GDPR Compliance
Codeehut ("we", "us", or "our") builds and operates Suite CodeeHut in line with Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), and Greek Law 4624/2019. This page explains how we meet those obligations, what our respective roles are, and how you — as a customer, an end-user, or a guest of one of our customers — can exercise your rights. It complements our Privacy Policy and Terms of Use, which remain the governing documents.
1. Our Commitment
Data protection is not a feature we added after the fact — it is part of how Suite CodeeHut is designed and operated. In practice this means:
- Privacy by design and by default (Art. 25 GDPR): new features are assessed for their data-protection impact before release, and default settings are the most privacy-preserving ones.
- Data minimisation: we collect only the personal data we actually need to deliver the Service.
- EU-first hosting: production data is stored and processed within the European Economic Area.
- Written agreements: every vendor with access to personal data is bound by a data-processing agreement.
- Accountability: we maintain records of processing activities under Art. 30 GDPR and can demonstrate our compliance on request.
2. Controller & Processor Roles
The GDPR assigns different obligations depending on who decides the purposes and means of processing. Within Suite CodeeHut there are two distinct situations:
- Codeehut as controller. For the personal data of our own customers — account holders, their team members, billing contacts and website visitors — we determine the purposes and means, and we act as controller. This processing is described in our Privacy Policy.
- Codeehut as processor. For the data you upload or generate inside your workspace — your guests, contacts, CRM records, loyalty members, bookings, menu and signage content — you are the controller and we process that data solely on your documented instructions, which are given through your use of the platform and the agreement between us.
As a processor we do not use your data for our own purposes, do not sell it, and do not use it to train third-party AI models beyond what is strictly required to deliver the feature you have enabled.
3. Data Processing Agreement
Where we act as processor, Art. 28 GDPR requires a written agreement. Our Data Processing Agreement (DPA) is incorporated into the Terms of Use and applies automatically to every customer — no separate signature is needed. It covers:
- the subject matter, duration, nature and purpose of the processing;
- the categories of data subjects and personal data involved;
- our obligation to process only on your documented instructions;
- confidentiality commitments for our personnel;
- the security measures listed in Section 7;
- the conditions for engaging sub-processors;
- our assistance with data subject requests, breach notification and impact assessments;
- deletion or return of personal data at the end of the contract;
- your right to receive the information needed to demonstrate compliance, including audits.
If your organisation requires a countersigned copy or an amended DPA, write to [email protected].
4. Principles We Apply
Article 5 GDPR sets out the principles that govern all processing. We apply them as follows:
- Lawfulness, fairness and transparency: every processing operation has an identified legal basis, documented in our Privacy Policy.
- Purpose limitation: data collected to run the Service is not repurposed for unrelated aims.
- Data minimisation: forms and integrations request only the fields required for the feature in question.
- Accuracy: you can correct account and workspace data at any time from within the platform.
- Storage limitation: retention periods are defined per data category (see Section 10).
- Integrity and confidentiality: encryption in transit, access control and monitoring (see Section 7).
- Accountability: we document our decisions and keep an Art. 30 record of processing activities.
5. Sub-processors
To deliver the Service we rely on a limited number of specialised vendors that may process personal data on our behalf. Each of them is engaged under a written contract imposing data-protection obligations no less protective than our own. The categories are:
- Cloud infrastructure and hosting — running the application, databases and backups.
- Payment processing — subscription billing and, where enabled, guest payments. Card data is handled by the payment provider; we never store full card numbers.
- Transactional and marketing email delivery — account notifications, and newsletters where you have opted in.
- Content delivery, DNS and security — protecting the platform against attacks and serving assets.
- Product analytics and error monitoring — understanding usage and diagnosing faults.
- Optional AI features — only where you explicitly enable them, and limited to the content you submit to that feature.
The current list of named sub-processors, together with their location and role, is available on request from [email protected]. We will inform customers of any intended addition or replacement of a sub-processor in advance, giving you the opportunity to object.
6. International Transfers
Production data is stored and processed within the European Economic Area. Where a transfer outside the EEA is unavoidable — for example because a vendor operates support or infrastructure in a third country — we rely on one of the following safeguards under Chapter V GDPR:
- an adequacy decision of the European Commission for the destination country;
- Standard Contractual Clauses (SCCs) approved by the European Commission, supplemented by a transfer impact assessment and, where necessary, additional technical measures such as encryption;
- certification under the EU–US Data Privacy Framework, where the recipient is an active participant.
You may request a copy of the relevant transfer mechanism for any sub-processor by contacting us.
7. Technical & Organisational Measures
In accordance with Art. 32 GDPR we implement measures appropriate to the risk, including:
- Encryption in transit using TLS for all connections to the platform and its APIs.
- Encryption at rest for databases and backups at the infrastructure layer.
