SEMAC Group (Greece) — Semac Construction S.A. & Semac Automation S.A.
Version 2.3 · Published 14 September 2026 · Effective date: 14 September 2026
Version 2.3 is a clarifying version: it restores the internal consistency of the text as regards automation.semac.gr, which was named in the scope (§1) but appeared neither in the controller table (§3.2) nor in the scope section (§4.1). It introduces no new processing, purpose, legal basis or recipient, and it does not alter the announcements made by versions 2.1 and 2.2, which take effect on their own dates.
Version 2.0, effective 15 August 2026, remains in force until 17 September 2026. The provisions introduced by version 2.1 concern advertising measurement on services.semac.gr and are marked "from 17 September 2026" where they appear. Version 2.2 adds one new named recipient for that same measurement — OpenAI Ads — and is marked "from 1 October 2026" where it appears. Both are listed in the change log in section 20. Both are published in advance under section 18, which requires at least 30 days' notice of a material change; neither operates before its own effective date, and for both, consent to the "Marketing" category is requested again before it starts.
This Privacy Policy covers the websites www.semac.gr, services.semac.gr and automation.semac.gr, together with all processing of personal data carried out by the Greek companies of the SEMAC Group in connection with those properties and with our business activities.
1. At a glance
- Who we are: two independent companies — Semac Construction S.A. and Semac Automation S.A. (Greece). Each acts as a separate controller for its own data.
- What this covers: the three properties named above and our relationships with visitors, enquirers, customers, suppliers and candidates.
- What we collect: mainly business contact details submitted through our forms, technical browsing data, contract and invoicing data and — on the Careers page — CVs.
- Why: to answer enquiries, prepare quotations, perform contracts, invoice, recruit, secure our systems and — only where permitted — send newsletters.
- On what legal basis: performance of a contract or pre-contractual steps (Art. 6(1)(b) GDPR), legal obligation (Art. 6(1)(c)), legitimate interests (Art. 6(1)(f)) and consent (Art. 6(1)(a)) where required.
- For how long: according to the detailed retention schedule in section 6 — e.g. 12 months for an enquiry that leads nowhere, 6 years for tax records.
- Who receives data: IT and hosting providers, represented manufacturers where a technical enquiry must be routed to them, our affiliated company Semac International Ltd (Cyprus) where an enquiry concerns the Cyprus or Middle East market, advisers and auditors, and public authorities where the law requires it. From 17 September 2026: also Google Ads, and from 1 October 2026 also OpenAI Ads — both as our processors for measuring our own advertising on services.semac.gr, and only if you accept marketing cookies.
- Outside the EEA: some providers are established in third countries; transfers are made under standard contractual clauses or an adequacy decision.
- We do not take automated decisions producing legal effects or similarly significantly affecting you, and we do not carry out profiling.
- We do not sell personal data and we do not make it available to advertisers or marketing partners for their own purposes. That remains true of the advertising measurement described in section 6 (purpose 20): the hashed contact details sent to Google Ads may be used only to measure our own campaigns, on our instructions, and not for Google's own purposes.
- Your rights: access, rectification, erasure, restriction of processing, portability, objection, withdrawal of consent, complaint to a supervisory authority. We respond within 1 month.
- Contact: privacy@semac.gr.
2. Table of contents
- At a glance
- Table of contents
- Who we are — the controllers
- Scope
- What personal data we collect
- Purposes, legal bases and retention
- Where the data comes from
- Recipients and processors
- International transfers
- Automated decision-making and profiling
- Security of your data
- Personal data breaches
- Your rights
- Direct marketing and the soft opt-in
- Children
- Users outside the EU/EEA
- Links to third-party sites
- Changes to this Policy
- How to contact us
- Version, effect and change log
3. Who we are — the controllers
3.1 The two companies
| Item | Semac Construction S.A. (ΣΕΜΑΚ ΚΑΤΑΣΚΕΥΑΣΤΙΚΗ Α.Ε.) | Semac Automation S.A. (ΣΕΜΑΚ ΑΥΤΟΜΑΤΙΣΜΟΙ Α.Ε.) |
|---|---|---|
| Country | Greece | Greece |
| Registered office | Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki | Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki |
| Branch | — | Ethnikis Antistaseos 125, 186 48 Drapetsona, Piraeus |
| Registration numbers | GEMI no. 38335405000 · VAT no. EL094490672 | GEMI no. 58436104000 · VAT no. EL099790960 |
| Telephone | (+30) 231 056 9823 | (+30) 231 056 9031 (Thessaloniki) · (+30) 210 462 2625 (Athens) |
| General contact | construction@semac.gr | automation@semac.gr · sales@semac.gr |
| Privacy contact | privacy@semac.gr | privacy@semac.gr |
Collectively we refer to ourselves as the "SEMAC Group", "SEMAC", "we", "us". Both companies are established in Greece and are together referred to as "the Greek entities".
