How we handle your data.
Last updated 27 September 2026
This policy explains what personal data we collect through eleonwood.com and when you contact us, why we use it, who helps us process it and what rights you have. It follows the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679), Greek Law 4624/2019 and Greek Law 3471/2006.
Who we are
eleonwood.com is run by Eleonwood (“we”, “us”), a hospitality technology studio in Santorini, Greece, that makes websites, software and marketing for hotels, restaurants and spas.
We are the controller of the personal data described in this policy: we decide why and how it is used. For any question about it, or to exercise your rights, write to [email protected].
What we collect
We collect only what you give us and what the site needs in order to work:
- Enquiries: your name and email address (required) and, if you choose to add them, your property or business name, phone number, what you are interested in (a package or a service), your timing and your message. We also record which page led you to the form: a package, a service or a case study.
- Anti-spam checks: your IP address is held for a few minutes, in server memory only, to limit how often the form can be sent. It is not stored with your enquiry. The form also uses a hidden field and a minimum-time check to filter out automated submissions.
- Technical request data: every request to the site carries your IP address, the time and the page requested. Our hosting provider and Cloudflare may keep this in technical logs, for security and operation, for limited periods that they set.
- Client details: if you become a client, the contact and invoicing details needed to carry out our agreement and invoice for it, and our correspondence about the work.
Why we use it, and on what legal basis
We use personal data only for the purposes below, each with its legal basis under Article 6(1) GDPR:
- To answer your enquiry and, if you want to go further, to prepare a proposal: steps taken at your request before entering into a contract (Article 6(1)(b)). Where you write on behalf of a business, also our legitimate interest in replying to and following up business enquiries (Article 6(1)(f)).
- To keep the site and the contact form secure and working, through rate limiting, spam filtering and technical logs: our legitimate interest in keeping the site secure (Article 6(1)(f)).
- To carry out work for our clients: the performance of our contract (Article 6(1)(b)) and our legal obligations, such as tax and accounting records (Article 6(1)(c)).
- To measure how the site is used, only if we enable analytics and you agree to it: your consent (Article 6(1)(a)). The cookies section below says whether analytics is in use.
We never sell personal data. We send no newsletters or advertising you have not asked for, and we make no decisions about you by automated means, including profiling.
Who helps us process it
We share personal data only with the service providers below, which process it on our behalf as processors:
- Cloudflare, Inc. (United States, global network): DNS, content delivery (CDN) and security for eleonwood.com. Every request to the site passes through Cloudflare, so it processes IP addresses and request data.
- Railway Corporation (United States; its infrastructure may be outside the European Economic Area): hosting. Each enquiry is written to the server logs of our hosting service.
- Resend, Inc. (United States): email delivery. Enquiries may be forwarded to our inbox through this service.
We may also disclose personal data where the law requires us to, for example to a competent authority.
Cookies
This site sets no cookies of its own and runs no analytics, advertising or tracking tools. The language you choose is kept in the page address, not in a cookie or in your browser’s storage.
Cloudflare may set strictly necessary security cookies to tell people apart from automated traffic and protect the site. They need no consent under Article 4(5) of Greek Law 3471/2006, because the site cannot be delivered securely without them.
If we add analytics in the future, nothing will run until you agree, and this section will say so.
Content from other services
Fonts, images and videos on this site are served from our own domain. We do not load Google Fonts, embed YouTube or Vimeo players or use social media widgets, so reading a page sends nothing to those services.
The share links at the end of each case study (LinkedIn, Facebook, WhatsApp, Viber and email) are plain links. Nothing is sent to those networks unless you click one; from then on, that network’s own privacy policy applies. The same is true of any link to another website.
Transfers outside the European Economic Area
Some of our providers are based in the United States or may process data outside the European Economic Area (EEA). Where they do, the transfer relies on an adequacy decision of the European Commission, including the EU–US Data Privacy Framework for providers certified under it, or on the Standard Contractual Clauses approved by the Commission.
You can ask us for more information about these safeguards at [email protected].
How long we keep it
- Enquiries that do not lead to work: deleted 12 months after our last contact, or sooner if you ask.
- Client data: kept for the duration of the engagement and afterwards for as long as Greek tax and accounting law requires us to keep invoicing records.
- IP addresses used to rate-limit the form: a few minutes, in server memory only.
- Technical request logs: kept by our hosting provider and Cloudflare for limited periods that they set.
How we protect it
The whole site is served over HTTPS, so what you send is encrypted on its way to us. Access to enquiries is limited to the people who handle them.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy of it;
- have inaccurate data corrected (rectification);
- have your data erased;
- restrict how we use it;
- receive the data you gave us in a structured, machine-readable format and have it passed to another controller (portability);
- object to processing based on our legitimate interest;
- withdraw your consent at any time, where processing is based on consent, without affecting the processing carried out before.
To exercise any of these rights, write to [email protected]. We reply within one month. Where a request is complex, or we receive many, that period can be extended by two further months, as Article 12 GDPR allows; if so, we will tell you why within the first month. We may need to confirm your identity before acting on a request.
Complaints
If you believe we have mishandled your data, you can lodge a complaint with the Hellenic Data Protection Authority, Kifisias 1-3, 115 23 Athens, www.dpa.gr, or with the supervisory authority of the EU country where you live or work. We would welcome the chance to put things right first, at [email protected].
Children
Our services are aimed at businesses, and this site is not directed at children. We do not knowingly collect personal data from anyone under 15, the age of digital consent in Greece. If you believe a child has sent us their details, write to [email protected] and we will delete them.
Changes to this policy
We may update this policy when our services, our providers or the law change. The date at the top shows the current version, and any material change is noted on this page.