Legal

GDPR Compliance

Last updated: May 23, 2026

We are GDPR-compliant by design.

All our systems are designed from the start with the principles of the General Data Protection Regulation (EU 2016/679). Self-hosted infrastructure means control of your data remains in Europe — not in US data centers.

Data Minimization
We collect only the data we need. No need for tracking cookies, fingerprinting or marketing pixels.
Purpose Limitation
Your data is used only to provide the service. We do not repurpose it for other uses.
Storage Limitation
AI conversations auto-delete after 30 days. Logs after 90.
Integrity & Confidentiality
Encryption at rest (LUKS), encryption in transit (TLS 1.3), strict access controls.
Accountability
Data Processing Records (DPR), Privacy Impact Assessments (PIA), regular security audits.
Rights of the Data Subject
All GDPR rights (access, rectification, erasure, portability, objection) available via email.

1. AI & GDPR — How we handle it

GDPR has specific requirements for AI processing (automated decision-making, profiling). Here is how we comply:

  • We do not make automated decisions with legal impact without human verification.
  • We do not do profiling for ads or consumer profiles.
  • AI is a tool — decisions and responsibility remain with you.
  • Transparency — we can explain why a model returned a specific answer.

2. Data Processing Agreement (DPA)

If you process personal data of your customers through Fixit (e.g. Talos chat collecting emails), we act as Data Processor and you as Data Controller. For enterprise customers we sign a separate DPA — request it.

3. Sub-processors

We use the following sub-processors for specific functions:

Sub-processor Purpose Location
StripePayment processingEU + US (DPF)
CloudflareCDN, DDoS, DNSEU edges
HetznerBackup storageGermany
BitbucketCode repositoryEU + US

4. Data Breach Notification

In case of a security incident affecting your data, we notify you within 72 hours by email, in accordance with Art. 33-34 GDPR. Communication with the Data Protection Authority where required.

5. International Transfers

All AI processing happens within the EU (Greece + Germany). In rare cases requiring transfer outside the EU (e.g. Stripe US for card refund), we use Standard Contractual Clauses (SCCs) or EU-US Data Privacy Framework (DPF).

6. DPO & Contact

We are not obliged to designate a DPO (Data Protection Officer) due to size, but there is a data controller:

Giorgos Mitsoudis
CEO, Fixit E.E.

7. Exercise of rights

Send email to [email protected] with subject "GDPR Request" and specify which right you are exercising. Response within 30 days at no cost. If unsatisfied, you have the right to lodge a complaint with the Data Protection Authority of Greece.