Privacy Policy
Last updated · July 2026
This Privacy Policy describes how Codegraph ("we", "us") collects, uses and protects the personal data of visitors to our website and of our clients. We respect your privacy and process your personal data in accordance with the General Data Protection Regulation (GDPR, EU Regulation 2016/679) and applicable Greek and European law.
What data we collect
- Information you fill in on the contact form: your name, email, phone (optional), the service you are interested in and the content of your message.
- Information you give us when you contact us by email or phone and, where an engagement follows, the details required for the agreement and invoicing.
- Technical data logged automatically by our hosting provider, such as IP address, device type, browser and request time, for security and stability reasons.
We use a cookieless analytics tool (Ahrefs Web Analytics) that counts page views and referring sites in aggregate. It stores nothing on your device, sets no cookies and builds no visitor profile, so you cannot be identified or tracked across sites from it. We use no advertising or remarketing tools. We do not request or collect special categories of personal data, such as health data, political or religious beliefs, or other sensitive data.
How we collect data
Data is collected when you fill in the website contact form, when you contact us by email or phone, and when you browse the website, through the server's technical logs.
Also when you choose a display language, at which point a strictly necessary cookie holding your choice is stored on your device.
Purposes of processing
- To respond to contact requests and send you an automatic acknowledgement that your message arrived.
- To give you information and a quote for our services and, where an engagement follows, to manage our collaboration.
- For the correct operation, stability and security of the website.
- To keep your language preference, so you do not have to choose it again.
- To comply with legal obligations, where required.
Legal bases for processing
- Legitimate interest: to respond to requests and for the security and correct operation of the website.
- Performance of a contract or pre-contractual steps at your request: to prepare a quote and manage the engagement.
- Consent: will be requested only if non-essential cookies, such as analytics or marketing, are enabled in future. None are used today.
- Legal obligation: where required by applicable law, such as for tax records.
Cookies
Cookies are small text files stored on your device when you visit a website, letting the site remember your actions and preferences.
- Essential cookies: required for the basic operation of the website. This site uses one such cookie, named NEXT_LOCALE. It stores only the value el or en, is set exclusively when you use the language toggle, lasts one year and contains no visitor identifier.
- Statistics / analytics cookies: help understand traffic. Not used on this website.
- Marketing cookies: used where advertising or remarketing tools are present. Not used on this website.
Because the only cookie in use is strictly necessary and is set as the direct result of your own action, no consent is required under Article 4(5) of Greek Law 3471/2006 and no cookie banner is shown. If non-essential cookies are added in future, a consent banner will appear before they are set and this Policy will be updated.
You can in any case delete or block cookies from your browser settings (Chrome: Settings, Privacy and security, Cookies · Firefox: Settings, Privacy and security · Safari: Preferences, Privacy · Edge: Settings, Cookies and site permissions).
For a per-cookie breakdown, see the Cookie Policy.
Sharing data with third parties
We do not sell or make your personal data available to third parties for their own independent commercial use, and we do not use it for advertising purposes.
We may share data only where necessary for the operation of the website or compliance with legal obligations: with our website hosting provider, with the provider of our company email account (through which contact-form messages are delivered), with our cookieless analytics provider, which receives only aggregate page-view data, with accounting or legal partners bound by confidentiality, and with competent authorities where there is a legal obligation.
Transfers outside the EEA
As a rule, we aim for personal data to be processed within the European Union or European Economic Area.
Some providers, such as those hosting the website or our analytics, may process data outside the EEA. In those cases the transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision, in accordance with the GDPR.
Data retention
We keep personal data only for as long as necessary for the purpose for which it was collected.
Indicatively: contact data is kept for as long as the exchange lasts and, where no engagement follows, for a reasonable period of up to two years so that we keep a record of the correspondence. Data for active engagements is kept for the duration of the agreement and for as long as tax law requires. Technical logs are kept for a reasonable period for security reasons. The language cookie expires after one year.
After the required period, data is deleted or anonymised, unless there is a legal reason for further retention.
Your rights
Under the GDPR, you have the right to access your data, rectify inaccurate or incomplete data, erase it (where permitted), restrict processing, object, port your data and withdraw consent where processing is based on it.
To exercise your rights, you can contact us at info@codegraph.gr. We respond within one month of receiving your request.
Data security
We take appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration or disclosure.
These measures include, indicatively, use of a secure SSL/TLS connection across the site, encrypted transmission of contact-form messages, limited access to authorised persons and two-factor authentication on our accounts.
Links to third-party sites
The website may contain links to third-party sites or platforms, such as client projects or social media. We are not responsible for the privacy practices or content of those sites. We recommend reading their policies before providing personal data.
Changes to this Policy
This Privacy Policy may be updated from time to time to reflect changes in the operation of the website, the technologies used or applicable law. Each new version is posted on this page with an updated date.
Contact
The data controller is Codegraph. For any question about this Policy or the processing of your personal data, you can contact us:
Codegraph
Registered office: [registered address], Heraklion, Crete
Company registry: [company registry number] · [VAT number, tax office]
Email: info@codegraph.gr
Phone: +30 698 022 3404
Website: codegraph.gr
Right to complain
If you believe the processing of your personal data infringes applicable law, you have the right to lodge a complaint with the Hellenic Data Protection Authority.
Hellenic Data Protection Authority
1-3 Kifisias Ave., 115 23 Athens
Phone: 210 6475600
Website: www.dpa.gr
