Privacy policy
Last updated: 1 October 2026
This page explains, in plain terms, which personal data we use when you visit our site, when you write to us or request the free audit, and when we approach you ourselves. The General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”), Greek Law 4624/2019 and Law 3471/2006 apply.
1. Who is the controller
The controller is KENOBI ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε. (GEMI no. 172868501000, VAT no. 802244194), with its registered office at Ορφέως 36, 118 54 Αθήνα, which operates the site and the service under the trading name “Citable”.
Contact for personal data matters: hello@citable.gr
We have not appointed a Data Protection Officer (DPO), because the law does not require one in our case. For any matter, write to the contact address above.
2. What data we process, for what purpose and on what legal basis
2.1 Visits to the site (technical data)
- Data: IP address, time and page requested, browser and device type (server logs).
- Purpose: security and proper operation of the site, dealing with abuse.
- Legal basis: our legitimate interest in keeping the site secure (art. 6(1)(f) GDPR).
- Retention: for a limited period, according to the hosting provider’s settings.
2.2 Cookies and statistics
The site uses no cookies and no statistics, advertising or tracking tools. More in the Cookie policy.
2.3 Request for the free audit (“AI visibility audit”)
- Data you give us: full name, business name, your website address (or a note that you have none), email, phone (optional), sector, town or area (optional).
- Data added automatically: language and page from which you sent the request, date and time, the version of the information text you saw and, if you reached the form from a package button, the package you were interested in.
- What we do with it: we carry out the audit of your site and send you the report. The audit is based only on publicly available information (your public site and the answers AI tools give when asked publicly about your business). We need no passwords or access to any of your accounts. We contact you once about the report, and about whatever you reply.
- Legal basis: steps taken at your request before entering into a contract (art. 6(1)(b) GDPR); for the single communication after the report, our legitimate interest (point (f)) in replying to someone who asked us for the audit.
- Retention: 12 months from the request, unless we go on to work together (then section 2.6 applies) or you ask for earlier deletion. The report we send you is kept for the same period, so we can compare it with a later measurement if you ask.
2.4 Email and other messages
- Data: what you write (name, contact details, your message).
- Purpose: to answer your question or prepare a proposal.
- Legal basis: art. 6(1)(b) (pre-contract steps at your request) or (f) (legitimate interest in answering a business enquiry).
- Retention: 12 months from the last contact, unless we go on to work together.
- Please do not send us sensitive data (for example health data) or similar data about third parties.
2.5 Contact that we initiate (email, LinkedIn): information under article 14 GDPR
If you received a message from us without having visited the site, this section explains why.
- Who we are and why we write: we approach businesses and professionals (for example hotels, law and accounting firms, exporters) who we think may be interested in the free audit or in our service, with an individual, personally written message.
- What data we hold: full name, business name and role, business email or LinkedIn profile, your business’s website address, and notes on whether and when we were in touch and what you replied. We may also hold the results of an audit of your public site.
- Where we got it: from publicly available sources (your business’s public website, your public LinkedIn profile, professional directories and registers) or a referral from a partner. We name the source in the message itself when it is not obvious. We do not buy lists and do not use automated collection tools (scraping).
- Legal basis: our legitimate interest (art. 6(1)(f) GDPR) in professionally proposing a relevant service to businesses, in a B2B relationship. We have balanced that interest against your rights: we limit data to what is strictly necessary, we do not build personality profiles, and we stop immediately when you ask. The balancing is documented and we give it to you on request.
- Right to object (art. 21 GDPR): you can at any time, without giving a reason, tell us “do not write to me again”. A reply to our message or an email to hello@citable.gr is enough. We will stop contacting you and keep only the minimum (for example your email or profile name) on a suppression list, so that we do not contact you again by mistake.
- Electronic communications: Law 3471/2006 (art. 11) sets specific rules for unsolicited communications for promoting services. We apply them to messages to companies too. That is why we send individual messages, say who we are, give an easy way to opt out, and stop at your first sign that you are not interested. We do not send bulk or automated messages. On LinkedIn we follow its terms of use.
