Privacy Policy
Comprehensive Privacy Statement
Information on the Processing of Personal Data
Team Candi Single Person Société Anonyme (hereinafter: the Company), with its registered office in Kallithea, at 2a Argyroupoleos st., Postal Code 176 76, with TIN 800467450, email: info@candi.gr, tel.: 211 – 9994800, website: https://candi.gr/, as duly represented, hereby informs that, for the purposes of its business activities, it processes the personal data of its customers and the users of its services in accordance with the applicable national legislation and the European Regulation 2016/679 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation, hereinafter referred to as the “Regulation”) as in force.
Team Candi Single Person Société Anonyme in its capacity of the provider of CandiSign services provides this information on the processing of personal data in the context of the provision and use of its services.
We would like to assure you that for our Company, the protection of the personal data of its customers and users of its services is of paramount importance. For this reason, we take all appropriate measures in order to protect the personal data we process and to ensure that personal data is always processed in accordance with the obligations imposed by the legal framework, both by the Company itself and by third parties processing personal data on behalf of the Company.
We would also like to assure you that at Team Candi Single Person Société Anonyme, we do not collect data about minors under the age of 16.
What is the GDPR?
The General Data Protection Regulation (GDPR) is the new regulatory framework of the European Union (EU) in this area. The purpose of the Regulation is to establish the conditions for the processing of personal data in order to protect the rights and freedoms of natural persons, in particular the right to the protection of personal data.
Contact details for the personal data protection
For any matter relating to the processing of personal data, please contact the email: dataprotection@candi.gr.
Company’s Role in the Processing of Data
Team Candi Single Person Société Anonyme processes personal data only if it has a legitimate reason to do so, ensuring that they are strictly necessary for the specific processing purposes, always in full compliance with the applicable regulatory framework. Our Company in the context of the provision, development, provision, support and operation of CandiSign services, depending on the specific elements and the specific context of data processing, acts either as a Data Controller or as a Data Processor.
In accordance with the General Data Protection Regulation, the Company acts as a Data Controller when it determines the purposes and manner of processing of personal data, while it acts as a Data Processor in cases where it processes personal data on behalf of the Data Controller.
Thus, the Company is a Data Controller for certain processing activities such as the provision of information about the CandiSign product and the services related to it, the process of your orders and related transactions, the creation and activation of accounts for the use of the services, the management of our contractual relationship and the adoption of actions related to its modification, renewal, and termination.
Furthermore, as part of our customers’ use of CandiSign services, we process and store limited personal information on their behalf as Data Processors. For example, in the context of e-signing through CandiSign, when a customer uploads contracts or other documents for review or signature, we act as Data Processors and process the documents on the customer’s behalf and in accordance with the customer’s instructions. In these cases, the customer is the data controller and is responsible for the specific aspects of the processing of personal data. If you have any questions about how we process personal data in these cases, including how to exercise your rights as a data subject, you should contact the customer (the natural or legal person requesting your signature). In case we receive requests to exercise rights relating to situations in which we act as data processors, we will forward your query to the relevant customer.
Moreover, we process and store the minimum necessary personal data (first name, last name, email address) through CandiSign Portal for administrators who use the CandiSign service through Microsoft Teams. The processing of the above personal data is carried out exclusively for the purposes of providing and operating the CandiSign service through Microsoft Teams, managing user accounts and access rights and ensuring the security, functionality, and technical support of the portal.
The personal data collected are limited to those necessary for the creation, administration, and operation of administrator user accounts within the portal. Such data may include identification and contact details, as well as technical and usage-related information required for access and proper operation of the service, as displayed in the relevant screenshots.
Please note that in cases where the Company acts as a Data Processor, it is our customer who determines the appropriate legal basis relating to the processing activities and any queries you may have about the applicable legal basis for processing should be directed to them.
What categories of personal data do we collect and from which sources?
We only process your personal data when we have a legitimate reason to do so. The personal data we collect and process are those that are strictly necessary, required and appropriate in order to achieve our intended purposes.
With regard to the personal data, we collect directly from you, we inform you that you must notify us of any changes to your data without delay, as well as respond to any request for updating.
Personal data that we collect from you, such as:
- Personal identification data & legalization data of the subject of the transactions (name, date of birth, gender, identity card or passport details, TIN, tax office, ID number, profession, etc.),
- Contact data (postal address, e-mail address, fixed or mobile telephone number, etc.).
- Transaction data (products or services purchased, methods of payment, etc.)
- Data when providing and operating the CandiSign service through Microsoft Teams (name, surname, email address)
Thus, we collect your personal data when you register or log in to your account, when you use our services to sign or review an electronic document, when you create or edit your user profile to use our services, when you contact customer support, when you submit a request for information about our services, when you subscribe to our newsletter to receive updates and offers.
