PERSONAL DATA
Privacy Policy
This policy explains what information we receive when you visit our website or contact us, why we use it and how you can exercise your rights.
Last updated: 8 October 2026
1. Who is responsible for your data
The company below, trading as MDG BUSINESS CONSULTANTS, is the controller for the website mdgbusiness.gr.
- Legal name
- MDG BUSINESS CONSULTANTS SINGLE MEMBER P.C.
- Trading name
- MDG BUSINESS CONSULTANTS
- Registered office
- 7 Patr. Grigoriou Z, 62125 Serres, Greece
- Greek tax identification number
- 803313301
- GEMI registration number
- 194381152000
- EUID
- ELGEMI.194381152000
- info@mdgbusiness.gr
This policy covers the website and initial enquiries. If we provide services to you, we supply additional information about processing associated with that engagement.
2. Information we receive
Contact form and email: your name, email address, optional telephone number and the contents of your communication. Your name, email address and message are needed to handle an enquiry. The form cannot be submitted without them.
Website visits: the hosting server may record IP addresses, access dates and times, requested pages, browser information and error details for operation and security. The contact form also uses an unreadable key derived from the IP address, valid for one minute, to limit repeated submissions.
With your consent to statistics: if Google Analytics 4 is enabled, it may collect cookie identifiers, page views, navigation events and general device and location information.
Please do not send health information, identity documents, passwords or confidential financial documents through the form. We agree a separate method of transmission for such material.
3. Purposes and legal bases
Service enquiries: to respond, understand your needs and, if requested, prepare an engagement. The legal basis is taking steps at your request before entering into a contract, where Article 6(1)(b) GDPR applies. For general questions or communications from a company representative, the basis is our legitimate interest in responding to business communications under Article 6(1)(f).
Operation, security and abuse prevention: our legitimate interest in protecting the website and communications under Article 6(1)(f).
GA4 statistics: your consent under Article 6(1)(a) and applicable cookie rules. Rejecting statistics does not prevent browsing or submitting an enquiry.
Legal obligations and claims: compliance with an applicable legal obligation under Article 6(1)(c), or our legitimate interest in establishing, exercising or defending legal claims under Article 6(1)(f).
We do not use contact form details to enrol you in a newsletter or send advertising messages. We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
4. How long information is kept
Enquiries that do not lead to an engagement are deleted no later than 12 months after the last communication. If an engagement follows, relevant information is retained for the purposes of the service and applicable tax, accounting or other legal obligations for the particular records.
Limited retention for longer may be necessary where a dispute or legal claim remains outstanding. Only information necessary for that purpose is retained.
Technical security logs are retained for the period needed to detect and investigate problems, depending on the hosting provider’s configuration and the incident involved.
Retention of optional cookies and statistics depends on the final settings of the relevant tool and is limited to the period needed to assess and improve the website. Detailed cookie information is completed before analytics is enabled.
5. Access and recipients
Access is limited to authorised company personnel handling your enquiry and, as necessary, hosting, business email and technical support providers. Where providers process information on our behalf, appropriate data protection obligations apply.
Information may be disclosed to competent authorities where legally required, or to professional advisers where needed for a specific matter or legal claim. We do not sell personal data.
If you allow GA4 to run, statistics data is transmitted to Google. Google Ireland Limited is the relevant entity for EEA users. Processing may also take place outside the EEA, including in the United States. Where required, the applicable adequacy decisions or appropriate safeguards, such as standard contractual clauses, apply.
Information about Google’s safeguards and copies are available on Google’s data transfer frameworks page. You can also contact us for information about transfers affecting your personal data.
7. Your rights
Subject to the GDPR’s conditions, you may request access and a copy of your data, correction, erasure or restriction of processing. Data portability applies where automated processing is based on consent or a contract.
You may object to processing based on legitimate interests on grounds relating to your particular situation. Where processing is based on consent, you may withdraw it at any time.
For questions or to exercise your rights, email info@mdgbusiness.gr or write to our registered office: 7 Patr. Grigoriou Z, 62125 Serres, Greece.
We normally respond within one month. Where the complexity or number of requests requires an extension of up to two additional months, we inform you within the first month and explain why. We may request only information needed to confirm your identity.
You may lodge a complaint with the Hellenic Data Protection Authority, 1–3 Kifisias Avenue, 11523 Athens, Greece, telephone +30 210 6475600.
8. Security and policy updates
We limit access and apply measures appropriate to the nature of the communication. No transmission or storage method provides absolute security. Contact us first to agree an appropriate method for sharing confidential material.
We update this policy when the website or our processing changes. The date at the beginning shows the latest update. Material changes requiring fresh consent take effect after that consent is obtained.