Privacy Policy
1. INTRODUCTION
This Privacy Policy explains how pialgorithms collects, uses, and protects personal data when you:
(a) visit or interact with our website at https://pialgorithms.com/ (“Website”); or
(b) use the pialgorithms SaaS platform (“Platform”) as an Authorised User on behalf of your organisation (“Customer”).
pialgorithms is committed to protecting your privacy and processing your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the EU Artificial Intelligence Act (EU) 2024/1689 (“EU AI Act”), the ePrivacy Directive (2002/58/EC), Greek Law 4624/2019, and all other applicable data protection legislation.
2. WHO WE ARE
pialgorithms
[ADDRESS], Athens, Greece
Registration No (GEMI): [NUMBER]
VAT: EL[NUMBER]
Data Protection Contact: Paraskevas Perlegkas, Founder & CEO
Email: paris.perlegkas@pialgorithms.com
Our role under the GDPR depends on the context:
- Website: pialgorithms is the Data Controller. We determine the purposes and means of processing personal data collected through the Website.
- Platform (SaaS services): pialgorithms acts as a Data Processor, processing personal data on behalf of your organisation (the Customer, who is the Data Controller) in accordance with the Software-as-a-Service Agreement and the Data Processing Agreement (DPA). For platform telemetry and operational monitoring only, pialgorithms acts as an independent Data Controller (see Section 9).
PART A: WHEN YOU VISIT OUR WEBSITE
3. WHAT DATA WE COLLECT ON THE WEBSITE
3.1 Data You Provide to Us
- Contact form submissions: Your name, email address, company name, and any information you include in the message body when you use the contact form on our Website
- Communications: Data you provide when contacting us by email, telephone, or any other means
3.2 Data Collected Automatically
- Website traffic data: Pages visited, time spent on pages, referral sources, browser type, device type, and approximate geographic location (country/region level)
- Cookies: Information collected through cookies placed in your browser (see Section 5 for details)
- Social media identifiers: If you interact with us through social media channels, your public username may be visible to us
4. HOW AND WHY WE USE WEBSITE DATA
| Purpose | Legal Basis (GDPR) |
|---|---|
| Responding to your contact form enquiries and communications | Consent (Article 6(1)(a)) - you voluntarily submit your data |
| Monitoring website traffic and improving the website experience | Consent (Article 6(1)(a)) - via cookie consent banner |
| Compliance with legal obligations | Legal obligation (Article 6(1)(c)) |
Where processing is based on your consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. COOKIES ON THE WEBSITE
5.1 What Are Cookies?
A cookie is a small file sent with the pages of a website and stored by your browser on the hard drive of your device. The information stored may be transferred to our servers or the servers of related third parties during subsequent visits.
5.2 Strictly Necessary Cookies
These cookies are essential for the Website to function and cannot be disabled. They do not store information that personally identifies you. No consent is required for strictly necessary cookies under the ePrivacy Directive (2002/58/EC).
5.3 Analytics Cookies
We use Google Analytics 4 (GA4), provided by Google Ireland Limited, to understand how visitors use the Website and to improve the user experience. Analytics cookies collect aggregated, anonymised data about website usage (page views). IP addresses are not logged or stored by GA4. We request your consent before placing analytics cookies via a cookie consent banner that implements Google Consent Mode v2 (Advanced). In advanced mode, when you decline analytics cookies, limited cookieless signals (page URL, timestamp, user agent, consent state) may still be sent to Google for aggregated statistical modelling only; these signals do not contain cookies or persistent identifiers.
5.4 Managing Cookies
You may manage or delete cookies through your browser settings:
- Google Chrome: Settings > Privacy and security > Cookies
- Mozilla Firefox: Settings > Privacy & Security > Cookies
- Microsoft Edge: Settings > Cookies and site permissions
- Apple Safari: Preferences > Privacy > Cookies
Please note that disabling cookies may affect the functionality of the Website. If you delete cookies in your browser, the cookie consent banner will be displayed again on your next visit.
5.5 No Marketing or Tracking Cookies
We do not use any marketing, advertising, or third-party tracking cookies on the Website.
6. WEBSITE DATA RETENTION
- Contact form submissions and communications: Retained for as long as necessary to respond to your enquiry and for a reasonable period thereafter for follow-up, unless you request deletion earlier.
- Analytics data: User-level analytics data is retained by Google Analytics 4 for fourteen (14) months; aggregated analytics reports are retained indefinitely by Google.
