Privacy policy
Last updated: 27 September 2026
In short
- Grand Systems processes only the personal data necessary for communications, business partnerships, newsletters, security, and contractual or legal obligations.
- The website does not use analytics, advertising or tracking cookies and does not use analytics tools.
- The newsletter is sent only after consent and double opt-in and includes an unsubscribe option.
- For software customers, Grand Systems generally acts as Processor under a separate DPA, while the customer is the Data Controller.
- You may exercise your rights through [email protected] and, if you consider that a violation has occurred, contact the Hellenic Data Protection Authority.
Data Controller
The data controller for personal data collected and processed through this website is Grand Systems, with offices in Athens 104 40 and Xylokastro 204 00.
For privacy matters, you may contact us at [email protected] or +30 694 207 5930 or +30 694 142 7221. No Data Protection Officer (DPO) has been appointed.
This Policy concerns processing carried out by the company as Data Controller through its corporate website. Personal data entered by customers into our software systems are covered separately by the section concerning our role as Processor.
What Personal Data We Collect
We collect and process only the data necessary for the specific purposes described in this Policy.
Contact form: full name, business name, email address, telephone number, services of interest and message content. The form includes a mandatory acceptance checkbox.
Partnership application form: full name, business name, email address, telephone number, type of business (e.g. accounting firm, IT company) and message, together with information necessary to assess the partnership request. The form includes a mandatory acceptance checkbox.
At present the forms do not store any data on the website: submitting a form opens your email application with a pre-filled message, which you send yourself to [email protected].
Newsletter: email address and language preference, Greek or English. We also record consent, including the date and time, and confirmation through double opt-in. Emails may record opens and clicks.
Technical data: the hosting infrastructure may process technical information such as IP address, user agent and log data necessary to deliver content, operate the service and maintain security, including protection against attacks.
The website uses a hidden honeypot field to protect against automated submissions. If Cloudflare Turnstile is used, technical data necessary for anti-spam verification may also be processed.
Purposes and Legal Bases
We use personal data only for specified and lawful purposes and do not process it in a manner incompatible with those purposes.
- Responding to contact requests and preparing offers: we process form data to communicate with you, understand your business needs and, where requested, prepare an offer. The legal basis is Article 6(1)(b) GDPR where processing is necessary for pre-contractual steps taken at your request and/or Article 6(1)(f) GDPR where based on our legitimate interest in responding to B2B communications and managing the relevant business request.
- Partnership applications: we assess and manage partnership requests from accountants, IT companies, resellers or other business partners. The legal basis is Article 6(1)(b) GDPR for pre-contractual steps and/or Article 6(1)(f) GDPR for managing and responding to B2B requests.
- Newsletter: we send informational and commercial emails on the basis of your consent, under Article 6(1)(a) GDPR and Article 11 of Greek Law 3471/2006. Consent is evidenced through the double opt-in process.
- Logs, security and website protection: we prevent, detect and address attacks, malicious activity and technical problems. The legal basis is Article 6(1)(f) GDPR, based on our legitimate interest in securing our information systems and website.
- Contract performance and tax obligations: where a contractual relationship exists, we process necessary data for contract performance under Article 6(1)(b) GDPR and to comply with legal and tax obligations under Article 6(1)(c) GDPR.
Logs and Security
The website is hosted as a static site on Cloudflare Pages. Cloudflare, Inc. may process technical information such as IP address, user agent and log data for content delivery, service operation and security, including protection against attacks.
The legal basis for processing necessary for website security is Article 6(1)(f) GDPR, based on our legitimate interest in protecting our information systems and services.
The website uses HTTPS, HSTS and Content-Security-Policy and follows data minimisation principles. Cloudflare logs are retained in accordance with Cloudflare's applicable policy and retention settings.
Recipients and Processors
- Cloudflare, Inc.: Cloudflare Pages hosting, content delivery and security/protection against attacks.
- Brevo (Sendinblue SAS), France: newsletter list management and delivery, including double opt-in and related open/click measurements.
- Spacemail (Spaceship, Inc., USA): corporate email provider, for receiving and managing messages submitted through the contact and partnership application forms.
- Accountant and legal advisers: access only to data necessary for accounting, tax or legal support, where required.
- Public authorities: where disclosure is required by law, court order or lawful administrative procedure.
Access by authorised company personnel is limited to the data necessary for the performance of their duties.
