PRIVACY POLICY – PROTECTION OF PERSONAL DATA
Version 06.08.2026
PRIVACY POLICY – PROTECTION OF PERSONAL DATA
A. Introduction
This Privacy Policy – Protection of Personal Data is intended to inform users regarding the processing of their personal data by the company under the corporate name "BENEFIT BRIDGE SINGLE-MEMBER PRIVATE COMPANY", having its registered office at 218 D. Gounari Street, Glyfada, Attica, Greece, Tax Identification Number (TIN): 803023291, Tax Office: KEFODE Attica, duly represented for the purposes hereof (hereinafter referred to as the "Company"), which acts as the Data Controller of such personal data.
The Company manages the protection of its users' personal data with the utmost seriousness and diligence, in full compliance with the applicable European and Greek legislation.
The Company reserves the right to amend the terms of this Privacy Policy in accordance with the applicable legislative framework from time to time. Accordingly, these terms may be modified and updated at any time without prior notice. Users of the Company's website and mobile application (application) (hereinafter collectively referred to as the "Website") are therefore advised to review this Privacy Policy regularly for any amendments.
B. What Are Personal Data
Personal Data means any information relating to an identified or identifiable natural person ("data subject").
An identifiable natural person is one whose identity can be established, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person (hereinafter referred to as "Personal Data" or "Data").
C. Collection and Processing of Personal Data – Purpose of Processing – Legal Basis for Processing
The Company collects and processes the personal data of its users, which are either:
- provided directly by the user by completing the relevant contact form;
- provided by sending an e-mail to the Company;
- provided through the user's registration (creation of a user account) and login to the Company's Website; or
- collected through the use of the services provided by the Company (e.g. IP address).
Such data are limited to those that are absolutely necessary and appropriate for the relevant purpose and may include the following (depending on the relationship, cooperation or transaction between the Company and the respective user):
- Full name;
- User's e-mail address;
- Mobile telephone number;
- Whether the individual is the Ultimate Beneficial Owner (UBO) of the account*;
- Politically Exposed Person (PEP) status and PEP position or role*;
- Residential address (country, street address, city and postal code);
- Tax information (country or countries of tax residence and tax identification number(s))*;
- Connection with Lithuania (for non-Lithuanian citizens)*;
- Purpose of the account*;
- Source of income*;
- Monthly gross turnover*;
- Personal data collected for the purpose of ensuring Strong Customer Authentication (SCA) *;
- Any other information voluntarily provided by the user through the contact form (e.g. curriculum vitae submitted for recruitment purposes) or by e-mail;
- Identity document details (date of issue, expiry date, identification number, issuing country and document type)*;
- Date of birth;
- Personal identification number, where applicable*;
- Photograph of the identity document (front, back, etc.)*;
- Remote identification data (facial photograph, selfie, video, etc.)*;
- IBAN and other payment details*;
- Data relating to complaints (name, contact details, content and circumstances of the complaint);
- Technical data relating to the user's device and internet connection (such as IP address, etc.) or information relating to the user's browsing activity on the Website (e.g. cookie preferences).
* Only where you are a holder of a BB Card.
The processing of the above data is carried out on the basis of the data subject's consent, and/or for the performance of our contractual services, and/or for the purposes of our legitimate interests (in a manner that is reasonably expected as part of the operation of our business and which does not materially affect the data subject's rights, freedoms or interests), and/or for compliance with our legal obligations.
Processing covers a wide range of operations which may be performed on personal data by automated or non-automated means. Such operations include the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction of personal data.
The General Data Protection Regulation (GDPR) applies to the processing of personal data wholly or partly by automated means, as well as to processing by non-automated means where such processing forms part of a filing system or is intended to form part of a filing system.
D. Security of Personal Data
The Company is committed to safeguarding the personal data of its users and, to this end, implements appropriate technical and organisational security measures for the protection of users' personal data.
The Company does not disclose, transfer, sell or otherwise make available users' or visitors' personal data to third parties for commercial purposes, nor does it publish such personal data, except where required by applicable law and only to the competent authorities and/or where necessary for the establishment, exercise or defence of the Company's legitimate rights and interests.
