Version 4.5, effective August 24, 2026
Klehomerie is committed to protecting your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019. This notice outlines how we collect, use, and safeguard your information.
This notice is informational. It does not itself constitute your consent. Where we rely on consent, that consent is collected separately, is entirely optional, and may be withdrawn at any time without any effect on your Service Agreement.
The entity responsible for processing your personal data is:
Klehomerie is not required to appoint a Data Protection Officer under Article 37 GDPR. All data protection enquiries are handled at the address above.
We collect and process the following categories of personal data necessary for our services:
We do not collect or process special categories of personal data as defined in Article 9 GDPR.
Provision of data. Providing identity, contact, and asset data is a contractual requirement. Without it we cannot deliver the Services. Automated decision-making. We carry out no automated decision-making or profiling producing legal or similarly significant effects.
Your data is processed for the following specific purposes:
Under Article 6 GDPR, each purpose above rests on a specific lawful basis:
Consent is optional and separate from your Service Agreement. Granting or refusing it has no effect on the services you receive, and it may be withdrawn at any time, free of charge.
We do not sell your data. We may share necessary data with:
The Vault is presented under Klehomerie branding; the underlying platform is operated by PropOS as our sub-processor. We will update this notice before engaging any new sub-processor.
The custody and export of your Asset File are governed by Annex 1 (Document Custody and Digital Vault) to your Service Agreement.
Data held in the Klehomerie Digital Vault is hosted on servers located in France, within the European Economic Area.
Where any of our cloud-based tools transfers personal data outside the EEA — including by access from outside the EEA by a provider's personnel — the transfer is made under appropriate safeguards in accordance with GDPR Chapter V, namely the European Commission's Standard Contractual Clauses or, where one applies to the destination country, an adequacy decision of the Commission.
You may request a copy of the safeguards applying to any transfer by writing to gdpr@klehomerie.com.
We retain your personal data for the duration of our contractual relationship.
Asset File. After termination, the Asset File — the system of record for your asset, comprising technical reports, photographic evidence, and works records — is retained for the period required by Greek tax and accounting legislation (five to ten years) or as required under a legal hold, after which it is securely deleted.
Digital Vault. Separately, Vault credentials are revoked and Vault-hosted data is deleted or returned within 14 days of termination. Deletion of Vault data does not delete the Asset File.
Keys and access credentials. Returned or destroyed within 14 days of termination, regardless of the retention period applying to other records.
Legal hold. Where personal data forms part of, or may reasonably be required for, legal, arbitral, insurance, or regulatory proceedings involving you, your asset, or Klehomerie, we retain it until those proceedings and any applicable appeal period have concluded. This applies notwithstanding any earlier deletion schedule or erasure request. We will inform you where a legal hold applies to your file.
Under GDPR, you have the right to:
To exercise these rights, please contact us at gdpr@klehomerie.com. We will respond within one month of receipt.
You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα) if you believe your data protection rights have been violated:
Kifissias 1-3, 115 23 Athens, Greece | Tel. +30 210 6475600 | contact@dpa.gr | www.dpa.gr
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, or misuse. This includes secure digital storage and limited access to physical files, individually issued credentials for Vault access, and contractual security obligations imposed on all sub-processors.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority without undue delay and, where the risk is high, inform you directly.
Our website uses strictly necessary cookies required for it to function, and, subject to your consent, analytics cookies which help us understand how the site is used. Analytics are provided by Google Analytics 4 (Google Ireland Limited), acting as our sub-processor.
Analytics and any non-essential cookies are set only after you give consent through our cookie banner. You may withdraw or change your choice at any time via the cookie settings link on our website. Refusing non-essential cookies does not affect your access to the site.
Where you subscribe to our newsletter or download a technical checklist, we process your email address on the basis of your consent, and record the date and source of that consent. Every email includes a one-click unsubscribe link.
In the course of the Services we also process limited personal data relating to individuals other than our clients:
Individuals in these categories hold the same rights set out in Section 8 and may contact us at gdpr@klehomerie.com.
We may update this notice to reflect legal or operational changes. Each version carries a version number and effective date. The latest version will always be available on our website. We will notify contracted clients of any material change.