securagen.ai
Legal & privacy

Privacy Policy

This notice explains how securagen.ai processes personal data in connection with this public website, our contact channels and, where applicable, our services. It is designed around Regulation (EU) 2016/679 (GDPR), Greek Law 4624/2019, Greek Law 3471/2006 implementing the ePrivacy framework, and relevant AI-transparency requirements where they apply to a particular service.

Last updated: 9 September 2026

01

Corporate transparency

Company name
securagen.ai P.C.
Distinctive title
securagen.ai
Legal form
Private Company (P.C.)
GEMI
185752903000
EUID
ELGEMI.185752903000
VAT / Tax office
802938352 · KEFODE Attikis
Registered seat
Municipality of Marousi, Attica, Greece
Registered address
44 Kifisias Avenue, Building C, 15125 Marousi, Athens, Greece
Share capital
EUR 10,000.00
Management
Dr. Georgios Feretzakis, Manager
02

Scope, controller & legal framework

For personal data processed through this website and its public contact channels, the data controller is securagen.ai P.C., unless a separate contract, data-processing agreement or service-specific notice states otherwise.

This notice applies to website visitors, people who contact us, prospective customers, business counterparts and, where relevant, users of our services. Service-specific processing may be supplemented by contract documents, statements of work, data-processing agreements, instructions for use, product documentation or additional privacy notices.

The principal legal framework relevant to this notice includes the GDPR (Regulation (EU) 2016/679), Greek Law 4624/2019, and Greek Law 3471/2006, which implements the ePrivacy rules for electronic communications and terminal-device access. Where a particular AI system or service falls within the scope of the EU AI Act, relevant transparency and governance obligations under Regulation (EU) 2024/1689, as amended, and applicable Greek implementing legislation are addressed in the service context. This Privacy Policy does not replace service-specific AI Act documentation, data-protection impact assessments, processor agreements or other compliance records where those are required.

03

Data we process

Data you provide directly

  • Identification and contact data such as name, email address, telephone number and company details.
  • Communication content such as messages sent through the website form or by email.
  • Business information relevant to a product enquiry, evaluation, procurement process, pilot, integration requirement or service request.

Technical and security data

  • IP address, browser/device information, access timestamps and related server or security-log information generated by website access.
  • Form-security metadata used for abuse prevention, troubleshooting and incident handling. The contact form uses a short-lived one-way hash derived from the source IP address for rate limiting; raw IP addresses and full user-agent strings are not included in the enquiry email.

Service and AI-related data

  • Depending on the engagement: prompts, documents, inputs, outputs, configurations, audit evidence, logs or other material supplied or generated under the applicable contract.
  • We do not seek special-category personal data through the public contact form. Please do not submit classified, special-category or highly confidential information through the public website unless specifically requested and protected by appropriate safeguards. If special-category personal data are required for a contracted processing activity, the applicable Article 9 GDPR condition and safeguards are addressed in that service context.

Data obtained indirectly

In some business or service contexts, limited personal data may be received from a customer organisation, business counterpart, authorised user, professional/public source or dataset relevant to the agreed service. Where Articles 13 or 14 GDPR require additional information, it will be provided in the appropriate context, subject to any lawful exemption.

Required and optional information

Fields marked as required in the public contact form are necessary for us to receive, assess and respond to the enquiry. If those fields are not provided, we may be unable to process the request. Other fields, such as company/organisation, are optional unless required for a specific business process.

04

Website analytics, cookies & logs

The website is deliberately configured without advertising trackers and without Google Analytics, Meta Pixel, LinkedIn Insight Tag or other behavioural-advertising technologies.

On the production website, Plausible Analytics is loaded for the domain securagen.ai. Plausible Analytics is provided by Plausible Insights OÜ (Estonia) and is used to understand aggregate website traffic such as page views, referral sources, device categories and approximate geographic statistics. According to the provider's current documentation, its analytics service does not use analytics cookies, browser storage or persistent identifiers; raw IP addresses and full user agents are not stored, and visitor analytics data is processed in the EU.

Our hosting provider may generate ordinary HTTP access, error and security logs necessary to deliver the website, maintain availability, troubleshoot failures, prevent abuse and investigate security incidents.

The public contact form itself does not start a PHP session and does not set cookies. If future functionality introduces non-essential cookies, local storage or similar access to a user's terminal equipment, we will reassess the requirements of Greek Law 3471/2006 before that technology is activated and will obtain consent where required.

For more detail, see our Cookies & Analytics Notice.

05

Purposes & legal bases

  • Responding to product and business enquiries: Article 6(1)(b) GDPR where processing is necessary to take steps at the request of the person before a contract, and/or Article 6(1)(f) GDPR for legitimate B2B communication and relationship management.
  • Providing contracted products, pilots, integrations or support: Article 6(1)(b) GDPR where applicable and Article 6(1)(f) GDPR for legitimate operational, support and business-continuity interests; legal obligations may also apply under Article 6(1)(c).
  • Website, form and infrastructure security: Article 6(1)(f) GDPR, based on our legitimate interests in protecting systems, preventing abuse, investigating incidents and maintaining availability, together with applicable legal obligations where relevant.
  • Compliance, audit and legal claims: Article 6(1)(c) GDPR where processing is required by law and Article 6(1)(f) GDPR for establishing, exercising or defending legal claims and maintaining governance records.
  • Privacy-minimised website measurement: Article 6(1)(f) GDPR, based on our legitimate interest in understanding aggregate site performance and improving the website using a cookieless, non-advertising configuration designed to minimise impact on visitors.
  • Consent-based activities: Article 6(1)(a) GDPR only where an activity genuinely relies on consent. Consent may be withdrawn at any time without affecting processing already carried out lawfully.

