Privacy Policy
Last updated: 16 September 2026
This page explains what personal data NeoQub collects through neoqub.gr, why we collect it, where we keep it and what rights you have over it. It is written to be read, not to exhaust you.
1. Who is responsible for your data
The data controller is NeoQub, based in Greece. For anything related to your data, write to privacy@neoqub.gr.
In progress: full company details (legal name, VAT number, tax office, company registry number and registered address) will be added here as soon as the company is formally incorporated. Until then, your requests are handled normally at privacy@neoqub.gr.
2. What data we collect
From the contact form
We only collect what you give us when you press "Send":
| Data | Why we ask for it |
|---|---|
| First and last name | To address you properly in our reply |
| Phone number (with country code) | So we can reach you if email fails |
| Email address | It is our main way of replying |
| Project type and budget | To prepare a realistic proposal |
| Your message | To understand what you need |
| Page language and dial-code country | To reply in your language |
There are no hidden fields. What you see in the form is what gets stored.
IP address
When you submit the form, your IP address is used temporarily for two things: to limit how many submissions can be made per minute (so the system is not flooded with automated messages), and to let Cloudflare Turnstile verify that you are not a bot. Your IP address is not stored in our database alongside your enquiry.
What we do NOT do
- We do not use Google Analytics or any other visitor-tracking tool.
- We have no advertising cookies or social network pixels.
- We do not build profiles and we make no automated decisions about you.
- We do not sell or rent your data to anyone.
3. Our legal basis
- Article 6(1)(b) GDPR — steps taken prior to entering a contract: you asked us for a quote, so we process your details in order to reply.
- Article 6(1)(f) GDPR — legitimate interest: protecting our site from automated abuse (this covers the IP check and Turnstile).
- Article 6(1)(c) GDPR — legal obligation: if you become a client, tax records are retained for as long as the law requires.
4. Where it is stored and who can see it
Enquiries are stored in a Cloudflare D1 database, with its storage region set to Western Europe (EU). They are not transferred outside the European Economic Area for storage.
Exactly one person has access to that database: the owner of NeoQub. The admin panel is protected by Cloudflare Access, sign-in through a Google account with two-factor authentication, and every request is independently verified by the server. The public website itself cannot read the database — it can only add new enquiries.
5. Third parties involved
| Provider | Role | Data |
|---|---|---|
| Cloudflare | Website hosting, database, bot protection (Turnstile), access control | Form contents, IP address, technical browser signals |
| Google (Workspace) | Our email — where correspondence with you lands | Whatever the correspondence contains |
| Google Fonts | Loads the fonts used on the page | Your IP address becomes known to Google when the fonts load |
Both companies act as data processors, under agreements that include the EU Standard Contractual Clauses for any international transfers.
6. How long we keep it
- Enquiries that did not lead to a project: up to 24 months after the last contact, then deleted.
- Client records: for as long as our working relationship lasts.
- Tax documents: for as long as Greek tax law requires, regardless of any deletion request.
7. Your rights
Under the GDPR you have the right to request:
- Access — a copy of everything we hold about you.
- Rectification — correction of anything inaccurate.
- Erasure — deletion of your data, where no tax obligation binds us.
- Restriction or objection to the processing.
- Portability — your data in a machine-readable format.
Send your request to privacy@neoqub.gr. We reply within one month, free of charge.
If you believe we have not respected your rights, you may lodge a complaint with the Hellenic Data Protection Authority (1-3 Kifissias Ave., 115 23 Athens, Greece).
8. Security
All communication with the site happens over encrypted HTTPS — any plain HTTP request is automatically redirected. The admin panel is unreachable without a verified identity, and every change to data is logged.
No internet service is absolutely secure. We do commit that, in the event of a breach posing a risk to your rights, we will notify the supervisory authority within 72 hours and you without undue delay.
9. Changes to this policy
If something material changes, the date at the top of this page will be updated. For significant changes that directly affect you, we will notify active clients by email.