Skip to content

Legal

Privacy Policy

This policy explains which personal data we collect through our website and service, why we need it, how long we keep it and what your rights are, in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.

Last updated:

Διαβάστε στα ελληνικά

The Greek text is the binding version. This English translation is provided for convenience.

1. Data controller

The controller of your personal data is AXIA Energy.

For any question about your data or this policy, contact us at info@axiaenergy.gr.

2. What data we collect

We collect only what is needed to answer your request and provide the service you asked for:

  • Website forms (analysis request, contact, partner interest): full name, email, phone number, whether you are an individual or a business, company name (businesses), company / activity (partners), an indicative monthly energy cost range, subject and message, and your consents with their date.
  • Origin of the request: the page you submitted the form from, campaign parameters (utm) and the referring website, so we know how you found us.
  • Analysis data: if you proceed with an analysis, you give us recent energy bills, which contain consumption, supply point, current tariff and charges.
  • Communications: whatever you write or tell us when we communicate by email or phone.
  • Technical data: your IP address and basic browser details are logged temporarily by our hosting provider for security and abuse prevention (for example, submission rate limiting). We do not link them to you as a person.
  • Statistics cookies: only if you accept them — see the Cookie Policy.

We do not collect special-category data (such as health data) or payment card details through the website.

PurposeDataLegal basis
Answering your request and providing the free analysis / adviceForm data, bill data, communicationsPerformance of a contract or steps taken at your request prior to entering into one (Article 6(1)(b) GDPR)
Assessing a partnership enquiryPartner form dataPre-contractual steps at your request (Article 6(1)(b))
Sending news and offersEmail, full nameYour explicit, optional consent (Article 6(1)(a) GDPR and Article 11 of Greek Law 3471/2006), which you can withdraw at any time
Knowing where requests come from (which campaign or website)utm parameters, referrer, submission pageOur legitimate interest in evaluating our marketing channels (Article 6(1)(f))
Security and abuse preventionIP address, technical dataOur legitimate interest in running the site securely (Article 6(1)(f))
Website usage statisticsGoogle Analytics cookiesYour consent (Article 4(5) of Greek Law 3471/2006)
Complying with legal obligations (e.g. tax) and establishing or defending legal claimsEngagement and contract dataLegal obligation (Article 6(1)(c)) and legitimate interest (Article 6(1)(f))

Providing the fields marked as required in our forms is necessary to process your request; without them we cannot respond. Consent to receive news is always optional and does not affect the service you receive.

4. Who has access to your data

Your data is not sold or handed to third parties for their own purposes. Access is limited to:

  • Our advisors, to the extent needed to handle your request.
  • Processors (service providers) contractually bound to act only on our behalf: Vercel Inc. (website hosting — form data is processed on servers in Frankfurt, EU), Supabase Inc. (database within the EU), Resend Inc. (email notification to us for each request), Sanity AS (website content management) and Google Ireland Ltd. (Google Analytics, only if you accept it).
  • Energy suppliers: only if you decide to enter into a supply contract, only the data required for it, and only on your instruction. From that point the supplier is an independent controller.
  • Referring partners: if you came to us through a partner (for example your accountant), we inform the partner only about the progress of the referral (e.g. “completed”), never about the content of your analysis.
  • Public authorities, where required by law.

5. Transfers outside the European Union

Our database and servers are located in the EU. Some of our providers (Vercel, Resend, Google) are based in the USA and may process limited data there (for example the notification email or technical data). These transfers are covered by the EU–US Data Privacy Framework and/or the European Commission's Standard Contractual Clauses. A copy of the relevant safeguards is available on request.

6. How long we keep your data

  • Requests that do not lead to an engagement: up to 24 months from our last contact, then deleted or irreversibly anonymised.
  • Customers: for the duration of the engagement and, after it ends, for as long as tax and commercial law or the limitation period for claims requires (generally up to 5 years).
  • Consent to receive news: until you withdraw it. We keep the date of consent and withdrawal as evidence.
  • Security logs (IP): for a short period, according to the hosting provider's settings.
  • Your cookie choice: 12 months.

7. Your rights

You have the right to request:

  • access to your data and a copy of it,
  • rectification of inaccurate or completion of incomplete data,
  • erasure (“right to be forgotten”) when there is no longer a reason to keep it,
  • restriction of processing,
  • portability of the data you provided, in a structured format,
  • objection to processing based on legitimate interest, and
  • withdrawal of your consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

To exercise your rights, email info@axiaenergy.gr. We will respond within one month at the latest. We may ask you to confirm your identity to protect your data.

If you believe the processing breaches the law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA): 1-3 Kifissias Ave., 115 23 Athens, Greece, tel. +30 210 6475600, email contact@dpa.gr, www.dpa.gr.

8. Security

We apply appropriate technical and organisational measures: encrypted connections (HTTPS) across the site, storage in an EU database with restricted access, access control for our staff and protection of forms against automated submissions. No system is completely secure; if we detect a breach affecting you, we will notify you as the law requires.

9. Minors and automated decisions

Our services are intended for adults. We do not knowingly collect data from minors; if we discover we have, we delete it.

We do not make decisions about you based solely on automated processing and we do not profile you in ways that have legal effects. Every proposal is prepared by one of our advisors.

10. Cookies

For the cookies and similar technologies the site uses, and how to change your choices, see the Cookie Policy.

11. Changes to this policy

We may update this policy when our services or the law change. The date of the last update appears at the top of the page. We will inform you appropriately of material changes that affect you.