certway
Ελληνικά ← Back to site

Privacy Policy

Last updated: 13 June 2026

Certway, established at 10 Omonoia Square, 10431, Athens, VAT No. 801721405, Tax Office KEFODE ATTIKIS, contact email support@certway.gr and telephone 213 038 1235, respects the privacy and personal data of visitors to the website certway.gr.

This Privacy Policy describes how we collect, use, store and protect the personal data you provide to us through the website, in particular through the contact form and the newsletter subscription.

Processing is carried out in accordance with the General Data Protection Regulation, Regulation (EU) 2016/679, as well as applicable Greek data-protection legislation.

1. Data Controller

The controller of the personal data is:

Certway
Registered office: 10 Omonoia Square, 10431, Athens
VAT No.: 801721405
Tax Office: KEFODE ATTIKIS
Email: support@certway.gr
Telephone: 213 038 1235
Website: certway.gr

For any matter concerning the processing of your personal data, you may contact us at: support@certway.gr.

2. What personal data we collect

Through our website we may collect the following data, depending on how you interact with it.

2.1 Data via the contact form. When you complete the contact form, we collect the data you provide, such as your full name, company or organisation, email address, telephone number, message content and any other information you choose to include in your message. Please do not include in your message special categories of personal data or other sensitive information, unless it is strictly necessary for your request.

2.2 Newsletter data. If you subscribe to the company's newsletter, we may collect your email address and, where requested or provided, your full name, company or role, communication preferences, the date and time of subscription, the IP address or other technical record of the subscription, as well as information regarding the status of your consent or unsubscription. Subscribing to the newsletter is optional and is not a precondition for using the website or the contact form.

2.3 Technical website-usage data. During your visit to our website, technical data may be collected, such as IP address, browser type and version, operating system, date and time of visit, pages visited, as well as basic website security and operation data. This data is used mainly for the secure and proper operation of the website.

3. Purposes of processing

We process your personal data for the following purposes:

  • to respond to questions, requests, comments or interest in our services,
  • to provide information about our consulting services,
  • to manage an existing or potential professional relationship, offer or collaboration,
  • to send newsletters or informational communications, where there is a legal basis,
  • for the secure and technically correct operation of the website,
  • to comply with legal obligations.

4. Newsletter and informational communications

The company may send newsletters or other informational communications to users who have subscribed or for whom there is another legal basis in accordance with applicable legislation.

The newsletter may include updates on services, articles, analyses, news, professional or regulatory developments, invitations to events, seminars or presentations, as well as other content relevant to the company's areas of activity.

Subscription to the newsletter is carried out on the user's own initiative, through the relevant form or another available means provided on the website. Where consent is required, it must be freely given, specific, informed and unambiguous.

The user may unsubscribe from the newsletter at any time via the unsubscribe link included in every informational email or by contacting the company at support@certway.gr. Unsubscribing does not affect the lawfulness of processing carried out before it.

The company may keep a record evidencing subscription, consent and unsubscription, to the extent necessary for compliance with the law and for documenting the lawful sending of informational communications.

5. Legal basis for processing

The processing of your personal data is based, as the case may be, on the following legal bases:

PurposeLegal basis
Responding to a request via the contact formLegitimate interest or taking steps prior to entering into a contract
Request for an offer or collaborationSteps taken prior to entering into a contract
Management of an existing collaborationPerformance of a contract
Sending the newsletterConsent or other legal basis provided by law
Documenting newsletter consentLegal obligation or legitimate interest in compliance
Technical website securityLegitimate interest
Compliance with legal or tax obligationsLegal obligation

6. Data retention period

We retain your personal data only for as long as is necessary for the purpose for which it was collected or for as long as required by law.

Data from the contact form is retained, indicatively, for up to 12 months from the completion of the communication, unless a collaboration arises or there is a lawful reason for further retention. Data relating to offers, contracts or the provision of services is retained for as long as required by tax, commercial or other applicable legislation.

Newsletter data is retained for as long as you remain subscribed to the newsletter. After you unsubscribe, limited records documenting the subscription, consent and unsubscription may be retained, where required for compliance and evidentiary purposes.

Technical security records, such as server logs, are retained for a limited period, typically up to 6 months, unless longer retention is required for security reasons or incident investigation.

7. Recipients of personal data

Your personal data is not sold, rented or transferred to third parties for independent commercial purposes.

It may be accessed, only to the extent necessary, by authorised staff or associates of the company, website hosting providers, technical support providers, email, newsletter or CRM providers, cloud service providers, accountants, legal or other professional advisors, as well as public authorities where provided for by law.

When third-party providers process data on our behalf, they act as processors and are bound by appropriate contractual and organisational data-protection obligations.

8. Transfer of data outside the European Economic Area

As a rule, we do not seek to transfer personal data outside the European Economic Area.

However, where technical services, cloud tools, email providers, newsletter platforms, analytics or other digital platforms are used that may entail such a transfer, appropriate safeguards are applied in accordance with the GDPR, such as adequacy decisions, standard contractual clauses and appropriate technical and organisational security measures.

9. Cookies and similar technologies

Simply browsing our website sets no cookies. We use no advertising, tracking or profiling cookies. We use only the following strictly necessary items:

  • Form security cookie (csrftoken) — set only at the moment you submit the contact form or subscribe to the newsletter, to protect against cross-site request forgery (CSRF). If you do not use a form, no cookie is set.
  • Admin session cookie (sessionid) — set only when an authorised administrator logs in to the management area.
  • Language preference — your language choice (Greek/English) is stored locally in your browser (local storage) when you switch languages. It is functional, stays on your device and is not used for tracking.

Where a website-statistics service is used, it operates without cookies, without collecting personal data and without cross-site tracking. In addition, the website hosts all of its resources locally (fonts, images, scripts) and loads no third-party content, so visiting it sends no data to third parties.

As only strictly necessary cookies are used, no cookie-banner consent is required to browse.

10. Security of personal data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, destruction, unlawful disclosure or misuse. These measures include, as the case may be, access control, the use of secure connections, restriction of access rights, regular technical maintenance and organisational data-protection procedures.

11. Rights of data subjects

Under the GDPR, you have the right of access, rectification, erasure, restriction of processing, objection to processing, data portability where applicable, and withdrawal of consent where processing is based on consent.

To exercise your rights you may contact us at: support@certway.gr. We will respond to your request within the statutory deadline, unless an extension is required under the GDPR.

Withdrawal of consent for the newsletter can be done at any time via the unsubscribe link included in informational emails or by contacting support@certway.gr.

12. Right to lodge a complaint

If you consider that the processing of your personal data infringes applicable legislation, you have the right to lodge a complaint with the competent supervisory authority. In Greece, the competent authority is the Hellenic Data Protection Authority, website www.dpa.gr, postal address 1-3 Kifisias Avenue, 115 23 Athens, telephone 210 6475600.

13. Links to third-party websites

Our website may contain links to third-party websites. We are not responsible for the privacy policy, content or data-protection practices of third-party websites. We recommend that you read the respective privacy policy of each website you visit.

14. Communication via email

If you contact us by email, we will process your details and the content of the communication solely to handle and respond to your request or to manage the professional relationship between us.

15. Changes to this Privacy Policy

This Privacy Policy may be amended from time to time to reflect changes in legislation, our services or the way the website operates. The version in force at any given time will be available on our website, indicating the date of the last update.