top of page

Privacy Policy

1.Introduction – Information about the Data Controller

This policy concerns the collection of personal data through the website, the internet in general, and by telephone.

Through this policy we wish to explain to you, as simply and clearly as possible:

  • What data we process about you

  • For what purposes and on what legal basis we process it

  • How long we retain it

  • Who the recipients of your data are, and

  • What your rights are regarding your data and how you can exercise them.

Through our website, telephone communications, and social media, we collect certain information that may lead to your direct or indirect identification. Under European and national law, some of this information constitutes personal data (e.g. full name, postal address, contact telephone number, email address, etc.) and can determine your identity (hereinafter "Personal Data" or "Data").

As users of our services and visitors to our website, you are referred to as "data subjects," while we are the "data controllers" of your personal data.

"Processing of Personal Data" means any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, and destruction.

The Data Controller of your personal data is the Private Legal Entity "ER.E.N.ZO." (ERENZO), based in Athens, 16 Thiseos Street, P.C. 10562, telephone: 2103008133, Email: contact@grufon.org.

For any clarification or additional information regarding this personal data protection policy, as well as to exercise your rights and requests arising from European and national law, you may contact the Data Protection Officer of ER.E.N.ZO. at the email address contact@grufon.org or at the postal address 16 Thiseos Street, Athens 105 62.

2.Basic principles for processing your data

We process your data lawfully and transparently, in accordance with European law (General Data Protection Regulation 679/2016 EU) and national law. We collect and process your data only for explicit, legitimate, and specified purposes, and only to the extent necessary for the purposes for which we process it.

We retain the data for as long as necessary, in accordance with the law, the contract, the purposes, and the policy of ER.E.N.ZO., and we take care to keep it as accurate as possible.

We make every possible effort to ensure that your data is safe and protected from unlawful processing, from accidental or malicious loss and destruction, and from unauthorised access. We have implemented a comprehensive information security programme and apply security controls based on the sensitivity of the information and the level of risk of our activity, taking into account the best practices of modern technology and the cost of their implementation. We have adopted appropriate internal security policies and procedures, policies, and technologies that ensure data security, and we have also trained our officers and staff to observe the rules of data confidentiality and privacy. Our staff and our third-party partners have committed in writing to maintaining the confidentiality and privacy of the data to which they have access.

The website www.grufon.org uses the SSL (Secure Sockets Layer) protocol, which employs methods of encrypting the data exchanged between two devices (most commonly computers), establishing a secure connection between them over the internet, resulting in the protection of your personal data as well as other sensitive data (e.g. instructions or research of the data controller). You can recognise that you are on a protected connection by seeing the characters https:// and the padlock symbol displayed in the address bar of your browser.

3.Purpose and legal basis for processing your data

As a rule, ER.E.N.ZO. collects and processes your data only when you provide it directly and voluntarily, either through the website or by telephone (e.g. by filling in a registration form on our website).

However, this rule cannot apply absolutely in two cases within the operation of the Website: (i) certain data that is collected automatically during your visit to our website, and (ii) data collected with the help of cookies and similar technologies.

3.1. Automatic collection of data when you visit the website

When you visit our website, our server collects the so-called server log files, specifically:

  • Date and time at the moment of entry to the website.

  • The volume of data sent, in bytes.

  • The browser and operating system you used when entering the website.

  • Your IP (Internet Protocol) address at the time of entry to the website. The IP address constitutes personal data, together with the date and time of your visit, although we cannot identify you on our own by means of this element alone. The reason (legal basis and purpose) for which we collect your IP address and retain it in special files (log files) is, on the one hand, our legitimate interest in processing this data in order to ensure the security of networks, information, and services against accidental events or unlawful or malicious actions that endanger the availability, authenticity, integrity, and confidentiality of stored or transmitted data (e.g. detection of "denial of service" attacks), and, on the other hand, the legal obligation to provide as secure an environment as possible for the processing of your personal data (Article 6(1)(f) and (c) GDPR).

This data will not be transferred or used in any other way. However, we reserve the right to examine the server log files if specific indications of unlawful use are found.

Like most websites, we also use cookies and similar technologies during your access to and navigation of the Website.

We use these technologies to make your navigation comfortable and effective, to give you access to a range of functions, such as sharing our pages on social media, as well as to provide us with certain information regarding your browsing, and also to display advertisements relevant to your interests and searches.

Cookies are small text files stored on the hard drive of the computer or other electronic device through which the user accesses the website. Cookies are unique to each web browser (e.g. Google Chrome, Mozilla Firefox, Internet Explorer, Opera, etc.) and contain anonymised information relating to the websites you visit and the devices you use.

Non-essential cookies are installed only after your explicit consent through the relevant banner, which you can withdraw at any time.

3.2. Registration and profile completion forms

If you choose to register or contact us through the special form available on our website, we collect the personal data that you provide to us, e.g. by filling in the contact form. This data includes full name, telephone, email address, and any other information you may provide during our communication, including images or videos. This data is stored and used exclusively to respond to your request or for contact and technical management by us.

The legal basis for processing this personal data is your consent, under Article 6(1)(a) GDPR. The data you provide will be deleted when you request it, provided that no legal claims for the storage of this data exist. In addition, and only with your optional consent, which constitutes the legal basis for processing under Article 6(1)(a) GDPR, we may process the email you provide so that you receive informational and promotional material from ER.E.N.ZO. At any time and in any subsequent communication, you may withdraw your relevant consent.

3.3. Contacting us through a special form, email, or telephone

In the context of our communication (e.g. through the contact form or email), we collect the personal data that you enter in the specific form and any other information you may provide during our communication, including images or videos. This data is stored and used exclusively to respond to your request or for contact and technical management by us.

The legal basis for processing this personal data is your consent so that we may respond to your request, which is founded on Article 6(1)(a) of the General Data Protection Regulation (GDPR). Your data will be deleted after the final processing of our communication. This will occur when it can be inferred from the circumstances that the communication has been completed, provided that no legal claims for the storage of this data exist.

3.4. Processing of data upon submission of an Application through our websites or in writing

With your consent, we process the ordinary and any special personal data you provide when completing the Application Form, specifically your first and last name, contact details, preferences, and other personal data. We process this data in order to manage your application, and the legal basis for the processing is your consent (Article 6(1)(a)).

Finally, and only with your optional consent, which constitutes the legal basis for the processing in accordance with Article 6(1)(a) GDPR, we may process your personal data (full name, contact details) for future communication with you.

Your data may in any case be processed, even without your consent, for reasons of compliance with laws, regulations, and EU law (Article 6(1)(c) GDPR).

The data is stored for as long as necessary to achieve the purposes for which it was collected. In any case, the criterion used to determine this period is based on compliance with the time limits set by law and by contract, as well as on the principles of data minimisation, storage limitation, and the rational management of records.

3.4a. Submission of Sighting Reports (UAP)

Through the special report forms on our platform, you may submit observations of flying objects or phenomena (UAP). In this context, we may collect the data that you voluntarily provide to us, such as full name, contact details, the location and time of the observation, a description of the incident, and any photographic or audiovisual material you attach.

We process this data exclusively for the research and documentation purposes of the Association, namely the recording, evaluation, study, and archiving of reports. The legal basis for the processing is your consent (Article 6(1)(a) GDPR) and, with regard to the maintenance of the research archive, our legitimate interest (Article 6(1)(f) GDPR).

Publication of reports: Your report is published publicly with the details you have provided only after your explicit and specific consent for that purpose. If you do not provide such consent, the report is either anonymised (the details leading to your identification are removed) before any display or statistical use, or kept strictly internal for the Association's research purposes, without publication. You may withdraw your consent to publication at any time, without affecting the lawfulness of the processing already carried out.

3.5. Electronic Donations

ER.E.N.ZO. offers the possibility of making electronic donations through the Viva.com payment service.

When making a donation, the following personal data may be collected and processed:

  • Full name

  • Email address

  • Donation amount

  • Date and time of the transaction

  • Transaction identifier (Order Code or Transaction ID)

  • Payment status

This data is used exclusively for:

  • completing and recording the donation,

  • communicating with the donor when required,

  • complying with applicable accounting, tax, and other legal obligations.

The processing of payment details is carried out exclusively through Viva.com. ER.E.N.ZO. does not collect, process, or store any credit or debit card details.

The legal basis for the processing is the execution of the donation at the donor's request, compliance with the legal obligations of ER.E.N.ZO., and, where required, its legitimate interest in the proper management of donations. The data is retained only for as long as required by applicable law.

3.5a. Purchase of Event Tickets

For the sale of tickets to our events, we cooperate with the ticket issuing and sales platform more.com, operated by the company "MORE.GR ELECTRONIC SERVICES SINGLE-MEMBER S.A." (registered office: Amarousiou–Chalandriou 18-20, Marousi 15125, VAT No. 998988329). When purchasing a ticket, data such as full name, email address, transaction details (order identifier, date/time, payment status), and the information required to validate the ticket (voucher) upon entry to the event may be collected and processed.

