- Home
- Privacy Policy
LEGAL
Privacy Policy
This policy explains what personal data ITSP collects through itsp.gr, on what legal basis, how long it is retained and which processors receive it. It also describes how to exercise your rights under Regulation 2016/679, the General Data Protection Regulation.
This text is a complete draft and must be reviewed by a lawyer before publication.
1. Data controller
The controller for data collected through itsp.gr is Ilias Tsaggalidis of Charalampos, a sole proprietorship trading under the name ITSP and the brand ITSP · Technical Solutions & Automation. The controller is a natural person, as the business is not incorporated as a company.
- Registered name
- Ilias Tsaggalidis of Charalampos
- Trade name
- ITSP
- Legal form
- Sole proprietorship
- Registered seat
- Aspropyrgos, Attica, Greece
- General Commercial Registry (ΓΕΜΗ) No.
- 15670710900
- Registered address
- 3 Acharnon St., Aspropyrgos 193 00, Greece
- Telephone
- +30 210 598 9588
- hello@itsp.gr
For any matter concerning your personal data, contact hello@itsp.gr or +30 210 598 9588.
There is no obligation to appoint a Data Protection Officer, as the conditions of Article 37 of the Regulation are not met.
2. What we collect
From the contact form: first name, last name, phone, email, company name and your message.
From the site survey request form: additionally your sector, approximate headcount, site location, the requirement you describe and how urgent it is.
Submission metadata: the page the submission came from and the service category it belongs to, so we know what the request concerns and can reply with the right engineer. We also record the IP address the submission came from, the browser and operating system of your device, and the country derived from the IP. The legal basis is our legitimate interest (Article 6(1)(f)) in protecting the forms against automated and abusive submissions and in documenting the request we received.
Campaign attribution data: if you reached the site from an advertisement or
a tagged link, we record the campaign parameters in the URL (utm_source,
utm_medium, utm_campaign, utm_term, utm_content and click identifiers
such as gclid), the page you landed on and the referring site. These are
stored in a cookie of ours for 90 days and accompany any request you submit, so
we know which activity brought us into contact. They are not transmitted to
advertising platforms and are not used to build an advertising profile. See the
Cookie Policy.
Browsing data: only where you have consented to analytics or marketing cookies. See the Cookie Policy.
We do not ask for and do not wish to receive special categories of data (health, biometric, political opinions and the rest of Article 9). Please do not include them in the free text of your message.
3. Purpose and legal basis
| Purpose | Legal basis |
|---|---|
| Answering your enquiry and preparing a quotation | Article 6(1)(b): steps prior to entering a contract |
| Performing a services and support contract | Article 6(1)(b): performance of a contract |
| Preventing automated abuse of the forms | Article 6(1)(f): legitimate interests |
| Meeting tax and accounting obligations | Article 6(1)(c): legal obligation |
| Usage statistics and advertising | Article 6(1)(a): consent |
Submitting the forms is optional. Without the required fields we cannot contact you, but you can always call instead.
4. Retention
- Enquiries that did not lead to an engagement: 12 months from the last contact.
- Client data under an active contract: for the duration of the contract.
- Invoices and accounting records: for as long as tax legislation requires.
- Abuse prevention records (anti-spam): up to 30 days.
After those periods the data is deleted or anonymised.
5. Recipients and processors
We do not sell or rent personal data. Data is shared only with providers necessary for running the site and our communications:
| Recipient | Role |
|---|---|
| Vercel | Hosting the site and running its serverless functions |
| Microsoft | Sending and archiving the emails generated by the forms (Microsoft 365) |
| Cloudflare | Protecting the forms against automated submissions |
| Usage statistics, only after consent | |
| Microsoft | Interaction recording (Clarity), on legitimate interests |
Some of these providers may process data outside the European Economic Area. In those cases the transfer relies on Standard Contractual Clauses or on an adequacy decision of the European Commission.
Data may also be disclosed to public authorities where there is a legal obligation to do so.
6. Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
To exercise your rights, write to hello@itsp.gr. We respond within one month of receiving the request.
If you believe the processing infringes the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).
7. Security
We apply the same technical and organisational measures we recommend to our clients: encrypted transport, role based access control, multi-factor authentication on administrative accounts, and regular backups.
8. Automated decision making
We do not take decisions concerning you based solely on automated processing, and we do not carry out profiling.
9. Changes to this policy
This policy is updated when our services or providers change. The date of the last update appears at the top of the page.