Last updated: 16 September 2026
Who we are
The nanobyte.gr website is run by NANOBYTE L.P. (NANOBYTE Ε.Ε.), distinctive title NANOBYTE, which operates as Nanobyte Digital Solutions. We are the controller of the personal data described here, which means we decide why and how it is used.
- Registered address: Dimitriou Gounari 227, 166 74 Glyfada, Greece
- General Commercial Registry (GEMI) no.: 177107201000
- VAT no.: EL802478318
- Email for privacy questions and requests: info@nanobyte.gr
In short
- We collect only the personal data you send us through a form, a booking or by email, plus the technical data every web server records.
- If you book a call or a visit, we also receive the time you choose and, depending on the type, your phone number or your office address.
- We use Google Analytics to see how the site is used, but only if you accept it in the bar at the bottom of the page. Decline, and nothing of Google’s is loaded at all. We don’t use advertising or ad-tracking tools.
- There are no user accounts and no payments on this website.
- We don’t sell your data.
- You can ask us at any time for access to your data, or to have it corrected or deleted.
When you contact us or request a demo
You can write to us through the Contact page, the message form in the contact window that opens from buttons across the site, or the demo request form on our EventOS, MaritimeOS and AI Studio pages. We receive:
- Contact page and contact window: your name, email address and message, plus your company if you add it.
- Demo request: your name and email address, your company and message if you add them, and the product the request is about.
- Added automatically: the date and time, the language of the page (English or Greek) and, for contact messages, whether you used the page or the window.
We use this only to reply to you and to discuss the services you or your company are interested in. Legal basis: our legitimate interest in answering the enquiries we receive and discussing possible work with the people and businesses who contact us (Article 6(1)(f) of the General Data Protection Regulation, GDPR). If you contact us about a contract with you personally, the basis is taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
Each submission is saved on our web server, in a folder that is not accessible through the website, and is included in the server’s backups. A copy is also emailed to our company mailbox, info@nanobyte.gr, from which we reply to you. If you email us directly at info@nanobyte.gr, we use your email in the same way and on the same legal basis.
When you book a call or a visit
You can book a free conversation with us in the same contact window that opens from buttons across the site: a video call, a Viber or WhatsApp call, a phone call, or a visit to your office in Attica. We receive:
- The type of conversation, the day and time you choose and, for a Viber or WhatsApp call, which of the two apps to use.
- Your name and email address, plus your company if you add it.
- Your phone number: required for a phone, Viber or WhatsApp call (a mobile number for Viber or WhatsApp) and for an office visit, optional for a video call.
- For an office visit, the address of your office.
- The topic you want to discuss, if you choose one.
- Added automatically: the date and time of the booking, the language of the page (English or Greek), a booking reference, whether, and after how many attempts, our confirmation email reached you (with the mail server’s response), and, if the booking is cancelled, when.
We use this to keep the time for you, to send you a confirmation, to hold the conversation (for example, to call you on the number you gave or to visit the address you gave) and to discuss the services you or your company are interested in. Legal basis: our legitimate interest in answering the requests we receive and discussing possible work with the people and businesses who contact us (Article 6(1)(f) GDPR). If you book a conversation about a contract with you personally, the basis is taking steps at your request before entering into a contract (Article 6(1)(b) GDPR).
As soon as you book, we email a confirmation with a calendar invitation (an .ics file) to the address you gave, and our company mailbox, info@nanobyte.gr, receives a copy of the booking, a short summary of each day’s bookings on the morning of that day, and a warning if our confirmation email to you could not be delivered. Each booking is saved on our web server, in a folder that is not accessible through the website, and is included in the server’s backups. The booking window shows other visitors only which times are still free, never who booked the others.
The conversation itself takes place through an outside service: for a Viber or WhatsApp call, the app you choose; for a video call, the service we use (Google Meet or Zoom). When we call you there or send you a link, that service processes your number or email address under its own terms and privacy policy, and may transfer it outside the EU.
