PRIVACY POLICY & NOTICE

(Updated: May 2026)

INCOM Ltd. with address at: 9A Tinou, Nea Ionia, 142 35, Athens, Greece, phone no. (0030) 210 865 3046, email: info@incomconsulting.gr (hereinafter referred to as “the Company”), addresses with respect and as primary concern issues of personal data and privacy. In this context, we are addressing you this Notice in accordance with Article 13 of Regulation (EU) 2016/679 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as “GDPR”) to inform you about how we collect and process your personal data when visiting our website (www.incomconsulting.gr) or when participating in our research, development, and business activities.

It shall be noted that personal data is any information relating to an identified or identifiable natural person.

 


 

1. DEFINITIONS

 1.1. For the purposes of this policy text, the following definitions apply:

  • “GDPR” shall mean Regulation 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
  • “Applicable Data Protection Law” means all applicable laws, regulations, legislative and regulatory requirements, and codes of practice applicable to the processing of personal data, including all the provisions of the GDPR, and any other relevant laws, regulations or instruments, as amended or superseded from time to time and together with any regulations or instruments made thereunder, that are applicable to a controller or processor.
  • “Personal Data” means any information relating to an identified or identifiable natural person (hereinafter “Data Subject”); an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of such a natural person.
  • “Controller” is the natural or legal person, authority, organization or other agency that makes decisions individually or together with other parties regarding the purposes and means for processing Personal Data.
  • “Processor” is a natural or legal person, authority, organization or other agency that processes Personal Data on behalf of the Controller.
  • “Sub-processor” is the contractual partner of the Processor, engaged to carry out specific processing activities on behalf of the Controller.
  • “Third Party” means a natural or legal person, public authority, agency, or body other than the Data Subject, Controller, Processor, Sub-processor, and persons who, under the direct authority of the Controller, Processor or Sub-processor, are authorized to process Personal Data.

The terms used in this policy text such as “processing” (and “process”), “transfer of data”, “categories of data”, “personal data breach” and “technical and organizational measures” shall have the meaning ascribed to them in the Applicable Data Protection Laws.

 


 

2. CONTROLLER

The Controller is the Company as defined above. This means that the Company determines the purposes and manner of processing your personal data in accordance with the GDPR and the general applicable legislation.

 


 

3. SOURCES OF PERSONAL DATA COLLECTION

The Company collects personal data directly from you when you submit an application (including your CV, email, completed checklist, and contact details), completed “Contact” form, or otherwise communicate with us.

 

We do not obtain your personal data from third parties.

 

Your data may also be collected when you explicitly consent to participate in activities related to EU-funded projects, including but not limited to technical assistance projects, recruitment processes, research activities, surveys, workshops, or focus groups.

 


 

4. PURPOSE, CATEGORIES & LEGAL BASIS OF PROCESSING

Purpose of Processing

Personal Data

Legal Basis of Processing (GDPR provisions)

Provide, troubleshoot, and improve Our Services. We use your personal information to provide functionality, analyse performance, fix errors, and improve usability and effectiveness of our website.

• The Internet protocol (IP) address used to connect your computer to the Internet;

• The location of your device or computer; device metrics such as when a device is in use, application usage, connectivity data, and any errors or event failures.

Art.6 § 1 f) GDPR: Processing is necessary for the purposes of the legitimate interests pursued by the Company and in IN IN In particular for the promotion of its aims and actions.

Job offering & Expert Evaluation

All personal data you submit by your own drafted CV form which you send to us by email at the address of info@incomconsulting.gr or other persons managing projects under company name.

Art.6 § 1 f) GDPR: Processing is necessary for the purposes of the legitimate interests pursued by the Company and in particular for the promotion of its aims and actions.


If finally selected for a project further processing may be made.

Respond to your request to contact

• Your name and email when completing our contact form.

Art.6 § 1 a) GDPR: You have provided your consent to the processing of your personal data for one or more specific purposes.

Research & Development (R&D) mainly within co-funded European Research Projects (including but not limited to the Horizon Europe framework) – Specifically for Focus Groups Discussions (FGD), workshops, and expert dataspace platform evaluation activities.

• Audio and/or video recordings (e.g., via MS Teams), transcriptions, expert opinions, professional experience, and registration or participation details.

Art.6 § 1 a) GDPR: The Data Subject has given explicit consent to the processing of his or her personal data for these specific R&D purposes via a dedicated project Consent Form.


 

5. APPLICATION FOR EXPERTISE PROVISION AND SUBMISSION OF CURRICULUM VITAE  (CV) & SPECIAL CATEGORY DATA (CRITICAL)

When submitting a CV to the Company for job opportunities or expert evaluation within research projects, Data Subjects are strictly requested NOT to include any sensitive or special-category personal data (i.e data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic/biometric data, health or sexual orientation etc.). Any such unnecessary sensitive information will be immediately and permanently deleted upon receipt.

 


 

6. ANONYMIZATION, DATA MINIMIZATION & RISK SCREENING

When participating as a partner in European research initiatives, the Company treats data sharing with the utmost care. Even after removing direct identifiers (names, emails, phones), remaining contextual data (employment history, rare qualifications, specific languages, or locations) might still allow indirect identification.

Therefore, before sharing your data further, the Company carries out a strict risk assessment and data minimization process:

  1. Risk Screening: In accordance with Article 35 GDPR, a preliminary screening is documented to assess whether the data processing or sharing poses a high risk to the rights of individuals (especially if automated evaluation or scoring mechanisms are involved). If necessary, a full Data Protection Impact Assessment (DPIA) is conducted.
  2. Technical NLP Tools: Natural Language Processing tools are used to automatically detect and redact direct identifiers.
  3. Contextual Generalization: To prevent indirect identification by recipients, specific contextual entries are generalized (e.g., replacing exact dates with years or age brackets, or broadening highly specific job titles and rare skills).

