Privacy Policy
Last updated: 8 October 2026
This Privacy Policy explains what personal data we collect when you visit smartupweb.com or contact us, why we collect it, how long we keep it, who we share it with and what rights you have. It is written in line with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and Greek Law 4624/2019.
1. Who we are
The data controller is:
SMARTUP ΥΠΗΡΕΣΙΕΣ ΤΩΝ ΤΕΧΝΟΛΟΓΙΩΝ ΚΑΙ ΤΗΣ ΠΛΗΡΟΦΟΡΙΑΣ Ι.Κ.Ε. (trading as “Smartup”)
Komninon 45, 56224 Evosmos, Thessaloniki, Greece
VAT: EL800451427 · GEMI: 123305106000
Email: [email protected] · Phone: +30 2310 52 62 79
For any question about your personal data, write to [email protected].
2. What data we collect and why
When you contact us or ask for a proposal
Through our contact form and project inquiry form we collect your name, email address, phone number (optional), company name (optional), the subject and content of your message, and the project details you choose to share, such as the type of project, the services you are interested in and an indicative budget.
Purpose: to reply to you, discuss your project and prepare a proposal.
Legal basis: steps taken at your request before entering into a contract (Art. 6(1)(b) GDPR) and, for general questions, our legitimate interest in answering the people who contact us (Art. 6(1)(f) GDPR).
The fields marked as required are needed for us to reply. You are not obliged to give us any other information.
When we work together
If you become a client, we process the contact and billing details of you and your team, and the communication and files we exchange during the project.
Purpose: to deliver our services, invoice and support you.
Legal basis: performance of our contract (Art. 6(1)(b) GDPR) and compliance with our tax and accounting obligations (Art. 6(1)(c) GDPR).
When you browse the website
Like every website, our servers automatically record technical data for each request: IP address, date and time, the page requested, browser and device type, and the referring page. Our security provider also checks forms for spam and abuse.
Purpose: to deliver the website, keep it secure, and protect our forms from spam and attacks.
Legal basis: our legitimate interest in running a secure website (Art. 6(1)(f) GDPR).
Cookies
We use only the cookies needed for the website to work, unless you accept more. Any analytics or marketing cookies load only after you give your consent (Art. 6(1)(a) GDPR), and you can withdraw that consent at any time. Details are in our Cookie Policy, and you can change your choice from the “Cookies” link at the bottom of every page.
Fonts and social media
The website’s fonts are served from our own server, so your browser does not contact Google Fonts. Our links to LinkedIn, Instagram, Facebook, X and YouTube are plain links: nothing is loaded from those networks until you click one, and from then on their own privacy policies apply.
3. Who receives your data
We do not sell or rent your personal data. We share it only with providers that help us run the website and our communication, and only as far as they need it to do their work for us:
Bluehost (Newfold Digital Inc., USA): website hosting.
Cloudflare, Inc. (USA): content delivery network, website security and spam protection for our forms (Cloudflare Turnstile).
Google Ireland Ltd / Google LLC (Google Workspace): our business email, through which form submissions reach us and we reply.
Our accountant, for invoices and tax filings, if you become a client.
We may also disclose data to public authorities when the law requires it.
4. Transfers outside the EU
Some of the providers above are based in the United States or may process data there. These transfers are covered by the EU–US Data Privacy Framework, where the provider is certified under it, or by the European Commission’s Standard Contractual Clauses.
5. How long we keep your data
Inquiries that do not lead to a collaboration: up to 2 years after our last communication, in case you come back to the same project. After that, we delete them.
Client data: for as long as we work together, and after that for as long as Greek tax and commercial law requires (usually 5 years from the end of the relevant tax year, and longer in specific cases).
Server and security logs: for a short period, normally a few weeks, unless they are needed to investigate a security incident.
Cookie preferences: 12 months, as described in the Cookie Policy.
6. Your rights
You have the right to:
ask for a copy of the personal data we hold about you (access);
ask us to correct inaccurate data (rectification);
ask us to delete your data (erasure);
ask us to limit how we use your data (restriction);
receive the data you gave us in a common, machine-readable format (portability);
object to processing that is based on our legitimate interest;
withdraw your consent at any time, without affecting processing that took place before.
To exercise any of these rights, email [email protected]. We will reply within one month. We may ask you to confirm your identity first.
If you believe we have not handled your data properly, you can lodge a complaint with the Hellenic Data Protection Authority (Kifisias 1-3, 115 23 Athens, www.dpa.gr).
7. Security
The website is served only over an encrypted connection (HTTPS). Access to our systems and mailboxes is limited to the people who need it and is protected with strong passwords and two-step verification.
8. Automated decisions
We do not make decisions about you based solely on automated processing, and we do not use your data for profiling.
9. Children
Our website and services are aimed at businesses and are not intended for children under 15. We do not knowingly collect their personal data.
10. Changes to this policy
We may update this policy when our website or the law changes. The date at the top shows when it was last updated.