Privacy Policy

Last updated: 2025-01-01

This Privacy Policy explains how Clear Edge Solutions ("we", "us", "our") collects, uses, and protects personal data when you visit clear-edge.eu (the "Site") or contact us through it. We are committed to processing your personal data in accordance with the EU General Data Protection Regulation 2016/679 ("GDPR"), the ePrivacy Directive 2002/58/EC, and Greek Law 4624/2019.

1. Data Controller

Clear Edge Solutions LP (Greek: Clear Edge Solutions ΕΕ) is the controller of the personal data collected through the Site within the meaning of Article 4(7) GDPR. Registered office: Alexandroupoleos 20, 11527 Athens, Greece. General Commercial Registry (GEMH) number: 193615201000. Tax identification number (VAT): EL803276546. Competent tax authority: KEFODE Attikis. Legal representative (managing partner): Skevos Papamichail. Email: [email protected]. We are not required by law to appoint a Data Protection Officer (DPO) under Article 37 GDPR, but you may direct any privacy-related question to the email address above.

2. Personal Data We Collect

(a) Information you provide voluntarily: when you submit our contact form, we collect your name, email address, and the contents of your message. (b) Technical data automatically collected: when you load the Site, our hosting and CDN provider receives standard HTTP request data — IP address, user agent string, referrer, and timestamp — for the purpose of delivering the page, mitigating attacks, and maintaining security logs. (c) Anti-abuse data on the contact page: to protect the contact form against automated submissions, we use Google reCAPTCHA v3. When the contact page loads, Google receives your IP address, a hardware/software identifier, browser and device information, and interaction signals (mouse movements, scroll, keystrokes timing) for the sole purpose of producing a bot-risk score. This processing is governed by Google's privacy policy. (d) Language preference: a single cookie ('i18n_redirected') stores your selected language. We do not knowingly collect special categories of personal data (Article 9 GDPR) and we do not collect data from children under 16.

3. Cookies and Local Storage

We use a minimal set of first-party cookies, all listed in detail in our cookie preferences modal (accessible from the footer). (a) Strictly necessary — exempt from consent under Article 5(3) of the ePrivacy Directive: 'i18n_redirected' (stores your selected language, up to 12 months); 'cc_cookie' (stores your cookie-consent choices and timestamp as proof of consent, up to 12 months); '__cf_bm' (set by Cloudflare to distinguish humans from bots and protect the Site against malicious traffic, ~30 minutes); '_cfuvid' (set by Cloudflare to support rate-limiting rules, session-only); '_GRECAPTCHA' (set by Google on www.google.com when reCAPTCHA v3 loads on the contact page; used to distinguish humans from bots and protect the form from spam; ~6 months). (b) Optional — set only with your prior, freely-given consent: Cloudflare Web Analytics. This service is cookieless and privacy-preserving — it does not set cookies, does not fingerprint visitors, and does not store individual IP addresses or track users across sites. We request your consent before loading its measurement beacon. We do not use advertising cookies, tracking pixels, social-media plugins, or analytics that identify individual visitors. We do not use browser local storage or session storage to track you. You may withdraw or change your consent at any time via the 'Cookie preferences' link in the footer.

4. Purposes and Legal Bases for Processing (Article 6 GDPR)

We process personal data only where we have a lawful basis to do so. (a) Responding to your inquiries — legal basis: your consent (Art. 6(1)(a)), given freely when you submit the contact form, combined with our legitimate interest (Art. 6(1)(f)) in handling business communications. (b) Operating, securing, and maintaining the Site — legal basis: our legitimate interest (Art. 6(1)(f)) in ensuring availability, integrity, and security of the Site, including protection against fraud and cyber-attacks. (c) Compliance with legal obligations — legal basis: Art. 6(1)(c), where we are required to retain or disclose data under applicable law.