3.2 Which company controls which property
| Property | Controller | Nature |
|---|---|---|
| www.semac.gr | Semac Construction S.A. and Semac Automation S.A. (the website is operated in common; each company remains a separate controller for the data relating to its own activity) | Public corporate website |
| services.semac.gr | Semac Automation S.A. | Service site for on-site flow instrumentation verification and calibration |
| automation.semac.gr | Semac Automation S.A. | Product site: process measurement instruments and automation solutions we represent in Greece |
3.3 Separate, not joint controllers
The two Greek entities act as separate (independent) controllers and not as joint controllers, unless expressly stated otherwise. Each determines the purposes and means of its own processing and is responsible for it.
Where a shared CRM, shared group IT infrastructure or the internal referral of an enquiry between the two companies is involved (for example, where an enquiry submitted on www.semac.gr concerns a product or service supplied by the other company), they still act as separate controllers. The transfer between them rests on the legitimate interests of the Group in internal administration and in serving the enquirer properly (Art. 6(1)(f) GDPR, read with Recital 48).
Enquiries that concern the Cyprus or Middle East market may be referred to our affiliated company Semac International Ltd (Cyprus), which is not a controller under this Policy but a separate controller in its own right; see section 8.1.
3.4 Data Protection Officer and contact point
SEMAC has not appointed a Data Protection Officer (DPO) under Art. 37 GDPR, because no such obligation arises: we are not a public authority, our core activities do not consist of processing operations requiring regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data.
We have, however, designated a Data Protection Contact Point, who coordinates compliance and handles data subject requests: Stamatios Evmorfiadis, privacy@semac.gr.
4. Scope
4.1 Sites covered
This Policy applies to www.semac.gr, services.semac.gr and automation.semac.gr.
4.2 People covered
- Visitors to our websites.
- Enquirers who submit a request through a contact form, by telephone or by email, or who download material from the Resource Center.
- Customers and their staff (contact persons, engineers, procurement officers, accounts payable staff).
- Suppliers, subcontractors and their staff.
- Candidates who submit a CV through the Careers page or by email.
4.3 What this Policy does not cover
- Processing of employee data in the employment context, is governed by a separate Employee / Internal Users Privacy Notice and its accompanying Acceptable Use Annex, which are issued to every employee and user.
- Cookies and similar technologies (trackers, pixels, local storage, device fingerprinting) are described in the separate Cookie Policy, which contains a per-site cookie table and the consent mechanism required by Art. 4(5) of Greek Law 3471/2006 and Art. 5(3) of Directive 2002/58/EC.
- Third-party websites we link to (see section 17).
5. What personal data we collect
We collect only the data necessary for the purposes set out in section 6 (data minimisation, Art. 5(1)(c) GDPR). Fields marked with an asterisk (*) are mandatory in the relevant form; without them we cannot answer your request.
5.1 www.semac.gr (S1)
| Category | Data |
|---|---|
| Contact form | first name, last name, email address, phone, company, message |
| Newsletter signup | email address; consent record (time, method, wording shown) |
| Resource Center (gated brochure / guide downloads) | the identification and contact details you provide, the item downloaded, time of download |
| Careers | CV and the data it contains (contact details, education, work history, certifications, references), covering letter, position of interest |
| Technical data | IP address, browser type and version, operating system, device type, language, referring page, pages visited, timestamps, server log files |
| Cookies and similar technologies | see the Cookie Policy |
| Platform | the site is hosted on Wix (Wix.com Ltd) |
5.2 services.semac.gr (S2)
| Category | Data |
|---|---|
| Contact form | first name, last name, company, industry (dropdown), email address, phone, installed flow instrumentation / application, message |
| Consent | ticking the box "I agree to the processing of my personal data according to the privacy policy" — we record the time and the wording displayed |
| Technical data | as in section 5.1 |
| Embedded maps | the pages contain embedded Google Maps showing our two hubs; loading them causes your device to communicate with Google servers |
| Advertising measurement (from 17 September 2026) | only if you accept marketing cookies: the identifier of the advertisement click that brought you to the site (gclid), and — when you submit the contact form — an irreversibly hashed (SHA-256) form of the email address, phone number and name you entered. The hash is sent to Google Ads so that the enquiry can be matched to the click that produced it; we send no readable contact details for this purpose, the plain values never leave the form submission described above, and if you refuse marketing cookies nothing is sent at all |
5.3 Data we receive from third parties
- Represented manufacturers / principals (Krohne, Bürkert, Danfoss, Ecom, Michell, Knick and others): contact details of prospective customers referred to us for the local market.
