Skip to main content

Privacy Policy

Privacy Policy

Last reviewed: 2026-05-01

1. Introduction

This Privacy Policy explains how TO BRIEF Ι.Κ.Ε. ("TO BRIEF", "we", "us") collects, uses, and protects personal data in connection with the websites tobrief.gr and tobrief.eu and any related services (together, the "Service"). TO BRIEF is the data controller for personal data processed through the Service, except where another controller is expressly identified below.

Controller details

  • Legal name: TO BRIEF Ι.Κ.Ε. (Ιδιωτική Κεφαλαιουχική Εταιρεία)
  • Registered office: Troon 26, 118 51, Αθήνα, Αττική, Ελλάδα
  • GEMI: 188116103000
  • AFM: 803045387
  • Email: [email protected]
  • Data-protection contact: [email protected]

We do not currently operate a statutorily appointed Data Protection Officer; nevertheless all data-protection enquiries are routed through the dedicated contact above and handled under a documented process that meets the standards expected of a DPO function under GDPR Art. 37-39 where applicable.

2. What data we collect

We collect only the minimum data needed to run the Service and meet our legal obligations.

2.1 Account data

When you register an account we store: your email address, a securely hashed password, your chosen display name (optional), the date of account creation, the edition you registered through (GR or EU), and subscription status. Legal basis: performance of a contract (GDPR Art. 6(1)(b)).

2.2 Usage and analytics data

If — and only if — you grant optional measurement consent through our cookie banner, we collect aggregated usage signals via Google Analytics 4, UX analytics/session signals via Contentsquare/Hotjar, conversion signals via the X pixel, and conversion signals via the Meta (Facebook/Instagram) pixel: pages viewed, device/browser class, approximate geography (country/region from IP, never the raw IP), referrer, session duration, interaction events, user experience friction signals, signups, and subscription conversions. Legal basis: consent (GDPR Art. 6(1)(a) and ePrivacy Art. 5(3)).

2.3 Payment data

Subscription payments are processed by Stripe Payments Europe, Limited ("Stripe"). Card numbers, CVV codes, and full billing identifiers are collected directly by Stripe and never touch our servers. Stripe is an independent data controller for the payment information it processes; its privacy notice is at https://stripe.com/privacy. We receive from Stripe only: customer identifier, subscription status, last four card digits, card brand, billing country, and invoice PDFs. Legal basis: performance of a contract and legal obligation (tax/accounting records).

2.4 Complaints and report data

When you use /report or email a complaint we store: your email, the complaint text, attachments you provide, a salted hash of your IP address (not the raw IP), the ticket number we assign, and the outcome of the investigation. Legal basis: legitimate interest (operating an accountable news service and defending legal claims) and legal obligation (EMFA Art. 20, DSA Art. 16).

2.5 Device and browser data

Our servers receive standard HTTP request metadata — user-agent, Accept-Language, referrer, truncated IP — which is retained in access logs. Legal basis: legitimate interest (security, fraud prevention, diagnostics).

2.6 Sensitive categories

We do not knowingly collect special categories of personal data (GDPR Art. 9) such as data about health, religion, political opinions, or sexual orientation. Please do not submit such data through free-text fields.

3. Why we use your data

PurposeData categoriesLegal basis
Providing the reading experienceAccount, deviceContract, legitimate interest
Billing, fraud prevention, tax compliancePayment, accountContract, legal obligation
Measuring engagement and improving the productMeasurementConsent
UX analytics through Contentsquare/HotjarMeasurementConsent
Conversion measurement via X pixelMeasurementConsent
Conversion measurement via the Meta pixelMeasurementConsent
Handling complaints and correctionsComplaints, accountLegitimate interest, legal obligation
Security, abuse detection, incident responseDevice, accountLegitimate interest
Complying with lawful requestsAll categories, as relevantLegal obligation

We do not use personal data for automated decision-making that produces legal or similarly significant effects on you (GDPR Art. 22).

