Privacy Policy
Effective date: 19 September 2026 · Version: 2.1
This Policy is drafted in English and in Greek. In case of divergence the Greek version prevails.
1. Who we are and how to reach us
DOMICODE P.C. (DOMICODE Ι.Κ.Ε.), General Commercial Registry (Γ.Ε.ΜΗ.) no. 193576701000, registered office 75 Thessalonikis Street, 183 45 Moschato, Attica, Greece ("Domicode", "we", "us"), is the controller for the processing described in this Policy, except where section 2 says otherwise. Contact for every privacy matter, including requests to exercise your rights: hello@domicode.gr, or by post to the registered office. We have not appointed a data protection officer because the nature and scale of our processing do not require one (Regulation (EU) 2016/679, "GDPR", Article 37).
2. Scope and our two roles
This Policy covers the websites domicode.gr and app.domicode.gr and the Domicode service (together, the "Service"). It applies to visitors, account holders, members of customer workspaces and people who contact us.
We act in two roles:
- Controller for the personal data of the people who use or enquire about the Service: account and identity data, usage data, communications, billing data, and the information described in sections 3 to 5.
- Processor for personal data contained in the documents, drawings and questions our customers submit (for example the names of property owners on a topographic survey or a permit). For that data the customer is the controller, we act only on the customer's instructions, and our Data Processing Agreement applies (Terms of Service, clause 9). If you are a third party whose data appears in a customer's documents, please address the customer that submitted them; we will assist the customer in responding.
3. The data we process
Account and identity. Name, professional email address, organisation and role, sign-in identifiers, session data and, if you sign in through a third-party identity provider such as a Google account, the identity information that provider shares with us. Passwords, where used, are never stored in readable form.
Content you submit. Questions, instructions, uploaded documents and files, the text we extract from them, their version history, and the outputs the Service generates. Please do not submit personal data that is not necessary for your question or task.
Conversations. Your full conversation history with the Service, the sources retrieved for each answer, and the internal analysis produced for each turn.
Project memory. The Service records facts about a project or workspace from your interactions (for example the parcel, the works, the decisions discussed and your preferences) so that later conversations in the same project have context. These records are visible in the project, editable, and deleted with the project.
Locations. Property addresses and coordinates you enter or select, and the parcel identifiers (ΚΑΕΚ) you look up.
Usage and technical data. Query counts, features used, response times, error events, IP address, device and browser information, and log records with timestamps.
Billing and plan data. Plan, credit balance, invoices and payment records. Payment card details are handled by our payment provider and never reach our systems.
Communications. Emails, support requests, messages sent through the booking form or the founders' chat on domicode.gr (name, firm, email, telephone if you give it, specialty, firm size and your message), and feedback you give in the Service.
Data we do not collect. We do not collect special categories of data on purpose and we ask you not to submit them. We do not collect data from minors; the Service is for professional use by adults.
4. Why we process it and on what legal basis
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Creating and administering accounts and workspaces, providing the Service, generating outputs, keeping project memory | Performance of a contract, Art. 6(1)(b) |
| Securing the Service, preventing abuse, enforcing usage limits, keeping logs | Legitimate interests, Art. 6(1)(f): keeping the Service safe and available |
| Reviewing conversation records for quality, safety and support (section 5) | Legitimate interests, Art. 6(1)(f): making the Service accurate and reliable; you may object |
| Creating de-identified content and aggregated statistics to develop, evaluate and improve the Service (section 5) | Legitimate interests, Art. 6(1)(f), with the safeguards in section 5; you may object |
| Answering enquiries and booking requests, providing support | Steps before a contract and performance of a contract, Art. 6(1)(b), or legitimate interests |
| Invoicing, accounting, tax and commercial record-keeping | Legal obligation, Art. 6(1)(c) |
| Telling existing customers about our own related services, with an opt-out in every message | Legitimate interests, Art. 6(1)(f) |
| Newsletters or marketing to anyone else, where offered | Consent, Art. 6(1)(a), withdrawable at any time |
| Measuring traffic on domicode.gr with Google Analytics, only where you have accepted it | Consent, Art. 6(1)(a) and Law 3471/2006, Art. 4(5), withdrawable at any time |
| Establishing, exercising or defending legal claims | Legitimate interests, Art. 6(1)(f) |
Where we rely on legitimate interests we have assessed that our interests are not overridden by yours; you can ask us for a summary of that assessment.
