Privacy Policy
Last updated: June 2025
Your privacy matters to us. This policy explains what personal data GoalCodex collects, why we collect it, how we use and protect it, and what rights you have regarding your data. We are committed to handling your information responsibly and in compliance with the General Data Protection Regulation (GDPR) and applicable Greek and EU data protection law.
Data Controller: GoalCodex is a service operated by ABCODE E.E., registered in Greece. For any data-related questions, contact us at info@goalcodex.com.
1. What Data We Collect
We collect only the minimum data necessary to provide the service:
- Account data: When you register, we collect your name, username, and email address.
- Password: Stored as a one-way bcrypt hash — we cannot read your password.
- Subscription data: If you subscribe, we store your plan type, subscription status, and start/end dates. Payment processing is handled entirely by Viva Wallet — we do not store card numbers or payment details.
- Usage data: Pages visited, filters applied, features used, and session timestamps. This data is used to improve the platform and is not tied to advertising profiles.
- Technical data: Your IP address (for rate limiting and security), browser type, and device type collected automatically via server logs.
- Communications: If you contact us via the contact form, we store your name, email, and message content to respond to your enquiry.
2. Legal Basis for Processing
We process your personal data on the following legal bases under GDPR Article 6:
- Contract (Art. 6(1)(b)): Processing necessary to provide the GoalCodex service you have signed up for, including account management and subscription handling.
- Legitimate interests (Art. 6(1)(f)): Security logging, rate limiting, fraud prevention, and aggregate usage analytics to improve the platform.
- Legal obligation (Art. 6(1)(c)): Retention of financial records as required by Greek and EU tax law.
- Consent (Art. 6(1)(a)): Where we request your consent for optional communications. You may withdraw consent at any time.
3. How We Use Your Data
- To create and manage your GoalCodex account
- To process and manage your subscription via Viva Wallet
- To send transactional emails (email verification, password reset, subscription confirmations)
- To respond to support enquiries submitted via the contact form
- To detect and prevent abuse, fraud, and unauthorised access
- To improve platform features based on aggregate, anonymised usage patterns
We will never sell, rent, or share your personal data with third parties for marketing or advertising purposes.
4. Third-Party Services
We use a limited number of third-party services to operate the platform:
- Viva Wallet — payment processing for subscriptions. Your payment details are entered directly on Viva's PCI DSS-compliant systems. We receive only confirmation of successful payment and a subscription identifier.
- Zoho Mail — transactional email delivery (verification emails, password resets, receipts). Email addresses are transmitted to Zoho solely for the purpose of sending these messages.
- Google Analytics — aggregate, anonymised website traffic analytics. IP addresses are anonymised before transmission. You can opt out via the Google Analytics opt-out browser add-on.
- DigitalOcean — our hosting provider. Servers are located in the European Union (Amsterdam). DigitalOcean processes server logs as a data processor acting on our behalf.
5. Cookies
GoalCodex uses the following types of cookies:
- Session cookies (strictly necessary): Used to keep you logged in during a visit. These are deleted when you close your browser and cannot be disabled without breaking the login functionality.
- Preference cookies: Used to remember your settings (e.g., filter choices, display preferences) between visits.
- Analytics cookies: Set by Google Analytics to measure aggregate traffic. These do not identify you personally.
We do not use advertising or tracking cookies. We do not build behavioural advertising profiles.
6. Data Retention
- Account data: Retained for as long as your account is active. If you delete your account, personal data is removed within 30 days, except where retention is required by law.
- Financial records: Subscription and payment records are retained for 10 years as required by Greek tax law.
- Server logs: IP-level access logs are retained for up to 90 days for security purposes, then deleted.
- Contact form messages: Retained for up to 12 months, then deleted unless ongoing correspondence requires longer retention.
7. Your Rights Under GDPR
As a data subject in the EU/EEA, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Right to restriction: Request that we limit how we use your data while a dispute is resolved.
- Right to data portability: Receive your personal data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests.
- Right to withdraw consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
To exercise any of these rights, contact us at info@goalcodex.com. We will respond within 30 days. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA) at www.dpa.gr.
8. Data Security
All data is transmitted over HTTPS (TLS). Passwords are hashed using bcrypt and are never stored in plain text. Access to the production database is restricted to authorised personnel via SSH key authentication. We apply the principle of least privilege: each part of the system accesses only the data it needs. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the HDPA within 72 hours as required by GDPR Article 33.
9. Children's Privacy
GoalCodex is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has registered without parental consent, please contact us and we will delete the account promptly.
10. Changes to This Policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify registered users by email. Continued use of GoalCodex after a policy update constitutes acceptance of the revised terms.
11. Contact
For any privacy-related questions or to exercise your data rights, contact us at info@goalcodex.com or use the contact form. We aim to respond to all requests within 5 business days.