- Business partners, agents and subcontractors: contact details of their representatives.
- Public registries and publicly available sources (GEMI, corporate websites, trade directories): company and contact details used for due-diligence checks and B2B business communication.
- LinkedIn: where you contact us or interact with our company pages, or where we identify public professional profiles in the context of recruitment or business communication.
5.5 Special categories of data
We do not seek to collect special categories of personal data (Art. 9 GDPR). Please do not include such data in your messages or CVs. Exceptionally, we may process health data in the context of health and safety at industrial sites (for example, medical fitness to enter a site) on the basis of Art. 9(2)(b) GDPR, or in the context of the establishment and exercise of legal claims (Art. 9(2)(f)).
6. Purposes, legal bases and retention
The following table is the master table of this Policy. Where the legal basis is legitimate interests, we have carried out a balancing exercise between our interest and your rights and freedoms; you may request a summary of that assessment at privacy@semac.gr.
| # | Purpose | Categories of data | Legal basis | Retention |
|---|---|---|---|---|
| 1 | Answering enquiries submitted through the contact forms (S1, S2), by telephone or by email | identification and contact details, company, industry, content of the message | Art. 6(1)(b) GDPR (steps prior to entering into a contract) or, where the enquirer acts on behalf of a company, Art. 6(1)(f) (legitimate interest in responding to a B2B enquiry) | 12 months from last contact, where no relationship follows |
| 2 | Preparing, sending and following up a quotation | contact details, technical requirements, installed equipment, commercial terms | Art. 6(1)(b) GDPR; alternatively Art. 6(1)(f) for the individual representatives | 5 years from the quotation (limitation period, Art. 250 Greek Civil Code) |
| 3 | Routing an enquiry to the represented manufacturer for quotation or technical support | contact details, technical description of the application | Art. 6(1)(b) GDPR (pre-contractual steps) and Art. 6(1)(f) (legitimate interest in providing a complete technical answer) | As rows 1–2, depending on the outcome |
| 4 | Referral of an enquiry to the responsible Group company, or to our affiliated company Semac International Ltd (Cyprus) where the enquiry concerns the Cyprus or Middle East market | contact details, content of the enquiry | Art. 6(1)(f) GDPR (legitimate interests, Recital 48) | As rows 1–2 |
| 5 | Performing an equipment supply or project contract — ordering, delivery, installation, commissioning, warranty | contact details of representatives, delivery details, technical files, correspondence | Art. 6(1)(b) GDPR | Duration of the contract + 5 years; up to 20 years where Art. 249 Greek Civil Code applies |
| 6 | Providing on-site flow instrumentation verification and calibration services (services.semac.gr) and issuing the related reports and certificates | contact person details, site details, measurement data, acceptance signatures | Art. 6(1)(b) GDPR; Art. 6(1)(c) where the customer's regulatory framework requires calibration records to be kept | Duration of the contract + 5 years |
| 7 | Managing suppliers and subcontractors, due-diligence checks | representatives' details, corporate and financial information, certificates | Art. 6(1)(b) GDPR (where the counterparty is an individual) and Art. 6(1)(f) (legitimate interest in selecting counterparties safely) | Duration of the contract + 5 years |
| 8 | Invoicing, accounting and tax compliance | billing details, VAT number, accounting documents, bank details | Art. 6(1)(c) GDPR (legal obligation) | 6 years from the end of the relevant fiscal year, under Greek tax legislation; extended where the assessment period is extended |
| 9 | Delivering Resource Center material (brochures, guides) and related follow-up | contact details, item downloaded | Art. 6(1)(b) or Art. 6(1)(f) GDPR for the delivery itself; Art. 6(1)(a) (consent) for any subsequent marketing communication | 12 months from last contact; where consent applies, until it is withdrawn |
