Πολιτική ΑπορρήτουPrivacy Policy
Ημερομηνία ισχύοςEffective date: [ΗΜΕΡΟΜΗΝΙΑ][DATE]
1. Who we are
DOMICODE P.C. (DOMICODE Ι.Κ.Ε.), a private company registered in Greece under General Commercial Registry (Γ.Ε.ΜΗ.) number 193576701000, with registered office at 75 Thessalonikis Street, 183 45 Moschato, Athens, Greece ("Domicode", "we", "us"), is the controller of the personal data described in this policy.
Contact for all privacy matters: info@domicode.gr | +30 697 406 4348.
2. Scope
This policy covers the websites domicode.gr and app.domicode.gr and the Domicode regulatory intelligence service (together, the "Service"). It applies to visitors, account holders and people who contact us.
3. Data we collect
Account data. Name, professional email address, organisation, professional role, and authentication credentials (passwords are stored only in hashed form).
Queries and content. Questions you submit to the Service, documents you upload for review, the responses generated, and any feedback you provide. Please do not include personal data in queries or documents unless it is necessary; in particular, avoid submitting personal data of third parties that is not needed for your question.
Technical data. IP address, device and browser information, log records and timestamps generated when you use the Service.
Communications. Emails and support requests you send us.
Billing data. When paid subscriptions launch, invoicing details required by Greek tax law. Card details are handled by our payment provider and are not stored by us.
4. Purposes and legal bases
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing and operating the Service, including generating responses to your queries | Performance of a contract, Art. 6(1)(b) |
| Securing the Service, preventing abuse, enforcing usage limits | Legitimate interests, Art. 6(1)(f) |
| Improving the Service using aggregated, de-identified usage information | Legitimate interests, Art. 6(1)(f) |
| Responding to enquiries and providing support | Contract or legitimate interests |
| Invoicing, accounting and tax compliance | Legal obligation, Art. 6(1)(c) |
| Informing existing customers about our own services, with an opt-out in every message | Legitimate interests, Art. 6(1)(f) |
| Newsletters or marketing to non-customers, where offered | Consent, Art. 6(1)(a), withdrawable at any time |
5. Cookies
The Service uses only strictly necessary cookies: session and authentication cookies, security cookies, and basic preference cookies (such as language). We do not use advertising or cross-site tracking cookies. If we later introduce tools that require consent, we will ask for it first and update this policy.
6. Who receives your data
We do not sell personal data. We share it only with:
- Service providers acting on our instructions (processors), by category: cloud hosting and infrastructure; database and authentication services; large language model inference providers used to generate responses; email delivery; error monitoring and analytics; and, when subscriptions launch, payment processing. Each is bound by a data processing agreement. We contractually restrict our providers from using customer content for their own purposes, including training their own models. A current list of subprocessors is available on request at info@domicode.gr.
- Professional advisers (legal, accounting, audit) where necessary.
- Public authorities where disclosure is required by law.
7. International transfers
We host data in the EU/EEA wherever the relevant service makes that possible. Where a provider processes data outside the EEA, we rely on European Commission adequacy decisions or Standard Contractual Clauses together with appropriate supplementary measures.
8. Retention
| Data | Retention |
|---|---|
| Account data | Life of the account, then up to 12 months |
| Queries and uploaded documents | Up to 12 months from creation, or earlier on deletion request where feasible |
| Technical logs | Up to 12 months |
| Support communications | Up to 24 months |
| Invoices and tax records | As required by Greek tax and commercial law |
After these periods, data is deleted or irreversibly anonymised.
9. Your rights
Under the GDPR you may request access to your data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting prior processing. To exercise any right, email info@domicode.gr; we respond within one month.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1-3, 115 23 Athens, Greece, www.dpa.gr.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, tenant-level separation of customer data, and least-privilege access for our team. No system is completely secure, and we cannot guarantee absolute security.
11. Automated decision-making
The Service retrieves and presents regulatory information to assist professional users. We do not carry out automated decision-making that produces legal effects or similarly significant effects on you within the meaning of Art. 22 GDPR. Decisions based on information from the Service remain with the professional user.
12. Children
The Service is intended for professional use and is not directed at anyone under 18. We do not knowingly collect data from minors.
13. Changes to this policy
We will post any changes on this page and update the effective date. For material changes, we will notify account holders through the Service or by email.
14. Contact
DOMICODE P.C., 75 Thessalonikis Street, 183 45 Moschato, Athens, Greece
Email: info@domicode.gr | Tel.: +30 697 406 4348