Privacy Policy

Privacy and Cookie Policy

Website: https://victoriatsolidou.com
Last updated: 27 August 2026

1. Who we are

The controller responsible for processing personal data through this website is:

Controller: Greece Lean Six Sigma
Business address: Thessaloniki, Greece
Email: info@greeceleansixsigma.gr
Telephone: +306946202808

In this policy, “we”, “us”, and “our” refer to the controller identified above.

This policy explains how we process personal data when you visit or interact with https://victoriatsolidou.com. It applies in accordance with Regulation (EU) 2016/679—the General Data Protection Regulation (“GDPR”)—Greek Law 4624/2019, Greek Law 3471/2006 on electronic communications, and other applicable data-protection legislation.

2. Personal data we process

Depending on how you use the website, we may process:

  • Information you submit, such as your name, email address, website address, username, profile information, comments, and uploaded material.
  • Technical information, such as your IP address, browser type and user-agent string, device information, timestamps, requested pages, and security or server-log information.
  • Account information if registration or login functionality is available.
  • Cookie identifiers, preferences, and similar information stored on or read from your device.
  • Information generated through comment moderation and spam-detection tools.
  • Information received from third-party content or services, where those services are enabled.

Please do not submit special-category or highly sensitive personal data through comments or other public areas of the website.

3. Why we process your data and our lawful bases

We process personal data only when we have an applicable legal basis. Depending on the activity, this may include:

  • Consent: for optional cookies, embedded third-party content, or other optional features where consent is required. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
  • Performance of a contract or steps requested before entering a contract: where processing is necessary to provide a service you requested or administer your account.
  • Compliance with a legal obligation: where we must retain or disclose information under applicable law.
  • Legitimate interests: to operate, secure, maintain, and improve the website; prevent fraud, abuse, and spam; respond to communications; moderate comments; and establish, exercise, or defend legal claims. We use this basis only where our interests are not overridden by your rights and freedoms.

Providing information marked as required is necessary for the relevant function, such as submitting a comment or creating an account. If you do not provide it, we may be unable to provide that function.

4. Comments

When you leave a comment, we collect the information entered in the comment form, together with your IP address, browser user-agent string, submission time, and related technical information. We use this information to publish and administer comments, maintain website security, and detect spam or abuse.

Your chosen display name, profile image, comment, and any other information you include in the public comment field may be visible to anyone. Do not include information that you do not want made public.

Comments may be checked using an automated spam-detection service. Automated tools may flag or temporarily hold a comment, but we do not use comment screening to make decisions that produce legal or similarly significant effects concerning you.

Gravatar

If Gravatar functionality is enabled, a pseudonymised hash generated from your email address may be sent to Gravatar to determine whether you use that service. If your comment is approved, your Gravatar profile image may be publicly displayed beside it.

Gravatar is operated by Automattic. Further information is available in the Automattic Privacy Notice.

Implementation note: If Gravatar is not necessary, remove this section and disable the feature. If it is retained, ensure that any required consent and international-transfer safeguards are implemented.

5. Media uploads

If the website allows you to upload images, avoid uploading files containing embedded location information, such as EXIF GPS data. Other visitors may be able to download publicly accessible images and extract that information.

You must have the necessary rights and permissions for any personal data relating to other people that you upload or publish.

6. Accounts and authorised users

If user registration is enabled, we store the information users provide in their profiles. Users may generally view, correct, or delete their profile information, except where particular information—such as a username—cannot technically be changed.

Website administrators may access and edit account information where necessary to administer the website, provide support, maintain security, or comply with legal obligations.

7. Cookies and similar technologies

Cookies are small files stored on your device. The website may use:

Strictly necessary cookies

These cookies support essential functions such as security, login sessions, comment preferences, load balancing, and remembering your cookie choices. Where a cookie is strictly necessary to provide a service you expressly requested, it may be used without consent.

Examples may include:

  • A temporary cookie on the login page that checks whether your browser accepts cookies. It contains no directly identifying information and is normally deleted when the browser closes.
  • Login cookies, which normally last for two days.
  • A “Remember Me” login cookie, which may retain a login for two weeks.
  • Screen-display preference cookies, which normally last for one year.
  • A cookie created when an authorised user edits or publishes an article. It contains the article’s post ID rather than personal data and normally expires after one day.
  • A cookie recording your cookie-consent choices.

Logging out removes applicable login cookies.

Comment preference cookies

If you leave a comment, you may choose to save your name, email address, and website in cookies so you do not need to enter them again. These convenience cookies normally last for one year and should be placed only after you actively choose this option.

Optional analytics, advertising, and third-party cookies

Analytics, advertising, social-media, embedded-content, and other non-essential cookies or trackers will be activated only after obtaining any consent required by law.

You must be able to accept or reject optional cookies by purpose and withdraw your consent as easily as you gave it. Withdrawing consent does not affect the lawfulness of earlier processing.

A current list of cookies—including each cookie’s provider, purpose, category, and duration—should be available through the website’s cookie settings or a separate cookie notice.

8. Embedded content and external links

Pages may contain embedded videos, images, maps, social-media posts, or other content supplied by third parties. When such content loads, the third-party provider may receive your IP address and technical information, place cookies, use similar technologies, and monitor your interaction with the content. If you are logged in to that provider’s service, it may associate your interaction with your account.

