Privacy Policy
1. Who we are
This service is operated by PublicFlow (info@publicflow.eu), the controller of personal data collected through this website. This policy explains what data we process, why, and what rights you have under the EU General Data Protection Regulation (GDPR) and Greek law.
2. Data we collect
- Account data: email address, a password (stored hashed), and optionally your name. If you sign in with Google, we receive your email address and name from Google.
- Company profile (onboarding): your company title and the CPV codes you are interested in (required), and — if you choose to provide them — a company description, keywords, certifications, ISO numbers, financial data, staff information, experience details, and documents you upload.
- Usage data: saved filters, notification preferences, favourites, and timestamps of actions such as registration, email verification and notification emails sent.
- Analytics data (anonymous): we track page views and clicks (page visited, referrer, UTM source, the element clicked). This data carries no identifier — no session id, no account link and nothing stored on your device — so it cannot be tied to you. We also count page views in aggregate (the day, the page, and whether the visitor was logged in), again with no identifiers.
3. Why we process data & legal basis
- To provide the service (performance of a contract, Art. 6(1)(b)): account creation, saved filters, favourites, and matching tenders to your interests.
- To send notification emails for tenders that match your filters (performance of a contract, Art. 6(1)(b)). You can turn these off at any time.
- Security, support and administration(legitimate interest, Art. 6(1)(f)): keeping the service secure, responding to your requests, and providing customer support.
- Analytics (legitimate interest, Art. 6(1)(f)): anonymous, non-identifying page-view and click data (page, referrer, UTM source, element clicked) used to understand how the site is used and to improve it. Because the data carries no identifier and nothing is stored on your device, it cannot be used to identify you or to profile you.
- Aggregate traffic counts (legitimate interest, Art. 6(1)(f)): non-identifying page-view counts (day, page, logged-in status) that we use to understand overall usage. No identifiers are stored with these counts.
- Registration acceptance: by creating an account you accept these terms and this policy.
4. Who we share data with
We use the following processors, each bound by data protection obligations:
- Microsoft Azure — email delivery (Azure Communication Services) and storage of uploaded documents (Azure Blob Storage), hosted in EU regions.
- Google — authentication (OAuth), which provides your email and name when you sign in with Google.
We do not sell your personal data. Authorized administrators may view account and company profile data to provide support and to manage notifications.
5. Cookies & storage
We use strictly necessary cookies (login session cookies) to keep you signed in. These do not require consent. Our analytics does not use cookies, does not store anything on your device, and carries no identifiers — it records anonymous page views and clicks server-side only.
6. Retention
Account and company profile data is kept for as long as your account is active. If you close your account, we delete your personal data unless we are required by law to keep it (for example for compliance reasons), in which case it is kept only as long as required. Anonymous analytics data is retained for a limited period for internal reporting and then deleted.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- rectify inaccurate data;
- erase your data — you can delete your account directly from your profile, which removes your data;
- restrict or object to processing;
- data portability; and
- object to analytics processing.
To exercise any of these rights, contact us at info@publicflow.eu. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).
8. Minors
The service is intended for businesses and professional users. It is not directed at minors; in Greece the minimum age for consent is 15. We do not knowingly collect data from children.
9. Security
We use encryption in transit (HTTPS), hashed passwords, httpOnly session cookies and restricted administrative access to protect your data. No method of transmission or storage is completely secure, but we take reasonable measures to safeguard your information.
10. Changes
We may update this policy. Significant changes will be notified to registered users by email. Continued use of the service after changes are published constitutes acceptance of the updated policy.
11. Contact
Questions about your data or this policy: info@publicflow.eu.