| 10 | Sending the newsletter to persons who are not customers | email address, signup details | Art. 6(1)(a) GDPR (consent), read with art. 11 of Law 3471/2006 | Until withdrawal of consent; evidence of consent + 5 years |
| 11 | Sending existing customers information about our own similar products and services ("soft opt-in") | email address obtained in the course of a previous transaction | Art. 11(3) of Law 3471/2006, read with Art. 6(1)(f) GDPR; an unsubscribe option in every message | Until objection / unsubscribe; evidence + 5 years |
| 12 | Strictly necessary cookies and technologies for the operation and security of the sites | session identifiers, preferences, load-balancing data | Exempt from consent (Art. 4(5) of Law 3471/2006); lawfulness under Art. 6(1)(f) GDPR | See the Cookie Policy |
| 13 | Non-essential cookies, web analytics and tracking technologies | identifiers, usage data, IP address | Art. 6(1)(a) GDPR (consent), read with Art. 4(5) of Law 3471/2006 | Consent record 12 months, then re-prompt; cookie lifetimes per the Cookie Policy |
| 14 | Assessing applications and running the recruitment process (Careers) | CV, covering letter, contact details, interview notes, references | Art. 6(1)(b) GDPR (steps prior to entering into an employment contract) | Deleted when the decision is taken, unless you consent to retention |
| 15 | Keeping an application in a talent pool for future vacancies | as above | Art. 6(1)(a) GDPR (consent) | 12 months from the decision |
| 16 | Network and information security, prevention of misuse and fraud, logging | IP address, server logs, access and audit records | Art. 6(1)(f) GDPR | 6 months; 12 months where a security incident has to be investigated |
| 17 | Health and safety at industrial sites and project locations | identification details, fitness certificates, health data where required | Art. 6(1)(c) and Art. 9(2)(b) GDPR (obligations under employment and social security law) | Duration of employment / project + 5 years; + 20 years where social security law requires it |
| 18 | Establishing, exercising or defending legal claims and conducting legal proceedings | any relevant data, including contractual and financial records | Art. 6(1)(f) GDPR; Art. 9(2)(f) where special categories of data arise | Until the matter is finally concluded and the limitation periods have expired |
| 19 | Handling data subject requests and demonstrating compliance | identification details, content of the request, our response | Art. 6(1)(c) GDPR (Arts. 12–22) read with Art. 5(2) (accountability) | 5 years from closure of the request |
| 20 | Measuring the performance of our own advertising on services.semac.gr, including matching an enquiry submitted through the contact form to the advertisement click that produced it ("enhanced conversions") — applies from 17 September 2026 | advertisement click identifier (gclid); irreversibly hashed (SHA-256) email address, phone number and name from the contact form. No readable contact details are transmitted for this purpose |
Art. 6(1)(a) GDPR (consent, given through the "Marketing" category of the cookie banner), read with Art. 4(5) of Law 3471/2006. Where that consent is not given, no data is transmitted for this purpose at all. Google Ads acts as our processor and may not use the data for its own purposes | Consent record 12 months, then re-prompt. Conversion data is retained by Google Ads for the period set out in its own documentation and is not stored by us in identifiable form |
6.1 What happens when a retention period expires
When a retention period expires, the data is securely deleted or anonymised. Data contained in backups is deleted in the ordinary course of the backup rotation cycle; in the meantime, processing of that data is restricted to what is strictly necessary to restore systems and it is not used for any other purpose. We do not refuse erasure merely because backups exist.
