Privacy Policy  ISOLead’s Platform

  1. Introduction

This Privacy Policy explains how ASPIRE SOLUTIONS ltd. (the “Provider”, “we”, “our”, or “us”) collects, uses, and protects personal data when users access and use the ISOLead platform (the “Platform”).

The Provider is committed to protecting personal data and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

This Policy applies to all users of the Platform.

  • Data Controller and Contact Information

For the purposes of data protection legislation, ASPIRE SOLUTIONS ltd. acts as the data controller for personal data related to the operation of the Platform.

Contact details:

ASPIRE SOLUTIONS ltd.

77-79 Pentelis Avenue, 15233 Chalandri

info@aspiresolutions.gr
www.aspiresolutions.gr/

For any privacy-related inquiries, users may contact us at the above email address.

  • Categories of Personal Data Collected

When users access or use the Platform, we may collect the following categories of personal data:

Account Information

  • name
  • email address
  • user role within the organisation
  • login credentials

Platform Usage Data

  • login timestamps
  • system activity logs
  • actions performed within the Platform

Technical Information

  • IP address
  • browser type
  • device information
  • system logs

Support Communications

If users contact support, we may process information included in communications.

  • Purpose of Data Processing

Personal data is processed for the following purposes:

  • providing access to the Platform
  • user authentication and access control
  • system administration and security monitoring
  • maintaining audit logs and system integrity
  • providing user support
  • improving the functionality and performance of the Platform
  • Legal Basis for Processing

Personal data is processed on the following legal bases:

Contractual necessity

Processing is necessary to provide the Platform services.

Legitimate interests

Processing may be required for security monitoring, system improvement, and service reliability. The Provider ensures that such legitimate interests do not override the fundamental rights and freedoms of users.

Legal obligations

Processing may be required to comply with applicable laws.

  • Processing of Customer Data

The Platform allows organisations to store and manage their own information within the system.

In such cases:

  • the Customer organisation acts as Data Controller
  • the Provider acts as Data Processor

Customer Data is processed solely for the purpose of providing the Platform services.

Further details regarding such processing may be governed by a Data Processing Agreement (DPA) or other applicable contractual data processing terms, where required.

  • Data Security

The Provider implements appropriate technical and organisational measures to protect personal data.

These measures include:

  • access control mechanisms
  • role-based access control and permission management
  • system logging and monitoring
  • logical data isolation between tenants
  • secure infrastructure environments

The Platform incorporates role-based access control, audit logging, and tenant-isolation mechanisms designed to ensure the secure handling of organisational and user data.

However, no system can guarantee absolute security.

  • Data Retention

Personal data is retained only for as long as necessary to fulfil the purposes described in this Policy.

Personal data is retained as follows:

Account data: for the duration of the contractual relationship and up to 5 years after termination.

System logs: up to 12 months

Support communications: for the duration of the contractual relationship and up to 5 years after termination.

  • Data Sharing

Personal data may be shared with trusted service providers involved in the operation of the Platform, such as:

  • cloud infrastructure providers
  • system hosting providers
  • technical support providers

Such providers process data only under contractual safeguards and in accordance with applicable data protection laws.

  1. International Data Transfers

If personal data is transferred outside the European Economic Area (EEA), the Provider ensures that appropriate safeguards are in place to protect such data, in accordance with applicable data protection laws.

Where required, additional technical and organisational measures are implemented to ensure an equivalent level of data protection.

  1. Data Subject Rights

Under applicable data protection laws, users may have the following rights:

  • Right of access by the data subject. The data subject has the right to find out if the organization is using or storing personal data related to her/him. The data subject can submit a data subject access request and receive relevant information and if desired a copy of the related data.
  • Right to rectification. The data subject has the right to ask the organization to correct the related personal data used or stored, in order to reflect the reality at any time.
  • Right to erasure (right to be forgotten’). The data subject has the right to ask the organization to delete her/his personal data. The organization is obliged to examine the request and delete the personal data if there is no relevant obligation prohibiting such an action (e.g. legal or contractual requirements). In any case, the organization shall notify the data subject accordingly and proceed with the erasure when allowed.
  • Right to restriction of processing. The data subject has the right to ask the organization to stop using her/his personal data. In contrast to the previous data right, the personal data does not need to be deleted but rather either temporarily or completely stop the processing.
  • Right to data portability*. The data subject has the right to receive her/his personal data from the organization, in order to transfer it to another service provider or request to send the data directly to such other service provider in a way that is machine-readable. (*Only processing operations based on the individual’s consent or on a contract to which the individual is party fall under the scope of the right to data portability).
  • Right to object and automated individual decision-making**. The data subject has the right to object, on grounds relating to his or her situation, at any time to processing of personal data concerning him or her, including profiling. (**Where personal data are processed for direct marketing purposes, the data subject shall have the right to object at any time to processing of personal data concerning him or her for such marketing, which includes profiling to the extent that it is related to such direct marketing). The data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
  • Right to withdraw consent***. The data subject has the right to withdraw consent for the processing implemented on her/his personal data. The existence of the right to withdraw consent at any time, does not affect the lawfulness of processing based on consent before its withdrawal. (*** This right is only applicable when explicit consent is used as the legal basis for the processing).
  1. Personal data breaches

In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.

The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with Article 33 of the GDPR.

The competent authorities have published forms for the reporting of personal data breaches. Each partner is encouraged to access the relevant location in order to identify the minimum information needed to be documented in the case of a personal data breach.

Hellenic Data Protection Authority

https://www.dpa.gr/en

Kifissias 1-3, PC 115 23, Athens, Greece

Telephone: +30-210 6475600

E-mail: contact@dpa.gr

  1. Cookies and Tracking Technologies

The Platform uses strictly necessary cookies or similar session technologies required for authentication, security, and proper operation of the service.

These technologies are essential for the functioning of the Platform and do not require user consent under applicable law.

No analytics or marketing cookies are used. If additional tracking technologies are introduced in the future, users will be informed and, where required, consent will be obtained through an appropriate mechanism.

  1. Updates to this Policy

This Privacy Policy may be updated from time to time.

Users will be notified of significant changes where required by applicable law.

  1. Contact

For any questions regarding this Privacy Policy or data protection practices, please contact:

ASPIRE SOLUTIONS ltd.

info@aspiresolutions.gr

Λεωφόρος Πεντέλης 77-79, 15233 Χαλάνδρι, Αθήνα.
+30. 210 6857010
Δευτ - Παρ: 09:00 - 17:00
© 2026 Aspiresolutions. All rights reserved.
Πολιτική Απορρήτου Πολιτική Cookies