lefteros_by SomniusX
EL ↗Say hello

LEFTEROS / PERSONAL NOTES

The 2022 company privacy policy — historical archive

5 October 2022 / LEFTEROS — historical archive

Historical document, not the current privacy notice. This English rendering describes the former company policy, last revised on 5 October 2022. Its accounts, tracking tools, service descriptions and contact details belong to that period. Read the current personal-site privacy notice. The original Greek text is preserved in the archive.

1. Introduction

The former LEFTEROS and lefteros.com website was managed by the Greek sole proprietorship ILIADIS ELEFTHERIOS, providing information-technology distribution, design and development services in Greece. The policy referred to it as “the Company” or “LEFTEROS” and identified it as controller of personal data collected through website visits, the application and online services. Personal data meant information identifying someone directly or indirectly. It named Eleftherios Iliadis as Data Protection Officer.

The policy stated that the company took measures to protect visitor and user information. It formed part of the website’s terms of use and applied to visitors and registered users. The historical text treated use of the website and registration as acceptance of the terms and privacy policy, and described acceptance as consent to the processing set out in it. These historical statements are reproduced here as context, not adopted as the legal basis for this personal website.

The text presented itself as information under Articles 13–14 of Regulation (EU) 2016/679. It asked readers to review what was collected, how it could be used and disclosed, how it was protected, and their choices and rights.

Its scope was the website and online services controlled by LEFTEROS, including collection, processing and management of visitor, user and member data. It instructed people who did not agree not to register or make a booking, or to use the opt-out procedures. It excluded services outside the company’s control and ownership, including linked third-party websites.

2. Browsing

Visitors could browse without supplying information beyond data collected automatically. Registration could collect name, email and telephone, with optional gender, date of birth and residential area. The company reserved the ability to store IP addresses and contact an internet service provider if the terms of use were breached.

3. Personal data and personally identifiable information

3.1 Information collected

The policy listed names, email addresses, mobile numbers and other identifying information needed for services. The original text also referred to managing a reservation with a restaurant and displaying targeted advertising, messages or content; this wording remains part of the historical record rather than a description of this website.

Other listed information included IP address, browser, operating system, cookies, advertising identifiers and device type. Registration required the minimum information described in section 5. GPS or similar technology could determine a location to show relevant messages, data or customised functions.

3.2 Purposes

The stated purposes were operation of the services and lawful transactions. The text referred to the GDPR, Greek data-protection legislation, decisions of the Greek supervisory authority, Law 3471/2006 and the ePrivacy Directive 2002/58/EC as amended by 2009/136/EC. It also described collecting statistical information disconnected from identifying details.

3.3 Opt-out and individual rights

The historical policy provided a contact for withdrawing consent or reaching the named DPO. Personal contact details have been removed from this public archive. Withdrawal was described as not affecting the lawfulness of earlier processing.

The listed opt-outs included the Network Advertising Initiative, Google Ads Settings and disabling device location services. It listed rights to information, access, rectification, erasure, restriction, portability and objection, including matters involving automated decisions or profiling, and a right to complain to the Hellenic Data Protection Authority.

For the current site, use the contact form.

4. Conditional collection and disclosure

4.1 Advertising, statistics and remarketing

The policy described advertising, statistical and remarketing activities involving third-party tools and information collected through use of the website. It directed visitors to the opt-out process in section 3.3. These are historical provisions, not tracking features enabled on the new site.

4.2 Third-party partnerships

Information could be transferred to partners to provide a requested service or a promotional offer. The described integrations included applications and websites using the company’s services through APIs, and APIs or services connected to LEFTEROS.

4.3 Social networks

Sharing features could exchange information with other applications, websites or media. The audience depended on the user’s social-profile settings. Readers were directed to the respective social networks’ privacy policies.

4.4 Mobile notifications

The policy described possible mobile SDK partners, including OneSignal Messaging SDK, for passive collection and personalised notifications. Depending on permissions, the listed information could include email, precise location, Wi-Fi information, installed or active applications, and device or account identifiers such as Android Advertising ID. The text also referred to targeted advertising and content.

