Privacy Policy
Last updated: 22 July 2026 | Version: 2.0
1. Who we are
This policy explains how MANA GI SINGLE MEMBER P.C. (trading as ManaGi) collects, uses and protects your personal data when you visit or use the website managi.eu.
ManaGi acts as Data Controller under the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.
- Company name: MANA GI SINGLE MEMBER P.C. (ΜΑΝΑ ΓΗ ΜΟΝΟΠΡΟΣΩΠΗ ΙΚΕ)
- VAT number: EL800817386
- Registered office: Agios Ioannis, Pyrgos Ilias, 27100, Greece
- Operating address: Nafsikas 237, Ilion, Athens, 13122, Greece
- Phone: +30 211 001 5245
- Data protection contact: [email protected]
2. What data we collect
2.1 Data you provide
- Identification — full name, company name, VAT number
- Contact details — email, phone, address, country
- Order details — products, quantities, shipping and billing address
- Account details — username, encrypted password
- Communication content — messages, quotation requests
We do not collect special categories of data (health, religious or political beliefs, biometric data, etc.) and we ask you not to send us such information.
2.2 Payment data
Card payments are processed by Revolut through the WooCommerce platform. We do not store card numbers, CVV codes or payment credentials on our systems. We receive only the transaction confirmation and the last digits of the card.
2.3 Data collected automatically
- IP address, browser type and version, operating system
- Pages visited, date and time, time spent on each page
- Security data (failed login attempts, suspicious activity)
3. Why we process your data and on what legal basis
- Order fulfilment, shipping, customer service — performance of a contract, Article 6(1)(b)
- Managing your user account — performance of a contract, Article 6(1)(b)
- Issuing and retaining invoices — legal obligation, Article 6(1)(c)
- Responding to requests and enquiries — legitimate interest, Article 6(1)(f)
- Website security, fraud prevention — legitimate interest, Article 6(1)(f)
- Newsletter — consent or legitimate interest, see section 4
- Non-essential cookies — consent, Article 6(1)(a)
4. Newsletter and commercial communication
You may receive commercial communication from us if:
- you actively subscribed to our list (legal basis: consent), or
- you provided your details in a professional context — a trade fair, a business card, previous correspondence — and our products are relevant to your business activity (legal basis: legitimate interest in business-to-business communication).
In every case: each message contains an unsubscribe link, unsubscribing is immediate and free of charge, and you may at any time ask us where we obtained your details by writing to [email protected].
We do not send commercial messages to private consumers without prior consent.
5. Who we share your data with
We do not sell or rent personal data. We share it only with providers acting as Data Processors on our behalf, bound by contract under Article 28 GDPR:
- Hostinger — website and database hosting — EU (Lithuania)
- Cloudflare — content delivery, security, attack protection — USA / global network
- Google Workspace — corporate email, document storage — USA / EU
- Brevo — transactional and newsletter email delivery — EU (France)
- Revolut — card payment processing — EU (Lithuania)
- Airtable — contact and sales opportunity management — USA
- Make (Celonis) — workflow automation — EU (Czech Republic)
We may also share data with:
- Freight forwarders and customs brokers, solely to deliver your order
- Accountants and legal advisors, bound by professional confidentiality
- Public authorities, where required by law or court order
Transfers outside the EEA
Some providers (Cloudflare, Google, Airtable) are established in the United States. Transfers are carried out on the basis of the European Commission’s Standard Contractual Clauses and/or the EU–US Data Privacy Framework, with additional technical measures (encryption in transit and at rest).
6. How long we keep your data
- Invoices and tax records — 5 years from the end of the financial year (Greek tax legislation)
- User account details — while the account is active + 2 years
- Order history — 5 years
- Correspondence and enquiries — 24 months from last contact
- Newsletter subscription — until you unsubscribe
- Cookies — up to 12 months
- Security logs — 12 months
After these periods, data is securely deleted or anonymised.
7. Cookies
Our website uses cookies:
- Strictly necessary — login, shopping cart, security. No consent required.
- Functional — language, display preferences.
- Statistical / measurement — anonymous traffic measurement via Cloudflare.
We do not use advertising, targeting or cross-site tracking cookies.
You can manage or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent the cart and login from working.
8. Security
We apply technical and organisational measures appropriate to the risk, including:
- Encryption of all communication (HTTPS/TLS)
- Two-factor authentication for all administrators
- Web application firewall and protection against automated attacks
- Role-based access control
- Regular backups and software updates
No method of transmission or storage is completely secure. In the event of a breach likely to affect your rights, we will notify the Data Protection Authority within 72 hours and you without undue delay.
9. Your rights
- Access (Art. 15) — to know what data we hold about you and receive a copy
- Rectification (Art. 16) — to correct inaccurate or incomplete data
- Erasure (Art. 17) — where no lawful ground for retention applies
- Restriction (Art. 18) — to request suspension of processing
- Portability (Art. 20) — to receive your data in a machine-readable format
- Objection (Art. 21) — to processing based on legitimate interest or to direct marketing
- Withdrawal of consent (Art. 7) — at any time
How to exercise them: send a request to [email protected]. We respond within one month. We may ask for proof of identity, to ensure data is not disclosed to a third party.
Right to lodge a complaint: you may contact the Hellenic Data Protection Authority: 1–3 Kifissias Avenue, 115 23 Athens, Greece, tel. +30 210 6475600, [email protected], www.dpa.gr
10. Automated decision-making
We do not make decisions concerning you based solely on automated processing, and we do not carry out profiling with legal or similarly significant effects.
11. Minors
This website is intended for businesses and adults. We do not knowingly collect data from individuals under 16. If we become aware that we have received such data without parental consent, we delete it immediately.
12. Links to other websites
Our website may contain links to third-party sites. We do not control and are not responsible for their privacy practices. We recommend reading the privacy policy of every website you visit.
13. Changes to this policy
Each new version is published on this page with an updated date and version number. In the event of material changes, we will notify you by email or through a prominent notice on the website before they take effect.
14. Contact
MANA GI SINGLE MEMBER P.C.
Nafsikas 237, Ilion, Athens 13122, Greece
Tel.: +30 211 001 5245
Email: [email protected]