Phostia keeps data collection to a minimum. This notice explains what personal data we collect through phostia.com, why and the rights you have over it under the EU General Data Protection Regulation (GDPR) and Greek data-protection law.
01 Who we are
Phostia trains hospitality, aviation and tourism teams to welcome guests with non-visible conditions. For the purposes of data-protection law, the data controller is Ioannis Vellios, trading as Phostia — a sole proprietorship (ατομική επιχείρηση) based in Athens, Greece.
For any question about this notice or your data, contact us at info@phostia.com.
02 What we collect
We only collect what you choose to send us:
- Enquiry details — when you use our contact form or email us: your name, organisation, role (optional), email address and the content of your message.
- Correspondence — any further emails or messages you send while we discuss working together.
We do not ask for sensitive personal data (such as health information) and would rather you did not send it through the website. If it is relevant to our work together, we will agree separately how it is handled.
03 Why and our legal basis
We use the information above to:
- Reply to your enquiry and answer your questions.
- Prepare a proposal and, if you go ahead, deliver the training you asked for.
- Keep a record of our correspondence.
Our legal bases are taking steps at your request before entering a contract (Art. 6(1)(b) GDPR) and our legitimate interest in responding to people who contact us (Art. 6(1)(f) GDPR).
04 Cookies & analytics
This website sets no tracking or advertising cookies, uses no third-party analytics and does not profile visitors. Your browser may store small, purely functional preferences on your own device; these never reach us. If we ever introduce analytics or a similar tool, we will update this notice first and ask for your consent where the law requires it.
06 How long we keep it
We keep enquiry and correspondence data for as long as needed to deal with your request and for a reasonable period afterwards, in case you come back to us. If our contact does not lead to work together, we delete or anonymise it within 24 months, unless the law requires us to keep it longer (for example accounting records once you become a client).
07 Where it is processed
We aim to keep your data within the European Economic Area (EEA). Where a service provider processes data outside the EEA, we make sure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses.
08 Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data (the "right to be forgotten").
- Restrict or object to our processing.
- Portability — receive your data in a common format.
- Withdraw consent at any time, where we relied on it.
To exercise any of these, email info@phostia.com. We will respond within one month.
09 Contact & complaints
If you believe we have mishandled your data, you can complain to the Greek supervisory authority, the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) at dpa.gr. We would appreciate the chance to put things right first.
10 Changes to this notice
We may update this notice as our website or services change. The date at the top shows when it was last revised. Material changes will be reflected here before they take effect.