5. How artificial intelligence and your content are used
Generating outputs. To answer your questions and draft documents, the Service sends the relevant content (your question, the conversation, the documents involved and the retrieved regulatory text) to artificial-intelligence providers that act as our processors. They return the output to us; they act only on our instructions under contract.
No training on identifiable content. We do not use your content or outputs in identifiable form to train, fine-tune or evaluate machine-learning models, and we have configured and contractually restricted our AI providers so that content submitted through the Service is not used to train their models.
De-identified content. We may create de-identified content and aggregated statistics from content, outputs and feedback, and use them to develop, evaluate and improve our retrieval systems, models and features. De-identification removes personal data and customer identifiers, generalises parcel identifiers to municipality level and discards fields that cannot be reliably cleaned, so that neither a person nor the customer can reasonably be identified. You may object at any time by writing to hello@domicode.gr, and customers on the Private Plan are excluded entirely.
Quality review. Records of conversations, including outputs, are stored with a tracing provider in the EU and may be reviewed by a small number of authorised members of our team to check the quality and safety of answers, to investigate errors you report, and to provide support. Access is limited to named team members bound by confidentiality.
No automated decisions. The Service retrieves and presents regulatory information and drafts documents to assist professional users. We do not make automated decisions that produce legal or similarly significant effects on you (GDPR Article 22). Every decision based on the Service's outputs remains with the professional using it.
6. Who receives your data
We do not sell personal data. We share it only with:
Processors acting on our instructions, by category and location:
| Category | What they receive | Where |
|---|---|---|
| Application database | Account, workspace, project, conversation, document, memory, location and billing records | Frankfurt, Germany (EU) |
| Vector search index | Text chunks of your documents and their embeddings | Sweden (EU) |
| File storage | Uploaded files in their original form | The provider's Eastern Europe region |
| Authentication and user management | Name, email, sign-in identifiers, sessions, third-party sign-in identity | United States |
| Artificial-intelligence inference (a broker routing to model providers) | Question text, conversation history, document content, drafting instructions | United States, with onward routing to model providers in the United States and other countries |
| Conversation tracing and quality review | Full conversation content including outputs | Frankfurt, Germany (EU) |
| Mapping and geocoding | Property addresses you enter | Global (primary provider); Germany (fallback provider) |
| Application hosting | All data in transit through the application | United States company; regions depend on the service (section 7) |
| Secrets management | No customer data; holds the credentials that protect it | United States company; regions depend on the service (section 7) |
| Email delivery (website forms and notifications) | Your name, email and message | United States company; regions depend on the service (section 7) |
| Website analytics, only after you accept it (section 11) | Truncated IP address, device and browser, and the pages you view on domicode.gr | United States company; the provider's own regions |
| Payments and subscription billing | Billing identifiers and payment records | United States and EU (the provider's own regions) |
Each processor is bound by a data processing agreement. A current list of our sub-processors with their legal names is available on request at hello@domicode.gr, and forms part of the Data Processing Agreement for business customers.
Professional advisers (legal, accounting, audit) where necessary, and public authorities where disclosure is required by law or to establish, exercise or defend legal claims.
Members of your workspace see the projects, files and conversations shared with them by your workspace administrator.
7. Transfers outside the EEA
Our application database, vector index and conversation-quality records are in the European Union. Some of our processors process data in the United States: our authentication provider, our artificial-intelligence broker (which routes requests onward to model providers in the United States and other countries; we do not currently restrict that routing to a region) and our mapping provider. Our payment, hosting, secrets and email providers are US companies whose processing location depends on the service. Where you accept website analytics, Google Ireland Limited processes the data for us and may transfer it to Google LLC in the United States.
For every transfer outside the EEA we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), supplemented by encryption in transit and at rest and by contractual restrictions on the recipient's own use of the data, or on an adequacy decision where one applies (including the EU-US Data Privacy Framework for certified recipients). You may ask us for a copy of the safeguards in place for a given provider.
