Privacy Policy
Last updated: 29 July 2026
This policy explains what personal data we collect, why, how long we keep it, and what rights you have. It applies to visitors to creattivica.com and to our clients and prospective clients.
1. Who is the data controller
Andr. Panagiotopoulos Kai SIA L.P., trading as Creattivica
Dagre 2, Argos, Argolis 21232, Greece
VAT (ΑΦΜ): 802110340 · GEMI: 170151013000
Data protection contact: privacy@creattivica.com · +30 700 700 1758
We are the data controller for personal data described in this policy. Where we process personal data on behalf of a client as part of a project, that client is the controller and we act as processor under a written data processing agreement.
2. What we collect and why
| Data | Why | Legal basis (GDPR Art. 6) | Kept for |
|---|---|---|---|
| Name, email, phone, company, message — submitted via our contact form or sent to us by email | To respond to your enquiry and prepare a proposal | Consent (6(1)(a)) and steps prior to entering a contract (6(1)(b)) | 24 months from last contact |
| Client contact details, billing address, VAT number, project correspondence | To deliver the services and manage the relationship | Performance of a contract (6(1)(b)) | Duration of the contract, then 5 years |
| Invoices, payment records and accounting data | To invoice you and meet our tax obligations | Legal obligation (6(1)(c)) — Greek tax and accounting law | 10 years, as required by Greek law |
| Server access credentials you provide | To carry out the work you engaged us for | Performance of a contract (6(1)(b)) | Deleted within 30 days of project completion unless you retain us for maintenance |
| IP address, browser and device type, pages visited, referring page | Site security, fraud prevention and aggregate analytics | Legitimate interests (6(1)(f)); consent for non-essential analytics cookies | 26 months |
We do not collect special category data. We do not carry out automated decision-making or profiling. We do not sell personal data to anyone, ever.
3. Payment data
We do not collect or store your card details. Card payments are processed by our payment service provider, which is PCI-DSS compliant. We receive only a confirmation of payment, the last four digits of the card and the cardholder name. Your payment provider’s own privacy policy applies to the data they hold.
4. Cookies
We use strictly necessary cookies to make the site work, and — only with your consent — analytics cookies to understand how the site is used. You can accept, reject or change your choice at any time through the cookie banner. Full detail is in our Cookie Policy.
5. Who we share data with
We share personal data only with service providers who help us run our business, under written contracts that require them to protect it and to process it only on our instructions:
- Hosting and infrastructure providers — to host this website and our systems
- Email and productivity providers — to send and store correspondence
- Payment service providers — to process card payments and direct debits
- Our accountant — to prepare accounts and meet tax obligations
- Analytics providers — where you have consented to analytics cookies
We may also disclose data where required by law, court order or a competent authority.
6. International transfers
Our data is stored within the European Economic Area wherever possible. Where a provider processes data outside the EEA, we rely on an adequacy decision of the European Commission or on Standard Contractual Clauses, together with any additional safeguards required. You can ask us for details of the safeguards applying to a specific transfer.
7. How we protect your data
We use TLS encryption on this website and on all data in transit, encryption at rest for backups, access control on a least-privilege basis, multi-factor authentication on administrative accounts, regular patching of our systems, and monitored, tested backups. We keep a record of processing activities and will notify you and the supervisory authority within 72 hours of becoming aware of a personal data breach affecting your rights.
8. Your rights
Under the GDPR you have the right to:
- Access — obtain a copy of the personal data we hold about you
- Rectification — have inaccurate or incomplete data corrected
- Erasure — have your data deleted where we have no overriding legal reason to keep it
- Restriction — ask us to limit how we use your data while a concern is resolved
- Portability — receive your data in a structured, machine-readable format
- Object — object to processing based on our legitimate interests, and to direct marketing at any time
- Withdraw consent — at any time, where processing is based on consent; this does not affect processing already carried out
To exercise any of these, email privacy@creattivica.com. We respond within one month and there is no charge. We may ask you to verify your identity first.
9. Complaints
If you are not satisfied with how we have handled your data, please tell us first so we can put it right. You also have the right to complain to the Greek supervisory authority:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias 1-3, 115 23 Athens, Greece
Telephone: +30 210 6475600
Web: www.dpa.gr
10. Children
Our services are directed at businesses. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. The date at the top shows when it was last revised. Material changes affecting your rights will be notified to clients by email.
12. Contact
Questions about this policy or your data: privacy@creattivica.com, or write to Andr. Panagiotopoulos Kai SIA L.P., Dagre 2, Argos, Argolis 21232, Greece.
