Grammateas ← Home
Ελληνικά English Deutsch Français Español

Legal

Privacy Policy

What personal data we process when you visit grammateas.gr, when you ask for a quote or a test call, and what happens to the data that passes through our customers' calls.

Last updated: 12 September 2026 · In force from: 12 September 2026 · This English version is provided for convenience; in case of divergence the Greek text prevails.

1. Who we are

The controller for everything described here is Retail Management Solutions, which develops and provides the "Grammateas" service (grammateas.gr).

CompanyRetail Management Solutions
VAT number801291892
Registered officeGrammou 73, Marousi 15124, Greece
Telephone+30 210 3004011 (Monday–Friday, 09:00–17:00)
E-mail for data mattersi.kotrotsios@rm.gr

We are not required to appoint a Data Protection Officer under Article 37 GDPR. The address above answers on every personal data matter.

2. Our two roles

The distinction matters, because it changes who decides about the data:

3. What data we collect from you

a) Simply visiting the site

You can read the whole site without giving any details at all. We use no tracking cookies, no Google Analytics and no advertising pixels — see the Cookie Policy. The server that serves the page keeps, as every server does, technical logs (IP address, time, page, browser type) for security and fault-finding.

b) The "Ask for a quote" form

Full name, business, telephone, e-mail (optional), your message, along with the IP address and the page it was sent from. The request is not stored in a database: it is forwarded as an e-mail to our team, through our e-mail provider, and from then on it lives in our mailbox.

c) The free test call

When you ask Grammateas to call you so that you can try her out:

We also take a request for a test call as an interest in the service and reply to you, as we do with the quote form.

d) The text demo (a conversation with the assistant)

Whatever you write in the page's chat box is sent to our platform to be answered and is stored as a demonstration conversation. Please do not write personal or sensitive details there — they are not needed for the demo. Your browser keeps a random session code in the tab's memory (sessionStorage), which is lost when you close it.

e) Our customers

For customers we process the contact and billing details of their representatives, their account credentials and the action logs (who changed what and when) — in order to perform the contract and for security and tax compliance.

4. Purposes and legal bases

ProcessingPurposeLegal basis (Article 6 GDPR)
The quote form To call you and give you a price Your request before entering into a contract (1(b))
The SMS confirmation code So that we do not call a number that is not yours Legitimate interest (1(f)): protecting third parties, preventing abuse
The test call and the demonstration conversation So that you can see how the service works Your request before entering into a contract (1(b))
Recording of the test call Quality and improvement of the service Consent (1(a)): the call tells you at the start and you may end it
Server logs Security, errors, abuse Legitimate interest (1(f))
Contract, billing, customer support To run the service you bought Performance of a contract (1(b)) and legal obligation (1(c)) for tax matters
Service updates to customers Changes, interruptions, new features Legitimate interest (1(f)) — with an unsubscribe link in every message

We do not send marketing messages to people who have not asked to be contacted, and we do not buy contact lists. We do not sell or rent personal data to anyone.

5. Who sees it

Internally, only those on our team who need to see it for their work. Externally, the providers we need in order to run the service (hosting, telephony, SMS, e-mail, speech recognition and synthesis, language models). They are all processors, bound by a contract under Article 28 GDPR, and are not permitted to use the data for their own purposes.

The full list, by name, with each one's role and location, is public: Sub-processors.

We also disclose data to public authorities where the law requires it, and to our legal or accounting advisers where it is needed to establish or exercise legal claims.

6. Transfers outside the EU

The platform, the database, the recordings and the transcripts are held on servers inside the European Union (Germany). Telephony and SMS are handled by Greek providers.

Some artificial-intelligence and e-mail providers are established in the United States. Where that is the case, the transfer rests on the European Commission's Standard Contractual Clauses (Article 46(2)(c) GDPR) and/or the EU–US Data Privacy Framework, with additional technical measures. The text and audio sent to artificial-intelligence models is not used to train them — that is a contractual commitment from the providers we use. Who is where is set out in the list of sub-processors.

7. How long we keep it

DataRetention
SMS code and the details of a test-call request10 minutes; then deleted automatically
The "we called this number" marker24 hours
The conversation and recording of a test call or text demoUp to 30 days
A quote request (an e-mail in our mailbox)24 months from the last contact, if you do not become a customer
Server logsUp to 30 days
Customer and account detailsFor the duration of the contract and 12 months afterwards
Invoices and tax documentsAs the law requires (as a rule, 5 years)
Action audit logs24 months

You can ask for earlier erasure — see Exercising your rights.

8. Security

Encryption in transit (TLS) and of stored secrets, access only for those who need it, separation of data per customer at the database level, logging of every sensitive action, and no personal details in the logs. In detail: Security.

In the event of a personal data breach that carries a risk, we inform the Hellenic Data Protection Authority within 72 hours and, where required, the people concerned.

9. Your rights

Under Articles 15–22 GDPR you have the right:

Send your request to i.kotrotsios@rm.gr. We answer within one month (extendable by two months for complex requests, telling you so). Exercising your rights is free of charge. Step-by-step instructions: Exercising your rights.

Complaints. If you believe we have not respected your rights, you may complain to the Hellenic Data Protection Authority: Kifisias 1-3, 11523 Athens, tel. +30 210 6475600, www.dpa.gr, contact@dpa.gr — or to the supervisory authority of the EU country where you live or work.

10. Data we process on behalf of customers

When you call a business that uses Grammateas, the call is answered by a digital assistant. Whatever is said — your name, your telephone number, the appointment, the transcript and, if the business has switched recording on, the audio file — belongs to the business you called. They are the controller; we are the processor.

These terms are written down in the Data Processing Agreement.

11. Children, automated decisions, changes

Children. The service is addressed to businesses. We do not knowingly collect data about children under 15. If we find that we have, we delete it.

Automated decision-making. The digital assistant converses, books appointments and takes messages. She takes no decisions with legal or similarly significant effects on people within the meaning of Article 22 GDPR, and builds no profiles for advertising. At any moment you can ask to speak to a person and the call is transferred.

Changes. If anything material changes, we update the date at the top and, for customers, send a notice before it takes effect. Previous versions are available on request.