Get in touch

Privacy Policy

Updated:

1. Who we are

The controller of the personal data processed through this website is ITHACA Information Technology Applications E.E. (GEMI No. 172610403000), Papanoutsou 5, 124 61 Chaidari, Attica, Greece. You can contact us about any privacy matter at [email protected].

2. Our approach

We collect and process personal data only when it is necessary. We do not sell, rent or otherwise disclose your personal data for marketing purposes.

3. Applicable legislation

This website and our internal IT systems are operated in accordance with Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019 and, for electronic communications, Greek Law 3471/2006.

4. What we process and why

Technical data and security. This website is delivered through Cloudflare, which provides hosting, content delivery and security protection. When you visit, technical data such as your IP address, browser type, device information, the pages requested and the time of the request is processed to deliver the site, protect it from abuse and keep it running. Legal basis: our legitimate interest in the secure and reliable operation of the website (Article 6(1)(f) GDPR).

Contacting us. When you use the contact form, the details you enter (full name, company, email, phone, topic and message) are sent to the HubSpot customer relationship management (CRM) system, which acts as a processor on our behalf, and we receive an email notification. We use them to respond to your request and to keep a record of the communication. Legal basis: your consent, given in the form, and taking steps at your request before entering into a contract. The details are kept for as long as needed to handle your request and for as long as the law requires or our legitimate interests justify (for example, for the duration of a business relationship). If you prefer to write to us directly by email, the message is processed by our email service (Microsoft 365) and protected in transit by TLS encryption where supported.

Newsletter. If you subscribe to our newsletter from the footer, your email address is sent to the HubSpot CRM, which acts as a processor on our behalf, together with the time and page of the subscription as proof of your consent. We use it only to send you the newsletter. Legal basis: your consent (Article 6(1)(a) GDPR), which you can withdraw at any time using the unsubscribe link in every message or by writing to [email protected]. After you unsubscribe, sending stops and we keep only what is needed so as not to email you again, and as proof of consent for as long as the law requires.

Free tools. Our free tools (the NIS2 eligibility check and the security readiness check) run entirely in your browser. The answers you give are not sent to our servers and we do not store them. In some tools (for example the calculators and the quiz) you can ask us to get in touch from the result itself. Only if you press "Contact me", the details you fill in on the form and a summary of the result are sent as described in the section on the contact form (HubSpot). What you entered in the calculator or quiz is not stored otherwise.

Domain security check. When you use the tool, we record the domain you check, the result, the time, the language and the country the request came from. We do not store your IP address: to limit abuse we temporarily use an irreversible value that changes every day and is deleted within two hours. The domain and the result are also recorded in HubSpot, from where we receive a notification. Purpose: providing the tool, security and abuse prevention, and understanding interest in our services. Legal basis: our legitimate interest. Retention: up to 12 months. DNS data and a website's public response are public information; the check does not access systems and does not include penetration testing.

5. Cookies and tracking tools

This website does not use advertising, profile-tracking tools, tracking cookies, embedded videos, social media plugins or newsletter sign-up forms, and it does not load fonts or scripts from third-party servers, with one exception: Cloudflare's statistics script (see below).

Traffic statistics. We use Cloudflare Web Analytics to understand how many visitors come and which pages they read. As Cloudflare states, the tool does not use cookies or localStorage and does not create a visitor fingerprint from the IP address or the browser; results are aggregated (page, country, device and browser type, referrer). Legal basis: our legitimate interest in improving the website. Cloudflare acts as a processor on our behalf.

The footer and the contact page contain links to our profiles on social networks. They are plain links: we do not load code or plug-ins from those networks and no data is passed to them while you stay on our website. If you click a link, you leave for the network's website, where its own terms and privacy policy apply.

We do not set cookies ourselves. Cloudflare may use strictly necessary technical cookies or similar technologies for security purposes, such as distinguishing legitimate visitors from automated traffic. These are essential for the secure operation of the site and do not require consent.

Display theme. If you change the website theme (dark or light), your choice is stored on your device, in the browser's local storage, only so that the website remembers it. It contains no personal data, is not sent to us or to third parties, and you can delete it from your browser settings.

If we introduce other tools or forms in the future, we will update this policy before they are used and, where required, ask for your consent.

6. Who we share data with

We use a limited number of service providers that process personal data on our behalf, namely Cloudflare (hosting, content delivery, security), Microsoft (email) and HubSpot (customer communication management). They act under data processing agreements and only on our instructions. Where data is transferred outside the European Economic Area, we rely on appropriate safeguards such as European Commission adequacy decisions or standard contractual clauses. We may also disclose data where the law requires it.

7. Your rights

Under the GDPR you have the right to:

  • access your data
  • have inaccurate data corrected
  • erasure
  • restriction of processing
  • data portability
  • object to processing based on legitimate interests
  • withdraw consent where it has been given

To exercise your rights, write to [email protected]. We will respond within one month, as the GDPR requires. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).

8. Security and data breaches

All traffic between this website and your browser is encrypted using HTTPS. We apply appropriate technical and organisational measures to protect personal data. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours of becoming aware of it and, where required, the persons affected.

9. Children

This website is aimed at businesses and is not directed at children. We do not knowingly collect personal data from children.

10. Changes to this policy

We may update this policy from time to time, for example when we change how this website works. The current version is always published on this page, together with the date of the last update.