Privacy Policy
Last updated: 26/6/2026
This Policy explains how Iris AI processes personal data, in accordance with the General Regulation (EU) 2016/679 (GDPR) and Greek Law 4624/2019.
1. Data controller
Name: Chrysovalantis Chatzigeorgiou Registered address: Thermopylon 28 VAT No. / Tax Office: 130821770 / Z’ Thessaloniki · Contact email for data matters: info@irisai.gr
2. What data we collect
a) Visitors of irisai.gr
- Contact form / demo request: name, email, e-shop website, message.
- Technical / cookies: basic browsing data (see Cookie Policy).
b) Clients (subscribers)
- Contact & billing details (name/business name, email, VAT number, address), subscription history.
c) Operation of the AI assistant on client websites
- The assistant processes end-user messages in real time in order to reply and does not store the content of conversations. When an end user voluntarily leaves their details (a lead), these are sent to the respective Client. For per-client usage, only numeric counters are kept (number of conversations/month), with no personal data.
3. Purposes & legal bases of processing
| Purpose | Legal basis |
|---|---|
| Responding to requests/contact form | Legitimate interest / pre-contractual measures |
| Providing & billing the Service | Performance of a contract |
| Legal/tax obligations | Legal obligation |
| Service improvement & security | Legitimate interest |
| Cookies/analytics (non-essential) | Consent |
4. Our role as “processor”
When the AI assistant operates on a Client’s website, the data controller is the Client (e-shop) and Iris AI acts as the processor on their behalf, under a separate Data Processing Agreement (DPA).
5. Recipients & sub-processors
We use trusted providers:
- Cloudflare — hosting/networking & usage counters (infrastructure with EU option).
- Anthropic — AI model (Claude) for generating answers (USA; transfer under Standard Contractual Clauses – SCCs).
- Formspree — handling contact-form submissions on irisai.gr (USA).
- Hosting/email provider for irisai.gr: Hostinger, Hetzner.
We do not sell personal data to third parties.
6. International transfers
Where data is transferred outside the EEA (e.g. Anthropic, Formspree in the USA), appropriate safeguards are ensured (SCCs and/or adequacy frameworks).
7. Retention period
- Requests/contact form: for as long as needed to handle the request and a reasonable period afterwards.
- Client/billing data: for the duration of the relationship and as required by tax law.
- End-user conversation content: not stored.
8. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, as well as to withdraw consent. To exercise these: info@irisai.gr.
If you believe your rights are being violated, you may lodge a complaint with the Hellenic Data Protection Authority (HDPA) — www.dpa.gr.
Note: if you interacted with the AI assistant on a third-party e-shop website, the data controller is that e-shop; please contact them first.
9. Security
We apply reasonable technical & organizational measures (encrypted connections, access control, data minimization). No method is 100% secure, but we make a continuous effort to protect your data.
10. Cookies
The website uses cookies as described in the Cookie Policy.
11. Changes
We may update this Policy. The current version is always published on irisai.gr with a date.
Contact: info@irisai.gr