Privacy Policy
Last updated: 24/07/2026
Contents
1. Who we are
SYMMETRON 25 is a design-and-construction practice based in Thessaloniki, Greece. For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and Greek Law 4624/2019, we are the controller of the personal data described in this policy — meaning we decide why and how it is used.
- Controller
- SYMMETRON 25 — full registered company name
- Registered address
- Tsimiski 88, 3rd floor, 546 22 Thessaloniki, Greece
- Company register (Γ.Ε.ΜΗ.)
- Γ.Ε.ΜΗ. number
- VAT number (Α.Φ.Μ.)
- Α.Φ.Μ. / tax office
- hello@symmetron25.gr
- Telephone
- +30 2310 00 00 00
We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR. Data protection questions go to the email address above and are handled by named person or role.
2. What this policy covers
This policy explains what we do with personal data collected through this website. It does not cover:
- Data we process under a signed contract for design or construction services, which is governed by that contract and any separate notice given to you at the time.
- Third-party websites we link to. Their operators have their own policies, and we are not responsible for them.
- Data about our employees and job applicants, which is handled under a separate internal notice.
3. What we collect
3.1 Information you give us
When you submit the enquiry form on our Contact page, we collect the name, email address, project type, location or site, and the message you write. Nothing on that form is required beyond your name, your email address and your message — the rest helps us reply usefully, and you can leave it blank.
If you email or telephone us instead, we hold whatever you choose to tell us in that correspondence.
3.2 Information collected automatically
Our hosting provider keeps standard server logs, which record the IP address making a request, the time, the page requested, the referring page and the browser identification string. These are produced by the web server, not by us, and are used for security and to diagnose faults.
We store one cookie of our own — the record of your cookie choice. Others may be set only if you allow them. The Cookie Policy lists every one, what it does and how long it lasts.
3.3 What we deliberately do not collect
We do not run advertising trackers, we do not buy or sell contact lists, and we do not embed third-party fonts, maps or video players that would report your visit to another company. The typefaces this site uses are served from our own server precisely so that visiting does not disclose anything to a third party.
We do not ask for and do not want special category data (Article 9 GDPR) — health, political opinions, religious beliefs and the like. Please do not include such information in an enquiry.
4. Why we use it, and on what legal basis
Article 6(1) GDPR requires a lawful basis for every use of personal data. Ours are as follows.
| What we do | Data used | Legal basis |
|---|---|---|
| Read and reply to your enquiry | Name, email, project details, message | Article 6(1)(b) — steps taken at your request before entering into a contract |
| Keep a record of enquiries and our replies | As above, plus the date and the page you sent it from | Article 6(1)(f) — our legitimate interest in knowing what was agreed and with whom |
| Keep the site available and secure, and investigate abuse | Server logs, IP address | Article 6(1)(f) — our legitimate interest in a working, unabused website |
| Remember your cookie choice | The consent cookie | Article 6(1)(c) — a legal obligation to record and honour that choice |
| Measure how the site is used, if you allow it | Analytics cookies and the data they generate | Article 6(1)(a) — your consent, which you may withdraw at any time |
| Meet accounting, tax and construction record-keeping duties | Contract and billing records | Article 6(1)(c) — compliance with Greek law |
| Establish, exercise or defend legal claims | Whatever is relevant to the claim | Article 6(1)(f) — our legitimate interest in defending ourselves |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights and freedoms, and concluded it is not — the processing is limited to what a person contacting an architectural practice would reasonably expect. You may object to it at any time (see Your rights), and we will stop unless we have compelling grounds to continue.
5. Who we share it with
We do not sell personal data and we do not share it for anyone else’s marketing. We disclose it only to:
- Our hosting provider, hosting company name and country, which stores the website and its database on our behalf as a processor under Article 28 GDPR.
- Our email provider, email provider name and country, through which enquiry notifications and our replies pass.
- Professional advisers — accountants, lawyers, insurers — where they need it and are bound by confidentiality.
