ELIAS KALYVAS

Privacy Policy

Effective: 2026-10-06 · Last updated: 2026-10-06 · Version 1.0

1. Controller and scope

Elias Kalyvas, Athens, Greece, operates this professional website and is the data controller for the website enquiries, meeting administration and security processing described here. Contact: info@eliaskalyvas.gr. This policy covers the website and its public contact and booking facilities; linked products and external platforms have their own policies.

2. Contact and enquiries

When you send a message, we process your name, email address, message, selected interest and language, together with a submission identifier, creation time and processing status. These details are stored in Supabase and used to respond, discuss collaboration and manage your enquiry. An owner notification may include your submitted details. If you choose the email alternative, your email service processes the draft and delivery; the website prepares the details you supplied in a mailto link.

We rely on steps taken at your request before a possible contract (Article 6(1)(b) GDPR), where applicable, or our legitimate interest in responding to genuine professional enquiries (Article 6(1)(f)). Providing the relevant form fields is necessary to submit the enquiry; you are not obliged to contact us. Please avoid including sensitive personal information or unnecessary information about other people.

3. Booking and meeting management

Booking processes your name, email, topic or reason, selected start/end time, timezone and language. It also uses booking references, status, revision, timestamps, submission identifiers, payload hashes and protected management links/tokens to prevent duplicate submissions and support rescheduling or cancellation. Calendar event identifiers, meeting links and synchronisation status support delivery of the requested meeting.

Supabase stores the booking and notification tasks. Google Calendar is used to check availability and create or update calendar resources; Google Meet provides a meeting link. The meeting name/topic and relevant scheduling details may be processed by Google. Required confirmations, changes and cancellation notifications are sent to the attendee and operator through Resend and may include an .ics attachment and management link. Notification records contain delivery status, recipient information and provider references.

The basis is taking steps at your request before possible professional collaboration (Article 6(1)(b)), where applicable, and legitimate interests in administering requested meetings (Article 6(1)(f)). Without required booking details we cannot arrange the meeting. Meeting recordings are not part of this website booking flow; any separate recording or additional meeting processing requires its own information and lawful basis. Keep management links private.

4. Technical information and anti-abuse protection

Hosting, network and security providers may process IP/network information, browser/device and request metadata, timestamps and technical logs to deliver and secure the website. The website API uses an infrastructure-provided IP address to derive a salted hash for rate-limit buckets; it does not add the raw IP to the enquiry or booking record. The API verifies Turnstile tokens and uses a honeypot to reject abusive submissions. Cloudflare may process technical verification information through its security service.

These measures serve our legitimate interest in preventing spam, fraud and attacks and maintaining availability (Article 6(1)(f)). Security checks may reject a request or require another verification attempt. They do not constitute decisions producing legal or similarly significant effects.

5. Cookies, local storage and preferences

The website uses necessary technical/security mechanisms and browser local storage to remember cookie preferences. The preference record contains a version, necessary/analytics/marketing choices and an ISO timestamp. It is stored on your browser, rather than sent to a website consent database. Browser storage is covered by these preferences even where it is not an HTTP cookie.

Necessary operation and security mechanisms remain available when non-essential categories are rejected, including Turnstile for contact and booking. There is currently no analytics or advertising tracker enabled by this website. Analytics and marketing categories are inactive and off; Accept all therefore does not authorise unknown future tracking. You can reopen Cookie Preferences, change your choices or clear browser storage at any time. If storage is blocked, a preference may not persist across visits.

Any future non-essential tracking will require prior, specific consent (Article 6(1)(a) GDPR where personal data is involved, and applicable electronic communications rules). Withdrawal does not affect the lawfulness of processing before withdrawal.

6. Providers and recipients

GitHub Pages currently hosts the preview website and delivers its static assets. Supabase provides the database, Edge Functions and supporting website infrastructure. Google Calendar/Meet support requested scheduling and meetings. Resend delivers enquiry and booking notifications. Cloudflare Turnstile provides anti-abuse verification. Providers process the information needed for their respective functions; their role may also include independent processing for their own service security or legal obligations.

Access to enquiry and meeting records is intended for the operator and authorised service providers. We may disclose information when required by law or where necessary and proportionate to establish, exercise or defend legal claims. Submitting an enquiry or booking does not subscribe you to marketing.

7. International processing

Some providers may process data using infrastructure outside the European Economic Area. Where a transfer takes place, the applicable GDPR conditions and lawful transfer mechanisms are required. The relevant safeguards depend on the provider, destination and processing arrangement; this policy does not designate a particular mechanism without verified information. You can request information about the relevant destinations and safeguards, and a copy or reference where applicable, at info@eliaskalyvas.gr.

8. Retention

We retain information according to the purpose: managing an enquiry or meeting, necessary follow-up, legitimate administrative/security needs and applicable legal obligations or claims. We do not publish a fixed deletion period for enquiry or booking records because no uniform automated retention schedule is currently configured. Cancellation or archiving changes a record’s status and does not itself erase the record or all provider copies.

We assess deletion or restriction when information is no longer needed, taking account of provider-held notifications, calendar resources and backups. Cookie preferences remain in your browser until replaced, cleared or invalidated by a consent-version change. Security rate-limit buckets have a technical expiry and cleanup mechanism, which is separate from retention of enquiries and bookings.

9. Your rights

Subject to the GDPR conditions, you may request access, rectification, erasure, restriction and data portability, and object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time. Rights are not absolute: a legal obligation or a need to defend claims may justify retaining limited information.

Send requests to info@eliaskalyvas.gr. We may request only the information reasonably necessary to verify your identity and will respond within the applicable statutory time limits. You may complain to the Hellenic Data Protection Authority (www.dpa.gr), or another competent supervisory authority, including in your place of habitual residence or work.

10. Automated decisions and AI references

This website does not make decisions with legal or similarly significant effects solely through automated processing. References to AI products, My Mentor, Aegis Link and Noctua Core describe separate products or services; they do not mean that the website profiles visitors or makes such decisions about them.

11. External links

Links to My Mentor, Aegis Link, Noctua Core, Google Play, LinkedIn, other social platforms or referenced websites take you to separate services governed by their own terms and privacy policies. An ordinary external link does not itself embed those services or grant them consent for tracking. Once you visit them, their operators may process your technical and other information under their own policies.

12. Signals and future functions

Signals is intended for articles, insights, analysis, commentary, publications and references. Reading public content alone should not require personal information beyond normal technical website processing. A newsletter, account, saved preference, comment, reaction, personalisation, behavioural measurement or advertising function is not authorised by this policy merely because it may be added later.

Before enabling any such function we will provide the relevant information, update this policy and consent categories/version where necessary, and obtain fresh consent where required. No blanket consent is sought for unknown future processing.

13. Children

This professional website is not specifically directed to children and does not intentionally seek to collect their personal information. If you believe a child has supplied personal data inappropriately, contact info@eliaskalyvas.gr so that we can assess and address it.

14. Security, obligations and updates

We use appropriate technical and organisational measures to protect website information, but no online service can promise absolute security. We may also process information to comply with applicable legal obligations (Article 6(1)(c)). This policy will be updated when the actual services or processing change. The effective date, last update and version appear at the top; significant changes will be brought to your attention where required.

Back to websiteTerms of Use