DL Software L.P., the company providing the Nephelo service, is the data controller for your account data, billing, communications and the operation of the platform.
The controller is DL Software L.P., a limited partnership trading as DL Software, VAT number 802945681, GEMI number 185924103000 and EUID ELGEMI.185924103000. Its registered office is at 13 Doiranis Street, Kypseli, 113 62 Athens, Greece.
For personal data you store inside your sites, email or your clients' databases, you or your client determine the purpose of the processing. In that case Nephelo acts as a processor and follows your lawful instructions.
This policy covers nephelo.gr, your account, the management dashboard, the public forms and the provision of the service.
We collect only the data needed to create your account, provide the service, keep it secure and communicate with you.
We neither receive nor store your full card number or security code. Those are submitted directly to the payment provider.
Every processing activity rests on a specific purpose and a lawful basis.
We do not use automated decision-making or profiling that produces legal or similarly significant effects for you.
We use necessary cookies so that the site and your account work securely.
Strictly necessary cookies do not require consent, because without them the service cannot work properly. You can block them in your browser, but your account or certain features may then not work.
Google Analytics 4 stays inactive until you choose “Accept all” or enable the “Statistics” category in the cookie settings. Before you consent, the tool is not loaded and no data is sent to Google.
We do not use advertising or targeting cookies. If we add new non-essential analytics or marketing tools in future, we will update this policy and ask for prior consent where required.
We use a limited number of providers to run the service. They receive only the data they need for their particular purpose.
Our providers are contractually bound to protect the data and use it only for the services they provide to us. An up-to-date list of sub-processors is available on request.
The core hosting data and the sites themselves are stored in data centres inside the European Union.
Some international providers, such as payment processors or network security services, may process limited data outside the European Economic Area.
Where such a transfer takes place, we use an appropriate GDPR mechanism, such as an adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where required. You can ask us for more information or a copy of the relevant safeguards.
We keep data only for as long as needed for the purpose for which it was collected and to meet our legal obligations.
Depending on the processing, you can exercise the rights the GDPR gives you.
To protect your data, we may ask for information confirming your identity and authorisation. We reply without undue delay and within one month. If a complex request requires an extension, we will tell you within that first month.
Where we process hosted data solely on behalf of one of our customers, we may refer you to the relevant controller.
If you believe the processing of your data breaches the law, you can lodge a complaint with the competent supervisory authority.
For Greece, that is the Hellenic Data Protection Authority. We would encourage you to contact us first, so that we can look into the matter and put it right.
We apply technical and organisational measures appropriate to the nature of the service and the risk to the data.
No system is completely secure. If you notice suspicious activity or a possible breach, please tell us immediately.
We update this policy when the service, our providers or the law changes.
The new version is published on this page with an updated date. If a change materially affects how we use your data, we will notify you by an appropriate means before it takes effect.
We recommend reviewing this policy periodically, particularly when new features are added to the service.
For questions about your data, or to exercise your rights under the GDPR, please get in touch.