Personal data collected automatically:
We may automatically collect personal information from you and your devices when you use our services, including when you visit our websites or apps without logging in.
The categories of personal information we may automatically collect include:
- Device, Usage Information and Transaction Data. We collect personal information about how you use our services and the devices (e.g., computers, mobile phones, tablets) you use to access them. This may include, but is not limited to:
- IP ad
- Precise geolocation information that you allow our applications to access (usually from your mobile device). To prevent collection of this information, you can disable location sharing on your device, change your device’s privacy settings, or deny location sharing in your browser.
- Unique device identifiers and device characteristics, such as operating system and browser type.
- Usage Data, such as web log data, referring and exit pages and URLs, platform type, click count, domain names, landing pages, pages and content viewed and the order of those pages, time spent on specific pages, date(s) and time(s) you used our Services, frequency of use of our Services, error logs, and other relevant information.
- Transaction Data, such as names and email addresses of the parties to a transaction, subject line, history of actions individuals take, in connection with a transaction (e.g., review, signatures, activation of features), and personal information about those individuals or their devices, such as name, email address, IP address, and authentication methods.
- Cookies and related technologies. We use cookies, which are text files containing information that is downloaded to your device, or related technologies, such as web beacons, local shared objects and tracking pixels, to collect and/or store information. For additional information about cookies and related technologies, including details on how to accept or reject them, please read our Cookie Policy by clicking on https://candisign.gr/cookies-policy/.
Personal data we collect from other sources:
Always in compliance with the applicable data protection regulatory framework, we collect and process your personal data from other sources, such as:
Third Parties, Business Partners and Affiliates: Examples of such sources include our business partners, associates, service providers and others who, where legally permitted to share your personal information with us, take action to do so. For example, if you sign up for our services on another website, that website may provide us with your personal information if permitted by the applicable regulatory framework.
Other customers: Other customers may provide us with your personal information. For example, if a customer wants you to sign an electronic document through our services, they will provide us with your email address and name.
Combining personal information from different sources: We may combine the personal information we receive from other sources with personal information we collect from you (or your device) and use it as described in this Statement, always in accordance with applicable law.
Personal information we collect and process on behalf of customers:
As part of our customers’ use of CandiSign services, we process personal data on their behalf as Data Processors. In these cases, the customer is the data controller and is responsible for the specific aspects of the processing of personal data, while we act as processors and process personal data on behalf of the customer and in accordance with the customer’s instructions.
For what purposes do we process your personal data?
We process your personal data, always in accordance with the conditions set by applicable law. Thus, we process your personal data for the purposes listed hereinbelow:
- To send updates and offers (newsletter)
If you have consented to this or it is covered by our legitimate interest (in the case of our business customers-partners) and under the specific conditions set by the legal framework, we send you updates on products, services, offers, etc. via E-mail, SMS, or telephone, but also via the social media we maintain (Facebook/Instagram/Youtube). In particular, both our Company and other companies of the Group to which the Company belongs or third partner associate companies, which process personal data in accordance with the, from time to time, applicable framework, inform you about our offers and news by sending informative newsletters.
- To explore cooperation and provide information in connection with CandiSign services, upon request
In cases where you submit a request to contact us, either through the contact form on https://candisign.gr/ or by sending a request to our company’s contact details, regarding the provision of information about the capabilities and solutions provided by our services, we will process your identification and contact details (such as name, email, mobile/landline phone) that we receive from you in order to respond to your request and provide you with information in relation to our services.
- To manage our contractual relationship
In cases where you wish to receive our services, we process your personal data for the purpose of configuring the service package you have chosen, arranging your orders, drawing up the relevant contracts, processing the relevant transactions. Further, in this context we process your personal data in the context of managing our contractual relationship such as for the modification, renewal, expiry, and termination of the contractual relationship.
- To activate, provide and manage our services
In order to provide our services, we process your personal data to create a user account, provide information on the use of the services, provide data and updates on tasks and actions on electronic documents carried out through our services (e.g., who initiated, viewed or signed the documents, IP addresses of signatories, timestamps).
- To provide support to users of our services
We further process your personal data to resolve problems you may have with our services, including providing answers to support, customer and user education and training questions.
- To manage the platform of the Services, including support systems and security.
For the purpose of systemic stability of the information systems of the Services, we may process personal data to ensure the security of the information elements of the platform for the provision of the relevant Services.
- To prevent, investigate and respond to cases of fraud, unauthorized access or use of our Services, violation of terms and policies or other illegal conduct.
Where required, we will process personal data to identify cases of fraud, unauthorized access or use of our Services and violation of the contractual terms and conditions of our Services.
