Privacy policy
Your privacy matters. This page explains in simple terms what data we collect, why, how we protect it, and what your rights are. We fully respect the General Data Protection Regulation (GDPR , EU Regulation 2016/679) and Greek Law 4624/2019.
1. Who we are
The data controller is Ourania Grigorakou (sole proprietorship trading as «Ethaura»), based in Greece. You can reach us at info@ethaura.gr for any matter related to your personal data.
2. What data we collect
We collect only what's strictly necessary to serve you:
- Information you provide: name, email, company (optional), project description or meeting topic, plus the selected date, time and meeting format when you book through Aura or the booking page.
- Your AURA conversation: your message and up to the 8 most recent messages in the same conversation are sent through our server to the OpenAI API to generate a reply. Do not enter passwords, card details, health data or other sensitive personal data.
- Necessary technical data: IP address and request time are used temporarily for security, abuse prevention and enforcement of Aura usage limits.
- Analytics data: device/browser type, general geographic location (city level), pages visited. Collected only if you consent to analytics cookies.
- Communication data: if you email us or start a collaboration, we keep correspondence history and billing data (where required).
3. Why we collect it (legal basis)
| Purpose | Legal basis (GDPR Article 6) |
|---|---|
| Responding to your request via form/email | Consent & pre-contractual measures , Art. 6(1)(a), (b) |
| Checking availability, scheduling an introductory meeting and sending a Google Calendar/Meet invitation | Pre-contractual measures , Art. 6(1)(b) |
| Executing agreed project | Contract , Art. 6(1)(b) |
| Invoicing & tax obligations | Legal obligation , Art. 6(1)(c) |
| Site usage analytics | Consent , Art. 6(1)(a) |
| Providing replies through Aura | Pre-contractual measures & legitimate interest , Art. 6(1)(b), (f) |
| Aura security and abuse prevention | Legitimate interest , Art. 6(1)(f) |
| Improving our services | Legitimate interest , Art. 6(1)(f) |
| Advertising performance measurement (Meta Pixel) | Consent , article 6(1)(a) |
4. How long we keep it
- Form requests and booking details: up to 24 months from last contact.
- Client data: for the duration of our collaboration plus 5 years after.
- Invoices & tax documents: 10 years, as required by Greek tax law.
- Analytics cookies: maximum 14 months.
- Aura conversation on your device: until the browser tab closes or after 30 minutes of inactivity. We do not keep a conversation database on our server.
- OpenAI API: requests are sent with application storage disabled (
store: false). Under standard API settings, content may be retained in abuse-monitoring logs for up to 30 days, unless longer retention is required by law or for security. API data is not used to train models unless the customer explicitly opts in to share it. - Aura security counters: pseudonymised request counters for up to 48 hours.
5. Who we share it with
We never sell your data. We share it only with the following types of service providers, under a Data Processing Agreement:
- Google services (Calendar, Meet and email) , for appointment scheduling, invitations, online meetings, and storing correspondence and project files.
- Form providers (Formspree) , for receiving contact form submissions.
- AI provider (OpenAI Ireland Ltd / OpenAI), to generate Aura replies through the API. Conversation history is sent only when you send a message.
- Website analytics (Google Analytics 4, Google Ireland Ltd) , for anonymous traffic measurement. Activated only after your consent to statistics cookies.
- Advertising measurement (Meta Pixel, Meta Platforms Ireland Ltd) , for measuring ad performance on Facebook and Instagram. Activated only after your consent to marketing cookies.
- Accounting office , for invoicing and tax filings.
- Judicial authorities , only when legally required.
6. International transfers
We use only providers that offer the appropriate safeguards under Chapter V of the GDPR. In detail:
| Provider | Place of processing | Safeguard |
|---|---|---|
| Google Ireland Ltd (Workspace, Analytics) | European Union | EU-based counterparty, Article 28 processing agreement |
| Meta Platforms Ireland Ltd (Pixel) | European Union | EU-based counterparty, Article 28 processing agreement |
| Formspree Inc. (contact form) | United States | European Commission Standard Contractual Clauses |
| OpenAI Ireland Ltd / OpenAI (Aura API) | EU and global infrastructure | Data Processing Agreement; Standard Contractual Clauses or an adequacy decision for transfers outside the EEA |
If any provider ceases to offer adequate safeguards, we stop using it. You may request a copy of these safeguards by emailing info@ethaura.gr.
7. Your rights
Under GDPR, you have the right to:
- Access , request a copy of all your data.
- Rectification , request correction of inaccurate data.
- Erasure ("right to be forgotten") , request your data be deleted.
- Restriction of processing , under specific conditions.
- Portability , receive your data in structured form.
- Object , to processing based on legitimate interest.
- Withdraw consent , at any time.
Email us at info@ethaura.gr. We'll respond within 30 days.
8. Withdrawing your consent
Where processing relies on consent (statistics cookies, advertising measurement cookies, sending your request through the form), you may withdraw it at any time, without giving reasons and with no consequences for you:
- By clicking "Cookie settings" in the footer of any page.
- By emailing info@ethaura.gr.
Withdrawal applies going forward and does not affect the lawfulness of processing carried out before it.
9. Automated decision-making
We do not make decisions about you based solely on automated processing, and we do not carry out profiling within the meaning of Article 22 GDPR.
Our digital assistant AURA uses generative AI to produce informational replies. Replies may contain errors and are not a binding offer. It does not evaluate you, categorise you or make decisions about you or about working together. Every substantive decision and final proposal is confirmed by a person. You can always ask to speak with the team.
10. Minors
Our services are aimed at businesses and adults. We do not knowingly collect data from children under 15 years old (the threshold set by Greek law 4624/2019, article 21). If we become aware that we have received such data, we delete it immediately. If you are a parent or guardian and believe this has happened, please write to info@ethaura.gr.
11. Right to lodge a complaint
If you believe we've violated your rights, you may file a complaint with the Hellenic Data Protection Authority (HDPA):
- Kifisias Ave. 1-3, PC 11523, Athens, Greece
- Tel: +30 210 6475600
- Email: contact@dpa.gr
- Web: www.dpa.gr
12. Security
We apply appropriate technical and organizational measures: HTTPS/TLS encryption, access controls, staff training, regular backups.
We choose providers with independently certified security. Our contact form provider (Formspree Inc.) holds SOC 2 Type II certification and incorporates its data processing terms (DPA) into its privacy policy, acting as a data processor on our behalf. For transfers outside the EU it applies the European Commission's Standard Contractual Clauses.
13. Changes to this policy
We may update this policy. The latest version will always be available on this page. We'll notify you of material changes.
← Back to home