Privacy Policy
Synapsecom Telecoms S.A. — telecommunications and cloud services provider
Last updated: 2026-09-05
1. Who we are
Synapsecom Telecoms S.A. ("Synapsecom", "we", "us") is a Greek electronic communications and cloud services provider. We are the data controller for the personal data described in this policy, except where we act as a data processor on behalf of a Customer (see Section 9).
| Controller | Synapsecom Telecoms S.A. |
| Registered office | 64 Pontou Street, B KTEO region, Kalochori, 54628, Thessaloniki, Greece |
| General contact | support@synapsecom.gr |
| Privacy / data protection contact | privacy@synapsecom.gr |
| Abuse reports | abuse@synapsecom.gr |
| Website | https://synapsecom.gr |
This policy covers our public website and documentation, the Liquid Cloud Services Portal, and all colocation, connectivity, cloud and managed services we deliver. It supplements — and does not replace — the Terms & Policies applying to each service.
2. Data we collect
2.1 Data you give us
- Identification and contact data — name, company, VAT/GEMI number, postal address, email, telephone.
- Contractual and billing data — service orders, subscribed products, invoices, payment status, bank or card details processed through our payment providers.
- Account and access data — Portal usernames, hashed passwords, MFA configuration, SSH keys, API tokens.
- Support data — tickets, correspondence, and, where you have been informed in advance, recordings of calls to our support desk.
2.2 Data generated by using our services
- Traffic and connection data — source and destination IP addresses, ports, protocols, session start/end times, volumes, and equivalent metadata generated by the operation of our network, as required to convey communications and bill for them.
- Service telemetry — VM, storage, power and bandwidth usage counters, availability and performance metrics, backup and snapshot records.
- Security and audit logs — Portal and infrastructure authentication events, administrative actions, firewall and abuse-detection events, SMTP logs as described in the SMTP Policy, and datacentre access-control and CCTV records at our facilities.
- Website data — pages viewed, referrer, browser and device type, and cookie identifiers, as described in Section 8.
2.3 What we do not collect
We do not access the content of your communications, the data stored inside your virtual machines, or the equipment you place in our datacentres, except as described in Section 9.
We do not use personal data for targeted or personalised advertising, we do not sell or transfer personal data to data brokers or information resellers, we do not use it for credit-scoring or lending decisions by third parties, and we do not use it to train generalised artificial-intelligence or machine-learning models.
3. Why we use it, and on what legal basis
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Providing and operating the contracted services | Contact, account, traffic, telemetry | Performance of a contract — Art. 6(1)(b) |
| Provisioning, support and incident handling | Contact, account, support, logs | Performance of a contract — Art. 6(1)(b) |
| Billing, collections, accounting | Contractual, billing, usage counters | Contract — Art. 6(1)(b); legal obligation — Art. 6(1)© |
| Network and information security, abuse and fraud prevention | Traffic, security logs, IP reputation data | Legitimate interests — Art. 6(1)(f); Art. 32 |
| Capacity planning and service improvement | Aggregated or pseudonymised telemetry | Legitimate interests — Art. 6(1)(f) |
| Physical security of datacentres | Access-control records, CCTV | Legitimate interests — Art. 6(1)(f) |
| Statutory reporting, lawful requests, retention duties | As required by the request or duty | Legal obligation — Art. 6(1)© |
| Service notices and outage notifications | Contact data | Contract — Art. 6(1)(b) |
| Marketing communications | Contact data | Consent — Art. 6(1)(a), or soft opt-in under Law 3471/2006 Art. 11 |
| Analytics cookies on our websites | Cookie identifiers, usage data | Consent — Art. 6(1)(a) |
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (see Section 10).
4. Who we share it with
We disclose personal data only to the following categories of recipients, and only to the extent needed:
- Subcontractors and service providers acting on our instructions — datacentre and carrier partners, hardware and software maintenance vendors, monitoring and backup platforms, billing and CRM systems, email delivery providers. Each is bound by a written data-processing agreement under GDPR Art. 28.
- Upstream and interconnecting operators — where required to route, deliver or troubleshoot a communication, or to resolve abuse originating from or directed at your service.
- Licensors — where you consume licensed third-party software through us (for example, Microsoft under the SPLA programme), we report the licence counts and, where the programme requires it, the end-customer identity.
- Payment institutions, banks, accountants and auditors — for payment processing and statutory accounting.
- Legal and professional advisers, debt-collection agents, insurers — where necessary to establish, exercise or defend legal claims.
- Public authorities — EETT, the Hellenic Data Protection Authority, the ADAE, tax authorities, courts, prosecutors and law-enforcement bodies, where we are legally compelled. We assess each request for validity and disclose the minimum required. We will notify you of a request concerning your data unless legally prohibited from doing so.
- A successor entity — in a merger, acquisition or transfer of the business or part of it, subject to this policy continuing to apply.
We do not sell personal data.
5. International transfers
Our infrastructure and our primary processors are located within the European Economic Area. Where a processor operates outside the EEA, the transfer is made under an adequacy decision of the European Commission or, failing that, under Standard Contractual Clauses together with supplementary technical measures (encryption in transit and at rest, key custody retained by us). A list of the processors and the transfer safeguards applying to your services is available on request from privacy@synapsecom.gr.
