LEGAL

Privacy & Cookies Policy

This Privacy & Cookies Policy explains how the Law Office of Nikolaos S. Zindros ("Zindros & Associates", "we", "us", "our") collects, uses, discloses, and protects personal data when you visit zindroslawfirm.com (the "Website"), contact us through it, or otherwise engage us for legal services.

It is written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), the Greek Data Protection Act (Law 4624/2019), the Greek ePrivacy rules on cookies (Law 3471/2006, as amended by Law 4070/2012, implementing Directive 2002/58/EC), and the professional confidentiality obligations of the Greek Code of Lawyers (Law 4194/2013).

1. Who We Are — Data Controller

The data controller responsible for your personal data is:

 

Controller Nikolaos S. Zindros, Attorney at Law, trading as Zindros & Associates
Address Promitheos 3, 54627, Thessaloniki, Greece
Bar registration Member of the Thessaloniki Bar Association (Δικηγορικός Σύλλογος Θεσσαλονίκης), registration no. [insert]
Phone +30 2310 508 547
Email info@zindroslawfirm.com

As a sole practice of this size, the Firm is not required under Article 37 GDPR to appoint a Data Protection Officer, as our core activities do not involve large-scale or systematic monitoring of individuals, nor large-scale processing of special categories of data. Nikolaos S. Zindros acts as the privacy contact point for all matters covered by this Policy — see Section 16.

2. Scope of This Policy

This Policy covers personal data processed through your use of the Website — browsing, the contact/consultation form, and any cookies or similar technologies. It also summarizes, at a high level, how we handle personal data once a client engagement begins.

Attorney-client relationship data

Where you become a client, the detailed handling of your case file is additionally governed by the engagement letter you sign with the Firm and by the confidentiality and professional secrecy obligations that bind every Greek lawyer under the Code of Lawyers (Law 4194/2013) and the Lawyers' Code of Conduct. Those obligations are, in most respects, stricter than this Policy and take precedence for matters they specifically cover.

Correspondence and case documents exchanged with opposing counsel, courts, notaries, or public registries in the course of representing you are handled under separate, matter-specific confidentiality rules and are outside the scope of this Website-facing Policy.

3. Data We Collect

3.1 Data you provide directly

  • Contact/consultation form (contact-us.html): full name, phone number, email address, the subject/matter you select, and any free-text message you write.
  • Direct correspondence: any personal data you include when you call, email, or write to us — for example when describing your legal matter.

3.2 Data collected automatically

  • Technical/log data: IP address, browser type and version, device/operating system, referring page, pages visited, and timestamps, collected via standard web server logs and, where enabled, cookies (see Cookies Policy).
  • Approximate location inferred from your IP address (country/city level only) — not precise geolocation.

3.3 Data from embedded third-party content

  • Google Fonts: the Website currently loads typefaces from Google's font CDN (fonts.googleapis.com / fonts.gstatic.com). Loading a font this way sends your IP address to Google before you have taken any action or given consent, purely to serve a font file. See the technical recommendation below.
  • Google Maps: the Contact page embeds a Google Maps iframe showing our office location. Once that iframe loads, Google may set cookies and collect data (including your IP address) under Google's own privacy terms, independent of this Policy.

4. Sensitive Data & Criminal-Offence Data

Because the Firm practices criminal law, international criminal law, immigration law, and related fields, messages you send us — through the contact form or otherwise — may reveal special categories of personal data under Article 9 GDPR (e.g. health, ethnic origin, religious belief) and/or data relating to criminal convictions and offences under Article 10 GDPR.

We process such data only where it is necessary for the establishment, exercise, or defense of legal claims, or for us to assess and provide legal advice at your request, in line with Article 9(2)(f) GDPR and the safeguards for criminal-offence data set out in Article 11 of Law 4624/2019. We do not use this data for any other purpose, and we apply additional access restrictions to it internally, on top of our standard professional secrecy obligations as lawyers.

Please avoid including sensitive details you are not comfortable sharing before an attorney-client relationship and formal engagement letter are in place; the initial enquiry form is not a secure channel for highly sensitive documents.

5. Why We Use Your Data & Legal Basis

Purpose Legal basis (Art. 6 GDPR)
Responding to your enquiry / assessing whether we can assist Art. 6(1)(b) — steps taken at your request prior to a contract for legal services
Providing legal services to engaged clients Art. 6(1)(b) contract, and Art. 6(1)(c) legal obligation (Bar/tax record-keeping)
Client due-diligence / identity checks (see Section 6) Art. 6(1)(c) — legal obligation under Greek AML law
Operating and securing the Website Art. 6(1)(f) — legitimate interest in a functioning, secure website
Non-essential cookies — if/when enabled Art. 6(1)(a) — your consent via the cookie banner
Compliance with legal obligations, defending legal claims Art. 6(1)(c) and Art. 6(1)(f)

Where we rely on consent (for example, non-essential cookies, or the consent checkbox on the contact form), you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.

6. Anti-Money-Laundering (AML) Checks

Under Greek Law 4557/2018 (implementing EU Anti-Money-Laundering Directives), lawyers are "obliged entities" and must carry out customer due diligence for certain categories of work — notably real estate transactions, company formation or restructuring, and management of client assets or bank/securities accounts. Where your matter falls into one of these categories, we are legally required to verify your identity, retain copies of identification documents, and, where applicable, identify beneficial owners, and to retain those records for five years from the end of the business relationship, even if you ask us to delete them sooner.

