Data protection
Privacy & GDPR
What we collect, why, how long we keep it, and how to make us stop.
This policy is a complete, ready-to-review draft. Before publication it must be checked against your actual hosting, email and analytics setup, and the retention periods confirmed. [TO CONFIRM: controller contact, hosting provider, analytics, retention periods, DPO if appointed]
Who is responsible
The controller of personal data is ΠΡΟΗΓΜΕΝΕΣ ΥΠΗΡΕΣΙΕΣ ΔΙΚΤΥΩΣΗΣ Ο.Ε. (brand: Polymathia), VAT EL801476978, ΑΡ.ΓΕΜΗ 157642159000, Chios, Greece. For any question about this policy or your data, write to [TO CONFIRM: privacy contact email].
What we collect
When you use the contact form. Your name, email address, organisation, country, role, the course or service you ask about, participant numbers, preferred period and the content of your message. We collect this because you sent it to us, and we use it only to answer you.
When you book a course or mobility. The information needed to run and certify the mobility: participant names and contact details, institution, dietary or accessibility requirements you choose to tell us, attendance records, evaluation responses and certificate data.
When you visit the site. Our web server keeps standard access logs (IP address, page requested, timestamp, browser identification) for security and troubleshooting. [TO CONFIRM: whether analytics is enabled; if so, name the provider and whether it uses cookies.]
Cookies. This site sets a session cookie only when it is technically necessary — for example while a form is being submitted. It does not use advertising or cross-site tracking cookies. [TO CONFIRM after analytics decision.]
Legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Answering your enquiry | Legitimate interest / steps prior to a contract, Art. 6(1)(f) and (b) |
| Delivering and certifying a course or mobility | Performance of a contract, Art. 6(1)(b) |
| Accounting and tax records | Legal obligation, Art. 6(1)(c) |
| Sending you the course calendar | Consent, Art. 6(1)(a) — withdrawable at any time |
| Server security logs | Legitimate interest, Art. 6(1)(f) |
Special categories of data (for example a health condition affecting participation) are processed only where you provide them explicitly and only to make the mobility work, under Art. 9(2)(a).
Who else sees your data
- Our email and hosting providers, as processors under Art. 28 contracts. [TO CONFIRM: names]
- Your sending organisation and, where a grant requires it, the relevant National Agency — for attendance and certification evidence.
- The National Europass Centre, where Europass Mobility documentation is issued.
- Tax authorities and our accountant, for invoices.
We do not sell personal data and we do not use it for advertising. Where a processor is outside the EEA, transfers are covered by an adequacy decision or standard contractual clauses. [TO CONFIRM]
How long we keep it
| Data | Retention |
|---|---|
| Unsuccessful enquiries | 24 months from last contact [TO CONFIRM] |
| Course participant records and attendance | 5 years after the mobility, for audit purposes [TO CONFIRM against grant conditions] |
| Certificate registry (name, course, dates, certificate number) | 10 years, so that certificates remain verifiable [TO CONFIRM] |
| Invoices and accounting records | As required by Greek tax law |
| Server logs | 12 months [TO CONFIRM] |
| Calendar mailing list | Until you unsubscribe |
Your rights
You have the right to access your data, to correct it, to have it erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out. Write to [TO CONFIRM: privacy contact email]; we answer within one month.
If you believe we have handled your data unlawfully you may complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr), or to the supervisory authority in your own country.
Security
Data is transmitted over TLS, access is limited to the people who need it, and enquiry records are stored on systems controlled by us. In the event of a personal data breach affecting your rights we will notify the supervisory authority within 72 hours and inform you where the law requires it.
Changes
If this policy changes we will publish the new version here with an updated date. Last updated: [TO CONFIRM: publication date].
Planning a mobility?
Tell us your dates, group size and priorities. You get a proposal, a draft programme and the documents your application needs.