- To improve services and develop new ones
As part of the continuous improvement of our services, we may process your personal data to develop new products and services in order to better meet the needs of our customers.
- To comply with legal obligations
Where our Company is subject to specific legal obligations governing its operating framework, we will process the personal data strictly necessary to comply with those obligations.
What are the legitimate grounds for processing your personal data?
The Company, acting both in its role as Data Controller and in cases where it acts as Data Processor, processes personal data in compliance with the applicable regulatory framework, in accordance with the principles of lawfulness, objectivity and transparency, purpose limitation, data minimization, accuracy, storage time limitation, confidentiality and integrity, always respecting the principle of accountability.
The lawful basis for processing your personal data, in cases where we act as Data Controllers, is determined according to the specific elements of each processing activity and on a case-by-case basis is:
- the necessity of processing your data in the context of the performance of our contractual relationship in the fulfilment of our contractual obligations or in the pre-contractual stage prior to the conclusion of a service contract for the performance of relevant acts and operations.
- the necessity of processing your data in the context of safeguarding our legitimate interests, provided that your data protection interests or your fundamental rights and freedoms do not supersede. In this context, we process personal data such as to ensure the security of the information assets and applications through which we provide our services, to ensure the uninterrupted operation of our services, to prevent, detect and respond to cases of fraud, to improve and develop our services.
- the compliance with an obligation imposed by law, so where required by the regulatory framework governing our Company, we process personal data for our compliance with the applicable legal provisions.
- the consent you provide under the specific conditions set by the regulatory framework, in order to receive updates on products, services, offers.
We note that in cases where the Company acts as a Data Processor, and processes personal data on behalf of a customer and in accordance with the customer’s instructions, it is the customer who determines the appropriate legal basis related to the processing activities and any questions you may have regarding the applicable legal basis for processing should be addressed to the customer.
Who are the recipients of personal data?
Our Company, in the context of the aforementioned processing purposes and in accordance with the legal reasons set out above, under the conditions set by the applicable legal framework, transmits personal data, as appropriate, to third parties, such as partners, companies providing support for our services, companies sending updates on products and offers.
In particular, the Company in the context of providing CandiSign services and support of its related software, since the relevant services are provided electronically via the Internet, stores all information entered in the software and relating to the services provided in Microsoft’s cloud infrastructure. For more information on the processing of personal data by Microsoft for this service see: https://privacy.microsoft.com/en-gb/privacystatement . Furthermore, and in connection with the use of our services relating to the electronic signature of documents and for the provision of the relevant service, the recipient of your absolutely necessary personal data is Docusign. For more information on the processing of personal data by DocuSign for this service see: https://origin.docusign.com/privacy/ .
Where the Company acts as Data Controller, it remains responsible for the processing of your personal data and defines the individual elements of the processing, and signs a specific contract with the third parties to whom it entrusts the performance of processing activities on its behalf, in order to ensure that the processing is carried out in accordance with the applicable legal framework and that each natural person can freely and unhinderedly exercise the rights conferred by the legal framework. The Company has lawfully ensured that those who process data on its behalf meet the requirements and provide sufficient assurances that appropriate technical and organizational measures are in place, in order to ensure that the processing of your personal data ensures the protection of your rights.
Furthermore, in the context of the provision of our services and their use by end users, personal data may, where applicable, be transferred to other CandiSign users where you have allowed them to access, use or process content in your account (e.g. if you send a folder to other users for review or signature, the content of the folder is made available to them), to the organization that holds the account of our services of which you are a user, when you create an account or a user role with an email address assigned to you as an employee, partner or member of an organization, that organization, if it is a customer of CandiSign services with certain features) may find your account and proceed to certain actions that may affect your account.
Moreover, we may transfer your personal data, if so required by law, to the competent judicial, prosecutorial, police, supervisory, or regulatory authorities or in the context of judicial or extrajudicial actions of a procedural nature, law enforcement bodies, government authorities and other third parties for the purpose of complying with our relevant legal obligations such as for the purpose of preventing or detecting criminal acts, providing customer account information, etc.
Please note that some of the recipients of your personal data listed above may be located in countries outside the European Economic Area, whose legislation may not provide an equivalent level of data protection. In such cases, we will ensure that adequate safeguards are in place to protect your personal data, which are in line with our legal obligations and comply with applicable law.
For further information about the transfers to countries outside the European Economic Area listed above and the appropriate safeguards we apply in relation to them (including copies of the relevant agreements), please contact the following email: dataprotection@candi.gr.
Data Retention Period
The data retention period is decided on the basis of the following specific criteria as the case may be:
Where processing is imposed as an obligation by provisions of the applicable legal framework, your personal data will be stored for as long as the relevant provisions require.
