Legal

Privacy Policy

Last updated: May 23, 2026

1. Who we are

Data Controller: Fixit E.E., G. Gennimata 54A, Kalamaria, Thessaloniki 55134. Contact email: [email protected].

2. What data we collect

Account
email, name, client_id
Required for authentication
Payments
Stripe customer ID, invoice IDs
We do not store card numbers — only Stripe
Wallet
token transactions, balance, services
For billing and history
Logs
IP, user agent, timestamps
Security + abuse prevention, 90 days
AI conversations
prompts & responses
Only for session duration — not for training
Contact form
name, email, company, message
Only to respond to your request

3. Legal basis for processing

  • Contractual obligation (Art. 6(1)(b) GDPR) — to provide the Service.
  • Legitimate interest (Art. 6(1)(f)) — for security, anti-fraud, service improvement.
  • Consent (Art. 6(1)(a)) — for marketing communications (opt-in).
  • Legal obligation (Art. 6(1)(c)) — for invoicing, tax compliance.

4. What we do NOT do

  • We do not sell or rent data to third parties.
  • We do not use your data to train general models without explicit consent.
  • We do not send your prompts to OpenAI, Anthropic, Google or other providers.
  • We do not use third-party tracking pixels (Facebook, Google Ads remarketing, etc).

5. Where data is hosted

All data is hosted on servers in Greece and the EU:

  • NVIDIA DGX Spark cluster — Thessaloniki (AI inference + databases)
  • Hetzner Germany — backups with encryption at rest
  • Cloudflare — CDN + DDoS protection (edge caching only, no persistent data)
  • Stripe — payment processing (PCI-DSS Level 1)

6. Cookies

We use only essential cookies (session, CSRF, theme preference). No 3rd-party analytics or tracking cookies. No consent banner needed — we do not compromise your appetite.

7. Data retention

  • Account: as long as active + 12 months after deletion.
  • Wallet transactions: 7 years (tax obligation).
  • AI conversations: 30 days (then auto-deleted).
  • Logs / security: 90 days.
  • Contact forms: 24 months after last contact.

8. Your rights

Under GDPR you have the right to:

  • Access — a copy of your data.
  • Rectification — if something is wrong.
  • Erasure — all your data except tax records.
  • Portability — export in JSON/CSV.
  • Objection — to specific processing.
  • Complaint — to the Data Protection Authority.

Exercise of rights: email [email protected] — response within 30 days.

9. Changes to this policy

Material changes are notified by email 30 days before taking effect. Continued use of the Service after a change constitutes acceptance.