At Exindium, we respect your privacy and aim to be transparent about how personal data is handled when you visit exindium.com or communicate with us.
Understanding how we protect your personal data.
Your Data,
Your Rights.
This Privacy Policy explains what personal data may be processed, why it is processed, how long it may be retained, and the rights available to you under the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable data-protection legislation.
Last updated: September 2026
- Data Controller
The data controller responsible for the processing described in this Privacy Policy is:
Exindium
Greece
Email: info@exindium.com
For questions regarding this Privacy Policy or the processing of your personal data, you may contact us using the email address above.
- Personal Data We Process
Exindium currently does not operate public contact forms, user registration, newsletter subscriptions, or other features that require visitors to submit personal information directly through the website.
However, limited personal data may still be processed in the following circumstances.
Email Communications
If you choose to contact us by email at info@exindium.com, we may receive and process information including:
- your name;
- your email address;
- the content of your message; and
- any other information you voluntarily provide.
Please avoid sending sensitive personal information unless it is necessary for your request.
Technical and Server Information
When you visit our website, our hosting infrastructure may automatically process limited technical information necessary to operate and protect the website.
This information may include:
- IP address;
- browser and device information;
- date and time of requests;
- requested pages or resources;
- server logs; and
- information related to website security and abuse prevention.
This information is primarily used for website operation, security, troubleshooting, and technical maintenance.
Cookies and Similar Technologies
The website may use cookies or similar technologies where necessary for its proper operation.
Where technologies that require consent are introduced, they will be used in accordance with applicable legal requirements.
For more information, please refer to our Cookie Policy.
- Purposes and Legal Basis for Processing
Personal data may be processed for the following purposes.
Website Operation and Security
Technical information may be processed to operate, maintain, secure, troubleshoot, and protect the website and its infrastructure.
The legal basis for this processing is our legitimate interest in maintaining a secure and functional website under Article 6(1)(f) GDPR.
Responding to Communications
If you contact us by email, we process the information you provide in order to respond to your enquiry or request.
Depending on the nature of your communication, the legal basis may be:
- our legitimate interest in communicating with users under Article 6(1)(f) GDPR; or
- processing necessary to take steps at your request before entering into a contract under Article 6(1)(b) GDPR.
Legal Obligations
Where necessary, personal data may be processed or retained in order to comply with applicable laws, legal obligations, or lawful requests from public authorities.
The legal basis for such processing is Article 6(1)(c) GDPR.
- Third-Party Service Providers
We may use third-party service providers where necessary for the operation of Exindium.
These may include providers of:
- website hosting and infrastructure;
- email services;
- website security;
- domain and DNS services; and
- other technical services necessary for operating the website.
These providers may process limited personal data where necessary to provide their services.
Where required by applicable data-protection law, appropriate safeguards are used for such processing.
We do not sell personal data to third parties.
- International Data Transfers
Some service providers may process information outside Greece or the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, appropriate safeguards will be used where required by applicable data-protection law, such as an adequacy decision or approved contractual safeguards.
- Data Retention
Personal data is retained only for as long as reasonably necessary for the purpose for which it was collected or where retention is required by law.
In general:
- email correspondence is retained only for as long as necessary to handle the relevant communication and reasonable follow-up;
- technical and security logs may be retained according to the operational and security requirements of our hosting infrastructure; and
- information required for legal purposes may be retained for the period required by applicable law.
When personal data is no longer required, it may be deleted, anonymised, or otherwise securely disposed of.
- Your Rights
Under the GDPR, and subject to the conditions provided by applicable law, you may have the right to:
- request access to personal data relating to you;
- request correction of inaccurate or incomplete personal data;
- request deletion of your personal data;
- request restriction of processing;
- object to processing based on legitimate interests;
- receive certain personal data in a structured, commonly used and machine-readable format;
- withdraw consent where processing is based on consent; and
- lodge a complaint with a competent supervisory authority.
These rights are not absolute and may depend on the circumstances and legal basis of the processing.
To exercise your rights or ask questions about your personal data, contact:
- Data Security
We take reasonable technical and organisational measures appropriate to the nature of the website and the information processed in order to protect personal data against accidental loss, unauthorised access, alteration, disclosure, or destruction.
However, no method of transmission or storage over the Internet can be guaranteed to be completely secure.
- Third-Party Websites
The Exindium website may contain links to external websites or services, including websites such as WordPress.org.
These third-party websites operate independently from Exindium and may have their own privacy policies and practices.
Exindium is not responsible for the privacy practices or content of third-party websites.
- Right to Lodge a Complaint
If you believe that your personal data has been processed in violation of applicable data-protection law, you have the right to lodge a complaint with a supervisory authority.
In Greece, the competent supervisory authority is the:
Hellenic Data Protection Authority
You may also contact us first at info@exindium.com if you would like us to address a privacy-related concern.
- Changes to This Privacy Policy
We may update this Privacy Policy when our website, services, technologies, or legal obligations change.
Any updated version will be published on this page together with a revised “Last updated” date.
