AURAConcept Group

Privacy Policy

This document describes our standard data practices. Final legal wording should be reviewed by Greek/EU legal counsel before public launch.

1. Data controller

AURA CONCEPT GROUP ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε., Kallithea, Attica, Greece, GEMI 183944301000, AFM/VAT 802850920.

2. Data we collect

Contact details (name, email, phone), event details (type, date, location, guest count, requirements), order and payment references (order number, Stripe transaction identifiers — never card numbers), technical data (IP address for security and rate limiting) and, with consent, marketing attribution data (UTM parameters, Google click identifiers).

3. Purposes and legal bases

We process data to deliver purchased services and respond to inquiries (contract), to meet legal and tax obligations (legal obligation), to secure the website (legitimate interest) and, only with your consent, for analytics and marketing measurement.

4. Payments

Payments are processed by Stripe. We receive confirmation of payment and transaction references but never your full card details. Stripe’s own privacy policy applies to their processing.

5. Retention

Order and invoice data is retained as required by Greek tax law. Inquiry data is retained for as long as needed to handle the inquiry and reasonable follow-up.

6. Sharing

Data is shared only with processors necessary for operation (payment processing, email delivery, hosting), each bound by data processing agreements. We do not sell personal data.

7. Your rights

Under GDPR you have rights of access, rectification, erasure, restriction, portability and objection, and the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).

8. Contact

For any questions regarding these terms, contact AURA CONCEPT GROUP ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε., Kallithea, Attica, Greece (GEMI 183944301000, AFM/VAT 802850920), email: [OFFICIAL COMPANY EMAIL].