Privacy Policy
Last updated: August 2026
1. Who we are
Promitheftes ("we") provides a B2B order-recording platform via an AI agent, for suppliers ("subscribers") and their customers.
2. Processing roles
For subscribers' account data (email, business details, billing) we are the Data Controller. For the personal data of customers that subscribers enter into the platform, the respective subscriber acts as the Data Controller and Promitheftes acts as the Data Processor, in accordance with Article 28 of the GDPR.
3. What data we collect
From the subscriber-supplier: email, phone, company name, VAT number, address, delivery hours, billing details (via Stripe).
From the supplier's customer: name, phone, email, optionally company name/VAT number/address/contact person (entered by the supplier), message/order content (text or voice-message transcription), order history.
Technical data: IP address (for security/abuse prevention), session cookies and display-preference cookies (dark mode, language).
4. Purpose
We use the data exclusively for: (a) recording and processing orders via AI, (b) sending notifications/confirmations, (c) login security (OTP codes), (d) subscription billing, (e) customer support.
5. Legal basis
Processing is based on the performance of a contract (Article 6§1(b) GDPR — provision of the service) and on our legitimate interest in security and abuse prevention (Article 6§1(f) GDPR).
6. Artificial Intelligence
The service uses artificial intelligence systems to analyze and structure order data. The output produced by these systems constitutes automated information processing and may, in exceptional cases, contain inaccuracies or misinterpretations. The user remains responsible for checking and confirming orders before fulfilling them.
7. Service providers
We do not sell data to third parties. To operate the service we use selected infrastructure/software providers (hosting & security, database, AI-based processing of order message content, email delivery, subscriber payment processing, and — only if you consent — website traffic statistics via Google Analytics), all bound by data processing agreements (DPA). These providers include, indicatively, Stripe (payment processing), Anthropic (AI-based processing of order content), Google (Google Analytics, traffic statistics — only upon consent), Cloudflare (hosting & security), Supabase (database) and Resend (email delivery).
Some of these providers (including Anthropic, Google, Cloudflare, Supabase and Resend) are based outside the EU/EEA; the transfer is covered by Standard Contractual Clauses (SCCs) and, where required, by additional technical and organizational safeguards in accordance with EU data protection law.
A full list of all providers and copies of the relevant data processing agreements are available upon request at support@promitheftes.com.
8. Retention period
Data is retained for the following periods:
- Subscriber account data: for as long as the subscription is maintained.
- Orders and customer data: until the account is deleted.
- Security log files: 12 months.
- Invoices/accounting records: in accordance with applicable tax obligations.
- OTP codes: deleted automatically after they expire.
After an account deletion request is submitted, data is deleted or anonymized within a reasonable period, unless its retention is required by tax or other mandatory legislation.
9. Your rights
You have the right to access, rectify, erase, restrict, and port your data, as well as the right to object to processing.
- Suppliers: obtain a copy of your data and permanently delete your account, automatically from the Account page in the dashboard.
- Suppliers' customers: obtain a copy of your data and delete your personal details, automatically from your Profile in the app (promitheftes.com/app).
Where processing is based on your consent, you have the right to withdraw it at any time, without affecting the lawfulness of processing carried out before the withdrawal.
For any other request, or if you don't have access to the tools above, contact support@promitheftes.com. You also have the right to lodge a complaint with the Hellenic Data Protection Authority.
10. Security
Data is encrypted (encrypted at rest and in transit). Access to the database is protected with Row-Level Security. Logging into an account requires a mandatory second factor (an OTP code via email).
11. Children's data
The service is not intended for use by minors and does not knowingly collect data from minors.
12. Automated decision-making
The platform does not make automated decisions that produce legal effects or significantly affect data subjects within the meaning of Article 22 of the GDPR.
13. Cookies
We only ever use strictly necessary cookies: session/login, security (Cloudflare Turnstile), and display-preference cookies (language, dark mode). We do not use advertising cookies.
In addition, only if you explicitly consent via the cookie notice shown on the site, we enable Google Analytics (Google Ireland Limited) for traffic statistics (e.g. visitor count, pages viewed) — cookies _ga/_ga_*, retained for up to 2 years. Before your consent, no Google Analytics script is loaded and no related cookie is set. You can withdraw or change your consent at any time via the cookie settings, without affecting the lawfulness of processing carried out before the withdrawal. A detailed table of all cookies, and a button to change or withdraw your consent at any time, are available in the Cookie Policy.
14. Data Protection Officer (DPO)
Promitheftes is not currently required to appoint a Data Protection Officer under the applicable regulatory framework.
15. Contact
For anything related to your privacy or your data: support@promitheftes.com.