Privacy Policy
We handle business and project data with care. This policy explains what we collect, why we collect it, how we protect it, and what rights you have.
Control over your data.
- Access your personal data
- Correct inaccurate information
- Request deletion where legally available
- Object to certain processing
- Request data portability
- Withdraw consent where processing relies on consent
Privacy Overview
This Privacy Policy explains how Ergofect collects, uses, shares, stores, and protects information when you visit our website, request an audit, contact us, or engage our AI automation services.
We design our data practices around operational necessity, security, transparency, and respect for client confidentiality.
Information We Collect
We may collect contact information such as name, work email, phone number, company name, role, project interest, budget range, and messages you submit through forms.
During audits or service delivery, we may collect workflow details, system diagrams, sample documents, operational metrics, integration requirements, and technical configuration data.
We may automatically collect limited technical information such as browser type, device data, pages viewed, referral source, approximate location, and usage analytics.
How We Use Information
We use information to respond to inquiries, evaluate automation opportunities, prepare proposals, deliver services, manage client relationships, provide support, and improve our website and offerings.
We may use aggregated or de-identified information to analyze service performance, benchmark workflows, improve automation patterns, and develop internal best practices.
Legal Basis for Processing
Where applicable, we process personal data based on your consent, contract performance, legitimate business interests, compliance with legal obligations, or protection of rights and security.
For marketing communications, you may opt out at any time using the unsubscribe mechanism or by contacting us directly.
How We Share Information
We do not sell personal information. We may share information with trusted vendors who help us provide hosting, analytics, CRM, communication, security, cloud, project management, or automation services.
We may disclose information if required by law, legal process, government request, security investigation, business transfer, or to protect rights, safety, and property.
AI Systems and Client Data
AI automation projects may require sample prompts, documents, tickets, workflows, transcripts, or structured data to design and test solutions.
We aim to use the minimum data needed for the project and recommend redaction, anonymization, or synthetic data where practical.
Use of third-party AI providers is governed by the relevant project agreement and the provider's own terms and security practices.
Data Retention
We retain information only as long as needed for the purposes described in this Policy, including service delivery, legal compliance, dispute resolution, security, and business records.
Retention periods may vary based on contract terms, data type, regulatory requirements, and operational needs.
Security Measures
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure.
Security measures may include access controls, least-privilege permissions, secure credential handling, encrypted services where available, monitoring, vendor review, and internal confidentiality practices.
Cookies and Analytics
We use a small amount of strictly necessary storage to remember your cookie choice. Everything else is optional and only loads after you click Accept in the cookie banner.
Optional tools are Google Tag Manager and Google Analytics (website usage and performance), the Apollo website tracker and form enrichment (to recognise companies that visit or contact us), and an IP-based visitor identification service that matches the network address of a visit to the company it belongs to and, where possible, to a business contact.
You can withdraw or change your choice at any time with the Cookie settings control on every page. If you reject, none of the optional tools load. You can also block cookies through your browser settings.
Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data we hold about you.
We may need to verify your identity before processing a privacy request. Some requests may be limited by legal, security, or contractual obligations.
International Transfers
Ergofect and its service providers may process information in countries other than your own. Where required, we use appropriate safeguards for cross-border transfers.
By using our website or services, you understand that information may be processed where we or our vendors operate.
Policy Updates
We may update this Privacy Policy to reflect operational, legal, or technology changes. The latest version will always be posted on this page with an updated effective date.
Material changes may be communicated through the website or direct notice where appropriate.
GDPR and UK GDPR
This section applies to visitors and contacts in the European Economic Area and the United Kingdom, and explains how we meet the General Data Protection Regulation (GDPR) and the UK GDPR.
Controller. Ergofect, Niovis 7, Gerakas, Athens 15344, Greece, is the controller of the personal data described in this policy. You can reach us about any privacy matter at info@ergofect.com or by post at that address.
Legal bases. We rely on contract performance when we prepare proposals and deliver services you asked for; on legitimate interests when we reply to enquiries, run our business, keep the website secure, and contact business prospects about relevant services; on consent for optional analytics, tracking and visitor identification on this website; and on legal obligation where the law requires us to keep records.
Visitor identification. If you accept optional cookies, we use Apollo and an IP-based visitor identification service to learn which companies visit our website, and in some cases which business contact at that company. We use this only to understand interest in our services and to plan relevant outreach. It does not produce decisions with legal or similarly significant effects about you. If you reject optional cookies, or later withdraw consent, this identification does not run.
Video assistant. Our homepage offers an optional AI video assistant provided by Tavus. Nothing is recorded until you open it and choose to start a conversation. When you do, your camera image (if you leave it on), your voice, a transcript of what is said and basic connection data are processed by Tavus to run the conversation. We use this on the basis of your consent, given by starting the call, and you can end it at any time. Please do not share sensitive personal information in the conversation. We use conversation transcripts only to answer your questions and follow up on your request, and keep them for no longer than 12 months.
Business outreach. We may contact professionals at companies that fit our services, using business contact details. Every message offers a simple way to opt out, and you can object at any time by emailing us. We then stop contacting you and keep only the minimum needed to respect that choice.
Processors and recipients. We share personal data only with providers that help us run the website and the business, including website hosting (Vercel), analytics (Google), sales intelligence and email tools (Apollo), the visitor identification provider, the AI video assistant (Tavus), and our email and document tools. They act on our instructions under data processing terms.
International transfers. Some providers process data outside the EEA or the UK, including in the United States. Where that happens we rely on an adequacy decision, the EU-US Data Privacy Framework where the provider is certified, or Standard Contractual Clauses (with the UK addendum where relevant).
Retention. Enquiry and audit request details are kept for up to 24 months after our last contact, unless we start working together. Client records are kept for the length of the contract and as long afterwards as the law requires. Analytics and visitor identification data are kept for no longer than 14 months.
Your rights. You have the right to access, correct, delete, restrict, or receive a copy of your personal data, to object to processing based on legitimate interests (including outreach, which we always stop on request), and to withdraw consent at any time without affecting earlier processing. Email info@ergofect.com and we will respond within one month.
Complaints. If you are unhappy with how we handle your data, please tell us first. You also have the right to complain to a data protection authority, for example the authority in the country where you live or work, the Hellenic Data Protection Authority in Greece, or the Information Commissioner’s Office in the UK.
Need to exercise your rights?
Send us a request and include enough information to verify your identity and locate the relevant data.