The Company also implements all appropriate organisational and technical measures to ensure the security of personal data and to protect them against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, and any other form of unlawful processing.
By way of example, the measures implemented by the Company include preventive security procedures, technical and physical access control mechanisms, access rights management procedures, while the Website also uses encryption protocols and technical security measures during the collection or transmission of information through the contact form.
Furthermore, the credentials used to authenticate the user's account consist of the Username and the Password, which constitute the user's personal access credentials. Whenever the user correctly enters these credentials, secure access to the user's personal account is granted.
The authentication process is carried out using appropriate technical and organisational security measures, including encryption of data during transmission over the internet (encryption in transit) to and from the Company's servers, as well as their secure storage within the Company's information systems.
Furthermore, users are provided with the ability to change their Password at any time through the relevant functionality of the platform.
Following its submission, the new password undergoes a secure hashing process and is stored in a manner that does not permit its retrieval in a readable form.
For security reasons, the Company does not have access to the user's complete password and is therefore unable to disclose or recover it. Consequently, the user is solely responsible for maintaining the confidentiality of his/her credentials and shall take all necessary measures to prevent unauthorised access, including, in particular, refraining from disclosing the password to third parties and changing it on a regular basis.
Should the user become aware of or suspect any unauthorised use of his/her account or compromise of his/her credentials, the user shall immediately notify the Company and promptly change his/her password.
E. Special Categories of Personal Data (where applicable)
The Company may process special categories of personal data, as defined in Article 9(1) of the GDPR, where such data are contained in documents which ConnectPay (see Section I below) submits, uploads or otherwise makes available to the Company.
When processing special categories of personal data, the Company undertakes to:
- implement appropriate technical and organisational measures to ensure the security and confidentiality of such data, including encryption and access controls;
- ensure that the processing is limited to what is strictly necessary for the provision of the Services;
- prevent unauthorised access to, disclosure of or processing of special categories of personal data through appropriate security mechanisms proportionate to the nature of the data; and
- implement additional safeguards or compliance measures where it determines that such measures are required.
F. Recipients
Personal Data are processed, in accordance with the principle of necessity, by the Company's duly authorised personnel, who are contractually bound to maintain confidentiality and protect personal data, as well as by our third-party partners referred to below (see Section I), who are likewise contractually bound to maintain confidentiality and protect personal data, in compliance with the applicable legal framework and by implementing all necessary technical and organisational security measures.
G. Data Retention
The Company shall store and retain users' Personal Data for a minimum period of eight (8) years, or for such longer period as may be necessary for the provision of services to the users, the fulfilment of our legal obligations and the establishment, exercise or defence of our legal rights.
H. Users' Rights
Users of the Website may contact the Company (e-mail address: info@benefitbridge.gr) in order to:
- request access to their Personal Data;
- request the rectification of their Personal Data;
- request the erasure of their Personal Data;
- request the portability of their Personal Data;
- request the restriction of the processing of their Personal Data; and
- object to the processing of their Personal Data or withdraw any consent previously granted.
Any user acting as a data subject may exercise the above rights at any time by contacting the Company using the contact details set out below (see Section IA).
Furthermore, every data subject has the right to lodge a written complaint with the competent supervisory authority regarding the protection of his or her Personal Data, namely the Hellenic Data Protection Authority (HDPA) (1-3 Kifisias Avenue, GR-115 23 Athens, Greece, Tel.: +30 210 6475600, e-mail: contact@dpa.gr).
I. Transfer of Data to Third Countries
Users' Personal Data are stored on servers located within the European Union.
However, for the provision of certain services, the Company may engage cooperating service providers (processors) established in the United States of America.
In order to ensure that Personal Data transferred to third countries benefit from a level of protection that is essentially equivalent to that guaranteed under European Union law, the following appropriate safeguards are implemented, where applicable:
- EU–U.S. Data Privacy Framework (DPF): For service providers established in the United States that have been certified under the above framework, the transfer is based on the European Commission's Adequacy Decision of 10 July 2023.
