Privacy Policy
How Intellinet MSP EE handles personal data under the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019. Last updated: 14 May 2026.
1. Data controller
The data controller for this website and for our service engagements is:
Intellinet MSP EE
ΓΕΜΗ 189952203000 · ΑΦΜ 803117560
Athens, Greece
info@intellinet.gr · +30 215 215 6504
For any data-protection matter, write to info@intellinet.gr with the subject line "Data protection request". A certified Data Protection Officer credential (TÜV Austria Hellas) is held within the firm and acts as the contact point for these requests.
2. Scope of this policy
This policy describes how we handle personal data in two contexts:
- visitors to intellinet.gr and our public web properties;
- persons whose data we process while providing services to our clients, where we act as a processor on the client's behalf.
Where we act as a processor, the controller is our client, and our processing is governed by the data-processing agreement between us. This policy then describes our general processor obligations.
3. What personal data we collect
From website visitors:
- technical access data (IP address, browser type, request timestamp) processed in standard web server logs for security and abuse-prevention purposes;
- information you choose to submit when contacting us (name, email, phone number, message contents).
From clients and counterparties:
- business contact details of named representatives;
- billing and tax data required for invoicing and Greek myDATA reporting;
- technical identifiers (user accounts, email addresses, device identifiers) required to deliver the agreed service.
We do not solicit special categories of personal data (Article 9 GDPR). If you provide such data in correspondence, we will minimise our processing of it.
4. Lawful basis
- Performance of a contract (Art. 6(1)(b)) — to deliver services you or your organisation engage us for.
- Legal obligation (Art. 6(1)(c)) — tax, accounting, and statutory record-keeping under Greek law.
- Legitimate interests (Art. 6(1)(f)) — running and securing our website, responding to enquiries, recovering debts.
- Consent (Art. 6(1)(a)) — only where required (e.g. non-essential cookies; this site uses none today).
5. How we use the data
- To respond to enquiries you send via the website or by email.
- To deliver, support, and bill for services you have contracted from us.
- To meet our legal obligations (invoicing, retention, security incident handling).
- To defend our legal rights where necessary.
We do not sell personal data. We do not use it for unrelated marketing.
6. Processors and sub-processors
We use carefully selected service providers to operate the firm. Current sub-processors include:
- Microsoft Ireland (Microsoft 365 — mail, productivity, identity);
- Freshdesk (support ticketing);
- Elorus (invoicing for the Greek market);
- Hosting providers used to operate our public web properties.
For client engagements, the specific sub-processor list applicable to that engagement is set out in the data-processing agreement.
7. International transfers
Where a processor is located outside the European Economic Area, the transfer is covered either by an adequacy decision of the European Commission or by the Standard Contractual Clauses (Commission Decision 2021/914) supplemented by appropriate technical and organisational measures.
8. Retention
We retain personal data only as long as needed for the purposes set out above and as required by applicable law. Indicative retention periods:
- Enquiry correspondence: up to 24 months unless an engagement results.
- Client records and engagement data: duration of the engagement plus statutory retention (Greek tax / accounting law: typically 5 years).
- Web server logs: up to 90 days for routine security purposes.
9. Your rights
Under the GDPR and Greek Law 4624/2019, you have the right to:
- request access to the personal data we hold about you;
- request correction of inaccurate data;
- request erasure where the lawful basis allows;
- request restriction of processing;
- request data portability;
- object to processing based on legitimate interests;
- withdraw consent at any time, where consent is the lawful basis;
- lodge a complaint with the Hellenic Data Protection Authority (HDPA), Kifisias 1-3, 11523 Athens, www.dpa.gr.
We respond to verified requests within one month. If your request is complex or we receive a large volume of requests, we may extend by a further two months and will inform you.
10. Security
We apply appropriate technical and organisational measures under Article 32 GDPR — access control, encryption in transit, segregation of environments, logging, incident-handling procedures. No measure eliminates risk; we describe what we do and do not promise outcomes we cannot guarantee.
11. Cookies
See our Cookies Policy. This site does not use analytics, advertising, or tracking cookies.
12. Changes
We may update this policy as our operations or applicable law change. The "last updated" date at the top of the page indicates when the current version took effect. Material changes will be highlighted in the same section.
13. Contact
Questions or requests: info@intellinet.gr.