DATA PROTECTION POLICY

This document outlines our policy regarding personal data collected from visitors to our pages (hereinafter “users”).

The Data Controller is the company under the name NOMAD INTERNATIONAL GR SINGLE-MEMBER P.C., based in Aktaiou Patras, 4 Thraki St., Postal Code 26504, VAT No. 801581190, Tax Office A’ Patras, and email: [email protected] (“Data Controller”).

In the course of our business activities and website operation, we process data concerning natural persons, including:

  • Customers

  • Partners, acting as processors on our behalf

  • Website visitors

  • Other stakeholders (employees, suppliers)

Our company complies with the General Data Protection Regulation (2016/679 EU GDPR) and all other applicable European and national legislation regarding the protection of personal data, electronic communications, etc., and is committed to always safeguarding your data.

  • Data is collected for specified, clear, and lawful purposes and not further processed in a way incompatible with those purposes.

  • We collect only the necessary personal data for each processing purpose and process it lawfully, fairly, and transparently.

  • We ensure the data is as accurate and up-to-date as possible and retain it only as long as necessary for processing purposes.

  • The retention period is determined based on compliance with legal obligations and the principle of data minimization.

  • We process data both electronically and manually, applying all appropriate measures to protect it from unauthorized or unlawful processing, accidental loss, destruction, or damage.


Collection, Purpose, Legal Basis, and Retention Period of Your Data

Data Automatically Collected via Our Website

The website uses the SSL (Secure Sockets Layer) protocol to encrypt data exchanged between devices, ensuring a secure connection and protecting your personal data.

When you visit our websites https://nomad-international.com , our server collects server log files, specifically:

  • Date and time of access

  • Data volume transmitted in bytes

  • Browser and operating system used

  • IP address during access
    (IP address is considered personal data when combined with date and time)

Legal Basis: Our legitimate interest in securing networks, information, and services, and our legal obligation to provide a secure data environment (GDPR Art. 6(1)(f) and (c)). Data is not transferred or used in any other way, except to investigate unauthorized use.


Customer Data

When visiting our business, we collect personal data like full name, father’s name, email, address, gender, age, occupation, and other information related to our service provision.

Purpose: Service delivery
Legal Basis: Contract performance and legal compliance (GDPR Art. 6(1)(b) and Art. 9(2)(h))
Retention: As required by law or until legal claims arise.

We do not maintain a public directory of users’ email addresses. Any personal data (e.g., usernames) appearing on our website is used solely for service functionality and may not be used by third parties without proper legal compliance.

Data is securely retained while you are subscribed to our services and deleted after your relationship with the Data Controller ends.


Data from Email and Contact Forms

We collect your name, email address, and any other information you provide via email or the contact form.

Legal Basis: Your consent (GDPR Art. 6(1)(a))
Retention: Until communication is complete, unless legal obligations require further storage.


Newsletter Subscription

With your consent, we collect your email to send newsletters and articles you may find interesting.

Legal Basis: Your consent (GDPR Art. 6(1)(a))
You may withdraw your consent at any time.


Supplier Data

To perform our contracts, we collect data from suppliers such as name, address, contact and financial details.

Legal Basis: Contract performance and legal compliance (GDPR Art. 6(1)(b), (c))
Retention: Up to 12 years or as required by tax and legal regulations.


Data Access & Transfers

Your data may be accessed by our employees and authorized personnel only.

We also collaborate with third parties (professionals, consultants, service providers like web hosting, accounting, transport) who may process data on our behalf. These third parties may act as Joint Controllers, Processors, or Authorized Persons. We ensure:

  1. They pass a privacy risk assessment.

  2. They contractually commit to:

    • Following our instructions and relevant laws

    • Notifying us of any security breach

    • Assisting with data subject rights

    • Allowing audits

We may also transfer data to public authorities, legal advisors, and insurers for lawful purposes.

Other than the above, no data is disclosed or disseminated to third parties.

We do not transfer data outside the EU, and if necessary (e.g., using cloud services), it will be done in accordance with GDPR Articles 44+, with safeguards such as consent, standard contractual clauses, or adequacy decisions.


Use of Cookies

To improve site functionality and navigation, and to enhance service provision, we use cookies—text files stored on your computer to remember your preferences and actions (e.g., ad personalization, traffic analysis).

Only the Data Controller and its authorized partners have access to cookie-related data.

You may manage or delete cookies as you wish. See aboutcookies.org for more.

Disabling cookies may affect site functionality.

More info on cookies used:


Data Security & Integrity

We apply reasonable technical and organizational security policies to protect data against loss, misuse, alteration, or destruction.

We restrict access to personal data to those who need it, and require confidentiality from them.

Please note that data transmission over the Internet is not fully secure. We do our best to protect your data but cannot guarantee full security during transmission. After receiving your data, we apply strict procedures to prevent unauthorized access.

We retain data only as long as needed for the original purpose or until deletion is requested, unless law requires longer retention.


Links to Other Websites

Our website may contain links to other websites with different privacy statements. Please read their policies before submitting personal data.

We are not responsible for the content, security, or privacy practices of other sites.


Data Concerning Minors

If we need to process data of minors (under 15, per GDPR), we do so only with written and explicit consent from their legal guardians. We make reasonable efforts to verify the consent, such as by checking ID or other proof.


Data Subject Rights

You may contact us by post or email (see section 1) to exercise your rights under GDPR Articles 15+. These include:

  • Requesting a list of those who have accessed your data

  • Confirming whether we process your personal data

  • Reviewing its content, origin, accuracy, and location

  • Requesting a copy

  • Requesting correction, restriction, or deletion (where applicable)

You may also file complaints with the Hellenic Data Protection Authority, 1-3 Kifisias Ave., Athens 115 23, Greece
Tel: +30-210 6475600
http://www.dpa.gr


Policy Changes

We review this Policy regularly and may modify it at our discretion. Any updates will reflect the new date of revision.

The updated Policy applies from that date. We encourage periodic review to stay informed of any changes.

Last updated: April 2025


Contact Us

For questions, comments, complaints, or to exercise any of your data rights, please contact:
[email protected]