Privacy policy
Last updated: September 5, 2026
What we see, why, for how long, and how one message from you deletes it. Processing is carried out under the General Data Protection Regulation (EU) 2016/679 and Greek Law 4624/2019.
If you are just visiting the site
No account is needed, there is no sign-up, and we set no cookies at all. Whatever you type into the try-it fields on the home page stays in your browser and is never sent to us.
- Traffic measurement: we count page views in aggregate. The measurement is cookieless and carries no identifier that follows you from site to site. Private previews are excluded from it entirely.
- Server logs: technical details of each request (IP address, time, page, browser type) are recorded for the security and operation of the site, for a short period.
If you write to us
When you send an email we process what it contains: your name, your address, and whatever you choose to tell us. The legal basis is taking steps at your request prior to entering into a contract (Art. 6(1)(b) GDPR) or our legitimate interest in answering a question you put to us (Art. 6(1)(f)).
If we sent you a private preview
We sometimes approach professionals who have no website, by sending them a preview that is already built. If you received such a message, here is exactly what happened:
- Source: we collected details your own business has published as business contact details — trading name, city, business email, business telephone and the public link to your maps listing. We buy no lists and we guess no email addresses.
- Use: those details were used to fill in one page and send one message. We do not sell them, share them, or combine them with other sources.
- Legal basis: our legitimate interest in direct marketing to businesses (Art. 6(1)(f) GDPR, read with Recital 47). We balanced that interest against your rights: the data is public business data, minimal in scope, used once, and deleted on its own.
- Duration: the preview expires automatically, typically after 30 days. On expiry your details are deleted from storage and the page stops rendering.
- Objection: you may object at any time, with no reason given, by replying to our message or writing to us. We delete immediately and do not contact you again.
Where the business is a sole trader, its business details may simultaneously be personal data. We treat them as personal data in every case.
Who else sees it
We sell no data and hand none to third parties for their own purposes. Only the following categories of recipient have access, each bound by a processing agreement and only for the purpose assigned to them:
- Technical infrastructure: the services that host the site and store the preview records.
- Email: the service through which we receive and send our correspondence.
- Accounting support: for our clients’ invoicing records, where tax law requires it.
Where a recipient is outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses. The one case in which your browser contacts a third party directly is described in the Cookie policy and concerns the embedded map.
How long we keep it
- Preview details
- Until the link expires — typically 30 days. Deleted thereafter.
- Correspondence
- For as long as the conversation runs and a reasonable period after it, so we can pick up a follow-up. Deleted on request.
- Client invoicing records
- For as long as tax law requires, irrespective of a deletion request.
- Technical logs
- A short period, for security purposes.
Your rights
You have the right of access, rectification, erasure, restriction of processing and data portability, and the right to object to any processing based on our legitimate interest. We take no automated decisions about you and carry out no profiling.
One email to info@myprofessionalsite.com is enough to exercise any of them. We answer within one month at the latest, free of charge.
If you believe we answered you badly, you may complain to the Hellenic Data Protection Authority (1-3 Kifisias Ave., 115 23 Athens, www.dpa.gr).
Security
- All traffic runs over HTTPS only, enforced at the browser level.
- No page loads third-party scripts; the content security policy forbids it.
- Private previews are excluded from indexing by three independent mechanisms and are never cached by an intermediary.
- Expiry is checked on the server, not in the browser, so it cannot be bypassed.
Changes to this policy
If the way we process data changes, this text changes with it, along with the update date at the top.