Skip to content
← Back to home

Privacy Policy

vectisdesigns.gr — Last updated: 04/06/2026

Data Controller

Vectis is the data controller for personal data processed through vectisdesigns.gr, in accordance with GDPR (Regulation (EU) 2016/679) and Greek Law 4624/2019.

Company details

  • Name: Vectis
  • Website: vectisdesigns.gr
  • Country: Greece
  • Service: Website development for local Greek businesses

Data Controller contact

  • Name: Ermis Papadopoulos
  • Email: ermis@oikion.com
  • Phone: +30 6976 593 477
  • Address: Athens, Greece

Scope

This Policy explains how we collect and process personal data when you visit vectisdesigns.gr. The Website has no user accounts or login.

What Data We Collect

a. Usage and technical data (analytics)

Device/browser information, anonymised IP address, pages viewed, time spent, navigation actions.

b. Data you provide

If you contact us via email or contact form, we may collect your name, email, phone, and message content.

Purposes of Processing

  • Operating, securing, and administering the Website
  • Measuring traffic and improving user experience
  • Responding to enquiries about our services

Legal Bases

  • Consent (Art. 6(1)(a) GDPR): for analytics cookies — withdrawable at any time
  • Legitimate interests (Art. 6(1)(f) GDPR): for Website security and administration
  • Contract performance (Art. 6(1)(b) GDPR): when communication relates to a service request
  • Legal obligation (Art. 6(1)(c) GDPR): where required by law

Cookies

We use Cookiebot for cookie consent management. On your first visit you may accept or reject non-essential cookies.

Google Analytics 4 (Measurement ID: G-VBMRZQY2Y9):

  • Cookie: _ga — Purpose: Distinguishes unique users — Duration: 2 years
  • Cookie: _ga_VBMRZQY2Y9 — Purpose: Session state for GA4 property — Duration: 2 years

Analytics cookies are activated ONLY after you give consent.

Newsletter Subscription

If you subscribe to our newsletter via the form on this Website, we process your email address on the basis of your explicit consent (Art. 6(1)(a) GDPR), given through a double opt-in flow.

What we collect

  • Email address
  • Signup source (footer or inline form)
  • IP address at signup time (audit trail)
  • Timestamps for signup and confirmation
  • The unique discount code we issue to you (valid until 3 December 2026)

Purpose

  • Sending offers and short business tips (approximately one email per month)
  • Issuing and tracking the 10% discount code

Retention

We retain your subscription record for as long as you remain subscribed. After you unsubscribe, your email address is kept on a suppression list to prevent accidental re-sending. You may request full deletion by emailing the contact above.

Unsubscribe

Every email contains a one-click unsubscribe link compliant with RFC 8058. Unsubscribing is immediate and free of charge.

Site Audit

If you submit a free site audit via the /audit page, we process the data on the basis of your explicit consent (Art. 6(1)(a) GDPR), given by form submission.

What we collect

  • URL of the website you submitted for audit
  • Email address where the report is sent
  • IP address at submit time (audit trail + rate limiting)
  • Optionally: newsletter signup consent (via checkbox)

How it works

The URL is forwarded to Google's PageSpeed Insights API, which runs a Lighthouse performance analysis against two strategies (mobile + desktop). The results are returned and emailed to you as a report.

Retention

We retain audit records for 12 months (operational analytics). If you become a customer, the record may be retained as part of project history.

Recipients of Data

We do not sell data. We may share data with:

  • Hosting/infrastructure providers
  • Google LLC (GA4 analytics)
  • Google LLC (PageSpeed Insights API — performance measurement for the free site audit)
  • Cookiebot/Usercentrics (consent management)
  • Email delivery providers (Resend) — for subscription confirmation, newsletter sends, transactional emails, and audit reports
  • Supabase (database hosting — newsletter list, audit records, EU region)
  • Cloudflare Turnstile — spam protection on the forms

Transfers Outside the EEA

Google may process data outside the EEA. Google is certified under the EU-US Data Privacy Framework.

Retention

We retain data only as long as necessary. Analytics cookies last 2 years.

Your Rights

Under GDPR and Greek Law 4624/2019:

  • Access — request a copy of your data
  • Rectification — correct inaccurate data
  • Erasure — right to be forgotten
  • Objection — object to processing
  • Restriction — limit processing
  • Portability — receive data in machine-readable format
  • Withdraw consent — at any time, without affecting prior processing

To exercise your rights: ermis@oikion.com
Lodge a complaint with the Hellenic DPA (ΑΠΔΠΧ): www.dpa.gr

Security

We apply appropriate technical and organisational measures to protect your data.

Third-Party Links

We are not responsible for the privacy practices of third-party websites.

Changes

We may update this Policy at any time. The effective date is always shown at the top.