Return to Home
GDPR Privacy Notice (Articles 13 & 14)

Privacy Notice & Data Protection Policy

Transparent data processing standards pursuant to Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.

Effective: January 1, 2026 • Strict data minimization architecture

§11. Identification of Operator & Contact Details

taakflow is operated as an independent software application by its natural-person developer (Operator: Nikos, located in Greece).

For all privacy and data protection inquiries, contact our dedicated Privacy Contact at privacy@taakflow.gr.

§22. Roles & Separation of Responsibilities (GDPR Arts 13 & 14)

taakflow maintains a strict separation of legal roles in accordance with European data protection law:

  • Host Account Data (Controller: taakflow - Art. 13): When a property manager or host registers, taakflow acts as Data Controller for their account email, name, password hash, property AMA code, and subscription status.
  • Guest Reservation & Stay Data (Processor: taakflow, Controller: Host - Arts 14 & 28): When tracking resilience fee collection for a stay, the property Host is the Data Controller. taakflow acts strictly as a Data Processor pursuant to our Article 28 DPA.

§33. Data Categories & Strict Data Minimization

In compliance with GDPR Article 5(1)(c) (Data Minimization) and AADE Decision A.1217/2023, taakflow collects only what is legally necessary to calculate and record the fee:

  • Host data: Manager name, email address, password hash, property AMA number, language preference.
  • Guest data: Full legal name, stay dates (arrival/departure), night count, calculated fee, payment status, and Stripe reference.
  • MINIMAL CHECKOUT DATA: the current taakflow guest checkout does not request a passport or national-ID number. Legacy imported records may contain historical identity data and can be cleaned by the operator.

§44. Legal Bases for Processing

We process data strictly under the following lawful grounds of GDPR Article 6:

  • Article 6(1)(b) Contract: To provide SaaS host account functionality, authentication, and service delivery.
  • Article 6(1)(c) Legal Obligation: Assisting hosts in complying with statutory accommodation tax records under Law 4389/2016 and Law 5162/2024.
  • Article 6(1)(f) Legitimate Interests: System security, fraud defense, IP rate limiting, and technical resilience.

§55. Data Retention Schedule

Personal data is held only for as long as strictly necessary under clear retention schedules:

  • Host account records: Maintained for active account duration plus 5 years for statutory tax audit trails.
  • Guest transaction records: Retained for 5 years in alignment with Greek statutory tax limitation rules (Law 4174/2013).
  • Authentication sessions & IP logs: Retained for up to 90 days.
  • Email verification OTP codes: Automatically expired and deleted after 15 minutes.

§66. Subprocessors & Technical Security Measures

All primary application compute and databases are located inside the European Union (Germany and Frankfurt/EU).

Active infrastructure partners are disclosed in the public subprocessor register at /subprocessors. Transactional email delivery is enabled only after the selected provider is disclosed there as well.

  • Technical and organizational measures (TOMs) under GDPR Art. 32 include TLS 1.3 encryption in transit, AES-256-GCM encryption at rest for sensitive tokens and configurations, salted password hashing, and strict role-based access control.

§77. Your Rights & Supervisory Authority

You have the right under GDPR Articles 15–22 to request access, rectification, erasure, restriction of processing, data portability, and to object to processing. Contact our privacy desk at privacy@taakflow.gr.

You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ): Kifissias 1-3, 115 23 Athens, Greece; Web: www.dpa.gr; Email: complaints@dpa.gr.

Privacy Contact

To exercise your GDPR rights or submit privacy inquiries:

Data Protection Officer

privacy@taakflow.gr
taakflow • Zero Commercial Tracking • Privacy information under GDPR (EU 2016/679) & Law 4624/2019