LEGAL

Privacy Policy

How we collect, use and protect personal data on orismos.gr, in line with the GDPR and Greek law.

Last updated: 2026-07-29

01Data controller

ORISMOS IT — Digital Technologies & Productions
24 Vryantos St., Athens 11364, Greece
Phone: +30 211 4067385 · Email: info@orismos.gr

This policy explains how we collect, use and protect your personal data when you visit orismos.gr or contact us, in line with Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.

02What data we collect

  • Contact form data: name, email, phone, company (optional), project type and your message.
  • Email or phone communications: whatever you choose to send us.
  • Technical data: IP address, device and browser type, pages visited — via cookies and analytics tools, only where you have consented.
  • Client data: billing and contact details needed to perform our contract.

03Purposes & legal bases

  • Responding to enquiries — Art. 6(1)(b) GDPR (pre-contractual steps) or 6(1)(f) (legitimate interest).
  • Delivering services & invoicing — Art. 6(1)(b) and 6(1)(c) (legal obligation, tax law).
  • Analytics & site improvement — Art. 6(1)(a) (consent via the cookie banner).
  • Marketing / newsletter — Art. 6(1)(a) (consent), withdrawable at any time.
  • Site security — Art. 6(1)(f) (legitimate interest in preventing abuse).

04Retention periods

  • Enquiries that do not lead to a project: up to 12 months.
  • Client & project data: for the duration of the engagement plus 5 years.
  • Invoices & accounting records: as long as Greek tax law requires.
  • Cookie consent records: 12 months from the moment your choice is stored.

05Recipients & processors

We do not sell personal data. We share it only with providers necessary to run our business, each bound by a data processing agreement: website hosting & infrastructure, email provider, analytics tools, our accountants, and public authorities where the law requires it.

Where data is transferred outside the EEA, this happens under an adequacy decision or the European Commission's Standard Contractual Clauses.

06Security

The site is served over HTTPS only. Access to the content management system requires an account with a password and is limited to authorised team members. We apply access controls, regular updates and backups. No transmission method is perfectly secure, so we maintain an incident response process and will notify the Hellenic Data Protection Authority within 72 hours where required.

07Your rights

You have the right of access, rectification, erasure, restriction, portability and objection, and you may withdraw consent at any time. Details on the GDPR & Your Rights page. You may also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).

08Changes to this policy

We may update this policy. The last-updated date appears at the top of the page and material changes will be highlighted on the site.

Questions about your data?

Email us and we'll respond within one month at the latest, as the GDPR requires.

info@orismos.gr →