Last Revised: 2026-08-18 14:36
PRIVACY POLICY & PERSONAL DATA PROTECTION
Article 1. Introduction, Data Controller Identity & Operational Model
1.1. This Privacy and Personal Data Protection Policy (hereinafter the "Policy") defines the principles, procedures, and terms under which the sole proprietorship trading as "Prootzos Online" (hereinafter the "Provider" or "Company") collects, stores, processes, and protects the personal data of natural persons.
1.2. Data Controller Identification (Single Source of Truth):
- Trade Name: Prootzos Online
- Legal Form / Representative: Sole Proprietorship / Prountzos Nikos (CEO)
- Registered Address & Postal Mail: 46 Karkavitsa Str., GR-27131, Pyrgos Ilia, Greece
- Tax Identification: VAT No: EL 047648274 | Tax Office: Pyrgos
- Communication Channels: Tel: +30 2621 121 373 | E-Mail:
contact@prootzos.com - Official Website:
[https://prootzos.com](https://prootzos.com)
1.3. Remote-First Operating Model: The Company operates strictly under a Remote-First model. The registered address serves exclusively as a tax domicile and postal correspondence address. There is no physical retail store, reception office, or walk-in customer support facility. All communications, data subject requests, or commercial transactions are conducted exclusively via the digital channels of the Client Area, email, or telephone.
Article 2. Regulatory Framework & Definitions Registry
2.1. Personal data processing is carried out in full compliance with:
- The General Data Protection Regulation (EU) 2016/679 (GDPR).
- Greek Law 4624/2019 implementing the GDPR framework.
- Directive 2002/58/EC (ePrivacy Directive), as amended, and Greek Law 3471/2006.
- Directive (EU) 2022/2555 (NIS2 Directive) and applicable national cybersecurity legislation.
2.2. All terms utilized within this Policy (such as "Client Area", "Controller", "Data Controller", "Data Processor", "Account Credits", "cgroups") are interpreted strictly in accordance with the definitions established in the Common Definitions Registry [DOC-002].
Article 3. Role Determination: Data Controller vs. Data Processor
3.1. Prootzos Online as Data Controller: The Provider acts as Data Controller for the personal data of its website visitors, registered account holders, and clients, which are collected directly for the purposes of contract performance, billing, identity verification, infrastructure security, and customer support.
3.2. Prootzos Online as Data Processor (Art. 28 GDPR): Regarding all third-party data (end-users, website visitors, or customers of the Client) stored, hosted, or transmitted across the hosting servers (Shared Hosting, Managed VM, Managed Dedicated), the Client acts as the sole and exclusive Data Controller. The Provider acts exclusively as Data Processor.
The terms, technical measures, and reciprocal obligations regarding the processing of hosted third-party data are governed exclusively and restrictively by the Data Processing Agreement (DPA) [DOC-007] and are not expanded by this document.
Article 4. Categories of Personal Data Processed
The Provider collects and processes exclusively the data strictly necessary for the fulfillment of its operational, commercial, and legal obligations:
4.1. Identity & Account Data (Collected via Client Area):
- Full name, company trade name, business registration title.
- Physical registered/residential address, postal code, country.
- Electronic mail address (email), contact telephone number.
- Passwords (stored exclusively in one-way salted cryptographic hash format).
4.2. Tax & Financial Transaction Data:
- Tax Identification Number (VAT/AFM), competent Tax Office (DOY), registered business activity code (KAD).
- Order history, issued invoices and receipts, payment timestamps, payment methods, transaction identifiers (Transaction IDs).
- Prorated Billing Data: Record of prorated credit/charge calculations during automated package upgrades or plan alterations executed via the Client Area.
- Setup Fees & Promotions: Record of non-refundable Setup Fees for Managed VMs/Dedicated and administration of first-billing-cycle discounts pursuant to [DOC-011].
- Account Credits: Record of accounting credits maintained in the billing system pursuant to the Billing Policy [DOC-011] (excluding cash refunds).
- Note: The Provider does not store payment card credentials (PAN, CVV2). Payments are processed directly through licensed payment institutions via tokenized encryption.
4.3. Technical Data & Infrastructure Logs (System & Network Logs):
- Internet Protocol (IP) addresses of visitors and authenticated users.
- Proxy headers (HTTP Request Headers, User Agent, browser type, and OS version).
- Server access and error logs (Apache/Nginx Web Server Access/Error Logs).
- Authentication logs (SSH/sFTP logs, FTP logs, Webmail login logs, Hosting Controller auth logs).
- Network traffic and resource consumption metrics via centralized monitoring systems (Monit/Graylog).