Users could usually disable push notifications through their device’s notification settings. Interest-based advertising could be disabled through the device’s Google advertising settings. The policy noted that settings could vary with the device and software version.

4.5 Sale, merger or change of control

In a sale, merger, consolidation, transfer of significant assets, reorganisation or liquidation, the policy allowed transfer or assignment of collected information to relevant third parties. It stated that affected members would be notified before transfer or a change of privacy policy.

4.6 Requests from authorities

The company could disclose information following a lawful request to comply with law, respond to official investigations or valid legal proceedings, or protect its rights, property, website and users.

5. Activities requiring personal information

5.1 Registration

An account required a name, email and password. Optional fields included residential area, date of birth, gender and phone number. Members could view or change account details using their credentials or by contacting LEFTEROS.

5.2 Electronic service assignments

A service assignment required an email, the beneficiary’s name and a contact number, potentially for another person on whose behalf the user acted. Additional service comments were optional. Relevant details were passed to the assigned employee for delivery of the service. Data could be shared with transport companies solely to deliver goods. The policy described confidentiality, purpose limitation and retention for the period needed to perform the service.

5.3 Comments and reviews

Where available, customers could submit comments, reviews and ratings through their accounts. The company could publish or reproduce this material on its website, social media, newsletters, promotional platforms, applications or other controlled channels. The stated attribution was a first name and surname initial, without other personal data. The original policy instructed users who did not want publication or reproduction not to use that feature.

5.4 Polls

Members could be invited to electronic polls and asked for a name and other information relevant to the questions, such as age or role. Votes were described as used only to draw conclusions about the subject, not for other purposes or disclosure to third parties.

5.5 Links to third-party websites

Links could lead to services such as Facebook or Twitter. Information shared through those services was governed by their respective policies and account settings. The company stated that it did not control third-party privacy practices.

6. Cookies

The policy described cookies as small text files stored on a visitor’s device for service access, preferences, statistics or marketing. Browsers could block cookies or warn when they were set, potentially affecting features.

6.1 Necessary cookies

The historical table listed:

Name Purpose Duration / party Operator
ASP.NET_SessionId Keep preferences between pages Session / first party LEFTEROS
cookie-popup* Store cookie preferences 30 days / first party LEFTEROS

The original text described these as necessary for website functions and noted that blocking them could affect operation.

6.2 Statistical cookies

These were described as measuring visits, traffic sources, popular pages and navigation. The historical table listed:

Name Purpose Duration / party Operator
_ga Distinguish users 2 years / third party Google
_gid Distinguish users 24 hours / third party Google
__atuvc Support AddThis sharing buttons 2 years / third party AddThis
__atuvs Support AddThis sharing buttons 2 years / third party AddThis

6.3 Marketing cookies

The text described third-party interest profiles and advertising based on browser, device or IP identifiers. Its table listed _gat, described as throttling requests, for one minute, operated by Google as a third-party cookie. The category and duration are reproduced from the historical policy, not verified descriptions of a present implementation.

7. Operating-system permissions

The policy discussed iOS and Android permission systems for accessing device data, including prompts or settings relating to API features. It stated that required permissions could change over time.

8. IP addresses

The policy described recording the IP address used to access the website and using it where necessary in connection with a breach of the terms of use.

9. General personal-data provisions

Users could contact the company without charge to check, correct, change or delete an account, or stop receiving electronic updates. Identity verification might be requested. Minors were described as not entitled to register. Account holders were responsible for credential confidentiality and for notifying the company of unauthorised access.

The text stated that authorised staff could access data where needed, that handling followed Greek and EU law, and that data was deleted after the relevant transactional relationship ended.

10. Changes and language

The historical policy reserved the ability to change the policy without prior notice, with changes effective on publication, and treated subsequent use as acceptance. It stated that translations were provided for convenience and that the Greek text prevailed in a discrepancy to the extent permitted by law.

Original revision date: 5 October 2022. This archive does not reinstate those terms or the former company’s infrastructure. The current privacy notice describes the personal site.