6. How we protect it
- Encryption in transit (TLS) for the Portal, our websites and management interfaces; encryption at rest for backups.
- Role-based access control, mandatory multi-factor authentication for administrative access, and least-privilege segregation between customer environments.
- Physically secured, access-controlled and monitored datacentre facilities.
- Logging and monitoring of administrative and authentication activity, with alerting on anomalies.
- Network filtering, DDoS mitigation, patch management and vulnerability remediation on the infrastructure we operate.
- Confidentiality obligations and training for personnel with access to customer data.
- Documented backup, restore and incident-response procedures, tested periodically.
If a personal data breach occurs, we notify the Hellenic Data Protection Authority within 72 hours where the breach is likely to result in a risk to individuals, and we notify affected customers and individuals without undue delay where the risk is high. Breaches affecting the security of the public electronic communications service are additionally notified under Law 3471/2006 and Regulation (EU) 611/2013.
7. How long we keep it, and how it is deleted
| Category | Retention |
|---|---|
| Contract, order and account records | Duration of the contract + 5 years (limitation period) |
| Invoices and accounting records | 10 years (Greek tax and accounting law) |
| Traffic and billing metadata | Up to 12 months for billing and dispute purposes; longer only where a specific statutory retention obligation applies |
| Security, authentication and administrative audit logs | 12 months |
| SMTP logs | Minimum 5 days as required by the SMTP Policy; up to 90 days for abuse investigation |
| Support tickets and correspondence | Duration of the contract + 2 years |
| Datacentre access records and CCTV footage | 15 days for CCTV; 12 months for access logs |
| Customer content in VMs, storage and backups | Deleted on termination, per the retention window in the applicable service terms |
| Website cookies | Per Section 8 |
| Marketing contact data | Until you withdraw consent or object |
When a retention period ends, data is deleted or irreversibly anonymised. Deletion of customer content follows the destruction procedure in the applicable service terms: instances and volumes are destroyed and the underlying storage blocks released for reuse; backup copies age out of rotation within the stated retention window. Media that leaves our custody is securely wiped or physically destroyed.
Requesting deletion. You can request deletion of your personal data at any time by emailing privacy@synapsecom.gr from a registered contact address, or by opening a ticket in the Portal. We respond within one month. We must decline for data we are legally required to retain (invoices, statutory traffic records) and for data needed to defend a live legal claim; where that applies we tell you which data and why, and delete the rest.
8. Cookies
Our documentation and public websites set a strictly necessary cookie to remember your cookie choice and interface preferences. Analytics cookies, where enabled, are set only after you accept them in the consent banner and are used to measure whether visitors find what they are looking for. You can change or withdraw your choice at any time via the Change cookie settings link in the page footer, or by clearing cookies in your browser.
9. Customer data we process on your behalf
When you run systems on our cloud or place equipment in our datacentres, personal data belonging to your users may pass through or be stored on that infrastructure. For that data:
- You are the controller and we are the processor. We process it only on your documented instructions, which are the service agreement, this policy and any tickets you raise.
- We do not access the content of your systems except where you explicitly ask us to as part of a support request, where it is unavoidable to restore service or maintain infrastructure integrity, or where a lawful order compels us. Such access is logged.
- You remain responsible for the lawfulness of what you process, for informing your own users, for the security configuration inside your instances, and for responding to their data-subject requests. We will assist you with these where reasonably possible.
- Sub-processors and transfers are as described in Sections 4 and 5. We notify you of changes to sub-processors handling your data with reasonable notice.
- On termination, we return or delete the data in line with the applicable service terms.
Where you require a separate Data Processing Agreement under GDPR Art. 28, contact privacy@synapsecom.gr.
10. Your rights
Under the GDPR and Greek Law 4624/2019 you have the right to:
- Access the personal data we hold about you and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erase data ("right to be forgotten"), subject to the limits in Section 7.
- Restrict processing while a dispute over accuracy or lawfulness is resolved.
- Portability — receive data you provided in a structured, machine-readable format, or have it transmitted to another controller.
- Object to processing based on legitimate interests, and to direct marketing at any time and without justification.
- Withdraw consent where processing is based on consent, without affecting the lawfulness of what was done before.
- Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not carry out such decision-making.
To exercise any of these, email privacy@synapsecom.gr. We reply within one month, extendable by two further months for complex requests, in which case we tell you within the first month. There is no charge unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before we act.
If you are not satisfied, you may lodge a complaint with the Hellenic Data Protection Authority (HDPA), Kifisias 1-3, 115 23 Athens, www.dpa.gr, or with the supervisory authority of your habitual residence.
11. Children
Our services are sold to businesses and are not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe we have, contact us and we will delete it.
12. Changes to this policy
We may update this policy to reflect changes to our services, our processors or the law. The "Last updated" date above always reflects the current version, and material changes are communicated to active customers by email or Portal notice before they take effect. Continued use of the services after a change takes effect constitutes acknowledgement of the updated policy.
13. Contact
- 📧 Privacy and data protection: privacy@synapsecom.gr
- 📧 Support: support@synapsecom.gr
- 📧 Abuse: abuse@synapsecom.gr
- 🌐 https://synapsecom.gr