Privacy Policy

This constitutes the Privacy Policy for the website “compatto.gr” which is operated by the company under the name “Compatto L.P.”, which as the Data Controller collects, stores, uses and generally processes personal data when you visit or use its website. The Company during the above procedures recognizes the importance of its obligation to comply with the General Data Protection Regulation 2016/679 (GDPR) (Regulation) and Law 4624/2019 to the extent that it is compatible with the GDPR but also with the relevant national and EU law. For this purpose, it has taken all necessary measures, including the drafting and citation of this Privacy Policy.

1. Controller

The company under the name “Compatto L.P.” and with distinctive title “Compatto” (hereinafter referred to as “the Company“) VAT 802413824, based in Athens, 71 Grammou Street, Maroussi PC 151 24, contact phone: +30 210 699 6846, email address: contact@compatto.gr, is responsible for the processing of personal data collected by the website “compatto.gr”.

2. What is personal data?

The term personal data refers to information of natural persons, such as their name, postal address, e-mail address, telephone number, etc., which identifies or can identify a specific natural person (“data subject”).

3. What is the processing of Personal Data?

Any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction

4. What Personal Data we collect, for what purpose and on what legal basis?

During your visit, navigation and use of our website, the Company collects only your absolutely necessary Personal Data, which are appropriate and relevant for the intended purpose, and only when it has a specific legal basis for their processing as detailed below.

Purpose of processingData categoryTypes of dataLegal basis for processing
Booking of an appointmentContact informationName, surname, email address, project type, message information, guest email addressThe processing is based on the explicit consent of the subject (Article 6 par. 1 a’ GDPR), which is provided upon completion of the appointment booking process.
Reply to email messages sent to the email address contact@compatto.grContact informationEmail address and messages’ contentThe processing is based on the explicit consent of the subject (Article 6 (1) a’ GDPR), which is provided by sending an email.

In addition, cookies are used on the compatto.gr website, which collect your necessary personal data for its better operation, only with your consent, when required, and in accordance with the Cookies Policy, which is also published on our website. To learn more about our use of cookies, please read our Cookie Policy.

5. Recipients of Personal Data

During the fulfillment of the contractual and legal obligations of our company as well as in case the company has received your consent, recipients of the data may be only authorized employees of the company and third party partners, who through contracts with the company have committed to comply with this policy and mainly not to copy, making available, destroying and altering such data.

The recipients of your data, on a case-by-case basis, are external partners of the company who perform processing on our behalf in accordance with the legislation on personal data, are the companies that provide us with web hosting services (DNHost), email hosting (Google Workplace) and an email Νewsletter if you have subscribed (Mailchimp). Our website also uses cal.com, which is a platform that books the appointments with us. These companies that store your data, are under the appropriate regulatory obligation of confidentiality and their services are provided in a completely secure environment. In particular, regarding the Newsletter service, it collects your e-mail address and the content of the information material we sent to you. Your email address will be deleted when you unsubscribe. In all cases, your personal data is processed and transmitted in accordance with the requirements of the General Data Protection Regulation (GDPR).

6. Personal Data Retention Period

Your Personal Data is kept only for as long as it is required to fulfill the purpose for which you have communicated it to us, in accordance with the relevant legislation, unless an extension of this time is required due to our legal claims or legal obligations.

Purpose of processingData retention period
Booking of an appointmentAccording to Cal.com ‘s privacy policy, data related to people who booked a call is stored for as long as necessary to fulfill the purpose of the booking. This includes maintaining records for service provisions, legal obligations, and resolving disputes. Specific retention periods may vary depending on the nature of the booking, but users can request data deletion under GDPR.

https://cal.com/privacy
Reply to email messages sent to the email address contact@compatto.gr 1 year from contact, if no service contract has been concluded.

7. Personal data from children

Our services through the website and our website itself are not directed to underage children. Our company does not knowingly collect information or personal data from children. If we become aware that we are processing information of a child under the age of 18 without the valid consent of a parent or guardian, we will delete the relevant data

8. Personal Data Security

To protect your Personal Data, the Company has taken the necessary technical and organizational measures to prevent the risk of loss, misuse, unauthorized access and disclosure of your personal information.

9. What are your rights?

According to the General Data Protection Regulation you have the right to submit the following requests:

A. Request for information (Article 15 GDPR): Based on this request, specific information is provided on whether the Company processes your personal data, the type of data, the purpose and reason (legal basis) for which it processes them, the details of third parties to whom their data is disclosed as well as the criteria that determine the period that these data are retained.

B. Request for correction (Article 16 GDPR): Based on this request, certain erroneous or (and) missing personal data concerning you, are corrected.

C. Request for erasure (Article 17 GDPR): Based on this request, your personal data which are not necessary are deleted. This subject to data retention to the extent required by applicable law.

D. Request for access (Article 20 (1) GDPR): Based on this request, you can see or view the personal data that are being processed, as well as request copies of the personal data.

E. Request for transfer (Article 20 (2) GDPR): Based on this request, personal data that the Company has at its disposal are transferred to third parties in accordance with your will, in a form in which processing is possible for the purpose for which the transmission was made.

F. Request for restriction of processing (Article 18 GDPR): Based on this request, the personal data collected or the processing to which they are submitted are restricted when they do not comply with the principles of lawfulness of processing and data minimization as imposed by the GDPR.

10. When do we respond to your requests?

The Company always responds to your requests free of charge without delay, and in any case within (1) one month after receiving your request. However, if your request is complex or there is a large number of your requests, it will inform you within the month if it needs to receive an extension of another (2) two months within which it will respond to you. If your requests are manifestly unfounded or excessive, in particular due to their repetitive nature, the Company may impose a reasonable fee, taking into account the administrative costs of providing the information or performing the requested action or refuse to respond to the request justifying the response to you.

If you do not receive a reply within the above deadline or the answer you received was not satisfactory or your issue has not been resolved, you may contact the Personal Data Protection Authority (“www.dpa.gr”).

11. Amendments to this Policy

We may, if appropriate, make certain modifications to the information contained in this Privacy Policy. In this case, we will notify you by any appropriate means so that you become aware of the relevant information, check the changes, evaluate them and in case you disagree and receive the services of the Center to withdraw your consent to the processing of your personal data. In any case, you are encouraged to check this Policy from time to time as there is a possibility that minor changes may be made or an interactive improvement may be incorporated.

12. Communication

For any clarification regarding our Privacy Policy regarding the management and processing of personal data or for any comment regarding the processing of your personal data but also for any advice or assistance regarding the submission and satisfaction of any of your requests, you are encouraged to contact us by email at info@compatto.gr

13. Supervisory Authority

The competent supervisory body for filing a complaint is the Hellenic Data Protection Authority (1-3 Kifissias Avenue, 11523, Athens, tel.: 210 6475600, fax: 210 6475628, email: contact@dpa.gr).
This Agreement entered into force on 10/10/2024