7. Who We Share Data With

We do not sell personal data. We share it only where necessary, with:

  • Service providers acting on our instructions (data processors): website hosting provider [insert provider/country], email provider [insert, e.g. Google Workspace], and IT/website maintenance contractors — each bound by a data processing agreement under Art. 28 GDPR.
  • Professional advisers: our external accountant/bookkeeper [insert name] for invoicing and statutory tax records.
  • Third parties necessary to conduct your legal matter: courts, opposing counsel, notaries public, land registries and cadastral offices, government authorities, expert witnesses, and correspondent/co-counsel law firms in our international network — only as required for your specific matter and, where relevant, on your instructions.
  • Independent third-party services embedded in the Website: Google (Fonts, Maps, and Analytics if enabled) and, if enabled, Meta Platforms (Facebook/Instagram Pixel) — each acts as an independent controller for the data it collects; see their own privacy policies (Google, Meta).
  • Authorities, where disclosure is required by law, court order, or to protect the Firm's or a client's legal rights.

8. International Data Transfers

Some of the third parties above (notably Google and, if enabled, Meta) may process data on servers located outside the European Economic Area, including in the United States. Where this occurs, the transfer is safeguarded either by the recipient's certification under the EU-U.S. Data Privacy Framework or by the European Commission's Standard Contractual Clauses, as applicable. You can request more detail on the specific safeguard used by contacting us (Section 16).

9. How Long We Keep Data

Data Retention period
Website enquiries that do not lead to an engagement 12 months from last contact, then deleted or anonymized
Client case files Per Thessaloniki Bar Association rules and the applicable statute of limitations (confirm exact minimum with the Bar Association; general civil claims in Greece typically run 5–20 years depending on the claim)
AML / client due-diligence records 5 years from the end of the business relationship (Law 4557/2018)
Accounting and tax records Per the Greek Tax Procedure Code — generally 5 years, confirm current period with our accountant
Cookie consent records Up to 12 months, or until you change your preference
Analytics cookies (if enabled) Per the specific cookie — see Cookies table

10. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you (Art. 15);
  • Rectify inaccurate or incomplete data (Art. 16);
  • Erasure ("right to be forgotten"), where applicable — this may be limited where we must retain client files or AML records under legal obligation (Art. 17);
  • Restrict processing in certain circumstances (Art. 18);
  • Data portability for data you provided, processed by automated means under contract or consent (Art. 20);
  • Object to processing based on legitimate interest, including profiling, and to direct marketing at any time (Art. 21);
  • Withdraw consent at any time, without affecting prior lawful processing (Art. 7(3));
  • Lodge a complaint with a supervisory authority — see Section 16.

To exercise any of these rights, contact us using the details in Section 16. We may need to verify your identity before actioning a request. We will respond within one month of a valid request, extendable by a further two months for complex requests, in which case we will explain the delay.

11. Security

We apply technical and organizational measures appropriate to the sensitivity of the data we hold, including HTTPS/TLS encryption of the Website, access controls limiting who within the Firm can view enquiry and case data, and confidentiality obligations that bind all Firm personnel under the Code of Lawyers. No system is completely secure, and we cannot guarantee absolute security of data transmitted to us over the internet.

12. Children's Data

The Website is not directed at children. Under Greek law implementing Article 8 GDPR, the age of consent for information-society services is 15; we do not knowingly collect personal data from anyone below that age without the consent of a parent or legal guardian. Where legal representation concerns a minor, all communication and instructions must come from, or be authorized by, the minor's parent or legal guardian in accordance with the Greek Civil Code.

13. Automated Decision-Making

We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects on you.

14. Cookies Policy

Cookies are small text files placed on your device when you visit a website, used to make the site function, remember preferences, or gather usage statistics. In line with the ePrivacy rules transposed into Greek law (Law 3471/2006, Art. 4 §5, as amended), we do not set any cookie that is not strictly necessary until you have given consent through the cookie banner shown on your first visit.

On your first visit, a cookie banner asks you to Accept All, Reject Non-Essential, or Customize your preferences by category. Non-essential cookies and the Google Maps embed are blocked from loading until you consent. You can change your choice at any time via the "Cookie Settings" link in the site footer, which reopens the preference panel.

Separately from our consent tool, you can block or delete cookies through your browser settings (Chrome, Firefox, Safari, Edge all provide this under Privacy/Security settings). Blocking all cookies, including strictly necessary ones, may affect how parts of the Website function, though the informational content of the site remains accessible either way.

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices, the services we offer, or legal requirements. The "Last updated" date at the top of this page shows when it was last revised. Material changes — for example, enabling a new analytics or advertising tool — will be reflected here and, where appropriate, flagged on the Website.

16. Contact & Complaints

For any question about this Policy or to exercise your rights, contact us:

Nikolaos S. Zindros, Law Office
Promitheos 3, 54627, Thessaloniki, Greece
Email: info@zindroslawfirm.com
Phone: +30 2310 508 547

If you believe we have not addressed your concern adequately, you have the right to lodge a complaint with the Greek supervisory authority:

Authority Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Address Kifisias 1-3, 115 23 Athens, Greece
Phone +30 210 6475600
Website www.dpa.gr

If you are habitually resident, or the alleged infringement occurred, in another EU/EEA member state, you may instead complain to that state's supervisory authority (Art. 77 GDPR).