The purchase and payment are carried out exclusively within the environment of more.com, which acts as an independent Data Controller for the data it collects through its platform, in accordance with its own Privacy Policy (www.more.com/gr-el/security-and-data-protection-policy). The Association does not collect, process, or store any credit or debit card details. As the organiser, the Association receives from more.com the necessary information to manage participation and entry to the event.

The legal basis for the processing is the performance of the ticket purchase contract at your request (Article 6(1)(b) GDPR), compliance with our legal accounting and tax obligations (Article 6(1)(c) GDPR), and, where required, our legitimate interest in the proper organisation of the event. The data is retained for as long as required by applicable law. To exercise your rights regarding the data held by more.com, you may contact the company's Data Protection Officer at dpo@more.com.

3.5b. Photography and Video Recording at Events

During the events we organise, photography and/or video recording may take place for the purpose of documenting, showcasing, and promoting the Association's activities (e.g. posting on the website and social media). Attendees may appear in this material.

The legal basis for the processing is the Association's legitimate interest in showcasing its activities (Article 6(1)(f) GDPR), taking into account that these are general-nature shots taken in the public context of an event. If you do not wish to be depicted, you may inform us before or during the event, and you may also request afterwards the removal or obscuring of your image from published material by contacting us at the details in paragraph (1). In cases of targeted images of an individual (e.g. an interview or portrait), the processing is based on your explicit consent (Article 6(1)(a) GDPR).

3.6. Traffic statistics and obligations towards OSDEL

For the operation of the GRUFON research platform, we use a web analytics service (e.g. Google Analytics). This data is aggregated and is not used to identify you. Under the licensing agreement with the Collective Management Organisation for Literary Works (OSDEL), the ERENZO Association is obliged to disclose to OSDEL a list of the reproduced works and statistical data on views per post, as well as to provide, upon request and up to twice per year, limited-duration access to the analytics service for verification purposes. This data concerns view counts and not the personal data of identifiable users. Legal basis: our legitimate interest and the fulfilment of a contractual obligation (Article 6(1)(f) and (b) GDPR).

3.7. Who has access to your data – Transfers

Your Data is accessible to the staff of ER.E.N.ZO. who are authorised to respond to your requests, as well as to staff dealing with administrative and accounting matters, IT, and internal audits, and to any other authorised person who must process your data in the context of their work duties. In addition, for the operation of our website, the management of our Pages, and the processing of your requests, we cooperate with third-party service providers—legal or natural persons, professionals, independent consultants—who provide us with commercial, professional, or technical services for the purposes mentioned above and to support ER.E.N.ZO., in whole or in part, in providing the services you request. Where applicable, these natural/legal persons will act as joint Data Controllers, Data Processors, or persons authorised to process personal data, for the same purposes mentioned above, with the same safeguards and in accordance with applicable law.

For the completion of electronic donations, we cooperate with the payment service provider Viva.com. Payments are made exclusively through the secure environment of Viva.com, and ER.E.N.ZO. neither acquires nor stores any credit or debit card details.

For the sale of event tickets, we cooperate with the more.com platform (MORE.GR ELECTRONIC SERVICES SINGLE-MEMBER S.A.), as set out in §3.5a. Payments are made exclusively through the secure environment of more.com, and ER.E.N.ZO. neither acquires nor stores any credit or debit card details.

Before the third party receives the Personal Data, we: (1) complete the legal privacy review to assess the privacy practices and risks associated with these third parties; (2) obtain contractual guarantees from these third parties that they will process Personal Data in accordance with the instructions of ER.E.N.ZO., and in accordance with this Policy and existing Legislation; that they will promptly notify ER.E.N.ZO. of any Privacy Incident, including any inability to comply with the standards set out in this Policy and existing legislation, or any Security Incident; that they will cooperate in the timely remediation of any documented Incident; that they will assist us in responding to the individual rights of the data subjects as defined below; and that they will allow ER.E.N.ZO. to audit and monitor their practices during processing with regard to compliance with these requirements.

In some cases, data may be transferred for purposes permitted by law and/or on the basis of legitimate interest (administrative and accounting needs, legal claims, business development, etc.). Finally, data may be further transferred to institutions, authorities, and public bodies for lawful purposes.

With the exception of the above, the Data will not be disclosed to third parties, whether natural or legal persons, and will not be disseminated.