- Mail filtering logs (Rspamd headers, SMTP logs, IP reputations) for outbound abuse and spam prevention.
4.4. Communication & Technical Support Data:
- Content of support requests (Support Tickets) submitted via the Client Area or email-piping.
- Telephone call metadata (timestamp, caller number, duration). Prootzos Online does not record or store the audio content of telephone conversations, unless prior explicit notification and consent are obtained at the beginning of the call.
Article 5. Purposes of Processing & Legal Bases
| Processing Purpose | Data Category | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Contract Execution & Service Delivery: Account provisioning, hosting setup on Controller, DNS zone management, SSL issuance. | Identity Data, Account Credentials, IP Addresses | Art. 6(1)(b): Performance of a contract to which the data subject is party (DOC-001). |
| Billing, Prorated Upgrades & Tax Compliance: Invoice issuance, myDATA reporting, administration of prorated charges and account credits. | Tax Records, Transaction Logs, Billing Address | Art. 6(1)(c): Compliance with a legal tax obligation incumbent upon the Provider (DOC-011). |
| Domain Name Registration: Transmission of registrant details to EETT, ICANN, and Openprovider for domain provisioning/renewals. | Domain Registrant Data (WHOIS/RDAP) | Art. 6(1)(b) & (c): Contract performance and regulatory registrar compliance (DOC-008). |
| Network Security & Abuse Prevention: Enforcement of Firewalls (L1-L4), Fail2ban, cgroups, detection of Outbound Abuse / DDoS / Spam. | Technical Logs, IP Addresses, Graylog Metrics | Art. 6(1)(f): Legitimate interest of the Provider in maintaining infrastructure stability and service continuity. |
| NIS2 Compliance & Significant Incident Management: Cybersecurity logging, mandatory notifications to CSIRT / regulatory bodies. | Incident Logs, Audit Trails, IP Flow data | Art. 6(1)(c): Compliance with a legal obligation (NIS2 Directive). |
| Customer Support & Troubleshooting: Ticket handling, technical diagnostics, account management. | Communication Records, Tickets, Call metadata | Art. 6(1)(b) & (f): Contract performance and legitimate interest in service quality (DOC-004). |
| Website Analytics & UX Optimization: Traffic measurement and UX refinement via Google Tag Manager. | Cookie identifiers, browsing interaction data | Art. 6(1)(a): Explicit prior consent (Opt-in) via Consent Mode v2 (DOC-006). |
Article 6. Cookies, Tracking Technologies & Google Tag Manager
6.1. Principle of Prior Consent (Opt-in): The operation of the Prootzos Online website is governed strictly by the principle of Prior Consent (Opt-in). No non-functional cookies, tracking pixels, or analytics/advertising tags are stored or executed on the visitor's browser without prior explicit, affirmative consent. Consent is collected exclusively via positive action, strictly prohibiting pre-ticked checkboxes. The visitor retains the right to revoke or adjust preferences at any time with equal ease via the permanently accessible cookie settings widget on the website.
6.2. Google Tag Manager (GTM) & Consent Mode v2 Deployment: The tag management platform (GTM) is configured strictly in compliance with Google Consent Mode v2. Prior to consent or in the event of refusal, relevant tags remain blocked or transmit exclusively cookieless anonymous pings.
6.3. Reference to Dedicated Policy: The complete classification of cookies, retention durations, third-party providers, and preference management mechanisms are governed exclusively by the Cookie Policy & Tracking Technologies [DOC-006].
Article 7. Data Recipients & Third-Party Transfers
The Provider does not sell, lease, or distribute personal data to third parties for marketing or commercial exploitation. Transfers occur strictly to the following necessary recipients:
7.1. Domain Name Registries & Accredited Registrars:
- Hellenic Telecommunications and Post Commission (EETT) and registry operators for
.gr/.ελdomains. - Openprovider (Hosting Concepts B.V.) and ICANN for gTLDs/ccTLDs, pursuant to the Domain Registration Policy [DOC-008].
7.2. Infrastructure & Datacenter Operators:
- Partner Data Centers located within the European Union / European Economic Area (EEA) providing physical hardware, colocation, and L1 network perimeter mitigation, bound by strict Data Processing Agreements (DPAs).
7.3. SSL Certificate Authorities:
- Let's Encrypt (Internet Security Research Group - ISRG): Automated transmission of public technical identifiers (Domain Name, Server IP, ACME HTTP-01 challenge tokens) strictly for domain validation and certificate generation under the EU-US Data Privacy Framework or Standard Contractual Clauses (SCCs). Let's Encrypt provisioning via the Controller requires prior, accurate routing of DNS A/AAAA records to our server IP.
