Privacy Policy
How Altrixys collects, uses and protects your personal data — written in plain language, in line with the GDPR.
Last updated: July 2026The short version
- We collect personal data only when you give it to us — through the contact form, one of our free tools, or by emailing us.
- We do not sell your data, we do not run advertising, and we do not profile you.
- Our contact form does not store submissions in a database. They reach us as an email and nothing is kept on the website.
- You can ask us at any time what we hold about you, or ask us to delete it. Write to [email protected] and we will respond within one month.
1. Who we are
Altrixys is a cybersecurity services company based in Athens, Greece. For the purposes of the General Data Protection Regulation (Regulation (EU) 2016/679, the GDPR) and Greek Law 4624/2019, Altrixys is the data controller for the personal data described in this policy.
Contact for anything relating to your data: [email protected]
We have not appointed a Data Protection Officer, as we are not legally required to do so. Data protection enquiries are handled directly by the person responsible for security at Altrixys, using the email address above.
2. What personal data we collect
Data you give us deliberately
Through the contact form: your first and last name, business email address, phone number (optional), company name, country, the nature of your enquiry, and the message you write.
Through our free self-assessment tools (NIS2 Self-Check, Cyber Health Check, GDPR Check): your answers stay in your browser and are never sent to us — unless you choose to email yourself the result. If you do, we receive your email address, your organization name if you provide one, and a summary of your result, so that we can send you the report and, if relevant, follow up.
By emailing us directly: whatever you choose to include in your message.
Data collected automatically
Like every website, our servers keep technical logs. These may include your IP address, browser type, operating system, the pages you visited, and the date and time. We use them for security, for troubleshooting, and to keep the site running.
We also store a record of your cookie choice in your browser. See our Cookie Policy for the detail.
What we do not collect
We do not collect special categories of data such as health, biometric, political or religious data. We do not use advertising or profiling cookies. We do not buy contact lists, and we do not track you across other websites.
3. Why we use it, and on what legal basis
| What we do | Why | Legal basis |
|---|---|---|
| Respond to your enquiry | You contacted us and expect a reply | Pre-contractual steps at your request, or our legitimate interest in answering business enquiries |
| Send you a tool result | You asked us to email it to you | Consent, which you may withdraw at any time |
| Deliver our services | To perform the work you engaged us for | Performance of a contract |
| Keep the website secure | To detect and block attacks, spam and abuse | Our legitimate interest in protecting our systems and visitors |
| Meet legal obligations | Invoices, tax records, statutory retention | Legal obligation |
Where we rely on legitimate interests, we have considered whether they are overridden by your rights. You can object at any time — see section 8.
4. Who we share it with
We do not sell, rent or trade your personal data. We share it only with the service providers we need in order to operate. Each acts as a processor under a written agreement and uses your data only on our instructions:
- Hosting provider — stores the website and its server logs.
- Content delivery and security network — sits in front of the site to speed it up and filter malicious traffic. It processes your IP address for that purpose.
- Email delivery provider — transmits the emails the site sends: your enquiry, your tool result.
- Google Fonts — the typefaces on this site are served by Google, so your browser makes a request to Google and your IP address is processed in the course of it. We mention this because it is the kind of detail most privacy policies quietly omit.
We may also disclose data where we are legally obliged to — for example in response to a lawful request from an authority or a court.
5. Transfers outside the EEA
Some of the providers above may process data outside the European Economic Area. Where that happens, the transfer relies either on an adequacy decision of the European Commission or on Standard Contractual Clauses, with supplementary measures where appropriate. You can ask us which safeguards apply.
6. How long we keep it
- Contact form enquiries — the form saves nothing on the website. The message reaches us as an email and is kept for up to 24 months after our last exchange.
- Tool results you emailed yourself — our copy is kept for up to 12 months, unless you become a client.
- Client records — for the engagement, and afterwards as long as the law requires, typically 5 years for accounting purposes.
- Server and security logs — typically up to 12 months, then deleted or anonymised.
When a retention period ends, the data is deleted.
7. How we protect it
We are a security company, and we hold our own systems to the standard we recommend to clients: encryption in transit, multi-factor authentication on administrative accounts, least-privilege access, hardened server configuration, security headers, disabled legacy interfaces, prompt patching, and monitoring for suspicious activity.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours of becoming aware of it, and we will inform you directly where the law requires it.
8. Your rights
Under the GDPR you have the right to:
- Access — ask what we hold about you and receive a copy.
- Rectification — have inaccurate data corrected.
- Erasure — ask us to delete your data, where no overriding reason to keep it exists.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive the data you gave us in a machine-readable format.
- Objection — object to processing based on our legitimate interests.
- Withdrawal of consent — at any time, where we relied on consent. This does not affect processing that already took place.
To exercise any of these, email [email protected]. We will respond within one month, free of charge, and we will not ask you to justify the request. We may need to verify your identity first, so that we do not disclose your data to someone else.
Right to complain. If you believe we have handled your data improperly, you may lodge a complaint with the Hellenic Data Protection Authority, Kifissias 1-3, 115 23 Athens, www.dpa.gr. We would appreciate the chance to put it right first, but that is your right and you do not need our permission.
9. Children
Our services are aimed at businesses and organizations. This website is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.
10. Changes to this policy
If we change how we handle personal data, we will update this page and the date at the top. Where a change is significant, we will make it obvious rather than quietly editing the text.
11. Contact us
Questions, requests or concerns about your data:
[email protected]
Altrixys — Athens, Greece