Phostia
Privacy notice

How we handle your data.

Last updated: 28 September 2026

Phostia keeps data collection to a minimum. This notice explains what personal data we collect through phostia.com, why and the rights you have over it under the EU General Data Protection Regulation (GDPR) and Greek data-protection law.

01 Who we are

Phostia trains hospitality, aviation and tourism teams to welcome guests with non-visible conditions. For the purposes of data-protection law, the data controller is Ioannis Vellios, trading as Phostia — a sole proprietorship (ατομική επιχείρηση) based in Athens, Greece.

For any question about this notice or your data, contact us at info@phostia.com.

02 What we collect

We only collect what you choose to send us:

We do not ask for sensitive personal data (such as health information) and would rather you did not send it through the website. If it is relevant to our work together, we will agree separately how it is handled.

03 Why and our legal basis

We use the information above to:

Our legal bases are taking steps at your request before entering a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to people who contact us (Art. 6(1)(f) GDPR).

04 Cookies & analytics

This website sets no tracking or advertising cookies, uses no third-party analytics and does not profile visitors. Your browser may store small, purely functional preferences on your own device; these never reach us. If we ever introduce analytics or a similar tool, we will update this notice first and ask for your consent where the law requires it.

05 Who we share it with

We do not sell your data or share it for anyone else's marketing. To run the website and reply to you, we rely on a small number of trusted service providers who process data on our behalf and only on our instructions — principally our website hosting provider (which stores the site and any message you send) and our email provider (which carries our correspondence with you). They may use your data only to provide their service to us, never for their own purposes.

06 How long we keep it

We keep enquiry and correspondence data for as long as needed to deal with your request and for a reasonable period afterwards, in case you come back to us. If our contact does not lead to work together, we delete or anonymise it within 24 months, unless the law requires us to keep it longer (for example accounting records once you become a client).

07 Where it is processed

We aim to keep your data within the European Economic Area (EEA). Where a service provider processes data outside the EEA, we make sure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses.

08 Your rights

Under the GDPR you have the right to:

To exercise any of these, email info@phostia.com. We will respond within one month.

09 Contact & complaints

Data protection contact

Phostia — info@phostia.com

Athens, Greece

If you believe we have mishandled your data, you can complain to the Greek supervisory authority, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) at dpa.gr. We would appreciate the chance to put things right first.

10 Changes to this notice

We may update this notice as our website or services change. The date at the top shows when it was last revised. Material changes will be reflected here before they take effect.