- Standard Contractual Clauses (SCCs): For service providers that are not certified under the above framework, the Standard Contractual Clauses approved by the European Commission are used, contractually requiring the recipient to ensure a level of protection consistent with Regulation (EU) 2016/679 (GDPR).
- Supplementary Measures: Where required, a Transfer Impact Assessment (TIA) is carried out and additional technical and organisational measures (such as, indicatively, encryption) are implemented in order to enhance the security and confidentiality of Personal Data.
In any transfer of Personal Data to third countries, including the United States of America, every reasonable effort is made to ensure that such data benefit from an adequate level of protection in accordance with the applicable provisions of European Union law, Greek law and this Privacy Policy.
I. List of Partners – Sub-processors
The Company cooperates with the following entities for the provision of its services:
1. ConnectPay
ConnectPay UAB, registration No. 304696889, having its registered office at 38 Algirdo Street, Vilnius, Lithuania, is an Electronic Money Institution (EMI) licensed by the Bank of Lithuania (BoL), which has notified its intention to provide services in Greece.
The Company has entered into a distribution agreement with ConnectPay, pursuant to which the Company provides ConnectPay's services in Greece in its capacity as an authorised distributor, as notified to the Bank of Greece.
The Company also cooperates with Wallester AS, registration No. 11812882, having its registered office at F.R. Kreutzwaldi 4, 10120 Tallinn, Estonia, a company incorporated under the laws of Estonia, with which both ConnectPay and the Company have concluded agreements for the issuance of BB Cards bearing the VISA trademark.
2. Sub-processors
The Company also cooperates with the sub-processors listed in the table below, who process Personal Data on the Company's behalf in accordance with the applicable legal framework and the relevant contractual arrangements.
# | Vendor | Legal entity | EU entity / representative | Registration no. | Registered / HQ address | Data-centre / EU region | Contact | Service to BenefitBridge | Data processed |
1 | Supabase | Supabase, Inc. (Delaware) | Supabase Pte. Ltd. (Singapore — ToS counterparty) | DE file no. 7816270 [moderate confidence] | 548 Market St, San Francisco, CA 94104, USA [mailbox] | EU: Frankfurt (AWS eu-central-1) [confirm project region] | privacy@supabase.com | Managed PostgreSQL + Auth + RLS + backups; primary datastore | All platform PII: names, emails, phones, IBANs, identity refs, transactions, balances, cards |
2 | Grandhosting Ltd | Grandhosting Ltd (Cyprus) | — (EU entity itself) | HE 488909; VAT CY60338088T | Lordou Vyronos 36, 1096 Nicosia, Cyprus | EU — servers in Germany (ISO 27001 EU DCs) | support@grandhosting.gr | K8s hosting — runs the API (ConnectPay, EWA processor, webhooks, crons); ALSO hosts the public WordPress/Elementor marketing site (benefit-bridge.gr). Dashboard app.benefit-bridge.gr is on Vercel, not here. | All platform data at rest + in transit, incl. PII, payment payloads, ConnectPay req/resp |
3 | Vercel | Vercel Inc. (Delaware) | — | DE file no. NOT PUBLIC (5857312 unverified) | 440 N Barranca Ave #4133, Covina, CA 91723, USA | EU function region: Frankfurt (fra1) — CONFIRMED via response header | privacy@vercel.com | Hosting for the employer DASHBOARD (app.benefit-bridge.gr). NOT the marketing site (that is WordPress on Grandhosting); the Next.js website repo on Vercel is not live. | Web request logs, session tokens, form inputs (company + employee PII) |