4. How long we keep your data

  • Account data: for as long as the account is active and up to two (2) years after closure, to handle post-closure disputes and chargebacks.
  • Analytics data: fourteen (14) months for GA4; Contentsquare/Hotjar measurement cookies are retained according to their purpose and generally up to thirteen (13) months for visitor-level UX analytics cookies.
  • Payment / invoicing data: seven (7) years, to meet Greek tax-archiving obligations (Κ.Φ.Α.Σ. / Law 4174/2013).
  • Complaints data: three (3) years from final response, aligned with the five-year statute for contractual claims but trimmed where possible.
  • Access logs: ninety (90) days.
  • Backups: encrypted backups roll off within 35 days.

After these periods we delete or irreversibly anonymise the data.

5. Who we share data with

We share personal data only with the recipients and for the purposes listed here. We do not sell personal data to any third party.

  • Stripe (payments, as independent controller).
  • Google Ireland Limited (GA4) — only if you consent to analytics.
  • Contentsquare/Hotjar — only if you consent to optional UX analytics measurement.
  • Twitter International Unlimited Company — only if you consent to optional measurement cookies (X conversion pixel).
  • Meta Platforms Ireland Limited — only if you consent to optional measurement cookies (Meta/Facebook pixel).
  • Hosting and infrastructure providers (e.g. Vercel, AWS, Cloudflare) acting strictly as processors under Art. 28 contracts.
  • Professional advisors (lawyers, accountants, auditors) where legally necessary and under confidentiality.
  • Competent authorities, where we are compelled by a lawful, specific, and proportionate request (court order, DPA, tax authority).

A current, auditable list of sub-processors is maintained internally and can be provided on request.

6. International data transfers

Some of our processors are established in the United States or operate globally. Where personal data is transferred outside the EEA we rely on:

  • the European Commission's Standard Contractual Clauses (Decision 2021/914), or
  • an adequacy decision (e.g. the EU-U.S. Data Privacy Framework, for Stripe, Google, and other certified importers), or
  • your explicit consent for limited, targeted transfers.

Supplementary measures such as encryption in transit (TLS 1.2+), encryption at rest, and access controls are applied on top of the legal transfer mechanism.

7. Your GDPR rights

You have the following rights under GDPR Arts. 15-22:

  • Access — confirmation that we process your data and a copy of it.
  • Rectification — correction of inaccurate or incomplete data.
  • Erasure ("right to be forgotten") — deletion where grounds exist.
  • Restriction — limiting how we process your data pending verification.
  • Portability — a machine-readable copy of data you provided under contract or consent.
  • Objection — to processing based on legitimate interests, including profiling.
  • Withdraw consent — at any time, without affecting processing performed before withdrawal.
  • Complain to a supervisory authority — especially the Hellenic Data Protection Authority (see §11).

To exercise any right, email [email protected] from the address on file or provide another reasonable means of identity verification. We respond within one (1) month, extendable once by two (2) further months for complex requests; we will explain any extension.

8. Cookies

We use cookies and similar technologies. The categories, purposes, and duration of each cookie are described in the Cookie Policy. You can configure your preferences and withdraw consent at any time via /cookie-preferences.

9. Children

The Service is not directed at children under fifteen (15) years old, the age of digital consent in Greece under Law 4624/2019 Art. 21. We do not knowingly collect data from younger children. If you believe a child has registered, please contact [email protected] and we will delete the account.

10. Security

We apply commercially reasonable technical and organisational measures — including TLS, hashed passwords (Argon2 family), isolated environments, principle-of-least-privilege access, logging, backups, and incident-response procedures — but no system is perfectly secure. In the event of a personal-data breach likely to result in a risk to your rights, we will notify the Hellenic DPA within 72 hours as required by GDPR Art. 33 and, where the risk is high, we will also notify you directly.

11. Changes to this policy

We will post a revised version at this URL and, for material changes, give notice at least thirty (30) days in advance through the Service or by email. The "Last reviewed" date at the top always reflects the most recent update. Historical versions of this document are preserved in the legal-pages change log.

12. Contact and supervisory authority

  • Data-protection enquiries: [email protected]
  • Postal address: Troon 26, 118 51, Αθήνα, Αττική, Ελλάδα

You have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα):

EU residents outside Greece may also contact the supervisory authority in their Member State of habitual residence.