7. Where the data comes from
| Source | Examples |
|---|---|
| Directly from you | contact forms, newsletter signup, Resource Center downloads, email, telephone, meetings, trade fairs, CVs |
| Automatically, as you browse | server log files, cookies and similar technologies (with consent where required) |
| From your employer or customer | where a company nominates you as contact person, engineer or acceptance signatory on a project |
| From represented manufacturers and business partners | referrals of matters concerning the local market |
| From public registries and public sources | GEMI, corporate websites, trade directories |
| From LinkedIn | public professional profiles and interactions with our pages |
| From the other Group company | internal referral of an enquiry (section 3.3) |
| From our affiliated company Semac International Ltd (Cyprus) | referral of an enquiry that concerns the Greek market (section 8.1) |
8. Recipients and processors
8.1 Categories of recipients
| Category | Named examples / clarifications |
|---|---|
| Website platform and hosting | Wix.com Ltd (www.semac.gr). For the other properties: Google Firebase Hosting (Google Ireland Ltd) for services.semac.gr |
| Email and productivity tools | Cloud email and productivity tool providers |
| CRM and marketing email platform | Customer relationship management and marketing communication provider |
| Web analytics | Google Analytics 4 (Google Ireland Ltd), used on services.semac.gr. It operates on the basis of consent only and never on legitimate interests |
| Maps | Google Maps (embedded maps on services.semac.gr) |
| Advertising and conversion measurement | Google Ads (Google Ireland Ltd), used on services.semac.gr to measure which advertisement produced an enquiry. It operates on the basis of consent only — the "Marketing" category of the cookie banner — and never on legitimate interests. Google acts as our processor for this purpose and may not use the data for its own purposes. From 17 September 2026 the measurement additionally uses the irreversibly hashed contact details described in section 6 (purpose 20); before that date it uses only the advertisement click identifier stored in a cookie |
| Advertising measurement on conversational platforms (from 1 October 2026) | OpenAI Ads (OpenAI Ireland Ltd), used on services.semac.gr to measure which advertisement shown inside ChatGPT produced an enquiry. It operates on the basis of consent only — the "Marketing" category of the cookie banner — and never on legitimate interests. OpenAI acts as our processor for this purpose and may not use the data for its own purposes. No contact details are sent, neither readable nor hashed: the measurement uses only the advertisement click identifier and the fact that an enquiry was submitted. Purpose 20 of section 6 ("enhanced conversions") does not extend to this provider; any future extension would be a new purpose and would require fresh notice and fresh consent under section 18. Unlike the Google tags, the script is not placed on the page at all without prior consent, because the provider offers no equivalent of Consent Mode — see §4.3.2 of the Cookie Policy |
| Corporate pages on social networks | LinkedIn, Facebook — see section 8.3 |
| Applicant tracking system (ATS) | Recruitment and CV-management software |
| Represented manufacturers (principals) | Krohne, Bürkert, Danfoss, Ecom, Michell, Knick and others, where your enquiry must be routed to them for a quotation or technical support. Legal basis: Art. 6(1)(b) and/or Art. 6(1)(f) GDPR. They generally act as separate controllers for their own processing |
| Professional advisers | lawyers, accountants, statutory auditors, insurers, banks |
| Freight forwarding and customs services | for the delivery of equipment |
| Public authorities | tax and social security authorities, supervisory authorities, courts and prosecuting authorities, where required by law or by a court order |
| Group companies | internal referral between Semac Construction S.A. and Semac Automation S.A. and shared IT infrastructure (section 3.3) |
| Affiliated company (separate controller) | Semac International Ltd (Cyprus, Reg. No. HE 397733), an affiliated company that acts as a separate controller under its own privacy policy published at semacint.com, to which we may refer an enquiry that concerns the Cyprus or Middle East market. The transfer rests on our legitimate interest in serving the enquiry (Art. 6(1)(f) GDPR, Recital 48). Once the enquiry has been referred, that company processes the data under its own responsibility and its own privacy policy |
We do not sell personal data and we do not make it available to advertisers, contest sponsors or marketing partners for their own promotional purposes. The two advertising-measurement rows in the table above (Google Ads, and from 1 October 2026 OpenAI Ads) are not an exception to that statement: both providers receive the data as our processors, on our instructions and solely to measure the performance of campaigns we ourselves run, neither receives readable contact details for that purpose, and neither receives anything at all from a visitor who has not accepted marketing cookies. OpenAI Ads is sent no contact details even in hashed form — purpose 20 does not extend to it.
8.2 Contracts with processors (Art. 28 GDPR)
With every processor we conclude a written contract meeting Art. 28(3) GDPR, which provides at least for: processing only on our documented instructions; a confidentiality undertaking from the processor's staff; appropriate technical and organisational measures under Art. 32; restrictions on the use of sub-processors and an obligation of prior authorisation or notification; assistance in satisfying your rights and in handling incidents; deletion or return of the data at the end of the engagement; and an obligation to demonstrate compliance and to submit to audits.
