Privacy notice
Last updated 1 August 2026
Who is responsible
TZEKOS.EU, an ατομική επιχείρηση established in Thessaloniki, Greece, is the data controller for this website and for the client portal on it. Questions, requests and complaints go to luca@tzekos.eu and are answered by a person, not a queue.
What this site collects
Three things, and nothing else.
The enquiry form
Your name, email address, company, what you want built, your budget range and your timeline. Lawful basis: steps taken at your request before entering a contract (GDPR Art. 6(1)(b)). It is stored so we can answer you and so we know what we have already discussed. It is never added to a mailing list and never passed to anyone.
The client portal
If you have an account: your email address, name, company, the tickets you open and the messages in them, the payment requests we issue you, and the record of which were paid. Lawful basis: performance of the contract (Art. 6(1)(b)) and our legal obligation to keep accounting records (Art. 6(1)(c)).
Technical records
Server logs, and a salted hash of the IP address on sign-ins and form submissions. The hash is one-way and salted with a secret held only on our server: it is enough to rate-limit abuse and to evidence when an account was accessed, and not enough to reconstruct where you were. Raw IP addresses are not stored in the database. Lawful basis: legitimate interest in keeping the service secure (Art. 6(1)(f)).
What this site does not do
- No analytics service, first-party or third-party. There is no tracking script.
- No advertising, no remarketing, no fingerprinting, no session recording.
- No third-party fonts, scripts or embeds — every asset is served from this domain.
- No cookie banner, because there is nothing to consent to.
Cookies
Exactly one, and only if you sign in: a session cookie holding a random identifier, marked
HttpOnly, Secure and SameSite=Lax. It is strictly
necessary to keep you signed in, which is why no consent prompt is required for it. It
lasts 30 days, and signing out deletes it and the session behind it immediately.
There is no consent banner on this site because there is nothing optional to consent to. That is not a loophole we are leaning on — the consent layer is real and running. This site is registered in our own consent control plane alongside Erioun and Kaeros, and you can open the manager and see the complete inventory at any time:
If we ever add anything optional — self-hosted analytics is the only candidate — it is published to that control plane, the notice appears by itself, and it stays switched off until you say otherwise. Every decision is recorded against the exact version of the wording you were shown, because a consent record you cannot reconstruct is not evidence of anything.
Where it is stored
On servers we own and administer ourselves in the European Union (OVH, Warsaw, Poland). There is no transfer outside the EU or EEA for anything described on this page.
Who else sees it
- Our email provider delivers notifications and sign-in links. It sees your address and the content of those messages.
- Our payment provider processes card payments. Card details are entered on their page and never reach this site; we store only the reference, the amount and whether it succeeded.
- Nobody else. We do not sell, rent or share personal data, and there is no advertising relationship of any kind.
How long it is kept
- Enquiries that do not become clients: 24 months, then deleted.
- Client accounts, tickets and payment records: for the contract, then as long as Greek accounting law requires.
- Sign-in links: 20 minutes, and they are single-use.
- Expired sessions and stale sign-in links: purged automatically every six hours.
- Server health and status data: 30 days for host figures, 7 days for raw checks. It is about machines, not people.
Your rights
Under the GDPR you may ask for a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. Write to luca@tzekos.eu and you will get an answer within 30 days — in practice, within a couple of days.
If a request concerns data we hold on behalf of one of our clients — for example a customer record inside a system we built and host for them — then they are the controller and we are the processor. We will pass the request on and tell you who to contact.
You may also complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), dpa.gr.
Changes
This notice is versioned by date, and material changes are announced on the news page rather than made quietly.