Privacy Policy & GDPR
VeloSite — Personal Data Protection
Last updated:
1. Data Controller
The controller of personal data collected through this website is VeloSite, based in Athens, Greece.
Email: hello@velosite.gr
Phone:
Full company details will be completed in site-config.
2. Scope
This Policy describes how we collect, use and protect personal data of visitors and prospective clients of the VeloSite website (and related contact pages), in line with Regulation (EU) 2016/679 (GDPR) and Greek law (Law 4624/2019 etc.).
For WaaS service terms, see the Terms of Use. For cookies, see theCookie Policy.
3. What Data We Collect
Depending how you interact with us, we may process:
- Contact details: full name, email, phone (if you provide them in the form).
- Message content: project details, package of interest, and other information you submit in a form.
- Technical data: IP address, browser type, device — as needed for security or (with consent) for analytics.
We do not seek to collect special-category data (health, religion, racial origin, etc.). Please do not submit such data via forms.
4. How Data Is Collected
- Via contact forms on the website.
- Via email when you contact us directly.
- Via cookies / similar technologies — see Cookie Policy.
5. Purpose & Legal Basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Responding to enquiries / quotes | Consent · pre-contractual steps |
| Performing the WaaS service contract | Contract performance (Art. 6(1)(b)) |
| Website security, spam prevention | Legitimate interest (Art. 6(1)(f)) |
| Analytics / site improvement | Consent (only if cookies accepted) |
| Tax / accounting obligations | Legal obligation |
6. Storage — No Local Database
Basic principle:We do not keep sensitive local databases of personal data on our own servers. Form data and related requests are processed securely viacompliant third-party providers (APIs / processing services within the EU or with appropriate safeguards)and forwarded to our email / systems to respond to your request, in line with the GDPR.
Website hosting runs on secure cloud infrastructure with SSL/HTTPS encryption. Third-party processors are chosen for security and, where required, bound by data processing agreements (DPAs) or equivalent safeguards.
7. Contact Forms (Formspree)
Contact with VeloSite is via form or email — no phone calls and no appointment calendar with the company. Messages are sent via a third-party external platform:
- Formspree (or equivalent form provider): receives the contact form submission at formspree.io and forwards it to the email / inbox we have set, without storing the content in a local VeloSite database.
By submitting the form, you accept that the relevant data will be processed by the above provider for the purpose of communication. For details on accounts, usage limits and third-party service charges on client projects, see the Terms of Use (section “Third-Party Services — Forms Policy”).
Client websites (WaaS): For forms on websites we build/host for clients, the data controller for data collected via the client's form is as a rule the client. VeloSite provides technical integration and, where agreed, acts as processor or account administrator of a third-party service on behalf of the client. This Policy mainly covers the VeloSite marketing website (velosite.gr) and the data you send us as prospects / clients.
8. Recipients
Data may be shared only with:
- contact form / email providers (e.g. Formspree),
- website hosting providers,
- analytics providers (only with consent),
- competent authorities, when required by law.
We do not sell personal data to third parties for advertising purposes.
9. Transfers outside the EEA
If a provider is outside the European Economic Area, we apply appropriate safeguards (e.g. European Commission Standard Contractual Clauses) under Articles 44 et seq. GDPR.
10. Retention Period
- Contact requests: up to 24 months from the last contact, unless a contractual relationship arises.
- Contractual / tax records: in line with applicable tax and commercial law.
- Cookies: in line with the Cookie Policy and your consent settings.
11. Your Rights
Under the GDPR, you have the right to:
- access your data,
- rectification or erasure (“right to be forgotten”),
- restriction of or objection to processing,
- data portability,
- withdraw consent at any time (without affecting lawfulness before withdrawal),
- lodge a complaint with the Hellenic Data Protection Authority (HDPA).
To exercise your rights: hello@velosite.gr. We respond within GDPR time limits.
12. Security
- SSL/HTTPS encryption across the connection.
- No storage of form data in our own local database.
- Anti-spam measures (Formspree form provider protection / rate limits when active).
- Limited access to incoming requests.
13. Minors
Our services are aimed at businesses and adults. We do not knowingly collect data from children under 16. If we learn of such collection, we will delete it.
14. Changes
We may update this Policy. The date of the last revision appears at the top of the page.
15. Contact
Email: hello@velosite.gr
Phone: