Data protection

Privacy & GDPR

What we collect, why, how long we keep it, and how to make us stop.

Who is responsible

The controller is PROIGMENES YPIRESIES DIKTYOSIS O.E. (brand: Polymathia), VAT EL801476978, AR.GEMI 157642159000, Kanellou Styl. 1, 82132 Chios, Greece.

For any question about this policy or your data, write to info@polymathia.eu. We have not appointed a Data Protection Officer; we are not required to.

What we collect

When you use the contact form. Your name, email address, organisation, country, role, and anything you choose to write in the message - including an Erasmus+ project number and participant numbers if you give them.

When you take part in a course. Your name, contact details, sending organisation, the course and dates, your attendance record, and your travel details if you give them to us. Where you tell us about dietary requirements or accessibility needs, that is special-category data under Article 9 and we process it only with your explicit consent, only to make the mobility work safely, and we delete it shortly after the course ends.

When you visit the site. Our web server keeps standard access logs - IP address, page requested, timestamp, browser identification - for security and troubleshooting.

Analytics: none. This website runs no analytics, no tracking pixels and no advertising technology. We do not profile visitors and we do not build audiences.

Cookies. This site sets one cookie, a session cookie used by the site software to keep a page request coherent. It is set when you load a page, it expires after 30 minutes, and it is marked Secure, HttpOnly and SameSite=Lax. It carries no identifier we can trace back to you. There are no advertising cookies and no cross-site tracking cookies.

Fonts and other resources are served from our own server. No part of this website loads content from a third-party domain, so visiting it does not disclose your IP address to anyone but us and our hosting provider.

Legal bases

Purpose Legal basis (GDPR Art. 6)
Answering your enquiry Legitimate interest - you contacted us
Organising and delivering a course you booked Performance of a contract
Issuing certificates and keeping them verifiable Legitimate interest, and the expectations of the Erasmus+ programme
Keeping invoices and accounting records Legal obligation under Greek tax law
Security logs Legitimate interest in keeping the service available
Dietary and accessibility needs Explicit consent, Art. 9(2)(a)
Course calendar mailing list Consent

Who else sees your data

Our hosting and email provider. The website, the mailbox and the database run on shared hosting provided by StableServer, on servers in Frankfurt, Germany, acting as a processor under an Article 28 contract.

Your sending organisation, and where a grant requires it, the relevant National Agency - for the attendance and completion evidence the grant depends on.

No one else. We do not sell your data, we do not share it with advertisers, and we do not use it for advertising.

No transfers outside the EEA. All processing takes place within the European Economic Area.

How long we keep it

Data Retention
Unsuccessful enquiries 24 months from last contact - roughly two Erasmus+ application cycles
Course participant records and attendance 5 years after the mobility. Programme rules allow the grant to be checked for up to five years after final payment, and your school may need our attendance evidence to answer that check
Certificate registry (name, course, dates, certificate number) 10 years, so that certificates stay verifiable for as long as a teacher may need to cite one
Travel details 30 days after the course ends
Dietary and accessibility needs 30 days after the course ends, then deleted automatically
Invoices and accounting records As Greek tax law requires - at least five years from the end of the financial year, longer where the law extends the period
Server logs 6 months
Course calendar mailing list Until you unsubscribe

Your rights

You have the right to access your data, to correct it, to have it deleted, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting processing already carried out.

Write to info@polymathia.eu; we answer within one month.

If you believe we have handled your data unlawfully, you can complain to the Hellenic Data Protection Authority, dpa.gr, or to the supervisory authority in your own country.

Security

Access to participant data is limited to the people who need it to run the course. The site is served over HTTPS. Documents and certificates are stored outside the public web directory. We keep backups, and we test that they restore.

If a breach occurs that is likely to put your rights at risk, we notify the supervisory authority within 72 hours and inform you where the law requires it.

Changes

If this policy changes we will publish the new version here with an updated date.

Last updated: 30 July 2026.

Planning a mobility?

Tell us your dates, group size and priorities. You get a proposal, a draft programme and the documents your application needs.

Start the conversation