Legal

Privacy Policy

Last updated: September 17, 2026

1. Who we are

Data Controller: Fixit E.E., G. Gennimata 54A, Kalamaria, Thessaloniki 55134. Contact email: [email protected].

2. What data we collect

Account
email, name, client_id
Required for authentication
Payments
Nexi transaction references, invoice IDs
We do not store card numbers — payment happens on Nexi's page
Wallet
token transactions, balance, services
For billing and history
Logs
IP, user agent, timestamps
Security + abuse prevention, 90 days
AI conversations
prompts & responses
Stored for the retention window you set — never used for training
Contact form
name, email, company, message
Only to respond to your request

3. Legal basis for processing

  • Contractual obligation (Art. 6(1)(b) GDPR) — to provide the Service.
  • Legitimate interest (Art. 6(1)(f)) — for security, anti-fraud, service improvement.
  • Consent (Art. 6(1)(a)) — for marketing communications (opt-in).
  • Legal obligation (Art. 6(1)(c)) — for invoicing, tax compliance.

4. What we do NOT do

  • We do not sell or rent data to third parties.
  • We do not use your data to train general models without explicit consent.
  • We do not send your prompts to OpenAI, Anthropic, Google or other providers.
  • We do not use tracking pixels (Facebook, Google Ads, etc.) without your consent.

5. Where data is hosted

All data is hosted on servers in Greece and the EU:

  • NVIDIA cluster — Thessaloniki (AI inference + databases)
  • Hetzner Germany — backups with encryption at rest
  • Cloudflare — CDN + DDoS protection (edge caching only, no persistent data)
  • Nexi XPay — payment processing (PCI-DSS Level 1)

6. Cookies

We use essential cookies (session, CSRF, language) that need no consent. Only with your consent (cookie banner, Art. 6(1)(a) GDPR) do we enable Google Analytics 4 and Google Ads cookies to measure traffic, conversions and ad performance. Without consent Google receives only anonymous, cookieless signals (Consent Mode). We never send your email, name or account details to Google. You can change your choice at any time from «Cookie settings» at the bottom of every page.

7. Data retention

  • Account: as long as active + 12 months after deletion.
  • Wallet transactions: 7 years (tax obligation).
  • AI conversations: removed by the retention window you set (7 days minimum). With no window set, they are kept until you delete them.
  • Logs / security: 90 days.
  • Contact forms: 24 months after last contact.

8. Your rights

Under GDPR you have the right to:

  • Access — a copy of your data.
  • Rectification — if something is wrong.
  • Erasure — all your data except tax records.
  • Portability — export in JSON/CSV.
  • Objection — to specific processing.
  • Complaint — to the Data Protection Authority.

Exercise of rights: email [email protected] — response within 30 days.

9. Changes to this policy

Material changes are notified by email 30 days before taking effect. Continued use of the Service after a change constitutes acceptance.

Using Talos on your store? The product-specific privacy annex is at api.fixit.gr/privacy