On the confirmation screen you can add the booking to your calendar. The “Add to calendar” button downloads the calendar file from our website through a private link, valid for a limited time, that only your browser receives. If you choose “Add to Google Calendar”, Google receives the title of the conversation, its time and a short note about it — not your name or contact details — and handles them under its own privacy policy. As with any link you follow, Google also receives your IP address and browser details, and links the event to your Google account if you are signed in.
To prevent misuse, one email address can be used for no more than 2 bookings in 24 hours and 3 upcoming bookings, and no more than 3 bookings in any 24 hours can be made from the same IP address. We check the email limits using the bookings we already store; the IP address limit is described under “When you visit the website”.
When you visit the website
As on any website, our server keeps a log of every request it receives: your IP address, the date and time, the page or file requested, the server’s response, the page you came from and your browser’s identification (user agent). The log does not contain anything you type into a form. The server also limits how many requests one IP address can make per second and logs the requests it turns away, together with their IP address. The server’s firewall and security logs may also record the IP address of connections that are blocked.
To keep spam out of our forms we use two simple checks, with no CAPTCHA and no outside service: a hidden field that only automated programs fill in (submissions in which it is filled in are not saved), and a limit of 5 submissions every 10 minutes from the same IP address for each type of form and for the booking window, together with limits of 60 checks for free times every 10 minutes, 3 bookings every 24 hours and 30 downloads of a calendar file every 10 minutes. For these limits, the IP address (for an IPv6 address, its first half) is held only in the server’s working memory. It is not saved with your submission or written to any file, and it is cleared whenever the website application restarts.
Purpose and legal basis: running the website securely and preventing abuse and spam, which is our legitimate interest (Article 6(1)(f) GDPR).
Analytics, only if you accept
We use Google Analytics 4, a service of Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland), to understand how this website is used: which pages people read, how they found us, and whether they reach the point of getting in touch.
Nothing of Google’s is loaded until you press “Accept” in the bar at the bottom of the page. If you decline, or simply carry on reading without answering, no Google script is loaded, no cookie is set and nothing about your visit reaches Google. This is deliberately not the usual arrangement, where the tag loads first and the question comes afterwards.
If you accept, Google Analytics records:
- the pages you open, in what order, and how long you stay;
- how you arrived — a search, a link on another website, a social network, or a direct visit;
- your device type, screen size, browser and language;
- your approximate location (country and city), which Google derives from your IP address and then discards: Google Analytics 4 does not store IP addresses;
- four actions we count as results — sending us a message, booking a conversation, requesting a demo, and subscribing to the newsletter. We record that one of them happened, never what you wrote: no name, email address, phone number or message text is sent to Google.
Purpose and legal basis: your consent (Article 6(1)(a) GDPR, and Article 4(5) of Greek Law 3471/2006 for storing the cookies on your device). You can withdraw it at any time, as described in the next section, and that does not affect what was collected before.
Google handles this data on our behalf, under its data processing terms. We have not linked this property to Google Ads or to any other advertising product, Google signals is switched off, and we have turned off sharing the data for Google’s own products and services. Google deletes it after 14 months.
Who else handles your data
We use a few providers that handle data only on our behalf and on our instructions (processors):
- Hostinger International Ltd (Cyprus): hosts our website and web server, including form submissions, bookings and server logs. The server is in Germany (EU).
- Our email hosting provider: runs our company mailboxes — info@nanobyte.gr, where we receive your emails, form submissions and bookings and reply to them, and web@nanobyte.gr, from which the website sends its emails, including your booking confirmation, and which receives any that cannot be delivered. Its mail servers are in the EU.
- Google Ireland Limited (Ireland): provides Google Analytics, and only if you accept it. It receives the information described above and handles it on our behalf. Google may process it on servers outside the EU.
- Backblaze, Inc. (USA): stores backup copies of our website’s files, including form submissions and bookings, in a data centre in the USA. We keep backups so we can restore the website and your submissions after a failure, which is our legitimate interest (Article 6(1)(f) GDPR).
- Mailchimp (The Rocket Science Group LLC, an Intuit company, USA): will send our newsletter once we connect it. Until then it receives nothing from us.
