Skip to content

Privacy notice

Last updated: 23 September 2026
Draft for legal review

This Privacy Notice explains how Lambda Twelve PC / Lambda Twelve IKE (Lambda Twelve, we, us) processes personal data when you visit our website, contact us, create or use an account, order services, receive support or otherwise deal with us.

1. Controller

Lambda Twelve PC
Efploias 11, 18537 Piraeus, Attiki, Greece
GEMI: 145563001000
VAT: EL800949070
Privacy contact: legal@lambda-twelve.com

Lambda Twelve is the controller for the processing described in this Notice unless we expressly state otherwise.

When we host or operate systems containing personal data solely on a customer's instructions, the customer will normally be the controller and Lambda Twelve will act as processor. That processing is governed by the customer's agreement and an applicable Data Processing Agreement, not solely by this Notice.

2. Personal data we collect

Depending on how you interact with us, we may process:

  • Identity and contact data: name, organisation, role, postal address, email address and telephone number.
  • Account data: account identifiers, authentication/security records, account status and preferences.
  • Commercial and billing data: ordered services, quotations, contracts, invoices, VAT information, billing history and payment status.
  • Payment-related data: transaction identifiers, payment status and limited payment metadata received from Stripe. Card/payment credentials entered into Stripe-hosted or Stripe-provided payment interfaces are processed by Stripe according to its role and terms.
  • Support and communications data: enquiries, support tickets, email correspondence, diagnostic information and records needed to resolve a request.
  • Technical and security data: IP address, request and server logs, timestamps, user agent/device information, authentication events, security events and information reasonably required to prevent abuse and protect systems.
  • Website analytics data: limited usage information collected through our cookieless Umami analytics deployment, configured without analytics cookies.
  • Customer-content data: where a service requires us to process data stored or transmitted by a customer. Our legal role for such data depends on the service and circumstances and is commonly that of processor acting on the customer's instructions.

We do not intentionally require special-category personal data for ordinary website, account or billing functions. Customers should not send such data to general contact channels unless necessary and appropriate.

3. Why we process personal data and legal bases

We process personal data for the following purposes:

Contract and pre-contract steps

To answer service requests, prepare quotations, create and administer accounts, accept and fulfil Orders, provision services, provide support, bill customers, process cancellation and otherwise perform our contract. The legal basis is performance of a contract or steps requested before entering into a contract.

Legal obligations

To meet accounting, tax, regulatory, lawful-request and other obligations imposed by law. The legal basis is compliance with a legal obligation.

Security, service operation and abuse prevention

To secure accounts and infrastructure, investigate faults, prevent fraud and abuse, maintain service integrity, enforce our terms and defend legal claims. The legal basis is our legitimate interests in operating and protecting our business and services, balanced against the rights and interests of affected individuals, and where applicable compliance with legal obligations.

Communications and relationship management

To respond to enquiries and communicate about existing services. Depending on context, the legal basis is contract/pre-contract steps or legitimate interests.

Website analytics

To understand aggregate website use and improve the site using a cookieless Umami deployment. We configure analytics to minimise personal-data collection. The legal basis relied upon for any personal data involved is legitimate interests in understanding and improving our website, subject to applicable ePrivacy/cookie rules and counsel confirmation of the deployed configuration.

Consent

Where we expressly ask for consent for a particular optional processing activity, we rely on that consent. Consent may be withdrawn at any time without affecting processing that was lawful before withdrawal.

4. Recipients and service providers

We disclose personal data only where reasonably necessary for the purposes described above, including to service providers acting under appropriate contractual arrangements and to authorities where legally required.

Current material providers include:

  • Hetzner - EU/EEA infrastructure and hosting capacity.
  • Contabo - EU/EEA infrastructure and hosting capacity.
  • Zoho (EU service configuration) - business email. We intend to replace this service with internally operated email; this Notice will be updated when that change occurs.
  • Stripe - online payment processing and related payment/fraud services.
  • Backblaze - S3-compatible object storage in Amsterdam, holding a further copy of backups.
  • CDNsun - the content delivery network our static asset hostnames are served through; it processes visitor connection data such as IP addresses.
  • eLorus - invoicing, and submission of invoices to the Greek myDATA platform as an authorised provider.
  • ClouDNS - DNS services and domain availability lookups.
  • modulus (Modulus Telecoms & IT S.A., Athens) - the SMS gateway used to send verification codes to a telephone number you give us. modulus acts as our processor for the messages we send, and states that message content and recipient identifiers are held for 90 days and communication metadata for 12 months, the latter being a retention period imposed on it by Greek law.

