Data protection
Privacy & GDPR
What we collect, why, how long we keep it, and how to make us stop.
Who is responsible
The controller is PROIGMENES YPIRESIES DIKTYOSIS O.E. (brand: Polymathia), VAT EL801476978, AR.GEMI 157642159000, Kanellou Styl. 1, 82132 Chios, Greece.
For any question about this policy or your data, write to info@polymathia.eu. We have not appointed a Data Protection Officer; we are not required to.
What we collect
When you use the contact form. Your name, email address, organisation, country, role, and anything you choose to write in the message - including an Erasmus+ project number and participant numbers if you give them.
When you take part in a course. Your name, contact details, sending organisation, the course and dates, your attendance record, and your travel details if you give them to us. Where you tell us about dietary requirements or accessibility needs, that is special-category data under Article 9 and we process it only with your explicit consent, only to make the mobility work safely, and we delete it shortly after the course ends.
When you visit the site. Our web server keeps standard access logs - IP address, page requested, timestamp, browser identification - for security and troubleshooting.
Analytics: none. This website runs no analytics, no tracking pixels and no advertising technology. We do not profile visitors and we do not build audiences.
Cookies. This site sets one cookie, a session cookie used by the site software to keep a page request coherent. It is set when you load a page, it expires after 30 minutes, and it is marked Secure, HttpOnly and SameSite=Lax. It carries no identifier we can trace back to you. There are no advertising cookies and no cross-site tracking cookies.
Fonts and other resources are served from our own server. No part of this website loads content from a third-party domain, so visiting it does not disclose your IP address to anyone but us and our hosting provider.
Legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Answering your enquiry | Legitimate interest - you contacted us |
| Organising and delivering a course you booked | Performance of a contract |
| Issuing certificates and keeping them verifiable | Legitimate interest, and the expectations of the Erasmus+ programme |
| Keeping invoices and accounting records | Legal obligation under Greek tax law |
| Security logs | Legitimate interest in keeping the service available |
| Dietary and accessibility needs | Explicit consent, Art. 9(2)(a) |
| Course calendar mailing list | Consent |
Who else sees your data
Our hosting and email provider. The website, the mailbox and the database run on shared hosting provided by StableServer, on servers in Frankfurt, Germany, acting as a processor under an Article 28 contract.
Your sending organisation, and where a grant requires it, the relevant National Agency - for the attendance and completion evidence the grant depends on.
No one else. We do not sell your data, we do not share it with advertisers, and we do not use it for advertising.
No transfers outside the EEA. All processing takes place within the European Economic Area.
How long we keep it
| Data | Retention |
|---|---|
| Unsuccessful enquiries | 24 months from last contact - roughly two Erasmus+ application cycles |
| Course participant records and attendance | 5 years after the mobility. Programme rules allow the grant to be checked for up to five years after final payment, and your school may need our attendance evidence to answer that check |
| Certificate registry (name, course, dates, certificate number) | 10 years, so that certificates stay verifiable for as long as a teacher may need to cite one |
| Travel details | 30 days after the course ends |
| Dietary and accessibility needs | 30 days after the course ends, then deleted automatically |
| Invoices and accounting records | As Greek tax law requires - at least five years from the end of the financial year, longer where the law extends the period |
| Server logs | 6 months |
| Course calendar mailing list | Until you unsubscribe |
Your rights
You have the right to access your data, to correct it, to have it deleted, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out.
Write to info@polymathia.eu; we answer within one month.
If you believe we have handled your data unlawfully, you can complain to the Hellenic Data Protection Authority, dpa.gr, or to the supervisory authority in your own country.
Security
Access to participant data is limited to the people who need it to run the course. The site is served over HTTPS. Documents and certificates are stored outside the public web directory. We keep backups, and we test that they restore.
If a breach occurs that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and inform you where the law requires it.
Changes
If this policy changes we will publish the new version here with an updated date.
Last updated: 30 July 2026.
Planning a mobility?
Tell us your dates, group size and priorities. You get a proposal, a draft programme and the documents your application needs.