- Password hashing with modern, salted algorithms — plaintext passwords are never stored.
- Role-based access control and workspace isolation, so each tenant only reaches its own data.
- Least-privilege administrative access, granted individually and reviewed periodically.
- Two-factor authentication available for user accounts.
- Logging and monitoring of authentication and administrative operations.
- Regular backups with restore testing, supporting availability and resilience.
- Secure development practices, including dependency updates and code review before release.
- Confidentiality obligations binding all personnel with access to personal data.
No system can be guaranteed absolutely secure; these measures are reviewed and updated as risks and technology evolve.
8. Data Subject Requests
Data subjects have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent (Arts. 15–22 GDPR). How a request is handled depends on the role described in Section 2:
- If you are our customer (an account holder or team member), write to [email protected]. We respond within one month, extendable by two further months for complex requests, and will tell you if an extension applies.
- If you are a guest or contact of one of our customers — for example your data sits in a hotel's CRM or loyalty programme — that business is the controller. Please address your request to them directly. If you contact us instead, we will forward the request to the relevant customer without undue delay and inform you that we have done so.
As processor we assist our customers in answering such requests through export, correction and deletion functions in the platform, and through direct support where the platform alone is not sufficient. We may ask for reasonable proof of identity before acting on a request.
9. Personal Data Breaches
We maintain an incident-response procedure covering detection, assessment, containment and notification. In the event of a personal data breach:
- where we are the controller, we notify the Hellenic Data Protection Authority within 72 hours of becoming aware of the breach where it is likely to result in a risk to rights and freedoms, and inform affected individuals without undue delay where the risk is high;
- where we are the processor, we notify the affected customer without undue delay after becoming aware, providing the information needed for the customer to meet its own notification duties;
- we document every breach, including the facts, effects and remedial action taken, in an internal register.
10. Retention, Export & Deletion
Personal data is kept only as long as necessary for the purpose it was collected for:
- Account data is retained while the account is active and for a 30-day grace period after deletion, during which recovery is still possible.
- Workspace data (guests, contacts, bookings, content) is retained for as long as you keep it. You control deletion at record level; on termination of your subscription, data is deleted or irreversibly anonymised after the grace period.
- Billing and accounting records are kept for 10 years, as required by Greek tax legislation.
- Support correspondence is kept for up to 3 years.
- Aggregated or anonymised statistics, which no longer identify anyone, may be kept indefinitely.
Export of your workspace data in a structured, machine-readable format is available on request before the end of the grace period.
11. Cookies & Consent
Cookies that are not strictly necessary are set only after consent, in line with the ePrivacy Directive and Art. 6(1)(a) GDPR. Strictly necessary cookies — authentication and session management — are used without consent because the Service cannot function without them. Consent can be granted or withdrawn at any time through the cookie preference centre, and withdrawal is as easy as granting. Details of each cookie category are set out in Section 6 of the Privacy Policy.
Where you use Suite CodeeHut to operate your own guest-facing pages — menus, signage, booking flows — you remain responsible for the consent notices displayed on those pages to your visitors.
12. Your Responsibilities as Controller
When you use Suite CodeeHut to process personal data about your own guests, customers or staff, you act as controller and the GDPR places certain duties on you. In particular you should:
- have a valid legal basis for each category of data you upload or collect through the platform;
- provide your data subjects with the information required by Arts. 13–14 GDPR, including the fact that Codeehut acts as your processor;
- obtain and record consent where required — for example for marketing emails, newsletters or loyalty enrolment;
- keep the data you store accurate and up to date, and delete what you no longer need;
- manage user accounts and permissions in your workspace, revoking access when a team member leaves;
- respond to data subject requests addressed to you, using the platform's export and deletion tools;
- avoid uploading special categories of data (Art. 9 GDPR) unless you have an appropriate legal basis and have informed us.
13. Data Protection Contact & Authority
Codeehut is not required to appoint a Data Protection Officer under Art. 37 GDPR. We have nevertheless designated a dedicated point of contact for all data-protection matters, reachable at [email protected].
Our lead supervisory authority is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), 1–3 Kifissias Avenue, 115 23 Athens, Greece — www.dpa.gr. You have the right to lodge a complaint with it, or with the supervisory authority of your habitual residence or place of work, at any time.
14. Changes to this Statement
We may update this GDPR statement to reflect changes in our processing, our vendors or the legal framework. The "Last updated" date at the top of the page always shows the current version. For material changes we notify customers by email or in-app notification at least 14 days before they take effect.
15. Contact
For any question about this statement, our DPA, our sub-processors or the exercise of your rights, contact us at:
Codeehut — Privacy TeamIppodameias Square 8, Piraeus 18531, Greece
General Commercial Register: 179997609000
[email protected]
