Last updated: August 2026
This GDPR Policy is the Art. 13/14 information notice for personal data processing by IronCloud PC in connection with ironcloud.gr and the IronCloud Registrar portal my.ironcloud.gr. It complements the Privacy Policy and Cookie Policy.
IronCloud PC
Leoforos Eleftherias 11, Alimos 17455, Greece
GEMI: 117557101000 · AFM: 800346977
Privacy: [email protected]
Support: [email protected] / [email protected]
Phone: +30 210 2202 667
| Purpose | Legal basis |
|---|---|
| Respond to contact / pre-contractual inquiries (marketing site) | Art. 6(1)(b) and/or 6(1)(f) |
| Newsletter | Art. 6(1)(a) consent |
| Analytics, reCAPTCHA, Maps (non-essential) | Art. 6(1)(a) consent |
| Language preference / essential session cookies | Art. 6(1)(f) / necessity for requested service |
| Registrar account, domain orders, support | Art. 6(1)(b) contract |
| Registrant data to FORTH-ICS / registries; tax invoicing | Art. 6(1)(c) legal obligation |
| Security, fraud prevention, audit logs | Art. 6(1)(f) legitimate interests |
| Optional Google OAuth | Art. 6(1)(a) and/or 6(1)(b) as applicable |
| Payments (Stripe / legacy Viva), SSL issuance | Art. 6(1)(b) |
Full detail is in the Privacy Policy.
Processors and recipients include, as applicable: FORTH-ICS, Cloudflare Registrar, Stripe, Viva (legacy), mytimologisi/AADE, The SSL Store, Let’s Encrypt, Google (OAuth/Analytics/reCAPTCHA/Maps), Mailchimp, and our SMTP provider. Registrant data for .gr/.ελ is provided to FORTH-ICS for EETT registrant-database obligations.
Some providers (e.g. Cloudflare Registrar, Stripe, Google, Mailchimp, The SSL Store) may process data outside the EEA. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) and supplementary measures as needed.
| Data | Retention |
|---|---|
| Contact emails | Up to 24 months |
| Newsletter | Until unsubscribe |
| Analytics | Per GA (typically ~14 months if enabled) |
| Account | While active + reasonable period after closure |
| Domain / registrant | Registration term + EETT/legal retention |
| Invoices / billing | Minimum 5 years (Greek tax) |
| Audit / security logs | Typically 2–7 years |
| KYC | Verification + legal/registry retention |
Where legal or registry obligations apply, erasure may be refused or limited until those obligations end.
We do not claim automated DSAR, export, or erasure tooling. Requests are handled by staff within GDPR timeframes.
You are not required to browse ironcloud.gr, but certain data are necessary for specific services. In particular, domain registration cannot proceed without required registrant and (where applicable) billing/KYC data. Failure to provide mandatory registrant data means we cannot register or maintain the domain under registry rules.
We do not use personal data for automated decision-making or profiling that produces legal or similarly significant effects within the meaning of Art. 22 GDPR.
You may lodge a complaint with the Hellenic Data Protection Authority (HDPA): www.dpa.gr.
Related: Privacy Policy · Cookie Policy · Terms of Service · Registrar portal.