ΕΛ | EN

Privacy Policy — GRYPAS-AI

Version v1.1 — 25 July 2026. Data controller: 4 Interests Protection - Information and Security Consulting Services P.C. ("4IP"), service trade name: GRYPAS-AI. 196 Syngrou Ave., 176 71 Athens, Greece. VAT 801119545. GEMI 149546901000. Data protection contact: grypas@4ip.gr. No DPO has been appointed (the conditions of Article 37 GDPR are not met).

1. In plain terms

When you request a scan, for 10-20 minutes we see where your device connects — not what you say or write. We install nothing, we do not read communications, and we do not keep your raw traffic. Analysis takes place only with your express consent, which you may withdraw at any time by disconnecting the VPN.

2. What we process and why

DataPurposeLegal basis
Email, order detailsConclusion/performance of contract, invoicingArt. 6(1)(b) (contract), (c) (tax law)
Traffic metadata (destination addresses/domains, ports, timestamps, volumes — NOT content)Detection of indications of surveillance softwareExpress consent (Art. 6(1)(a), 9(2)(a))
Findings & PDF reportDeliverable of the scanAs above
Consent record (timestamp, text version, IP)Proof of lawful performanceArt. 7(1) (accountability)
Security logsProtection of infrastructureLegitimate interest (Art. 6(1)(f))

We ask for express consent because the domains a device communicates with may indirectly reveal sensitive information (e.g. health apps). Withdrawal does not affect the lawfulness of processing carried out beforehand.

3. What we do NOT do

We do not sell or share your data · We do not advertise or profile · We do not decrypt communications · We do not retain raw traffic · We do not log DNS queries · We do not send data to third parties outside the EU

4. Where your data is located

Our infrastructure is located exclusively within the EU: analysis and storage server in Germany (Contabo GmbH), notification email service in France (Scaleway). Your account, findings and reports are stored only within the EU.

5. No transfers outside the EU

None of your data leaves the European Union.

The analysis of your traffic is carried out entirely on our own systems within the EU. We do not submit queries to any third-party service regarding your device, your findings or any element of your traffic — neither to reputation services, nor to artificial intelligence services, nor to any other provider outside the EU.

6. Retention periods

DataRetention
Raw trafficNot stored
Technical analysis filesUp to 90 days (automated deletion)
Findings & report12 months or until your deletion request — whichever comes first
AccountDuration of the relationship + 12 months from last activity
Consent recordRetained after deletion (see §7)
Tax documentsAs required by tax legislation

7. Your rights

Access, rectification, erasure, restriction, portability, objection, withdrawal of consent — at grypas@4ip.gr, response within one month. Regarding erasure: we remove your account, findings, reports and files, and anonymise security traces; we retain only the record of your consent (timestamp, text version) as proof that the scan was lawfully performed (Articles 5(2), 7(1) GDPR) — it contains no findings or details of your device. Right to lodge a complaint: Hellenic Data Protection Authority, 1-3 Kifissias Ave., 115 23 Athens, dpa.gr.

8. Security — Automated analysis — Other

Encryption on all transfers (TLS/HSTS, encrypted tunnel), EU-only infrastructure, access via unique links of limited validity with immediate revocation capability, cryptographic integrity sealing of reports (SHA-256). In the event of a breach we notify the Hellenic DPA and, where required, you (Articles 33-34). Analysis is automated; the report does not constitute a decision producing legal effects under Article 22 — its use rests with you. Cookies: only a technically necessary session cookie is used for the operation of your login — no consent is required (Article 4(5) of Greek Law 3471/2006); no advertising or third-party cookies are used. Material changes are published with a date.

Terms of Service · Home