Skip to content
CompFlow mark CompFlow
LEGAL / PRIVACY POLICY

Privacy policy

How CompFlow collects, uses and protects personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and Greek Law 4624/2019.

LAST UPDATED: 26 JULY 2026 VERSION 1.0
01 — DATA CONTROLLER

Who is responsible for your data

CompFlow is the data controller for personal data processed through this website and in the course of our consultancy work. You can reach us for any privacy matter using the details below; we aim to respond to every request within one month, as required by Article 12(3) GDPR.

MAIN OFFICE — ATHENS
Odisseos 7, 10437 Athens, Greece
Tel: +30 210 5221665
PRIVACY CONTACT
info@compflow.eu
Subject line: “GDPR request”
02 — DATA WE COLLECT

What we collect and why

CATEGORYDATAPURPOSELEGAL BASIS
Contact enquiries Name, email, company, phone, project description and requirements you submit Responding to your enquiry and preparing a proposal Art. 6(1)(b)
Client project data Geometry, operating conditions and correspondence supplied during a project Performing the consultancy contract Art. 6(1)(b)
Server logs Truncated IP address, user agent, timestamp, requested page Security, abuse prevention and service integrity Art. 6(1)(f)
Analytics & advertising Cookie identifiers, device and approximate location data, pages viewed, conversions Measuring site usage and advertising performance Art. 6(1)(a)
Job applications CV, cover letter and contact details you send us Assessing your application Art. 6(1)(a)

We do not collect special categories of personal data (Article 9 GDPR), we do not knowingly collect data from children, and we do not carry out automated decision-making or profiling that produces legal effects for you.

03 — GOOGLE ANALYTICS

Google Analytics 4

With your consent we use Google Analytics 4, a web analytics service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). Analytics cookies and identifiers are only set after you accept the analytics category in our cookie banner — nothing is loaded before that. Consent is the legal basis (Article 6(1)(a) GDPR) and you may withdraw it at any time.

+ We use the EU-based collection endpoint and IP anonymisation, so your IP address is truncated before storage and never used to identify you.
+ Google Signals and cross-device advertising features are disabled unless you also accept the marketing category.
+ Data sharing with other Google products for Google’s own purposes is switched off in our property settings.
+ The Analytics user and event data retention period is set to 14 months, after which records are deleted automatically.
+ We do not upload any directly identifying information (such as names or email addresses) into Analytics.
+ Declining analytics has no effect on your ability to use the site or contact us.

We have a Data Processing Addendum in place with Google under Article 28 GDPR. You can also install the Google Analytics Opt-out Browser Add-on to prevent measurement across all websites.

04 — GOOGLE ADS

Google Ads and conversion measurement

If you accept the marketing category, we may use Google Ads to measure the effectiveness of our advertising and to show relevant ads on Google's network. This can involve a conversion cookie, remarketing lists, and — where enabled — enhanced conversions, in which a hashed version of an identifier you submitted (such as your email address) is transmitted to Google in irreversible form.

+ Advertising tags load only after you accept the marketing category in the banner.
+ Enhanced conversions, where used, transmit only irreversibly hashed identifiers — Google cannot recover the original value.
+ We do not build remarketing audiences from sensitive characteristics, and we do not combine ad data with your project files.
+ When marketing consent is denied, Consent Mode still allows Google to model aggregate results without cookies or identifiers.
+ You can withdraw marketing consent at any time; existing cookies are then no longer read and expire on schedule.

In this context Google acts partly as our processor and partly as an independent controller. Google's own handling of data is described in the Google Privacy Policy; you can manage ad personalisation at Google Ad Settings.

06 — INTERNATIONAL TRANSFERS

Transfers outside the EEA

Data processed by Google may be transferred to servers in the United States. Such transfers rely on the EU–US Data Privacy Framework, under which Google LLC is certified, and on the European Commission's Standard Contractual Clauses together with supplementary technical measures such as encryption in transit and at rest. Despite these safeguards, a transfer to a third country may carry residual risk — for example access requests by local authorities. Where transfers depend on your consent, that consent also covers this transfer under Article 49(1)(a) GDPR.

07 — RETENTION

How long we keep data

Enquiry correspondence where no engagement follows 24 months
Client project data and deliverables Contract term + 5 years
Invoices and accounting records (Greek tax law) 10 years
Google Analytics event and user data 14 months
Cookie consent record 12 months
Unsuccessful job applications 12 months
08 — YOUR RIGHTS

Your rights under the GDPR

ART. 15 Access
Obtain confirmation of whether we process your data and receive a copy of it.
ART. 16 Rectification
Have inaccurate or incomplete data corrected without undue delay.
ART. 17 Erasure
Request deletion where data is no longer necessary or consent is withdrawn.
ART. 18 Restriction
Limit our processing while accuracy or a legitimate interest is being verified.
ART. 20 Portability
Receive data you provided in a structured, machine-readable format.
ART. 21 Objection
Object to processing based on legitimate interests, including direct marketing.
ART. 7(3) Withdraw consent
Withdraw analytics or marketing consent at any time, with no effect on prior lawfulness.
ART. 77 Complaint
Lodge a complaint with the Hellenic DPA or your local supervisory authority.

To exercise any right, email info@compflow.eu. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Kifissias 1-3, 11523 Athens, dpa.gr) or with the supervisory authority of your EU country of residence.

09 — SECURITY & CONFIDENTIALITY

How we protect your data

All project work is carried out exclusively by CompFlow personnel at company premises and is never outsourced, under strict bidirectional non-disclosure agreements. Technical measures include TLS encryption for the website, access control on our computing facilities, and encrypted storage of project data. Access to personal data is limited to staff who need it to perform their role.

10 — CHANGES

Updates to this policy

We review this policy whenever our processing changes and at least annually. Material changes affecting the basis on which we process your data will be announced on this page, and where consent is required we will ask for it again before any new processing begins.