WEBSITE PRIVACY POLICY

Effective Date: August 14, 2026

Data Controller: DIAPLOUS MARITIME SERVICES Ltd.

1. Introduction & Scope

DIAPLOUS MARITIME SERVICES Ltd. (“Diaplous”, “we”, “us”, or “our”) acts as the Data Controller (PII Controller) for personal data collected through our official website located at https://www.diaplous.com/.

This Privacy Policy outlines how we collect, process, store, transfer, and protect the personal data of website visitors, prospective clients, and individuals reaching out through our digital channels (“Users” or “PII Principals”).

In accordance with ISO/IEC 27701:2019 (Clause 7.2.5 & Control A.7.3.1) and Article 13 of the EU General Data Protection Regulation (GDPR 2016/679), this policy transparently defines our privacy practices and data protection commitments.

2. Information We Collect

We collect personal data directly when you interact with our online contact forms, as well as automatically through technical logging and cookie technologies when you navigate our site.

A. Personal Data Provided Directly by You

  • Contact & Inquiry Data: Full name and corporate or personal email address submitted via our online contact forms. Providing this data is voluntary; however, failure to provide a valid email address will prevent us from responding to your inquiry

B. Information Collected Automatically

  • Technical & System Diagnostic Data: Anonymized/masked IP address, browser type and version, operating system details, device type, diagnostic data, timestamps, and server access/error logs.
  • Cookie & Preference Data: Essential functional cookie data, analytics interaction metrics, and user consent choices recorded through our Cookie Consent Management Banner.

3. Purpose of Processing & Lawful Bases

In alignment with GDPR Article 6 and ISO/IEC 27701 Control A.7.2.2, your personal data is processed for explicit, legitimate business purposes:

  • Managing Contact Inquiries (GDPR Art. 6.1(b) – Contract Performance / Pre-Contractual Measures): To respond to incoming client requests, service inquiries, and business communications.
  • Website Security & Performance (GDPR Art. 6.1(f) – Legitimate Interest): To ensure website availability, maintain server integrity, detect and prevent malicious traffic or brute-force attacks, and protect corporate IT infrastructure.
  • Website Usage Analytics (GDPR Art. 6.1(a) – Consent): To measure audience traffic, analyze page interactions, and optimize user experience (activated strictly upon explicit opt-in).
  • Demonstrating Regulatory Compliance (GDPR Art. 6.1(c) – Legal Obligation): To maintain opt-in logs and consent records under ePrivacy directives and GDPR Article 7.
  We do not use personal data for automated decision-making or profiling.

4. Cookies & Tracking Technologies

  • Essential & Security Cookies: Automatically deployed to ensure fundamental site navigation, page loading, and Web Application Firewall (Wordfence WAF) security defense. Essential cookies do not require prior user consent.
  • Analytics Cookies: Deployed via Google Analytics 4 (GA4) to analyze visitor trends. Native IP anonymization/masking is enforced, ensuring your full IP address is never stored or written to disk.
  • Managing Preferences: Non-essential analytics cookies are disabled by default. You can customize, grant, or revoke your consent at any time by clicking the “Cookie Preferences” link in our website footer.

5. Sub-processors & International Transfers

We do not sell, rent, or trade personal data. Data is shared strictly with authorized service providers (“Sub-processors”) required for website hosting, security, and performance under binding Data Processing Addendums (DPAs) pursuant to GDPR Article 28.

Where international data transfers occur outside the European Economic Area (EEA) , Diaplous ensures appropriate safeguards under GDPR Articles 45 & 46 and ISO/IEC 27701 Control A.7.5.1, utilizing the EU-U.S. Data Privacy Framework (Adequacy Decision) and Standard Contractual Clauses (SCCs).

6. Data Retention Schedule

In compliance with ISO/IEC 27701 Control A.7.4.5 and data minimization principles, personal data is retained strictly for the minimum necessary duration:

  • Server Access & Error Logs: Up to 90 days (automated rolling purge).
  • Contact Form Inquiries: 2 years from inquiry resolution.
  • Google Analytics Data: 2 years (automated GA4 retention settings).
  • Cookie Preference Records: 1 year (automated annual consent refresh request).