Contabo and Zoho are used for legacy arrangements and existing customers rather than for new services.

Our CRM/helpdesk/ticketing functions are operated in-house, and our website analytics runs on infrastructure we operate ourselves.

The infrastructure on which we host customer services is located in the EU/EEA, unless a customer expressly contracts for something different in writing.

5. International transfers

We aim to keep customer hosting infrastructure in the EU/EEA. However, this does not mean every business-service provider is incapable of processing personal data outside the EEA.

Stripe operates globally and may transfer personal data internationally. Where required, Stripe states that it uses recognised transfer mechanisms including the EU-U.S. Data Privacy Framework and/or Standard Contractual Clauses or other lawful safeguards. Information about Stripe's current transfer arrangements is available from Stripe.

modulus is established in Greece, but states that some of its partners hold servers outside the EEA and that transfers to them are made under Standard Contractual Clauses approved by the European Commission. Information about those arrangements is available from modulus.

If Lambda Twelve itself makes a restricted transfer of personal data outside the EEA, we will use an applicable lawful transfer mechanism and provide information about the relevant safeguards as required by law.

6. Retention

We keep personal data only for as long as reasonably necessary for the relevant purpose, including legal, accounting, security and dispute requirements.

Our default periods are:

  • enquiries that do not become customers: 24 months from the last contact;
  • customer and account records, including contracts and Orders: for the life of the relationship, and for 5 years after it ends, for legal, tax and limitation-period purposes;
  • invoices and statutory accounting records: for the period required by Greek law, which is longer than the periods above for some records;
  • support records: 24 months after the ticket is closed, for service history, security and dispute purposes;
  • operational and security logs: 6 months, and minimised where practical;
  • backup copies: according to the applicable backup rotation for the service, so a copy may persist until it is overwritten in the normal cycle. For shared hosting that is a rolling 7 days; for virtual machines it is 3 daily, 1 weekly and 1 monthly recovery point.

Where a record is subject to more than one of these, the longer period applies. We may keep information for longer where we are required to by law, or where it is needed to establish, exercise or defend a legal claim.

7. Security

We use technical and organisational measures appropriate to the nature and risk of the processing. These may include access controls, authentication, network segmentation, encryption where appropriate, logging, backups and security monitoring. No system can be guaranteed absolutely secure.

8. Your rights

Subject to the conditions and exceptions in applicable data-protection law, you may have rights to:

  • access personal data concerning you;
  • correct inaccurate or incomplete data;
  • request erasure;
  • restrict processing;
  • object to processing based on legitimate interests;
  • receive data in a portable format where the statutory conditions apply;
  • withdraw consent where processing is based on consent; and
  • lodge a complaint with a competent supervisory authority.

Requests may be sent to legal@lambda-twelve.com. We may request information reasonably necessary to verify identity before acting on a request.

In Greece, the competent supervisory authority is the Hellenic Data Protection Authority (HDPA). You may contact the HDPA directly if you believe your data-protection rights have been infringed.

9. Automated decision-making

Lambda Twelve does not currently use solely automated decision-making producing legal or similarly significant effects on website visitors or ordinary customers, unless expressly disclosed for a particular service.

Stripe and other payment/fraud providers may apply their own automated fraud or risk controls under their applicable terms and privacy information.

10. Children

Our services are not directed to children. Consumer customers must be at least 18 years old to contract with Lambda Twelve unless applicable law and an expressly supported service provide otherwise.

11. Cookies and local storage

Our current public website analytics is configured to operate without analytics cookies. Strictly necessary cookies or similar storage may be used for account authentication, security, shopping/checkout state or other functionality requested by the user. See the Cookie Policy for details.

If we introduce optional analytics, advertising or other non-essential tracking technologies, we will update our disclosures and obtain consent where required before using them.

12. Changes to this Notice

We may update this Notice when our processing, providers or legal obligations change. The current version will be published on this website with its effective date. Material changes will be communicated where required by law.

13. Contact

Privacy and legal enquiries: legal@lambda-twelve.com
General enquiries: hello@lambda-twelve.com

Tell us what you are trying to run.

Describe the workload or the system you have in mind and we will tell you what it needs, what it costs, and whether we are the right people for it.