 


 

7. DISCLOSURE TO THIRD PARTIES & RECIPIENTS

Access to your data should also be available to IT professionals in the context of providing relevant services to the Company if this is necessary in the context of their services.

Your CV shall be processed by our designated personnel and may be revealed to our third-party project partners when evaluating your candidature for that project. Your name and email address, provided when completing the contact form, will not be disclosed to any third party without your prior consent.

With respect to the research projects funded by European commission, if the remaining CV data cannot be fully anonymized without destroying its research utility, it will be treated as personal data. In such cases, data sharing with international project consortium partners is strictly limited to R&D purposes and is legally safeguarded under Data Sharing Agreements (DSA). These agreements put in place clear restrictions on re-identification, unauthorized onward sharing, and linkage with other datasets.

 


 

8. SECURITY

The Company shall process your personal data in a manner that ensures its protection by taking all appropriate organizational and technical measures for data security and its protection against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access and any other form of illicit processing.

 


 

9. SUBJECT’S RIGHTS

This section presents your rights with respect to your personal data. These rights are subject to certain exceptions, reservations or limitations. Please submit your requests responsibly. The Company will respond as soon as possible and in any case within one (1) month of receipt of the request. If the review of your request is going to take longer, you will receive relevant information.

To exercise your rights or for any matter relating to the processing of personal data and the present notice, please contact our dedicated legal compliance contact point at: viola@incomconsulting.gr.

The Company ensures the exercise of your rights:

9.1 THE RIGHT TO INFORMATION

You have the right to request and receive clear, transparent and easily understandable information about how we process your personal data in accordance with the Company’s policies and procedures.

9.2 THE RIGHT TO ACCESS

You have the right to access your personal data free of charge in accordance with the relevant policies and procedures of the Company, except in the following cases where there may be a reasonable charge to cover the administrative expenses of the Company:

  • Manifestly unreasonable or excessive / repeated requests, or
  • Additional copies of the same information.

9.3 THE RIGHT TO RECTIFICATION

You have the right to ask for your personal data to be corrected if it is inaccurate or incomplete, in accordance with the relevant policies and procedures of the Company.

9.4 THE RIGHT TO ERASE («TO BE FORGOTTEN»)

You have the right to request the deletion or removal of your personal data when it is no longer necessary for the purposes collected or there is no legitimate reason to continue processing it in accordance with the Company’s policies and procedures. The right of deletion is not absolute, to the extent that there is a particular legal obligation or other legitimate reason for the retention of your personal data by the Company.

Specific Limitation regarding Research Activities (e.g., Focus Groups, testing & validation activities publishing personal data etc.): You may withdraw your consent at any time during the active research phase. However, once the research dataset has been fully anonymized and aggregated, erasing your personal data becomes technically impossible, as the data no longer correlates with any identifiable natural person.

9.5 THE RIGHT TO RESTRICTION OF PROCESSING

In some cases, you have the right, in accordance with the relevant policies and procedures of the Company, to restrict or remove further processing of your personal data. In cases where processing has been restricted, your personal data remains stored, without further processing.

9.6 THE RIGHT TO DATA PORTABILITY

You have the right to request your personal data, which you have provided to us in a structured, commonly used and machine-readable format, and to transfer that data to another controller in accordance with the relevant policies and procedures of the Company.

9.7 THE RIGHT TO OBJECT

You have the right to oppose, at any time and for reasons related to your particular situation, to the processing of your personal data based on Article 6 (1) (a) & (f) of the GDPR (consent, processing for reasons of lawful interest of the Company), on the basis of that provision. In such a case, the Company as controller will no longer submit the personal data unless it demonstrates imperative and legitimate reasons for processing that override the interests, rights and freedoms of the subject, or the filing, exercise or support legal claims.

9.8 RIGHTS ON AUTOMATED DECISION-MAKING MECHANISMS

The Company does not make automated individual decision-making, including profiling.

9.9 HOW TO EXERCISE THE RIGHT

The exercise of the aforementioned rights takes place with the submission of a written application to the Company in accordance with its policies and procedures. The Company reserves the right to reply no later than one month after receiving the request, in accordance with the terms of the GDPR.

 


 

10. TIME OF RETENTION OF PERSONAL DATA

For each category of personal data, the Company determines the retention time in accordance with the provisions of the law and its policies and procedures.

  • CVs: The CVs submitted, especially for general recruitment purposes, are retained for a period of two years following their receipt. You have the option to update your CV at any time for company’s records or withdraw your participation.
  • Research Project Data: Primary research data, audio/video data, and non-anonymized transcriptions collected during research activities will be safely stored with strict access controls and subsequently permanently destroyed five (5) years after the official completion and formal closure of the respective co-funded research project.

 


 

11. CONTACT OF THE DATA PROTECTION AUTHORITY

For further information and advice on your rights or to submit a complaint, you can contact the Greek Data Protection Authority (www.dpa.gr):

  • Postal Address: Data Protection Authority Offices: Kifissias 1-3, 115 23 Athens, Greece
  • Call Centre: +30-210 6475600
  • Fax: +30-210 6475628
  • E-mail: contact@dpa.gr

 


 

12. AMENDMENTS OF THE PRESENT NOTICE

We aim to review and keep up-to-date the present Notice in order to comply with privacy laws and new developments. Any updates to this Notice will be communicated to you immediately.

  • Original Publication Date: July 26, 2018
  • Last Amended/Updated: May 2026