Privacy Policy

1. Introduction and General Information

Online Developer is committed to protecting the privacy of its users and ensuring the security of their personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR). This Privacy Policy provides a transparent overview of how we collect, process, and safeguard the information of all visitors and customers of the website online-developer.gr. By interacting with our services, you acknowledge the processing practices described in this document.

2. Identity of the Data Controller

The entity responsible for the processing of your personal data (the “Controller”) is:

  • Business Name: MPIRMPAS CHRISTOS TOU ATHANASIOU
  • Brand Name: Online Developer
  • Register Number (ΓΕΜΗ): 153578003000
  • VAT Number: 143366812
  • Address: Ap Paulou 50, Agios Dimitrios – Attikis, Zip Number: 17343, Greece
  • Email: info@online-developer.gr

3. Legal Basis and Purposes of Processing

We process personal data only when there is a valid legal basis under Article 6 of the GDPR. The table below maps our processing purposes to their respective legal grounds:

Purpose of ProcessingLegal Basis (GDPR Article 6)
Provision of Services: Development services, WordPress plugin subscriptions, and web hosting.Art. 6(1)(b): Performance of a Contract
Website Security & Spam Prevention: Implementation of reCAPTCHA to protect web forms.Art. 6(1)(f): Legitimate Interest*
Website Aesthetics & Styling: Dynamic loading of Google Fonts for consistent typography.Art. 6(1)(f): Legitimate Interest*
Performance Analytics: Evaluation of site usage and traffic via Google Analytics.Art. 6(1)(a): Consent
Marketing & Ad Effectiveness: Measurement of conversion and targeting via Facebook Pixel.Art. 6(1)(a): Consent

*Note: For processing based on Art. 6(1)(f), Online Developer has conducted a balancing test (Legitimate Interest Assessment) to ensure that our interests do not override the fundamental rights and freedoms of the data subject.

4. Types of Personal Data Collected

We categorize the data collected into the following types:

  • Account & Profile Data: Name, email address, and authentication credentials provided for subscriptions and service access.
  • Checkout & Transaction Data: Billing address, purchase history, and service-specific configuration details.
  • Payment Data: Financial transactions are processed via Stripe. Online Developer does not store full credit card numbers or CVV codes; all payment processing is handled by our PCI-DSS compliant provider.
  • Tracking & Technical Data: IP addresses, browser types, device identifiers, and behavioral data (e.g., clickstreams) collected via cookies and pixels.

5. Infrastructure and Data Processors

To maintain high availability and security, we utilize the following infrastructure:

  • Hosting: Our primary website infrastructure is located in the Netherlands (EU).
  • Backups: Encrypted website and database backups are securely stored in Lithuania (EU).
  • Payments: We utilize Stripe as our primary payment gateway. Where data is transferred to Stripe’s infrastructure in the United States, such transfers are protected by the EU-U.S. Data Privacy Framework or Standard Contractual Clauses (SCCs) to ensure an adequate level of protection.

6. Third-Party Tracking and External Services

We integrate specific third-party services to enhance functionality and site performance.

6.1 Google Analytics

We use Google Analytics to monitor site traffic. We have enabled IP anonymization to ensure your full IP address is never written to disk. This service is disabled by default and only activates if you provide explicit consent via our cookie banner.

6.2 Facebook Pixel

The Facebook Pixel is used to measure advertising ROI and build marketing audiences. This tracking is only active upon receiving your explicit consent.

6.3 Google Fonts (Non-Selfhosted)

Our website loads fonts dynamically from Google’s servers. This results in the transmission of the visitor’s IP address to Google LLC, including servers located in the United States. This is necessary for the consistent technical delivery of our interface (Art. 6(1)(f)). Transfers to Google LLC are governed by the EU-U.S. Data Privacy Framework.

6.4 Google reCAPTCHA

To prevent automated spam, we implement Google reCAPTCHA on contact and registration forms. This service analyzes hardware and software characteristics. Data processed (including IP addresses) is transmitted to Google LLC in the United States under the EU-U.S. Data Privacy Framework.

7. Data Retention Period

We retain personal data only for the duration necessary to fulfill the purposes defined in Section 3:

  • Financial/Tax Data: Retained for ten (10) years or as required by the applicable Greek Tax Law.
  • Subscription Data: Retained for the duration of the active contract/subscription plus the statutory limitation period for legal claims.
  • Analytics Data: Google Analytics data is configured to expire and be automatically deleted after 14 months.
  • Security Logs: Retained for a maximum of 90 days unless required for an ongoing security investigation.

8. Data Subjects’ Rights under GDPR

As a data subject, you possess the following rights which you may exercise at any time:

  1. Right of Access: Request a copy of the personal data we hold about you.
  2. Right to Rectification: Request correction of inaccurate or incomplete data.
  3. Right to Erasure (‘Right to be Forgotten’): Request deletion of data where it is no longer necessary.
  4. Right to Restriction of Processing: Limit the processing of your data under specific conditions.
  5. Right to Data Portability: Receive your data in a structured, machine-readable format.
  6. Right to Object: Object to processing based on legitimate interests.
  7. Right to Withdraw Consent: Where processing is based on consent (e.g., Analytics/Pixels), you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

To exercise these rights, contact us at info@online-developer.gr. You also have the right to lodge a formal complaint with the Hellenic Data Protection Authority (DPA) (www.dpa.gr).

9. Cookies Policy Reference

For a comprehensive breakdown of the cookies we utilize, their lifespan, and how to manage them, please visit our Cookies Policy: https://online-developer.gr/cookies-policy-ee/

10. Terms of Service Reference

The use of our website and the purchase of services are subject to our Terms and Conditions: https://online-developer.gr/terms-and-conditions/

11. Security Measures and Data Breaches

Online Developer implements rigorous Technical and Organizational Measures (TOMs), including TLS encryption for all data in transit and restricted access controls. In accordance with Article 33 of the GDPR, in the event of a personal data breach, we will notify the Hellenic DPA without undue delay and, where feasible, not later than 72 hours after having become aware of it, unless the breach is unlikely to result in a risk to your rights.

12. Changes to this Privacy Policy

We reserve the right to update this policy to reflect changes in our services or legal obligations. The “Last Updated” date at the bottom of this page will reflect the most recent revision.

13. Contact Information

For any privacy-related inquiries or to exercise your statutory rights, please contact our privacy team:

Email: info@online-developer.gr Address: Ap Paulou 50, Agios Dimitrios – Attikis, 17343, Greece

Last Updated: May 22, 2024

Scroll to Top