Legal
Privacy policy
This policy explains which personal data the abletopower.gr website collects, why it collects them, how long they are kept and what rights you have. It follows Regulation (EU) 2016/679 (GDPR) and Greek law 4624/2019.
Last updated: 9 September 2026 · policy version 1.0
1. Data controller
The controller for the processing described below is AbleToPower — electromechanical applications, established at Γεωργίου Πίνη 60, Μαρκόπουλο Μεσογαίας, Τ.Κ. 19003.
Contact details: telephone +30 22990 25 564 - +30 6944 887 117, email info@abletopower.gr.
VAT number (ΑΦΜ) / company registry number (ΓΕΜΗ): [to be completed]. These identifiers are not published anywhere on the existing company website; they are filled in by the business before publication. No placeholder number has been invented here.
The business is not required to appoint a Data Protection Officer under article 37 GDPR: it carries out no large-scale systematic monitoring and processes no special categories of data on a large scale.
2. What we collect
The site has no user accounts, sells nothing online and builds no visitor profiles. Only the following are collected:
- Contact form data
- Your name, email, phone (optional), subject, the service you are interested in and the text of your message. The IP address and user agent the message was sent from are also recorded, as a safeguard against automated abuse of the form.
- Cookie consent record
- Every time you make a choice in the cookie banner one record is stored: a random consent identifier (UUID), your three choices, how the choice was made (accept all, reject all, custom, withdraw), the policy version, the language, the IP address, the user agent and the date.
- Server logs
- The server automatically records the IP address, date and time, the page requested, the response code and the user agent. These logs serve security and error diagnosis only.
- Traffic statistics
- Only if you have given explicit consent to the “Statistics” category. Without it no measurement script is loaded and no data is sent to any third party.
We collect no special categories of data (article 9 GDPR) and take no decisions based on automated processing or profiling.
3. Purpose and legal basis per category
- Answering your message
- Purpose: to answer your enquiry and, if you ask for one, prepare a quote. Legal basis: article 6(1)(b) GDPR — steps taken at your request prior to entering into a contract.
- Protecting the form against abuse
- Purpose: preventing automated submissions and spam. Legal basis: article 6(1)(f) GDPR — our legitimate interest in the security and operation of the website.
- Proving cookie consent
- Purpose: being able to demonstrate that, and when, you gave or refused consent. Legal basis: article 7(1) GDPR together with article 6(1)(c) — compliance with a legal obligation.
- Website security and stability
- Purpose: detecting errors and attacks through the server logs. Legal basis: article 6(1)(f) GDPR — legitimate interest.
- Statistics and marketing
- Purpose: measuring traffic and, should it ever be added, measuring advertising campaigns. Legal basis: article 6(1)(a) GDPR — your consent alone, which you may withdraw at any time.
4. Retention periods
- Contact form messages: 24 months from our last exchange with you. If the message leads to a project, the related records are kept for as long as tax and civil law require.
- Cookie consent records (including the IP address): 5 years from the record date. This period was chosen so that the proof of consent covers the five-year limitation period for claims.
- Server logs: up to 12 months.
- The consent cookie in your browser: 6 months, after which you are asked again.
Once these periods expire the data is deleted or anonymised.
5. Who receives the data
We do not sell, rent or trade personal data. Access is limited to:
- AbleToPower staff handling customer enquiries;
- the website hosting provider, acting as a processor under a contract meeting article 28 GDPR;
- Google Ireland Limited, only if you have accepted the “Statistics” category;
- public authorities, only where there is a legal obligation to disclose.
6. Transfers outside the European Economic Area
In the default configuration of this website no data is transferred outside the EEA. The site loads no third-party fonts, maps, videos or widgets: before any consent is given not a single request to an external server is made.
If traffic measurement is enabled and you accept it, the related data is processed by Google Ireland Limited inside the EU; any onward transfer to the United States is covered by the EU–US Data Privacy Framework and the European Commission’s standard contractual clauses.
7. Cookies
The cookies and your choices are described one by one in the cookie policy.
8. Security
The site is served exclusively over an encrypted HTTPS connection. Form submissions are protected with a CSRF token, data is stored using parameterised database queries, and server access is restricted. No method of transmission over the internet is absolutely secure, but we apply measures appropriate to the risk, as required by article 32 GDPR.
9. Your rights
As a data subject you have the following rights:
- Access (article 15) — to learn which of your data we hold and receive a copy.
- Rectification (article 16) — to correct inaccurate or incomplete data.
- Erasure, the “right to be forgotten” (article 17) — to have your data deleted, unless a legal retention obligation says otherwise.
- Restriction of processing (article 18).
- Portability (article 20) — to receive your data in a structured, commonly used, machine-readable format.
- Objection (article 21) — to object to processing based on our legitimate interest.
- Withdrawal of consent (article 7(3)) — at any time and as easily as you gave it, through the “Cookie settings” link in the footer. Withdrawal does not affect the lawfulness of processing carried out beforehand.
Exercising these rights is free of charge. We answer within one month, extendable by a further two months for particularly complex requests, in which case we will tell you.
10. Right to lodge a complaint
If you believe the processing of your data breaches the law, you have the right to lodge a complaint with the supervisory authority:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), 1-3 Kifissias Avenue, 115 23 Athens, Greece. Telephone: +30 210 6475600. Website: www.dpa.gr.
We would appreciate it if you contacted us first, so that we can try to resolve the matter directly.
11. Changes to this policy
Every material change comes with an increase of the policy version. When the version changes, your previous cookie consent stops being valid and the banner appears again so that you can decide afresh. The date of the last update is shown at the top of this page.
Change your choices
You can change or withdraw your consent at any time through the “Cookie settings” link in the footer of every page.
Contact us about your data
For any request concerning your data or these terms, write to info@abletopower.gr or call +30 22990 25 564 - +30 6944 887 117. We answer within one month of receiving the request at the latest.