Skip to content
ORYNDEX
Start a project

Privacy Policy

Your data, handled with care.

This studio collects as little as the work allows, and only ever with a clear legal basis. Here is the complete picture, in plain language.

This Privacy Policy explains what personal data ORYNDEX processes through this website — when you simply read it, and when you write to us — why we process it, on what legal basis, who else is involved, and the rights you have under the GDPR.

1. In short

The long version follows, and it is the one that counts. This is what it says:

  • We collect what you choose to send us through the contact form, and the technical data any website receives in order to be served at all. There is nothing else — no accounts, no tracking of you between visits unless you have agreed to it.
  • Nothing that measures or advertises to you runs before you agree to it. Decline, and only the strictly necessary processing happens.
  • We do not sell your data, we do not build advertising profiles of you off the back of an inquiry, and there is no newsletter list you are quietly added to.
  • You can ask us at any time what we hold, have it corrected, or have it deleted. One email is enough.

2. Who is responsible for your data

ORYNDEX is the data controller for this website (oryndex.com) under the EU General Data Protection Regulation (GDPR) and Greek data-protection law (Law 4624/2019). ORYNDEX is the trading name of a boutique digital studio operating as a sole proprietorship established in Greece:

  • BusinessΜΙΧΑΗΛ ΔΗΜ. ΜΑΡΚΟΥ — Sole proprietorship (Ατομική Επιχείρηση)
  • VAT numberEL130649964
  • Registered addressZipari, Kos 85300, Greece
  • Emailstudio@oryndex.com

3. Supervisory authority

The competent supervisory authority for this studio is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifissias 1-3, 115 23 Athens, dpa.gr. You may complain to them at any time — but you are welcome to write to us first, and we would rather you did.

Because we are a small studio whose core activity is not large-scale monitoring or the processing of special categories of data, we are not required to appoint a Data Protection Officer under Article 37 GDPR. Privacy questions go to the address above and are answered by a person, not a queue.

4. The data we process

We process different data depending on what you do on the site. Simply reading a page involves the first two categories below and nothing else.

  • Technical & log dataOur hosting and security infrastructure automatically records standard technical data — IP address, browser and device type, referring page, and the pages requested — to serve the site, keep it available and secure, and diagnose faults. This happens for every visitor and cannot be switched off, because without it the site cannot be delivered to you.
  • Your cookie choiceWhen you answer the cookie banner, your answer is stored in your browser's local storage under the key oryndex-consent. It never leaves your device, and it exists so that we can honour your decision on every later visit instead of asking again.
  • Contact form and emailWhen you use the contact form or email us, we receive the name, email address, and message you provide. We generate a case reference (in the form ORX-XXXXXX) so the inquiry can be tracked and answered, and we send that reference back to your address as confirmation, with a copy of what you wrote. That confirmation is a reply to your own action, not marketing: it subscribes you to nothing, and there is nothing to unsubscribe from. You choose what to put in the message; please do not include sensitive personal data you do not want us to hold.
  • Anti-spam and abuse signalsThe contact form is protected against automated abuse. We count submissions per IP address over a short window to rate-limit floods, we record how long the form took to complete, and we operate a hidden field that only automated scripts fill in. Where the bot-protection challenge is enabled, Cloudflare Turnstile additionally processes your IP address, browser signals such as the user-agent, and the site key of this website, in order to decide whether you are a person. These signals are used to block abuse and for nothing else.
  • Measurement and advertising dataWhere — and only where — you consent, measurement and advertising tools record how you interact with the site: pages viewed, approximate location derived from IP, device and browser characteristics, and identifiers stored in cookies. These are itemised in our Cookie Policy.

5. Why we process it, and our legal basis

We process personal data only where a legal basis under Article 6 GDPR applies:

  • Steps prior to a contract — Art. 6(1)(b)Answering an inquiry about a possible engagement, and taking the steps you ask for before any agreement is made. Here the processing is what makes your own request possible at all.
  • Legitimate interests — Art. 6(1)(f)Keeping the site available, fast, and secure; preventing spam and automated abuse of the forms; and replying to messages that are not about a possible engagement. We weigh these interests against your rights each time, and we use the least data that achieves the purpose.
  • Consent — Art. 6(1)(a)Analytics, advertising, and every other non-essential cookie or tag. These run only after you agree through the cookie banner, and you can withdraw that agreement at any time — the Cookie Settings control in the footer reopens the choice, and withdrawal is exactly as easy as giving it.
  • Legal obligation — Art. 6(1)(c)Where we are required to retain certain records, for example for tax or accounting purposes once an engagement begins.

6. Cookies, analytics, and advertising

This site is built to load, subject to your consent, Google Analytics, Google Ads, and the Meta (Facebook) Pixel through Google Tag Manager. These tools set cookies and collect usage and device data, and they may be used to measure traffic, understand how the site performs, and measure or support advertising campaigns.

None of them load, and none of their cookies are set, until you have given consent. We use Google Consent Mode with every consent signal defaulting to denied before the tag manager loads, so the denial is in force from the first moment of the page rather than applied afterwards. Until you agree, only strictly necessary technical processing takes place.