- When we inform you: our first message contains a short notice and a link to this page (art. 14(3) GDPR).
- Retention: if you do not respond, we delete your data 6 months after our last contact attempt, except for the suppression list (as long as needed to honour your objection). If you do respond, sections 2.3 and 2.4 apply.
2.6 Clients and contracts
If we go ahead, there will be a separate written contract and we will process the data needed to perform it, to invoice, and for our tax compliance (art. 6(1)(b) and (c) GDPR). We keep it for the duration of the engagement and afterwards as long as tax and accounting law requires and, if a dispute arises, until the related claims are time-barred. If during a project we process personal data of clients or of visitors to a client’s site, we deal with it in a separate data processing agreement (art. 28 GDPR).
3. What we do not do
- We do not sell your data and do not use it for third-party advertising.
- We have no newsletter. If we start one, it will be only with your separate, optional consent.
- We have no advertising or tracking tools, and no third-party videos or maps on the site.
4. AI tools and automated decisions
- We take no decisions based solely on automated processing that produce legal effects or significantly affect you, and we do not profile you (art. 22 GDPR).
- The site has no AI assistant (chatbot) and no automated replies. If we add one in future, we will first update this policy and clearly tell you before you use it.
- We use AI tools to work faster on copy and audits. An audit of a business is done by publicly asking AI tools about the business and its sector. TBD: confirm: contact details are never entered into AI tools
- A person edits every audit report before it is sent to you.
5. Transfers outside the European Economic Area
The provider hosting the site and the form (Netlify, Inc.) is based in the USA. The transfer relies on: TBD: legal basis for transfers to Netlify (USA). Where there is no adequacy decision, we require standard contractual clauses and, where needed, supplementary measures (arts 45 and 46 GDPR).
You can ask for a copy of the relevant safeguards at hello@citable.gr.
6. How long we keep data (summary)
| Data | Retention |
|---|---|
| Server logs | A limited period, according to the hosting provider’s settings |
| Free-audit request and report | 12 months from the request, unless we work together |
| Email and other messages | 12 months from the last contact, unless we work together |
| Contacts we approached who did not respond | 6 months from the last attempt |
| Suppression list (people who asked us not to write again) | As long as needed to honour your objection, with the minimum data |
| Clients: contract, invoices | As long as tax and accounting law requires |
When retention ends, we delete or anonymise the data. If a dispute is pending, we keep it until it ends.
7. Your rights
You have the right to:
- access your data and obtain a copy (art. 15),
- rectification (art. 16),
- erasure (“right to be forgotten”) (art. 17),
- restriction of processing (art. 18),
- portability of the data you gave us (art. 20),
- object to processing based on our legitimate interest, and an absolute right to object to processing for direct marketing (art. 21),
- withdraw consent where processing relies on it, without affecting the lawfulness of earlier processing (art. 7(3)).
How to exercise them: write to hello@citable.gr. We reply within one month at the latest (extendable by two months for complex requests, with notice to you). It is free, except for manifestly unfounded or excessive requests. To identify you, we may ask you to confirm that the request comes from you.
8. Complaint to the authority
If you believe we are infringing your rights, you can lodge a complaint with the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ), 1–3 Kifissias Ave., 115 23 Athens, tel. +30 210 6475600, www.dpa.gr. We would appreciate the chance to resolve it first, but you are not obliged to.
9. Security
We use HTTPS, access to data restricted to those who need it, and a “minimum data” rule. No method is absolutely secure; if an incident affecting you occurs, we will make the notifications the law requires (arts 33–34 GDPR).
10. Minors
The site and our services are aimed at businesses and professionals. We do not knowingly collect data of minors.
11. Links to other sites
The site may contain links to third-party services. We are not responsible for their policies; read them before you use them.
12. Changes
We will update this policy when our practices or the law change. The date of the last update is shown at the top. For material changes we will also inform you by another suitable means (for example a notice on the site or an email to those we are already in touch with).
13. Contact
KENOBI ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε., Ορφέως 36, 118 54 Αθήνα · hello@citable.gr