Legal & compliance
Privacy policy
Last updated:
How evoICT Solutions collects, uses and protects personal data on this website and in the delivery of managed IT and security services.
Who we are
evoICT Solutions is the data controller for personal data collected through this website. Our contact details for privacy matters are set out at the end of this document. For personal data contained in systems we manage on behalf of a client, the client is normally the controller and we act as a processor under a written data processing agreement.
What we collect
- Contact form: your name, email address, company name, the content of your message and your consent record.
- Server logs: IP address, request time, page requested, user agent and referrer, kept for security and troubleshooting.
- Preferences stored on your device: accessibility settings and whether you dismissed the offer bar. These stay in your browser and are never sent to us.
- Service delivery: contact details of client staff, ticket content, device and system telemetry, and any personal data contained in systems, backups or mailboxes we administer.
Why we use it and on what legal basis
- To answer your enquiry and prepare a proposal, on the basis of your consent and steps taken at your request before entering into a contract, under Article 6(1)(a) and 6(1)(b) GDPR.
- To deliver, support and invoice contracted services, on the basis of contract performance, Article 6(1)(b).
- To keep our systems and yours secure, detect and investigate incidents, on the basis of our legitimate interests, Article 6(1)(f).
- To meet accounting, tax and regulatory obligations, including incident reporting duties, on the basis of legal obligation, Article 6(1)(c).
Controller and processor roles
Where we manage infrastructure, backups, mailboxes or endpoints for a client, we process personal data only on that client's documented instructions. Our data processing agreement covers the subject matter and duration of processing, the categories of data and data subjects, confidentiality obligations on our staff, security measures, the use of sub-processors, assistance with data subject requests and breach notification, and deletion or return of data at the end of the engagement, as required by Article 28 GDPR.
Who we share data with
We do not sell personal data and we do not use it for advertising. We share it only with providers that are necessary to run our services, under written agreements. These typically include our cloud and email platform provider, backup and endpoint protection vendors, remote support tooling, our hosting provider, and our accountants. A current list of sub-processors is available to clients on request.
International transfers
We store data in data centres in the European Union or European Economic Area by default. Where a provider processes data outside the EEA, we rely on an adequacy decision or on standard contractual clauses together with any additional safeguards required, and we document that in the relevant agreement.
How long we keep it
- Enquiries that do not lead to a contract: up to 24 months from last contact.
- Client contractual and support records: for the duration of the contract and up to 5 years afterwards, or longer where accounting or tax law requires it.
- Server logs: up to 12 months.
- Data inside managed systems and backups: according to the retention schedule agreed with the client.
Your rights
Under the GDPR you may request access to your personal data, correction of inaccurate data, erasure, restriction of processing, portability, and you may object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting the lawfulness of earlier processing. Please contact us using the details below; we respond within one month.
If you believe we have handled your data unlawfully, you may complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, www.dpa.gr, or to the supervisory authority in your country of residence.
How we protect data
We apply multi-factor authentication, least-privilege access, encryption in transit and at rest, endpoint protection, centralised logging, segregated backups with immutability where appropriate, documented incident response, and staff confidentiality and awareness training. We review these measures periodically and after any significant incident.
Changes to this policy
We update this policy when our processing changes or when required by law. The date of the current version is shown above.
Contact
- AddressevoICT Solutions, Plateia Alonion 1, Alonia, Pieria 60300, Greece
- Phone+30 6988 30 000 6
- Email[email protected]