Privacy Policy

Last updated: 25 June 2026

Introduction

Infimum (“Infimum”, “we”, “us” or “our”) is a software and AI consultancy that designs and builds large-scale data management systems for the public sector, municipalities, air transportation and education. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit our website, contact us, or otherwise engage with our services, and describes the rights available to you under applicable data protection law, including the EU and UK General Data Protection Regulation (GDPR).

For the purposes of the GDPR, Infimum acts as the data controller in respect of the personal data described in this policy. Where we process personal data on behalf of our clients in the course of delivering services, we act as a data processor and such processing is governed by the relevant client agreement and data processing terms.

Information we collect

We collect personal data in a limited number of ways, principally where you choose to share it with us and automatically as you interact with our website.

Information you provide to us. When you complete a contact form, request information, or correspond with us by email, we may collect your name, business email address, organisation, job title, and the content of your message. As we provide services to business and government clients, the information you share is typically professional or organisational in nature.

Information collected automatically. When you visit our website, our servers and infrastructure providers may automatically record certain information, such as:

Cookies and similar technologies. We may use cookies and similar technologies to operate the website, to remember your preferences and, where you have consented, to understand how the website is used. See the section on Cookies and analytics below.

How we use information

We use the personal data we collect for the following purposes:

Legal bases for processing

Where the GDPR applies, we rely on one or more of the following legal bases to process your personal data:

Cookies and analytics

We use a small number of cookies and similar technologies. Strictly necessary cookies are required for the website to function and do not require your consent. Where we use analytics or other non-essential technologies to understand and improve how our website is used, we do so only with your consent, which you may withdraw at any time. You can also control cookies through your browser settings, although disabling certain cookies may affect the functionality of the website.

Data sharing and sub-processors

We do not sell your personal data. We may share personal data with trusted third parties who process it on our behalf and under our instructions, including:

We engage sub-processors under written agreements that require them to protect personal data and to process it only as instructed. We may also disclose personal data where required to do so by law, regulation or legal process, or to protect the rights, property or safety of Infimum, our clients or others.

International transfers

Your personal data may be processed in, or transferred to, countries outside your own, including countries that may not provide the same level of data protection as your jurisdiction. Where we transfer personal data internationally, we put in place appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms, to ensure your personal data remains protected in accordance with applicable law.

Data retention

We retain personal data only for as long as is necessary for the purposes for which it was collected, including to satisfy any legal, accounting, contractual or reporting requirements. When personal data is no longer required, we will delete or anonymise it securely. The retention period applied depends on the nature of the data and the purpose of processing.

Your rights

Subject to applicable law, you have the following rights in respect of your personal data:

To exercise any of these rights, please contact us using the details below. We will respond in accordance with applicable law.

Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction. These measures include access controls, encryption in transit, network security and ongoing monitoring. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Children’s privacy

Our website and services are directed at businesses and public sector organisations and are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.

Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically.

Contact

If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise your rights, please contact our privacy team at privacy@infimum.gr. You can also reach us through our contact page.

This document is a general template provided for informational purposes only and does not constitute legal advice. It should be reviewed and adapted by qualified legal counsel to reflect your specific circumstances and applicable law before being relied upon in production.