Last updated: 25 September 2026

This policy explains what personal data we collect when you visit integroflow.com, contact us or become a client, why we collect it, who receives it and what rights you have under the EU General Data Protection Regulation (GDPR).

Who is responsible for your data

The controller of your personal data is Dmitrii Morozan, sole proprietor, who operates IntegroFlow · ΑΦΜ 183161794 · Tilemachou 13, Kato Diminio 20200, Greece. For any question or request about your data, email hello@integroflow.com.

What data we collect

We collect only what we need to answer you, work with you and get paid. What that is depends on how you interact with us:

When you browse the website. Our hosting server records technical data about each request — IP address, browser (user agent), the page requested, date and time — in server logs, which are used for security and troubleshooting. We use no analytics, advertising or tracking tools. The only cookie set for visitors remembers your language; see our Cookie Policy.

When you use the contact form. We ask what you need help with (a website, automation, both or not sure yet), your name and work email and, if you wish, your company name, phone or messenger, budget range, preferred way of communication and a message. Spam is filtered with a hidden form field; there is no third-party captcha. Your submission is sent to us by email. A copy is also kept in the website database, together with your IP address and browser details (user agent), so that no enquiry is lost if an email does not arrive.

When you email, call or message us. We receive your name, contact details and whatever you write to us — by email, by phone or on WhatsApp.

When you become a client. We keep your name, company, billing address, tax or VAT number (ΑΦΜ), contact details, the proposal and agreement, project correspondence and invoices. Invoices are issued through myDATA, the electronic books of the Greek tax authority (ΑΑΔΕ), as Greek law requires.

When you pay. Payment data is handled by Stripe — see “Payments” below.

When you read our blog. The author’s picture in a blog post may be loaded from Gravatar (secure.gravatar.com), a service of Automattic Inc. in the United States. Your browser then connects to Gravatar, which receives your IP address and browser details.

Payments

Card payments are processed by Stripe. You enter your card details on Stripe’s secure payment page — a payment link or an invoice we send you — and not on our website. We never receive or store your full card number or security code (CVC).

In our Stripe account we see your name, email address, the amount and currency, the card brand, the last four digits and expiry date of the card and the card’s country. We use them to match payments to invoices, issue tax documents, make refunds and respond to disputes.

Stripe processes payment data on our behalf and, for some purposes — such as fraud prevention and compliance with financial regulations — as an independent controller. How Stripe handles your data is explained in the Stripe Privacy Policy. Stripe is certified as a PCI DSS Level 1 service provider, and its payment pages are served over encrypted HTTPS connections.

Why we use your data

We use personal data only for the purposes below, each with its legal basis under Article 6(1) GDPR:

  • Answering your enquiry, preparing an assessment and a proposal — steps taken at your request before a contract, Article 6(1)(b).
  • Carrying out a project or support plan and communicating with you about it — performance of a contract, Article 6(1)(b).
  • Invoicing, accounting and tax obligations — compliance with a legal obligation, Article 6(1)(c).
  • Security, fraud prevention and legal claims — keeping the website and our systems safe, preventing misuse of payments, and establishing or defending legal claims such as payment disputes — our legitimate interests, Article 6(1)(f).

We do not sell your data, do not use it for advertising and do not make decisions about you by automated means, including profiling.

Who receives your data

We share personal data only with the providers and bodies we need to run the business:

  • our hosting provider, in the EU, which hosts the website and its server logs;
  • our email provider;
  • Stripe, for payments;
  • Meta (WhatsApp), if you contact us on WhatsApp;
  • Automattic (Gravatar), for author pictures in blog posts;
  • our accountant, for invoices and accounting records;
  • the Greek tax authority (ΑΑΔΕ), through myDATA, as required by tax law.

We may also disclose data to public authorities when the law requires it.

Transfers outside the EU

Stripe, Google, Meta and Automattic are based in the United States or may process data there. These transfers rely on the EU–US Data Privacy Framework, where the provider is certified under it, or on the Standard Contractual Clauses approved by the European Commission.

How long we keep your data

We keep personal data only as long as its purpose requires:

  • Enquiries that do not lead to a contract, including contact form emails and stored form submissions: 12 months after our last contact, then deleted.
  • Agreements, invoices and accounting records: for as long as Greek tax law requires.
  • Other client correspondence and project files: for the duration of our collaboration and afterwards for as long as needed for warranty, support and possible legal claims.
  • Server logs: as set by our hosting provider.

Data we process for our clients

When we build or run automations that handle personal data of our clients’ customers or staff, we process that data on the client’s behalf, as a processor under Article 28 GDPR and under a data processing agreement. That processing is covered by the client’s own privacy policy, not by this one.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • have inaccurate data corrected;
  • have your data erased, unless we must keep it by law;
  • restrict how we use your data;
  • receive the data you gave us in a portable format;
  • object to processing based on our legitimate interests.

To use any of these rights, email hello@integroflow.com. We reply within one month, and we may ask you to confirm your identity first.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), www.dpa.gr, or with the data protection authority of the EU country where you live or work.

Cookies

For visitors, the website sets a single cookie, pll_language, which remembers the language you browse in. We use no analytics, advertising or tracking cookies. The details are in our Cookie Policy.

Security

We protect the data we hold with encrypted connections (HTTPS), access limited to what each service needs, and regularly updated software. Card data never reaches our systems: it stays with Stripe.

Changes to this policy

We update this policy when the way we handle personal data changes — for example, if we ever add analytics. The current version is always on this page, with its “Last updated” date.

Contact

IntegroFlow is operated by Dmitrii Morozan, sole proprietor · ΑΦΜ 183161794 · Tax office ΔΟΥ Κορίνθου · Tilemachou 13, Kato Diminio 20200, Greece. Email hello@integroflow.com, phone +30 694 080 2843, or message us on WhatsApp. You can also reach us through our contact page.

Related policies: Terms of Service, Refund & Cancellation Policy, Cookie Policy.