- Cookies: Retained for the duration specified in the cookie consent banner. Session cookies are deleted when you close your browser.Analytics data: User-level analytics data is retained by Google Analytics 4 for fourteen (14) months; aggregated analytics reports are retained indefinitely by Google.
PART B: WHEN YOU USE OUR PLATFORM (SaaS Services)
7. WHAT PERSONAL DATA WE PROCESS ON THE PLATFORM
7.1 Data Collected Automatically When You Use the Platform
- Authentication data: Your Microsoft Entra External ID user identifier (Object ID), display name, and email address, as provided by your organisation’s identity provider
- Session data: Secure authentication cookies managed by the Platform infrastructure (strictly necessary, no tracking)
- Usage telemetry: Pseudonymised interaction events, page views, and feature usage (PII is sanitised in production – user IDs are hashed, file names are redacted, personal data is removed from logs)
7.2 Data You Provide Through the Platform
- Documents: Files you upload for storage, indexing, and processing (may contain personal data of third parties such as names, contact details, financial data)
- Chat messages: Queries you submit to the Lexicon AI assistant and the resulting AI-generated responses
- Extraction data: Structured information extracted from documents via Hermes (e.g. contract parties, dates, financial terms)
- Tags and metadata: Labels and categories you assign to documents
7.3 Data Contained Within Uploaded Documents
Documents uploaded by you or your organisation may contain personal data of third parties (e.g. contract counterparties, invoice recipients, email correspondents). Your organisation, as Data Controller, is responsible for ensuring a lawful basis exists for uploading and processing such data.
8. HOW AND WHY WE USE PLATFORM DATA
We process personal data solely for the following purposes:
| Purpose | Legal Basis (GDPR) |
|---|---|
| Providing the Platform services: document storage, indexing, search, AI-powered retrieval, structured extraction, and analytics as described in the SaaS Agreement | Performance of a contract (Article 6(1)(b)) |
| Authentication and access control: verifying your identity and determining your access permissions | Performance of a contract (Article 6(1)(b)) |
| Platform security: monitoring for security threats, detecting anomalies, and preventing unauthorised access | Legitimate interests (Article 6(1)(f)) |
| Platform reliability: error detection, performance monitoring, and service improvement | Legitimate interests (Article 6(1)(f)) |
| Compliance: maintaining records of processing activities and responding to data subject rights requests | Legal obligation (Article 6(1)(c)) |
9. TELEMETRY AND MONITORING (PIALGORITHMS AS CONTROLLER)
For the limited purpose of maintaining platform security and operational integrity, pialgorithms acts as an independent Data Controller for the following processing:
- Collection of pseudonymised usage telemetry via Azure Application Insights
- Security event logging and monitoring via Azure Monitor
- Error and performance tracking
Our legitimate interest is maintaining a secure and reliable service. This processing is minimally invasive as all telemetry data is pseudonymised in production. You have the right to object to this processing under Article 21 of the GDPR by contacting our Data Protection Contact (see Section 20). We will assess whether our legitimate interests override your objection.
PII Protection in Telemetry:
- User identifiers are hashed with a salt (not stored in plain text)
- File names are replaced with generic categories (e.g. “document”, “image”)
- Email addresses are partially redacted (e.g. ***@domain.com)
- Phone numbers and IP addresses are fully redacted
- Sensitive fields (passwords, tokens, credentials) are never logged
10. AI PROCESSING DISCLOSURE
In accordance with EU Regulation 2024/1689 (EU AI Act):
- The Platform uses artificial intelligence models provided by Microsoft Azure OpenAI for document analysis, information extraction, retrieval, tagging, and conversational features
- AI-generated outputs are produced by third-party models and may contain inaccuracies, omissions, or errors
- All AI outputs require human review and validation before reliance
- The AI features do not constitute automated decision-making that produces legal effects within the meaning of GDPR Article 22
- Your data is not used to train or improve AI models
- For conversational AI features (Lexicon), prompts and responses are retained by Azure OpenAI for up to thirty (30) days to enable multi turn conversation continuity. This data is encrypted at rest (AES-256) and in transit (TLS 1.2+), stored within the EU Azure region, and isolated to your organisation’s Azure OpenAI resource. When you delete a chat session, the chat record itself is archived (not permanently deleted) in Azure Cosmos DB for billing accountability and operational analytics (see Section 14). Associated Azure OpenAI Responses API data is deleted on a best-effort basis at the time of archival. Your organisation may request permanent erasure of archived chat records at any time by contacting the Data Protection Contact (see Section 16), or all archived records are deleted within 30 days of Agreement termination. For all other AI features (document tagging, extraction, image captioning), Azure OpenAI does not retain data beyond the immediate request