International Data Transfers
Cloudflare, Inc. is a US company and its services may involve transfers of personal data to the United States. According to the information applicable to the service, such transfers rely on the EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses.
For Brevo (Sendinblue SAS), the newsletter service we use is described as storing data in the European Union. Corporate email is provided by Spacemail of Spaceship, Inc., a company based in the United States, where processing takes place. The transfer relies on Standard Contractual Clauses.
Where a transfer of personal data to a third country is required, we apply the appropriate safeguards provided by the GDPR and provide information on the applicable transfer mechanism where required.
Data Retention
We retain personal data only for as long as necessary for the purpose for which it was collected, unless a longer period is required by law or is necessary for the establishment, exercise or defence of legal claims.
- Contact and offer requests without a business relationship: 12 months.
- Partnership requests: 12 months, unless a business relationship follows or longer retention is required for a lawful reason.
- Newsletter: until unsubscribe or withdrawal of consent. Evidence of consent may be retained for as long as necessary to demonstrate the lawfulness of the mailing and defend related claims.
- Contractual and tax data: for the period required by applicable law.
- Cloudflare logs: in accordance with Cloudflare's applicable policy and retention settings.
Data Security
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
The website operates over HTTPS and uses HSTS and Content-Security-Policy. We also apply data minimisation and access restriction principles. Nevertheless, no transmission or storage of data over the internet can guarantee absolute security.
In the event of a personal data breach, we comply with the obligations imposed by the GDPR, including, where required, notification to the competent supervisory authority and communication to affected data subjects.
Our Role as Processor for Software Customers
This Policy concerns visitor and website user data for which Grand Systems acts as Data Controller.
For personal data that our customers enter or process through our software and systems, such as ERP, POS, PDA, kiosk, reservation system and VoIP call centre, we generally act as a Processor under Article 28 GDPR. In that case, the customer is the Data Controller and determines the purposes and means of processing.
The relevant processing is governed by a separate Data Processing Agreement (DPA), which defines the parties' obligations and rights, security measures, sub-processors and other matters required by Article 28 GDPR. This Policy does not replace the DPA and does not determine the purposes for which customer data are processed in our systems.
Data Subject Rights
Depending on the legal basis and circumstances of the processing, you have the rights provided by the GDPR, including:
- Access: to request confirmation as to whether we process your data and, where applicable, a copy and information about the processing.
- Rectification: to request correction of inaccurate data or completion of incomplete data.
- Erasure: to request deletion of your data where the conditions of Article 17 GDPR are met. This right is not absolute and legal exceptions or retention obligations may apply.
- Restriction: to request restriction of processing in the circumstances set out in Article 18 GDPR.
- Data portability: to receive data concerning you in a structured, commonly used and machine-readable format and request transmission to another controller where the conditions of Article 20 GDPR are met.
- Objection: to object to processing based on Article 6(1)(e) or (f) GDPR on grounds relating to your particular situation and, in particular, to object at any time to processing for direct marketing purposes.
- Withdrawal of consent: where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
You may exercise your rights by sending a request to [email protected]. We may request reasonable additional information to verify your identity where necessary to protect your data.
We will respond without undue delay and, in any event, within one month of receiving your request. This period may be extended by two further months where necessary due to the complexity or number of requests, in which case we will inform you within the first month. Requests are generally free of charge, subject to the exceptions provided by the GDPR.
Minors
The website and services described in this Policy are directed to businesses and professionals and are not directed to minors. We do not knowingly seek to collect children's personal data through the website.
Automated Decision-Making and Profiling
We do not carry out through this website automated decision-making that produces legal effects or similarly significantly affects individuals within the meaning of Article 22 GDPR. We do not carry out profiling of website visitors for the purposes of the website.
Third-Party Links
The website may contain links to third-party websites or services. When you select such a link, you enter an environment that is not controlled by us. Processing of personal data by the third party is governed by its own privacy policy and terms. We recommend reviewing them before providing personal data.
Changes to this Privacy Policy
We may amend this Privacy Policy when our services, processing activities, technical infrastructure or applicable legal framework changes. The current version will be published on the website with its relevant update date.
Where a change is material and the GDPR requires it, we will take appropriate steps to inform you.
Contact
For questions about this Policy or to exercise your rights, you may contact Grand Systems at [email protected] or +30 694 207 5930 or +30 694 142 7221.
Company details: Grand Systems, Athens 104 40 and Xylokastro 204 00, [email protected].