Privacy policy

Privacy and Personal Data Protection Policy

Compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable national legislation (Law 4624/2019).

Date of last update: 13/07/2026

1. Data controller and contact details

Data controller: Panhellenic Association of Professional Translators Graduates of the Ionian University (hereinafter ‘PEEMPIP’ or ‘the Association’), through its Board.

Data processor (in-house): PEEMPIP Board.

Data Protection Officer / point of contact: Dimitra Sachpatzidou, PEEMPIP Board member.

Contact details for matters relating to personal data:

  • Email: info@peempip.gr

 

For any enquiries regarding this policy or the exercise of your rights, please contact us using the details above.

2. Purpose of the policy

This policy explains how PEEMPIP collects, uses, stores and protects the personal data of individuals who come into contact with the Association. It covers both PEEMPIP members and non-members, such as website visitors and individuals who submit requests or enquiries via the Association’s forms and communication channels.

The aim is to provide you with transparent information and to ensure PEEMPIP’s compliance with the GDPR, including the principle of accountability.

3. Categories of data subjects

This policy applies to:

  • Members and prospective members of PEEMPIP;
  • Visitors to PEEMPIP’s website;
  • Interested parties who submit enquiries or requests via a form or by email;
  • Participants or individuals expressing an interest in the Association’s initiatives, events or activities;
  • Third parties who are not members, partners, representatives of organisations and any other person who contacts the Association.

 

4. Categories of data we collect

4.1. Data relating to members and prospective members

For example: full name, home address, work address, contact address (if different), landline and/or mobile telephone number, email address, tax identification number, proof of payment sent for the payment of subscriptions, sponsorships or donations, gender, degrees and training certificates, country of residence, legal entity, job title and related details required under the Articles of Association and provided by the members themselves in their profiles.

4.2. Non-members’ data (forms and communication)

For example: first name, surname, email address, telephone number, capacity or role, organisation represented, and the content of the message or request you submit.

We ask that you avoid sending special categories of data (e.g., health data) via the forms or by email, unless it is absolutely necessary for your enquiry.

4.3. Technical data

When you visit the website, technical data (e.g., IP address, browser type) may be collected by the hosting provider or via cookies, as described in section 15.

5. Methods of data collection

We collect data:

  • From the membership application form and the Articles of Association forms.
  • From the website’s contact form (WordPress).
  • From forms for submitting requests or registration forms, including Google Forms.
  • From emails you send to us.
  • From proof of payment documents that you send for subscriptions or donations.
  • From any other future data collection forms on the website or in linked tools.

 

6. Purposes of processing

For members:

  • Maintaining the Association’s Register and creating a member profile.
  • Transaction history between PEEMPIP and its members.
  • Issuing invoices and receipts.
  • Correspondence with members.
  • Reporting to the Audit Committee or the Disciplinary Council, as required by the Articles of Association.
  • Fulfilment of obligations arising from the Articles of Association.
  • Sending notices and updates to members.

 

For non-members:

  • Responding to enquiries and handling requests.
  • Communicating with the data subject.
  • Managing participation in or interest in activities, where applicable.
  • Maintaining the necessary communication records for a reasonable period of time.

 

We do not use data collected via forms or email for purposes unrelated to your enquiry. We do not send commercial or promotional communications without an appropriate legal basis or your consent, where required.

 

7. Legal basis for processing

We process your data on the basis of one or more of the following legal bases set out in Article 6 of the GDPR:

  • Performance of a contract or pre-contractual measures, Article 6(1)(b). This relates to the member’s relationship with the Association and the fulfilment of the obligations set out in the Articles of Association.
  • Compliance with a legal obligation, Article 6(1)(c). This relates in particular to tax and accounting obligations (e.g. keeping records).
  • Legitimate interest, Article 6(1)(f). This relates to responding to enquiries, handling requests and ensuring the secure operation of the website, provided that your rights do not take precedence.
  • Consent, Article 6(1)(a). This applies to cases where your consent is explicitly requested, such as certain forms, newsletters or non-essential cookies. You may withdraw your consent at any time, without this affecting the lawfulness of the processing carried out prior to the withdrawal.

 

8. Contact forms and other data submission forms

When you complete a contact form, enquiry form, Google Form or other form, the following applies:

  • What data is collected: only the details you enter into the form, usually your first name, surname, email address, telephone number, title and the content of your message.
  • Why they are collected: to respond to your enquiry, to process your request or participation, and to keep a record of our correspondence.
  • Who has access: members of the Board and the relevant working groups of PEEMPIP, to the extent necessary to process the request.
  • Third-party platforms: the forms operate via WordPress or Google Forms, and messages are received by the Association via its email provider. These providers act as data processors or recipients, as described in section 10.
  • Use of data: the data is not used for purposes unrelated to your enquiry and is not sold to third parties.
  • Marketing communications: No promotional messages or newsletters are sent without an appropriate legal basis or your consent, where required.

