Client data
When we build or run something for you, data about your own customers, visitors or partners often passes through our hands. This page describes how we handle it as your processor under Article 28 GDPR: only on your instructions, under a written agreement, with as little access as possible and only for as long as needed.
Last updated:
Roles
You decide, we carry it out
For the data of your customers, visitors and partners, you are the controller: you decide why and how it is used. Noria is the processor: it processes the data only on your behalf, only for the work we agreed and only on your written instructions. If an instruction seems to us to break the law, we tell you before we carry it out.
An agreement before the first task
Before any work that touches personal data begins, we sign a data processing agreement with you, as Article 28 GDPR requires, on our template or on yours. The agreement sets out:
- The subject, duration and purpose of the processing.
- Which data we process and about whom.
- Your instructions and the limits of our work.
- The security measures.
- The sub-processors and where they process the data.
- What happens to the data when the collaboration ends.
When we are the controller
For the details of your people we work with and for invoicing, we are the controller; the Privacy policy describes this. We never use your customers' data for our own purposes, never combine it with other clients' data and never give it to anyone.
Access
Only the access the work needs
We ask for access only to the systems and data the work needs, and only for as long as it needs them. Every person on our team signs in with their own account, never with shared passwords, and with two-step verification wherever the system supports it. Everyone with access is bound in writing to confidentiality. When the work ends, or when someone leaves, their access is revoked.
Sub-processors
In many projects we use specialist providers, for example for hosting, sending email or artificial intelligence models. For each project we name them in the agreement, together with where they process the data. We do not add or change a sub-processor without telling you first, so that you can object, and we impose on each one the same obligations as ours.
Where the data is hosted
We prefer providers and data centres within the European Union. Where a provider processes data outside the European Economic Area, this happens only under an adequacy decision of the European Commission, such as the EU–US Data Privacy Framework for certified providers, or under standard contractual clauses with an assessment of the destination country's law. We tell you before, not after.
Security
Security measures
We apply measures that match the risk (Article 32 GDPR): encryption in transit, backups, software updates, separate environments for each client and access logging wherever the system allows. Where we can, we test with realistic but not real data, and where real data is needed, with as little of it as possible.
If an incident happens
If we become aware of a breach involving your data, we tell you without delay, with everything we know: what happened, which data it concerns, what we have done and what we recommend. This lets you notify the Hellenic Data Protection Authority within the 72 hours the law allows and, where necessary, the people affected (Articles 33 and 34 GDPR).
Help with requests and audits
We help you answer people who exercise their rights, with impact assessments and with questions from the Authority. We give you the information you need to show that the processing is lawful, and we accept audits with reasonable notice.
AI
What data reaches AI tools
When a project uses artificial intelligence tools, for example an assistant that answers your customers or an automation that sorts your inbox, the tools see only what the specific task needs. We remove or mask names and contact details where they are not needed. We do not pass special categories of data, such as health information, to AI tools unless you ask us to in writing and have a legal basis for it; for such matters we recommend that the assistant hands over to a person.
Your data does not train models
We use business editions or the programming interfaces (APIs) of AI providers, where the provider commits by contract not to use the data to train its models. Where an opt-out from training exists, we switch it on. These providers are sub-processors and are named in the agreement like all the others.
A person in control
At the start of every project, whatever an AI system writes on your behalf is checked by a person before it reaches your customers. It answers on its own only the kinds of questions we agreed in writing, once it has been tested on them. The systems we build do not take decisions with legal or similarly significant effects on people on their own (Article 22 GDPR); such decisions stay with you.
It says it is AI
When an assistant talks or writes to people, it says from the first moment that it is an artificial intelligence system, as Article 50 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) requires. Where we make images, video or voice with AI that could pass as real, we tell you and help you label them as the law requires. We do not reproduce the voice or face of a real person without their written consent.
Visibility
Accounts in your name
Advertising accounts (such as Google Ads, Meta, LinkedIn and TikTok) and measurement tools, with their pixels and tags, are opened in your company's name and belong to you. We work through user access you grant us and can revoke at any time. So the data and the history stay with you, whatever happens.
Consent first, then measurement
On the websites we build or manage, pixels, analytics and server-side measurement run only for visitors who consent, and we set up the consent banner so that refusing is as easy as accepting. Customer lists are uploaded to advertising platforms only if you have a legal basis for it, usually consent, and only in hashed form.
Contacting businesses on your behalf
In our business client acquisition service, you are the controller for the contacts, and every message carries your company's name. We follow the Greek rules on unsolicited communications (Article 11 of Law 3471/2006), which apply even when the recipient is a company: the first contact is a phone call, after we have checked that the number is not on the register of those who refuse marketing calls, or a letter, and we send email only to those who asked for it.
Every “no” is respected at once and for good. We never use one client's list for another. What applies to the people we contact is on the If we contacted you page.
The end
When the collaboration ends
When the collaboration ends, we return the data to you in a common, readable format or delete it, as you choose, within 30 days, and confirm it in writing. Copies in backups are deleted in their next cycle. We keep only what the law obliges us to keep.
Questions
If you would like to see our data processing agreement template or the providers we would use in your project, write to us at info@noria.gr.





