4 | Cloudflare R2 | Cloudflare, Inc. (Delaware; NYSE: NET) | — | DE file no. 4710875 (GLEIF); SEC CIK 0001477333 | 101 Townsend St, San Francisco, CA 94107, USA | EU jurisdiction via Data Localization Suite [verify] | privacyquestions@cloudflare.com / dpo@cloudflare.com | Object storage (R2) — log archive (PII-redacted) | PII-redacted logs (request/audit metadata) |
5 | Better Stack | Better Stack, Inc. (Delaware) | Operational base: Prague, Czech Republic | Czech IČO 7053550 (US entity, foreign-registered); DE file no. NOT PUBLIC | Reg. agent: 651 N Broad St, Ste 206, Middletown, DE 19709, USA [Prague office unconfirmed] | Primarily EU (subprocessors: Google IE, Hetzner DE) + US | hello@betterstack.com | Log aggregation, uptime monitoring, on-call alerting | PII-redacted structured logs + uptime metadata |
6 | iDenfy | UAB "iDenfy" (Lithuania) | — (EU entity itself) | Reg. code 304617621; VAT LT100011161819 | Gričiupio g. 7-212, LT-51372 Kaunas, Lithuania | EU — AWS Europe (Dublin) | dpo@idenfy.com | Identity verification (KYC/IDV) for ConnectPay onboarding | SPECIAL CATEGORY (Art.9): biometric facial data; ID docs, name, DOB, nationality, doc numbers |
7 | GatewayAPI | ONLINECITY.IO ApS (Denmark) | — (EU entity itself) | CVR 27364276 | Buchwaldsgade 50, 5000 Odense C, Denmark | EU region in use (GatewayAPI.eu / EU setup; core DB Google Belgium) | (via dashboard / privacy@gatewayapi.com) [verify] | SMS / OTP delivery — SCA possession factor | Mobile phone numbers, OTP codes |
8 | Resend | Plus Five Five, Inc. (d/b/a Resend) | — | Delaware (file no. NOT PUBLIC); CA foreign #5428684, WA #605084474 | 2261 Market St #5039, San Francisco, CA 94114, USA | Email region: Ireland (eu-west-1) — mail.benefit-bridge.gr verified | support@resend.com | Transactional email (auth, onboarding, receipts, alerts) | Email addresses, recipient names, email content (status/transaction refs) |
9 | Sentry | Functional Software, Inc. (d/b/a Sentry) | Sentry Software Netherlands B.V. (Amsterdam) | DE file no. 5214647 + CA C3808470 (both confirmed via GLEIF) | 45 Fremont St, 8th Floor, San Francisco, CA 94105, USA | EU region: Frankfurt, Germany (all plans) | compliance@sentry.io | Error/crash monitoring + 10% tracing (api/web/mobile) | PII-scrubbed error events + stack traces |
10 | Novus | Novus Conceptus Ο.Ε. (Greek O.E.) | — (EU entity itself) | ΓΕΜΗ 154255449000; ΑΦΜ NOT PUBLIC (behind authenticated ΓΕΜΗ portal) | Σπύρου Λειβαδά 43, Πάργα 48060, Greece | Greece (EU) | info@timologisi.online / info@novusconceptus.com | Greek e-invoicing (myDATA → AADE) via provider.timologisi.online; AADE cert 2020_11_105 | Company/employer name, AFM/VAT, invoice amounts, service descriptions |
11 | Discord | Discord Inc. (Delaware) | Discord Netherlands B.V. (KvK 82229864) | DE file no. 5128862 | 444 De Haro St, Ste 200, San Francisco, CA 94107, USA / EU: Schiphol Blvd 195, Schiphol, NL | US | privacy@discord.com / dpo@discord.com | Internal ops/incident/fraud alerting via webhook (no customer PII) | Alert metadata only — NO customer PII (enforced) |
12 | Docker Hub | Docker, Inc. (Delaware; LEI 2549000RVI3MXKU6VF93) | Docker Germany GmbH (EU rep) | DE file no. 4817464 (GLEIF) | 3790 El Camino Real #1052, Palo Alto, CA 94306, USA | US [region not disclosed] | privacy@docker.com | Container image registry (API images) | Container images only — no personal data |