- Commercial Certificate Authorities (via Openprovider): For the issuance of commercial SSL certificates ordered by the Client.
7.4. Financial Institutions & Payment Gateways:
- Licensed banks and payment institutions for electronic transaction clearance.
7.5. Public, Judicial & Regulatory Authorities:
- Data disclosure is permitted strictly pursuant to statutory legal obligations, prosecutor orders, judicial rulings, or binding requests from competent supervisory authorities (e.g., Hellenic DPA, EETT, Cybercrime Division, CSIRT) under applicable law and NIS2 requirements.
7.6. International Transfers Outside the EEA: Personal data are stored and processed primarily within the European Economic Area (EEA). If a transfer outside the EEA is required (e.g., for ICANN domain registries or Let's Encrypt ACME verification), it is executed strictly on the basis of European Commission Adequacy Decisions, the EU-US Data Privacy Framework, or Standard Contractual Clauses (SCCs).
Article 8. Data Retention Periods & Automations
The Provider retains personal data strictly for the duration necessary to fulfill the respective processing purposes:
8.1. Client Account & Billing Data:
- Profile data and statutory accounting records are retained for ten (10) years following the end of the respective tax year, pursuant to the Greek Tax Procedure Code.
8.2. Technical Server & Network Logs:
- Web, FTP, and mail access logs, along with Monit/Graylog system records, are retained for up to ninety (90) days and are subsequently deleted or anonymized automatically.
- Logs associated with recorded cyberattacks, unauthorized access attempts (Fail2ban triggers), or Outbound Abuse incidents are placed under Forensic Preservation for up to twelve (12) months for evidence, legal defense, and authority assistance.
8.3. Infrastructure Backups:
- Infrastructure-level Disaster Recovery Backups are maintained pursuant to the retention cycles specified in the Backup, Retention & Disaster Recovery [DOC-010]. Upon fulfillment of an erasure request, data are immediately expunged from active production systems; in encrypted Disaster Recovery backups, data are permanently overwritten upon completion of the automated snapshot rotation cycle.
8.4. Customer Support Records (Support Tickets):
- Closed support tickets are retained within the Client Area for three (3) years following resolution for quality tracking and commercial dispute resolution.
8.5. Automated Cleanup of Inactive Accounts (Data Retention Automation):
- User accounts in the Client Area that remain inactive (with no active services or outstanding balances) for over twenty-four (24) months are automatically subjected to anonymization or permanent profile erasure via native Data Retention Automation routines, excluding statutory tax records.
Article 9. Technical & Organizational Measures (TOMs) & Infrastructure Baseline
Prootzos Online implements state-of-the-art technical and organizational security measures pursuant to the Infrastructure Constraints & Security Baseline [DOC-012]:
9.1. Multi-Tier Perimeter Defense Architecture:
- Tier 1 (Datacenter): Hardware Anti-DDoS mitigation and traffic scrubbing.
- Tier 2 (Proxmox VE): Hypervisor firewalling and virtual switching isolation.
- Tier 3 (Fail2ban): Automated brute-force detection and dynamic host blocking.
- Tier 4 (ufw / iptables): Strict stateful port filtering at the operating system level (Debian).
9.2. Encryption & Transmission Security:
- Mandatory enforcement of modern SSL/TLS cryptographic protocols across all public interfaces (HTTPS for Client Area and Controller, IMAPS, SMTPS, FTPS/sFTP).
9.3. Resource Isolation & Access Control:
- Enforcement of Linux kernel cgroups v2 for strict per-user resource isolation (CPU, RAM, IOPS, Nproc) and Noisy Neighbor prevention. In the Hosting Controller UI, Shared Hosting clients have visibility exclusively over Storage Quota and Traffic Quota metrics.
- Strict prohibition of root shell access. User access is restricted to chrooted FTP or jailed sFTP environments confined within
/var/www/clients/clientX/webY. - Database instances are segregated without
SUPERprivileges or unencrypted remote exposure.
9.4. vHost Options Directives Management & Liability:
- In Shared Hosting environments, vHost configuration parameters are locked.
- In Managed VM and Managed Dedicated environments, custom directive entry in the Options tab is performed under the sole technical responsibility of the Client. Web server daemon crashes resulting from directive syntax errors are logged locally and restored exclusively as a Billable Professional Service [DOC-009].