Where processing is carried out on the basis of a contract, your personal data will be stored for as long as necessary for the performance of the contract, while in the event of its termination, where and for those data for which it is not otherwise required by law as above, the personal data will be kept for a period of 3 months, after which they will be deleted. If legal claims of a judicial or extrajudicial nature arise in the context of the performance of the contract, your personal data will be stored for as long as necessary for the establishment, exercise, and/or support of legal claims based on the contract.
Where processing is based on your consent, your personal data shall be kept until your consent is withdrawn. This can be carried out by you at any time. Withdrawal of consent does not affect the lawfulness of the processing based on consent in the period prior to its withdrawal.
To withdraw your consent, you can contact the following email: dataprotection@candi.gr .
What are your rights in relation to your personal data?
Every natural person whose data is processed by the Company enjoys the following rights:
Right of access:
You have the right to be aware of and verify the lawfulness of processing. Therefore, you have the right to have access to the data and to obtain additional information about their processing.
Right to rectification:
You have the right to study, rectify, update or modify your personal data.
Right to erasure:
You have the right to request the erasure of your personal data when we process them on the basis of your consent or in order to protect our legitimate interests. In all other cases such as, by way of indication, where there is a contract, where there is an obligation to process personal data imposed by law, said right is subject to specific limitations or does not exist as the case may be.
Right to restrict processing:
You have the right to request the restriction of processing of your personal data in the following cases: (a) where the accuracy of the personal data is contested and until verification is made; (b) where you object to the erasure of personal data and request restriction of use instead of erasure; (c) where the personal data are not necessary for the purposes of processing, but is nevertheless necessary for the establishment, exercise, support of legal claims; and (d) where you object to processing and until it is verified whether there are legitimate grounds concerning us which supersede the reasons why you object to the processing.
Right to object to processing:
You have the right to object at any time to the processing of your personal data where, as described above, it is necessary for legitimate interests pursued by us as data controllers, as well as to processing for direct marketing purposes.
Right to data portability:
You have the right to receive your personal data free of charge in a format that allows you to access, use and process it by commonly used processing methods. You also have the right to ask us, where technically feasible, to transfer the data directly to another data controller. This right exists for data that you have provided to us and is processed by automated means on the basis of your consent or in performance of a relevant contract.
Right to withdraw consent:
Finally, the Company informs you that where the processing is based on your consent, you have the right to freely withdraw it, without affecting the lawfulness of the processing based on your consent before such withdrawal. To withdraw your consent, please contact us by email: dataprotection@candi.gr.
You can also use the unsubscribe options by clicking on the corresponding link in our electronic communications.
To exercise any of the above rights, you can contact us by email at: dataprotection@candi.gr.
In the above cases, we will make every effort to respond to your request within thirty (30) days upon its submission. Said period may be extended for sixty (60) additional days, if deemed necessary, taking into account the complexity of the request and the number of requests, in which case we will inform you within the aforementioned thirty (30) day period.
Our Company is itself responsible for responding to, evaluating and managing your aforementioned requests in cases where it acts as Data Controller of your personal data.
If we receive requests to exercise rights relating to cases where we are acting as Data Processor on behalf of a customer, we will forward the request to the relevant customer. If you have any questions about how we process personal data in these cases, including how to exercise your rights as a data subject, you should contact the customer (the natural or legal person requesting your signature).
Right to complain to the Hellenic Data Protection Authority
Ιn the event that you do not receive a response within the legally prescribed timeframe or your issue has not been resolved, you may contact the Hellenic Data Protection Authority (http://www.dpa.gr/).
Personal Data Security
The Company applies appropriate technical and organizational measures to ensure the secure processing of personal data and to prevent accidental loss or destruction and unauthorized and/or unlawful access, use, modification or disclosure of personal data. In any case, the way the Internet works and the fact that it is free to anyone does not allow for guarantees that unauthorized third parties will never be able to breach the technical and organizational measures in place, gaining access and possibly making use of personal data for unauthorized and/or illegitimate purposes.
Information on the Cookies Policy
We use cookies for the operation and optimal provision of our services. You can see in detail which cookies we use and our Cookies Policy by clicking on https://candisign.gr/cookies-policy/. You also have the option to change your choices by clicking on https://candisign.gr/cookies-policy/.
Changes to the Privacy Policy
The information on this privacy policy reflects the current state of data processing. In the event of changes in data processing, this data protection information will be updated accordingly. On our website and in the relevant applications of our services, the latest version of this data protection information will always be available, so that you are kept up to date on the scope of data processing. We encourage you to always be aware of how we process and protect your personal information. All future changes regarding this Privacy Statement will be made known to the sources listed above.
Last Update 22/12/2025
FA-RUL-15-3-(v1)