5. Recipients and Third-Party Processors

We do not sell, rent, trade, or otherwise share your personal data with third parties for marketing purposes. We rely on the following processors, each bound by a Data Processing Agreement compliant with Article 28 GDPR: (i) Cloudflare, Inc. — provides our content delivery network, DNS, DDoS protection, and TLS termination; processes IP addresses and request metadata; data processing addendum: https://www.cloudflare.com/cloudflare-customer-dpa/. (ii) Cloudflare Web Analytics (if enabled on the Site) — provides aggregated, cookieless, privacy-preserving traffic analytics; does not use cookies, does not fingerprint visitors, and does not store individual IP addresses. (iii) Web3Forms (operated by White Cube Online) — receives and forwards contact form submissions to us by email; privacy policy: https://web3forms.com/privacy. (iv) Google LLC (Google Ireland Limited for EU users) — provides reCAPTCHA v3 anti-bot protection for the contact form; processes IP address, device/browser characteristics, and interaction signals to produce a bot-risk score; legal basis: our legitimate interest (Art. 6(1)(f)) in protecting the Site against fraud and automated abuse; privacy policy: https://policies.google.com/privacy; terms: https://policies.google.com/terms. (v) Our hosting provider — stores and serves the Site files. Public authorities may receive data where required by law (e.g., court order).

6. International Data Transfers

Where a processor operates servers outside the European Economic Area (EEA) — notably Cloudflare, Inc. and Google LLC, both established in the United States — transfers are protected by the European Commission's Standard Contractual Clauses (SCCs) under Article 46(2)(c) GDPR, supplemented by additional technical measures (encryption in transit and at rest). Both Cloudflare and Google are certified under the EU–U.S. Data Privacy Framework. We do not transfer data to any country lacking an adequacy decision or appropriate safeguards.

7. Data Retention

We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is deleted or anonymised. Specifically: contact form submissions and resulting email correspondence — up to 24 months from the last interaction; server access logs held by our infrastructure providers — up to 14 days under their default retention; cookie 'i18n_redirected' — up to 12 months from your last visit (you may delete it at any time via your browser). Where we are subject to a longer statutory retention obligation (e.g., tax law), data may be kept for the period required by law.

8. Your Rights as a Data Subject (Articles 15–22 GDPR)

You have the right to: (a) access — obtain confirmation of whether we process your data and a copy thereof; (b) rectification — correct inaccurate data; (c) erasure ("right to be forgotten") — request deletion in the cases listed in Art. 17; (d) restriction of processing under the conditions of Art. 18; (e) data portability — receive your data in a structured, machine-readable format (Art. 20); (f) objection — object to processing based on legitimate interests (Art. 21); (g) not to be subject to automated decision-making, including profiling (Art. 22). You may exercise any of these rights free of charge by emailing [email protected]. We will respond within one month, extendable by two further months for complex requests.

9. Withdrawal of Consent

Where processing is based on your consent, you may withdraw it at any time without giving reasons by emailing [email protected]. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

10. Right to Lodge a Complaint

Without prejudice to any other administrative or judicial remedy, you have the right under Article 77 GDPR to lodge a complaint with a supervisory authority — in particular, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1–3, 11523 Athens, Greece, +30 210 6475600, https://www.dpa.gr — or with the supervisory authority of the EU Member State of your habitual residence, place of work, or place of the alleged infringement.

11. Automated Decision-Making and Profiling

We do not use automated decision-making or profiling within the meaning of Article 22 GDPR. All correspondence is reviewed and handled by people.

12. Children's Privacy

The Site is not directed at children under the age of 16, and we do not knowingly collect personal data from minors. If you believe a child has provided personal data, please contact us so we can delete it.

13. Security Measures

We implement appropriate technical and organisational measures pursuant to Article 32 GDPR, including: TLS encryption for all traffic (HTTPS-only); access controls and least-privilege provisioning on infrastructure; security logging and monitoring; encrypted backups; and use of reputable processors with their own security certifications. No method of transmission over the internet is 100% secure; we cannot guarantee absolute security but maintain procedures to detect, investigate, and remediate incidents.

14. Data Breach Notification

In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours of becoming aware of the breach (Art. 33 GDPR), and notify affected data subjects without undue delay where the risk is high (Art. 34 GDPR).

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last updated" date at the top of the policy indicates the date of the most recent revision. We encourage you to review this page periodically. Material changes will be communicated through a prominent notice on the Site.

16. Contact

For any question regarding this Privacy Policy or to exercise any of your rights, please contact us at: [email protected]. Postal correspondence: Clear Edge Solutions LP, Alexandroupoleos 20, 11527 Athens, Greece (GEMH 193615201000).