Privacy Notice

Last updated: 29 July 2026

Who we are

Eidosyn is an early-stage project based in Greece. The data controller responsible for the processing described in this notice is Paschalis Michalakopoulos. Privacy enquiries may be sent to paschalis@eidosyn.com.

The data we use

For limited business research and business-to-business product validation, we may process a small amount of professional information, including:

We do not intentionally collect sensitive or special-category personal data for this purpose.

Where we obtain the information

We may obtain professional information from publicly available business and professional sources, including company websites, professional networking platforms, public corporate registers, business directories, and other publicly available professional sources.

Why we use the information

We use this information for limited and targeted B2B product validation and research relating to the Eidosyn concept. This may include identifying professionals whose roles are relevant to procurement, supply chain, sourcing or related business functions, contacting them in their professional capacity, presenting an early concept, and obtaining feedback on whether it may address real business needs.

Lawful basis

We rely on our legitimate interests under Article 6(1)(f) GDPR and, where applicable, UK GDPR for relevant and proportionate B2B outreach and product validation.

Our legitimate interest is to evaluate and develop the Eidosyn concept by obtaining feedback from professionals whose roles are directly relevant to the problem being researched.

We have assessed the purpose of the processing, whether limited professional contact information is reasonably necessary, and whether our interests are outweighed by the privacy rights and reasonable expectations of the people contacted.

We limit the impact of this processing by keeping outreach targeted and low-volume, using professional information only, avoiding sensitive information, reviewing contacts individually, providing clear information about who is contacting you, and respecting objections to further contact.

You may request further information about this assessment by contacting us.

Use of AI-assisted tools

We may use AI-assisted tools to help research organisations, organise publicly available professional information, summarise information, or assist with drafting communications.

We do not use AI systems to make solely automated decisions about individuals that produce legal or similarly significant effects. A human reviews and decides before outreach is sent.

Sharing and service providers

We may use third-party service providers for functions such as email, website hosting and record keeping. They may process limited information where necessary to provide those services. We do not sell professional contact information.

International transfers

Some service providers may process information outside the European Economic Area or the United Kingdom. Where applicable, we rely on appropriate safeguards required by data protection law.

How long we keep information

We normally retain outreach records for up to 12 months after the last relevant interaction, unless there is an ongoing business discussion or another legitimate reason to retain them.

If you ask us not to contact you again, we may retain the minimum information necessary in a suppression or do-not-contact record for as long as needed to respect that request.

Your rights

Depending on the circumstances, you may have rights including access to your personal data, correction of inaccurate data, deletion, restriction of processing, objection to processing, and data portability where applicable.

You have the right to object at any time to the use of your personal data for direct marketing. If you object, we will stop using your information for that purpose and may retain only the minimum information necessary to ensure that we do not contact you again.

How to object or opt out

Simply reply to any email from us and tell us that you do not wish to receive further communication, or email paschalis@eidosyn.com.

Complaints

You have the right to lodge a complaint with a competent data protection supervisory authority. As the controller is based in Greece, the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) is the relevant Greek supervisory authority. Where other data protection laws apply, you may also have rights before another competent supervisory authority.

Changes to this notice

We may update this notice if our activities, use of personal data or legal obligations change. The latest version will be available at eidosyn.com/privacy.

Contact

Paschalis Michalakopoulos
paschalis@eidosyn.com