When you book a conversation, the app or service used for it — Viber or WhatsApp for a call to your mobile, Google Meet or Zoom for a video call — receives your phone number or email address when we call you or send you a link. It is not our processor: it processes that data under its own terms and privacy policy.
We don’t sell your data, and we don’t share it with anyone else unless the law requires it.
Transfers outside the EU
Backblaze and, once connected, Mailchimp are based in the USA. Transfers to them rely on the EU-U.S. Data Privacy Framework, which the European Commission recognises as providing an adequate level of protection. Backblaze’s and Mailchimp’s data processing terms also include the European Commission’s Standard Contractual Clauses; you can ask us for a copy at info@nanobyte.gr. If you accept analytics, Google may also process that data on servers outside the EU; those transfers rely on the same Data Privacy Framework and on the Standard Contractual Clauses in Google’s data processing terms. Separately, when a booked conversation takes place on Viber, WhatsApp, Google Meet or Zoom, or when you add a booking to Google Calendar, that service handles the data it receives as a controller in its own right and may transfer it outside the EU under its own terms.
How long we keep your data
- Contact messages, demo requests and bookings, and the related emails: up to 2 years after our last contact with you (for a booking, after the date of the booked conversation). If your enquiry leads to a project, we keep what the work and our legal obligations (for example, tax records) require, for as long as they require it.
- Newsletter sign-ups: until you unsubscribe or ask us to delete your address.
- Server logs: the website’s request logs up to 8 days; a few system security logs that can record an IP address (for example, of blocked connections) up to 5 weeks. They are then deleted automatically.
- IP addresses for the form and booking limits: only in the server’s working memory, until the website application next restarts.
- Backups: 7 days, then deleted automatically. Data we delete from our server can therefore remain in a backup for up to 7 more days.
- Google Analytics data, and only if you accepted it: 14 months, then deleted automatically by Google. Your answer to the cookie bar stays in your browser until you change it or clear your browser data.
When a set period ends, we delete the data.
Do you have to give us your data?
No. There is no legal or contractual obligation. But to answer an enquiry or demo request we need your name and email address (and, on the contact form, your message). To book a conversation we also need the day and time, a phone number for a phone, Viber or WhatsApp call or an office visit, and your office address for a visit. For the newsletter we need only your email address. The “Company” field is always optional. Server logs are created automatically when you visit the website.
No automated decisions or profiling
We don’t make decisions about you based solely on automated processing that have legal or similarly significant effects on you, and we don’t build profiles of visitors. The only automatic checks are the spam checks and booking limits described above. They can stop a form or a booking from being sent; if that happens, you can email us at info@nanobyte.gr instead.
Your rights
Under the GDPR, and under the conditions it sets for each right, you have the right to:
- access the data we hold about you and get a copy of it;
- have inaccurate data corrected;
- have your data deleted;
- restrict how we process it;
- receive the data you gave us in a structured, commonly used, machine-readable format, or have it sent to another provider (portability), where we use it based on your consent or for steps before a contract;
- withdraw your consent at any time — for analytics, through “Cookie settings” at the bottom of any page; for the newsletter, by unsubscribing. This does not affect the lawfulness of what we did before you withdrew it.
Your right to object: where we use your data based on our legitimate interest (enquiries, bookings, server logs, spam protection and backups), you can object at any time for reasons relating to your particular situation. We will then stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. You can also stop receiving our newsletter at any time, without giving a reason.
To use any of these rights, email info@nanobyte.gr. It is free of charge. We reply within one month, and we may first ask you to confirm that the email address is yours.
If you think we handle your data unlawfully, you can complain to the Hellenic Data Protection Authority, Kifissias 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, www.dpa.gr, or to the data protection authority of the EU country where you live or work. You are welcome to contact us first so we can try to resolve it.
Children
Our website is meant for businesses, not children. We don’t knowingly collect data from anyone under 18. If you think a child has sent us personal data, let us know and we will delete it.
Our mobile apps
Our mobile apps NB Scanner and Nano Scan are not covered by this policy. Each has its own:
Changes to this policy
We will update this policy when the website or the way we handle data changes, for example when we add a new tool or service. The date at the top shows the current version. Before we use your data for a new purpose, we will tell you.
