Privacy Policy
This policy explains which personal data Firstidea may process when you visit the website or contact us, why it is used and which rights are available.
Controller
The controller is Firstidea – Anagnostou Th. O.E. (General Partnership), VAT ID EL802252711, 79 Panepistimiou Street, Patras 26441, Greece. Privacy contact: [email protected].
Data we collect
We may collect information submitted through forms or email, such as name, organisation, email, telephone and enquiry details, as well as technical data such as IP address, browser, timestamps, pages visited and security events.
Please do not submit sensitive data through general contact forms.
Purposes and legal bases
Data is used to respond to enquiries, prepare proposals, provide or support services, protect security, meet legal obligations and improve the website. Depending on context, processing relies on pre-contractual steps or contract, legal obligation, legitimate interests or consent.
Recipients, providers and transfers
Access is limited to authorised people and necessary infrastructure, email, security, analytics or professional providers under appropriate commitments. Where a transfer outside the EEA occurs, the legally required transfer mechanism is used.
Form protection and CleanTalk
Contact forms are protected by CleanTalk Anti-Spam. When a form is submitted, CleanTalk Inc. may receive the IP address, email, name, submitted content and other completed fields, page URL, timestamps, user agent, and browser technical or behavioural data solely to detect spam and abuse.
CleanTalk acts as a processor and may use infrastructure in the EU and the United States under the applicable transfer mechanisms. Service logs are retained for up to 7 or 45 days depending on the active plan and settings. More information: https://cleantalk.org/privacy.
If the automatic email handoff fails, the website creates an encrypted recovery copy of the valid enquiry. It is available only to authorised administrators and is automatically deleted within 30 days. No such failure copy is created when the mail transport accepts the message.
Retention and security
Data is kept only for as long as required for its purpose, the contractual relationship, security and legal obligations. Organisational and technical safeguards are applied, although no system can be considered completely secure.
Your rights
You may request access, rectification, erasure, restriction, portability or objection and may withdraw consent. You may also complain to the competent data-protection authority. Additional information may be requested to verify identity and protect data.
Cookies and similar technologies
Strictly necessary cookies support core functions and security. Google Analytics 4 may be used when the visitor enables “Statistics”. Google Ads may be used for campaign-performance and conversion measurement under the separate “Marketing” choice. Details entered in forms, such as name, email, telephone and enquiry content, are not sent to Google Analytics or Google Ads by this setup. Choices can be changed through “Cookie settings” in the footer.
With consent to the “Marketing” category, Firstidea may temporarily store in the browser’s first-party sessionStorage, for up to 12 hours, one campaign-attribution record: the landing-page path; utm_source, utm_medium, utm_campaign, utm_term and utm_content; and, when present, gclid, gbraid and wbraid. The record is removed when the Marketing choice is withdrawn or after a verified successful form submission. If a form is submitted while consent remains in place, these values may accompany the enquiry in Firstidea’s internal email and, if a separately reviewed integration is implemented later, in its CRM, so that the enquiry can be associated with the campaign. Access to internal email is limited to authorised people. This internal handoff does not send the payload to Google Analytics, Google Ads, Meta Pixel or Meta Conversions API. If the automatic email handoff fails, the same values may be included in the encrypted recovery copy described above and are automatically deleted within 30 days.
Children and updates
The website is intended for businesses and professionals and is not directed at children. This policy is updated when data flows or legal requirements change.
Last updated: 23 August 2026.
