Legal
Privacy Policy
Last updated: May 23, 2026
1. Who we are
Data Controller: Fixit E.E., G. Gennimata 54A, Kalamaria, Thessaloniki 55134. Contact email: [email protected].
2. What data we collect
Account
email, name, client_id
Required for authentication
Payments
Stripe customer ID, invoice IDs
We do not store card numbers — only Stripe
Wallet
token transactions, balance, services
For billing and history
Logs
IP, user agent, timestamps
Security + abuse prevention, 90 days
AI conversations
prompts & responses
Only for session duration — not for training
Contact form
name, email, company, message
Only to respond to your request
3. Legal basis for processing
- Contractual obligation (Art. 6(1)(b) GDPR) — to provide the Service.
- Legitimate interest (Art. 6(1)(f)) — for security, anti-fraud, service improvement.
- Consent (Art. 6(1)(a)) — for marketing communications (opt-in).
- Legal obligation (Art. 6(1)(c)) — for invoicing, tax compliance.
4. What we do NOT do
- We do not sell or rent data to third parties.
- We do not use your data to train general models without explicit consent.
- We do not send your prompts to OpenAI, Anthropic, Google or other providers.
- We do not use third-party tracking pixels (Facebook, Google Ads remarketing, etc).
5. Where data is hosted
All data is hosted on servers in Greece and the EU:
- NVIDIA DGX Spark cluster — Thessaloniki (AI inference + databases)
- Hetzner Germany — backups with encryption at rest
- Cloudflare — CDN + DDoS protection (edge caching only, no persistent data)
- Stripe — payment processing (PCI-DSS Level 1)
6. Cookies
We use only essential cookies (session, CSRF, theme preference). No 3rd-party analytics or tracking cookies. No consent banner needed — we do not compromise your appetite.
7. Data retention
- Account: as long as active + 12 months after deletion.
- Wallet transactions: 7 years (tax obligation).
- AI conversations: 30 days (then auto-deleted).
- Logs / security: 90 days.
- Contact forms: 24 months after last contact.
8. Your rights
Under GDPR you have the right to:
- Access — a copy of your data.
- Rectification — if something is wrong.
- Erasure — all your data except tax records.
- Portability — export in JSON/CSV.
- Objection — to specific processing.
- Complaint — to the Data Protection Authority.
Exercise of rights: email [email protected] — response within 30 days.
9. Changes to this policy
Material changes are notified by email 30 days before taking effect. Continued use of the Service after a change constitutes acceptance.