ER.E.N.ZO. does not transfer Personal Data outside the European Union; should it need to do so (e.g. for the use of Cloud services), this will be done under the terms and safeguards provided for by Articles 44 et seq. GDPR, such as, for example, by obtaining your consent, applying standard contractual clauses approved by the European Commission, or operating in countries considered safe by the European Commission.

3.7.1. Data of minors

When we need to process the data of minors, the processing takes place only with the written and explicitly expressed consent of the persons who have parental responsibility for the minor. In any case, we make reasonable efforts to verify that consent is given or approved by the person who actually holds parental responsibility for the child, namely through identity verification and any other available means.

3.7.2. Your Rights

You may contact the Data Protection Officer of ER.E.N.ZO. at the email address, postal address, and telephone numbers shown in paragraph (1) of this document at any time, in order to exercise your rights under Articles 15–22 GDPR, namely the rights of access, rectification, erasure (where permitted), restriction of processing, notification, portability, as well as the right to withdraw consent in accordance with Article 7(3) and to lodge a complaint with a supervisory authority in accordance with Article 77 GDPR.

For example, you may obtain an updated list of the persons who have access to your data, receive confirmation as to whether or not personal data relating to you exists, check its content, origin, accuracy, retention period, and location (including in relation to any third country), request a copy, request its rectification and, in the cases provided for by law, request the restriction of its processing or its erasure. You may also object to direct communication activities (sending of the newsletter) by ER.E.N.ZO. Likewise, you may at any time raise observations regarding specific uses of your data that are considered erroneous or unjustified, or lodge complaints with the Hellenic Data Protection Authority, 1-3 Kifisias Avenue, P.C. 115 23, Athens, telephone centre: +30-210 6475600, or at the electronic address http://www.dpa.gr/

You may withdraw your consent at any time, without, however, affecting the lawfulness of the processing carried out before the withdrawal of consent. We reserve, however, the right to further processing if we can demonstrate compelling legitimate grounds requiring protection that override your interests, fundamental rights, and freedoms, or if the processing serves the establishment or defence of legal claims.

3.7.3. Changes to this privacy policy

This Personal Data Protection Policy may be amended whenever ER.E.N.ZO. deems it necessary. Any forthcoming significant change to our policy will be posted on our website www.grufon.org before the changes take effect. Finally, you may request, by post or telephone, that we send you a copy of this document.

Cookie Policy

What Are Cookies?

To ensure that our website functions properly, we may occasionally place a small piece of data known as a “cookie” on your computer or mobile device. A cookie is a text file that is stored by a web server on a computer or mobile device. The contents of a cookie can only be retrieved or read by the server that created it. The text in a cookie often consists of identifiers, site names, and certain numbers and characters. Cookies are unique to the browser or mobile application you use and allow websites to store information such as your preferences.

What categories of cookies are used on www.grufon.org?

Our website uses the following categories of cookies to ensure its smooth and secure operation, as well as to improve your browsing experience:

1. Strictly Necessary Cookies

These cookies are essential for the proper functioning of the website and cannot be disabled in our systems. They are usually set in response to actions you take, such as filling in forms, setting your privacy preferences, or logging in. You can set your browser to block or alert you about these cookies, but some parts of the site may not work properly as a result.

2. Performance and Analytics Cookies

These cookies allow us to collect information about how visitors use our website for example, which pages are visited most often, or whether users encounter errors. The information collected is aggregated and anonymous. These cookies help us understand how our website is used and improve its performance and content.

Aggregate usage statistics relating to the research platform may be shared with OSDEL in accordance with Section 3.6 of the Licence Agreement.

3. Functionality Cookies

These cookies enable the website to remember your preferences (such as language settings or region) and provide enhanced, more personalized features. The information collected by these cookies may be anonymized and does not track your browsing activity on other websites.

4. Third-Party Cookies

In some cases, we may use cookies from trusted third parties, such as analytics or social media service providers, to better understand the effectiveness of our content and communication. These third parties may collect and process data in accordance with their own privacy policies, over which we have no control.

Enabling cookies is not strictly necessary for the operation of this website however, it will enhance your browsing experience. You may delete or block access to these cookies, but if you do so, certain features of the website may not function properly.

The Data Controller responsible for the processing of cookies is E.R.E.N.ZO.

The information related to cookies is not used to personally identify you, and we maintain full control over the data. Cookies are not used for any purposes other than those described in this document.

You can manage and/or delete cookies as you wish. You can delete all cookies that are already stored on your computer, and you can also set most browsers to prevent cookies from being installed. However, if you do so, you may have to manually adjust certain preferences each time you visit the site.

bottom of page