EyeWide - Service Provider Privacy Policy

Hosting and Website Services Provider 

This policy explains how EYEWIDE LTD (“we”, “us”, “our”) processes personal data in connection with websites that we host and, in many cases, also design, develop and administer. It applies to the personal data we process at the hosting and server level and, where we provide those services, in the course of building and administering a website. This is a standalone policy describing our own processing; it can be read on its own, and where the operator of a website we host has its own privacy and cookie policy, it sits alongside that policy. The website operator remains the controller of, and responsible for, the content of its website and any additional processing, cookies or tracking technologies that it or its service providers deploy. 

Who we are 

We provide the web-hosting infrastructure for this website. We have appointed a Data Protection Officer for the processing described in this policy. Our details are: 

Company: EYEWIDE LTD 

Registered address: 12 Konstantinoupoleos Street, Heraklion, Crete, Greece 71304 

Data Protection Officer: dpo@eyewide.gr 

For any questions about the processing described in this policy, or to exercise your rights, please contact us using the details above. 

Website design, development and administration 

In many cases we are also the designer, developer and administrator of this website, which we provide as a service to the website operator (our client). In that role we act as a data processor on behalf of the website operator, who is the data controller and who provides the content published on the website. We process personal data in this role only on the website operator’s documented instructions and under a written data processing agreement that meets the requirements of Article 28 of the GDPR. 

In the course of designing, building, maintaining and administering the website, we may have access to the personal data contained in the content the website operator provides to us for publication, to personal data that visitors submit through the website (for example, through contact or enquiry forms), and to the technical and account data needed to configure and maintain the website. 

We process this data solely to design, develop, configure, maintain and administer the website on the website operator’s behalf, and not for our own purposes. Because we act as a processor in this role, the legal basis for this processing, and the information provided to you about it, are determined and given by the website operator, as data controller, in its own privacy policy. 

Server access and security logs 

Our servers automatically record a log entry for every request made to this website. This logging takes place at the server level for security and operational reasons. It operates independently of any cookies and independently of any consent given or withheld on this website. For each request, we record: 

  • the IP address of the requesting device; 
  • the page or resource requested; 
  • the date and time of the request; 
  • the response status returned by the server; 
  • the type and version of the browser or client making the request (the user agent); and 
  • the referring page or source, where provided by the browser. 

We use this information solely to protect the security, availability and integrity of the hosting infrastructure and the websites it serves, to detect, investigate and prevent malicious or abusive activity, and to diagnose and resolve technical problems. We do not use these logs to build visitor profiles or to track individuals across sessions or websites. 

An IP address is personal data under the General Data Protection Regulation (GDPR) (Article 4(1); see also Recital 30). Our legal basis for this processing is our legitimate interests (Article 6(1)(f)) in maintaining the security, availability and integrity of our systems and of the websites we host. We retain these logs for 90 days, after which they are deleted or anonymised. 

No analytics from our hosting infrastructure 

The web-statistics and traffic-analysis tools bundled with our hosting environment are disabled on all domains we host. The server access logs described above are not processed into visitor analytics, audience measurement or usage statistics by our hosting infrastructure, and we do not use those logs to analyse your browsing behaviour or to build marketing or advertising profiles. 

Any analytics, statistics or tracking technologies you encounter on this website are configured by the website operator, or by us acting on the website operator’s behalf, and are governed by the website operator’s own privacy and cookie policy, not by this policy. 

Administrative access to the hosting environment 

Access to the administrative controls of the hosting environment is restricted to our own authorised personnel. Neither the website operator nor its staff have access to these administrative controls. Administrative connections are permitted only from our own controlled network addresses, and the administrative activity log therefore records the actions of our personnel — not those of the website operator or of site visitors. 

Cookies 

We do not place cookies or similar tracking technologies on your device through the hosting infrastructure itself, and the server-level logging described above does not rely on, and is not affected by, cookies or your cookie preferences. 

The cookies and similar technologies used on this website are set by the website operator, by us acting on the website operator’s behalf, or by third-party services integrated with the website. As part of building and administering this website, we typically implement Google Analytics (to help the website operator understand how the site is used) and a cookie-consent banner (to obtain and record your cookie choices); where consent is required, Google Analytics is loaded only after you give your consent through the banner, and you can change or withdraw your consent at any time using the same banner. 

The specific cookies used on a website we manage are listed in that website’s own cookie declaration, which is generated by our cookie-consent tool and made available through the consent banner on the site. The declaration is refreshed automatically as the site is re-scanned, so it reflects the cookies actually in use. Further detail may also appear in the website operator’s own cookie policy. 

Your rights 

Where we process your personal data as described in this policy, and to the extent the GDPR applies to you, you have the right to request access to that data, to request its rectification or erasure, to request restriction of its processing, and to data portability, in each case subject to the conditions and exceptions set out in Articles 15 to 22 of the GDPR. 

Because we rely on legitimate interests for the server logging described above, you also have the right to object to that processing on grounds relating to your particular situation (Article 21 of the GDPR). 

In addition, a website operator whose site we host may ask us to disable IP-address logging for their domain. Where we do so, IP addresses will not be recorded in the server logs for that domain. 

You have the right to lodge a complaint with a data protection supervisory authority, which in Greece is the Hellenic Data Protection Authority (HDPA; www.dpa.gr). To exercise any of these rights in respect of the processing for which we are the controller (the server logs described above), please contact us using the details in “Who we are” above. Where we act only as a processor on the website operator’s behalf, please direct your request to the website operator, as data controller, and we will assist them in responding as required. 

Sub-processors 

We rely on the following third-party providers (sub-processors) to deliver the hosting service; depending on the configuration of a particular website, not all of them are engaged for every site: OVHcloud (OVH), which provides the public-cloud infrastructure on which the servers and website files are hosted, including the compute instances, IP addressing, storage, backups and network firewalling; Microsoft Azure Front Door, a content delivery network (CDN) used to serve files for certain websites; and Cloudflare, which provides DNS and content delivery network (CDN) services for certain websites. Some of these providers operate global networks and may process data outside the European Economic Area (EEA); where personal data is transferred outside the EEA, we put in place an appropriate transfer mechanism recognised under the GDPR, such as the European Commission’s Standard Contractual Clauses. 

Governing law and updates 

This policy is governed by the laws of Greece, including the GDPR and Greek Law 4624/2019, which implements and supplements the GDPR in Greece. We may update this policy from time to time to reflect changes in our practices or in legal requirements; the version that applies is the one published here at the time of your visit.