Data controller
The controller of your personal data is ΠΕΡΣΗΣ ΙΔΙΩΤΙΚΗ ΚΕΦΑΛΑΙΟΥΧΙΚΗ ΕΤΑΙΡΕΙΑ (ΠΕΡΣΗΣ Ι.Κ.Ε. — PERSIS P.C.), VAT No. 800882264, Rhodes Tax Office, registered office at Georgiou Seferi 108, Rhodes, 85100, Greece, GEMI (Companies Registry) No. 143888520000, which operates the home.gr platform.
Contact for personal data matters: privacy@home.gr.
We have not appointed a Data Protection Officer (DPO), as the conditions of Article 37 GDPR are not met. Your requests are answered directly by the controller.
What data we process
Account data
Full name, email address, password in encrypted form (a hash — never stored in readable form), optionally a phone number, user role (owner or tenant), registration date and email verification status.
Listing details
For owners: the area and address of the property, floor area, storey, number of rooms, furnishings, price and what it includes, availability, description and the photos you upload. Some of these are public by definition — that is the purpose of a listing.
Messages
The content and metadata (sender, recipient, time) of the messages you exchange with other users inside the platform, and the contact requests you send.
Reports and blocks
When you report a listing, a user or a message, we keep who made the report, what it concerns, the reason you picked, your optional comment, its status and the reasoning on which it was closed. When you block a user, we keep who blocked whom, when, and the optional reason.
This information is visible only to you and to the person reviewing the report. We do not disclose who submitted a report to the person it concerns, and there is no list anywhere of who has blocked someone. See also section 09 of the terms of use.
Signing in with Google or Apple
You can sign in with a Google or Apple account instead of a password. In both cases we never see your password: the provider identifies you and returns a signed token to us.
From Google we request three fields only — openid, email, profile — and receive: your permanent Google identifier, your email address and whether it is verified, your display name and the address of your profile picture. We do not request and do not obtain access to Gmail, Contacts, Drive, Calendar or any other Google service.
From Sign in with Apple we receive the identifier Apple generates and an email address — either your real one or an anonymous relay, as you choose. Apple provides your name only the first time you approve the sign-in. Nothing else from your Apple account.
What we do with them: we keep the provider’s identifier so we can recognise you at your next sign-in. The email becomes your account email — and if the provider certifies that it is verified, it links you to an existing account with the same email instead of creating a duplicate. The name pre-fills your profile. This data is used solely for identifying you and for your account: we do not sell it, do not pass it to advertising networks or data brokers, and do not use it for advertising, targeting or training models.
They are deleted together with your account. You can also revoke access at any time from your account settings at Google or Apple — that stops future sign-ins; it does not by itself delete your home.gr account.
Technical data and logs
IP address, browser type and version, operating system, date and time of the request, referring page and application errors. This data is generated automatically by the infrastructure and is necessary for operation and security.
Contacting us
Whatever you send us by email — message content, contact details and any attachments.
iOS app
The app requests three permissions, and only when you press the corresponding button — never on launch:
- Location (while using the app only): exclusively when you press “My location” while listing a property, so the point can be placed on the map. Your position is not recorded in the background and the exact point is never published: the public sees only a circle of 150–1,200 metres around a shifted position.
- Camera: only when you choose “Take a photo now” for a listing photo.
- Photos and Files: when you pick images for your listing. The app does not scan your library — the iOS picker runs separately and gives us only what you selected.
If you turn on notifications, we store the device token, the platform and a device name, so we know where to send them. It is erased when you turn them off or delete your account.
The app contains no advertising networks, does not track your activity across other apps or websites, and does not share data with data brokers.
Usage measurement
We keep our own, first-party measurements of what works on the platform. The IP address is never stored: we keep only a cryptographic digest (SHA-256) with a rotating secret, so it cannot be traced back to a device. We do not use Google Analytics or any other third-party tool.
We neither seek nor request special categories of data (Article 9 GDPR). Please do not include such information in listings or messages.
Minors
The service is intended for adults and the terms of use require you to be 18. We do not address children and do not knowingly collect their data.
For the record: under Law 4624/2019 (Article 21), processing a minor’s data on the basis of consent is lawful in Greece from the age of 15; below that, the consent of the holder of parental responsibility is required. If we identify an account belonging to a minor, we delete it.
Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Creating and running your account | Account data | Performance of a contract — Article 6(1)(b) |
| Publishing and displaying listings | Listing details, photos | Performance of a contract — Article 6(1)(b) |
| Communication between users | Messages, account details | Performance of a contract — Article 6(1)(b) |
| Security, prevention of fraud, abuse and spam | Technical logs, metadata | Legitimate interests — Article 6(1)(f) |
| Reviewing reports and protecting users | Reports, the reported content, account details | Legitimate interests — Article 6(1)(f) |
| Blocking communication at your instruction | The pair of accounts, time, optional reason | Performance of a contract — Article 6(1)(b) |
| Improving and stabilising the service | Technical logs, application errors | Legitimate interests — Article 6(1)(f) |
| Responding to support requests | Contact details, message content | Legitimate interests or performance of a contract |
| Newsletter emails about platform news | Email, name | Consent — Article 6(1)(a) (revocable at any time) |
| Meeting tax and accounting obligations | Invoicing details for optional services | Legal obligation — Article 6(1)(c) |
Where processing is based on our legitimate interests, we have balanced those interests against your rights and freedoms. You can ask for the relevant documentation and exercise your right to object.
Recipients and processors
We do not sell or rent personal data. Your data is made accessible only to the recipients below, to the extent necessary for the platform to work:
| Recipient | Role | Location |
|---|---|---|
| Neon | Database hosting | European Union |
| Amazon Web Services (S3) | Storage of listing photos | Frankfurt, Germany (EU) |
| Resend | Sending transactional email (verification, notifications) | See section 5 |
| MapTiler | Displaying maps and geocoding areas | Europe |
Other users: when you publish a listing or send a message, the relevant details become visible to their recipients. This is inherent in how the platform works.
Public authorities: only where there is a legal obligation or a lawful request.
A contract under Article 28 GDPR has been or will be concluded with every processor before the platform goes into production. We currently use no analytics tools, advertising networks or user-profiling tools. If that changes, this policy will be updated before they are switched on.
International transfers
We aim to keep your data within the European Economic Area. The database and the photos are hosted on infrastructure inside the EU.
Some providers may process limited data (e.g. email addresses for message delivery) outside the EEA, or may have support functions outside the EEA. In those cases the transfer relies on an adequacy decision of the European Commission or on Standard Contractual Clauses (SCCs), with appropriate supplementary measures.
You can request a copy of those safeguards at privacy@home.gr.
Retention periods
We keep data only for as long as is needed for the purposes for which it was collected:
| Category | Retention |
|---|---|
| Account data | For as long as the account is active; deleted within 30 days of a deletion request |
| Listings and photos | For as long as they are published; up to 12 months after withdrawal, so you can restore them |
| Messages | Up to 24 months from the last exchange |
| Reports | Up to 24 months from their closure — needed so a repeated incident can be recognised as such |
| Blocks | For as long as they are in force; deleted as soon as you lift them |
| Technical logs | Up to 12 months |
| Backups | Up to 90 days, on a rolling basis |
| Invoices for optional services | As long as tax legislation requires |
Once those periods end, the data is deleted or anonymised in a way that does not allow you to be identified.
Your rights
Under the General Data Protection Regulation (EU) 2016/679, you have the following rights:
- Access — to find out which of your data we process and to receive a copy.
- Rectification — to have inaccurate data corrected or incomplete data completed.
- Erasure (“the right to be forgotten”) — to have your data deleted, where no ground for retention applies.
- Restriction of processing in specific circumstances.
- Portability — to receive the data you have provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Objection — to object to processing based on our legitimate interests.
- Withdrawal of consent — where processing rests on consent, you can withdraw it at any time, without affecting the lawfulness of processing before the withdrawal.
How you exercise them
Send an email to privacy@home.gr from the address registered on your account. We reply without undue delay and at the latest within one month; that period may be extended by a further two months for complex requests, and we will tell you if it is.
Where there are reasonable doubts about your identity, we may ask for additional verification. Exercising your rights is free of charge, except for manifestly unfounded or excessive requests.
Right to lodge a complaint
If you consider that the processing of your data infringes the law, you have the right to lodge a complaint with the supervisory authority:
Hellenic Data Protection Authority
1-3 Kifisias Avenue, 115 23 Athens, Greece
Website: www.dpa.gr
We would be glad, though, if you contacted us first — most of the time the matter is resolved straight away.
Security
We apply appropriate technical and organisational measures to protect your data:
- Encrypted data transmission over HTTPS/TLS across the whole platform.
- Passwords stored exclusively as cryptographic hashes — never in readable form.
- Restricted access to the data, only for those who need it to run the service.
- Regular backups and separation of development and production environments.
- Choosing infrastructure providers that operate within the EU.
No method of transmission or storage is completely secure. In the event of a breach posing a high risk to your rights, we will inform you and notify the Authority, as Articles 33 and 34 GDPR require.
We hold no third-party security certifications, and we do not claim to.
Cookies and local storage
The platform uses a minimal set of strictly necessary cookies, plus one local storage key for language. We currently use no third-party cookies and no analytics.
The details are set out in the Cookie policy.
Changes to this policy
We may update this policy when the platform’s features, our providers or the legal framework change. The date of the last update is shown at the top of the page.
For material changes we will notify registered users by email or by a notification within the platform.