Privacy Notice
Who we are
Eidosyn is an early-stage project based in Greece. The data controller responsible for the processing described in this notice is Paschalis Michalakopoulos. Privacy enquiries may be sent to paschalis@eidosyn.com.
The data we use
For limited business research and business-to-business product validation, we may process a small amount of professional information, including:
- your name;
- your job title or professional role;
- the organisation you work for;
- your business email address;
- publicly available professional information relevant to your role;
- the public source from which the information was obtained; and
- correspondence relating to our communication with you.
We do not intentionally collect sensitive or special-category personal data for this purpose.
Where we obtain the information
We may obtain professional information from publicly available business and professional sources, including company websites, professional networking platforms, public corporate registers, business directories, and other publicly available professional sources.
Why we use the information
We use this information for limited and targeted B2B product validation and research relating to the Eidosyn concept. This may include identifying professionals whose roles are relevant to procurement, supply chain, sourcing or related business functions, contacting them in their professional capacity, presenting an early concept, and obtaining feedback on whether it may address real business needs.
Lawful basis
We rely on our legitimate interests under Article 6(1)(f) GDPR and, where applicable, UK GDPR for relevant and proportionate B2B outreach and product validation.
Our legitimate interest is to evaluate and develop the Eidosyn concept by obtaining feedback from professionals whose roles are directly relevant to the problem being researched.
We have assessed the purpose of the processing, whether limited professional contact information is reasonably necessary, and whether our interests are outweighed by the privacy rights and reasonable expectations of the people contacted.
We limit the impact of this processing by keeping outreach targeted and low-volume, using professional information only, avoiding sensitive information, reviewing contacts individually, providing clear information about who is contacting you, and respecting objections to further contact.
You may request further information about this assessment by contacting us.
Use of AI-assisted tools
We may use AI-assisted tools to help research organisations, organise publicly available professional information, summarise information, or assist with drafting communications.
We do not use AI systems to make solely automated decisions about individuals that produce legal or similarly significant effects. A human reviews and decides before outreach is sent.
Sharing and service providers
We may use third-party service providers for functions such as email, website hosting and record keeping. They may process limited information where necessary to provide those services. We do not sell professional contact information.
International transfers
Some service providers may process information outside the European Economic Area or the United Kingdom. Where applicable, we rely on appropriate safeguards required by data protection law.
How long we keep information
We normally retain outreach records for up to 12 months after the last relevant interaction, unless there is an ongoing business discussion or another legitimate reason to retain them.
If you ask us not to contact you again, we may retain the minimum information necessary in a suppression or do-not-contact record for as long as needed to respect that request.
Your rights
Depending on the circumstances, you may have rights including access to your personal data, correction of inaccurate data, deletion, restriction of processing, objection to processing, and data portability where applicable.
How to object or opt out
Simply reply to any email from us and tell us that you do not wish to receive further communication, or email paschalis@eidosyn.com.
Complaints
You have the right to lodge a complaint with a competent data protection supervisory authority. As the controller is based in Greece, the Hellenic Data Protection Authority (HDPA / ΑΠΔΠΧ) is the relevant Greek supervisory authority. Where other data protection laws apply, you may also have rights before another competent supervisory authority.
Changes to this notice
We may update this notice if our activities, use of personal data or legal obligations change. The latest version will be available at eidosyn.com/privacy.
Contact
Paschalis Michalakopoulos
paschalis@eidosyn.com