8.3 Company pages — joint controllership for page insights
We maintain company pages on LinkedIn and Facebook. For the page insights statistics generated by those platforms, SEMAC and the relevant platform act as joint controllers under Art. 26 GDPR, following the case law of the CJEU in C-210/16 (Wirtschaftsakademie Schleswig-Holstein) and C-40/17 (Fashion ID).
In that context we receive aggregated statistics (for example, views, interactions, general audience demographics) and we have no access to the underlying data of individual users. The processing carried out by the platform itself is governed by its own terms and privacy policy; you may exercise your rights either against us or against the platform. The essence of the arrangement between us is made available by the relevant platform.
9. International transfers
9.1 When they happen
Some of our service providers (for example, the website platform, email, maps, advertising measurement and social networks) are established or maintain infrastructure outside the European Economic Area, mainly in the United States and Israel. In addition, where a project, a delivery or a quotation concerns a customer established outside the EEA, performing the contract or submitting the quotation involves transferring the contact details of the individuals concerned.
9.2 What safeguards apply
Every transfer to a third country is made in accordance with Arts. 44 to 49 GDPR, on one of the following bases:
- An adequacy decision of the European Commission (Art. 45 GDPR). For transfers to US organisations certified under the EU–US Data Privacy Framework, the European Commission's adequacy decision of 10 July 2023 applies, which is currently valid but subject to ongoing judicial review.
- The standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914 (Art. 46(2)(c) GDPR), accompanied by a transfer impact assessment and, where necessary, by supplementary measures (for example, encryption, pseudonymisation, contractual transparency undertakings regarding government access requests).
- Exceptionally, and for occasional, non-repetitive transfers, the derogations in Art. 49 GDPR — in particular where the transfer is necessary for the performance of a contract between you and us or of a contract concluded in your interest (Art. 49(1)(b) and (c)), or with your explicit consent after being informed of the risks (Art. 49(1)(a)). For transfers to countries not covered by an adequacy decision we rely as a rule on standard contractual clauses or, where these cannot be put in place, on Art. 49(1)(b).
9.3 How to obtain a copy of the safeguards
You may request a copy or a description of the safeguards applied to a particular transfer by writing to privacy@semac.gr. We may redact commercially confidential information (for example, pricing) before providing a copy.
10. Automated decision-making and profiling
SEMAC does not carry out automated decision-making producing legal effects or similarly significantly affecting individuals, including profiling, within the meaning of Art. 22 GDPR.
Specifically: we do not screen job applications automatically, we do not score customers or suppliers automatically, and we do not take automated credit or commercial decisions. If this changes, we will inform you in advance, provide the information required by Art. 13(2)(f) GDPR and give you the right to obtain human intervention.
11. Security of your data
We implement appropriate technical and organisational measures under Art. 32 GDPR, proportionate to the nature, context and risks of the processing:
- Access control and least privilege: access to data is granted by role and only to the extent required by the user's duties; permissions are reviewed periodically and revoked immediately when staff leave or change role.
- Strong authentication: multi-factor authentication (MFA) is mandatory for access to corporate email accounts; we enforce a strong-password policy and store credentials in hashed form.
- Encryption in transit: all connections to our sites and application use TLS 1.2 or later, with HTTP-to-HTTPS redirection enabled.
- Encryption at rest: databases, backups and laptop disks are encrypted.
- Backup and recovery: regular backups with integrity checking and periodic restore testing; backups are held encrypted and in a separate location.
- Segregation of environments and data: separate production and test environments; real personal data is not used in test environments; logical segregation of data between Group companies where required.
- Vendor due diligence: each provider is assessed before engagement (processing location, certifications, sub-processors, security measures) and a contract meeting Art. 28 GDPR is put in place.
- Staff training and confidentiality: regular data protection and information security training, phishing awareness, and confidentiality undertakings for all staff.
- Logging, monitoring and incident response: access and audit logs are kept, systems are patched, and a documented incident management procedure defines roles and response times.
No method of transmitting or storing data is completely secure and we cannot guarantee absolute security. This does not limit our obligations or our liability: we remain responsible for implementing and keeping appropriate measures up to date, for investigating every incident, and for the consequences of any failure on our part under the applicable law.