- For document tagging (Smart Tag) and image captioning operations, pialgorithms stores audit records in Azure Cosmos DB containing token usage data, prompts sent to the AI model, model responses, and tag change history (snapshots of tag state after each manual or AI driven change, with per-user attribution via pseudonymised identifiers (Entra Object ID)). These records support billing accountability and operational auditing. They are encrypted at rest (AES-256) and in transit (TLS 1.2+), stored within the EU Azure region, and archived when the associated document is deleted by any authorised user (see Section 14). Tag records are included in your data export (Section 15)
- To detect and prevent misuse of AI services, Microsoft operates a standard abuse monitoring system. Prompts and completions flagged by automated content classification as potentially violating Microsoft’s Code of Conduct may be stored for up to thirty (30) days for review by automated systems and, where necessary, authorised Microsoft employees located within the EEA. This data is encrypted at rest (AES-256) and in transit (TLS 1.2+), logically isolated per customer resource within the EU region, and accessible only to authorised Microsoft employees via Secure Access Workstations. This processing is governed by Microsoft’s Data Protection Addendum and is limited to abuse detection and prevention. No flagged data is used to train AI models. For details, see https://learn.microsoft.com/en-us/azure/ai-foundry/responsible-ai/openai/data-privacy
11. DATA RECIPIENTS AND SUB-PROCESSORS
11.1 Website
- Analytics provider: Website traffic data (page views) is processed by Google Ireland Limited, acting as data processor, via Google Analytics 4 (GA4). GA4 collects EU traffic data through EU based servers. IP addresses are not logged or stored. For any processing by Google LLC (United States), the legal basis for the international transfer is the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), under which Google LLC is a certified participant. For details, see Google’s privacy policy at https://policies.google.com/privacy
- No personal data from the Website is sold, rented, or shared with any other third parties.
11.2 Platform
- Microsoft Corporation (Azure cloud services): All Platform infrastructure is hosted on Microsoft Azure in EU data centres. Microsoft processes data under its Data Protection Addendum and holds ISO 27001, ISO 27018, SOC 1/2/3 Type II, and GDPR compliance certifications.
- A complete list of Azure services used is maintained in the Subprocessor and Data Residency Statement, available upon request from your organisation’s administrator or from pialgorithms.
- No personal data from the Platform is sold, rented, or shared with any other third parties.
12. COOKIES AND SESSION MANAGEMENT ON THE PLATFORM
The Platform uses only strictly necessary cookies:
- Authentication session cookies: Managed by Azure Static Web Apps. These are secure, HttpOnly, and SameSite cookies required for authentication. They are not used for tracking or analytics.
- No marketing, advertising, or third-party tracking cookies are used on the Platform.
- No cookie consent is required for strictly necessary cookies under the ePrivacy Directive (2002/58/EC).
Session Management:
- Sessions expire after 15 minutes of inactivity (idle timeout)
- Sessions have an absolute timeout of 12 hours regardless of activity
- Session data is stored in localStorage for session management only and is cleared on logout
COMMON PROVISIONS
13. INTERNATIONAL DATA TRANSFERS
All personal data processed through the Platform is processed exclusively within the European Economic Area (EEA). All Azure services are deployed in EU Azure regions. No personal data from the Platform is transferred to any country outside the EEA. Sub-processor processing (including Microsoft’s abuse monitoring described in Section 10) remains within the EEA as described in the Subprocessor and Data Residency Statement.
For the Website, personal data is processed within the European Union. Website analytics data may be processed by Google LLC (United States) under the EU-US Data Privacy Framework (Commission Implementing Decision (EU) 2023/1795), under which Google LLC is a certified participant. All other Website data is processed within the EU. No transfer of personal data to a country outside the European Union takes place except under an applicable adequacy decision or where adequate safeguards are in place.
14. DATA RETENTION
Website:
- Contact form submissions and communications: Retained for as long as necessary to respond to your enquiry. You may request deletion at any time.
- Analytics data: User-level analytics data retained by Google Analytics 4 for fourteen (14) months; aggregated reports retained indefinitely by Google.
