Privacy Policy
Last updated: 23 June 2026
This Privacy Policy explains how InfinityTech Enterprise Solutions ("HelmBook", "we", "us", or "our") handles personal data in connection with the HelmBook website at https://helmbook.com (the "Website") and the HelmBook yacht-management software (the "Software").
We are committed to protecting your privacy and processing personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and Greek Law 4624/2019.
1. Two different contexts - please read this first
HelmBook is not a multi-tenant cloud service. It is deployed as a dedicated, separate instance for each customer. As a result, personal data is handled in two clearly distinct contexts, and the roles and responsibilities differ between them:
| Context | Who controls the data | What this policy covers |
|---|---|---|
| A. The HelmBook Website (marketing site, contact and demo requests, sales communications) | We are the data controller | Yes - Sections 3-11 |
| B. A deployed HelmBook instance (the application your organisation operates, containing your operational, financial and personnel data) | The customer that operates the instance is the data controller; we act only as a processor or support provider where engaged | Summarised in Section 2; governed by a separate Data Processing Agreement |
If you are an end user of a HelmBook application instance (for example, an employee, crew member, or accountant using the system at your organisation), your employer or the company operating that instance is responsible for your personal data, not us. Please direct privacy requests to that organisation.
2. The deployed Software (instance-per-customer model)
Each HelmBook instance is installed and operated for a single customer on infrastructure agreed with that customer. Within that instance:
- The customer is the data controller for all personal data entered into or generated by the Software (e.g. employee and crew records, counterparties, documents, financial entries).
- We do not operate a central database that aggregates customer data across instances. We do not have routine access to the contents of a customer's instance.
- Where a customer engages us for hosting, maintenance, or support that requires access to personal data, we act as a data processor on the customer's documented instructions, under a Data Processing Agreement (DPA) concluded pursuant to Article 28 GDPR. That DPA - not this Policy - governs that processing.
- Any access we are granted for support is limited, logged, and used only to the extent necessary to deliver the requested service.
The remainder of this Policy concerns context A - your use of our Website and your interactions with us as a prospect, customer contact, or partner.
3. Personal data we collect (Website & business contacts)
We collect only what we need to operate our Website and our business relationships:
a. Information you give us
- Contact and demo requests: name, company name, business email, telephone number, and the content of your message.
- Business correspondence: information you provide when you email, call, or otherwise communicate with us.
- Contractual contacts: names and business contact details of customer and supplier representatives.
b. Information collected automatically when you visit the Website
- Technical data: IP address, browser type and version, device and operating system, referring pages, and pages viewed.
- Cookies and similar technologies: see Section 9.
We do not knowingly collect special categories of personal data (Article 9 GDPR) through the Website, and we do not direct the Website to children.
4. Purposes and legal bases
We process the above personal data for the following purposes, each with a legal basis under Article 6 GDPR:
| Purpose | Legal basis |
|---|---|
| Responding to contact, demo, and sales enquiries | Steps taken at your request prior to entering a contract (Art. 6(1)(b)); our legitimate interest in responding to enquiries (Art. 6(1)(f)) |
| Managing customer, supplier, and partner relationships | Performance of a contract (Art. 6(1)(b)); legitimate interest (Art. 6(1)(f)) |
| Operating, securing, and improving the Website | Legitimate interest in a secure, functional website (Art. 6(1)(f)) |
| Sending service or business communications you have requested | Consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)) |
| Complying with legal, accounting, and tax obligations | Legal obligation (Art. 6(1)(c)) |
| Establishing, exercising, or defending legal claims | Legitimate interest (Art. 6(1)(f)) |
Where we rely on consent, you may withdraw it at any time (Section 8); this does not affect the lawfulness of processing before withdrawal.
5. How we share personal data
We do not sell personal data. We may share it with:
- Service providers (processors) who support our Website and business, e.g. website hosting, email, and analytics providers, under contracts that require them to process data only on our instructions and to protect it.
- Professional advisers such as accountants and lawyers, where necessary.
- Public authorities where required by law.
- Successors in the event of a merger, acquisition, or reorganisation, subject to this Policy.
A current list of the key processors we use for the Website is available on request at [email protected].
6. International transfers
We aim to keep personal data within the European Economic Area (EEA). Where a processor is located outside the EEA, we ensure an appropriate safeguard under Chapter V GDPR is in place - typically the European Commission's Standard Contractual Clauses - or that the country benefits from an adequacy decision. You may request a copy of the relevant safeguard at [email protected].
7. Retention
We keep personal data only as long as necessary for the purposes set out above:
- Enquiry and demo-request data: for the duration of our discussions and up to 24 months afterwards, unless a business relationship begins.
- Customer and supplier relationship data: for the duration of the relationship and as required to meet legal, accounting, and tax obligations (generally up to the limitation periods applicable under Greek law).
- Website technical logs: typically up to 12 months.
When personal data is no longer needed, we delete or anonymise it.
8. Your rights
Subject to the conditions in the GDPR, you have the right to:
- Access your personal data and obtain a copy.
- Rectify inaccurate or incomplete data.
- Erasure ("right to be forgotten").
- Restrict processing in certain circumstances.
- Data portability for data you provided, where applicable.
- Object to processing based on legitimate interests, including direct marketing.
- Withdraw consent at any time where processing is based on consent.
To exercise any right, contact us at [email protected]. We will respond within one month, as required by Article 12 GDPR. We may need to verify your identity first.
You also have the right to lodge a complaint with the Greek supervisory authority:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias Ave. 1-3, 115 23 Athens, Greece
Tel: +30 210 6475600 - Web: www.dpa.gr
Note: If your request concerns data held inside a deployed HelmBook instance, please contact the organisation that operates that instance (see Section 1), as they are the controller for that data.
9. Cookies
The Website uses cookies and similar technologies. We distinguish:
- Strictly necessary cookies, required for the Website to function. These do not require consent.
- Analytics and preference cookies, which we set only with your consent via the cookie banner.
You can manage or withdraw consent at any time through the cookie settings on the Website and through your browser settings. A detailed cookie list is available in our [Cookie Notice / cookie banner].
10. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or alteration, including encrypted transport (HTTPS), access controls, and logging. For deployed instances, security responsibilities are allocated between the customer and us in the applicable agreement and DPA.
11. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date above reflects the latest version. Material changes will be communicated through the Website or by direct notice where appropriate.
12. Contact us
Data controller: InfinityTech Enterprise Solutions
Registered address: Char. Trikoupi 6, Pireas 185 36, Greece
Phone: 210 444 68 93
Company registration (Γ.Ε.ΜΗ.) / VAT (ΑΦΜ): 175068807000 / 802364677
Email: [email protected]
Data Protection contact: [email protected]
If you have any questions about this Privacy Policy or our handling of your personal data, please contact us using the details above.