play
- When we process personal data for our own purposes (for example, running the Website, handling enquiries, managing our clients, marketing and meeting our legal obligations), we act as a data controller. This Policy describes that processing.
- When we process personal data on behalf of a Client as part of the Services (for example, analysing datasets a Client provides, or building and operating systems that hold the Client's own customer data), the Client is the controller and we act as a processor. That processing is governed by the Client's own privacy notice and by a data processing agreement concluded under Article 28 GDPR, not by this Policy.
3. Who is responsible for your data (Data Controller)
- Controller: [LEGAL ENTITY NAME], [LEGAL FORM]
- Address: [STREET ADDRESS], Thassos, [POSTCODE], Regional Unit of Kavala, Greece
- Γ.Ε.ΜΗ. No.: [ΓΕΜΗ NUMBER] · Α.Φ.Μ.: [VAT NUMBER]
- Email for privacy matters: [PRIVACY EMAIL] · Telephone: [PHONE]
3.2 Data Protection Officer (if applicable). [Where appointed:] You can contact our Data Protection Officer at [DPO NAME / EMAIL]. [If no DPO is appointed, delete this Section 3.2 and direct all requests to the privacy email above.]
4. What personal data we collect and why
We collect only what we need. Depending on how you interact with us, this may include:
(a) Website visitors
- Data: IP address, device and browser type, operating system, referring URLs, pages viewed, date/time and duration of visits, and similar technical/usage data, together with cookie identifiers.
- Purpose: to operate, secure and improve the Website and to produce aggregate statistics.
- Legal basis: our legitimate interests (Art. 6(1)(f) GDPR) in running and securing the Website for strictly necessary processing; and your consent (Art. 6(1)(a) GDPR and Law 3471/2006) for analytics and any non-essential cookies. See our Cookie Policy.
(b) Enquiries and contact forms
- Data: name, email address, telephone number, company name, and the content of your message.
- Purpose: to respond to your enquiry and take steps at your request prior to entering into a contract.
- Legal basis: pre-contractual steps / performance of a contract (Art. 6(1)(b) GDPR) and/or our legitimate interest (Art. 6(1)(f)) in responding to enquiries.
(c) Clients and prospective clients
- Data: business contact details, role, correspondence, project information, billing and payment details, and information necessary to deliver the Services.
- Purpose: to negotiate, conclude and perform Service Agreements, manage the relationship, provide support, and keep records.
- Legal basis: performance of a contract (Art. 6(1)(b)); compliance with legal obligations (Art. 6(1)(c)); and our legitimate interests (Art. 6(1)(f)) in administering and developing our business.
(d) Marketing communications
- Data: name, email address and communication preferences.
- Purpose: to send you updates, newsletters or offers where you have asked to receive them or where permitted for existing clients regarding similar Services.
- Legal basis: your consent (Art. 6(1)(a)); or our legitimate interest (Art. 6(1)(f)) in marketing to existing clients under the "soft opt-in" permitted by Law 3471/2006. You can withdraw consent or opt out at any time (see Section 8).
(e) Job applicants (if you apply to us)
- Data: the information in your CV, application and correspondence.
- Purpose: to assess your application and manage recruitment.
- Legal basis: pre-contractual steps (Art. 6(1)(b)) and our legitimate interest (Art. 6(1)(f)) in recruiting.
We do not seek to collect special categories of personal data (Art. 9 GDPR) through the Website, and we ask that you do not send us such data unless strictly necessary and lawful.
5. How we collect your data
We collect personal data: (i) directly from you when you contact us, request a proposal, become a client or apply for a role; (ii) automatically when you use the Website, through cookies and similar technologies; and (iii) occasionally from publicly available or third-party business sources for legitimate business-development purposes.
6. Automated decision-making and profiling
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing within the meaning of Article 22 GDPR. Where we use analytics to understand Website usage in aggregate, this does not single you out for individual decisions.