Where required, embedded content that uses non-essential tracking will remain blocked until you consent. You can review the relevant provider’s privacy notice before enabling it.

External websites operate independently, and we are not responsible for their privacy practices.

9. Password resets

If you request a password reset, your IP address may be included in the reset email or related security records. We process this information to authenticate the request, protect accounts, and prevent abuse.

10. Recipients of personal data

Where necessary, personal data may be disclosed to:

  • Website hosting, maintenance, security, backup, and technical-support providers.
  • Email and communications providers.
  • Comment-moderation and spam-detection providers.
  • Automattic or Gravatar, if the relevant features are enabled.
  • Analytics, embedded-content, or social-media providers, but only where they are enabled and any required consent has been obtained.
  • Professional advisers, such as lawyers or accountants, where necessary.
  • Public authorities, courts, regulators, or law-enforcement bodies where disclosure is required or permitted by law.
  • A purchaser, successor, or adviser in connection with a genuine business restructuring, subject to appropriate confidentiality and data-protection safeguards.

Service providers acting as processors may use personal data only on our documented instructions and must protect it appropriately.

11. International data transfers

We aim to process personal data within the European Economic Area (“EEA”). Some service providers may, however, process data in countries outside the EEA.

Where a transfer is made outside the EEA, we will use a lawful transfer mechanism where required, such as:

  • An adequacy decision adopted by the European Commission.
  • The EU–US Data Privacy Framework, where the US recipient is validly certified and the framework applies.
  • European Commission Standard Contractual Clauses, together with supplementary safeguards where necessary.
  • Another transfer mechanism permitted by the GDPR.

You may contact us for information about the applicable safeguards and, where available, a copy of them.

12. How long we retain personal data

We retain personal data only for as long as reasonably necessary for the relevant purpose, taking account of legal, accounting, security, and dispute-resolution requirements.

Unless a different period is required:

  • Comments and associated metadata: retained while the comment and relevant article remain published, or until the comment is deleted or anonymised. Limited records may be retained longer where necessary to prevent abuse or handle legal claims.
  • Registered-user information: retained while the account remains active and for 6 months after closure, unless earlier deletion is appropriate or longer retention is legally required.
  • Security and server logs: retained for 90 days, unless needed longer to investigate a security incident.
  • Cookie information: retained for the duration stated in the website’s cookie settings or cookie table.
  • Consent records: retained for as long as necessary to demonstrate compliance and ordinarily for 6 months after the consent is withdrawn or expires.
  • Rights requests and related correspondence: retained for 6 months to demonstrate that the request was handled appropriately.
  • Legal or dispute records: retained until the applicable limitation period expires and any proceeding is completed.

We periodically review stored information and securely delete or anonymise data that is no longer required.

13. Your data-protection rights

Subject to the conditions and limitations in applicable law, you may have the right to:

  • Obtain information about how we process your personal data.
  • Request access to your personal data and receive a copy.
  • Correct inaccurate or incomplete personal data.
  • Request erasure of your personal data.
  • Request restriction of processing.
  • Object to processing based on legitimate interests.
  • Receive personal data you provided in a structured, commonly used, machine-readable format and, where technically feasible, have it transmitted to another controller.
  • Withdraw consent at any time where processing is based on consent.
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects.

These rights are not absolute. For example, we may retain information where this is necessary to comply with a legal obligation, protect freedom of expression and information, or establish, exercise, or defend legal claims.

To exercise a right, contact us at info@greeceleansixsigma.gr. Please explain your request and provide sufficient information for us to identify the relevant records. We may ask for proportionate proof of identity where necessary.

Requests are normally handled without charge and within one month. That period may be extended by up to two further months where permitted because of the complexity or number of requests; if so, we will inform you.

14. Complaints

Please contact us first if you have concerns about our handling of your personal data.

You also have the right to lodge a complaint with the supervisory authority in Greece:

Hellenic Data Protection Authority
1–3 Kifisias Avenue
115 23 Athens, Greece
Telephone: +30 210 6475600
Website: https://www.dpa.gr
Complaint information: https://www.dpa.gr/en/individuals/complaint-to-the-hellenic-dpa

You may also contact the supervisory authority in the EU or EEA country where you habitually reside or work, or where the alleged infringement occurred.

15. Children’s privacy

This website is not intended to collect personal data knowingly from children under 15 through services offered directly to them on the basis of consent.

In Greece, where consent is the lawful basis for an information-society service offered directly to a child, a child who is at least 15 may provide their own consent. For a child under 15, consent must be given or authorised by the child’s legal representative.

If you believe a child has submitted personal data improperly, contact us so that we can investigate and take appropriate action.

16. Security

We apply appropriate technical and organisational safeguards designed to protect personal data against accidental or unlawful loss, destruction, alteration, unauthorised disclosure, or access.

No internet transmission or storage system is completely secure. You are responsible for keeping any account credentials confidential and should notify us if you suspect unauthorised use of your account.

17. Changes to this policy

We may update this policy when our website, services, providers, or legal obligations change. The current version will be published on this page with a revised “Last updated” date.

Where a change materially affects processing based on consent, we will request new consent where required.