8. How long we keep it
| Data | Retention |
|---|---|
| Account and identity data | For the life of the account, then deleted within 12 months of closure |
| Content, conversations, outputs, project memory | Under your control: kept until you delete them or the project, or until the account is closed; accounts inactive for 24 months are notified and then deleted |
| De-identified content and aggregated statistics (Variant A only) | Kept indefinitely; they no longer identify you |
| Conversation records held for quality review | For as long as needed for quality review and support, and no longer than the conversation itself is kept |
| Usage and technical logs | Up to 12 months |
| Communications and support requests, booking-form and chat messages | Up to 24 months |
| Invoices, payment and tax records | For the period required by Greek tax and commercial law (at least five years) |
Backups. The application database is protected by continuous point-in-time recovery, stored encrypted in the same EU region. Data you delete is removed from live systems on request and expires from the recovery history within the provider's rolling recovery window; it cannot be removed from the recovery history earlier. Uploaded files are stored in encrypted object storage without a separate backup copy we control; keep your own copies of original documents.
After these periods, data is deleted or irreversibly anonymised.
9. Security
We apply technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, direct browser-to-storage uploads with short-lived credentials, access scoped to your workspace on every request, restriction of production access to a small number of named administrators, and separation of customer content from our team's day-to-day tools. Our Data Security page at domicode.gr/security describes these measures, and their current limits, in detail. No system is completely secure, and we cannot guarantee absolute security. If a personal data breach is likely to result in a high risk to you, we will inform you without undue delay, and we notify the supervisory authority within 72 hours where required (GDPR Articles 33 and 34).
Our Data Processing Agreement is available on request at hello@domicode.gr.
10. Your rights
You have the right to access your personal data, to have it rectified or erased, to restrict its processing, to receive it in a structured, commonly used, machine-readable format and to have it transmitted to another controller (portability), and to object to processing based on legitimate interests, including the quality review and de-identification described in section 5. Where processing is based on consent, you may withdraw it at any time without affecting processing before withdrawal.
To exercise any right, email hello@domicode.gr from the address linked to your account, or write to our registered office. We respond within one month; for complex or numerous requests we may extend by up to two further months and will tell you why. Requests are handled by our team; we may ask you to confirm your identity. Export of your content is provided in a machine-readable format as described in the Terms of Service, clause 13.3.
You have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr, or with the supervisory authority of your habitual residence or place of work.
11. Cookies and local storage
The website domicode.gr sets no cookie of its own. It stores two values in your browser's local storage: your language choice and, once you answer the bar at the foot of the page, your answer about analytics. Neither value leaves your browser.
We use Google Analytics 4 to count visits and to see which pages are read. It is not necessary for the website to work, so under Law 3471/2006, Article 4(5) it runs only with your consent. Until you accept, no Analytics script is loaded, no Analytics cookie is written and no request reaches Google. If you accept, Google Analytics sets its own cookies in your browser, named _ga and ga followed by the property identifier and expiring after two years, and processes your truncated IP address, your device and browser and the pages you view, acting as our processor. We have switched off Google signals, advertising features and ad personalisation, so the data is not used to build advertising profiles or to follow you across other websites, and we do not link it to any account you hold with us.
You can give or withdraw your consent at any time through the Analytics and cookies link in the footer of every page. Withdrawing takes effect at once: measurement stops and the Analytics cookies are deleted from your browser. Refusing costs you nothing, because the website works in exactly the same way either way.
The application app.domicode.gr uses only strictly necessary cookies and similar technologies: session and authentication cookies, security cookies and basic preference settings. These are exempt from consent under Law 3471/2006, Article 4(5). We do not use advertising or cross-site tracking cookies. If we introduce any further tool that requires consent, we will ask for it first and update this Policy.
12. Children
The Service is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors; if you believe a minor has provided us with data, contact us and we will delete it.
13. Changes to this Policy
We will post changes on this page and update the effective date at the top. For material changes we will notify account holders in the Service or by email before they take effect. Previous versions are available on request.
14. Contact
DOMICODE P.C., 75 Thessalonikis Street, 183 45 Moschato, Attica, Greece · hello@domicode.gr