Article 10. Incident Management, NIS2 Compliance & Suspension Differentiation
10.1. Personal Data Breach Protocols (GDPR Art. 33 & 34): In the event of a personal data breach, the Provider notifies the Hellenic Data Protection Authority (HDPA) within 72 hours of becoming aware of the incident, and informs affected data subjects without undue delay if a high risk to their rights and freedoms is identified.
10.2. NIS2 Notification Timelines (Significant Incidents): For any cybersecurity incident classified as a "Significant Incident" under the objective criteria of the NIS2 Directive (causing severe operational disruption or potential material/non-material damage):
- Within 24 hours (Early Warning): Submission of an early warning to competent authorities (CSIRT / EETT).
- Within 72 hours (Incident Notification): Submission of a detailed notification with initial impact assessment and mitigation steps.
- Within 1 month (Final Report): Submission of a comprehensive Root Cause Analysis (RCA) report.
10.3. Differentiation: Billing Suspension vs. Security Quarantine:
- Commercial Suspension (Billing Suspension): Executed automatically via the Client Area strictly for overdue invoices or service expiration, pursuant to [DOC-011].
- Technical Isolation (Security Quarantine / Null-Route): Imposed immediately and autonomously at the OS, Proxmox hypervisor, Controller, or Firewall (L1–L4) levels, without prior notice, in events of Outbound Abuse, DDoS attacks, Botnets, Crypto Mining, Phishing, or severe cgroups resource threshold breaches, pursuant to [DOC-003] and [DOC-012]. In such cases, the Provider enforces Forensic Preservation over relevant logs for up to 12 months for evidence preservation.
Article 11. Data Subject Rights
Every natural person whose personal data are processed by the Provider retains the following statutory rights under Articles 15–22 of the GDPR:
- Right of Access (Article 15): The right to obtain confirmation as to whether personal data are processed, including processing purposes, categories, and recipients.
- Right to Rectification (Article 16): The right to rectify inaccurate data or complete missing profile details (directly manageable via the Client Area).
- Right to Erasure / "Right to be Forgotten" (Article 17): The right to obtain data erasure when data are no longer necessary or when no overriding legal/tax obligation mandates retention (subject to snapshot backup rotation under [DOC-010]).
- Right to Restriction of Processing (Article 18): The right to restrict processing under defined statutory circumstances.
- Right to Data Portability (Article 20): The right to receive personal data provided by the user in a structured, commonly used, and machine-readable format via the self-service export tools of the Client Area and the Controller. Complex format conversions, custom database extractions, or external server migrations (migrations exceeding 3 sites / 5 GB) are governed by the Professional Services Terms [DOC-009].
- Right to Object (Article 21): The right to object to data processing based on legitimate interests (Article 6(1)(f) GDPR).
- Right to Withdraw Consent: The right to withdraw consent at any time via the persistent cookie settings widget on the website, without affecting the lawfulness of processing based on consent prior to withdrawal.
Article 12. Rights Exercise Procedures, Administrative Fees & Complaints
12.1. Submission Channels (Remote-First Model): To exercise statutory data protection rights, individuals may contact the Provider:
- Registered Clients: By opening a Support Ticket under the "GDPR & Data Protection" department within the authenticated Client Area.
- Visitors / Unregistered Persons: By transmitting an email to
contact@prootzos.com(Subject: "GDPR Data Subject Request").
12.2. Response Timelines & Administrative Fees: Data subject requests are processed free of charge within one (1) month of verified receipt (extendable by 2 additional months in complex scenarios). If requests are manifestly unfounded or excessive, particularly due to their repetitive character, the Provider reserves the right, pursuant to Article 12(5) of the GDPR, to either charge a reasonable administrative fee or refuse to act on the request, providing written justification.
12.3. Right to Lodge a Complaint with Supervisory Authority: If a data subject considers that the processing of their personal data infringes applicable data protection law, they maintain the right to lodge a complaint with the competent supervisory authority:
- Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ)
- Address: 1-3 Kifissias Ave., GR-11523, Athens, Greece
- Switchboard: +30 210 6475600
- Complaints Portal:
www.dpa.gr| E-Mail:complaints@dpa.gr
Article 13. Policy Amendments & Version Governance
13.1. This Policy is integrated into the Document Governance System of Prootzos Online. All modifications are tracked pursuant to the Change Impact Matrix:
- Major Changes (vX.0): Notified to registered clients via email or Client Area alert thirty (30) days prior to effective application.
- Minor / Clarification Changes (v1.X): Effective immediately upon publication on the official website.
13.2. In the event of any linguistic conflict, discrepancy, or ambiguity between translated language versions, the original Greek Master Version shall strictly prevail over all translations.