WEBSITE PRIVACY POLICY
Effective Date: August 14, 2026
Data Controller: DIAPLOUS MARITIME SERVICES Ltd.
1. Introduction & Scope
DIAPLOUS MARITIME SERVICES Ltd. (“Diaplous”, “we”, “us”, or “our”) acts as the Data Controller (PII Controller) for personal data collected through our official website located at https://www.diaplous.com/.
This Privacy Policy outlines how we collect, process, store, transfer, and protect the personal data of website visitors, prospective clients, and individuals reaching out through our digital channels (“Users” or “PII Principals”).
In accordance with ISO/IEC 27701:2019 (Clause 7.2.5 & Control A.7.3.1) and Article 13 of the EU General Data Protection Regulation (GDPR 2016/679), this policy transparently defines our privacy practices and data protection commitments.
2. Information We Collect
We collect personal data directly when you interact with our online contact forms, as well as automatically through technical logging and cookie technologies when you navigate our site.
A. Personal Data Provided Directly by You
- Contact & Inquiry Data: Full name and corporate or personal email address submitted via our online contact forms. Providing this data is voluntary; however, failure to provide a valid email address will prevent us from responding to your inquiry
B. Information Collected Automatically
- Technical & System Diagnostic Data: Anonymized/masked IP address, browser type and version, operating system details, device type, diagnostic data, timestamps, and server access/error logs.
- Cookie & Preference Data: Essential functional cookie data, analytics interaction metrics, and user consent choices recorded through our Cookie Consent Management Banner.
3. Purpose of Processing & Lawful Bases
In alignment with GDPR Article 6 and ISO/IEC 27701 Control A.7.2.2, your personal data is processed for explicit, legitimate business purposes:
- Managing Contact Inquiries (GDPR Art. 6.1(b) – Contract Performance / Pre-Contractual Measures): To respond to incoming client requests, service inquiries, and business communications.
- Website Security & Performance (GDPR Art. 6.1(f) – Legitimate Interest): To ensure website availability, maintain server integrity, detect and prevent malicious traffic or brute-force attacks, and protect corporate IT infrastructure.
- Website Usage Analytics (GDPR Art. 6.1(a) – Consent): To measure audience traffic, analyze page interactions, and optimize user experience (activated strictly upon explicit opt-in).
- Demonstrating Regulatory Compliance (GDPR Art. 6.1(c) – Legal Obligation): To maintain opt-in logs and consent records under ePrivacy directives and GDPR Article 7.
4. Cookies & Tracking Technologies
- Essential & Security Cookies: Automatically deployed to ensure fundamental site navigation, page loading, and Web Application Firewall (Wordfence WAF) security defense. Essential cookies do not require prior user consent.
- Analytics Cookies: Deployed via Google Analytics 4 (GA4) to analyze visitor trends. Native IP anonymization/masking is enforced, ensuring your full IP address is never stored or written to disk.
- Managing Preferences: Non-essential analytics cookies are disabled by default. You can customize, grant, or revoke your consent at any time by clicking the “Cookie Preferences” link in our website footer.
5. Sub-processors & International Transfers
We do not sell, rent, or trade personal data. Data is shared strictly with authorized service providers (“Sub-processors”) required for website hosting, security, and performance under binding Data Processing Addendums (DPAs) pursuant to GDPR Article 28.
Where international data transfers occur outside the European Economic Area (EEA) , Diaplous ensures appropriate safeguards under GDPR Articles 45 & 46 and ISO/IEC 27701 Control A.7.5.1, utilizing the EU-U.S. Data Privacy Framework (Adequacy Decision) and Standard Contractual Clauses (SCCs).
6. Data Retention Schedule
In compliance with ISO/IEC 27701 Control A.7.4.5 and data minimization principles, personal data is retained strictly for the minimum necessary duration:
- Server Access & Error Logs: Up to 90 days (automated rolling purge).
- Contact Form Inquiries: 2 years from inquiry resolution.
- Google Analytics Data: 2 years (automated GA4 retention settings).
- Cookie Preference Records: 1 year (automated annual consent refresh request).
When personal data is no longer required, it is securely deleted or permanently anonymized.
7. Data Security Safeguards
Diaplous maintains an integrated Information Security & Privacy Information Management System certified under ISO/IEC 27001:2022 and ISO/IEC 27701:2019. Technical security measures include:
- Encryption in Transit: End-to-end SSL/TLS encryption (Let’s Encrypt RSA 2048-bit) enforcing
HTTPSacross all web traffic. - Perimeter Security: Active Web Application Firewall (Wordfence WAF) with rate-limiting and active brute-force protection.
- Access Control: Multi-Factor Authentication (MFA) and strict Role-Based Access Control (RBAC) enforced for website management panels.
8. Data Subject Rights
Under GDPR Articles 15–22 and ISO/IEC 27701 Controls A.7.3.1–A.7.3.9, you have the right to request:
- Access to the personal data we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your personal data when no longer necessary.
- Restriction or Objection to specific processing activities.
- Data Portability in a structured, machine-readable format.
- Withdrawal of Consent at any time without affecting prior lawful processing.
To exercise any of your rights, contact our Data Protection Officer at dpo@diaplous.com. Requests are handled free of charge within 30 days .
9. Contact Information & Regulatory Complaints
Data Protection Officer (DPO)
- Email: dpo@diaplous.com
Supervisory Authority
If you consider that our processing infringes data protection laws, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):
- Email: : contact@dpa.gr
- Website: https://www.dpa.gr/en
