Thracore — Legal
Privacy Policy
How we collect, use, and protect your personal data under the GDPR and Greek Law 4624/2019.
Last updated: 8 May 2026
1. Introduction
Thracore Software Solutions ('we', 'us', 'our') is committed to protecting your personal data. This Privacy Policy explains how we process personal information collected through our website in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation, GDPR) and Greek Law 4624/2019.
2. Data Controller
The data controller responsible for your personal data is Thracore Software Solutions, based in Xanthi, Greece. You can contact us at any time regarding data protection matters at info@thracore.com.
3. Data We Collect
We may collect the following categories of personal data: (a) Contact form data: name, email address, company name, type of service requested, and estimated budget, when you submit our contact form — this data is transmitted directly to Resend Inc. (EU servers) and is never stored or processed by our website hosting provider; (b) Usage data: anonymised IP address, browser type, pages visited, and time spent on pages, collected automatically via cookies and analytics tools; (c) Technical data: device type, operating system, and browser version. Technical and usage data may be processed by our hosting infrastructure for the sole purpose of delivering web pages and maintaining security.
4. Legal Basis for Processing
We process your personal data on the following legal grounds under Article 6 GDPR: Legitimate interests (Art. 6(1)(f)): for responding to contact form enquiries, website security, fraud prevention, and aggregate analytics; Consent (Art. 6(1)(a)): for non-essential cookies (analytics and preference cookies); Contract performance (Art. 6(1)(b)): when delivering services you have engaged us for.
5. Cookies
Our website uses cookies, small text files stored on your device. We use three categories: Necessary cookies (always active) which are essential for the website to function; Analytics cookies (require consent) which use Google Analytics 4 to help us understand site usage — all data is anonymised and IP addresses are truncated before processing; Preference cookies (require consent) which remember your settings such as language and theme. You can manage your cookie preferences at any time using the cookie banner or by adjusting your browser settings.
6. Data Retention
We retain personal data only for as long as necessary: Contact enquiry data is retained for up to 3 years; Anonymised analytics data is retained for up to 24 months; Cookie consent records are retained for 12 months. After these periods, data is securely deleted or anonymised.
7. Third Parties & Data Transfers
We use the following trusted third-party service providers: Netlify Inc. (website hosting, United States) — Netlify processes only technical routing data (such as IP addresses) strictly necessary to deliver web pages. Contact form data is never routed through or stored by Netlify. Transfers to Netlify are governed by Netlify's Data Processing Agreement (available at netlify.com/gdpr-ccpa) and the European Commission Standard Contractual Clauses (Implementing Decision (EU) 2021/914, Module 2: Controller to Processor), which provide an adequate level of protection for your personal data. Resend Inc. (transactional email delivery) — contact form submissions are processed exclusively on Resend servers located within the EU (eu-west-1 region); no transfer outside the EU/EEA occurs. Google LLC (Google Analytics 4, anonymised website analytics) — data is anonymised prior to transmission, IP addresses are truncated, and transfers are governed by Standard Contractual Clauses (Decision (EU) 2021/914). We do not sell your personal data to any third party. You have the right to obtain a copy of the safeguards under which your data is transferred outside the EU/EEA by contacting us at info@thracore.com.
8. Your Rights
Under the GDPR, you have the following rights regarding your personal data: Right of access (Art. 15): request a copy of the data we hold about you; Right to rectification (Art. 16): request correction of inaccurate data; Right to erasure (Art. 17): request deletion of your data ('right to be forgotten'); Right to restriction (Art. 18): request we limit how we use your data; Right to data portability (Art. 20): receive your data in a machine-readable format; Right to object (Art. 21): object to processing based on legitimate interests; Right to withdraw consent: withdraw consent at any time without affecting prior processing; Right to lodge a complaint (Art. 77): you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr, or by post at Kifissias 1-3, 115 23 Athens, Greece. To exercise any of the above rights, contact us at info@thracore.com.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or alteration, in accordance with Article 32 GDPR.
10. Automated Decision-Making & Profiling
We do not carry out any automated decision-making or profiling activities as defined under Article 22 GDPR. No decision producing legal or similarly significant effects is made about you solely on the basis of automated processing.
11. Contact Us
For any questions, requests, or concerns regarding this Privacy Policy or your personal data, please contact us at info@thracore.com. We will respond within 30 days.
This document is provided for general informational purposes. For specific legal advice regarding your situation, please consult a qualified legal professional.
Questions? Contact us at info@thracore.com