Privacy Policy
Last updated: 25 June 2026
Introduction
Infimum (“Infimum”, “we”, “us” or “our”) is a software and AI consultancy that designs and builds large-scale data management systems for the public sector, municipalities, air transportation and education. This Privacy Policy explains how we collect, use, disclose and safeguard personal data when you visit our website, contact us, or otherwise engage with our services, and describes the rights available to you under applicable data protection law, including the EU and UK General Data Protection Regulation (GDPR).
For the purposes of the GDPR, Infimum acts as the data controller in respect of the personal data described in this policy. Where we process personal data on behalf of our clients in the course of delivering services, we act as a data processor and such processing is governed by the relevant client agreement and data processing terms.
Information we collect
We collect personal data in a limited number of ways, principally where you choose to share it with us and automatically as you interact with our website.
Information you provide to us. When you complete a contact form, request information, or correspond with us by email, we may collect your name, business email address, organisation, job title, and the content of your message. As we provide services to business and government clients, the information you share is typically professional or organisational in nature.
Information collected automatically. When you visit our website, our servers and infrastructure providers may automatically record certain information, such as:
- your IP address and approximate location derived from it;
- browser type and version, device and operating system information;
- pages visited, referring URLs, and the date, time and duration of your visit;
- diagnostic and log data used to operate and secure the website.
Cookies and similar technologies. We may use cookies and similar technologies to operate the website, to remember your preferences and, where you have consented, to understand how the website is used. See the section on Cookies and analytics below.
How we use information
We use the personal data we collect for the following purposes:
- to respond to your enquiries and provide the information or services you request;
- to establish, manage and perform client engagements and contracts;
- to operate, maintain, secure and improve our website and services;
- to communicate with you about our work where you have asked us to or where we have a legitimate interest in doing so;
- to comply with our legal and regulatory obligations and to protect our legal rights.
Legal bases for processing
Where the GDPR applies, we rely on one or more of the following legal bases to process your personal data:
- Consent — where you have given clear consent for a specific purpose, such as the use of non-essential cookies or analytics.
- Contract — where processing is necessary to enter into or perform a contract with you or your organisation.
- Legitimate interests — where processing is necessary for our legitimate interests, such as responding to enquiries, securing our website, and developing our business, provided these interests are not overridden by your rights.
- Legal obligation — where processing is necessary to comply with a legal or regulatory obligation to which we are subject.
Cookies and analytics
We use a small number of cookies and similar technologies. Strictly necessary cookies are required for the website to function and do not require your consent. Where we use analytics or other non-essential technologies to understand and improve how our website is used, we do so only with your consent, which you may withdraw at any time. You can also control cookies through your browser settings, although disabling certain cookies may affect the functionality of the website.
Data sharing and sub-processors
We do not sell your personal data. We may share personal data with trusted third parties who process it on our behalf and under our instructions, including:
- hosting, infrastructure and cloud service providers;
- analytics, email and communications providers;
- professional advisers, such as legal, accounting and audit firms.
We engage sub-processors under written agreements that require them to protect personal data and to process it only as instructed. We may also disclose personal data where required to do so by law, regulation or legal process, or to protect the rights, property or safety of Infimum, our clients or others.
International transfers
Your personal data may be processed in, or transferred to, countries outside your own, including countries that may not provide the same level of data protection as your jurisdiction. Where we transfer personal data internationally, we put in place appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or equivalent mechanisms, to ensure your personal data remains protected in accordance with applicable law.
Data retention
We retain personal data only for as long as is necessary for the purposes for which it was collected, including to satisfy any legal, accounting, contractual or reporting requirements. When personal data is no longer required, we will delete or anonymise it securely. The retention period applied depends on the nature of the data and the purpose of processing.
Your rights
Subject to applicable law, you have the following rights in respect of your personal data:
- the right of access to the personal data we hold about you;
- the right to rectification of inaccurate or incomplete data;
- the right to erasure of your personal data in certain circumstances;
- the right to data portability, where applicable;
- the right to restrict or object to certain processing;
- the right to withdraw consent at any time, where processing is based on consent;
- the right to lodge a complaint with a supervisory authority in your country of residence, place of work or where an alleged infringement occurred.
To exercise any of these rights, please contact us using the details below. We will respond in accordance with applicable law.
Security
We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction. These measures include access controls, encryption in transit, network security and ongoing monitoring. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children’s privacy
Our website and services are directed at businesses and public sector organisations and are not intended for children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so that we can take appropriate action.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. When we do, we will revise the “Last updated” date at the top of this page. We encourage you to review this policy periodically.
Contact
If you have any questions about this Privacy Policy or how we handle your personal data, or if you wish to exercise your rights, please contact our privacy team at privacy@infimum.gr. You can also reach us through our contact page.
This document is a general template provided for informational purposes only and does not constitute legal advice. It should be reviewed and adapted by qualified legal counsel to reflect your specific circumstances and applicable law before being relied upon in production.