Where we rely on legitimate interests, those interests generally include secure operation of our website and products, prevention of misuse, B2B relationship management, product improvement, auditability and the establishment or defence of legal claims. The privacy acknowledgement checkbox on the contact form records that the notice was presented; it is not, by itself, the legal basis for processing the enquiry.

06

Recipients & processors

Personal data is shared only where necessary and on a need-to-know basis. Categories of recipients may include hosting and infrastructure providers, security providers, business-email providers, analytics providers, professional advisers, auditors, regulators, courts and public authorities where disclosure is legally required.

  • Hostinger: website hosting and related infrastructure/log processing under the applicable service and data-processing terms.
  • Microsoft 365 / Exchange Online / Microsoft Graph: secure server-to-server delivery of website enquiries to our corporate mailbox and subsequent business correspondence under the applicable Microsoft service and data-protection terms.
  • Plausible Insights OÜ: privacy-oriented aggregate website analytics under its applicable data-processing terms.

Additional processors or subprocessors may be used for a particular contracted service and are addressed through the applicable agreement, service documentation or processor information. We do not sell personal data.

07

AI-specific processing

Security-first processing principles
  • Data isolation: client data is processed in isolated or access-controlled environments as appropriate.
  • Purpose limitation: processing is limited to the agreed purpose and engagement scope.
  • Data minimisation: we seek to process only data necessary for the service.
  • No general model training without authorisation: client data is not used to train general-purpose models without explicit authorisation.
  • Human oversight where required: where automated processing could materially affect individuals, applicable human-review and legal safeguards are addressed according to the service context.

The public website and contact form do not use solely automated decision-making or profiling that produces legal effects concerning a person or similarly significantly affects a person within the meaning of Article 22 GDPR.

Where a contracted AI service involves automated decision-making, profiling, high-risk processing, biometric/emotion-recognition functions, synthetic-content transparency or other regulated AI functionality, the relevant GDPR and AI Act information, safeguards and human-oversight arrangements are addressed in the service-specific context. Where we act as a processor for a customer, the customer may remain the controller for the relevant personal data and the allocation of roles is addressed contractually.

08

Retention

We retain personal data only as long as necessary for the relevant purpose, subject to legal, contractual, tax, accounting, audit and security obligations.

  • Contact-form and general enquiry data: ordinarily retained for up to 24 months from the last substantive communication, unless the enquiry develops into a contractual relationship, a longer period is required by law, or retention is necessary to establish, exercise or defend legal claims.
  • Temporary contact-form rate-limit state: a one-way hash used for abuse prevention is functionally relevant only for the short rate-limit window. Stale rate-limit files older than approximately one hour are removed when the cleanup routine next runs; hosting-level temporary-file maintenance may also remove them.
  • Contract and project records: retained for the duration of the relationship and for periods required by applicable legal, tax, accounting, audit, warranty or claims-related obligations.
  • Technical and security logs: retained according to operational-security needs, provider/configuration settings and incident-handling requirements. We seek to minimise retention where we control the setting.
  • AI service data: governed by the relevant contract, service configuration, agreed retention requirement or controller instruction.
09

International transfers

Plausible states that visitor analytics data for its analytics service is processed and stored in the European Union. Other infrastructure or business-service providers may process data in the EEA and, depending on the applicable service arrangement, may involve access or transfers outside the EEA.

Where a transfer of personal data outside the EEA requires a transfer mechanism, we rely on an applicable mechanism such as an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard under Chapter V GDPR, together with supplementary measures where required. Information about the applicable safeguard, and where appropriate how to obtain a copy subject to confidentiality restrictions, may be requested at contact@securagen.ai.

10

Your rights

Subject to the conditions and limitations of applicable law, you may have the right to be informed, access your personal data, rectify inaccurate data, request erasure, restrict processing, receive data portability where applicable, object to processing based on legitimate interests, withdraw consent where consent is used, and exercise rights relating to certain automated decisions.

To exercise your rights, contact contact@securagen.ai. We may need to verify identity before responding. We aim to respond without undue delay and normally within one month, subject to the extensions permitted by Article 12 GDPR for complex or numerous requests.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority, 1–3 Kifisias Avenue, 115 23 Athens, Greece, telephone +30 210 6475600, email contact@dpa.gr, or through www.dpa.gr.

11

Security

We use technical and organisational measures appropriate to the risks presented by the processing, including access control, encrypted transport, security monitoring, controlled credentials, least-privilege access and process controls proportionate to the service. No method of transmission or storage can be guaranteed to be absolutely secure.

12

Children

This website and our business-facing services are not directed to children. We do not knowingly seek personal data from children through the public website.

Where consent under Article 6(1)(a) GDPR is relied on for an information-society service offered directly to a minor in Greece, Greek Law 4624/2019 provides that a minor aged 15 or over may give the relevant consent; below 15, consent must be given by the minor's legal representative, subject to the conditions of applicable law.

13

Electronic communications & direct marketing

The public contact form is intended for enquiries and does not automatically enrol users in a marketing list. If we introduce direct electronic marketing, we will apply the requirements of Greek Law 3471/2006 and the GDPR, including consent or another permitted basis where applicable and a clear means to object or unsubscribe.

Where personal data are processed for direct marketing, the data subject has the right to object at any time to processing for that purpose, including related profiling.

14

Changes to this Privacy Policy

We may update this notice to reflect legal, technical, product or business changes. Material changes will be reflected in the content and the last-updated date. Where a new purpose of processing requires additional information, that information will be provided before or at the time required by applicable law.

15

Contact

securagen.ai P.C.
44 Kifisias Avenue, Building C
15125 Marousi, Athens, Greece

Email: contact@securagen.ai