7. Who we share your data with
We do not sell your personal data. We may share it with:
- Service providers acting as our processors, under written contracts with appropriate safeguards, for example:
- website hosting and cloud infrastructure — [PROVIDER, e.g. name/region];
- web analytics — [PROVIDER, e.g. Google Analytics / a privacy-focused tool such as Matomo or Plausible];
- email, CRM and communications — [PROVIDER];
- payment processing — [PROVIDER];
- our accountants, auditors and professional advisers;
- public authorities, courts or regulators where required by law; and
- a successor in the event of a merger, acquisition or reorganisation of our business, subject to this Policy.
Replace the bracketed providers above with your actual sub-processors and keep the list up to date.
8. Your rights
Under the GDPR and Law 4624/2019 you have the right to:
- Access your personal data and obtain a copy;
- request rectification of inaccurate or incomplete data;
- request erasure ("right to be forgotten") where the conditions are met;
- request restriction of processing in certain circumstances;
- data portability — receive certain data in a structured, commonly used, machine-readable format;
- object to processing based on our legitimate interests, and to object to direct marketing at any time;
- withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.
To exercise any of these rights, contact us at [PRIVACY EMAIL]. We will respond within one month of receiving your request (extendable by two further months for complex or numerous requests, in which case we will inform you). We may need to verify your identity before acting. Exercising these rights is free of charge unless a request is manifestly unfounded or excessive.
9. Right to lodge a complaint
If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the supervisory authority in Greece:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) Kifissias 1-3, 115 23 Athens, Greece Tel: +30 210 6475600 · Email: [email protected] · Website: www.dpa.gr
You may also complain to the supervisory authority in your EU country of residence or workplace. We would, however, appreciate the chance to address your concerns first.
10. International transfers
Where personal data is transferred outside the European Economic Area (for example because a service provider is located in, or stores data in, a third country), we ensure an appropriate safeguard is in place, such as an adequacy decision of the European Commission (including, where applicable, transfers to providers certified under the EU–US Data Privacy Framework) or the European Commission's Standard Contractual Clauses, together with any supplementary measures required. You can request further information using the contact details above.
11. How long we keep your data
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting or reporting requirements. As a general guide:
- Enquiries that do not lead to an engagement: [e.g. up to 12–24 months], then deleted or anonymised.
- Client and contract records: for the duration of the relationship and thereafter for the period required to establish, exercise or defend legal claims.
- Accounting and tax records: for the period required by Greek tax and accounting legislation (in particular Law 4308/2014 on Greek Accounting Standards and the Code of Tax Procedure) — generally at least five (5) years.
- Marketing data: until you unsubscribe or withdraw consent, after which we retain a suppression record to honour your choice.
- Recruitment data: [e.g. up to 6–12 months] after the process concludes, unless you agree to longer retention.
12. Data security
We implement appropriate technical and organisational measures to protect personal data against unauthorised or unlawful processing and against accidental loss, destruction or damage, including encryption in transit (TLS), access controls, the principle of least privilege, logging, and regular review of our security practices. No transmission over the internet can be guaranteed to be completely secure; we cannot guarantee absolute security but we take these risks seriously.
13. Children
The Website and the Services are directed at businesses and professionals and are not intended for children. We do not knowingly collect personal data from children below the age of digital consent under Greek law (currently 15 years). If you believe a child has provided us with personal data, please contact us and we will delete it.
14. Third-party websites
Our Website may link to external sites we do not operate. This Policy does not apply to those sites, and we are not responsible for their privacy practices. Please review their privacy notices.
15. Changes to this Policy
We may update this Privacy Policy from time to time. The current version, shown by the date above, applies. Where changes are material, we will take reasonable steps to bring them to your attention.
16. Contact
For any question about this Policy or your personal data, contact [PRIVACY EMAIL] or write to [LEGAL ENTITY NAME], [STREET ADDRESS], Thassos, [POSTCODE], Kavala, Greece.