The full list of tools, the cookies they set, how long each lasts, and how to change your choice is in the Cookie Policy.

7. Who receives your data

We do not sell or rent personal data, and we do not share it with anyone for their own marketing. We use a small number of service providers that process data on our behalf under a data processing agreement, and only as far as running the site and answering you requires:

  • Vercel — hosting and deliveryServes this website and its content delivery network, and keeps the technical and security logs described above.
  • Supabase — inquiry recordsThe database where contact inquiries and their case references are stored, so that a message cannot be lost and can be traced from first contact to answer.
  • Resend — email deliveryDelivers the message you send through the contact form to the studio inbox, with your email address set as the reply address so we can answer you, and delivers the confirmation back to you.
  • Google — measurement, with consent onlyWhere you have consented to analytics or advertising cookies, Google provides Tag Manager, Analytics, and Ads. Decline, and no request is made to Google from this site at all.
  • Cloudflare — bot protectionWhere the Turnstile challenge is enabled, Cloudflare assesses the signals described in section 3 to distinguish people from automated scripts. Cloudflare acts as our processor for this and, by its own account, cannot identify individuals from those signals.
  • Meta — advertising, with consent onlyWhere you have consented to advertising cookies, the Meta Pixel measures campaign performance and supports audience building on Meta platforms.

8. International transfers

Several of the providers above are established in the United States or process data there. Where personal data leaves the European Economic Area, we rely on an appropriate safeguard under Chapter V GDPR — certification under the EU–U.S. Data Privacy Framework where the provider holds it, or the European Commission's Standard Contractual Clauses, supported by the provider's own technical and organisational measures.

The purpose of those safeguards is that your data keeps a level of protection essentially equivalent to the one it has in the EEA. You may ask us which mechanism applies to a particular provider, and we will tell you.

9. How long we keep it

We keep personal data only as long as the purpose it was collected for requires:

  • Inquiries and their case referencesFor as long as it takes to handle your request, and for a reasonable period afterwards in case the conversation resumes — then deleted or anonymised. If an engagement follows, the record is kept for the life of the engagement and for the statutory retention period that applies to it.
  • Technical and security logsA short period only — long enough to investigate a fault or an attack, not longer.
  • Rate-limit countersHeld in memory for a ten-minute window and then discarded. They are never written to a database.
  • Your cookie choiceStays in your browser until you clear your browser storage or change the choice. Clearing it simply means you are asked again.
  • Analytics and advertising dataRetained according to the settings and defaults of each tool, as set out in the Cookie Policy — and never longer than the consent that permits it.

10. How we protect it

The site is served over HTTPS throughout. Credentials for the email and database services are held as server-side secrets and are never exposed to your browser. Access to inquiries is limited to the people who need it to do the work, and the contact form is protected by the layered anti-abuse measures described in section 4.

No system is perfect, and we will not claim otherwise. If a breach ever occurs that is likely to result in a risk to your rights and freedoms, we will notify the supervisory authority and, where the GDPR requires it, you.

11. What we do not do

It is worth being explicit about the absences, because they are choices:

  • There is no newsletter and no mailing list. Sending an inquiry does not subscribe you to anything.
  • There are no accounts, no logins, and no user profiles on this site.
  • The Notes section carries no comment system, no tracking pixels of its own, and no third-party embeds. Reading an article is the same, technically, as reading any other page here.
  • We do not use your inquiry to build advertising audiences, and we do not upload contact details to any advertising platform.
  • We do not use your personal data to train artificial-intelligence models, and we do not pass it to anyone else for that purpose.

12. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you, and receive a copy (Art. 15).
  • Have inaccurate data corrected and incomplete data completed (Art. 16).
  • Have your data erased where the law allows — the right to be forgotten (Art. 17).
  • Restrict our processing while a question about it is resolved (Art. 18).
  • Object to processing based on our legitimate interests, including any profiling (Art. 21).
  • Receive the data you gave us in a portable, machine-readable format (Art. 20).
  • Withdraw consent at any time, without affecting the lawfulness of processing already carried out (Art. 7(3)).
  • Lodge a complaint with your local data protection supervisory authority, wherever you live or work in the EEA (Art. 77).

13. Managing your consent

Use the Cookie Settings control in the footer of any page to reopen the cookie choice and change or withdraw it. It appears whenever any non-essential tool is configured for this site — if it is not there, none is running and there is nothing to withdraw. Withdrawing consent stops the relevant tools from loading on future visits; it cannot undo processing that already lawfully took place while consent was in force.

You can also delete cookies and block them in your browser at any time, independently of anything we do.

14. Automated decisions and children

We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects on you. The bot-protection challenge decides only whether a form submission looks automated; it has no bearing on you as a person, and a human being reads every message that reaches us.

This site is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has sent us personal data, write to us and we will delete it.

15. Changes to this policy

If this policy changes, the date at the foot of this page changes with it, and material changes will be made clear here before they take effect. We will not weaken the protections described above without saying so plainly.

16. Contact

To exercise any right, or for any privacy question at all, write to studio@oryndex.com. We answer within the timeframes the GDPR requires — normally one month, and sooner where we can.

Last updatedAugust 2026