 

9. Processing of non-members’ data

The data of non-members who contact the Association (interested parties, visitors, participants in events, third parties submitting enquiries, partners, representatives of organisations) are processed solely for the purpose of managing their communication or enquiry.

  • Legal basis: as a general rule, the Association’s legitimate interest in responding to enquiries, or your consent where required.
  • This data is retained for a reasonable period, as set out in section 11, and is subsequently deleted or anonymised, unless there is a legal obligation to retain it.
  • It is not included in the Members’ Registry and is not used for purposes relating to membership.

 

10. Recipients and third-party providers

Your data may be accessed or transferred to:

  • Technical infrastructure and service providers, who act as data processors on our behalf, such as the WordPress website hosting provider, the email provider, and Google (Google Forms, Google Drive, Google Workspace).
  • Professionals and partners who provide services to the Association, such as accountants, consultants and technical support and IT specialists.
  • Third parties with whom we collaborate to provide services that benefit members, where applicable.

 

We enter into, or will enter into, contracts with data processors that include confidentiality and data protection clauses, in accordance with Article 28 of the GDPR.

International transfers: certain service providers (e.g., Google) may process data in countries outside the European Economic Area. In such cases, the transfer is governed by appropriate safeguards, such as an adequacy decision or the European Commission’s standard contractual clauses.

We do not sell your data to third parties.

11. Data retention period

We retain your data for as long as there is a legal obligation to do so or as long as it is necessary for the purposes for which it was collected.

  • Member data: for the duration of membership and, following cancellation, for the purposes of maintaining accounting records, history and archives, as well as for handling any enquiries.
  • Accounting and tax documents: for the period specified by tax legislation, in particular five years.
  • Non-members’ contact details: for a reasonable period following the conclusion of the communication, i.e., twelve months, unless a longer retention period is required.

 

Once the above periods have elapsed, the data is deleted or anonymised.

12. Your rights

Under the GDPR, you have the following rights:

  • The right to be informed about how your data is collected and processed.
  • The right to access your data.
  • The right to have inaccurate or incomplete data rectified.
  • The right to erasure (‘right to be forgotten’), Article 17 of the GDPR.
  • Right to restriction of processing, Article 18 of the GDPR.
  • Right to data portability, Article 20 of the GDPR.
  • Right to object to processing, Article 21 of the GDPR.
  • Right to withdraw consent, where processing is based on consent.
  • Right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).

 

Automated decision-making: PEEMPIP and its Board do not carry out automated individual decision-making or profiling.

13. How to exercise your rights

You may exercise your rights by submitting a written request via email to info@peempip.gr.

  • We will respond without undue delay and within one month of receiving your request. This deadline may be extended by a further two months where necessary, in which case we will inform you accordingly.
  • We may ask for information to verify your identity in order to protect your data.
  • Exercising your rights is, in principle, free of charge.

 

14. Data security

We take appropriate technical and organisational measures to protect your data, including:

  • Antivirus software.
  • Firewall.
  • Password protection for computers, servers and software.
  • Password protection for email accounts.
  • Password management using specialised software with a two-factor authentication system.

 

Data is entered manually into the PEEMPIP Registry or into secure folders on Google Drive, with access restricted to authorised members of the Board and working groups.

15. Cookies

The website may use cookies for its operation and, subject to your consent, for statistical or analytical purposes. Detailed information is provided in the [Cookies Policy], where a separate document exists. If non-essential cookies or analytics tools are not used, this section will be updated accordingly.

16. Updates to the policy

This policy may be updated. Each new version is dated and published on the PEEMPIP website. We recommend that you check the text periodically.

17. Contact

For any enquiries regarding your personal data or this policy:

  • Data Protection Officer: Dimitra Sachpatzidou, PEEMPIP Board member.
  • Email: info@peempip.gr

 

Further information on the GDPR:

EUR-Lex: http://eur-lex.europa.eu/legal-content/EN-EL/TXT/?uri=CELEX:32016R0679&from=EN

European Commission: https://ec.europa.eu/info/law/law-topic/data-protection/data-protection-eu_en

Data Protection Authority: https://www.dpa.gr

 

Our partnerships
PEEMPIP is a member of FIT/IFT, EULITA, AVTE and SEGE.