13 | GitHub | GitHub, Inc. (Microsoft subsidiary) | GitHub B.V. (Amsterdam) | DE file no. 5157550 (GLEIF); CA C3268102 | 88 Colin P. Kelly Jr St, San Francisco, CA 94107, USA / EU: Prins Bernhardplein 200, 1097 JB Amsterdam, NL | US default; EU residency on Enterprise Cloud (Azure) | privacy@github.com / dpo@github.com | Source control + CI/CD | Application source code — no customer personal data |
14 | Termly | Termly Inc. (Delaware) | — | Delaware (file no. NOT PUBLIC); reg. agent Dover, DE | 906 W 2nd Ave, Ste 100, Spokane, WA 99201, USA (reg. agent: Dover, DE) | US default; EU DC option on request | privacy@termly.io | Cookie-consent management + policy publication (marketing site) | Consent signals, visitor identifiers |
15 | Expo (EAS) | 650 Industries, Inc. (California) | — | CA file no. C3618919 | 624 University Ave, FL1, Palo Alto, CA 94301, USA | US only | privacy via form expo.dev/contact (no email) | Mobile build (EAS) + OTA updates + Expo Push Service (push transport; iOS via APNs) | Expo push tokens; push payloads; build artifacts (no PII) |
16 | Apple | Apple Inc. (California) | Apple Distribution International Ltd. (Cork, Ireland; CRO 470672) | CRO 470672; LEI 54930027SQL2KPSDBM58 | One Apple Park Way, Cupertino, CA 95014, USA / EU: Hollyhill Industrial Estate, Cork T23 YK84, Ireland | EU App Store via Apple Distribution Intl; APNs global | (Developer Program account) | App Store distribution; APNs (iOS push, via Expo); signing + Universal Links (Team ID 5JV2Y3BA99) | Device push tokens; push payloads (PII-minimised) |
17 | Google (Play / FCM) — FUTURE | Google LLC (California; Alphabet) | Google Ireland Limited (Dublin; CRO 368047) | CRO 368047; LEI YYPPRNO5HB304LHFVG31 | 1600 Amphitheatre Pkwy, Mountain View, CA 94043, USA / EU: Gordon House, Barrow St, Dublin 4, D04 E5W5, Ireland | Play/contracting EU via Google Ireland; FCM global | (Play Console / Firebase account) | Google Play distribution + FCM push — NOT YET ACTIVE (Android launch deferred; no Firebase project. Becomes the Android push transport via Expo if enabled). | Device push tokens; push payloads (PII-minimised) — once Android push enabled |
18 | Bunny CDN | BUNNYWAY, informacijske storitve d.o.o. (Bunny.net) | — (EU entity itself) | Matična 7297513000; VAT SI99251558 | Dunajska cesta 165, 1000 Ljubljana, Slovenia | Global edge; api.benefit-bridge.gr via German (DE1) edge | info@bunny.net | CDN + WAF/reverse-proxy in front of api.benefit-bridge.gr — ALL inbound API traffic (clients + ConnectPay webhooks) transits the edge | In transit: source IPs, request headers/paths, request/response bodies (PII, payment + ConnectPay webhook payloads); edge cache |
19 | Qboxmail | Qboxmail Srl | — (EU entity itself) | REA PO 525585; CF/P.IVA 02338120971 | Via Pollative 111/O, 59100 Prato (PO), Italy | EU (Italy) [verify mail storage region] | privacy@qboxmail.it / dpo@qboxmail.it | Hosted email provider — BB corporate mailboxes + SMTP relay for the WordPress contact form (distinct from Resend = API transactional email) | Email content + addresses; contact-form submissions (name/email/message); inbound customer/employee correspondence |
IA. Contact
For any questions regarding this Privacy Policy, the collection and processing of your Personal Data, our sub-processors or any related matter, you may contact the Company using the following contact details:
By e-mail: info@benefitbridge.gr
By telephone: +30 210 7177777
By post:
BENEFIT BRIDGE SINGLE-MEMBER PRIVATE COMPANY
218 D. Gounari Street
GR-16674 Glyfada
Greece
Last updated: May 2026