Platform:
- Platform data (documents, chat sessions, extraction records, Athenaeum tag and Image Caption audit records, tag change history): Retained for the duration of the SaaS Agreement between pialgorithms and your organisation. You may delete individual documents and chat sessions at any time. When a document is deleted by any authorised user, the document file and all derived content artefacts (canonical copies, extracted figures, layout analysis results) are permanently deleted. Derived operational records — including structured extraction data (Hermes) and tag operation audit records (Athenaeum tag records with tag change history snapshots covering both manual and AI-driven changes, Image Caption AI audit records) — are archived (not deleted) and retained for the duration of the Agreement for billing accountability, regulatory compliance, and analytics purposes. When a chat session is deleted by an authorised user, the session record is archived (not permanently deleted) and retained for the duration of the Agreement for billing accountability and operational analytics; associated Azure OpenAI Responses API data is deleted on a best-effort basis at the time of archival. Archived records (including archived chat session records) are not accessible through the Platform interface. Deleted documents and their derived storage artefacts enter a seven (7) day soft-delete recovery window during which the data is inaccessible through the Platform but retained in Azure Blob Storage to protect against accidental deletion. After seven (7) days, soft-deleted data is permanently and irrecoverably erased by Azure. All data, including archived records, is deleted within 30 days of Agreement termination.
- Erasure of archived records: Your organisation may request erasure of specific archived records (including archived chat session records) at any time by contacting the Data Protection Contact (see Section 20). pialgorithms will respond within thirty (30) days
- Authentication data: Retained for the duration of the SaaS Agreement. Managed by Microsoft Entra External ID.
- Telemetry and monitoring data: Retained in accordance with Azure Application Insights default retention policies (90 days), with PII sanitised in production.
Retention periods attributed to third-party services (Azure Application Insights, Azure OpenAI, Google Analytics) reflect those providers’ current policies or pialgorithms’ current configuration on their platforms. These periods may change if the respective provider updates its defaults or available options. pialgorithms monitors material changes and updates this policy accordingly.
15. YOUR RIGHTS
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Article 15): You may request information about what personal data is processed about you
- Right to rectification (Article 16): You may request correction of inaccurate personal data
- Right to erasure (Article 17): You may request deletion of your personal data
- Right to restriction (Article 18): You may request restriction of processing in certain circumstances
- Right to data portability (Article 20): You may request your data in a structured, commonly used, machine-readable format
- Right to object (Article 21): You may object to processing based on legitimate interests
- Right to withdraw consent: Where processing is based on consent (e.g. analytics cookies), you may withdraw your consent at any time
How to exercise your rights:
Website: Contact our Data Protection Contact at paris.perlegkas@pialgorithms.com.
Platform: Since your organisation is the Data Controller, please contact your organisation’s designated data protection contact to exercise these rights. Your organisation will coordinate with pialgorithms as needed. If you have questions about how pialgorithms processes your data as a Processor, you may also contact our Data Protection Contact at paris.perlegkas@pialgorithms.com.
16. DATA SECURITY
We are committed to protecting your personal data. We have implemented appropriate technical and organisational measures to secure and protect your data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
Website:
- SSL/TLS encryption for all data transmitted between your browser and our Website
Platform:
- All data hosted exclusively in EU Microsoft Azure data centres
- AES-256 encryption at rest for all storage services
- TLS 1.2+ encryption in transit for all communications
- Authentication via Microsoft Entra External ID
- Managed Identity for all backend service connections (no API keys or shared credentials)
- Role-Based Access Control with least-privilege principle
- Per-user personal storage containers with pseudonymised identifiers for individual data isolation
- PII sanitisation in production logs
- Session management with idle and absolute timeouts
- Azure Monitor and Application Insights for security event detection
Full details of security measures are described in the SaaS Agreement.
17. CHILDREN’S DATA
Our Website and Platform are business-to-business services and are not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children.
18. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our processing activities, technology, or legal requirements. The “Last Updated” date at the top of this policy will be revised accordingly. Material changes will be communicated through the Website, the Platform, or via your organisation.
19. COMPLAINTS
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. The relevant supervisory authority for pialgorithms is:
Hellenic Data Protection Authority (HDPA)
Kifissias 1-3, 11523 Athens, Greece
Tel: +30 210 6475600
Email: complaints@dpa.gr
Website: www.dpa.gr
You also have the right to lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or place of work.
20. CONTACT US
For questions or concerns about this Privacy Policy or the processing of your personal data:
pialgorithms
[ADDRESS], Athens, Greece
Data Protection Contact: Paraskevas Perlegkas, Founder & CEO
Email: paris.perlegkas@pialgorithms.com