- Public authorities, where the law requires it, and only to the extent it requires.
- A buyer or successor, if the practice is ever sold or reorganised, under the same protections set out here.
Every processor works under a written contract requiring them to act only on our instructions, keep the data secure, and delete or return it when the work ends.
6. Transfers outside the EEA
We prefer suppliers who store data within the European Economic Area. Where a supplier processes data outside it, we rely on one of the safeguards in Chapter V GDPR — an adequacy decision by the European Commission under Article 45, or the Commission’s Standard Contractual Clauses under Article 46, together with any additional technical measures the transfer needs.
Current arrangements: list any non-EEA processors and the safeguard relied on, or state “all processing takes place within the EEA”. You may ask us for a copy of the safeguards by emailing us.
7. How long we keep it
We keep personal data only as long as there is a reason to, then delete it.
| Record | Kept for | Why |
|---|---|---|
| Enquiries that do not lead to a project | 24 months from the last message | Enquiries often revive a year or two later; after that the record has no value |
| Enquiries that become projects | For the project, then 20 years after completion | The limitation period for claims relating to construction works |
| Contracts, invoices and accounting records | 10 years | Greek tax and accounting law |
| Server logs | confirm with your host — typically 30 to 90 days | Security and fault diagnosis |
| Your cookie choice | 6 months, then we ask again | Consent should be refreshed rather than assumed indefinitely |
8. Your rights
Under the GDPR you have the following rights over your personal data. They are free to exercise, and we will respond within one month — extendable by two further months for complex requests, in which case we will tell you why.
- Access (Article 15) — a copy of the data we hold about you, and an explanation of what we do with it.
- Rectification (Article 16) — correction of anything inaccurate, and completion of anything incomplete.
- Erasure (Article 17) — deletion, where we no longer need the data, where you withdraw consent we relied on, or where you successfully object. This right gives way where we must keep records by law.
- Restriction (Article 18) — a pause on processing while a dispute about accuracy or lawfulness is resolved.
- Portability (Article 20) — the data you gave us, in a structured, commonly used, machine-readable format, where processing rests on consent or contract and is automated.
- Objection (Article 21) — to processing based on legitimate interests, on grounds relating to your situation. If we ever process for direct marketing, you may object at any time and we must stop immediately.
- Withdraw consent (Article 7(3)) — at any time, without affecting what was lawful beforehand. For cookies, use Cookie settings.
To exercise any of these, email hello@symmetron25.gr. We may ask for enough information to be sure who you are — we are not going to hand your data to somebody else claiming to be you.
9. Complaints
If you think we have handled your data badly, please tell us first: we would rather fix it. You also have the right under Article 77 GDPR to complain to the supervisory authority, which for Greece is the Hellenic Data Protection Authority:
- Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα
- Kifisias 1–3, 115 23 Athens, Greece
- Telephone +30 210 6475600
- Email contact@dpa.gr · www.dpa.gr
If you live or work in another EU country, you may complain to your own national authority instead.
10. Security
We take the measures Article 32 GDPR requires, judged against the risk: the site is served over HTTPS; access to the administration area is limited to named accounts with individual passwords; the enquiry form is protected against automated abuse; software is kept patched; and backups are held by our hosting provider. No system is perfectly secure, and we will notify you and the Authority as Articles 33 and 34 require if a breach is likely to put you at risk.
11. Automated decisions and profiling
We do not make decisions about you by automated means, and we do not profile you, within the meaning of Article 22 GDPR. A person reads every enquiry.
12. Children
This site is aimed at people commissioning building work and is not directed at children. We do not knowingly collect data from anyone under 15, the age of digital consent in Greece under Article 8 GDPR as implemented by Law 4624/2019. If you believe a child has sent us personal data, tell us and we will delete it.
13. Changes to this policy
We update this policy when what we do with personal data changes. The date at the top shows the current version. Material changes will be flagged on the site, and where the change concerns something you consented to, we will ask again rather than assume.