Privacy Policy
Last updated: 07/2026
1. Introduction
This Privacy Policy is intended to explain how personal data is collected, used, and protected by [Studio/Practice Name] ("we," "us," "our") when this website is visited or when contact is made regarding architectural services. This practice is based in Kalamata, Messinia, Greece, and personal data is processed in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Greek data protection law (Law 4624/2019).
Data Controller [Studio/Practice Name] Kalamata, Messinia, Greece Email: [insert contact email]
Any questions regarding this policy or the handling of personal data may be directed to the contact details above.
2. Personal Data Collected
Depending on how this website is used, the following data may be collected:
Identity and contact details — name, email address, phone number, postal or project address
Enquiry and project information — details submitted when a consultation, quote, or site visit is requested, including project briefs, plot/property information, or attached files (sketches, photos, documents)
Correspondence — records of emails, messages, or calls related to an enquiry or project
Technical data — IP address, browser and device type, and data collected through cookies (see Section 5)
Usage data — pages viewed, time spent on the site, and navigation patterns
Newsletter data — an email address, where a subscription to updates is made
Special categories of data (e.g., health information) are not intentionally collected, and it is requested that such details be omitted from enquiry forms unless directly relevant to a project's accessibility requirements.
3. Purposes and Legal Basis for Processing
Purpose to Legal basis (GDPR Art. 6)
Enquiries and consultation requests are responded to -> Legitimate interest, or steps taken at the data subject's request prior to a contract
Proposals are prepared and architectural services are delivered -> Performance of a contract
The website is operated and secured -> Legitimate interest
Website analytics are conducted -> Consent (where cookies are non-essential)
Newsletters or project updates are sent -> Consent
Records are kept for tax, insurance, or professional liability purposes -> Legal obligation
Consent may be withdrawn at any time where processing is based on it, without affecting the lawfulness of processing carried out beforehand.
4. Data Retention
Enquiries that do not result in a project are generally retained for up to 12 months, after which they are deleted.
Client and project records are retained for as long as required by Greek professional, tax, and insurance obligations for architectural work (commonly several years after project completion, given the liability periods applicable to construction-related work).
Newsletter subscriber data is retained until unsubscription occurs.
5. Cookies
Cookies and similar technologies are used on this website to:
Ensure core site functionality
Understand how the site is used by visitors (analytics)
Non-essential cookies (such as those used for analytics) are set only where consent has been given, which is requested via a cookie banner upon first visit. Consent may be withdrawn or adjusted at any time through browser settings or the site's cookie preferences, although certain site features may be limited as a result.
6. Data Sharing
Personal data is not sold. It may be shared with:
Service providers engaged to support operations — for example, website hosting, email, or analytics providers — bound by data processing agreements under Article 28 GDPR
Professional collaborators (engineers, contractors, consultants) where required to deliver a specific project, and only where the data subject has been informed
Public authorities, where disclosure is required by law (e.g., permitting or tax authorities)
7. International Transfers
Where a service provider processes data outside the European Economic Area, appropriate safeguards, such as the European Commission's Standard Contractual Clauses, are ensured before any transfer takes place.
8. Data Security
Reasonable technical and organisational measures are applied to protect personal data, including encrypted (SSL/TLS) connections, access restrictions, and secure storage of project files. No system can be considered entirely risk-free, and it is recommended that highly sensitive information not be sent by unencrypted email where possible.
9. Data Subject Rights
Under the GDPR, the following rights may be exercised:
The right of access to personal data held
The right to request correction of inaccurate data
The right to request erasure of data, subject to legal retention requirements
The right to restrict or object to certain processing
The right to request data portability
The right to withdraw consent at any time, where processing is consent-based
The right to lodge a complaint with a supervisory authority
To exercise any of these rights, contact may be made at [insert contact email]. A response will be provided within one month, as required by the GDPR.
10. Supervisory Authority
Where it is believed that data protection rights have been infringed, a complaint may be lodged with:
Hellenic Data Protection Authority (HDPA) Website: https://www.dpa.gr
11. Children's Privacy
This website and the services offered are directed at adults seeking architectural services. Personal data from children is not knowingly collected.
12. Changes to This Policy
This policy may be updated periodically to reflect changes in practices or legal requirements. The "Last updated" date at the top of this page will always reflect the most recent revision. Periodic review of this page is encouraged.