When personal data is no longer required, it is securely deleted or permanently anonymized.

7. Data Security Safeguards

Diaplous maintains an integrated Information Security & Privacy Information Management System certified under ISO/IEC 27001:2022 and ISO/IEC 27701:2019. Technical security measures include:

  • Encryption in Transit: End-to-end SSL/TLS encryption (Let’s Encrypt RSA 2048-bit) enforcing HTTPS across all web traffic.
  • Perimeter Security: Active Web Application Firewall (Wordfence WAF) with rate-limiting and active brute-force protection.
  • Access Control: Multi-Factor Authentication (MFA) and strict Role-Based Access Control (RBAC) enforced for website management panels.

8. Data Subject Rights

Under GDPR Articles 15–22 and ISO/IEC 27701 Controls A.7.3.1–A.7.3.9, you have the right to request:

  • Access to the personal data we hold about you.
  • Rectification of inaccurate or incomplete data.
  • Erasure of your personal data when no longer necessary.
  • Restriction or Objection to specific processing activities.
  • Data Portability in a structured, machine-readable format.
  • Withdrawal of Consent at any time without affecting prior lawful processing.

To exercise any of your rights, contact our Data Protection Officer at dpo@diaplous.com. Requests are handled free of charge within 30 days .

9. Contact Information & Regulatory Complaints

Data Protection Officer (DPO)

Supervisory Authority

If you consider that our processing infringes data protection laws, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

Privacy Policy

Effective date: September 01, 2019

Diaplous group (“us”, “we”, or “our”) operates the http://www.diaplous-ms.com/ website (the “Service”).

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. Our Privacy Policy for Diaplous group is created with the help of the Free Privacy Policy Generator.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, terms used in this Privacy Policy have the same meanings as in our Terms and Conditions, accessible from http://www.diaplous-ms.com/

Information Collection And Use

We collect several different types of information for various purposes to provide and improve our Service to you.

Types of Data Collected

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally identifiable information may include, but is not limited to:

  • Email address
  • First name and last name
  • Phone number
  • Address, State, Province, ZIP/Postal code, City
  • Cookies and Usage Data

Usage Data

We may also collect information how the Service is accessed and used (“Usage Data”). This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

Tracking & Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information.

Cookies are files with small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Tracking technologies also used are beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use:

  • Session Cookies. We use Session Cookies to operate our Service.
  • Preference Cookies. We use Preference Cookies to remember your preferences and various settings.
  • Security Cookies. We use Security Cookies for security purposes.

Use of Data

Diaplous group uses the collected data for various purposes:

  • To provide and maintain the Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer care and support
  • To provide analysis or valuable information so that we can improve the Service
  • To monitor the usage of the Service
  • To detect, prevent and address technical issues

Transfer Of Data

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.

If you are located outside Greece and choose to provide information to us, please note that we transfer the data, including Personal Data, to Greece and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Diaplous group will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

Disclosure Of Data

Legal Requirements

Diaplous group may disclose your Personal Data in the good faith belief that such action is necessary to:

  • To comply with a legal obligation
  • To protect and defend the rights or property of Diaplous group
  • To prevent or investigate possible wrongdoing in connection with the Service
  • To protect the personal safety of users of the Service or the public
  • To protect against legal liability

Security Of Data

The security of your data is important to us, but remember that no method of transmission over the Internet, or method of electronic storage is 100{12a5c5575f2df2d4ce926b926bb098bd062f0bf5039515f153b5e12dd4d62161} secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Service Providers

We may employ third party companies and individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, to perform Service-related services or to assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Analytics

We may use third-party Service Providers to monitor and analyze the use of our Service.

Links To Other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third party sites or services.

Children’s Privacy

Our Service does not address anyone under the age of 18 (“Children”).

We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Children has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

Changes To This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • By visiting this page on our website: http://diaplous-ms.com/contact-us/