Privacy Policy ISOLead’s Platform
This Privacy Policy explains how ASPIRE SOLUTIONS ltd. (the “Provider”, “we”, “our”, or “us”) collects, uses, and protects personal data when users access and use the ISOLead platform (the “Platform”).
The Provider is committed to protecting personal data and ensuring compliance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
This Policy applies to all users of the Platform.
For the purposes of data protection legislation, ASPIRE SOLUTIONS ltd. acts as the data controller for personal data related to the operation of the Platform.
Contact details:
ASPIRE SOLUTIONS ltd.
77-79 Pentelis Avenue, 15233 Chalandri
info@aspiresolutions.gr
www.aspiresolutions.gr/
For any privacy-related inquiries, users may contact us at the above email address.
When users access or use the Platform, we may collect the following categories of personal data:
Account Information
Platform Usage Data
Technical Information
Support Communications
If users contact support, we may process information included in communications.
Personal data is processed for the following purposes:
Personal data is processed on the following legal bases:
Contractual necessity
Processing is necessary to provide the Platform services.
Legitimate interests
Processing may be required for security monitoring, system improvement, and service reliability. The Provider ensures that such legitimate interests do not override the fundamental rights and freedoms of users.
Legal obligations
Processing may be required to comply with applicable laws.
The Platform allows organisations to store and manage their own information within the system.
In such cases:
Customer Data is processed solely for the purpose of providing the Platform services.
Further details regarding such processing may be governed by a Data Processing Agreement (DPA) or other applicable contractual data processing terms, where required.
The Provider implements appropriate technical and organisational measures to protect personal data.
These measures include:
The Platform incorporates role-based access control, audit logging, and tenant-isolation mechanisms designed to ensure the secure handling of organisational and user data.
However, no system can guarantee absolute security.
Personal data is retained only for as long as necessary to fulfil the purposes described in this Policy.
Personal data is retained as follows:
Account data: for the duration of the contractual relationship and up to 5 years after termination.
System logs: up to 12 months
Support communications: for the duration of the contractual relationship and up to 5 years after termination.
Personal data may be shared with trusted service providers involved in the operation of the Platform, such as:
Such providers process data only under contractual safeguards and in accordance with applicable data protection laws.
If personal data is transferred outside the European Economic Area (EEA), the Provider ensures that appropriate safeguards are in place to protect such data, in accordance with applicable data protection laws.
Where required, additional technical and organisational measures are implemented to ensure an equivalent level of data protection.
Under applicable data protection laws, users may have the following rights:
In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. When the personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the personal data breach to the data subject without undue delay.
The controller shall document any personal data breaches, comprising the facts relating to the personal data breach, its effects and the remedial action taken. That documentation shall enable the supervisory authority to verify compliance with Article 33 of the GDPR.
The competent authorities have published forms for the reporting of personal data breaches. Each partner is encouraged to access the relevant location in order to identify the minimum information needed to be documented in the case of a personal data breach.
Hellenic Data Protection Authority
Kifissias 1-3, PC 115 23, Athens, Greece
Telephone: +30-210 6475600
E-mail: contact@dpa.gr
The Platform uses strictly necessary cookies or similar session technologies required for authentication, security, and proper operation of the service.
These technologies are essential for the functioning of the Platform and do not require user consent under applicable law.
No analytics or marketing cookies are used. If additional tracking technologies are introduced in the future, users will be informed and, where required, consent will be obtained through an appropriate mechanism.
This Privacy Policy may be updated from time to time.
Users will be notified of significant changes where required by applicable law.
For any questions regarding this Privacy Policy or data protection practices, please contact:
ASPIRE SOLUTIONS ltd.
info@aspiresolutions.gr