Book a call

Legal

Privacy Policy

Last updated: 10 September 2026

1. Data Controller

The data controller for this website is Embeddedware, a sole-proprietor consultancy (single-person IKE) based in Greece.

Contact: hello@embeddedware.gr

2. Personal Data We Collect

We collect personal data only when you actively provide it or when it is generated automatically by your use of this website. Specifically:

  • Contact form submissions. The contact form on this site does not send data to us or to any third party on its own. When you complete it, it opens a draft message in your own email program (via a mailto link) pre-filled with the name, email, optional company name, and message you entered. Nothing is transmitted until you choose to send that email yourself. We then receive and process whatever you send.
  • Server and hosting logs. Our hosting provider (Vercel) automatically records standard server log data including your IP address, browser user-agent string, referring URL, and the date and time of requests. This is inherent to how web hosting works and is processed by Vercel under their own privacy terms.
  • Analytics. With your consent, Vercel Web Analytics measures public-page visits. It receives page paths, referral and browser/device information and derives approximate location and a daily visitor hash from the request. It does not use analytics cookies. We remove query strings and fragments from page URLs and send no form contents or custom events. Analytics does not load before acceptance. You can withdraw through Analytics settings in the footer.

3. Purposes and Legal Basis (GDPR Art. 6)

We process your personal data for the following purposes and on the following legal bases under GDPR Article 6:

  • Responding to enquiries. When you contact us via the contact form or by email, we process the data you provide in order to read and respond to your message. Legal basis: consent (you chose to submit the form) and/or legitimate interests (responding to business communications).
  • Pre-contractual steps. If your enquiry concerns a potential engagement, we may use the information to take steps prior to entering into a contract with you. Legal basis: steps prior to entering a contract (Art. 6(1)(b)).
  • Operating and securing the site. Server logs are processed to maintain site security and diagnose technical issues. Legal basis: legitimate interests (Art. 6(1)(f)).

4. Data Sharing and Processors

We do not sell your personal data. We share data only with third-party processors that are strictly necessary to operate this site and respond to your enquiries:

  • Vercel (hosting). This site is hosted on Vercel, Inc., which also provides optional consent-based Web Analytics. Requests expose IP address and browser metadata to the provider; daily visitor identifiers are discarded after 24 hours. Reporting history is separate from that identifier lifetime.
  • Email provider. Our email inbox provider processes the messages you send us, including any later replies in the same conversation.

The contact form uses no third-party form-delivery service. The web fonts used on this site are self-hosted, so fonts do not contact a third-party font service. Optional analytics contacts Vercel only after acceptance. All processors we do use are selected to provide appropriate technical and organisational safeguards for your data.

5. International Data Transfers

Our hosting provider (Vercel) is based in the United States and may process server logs and consented analytics outside the European Economic Area (EEA). Where data is transferred outside the EEA, we rely on appropriate safeguards - such as Standard Contractual Clauses (SCCs) adopted by the European Commission - to ensure your data is protected to an equivalent standard.

6. Data Retention

We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected:

  • Contact form messages and email correspondence are kept for as long as needed to complete your enquiry and for reasonable follow-up, or for as long as required by legitimate business record-keeping obligations, after which they are deleted.
  • Server logs and analytics history follow Vercel retention policies and project settings. The daily visitor hash expires after 24 hours; reporting history can remain longer. Contact hello@embeddedware.gr for retention and deletion requests.

8. Your Rights Under GDPR

If you are located in the EEA (or the UK, or another jurisdiction with equivalent rights), you have the following rights regarding your personal data:

  • Access. Request a copy of the personal data we hold about you.
  • Rectification. Ask us to correct inaccurate or incomplete data.
  • Erasure. Ask us to delete your personal data ("right to be forgotten"), where applicable.
  • Restriction. Ask us to restrict processing of your data in certain circumstances.
  • Portability. Receive your data in a structured, machine-readable format.
  • Objection. Object to processing based on legitimate interests.
  • Withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, please email us at hello@embeddedware.gr. We will respond within one month as required by GDPR.

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority. As Embeddedware is based in Greece, the relevant authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα - Hellenic DPA), reachable at www.dpa.gr.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page will be revised accordingly. We encourage you to review this page periodically.

Note

This privacy policy is a general template prepared in good faith to reflect our current data practices. It has not been reviewed by a qualified legal practitioner. Before relying on this document for compliance purposes - or before making any material changes to data processing activities - it should be reviewed and approved by a lawyer qualified in EU data protection law.