Skip to content

LEGAL

Privacy Policy

This policy explains what personal data ITSP collects through itsp.gr, on what legal basis, how long it is retained and which processors receive it. It also describes how to exercise your rights under Regulation 2016/679, the General Data Protection Regulation.

This text is a complete draft and must be reviewed by a lawyer before publication.

1. Data controller

The controller for data collected through itsp.gr is Ilias Tsaggalidis of Charalampos, a sole proprietorship trading under the name ITSP and the brand ITSP · Technical Solutions & Automation. The controller is a natural person, as the business is not incorporated as a company.

Registered name
Ilias Tsaggalidis of Charalampos
Trade name
ITSP
Legal form
Sole proprietorship
Registered seat
Aspropyrgos, Attica, Greece
General Commercial Registry (ΓΕΜΗ) No.
15670710900
Registered address
3 Acharnon St., Aspropyrgos 193 00, Greece

For any matter concerning your personal data, contact hello@itsp.gr or +30 210 598 9588.

There is no obligation to appoint a Data Protection Officer, as the conditions of Article 37 of the Regulation are not met.

2. What we collect

From the contact form: first name, last name, phone, email, company name and your message.

From the site survey request form: additionally your sector, approximate headcount, site location, the requirement you describe and how urgent it is.

Submission metadata: the page the submission came from and the service category it belongs to, so we know what the request concerns and can reply with the right engineer. We also record the IP address the submission came from, the browser and operating system of your device, and the country derived from the IP. The legal basis is our legitimate interest (Article 6(1)(f)) in protecting the forms against automated and abusive submissions and in documenting the request we received.

Campaign attribution data: if you reached the site from an advertisement or a tagged link, we record the campaign parameters in the URL (utm_source, utm_medium, utm_campaign, utm_term, utm_content and click identifiers such as gclid), the page you landed on and the referring site. These are stored in a cookie of ours for 90 days and accompany any request you submit, so we know which activity brought us into contact. They are not transmitted to advertising platforms and are not used to build an advertising profile. See the Cookie Policy.

Browsing data: only where you have consented to analytics or marketing cookies. See the Cookie Policy.

We do not ask for and do not wish to receive special categories of data (health, biometric, political opinions and the rest of Article 9). Please do not include them in the free text of your message.

PurposeLegal basis
Answering your enquiry and preparing a quotationArticle 6(1)(b): steps prior to entering a contract
Performing a services and support contractArticle 6(1)(b): performance of a contract
Preventing automated abuse of the formsArticle 6(1)(f): legitimate interests
Meeting tax and accounting obligationsArticle 6(1)(c): legal obligation
Usage statistics and advertisingArticle 6(1)(a): consent

Submitting the forms is optional. Without the required fields we cannot contact you, but you can always call instead.

4. Retention

  • Enquiries that did not lead to an engagement: 12 months from the last contact.
  • Client data under an active contract: for the duration of the contract.
  • Invoices and accounting records: for as long as tax legislation requires.
  • Abuse prevention records (anti-spam): up to 30 days.

After those periods the data is deleted or anonymised.

5. Recipients and processors

We do not sell or rent personal data. Data is shared only with providers necessary for running the site and our communications:

RecipientRole
VercelHosting the site and running its serverless functions
MicrosoftSending and archiving the emails generated by the forms (Microsoft 365)
CloudflareProtecting the forms against automated submissions
GoogleUsage statistics, only after consent
MicrosoftInteraction recording (Clarity), on legitimate interests

Some of these providers may process data outside the European Economic Area. In those cases the transfer relies on Standard Contractual Clauses or on an adequacy decision of the European Commission.

Data may also be disclosed to public authorities where there is a legal obligation to do so.

6. Your rights

You have the right of access, rectification, erasure, restriction of processing and data portability, as well as the right to object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.

To exercise your rights, write to hello@itsp.gr. We respond within one month of receiving the request.

If you believe the processing infringes the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).

7. Security

We apply the same technical and organisational measures we recommend to our clients: encrypted transport, role based access control, multi-factor authentication on administrative accounts, and regular backups.

8. Automated decision making

We do not take decisions concerning you based solely on automated processing, and we do not carry out profiling.

9. Changes to this policy

This policy is updated when our services or providers change. The date of the last update appears at the top of the page.