12. Personal data breaches
We maintain a documented procedure for detecting, recording, assessing and responding to personal data breaches.
- Notification to the supervisory authority: where a breach is likely to result in a risk to the rights and freedoms of natural persons, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it (Art. 33 GDPR). Where notification is delayed, we give the reasons for the delay.
- Communication to data subjects: where a breach is likely to result in a high risk to your rights and freedoms, we inform you without undue delay, in clear and plain language, describing the nature of the breach, its likely consequences, the measures we have taken, the measures you can take, and contact details (Art. 34 GDPR).
- Internal record: we keep a record of all incidents, whether or not notified, setting out the facts, the effects and the remedial action taken.
- Processors: our contracts require processors to notify us without undue delay after becoming aware of a breach.
13. Your rights
As a data subject you have the following rights:
| Right | Article | What it means |
|---|---|---|
| Access | 15 | To find out whether we process data about you and to obtain a copy, together with information on purposes, recipients, retention and transfers |
| Rectification | 16 | To have inaccurate data corrected and incomplete data completed |
| Erasure ("right to be forgotten") | 17 | To have data deleted, where no ground for retention applies — such as a legal obligation or legal claims |
| Restriction of processing | 18 | To have processing "frozen", for example while accuracy or a legitimate interests balancing exercise is being verified |
| Portability | 20 | To receive the data you provided to us in a structured, commonly used and machine-readable format and to transmit it to another controller — for processing based on consent or on a contract and carried out by automated means |
| Objection | 21 | To object to processing based on legitimate interests, on grounds relating to your particular situation. As regards direct marketing, the right to object is absolute (Art. 21(2)) and we stop the processing immediately |
| Not to be subject to an automated decision | 22 | See section 10 — we do not carry out such processing |
| Withdrawal of consent | 7(3) | Where processing is based on consent, you may withdraw it at any time, as easily as you gave it; withdrawal does not affect the lawfulness of processing carried out beforehand |
| Complaint to a supervisory authority | 77 | See section 19 |
| Judicial remedy | 79 | The right to an effective judicial remedy against a controller or processor |
13.1 How to exercise your rights
Send your request to privacy@semac.gr, or by post to the address in section 19. Please state which right you are exercising and, if possible, which processing activity you are referring to — this helps us answer faster.
13.2 Deadlines and cost
We respond without delay and in any event within one (1) month of receiving your request. That period may be extended by two (2) further months where justified by the complexity or number of requests; in that case we inform you of the extension and the reasons for it within one month (Art. 12(3) GDPR).
Exercising your rights is free of charge. Only where a request is manifestly unfounded or excessive, in particular because of its repetitive character, may we either charge a reasonable fee or refuse to act — always giving reasons and informing you of your right to complain and to a judicial remedy (Art. 12(5) GDPR). The burden of demonstrating that a request is manifestly unfounded or excessive lies with us.
13.3 Identification
We may ask for additional information where we have reasonable doubts as to the identity of the person making the request (Art. 12(6) GDPR). Identification is proportionate: as a rule it is enough that the request comes from an email address we already hold, or that you confirm details we already have. We do not ask for a copy of an identity document as a blanket rule; where an identity document is genuinely needed in a particular case, we ask for the minimum information, accept redaction of the fields that are not required, and do not keep the copy beyond the time needed to verify.
13.4 Request handling procedure
The way in which we receive, record, assess and answer requests is described in the separate document "Data Subject Access Request (DSAR) Procedure", available on request.
14. Direct marketing and the soft opt-in
- If you are not a customer, we send you a newsletter or other marketing message only with your prior express consent (Art. 6(1)(a) GDPR, art. 11 of Law 3471/2006).
- If you are already a customer, we may use the email address you gave us in the course of a previous transaction to tell you about our own similar products and services ("soft opt-in", art. 11(3) of Law 3471/2006). You are given a clear opportunity to object both at the point of collection and in every subsequent message.
- Every marketing message contains a link or another simple, free method of unsubscribing, together with the identity of the sending company.
- The right to object to direct marketing is absolute (Art. 21(2) GDPR): once you exercise it, we stop that processing immediately and you do not need to give reasons. We keep a suppression list containing the minimum data necessary to ensure that you do not receive messages again.
- Objecting does not affect operational messages connected with a contract or service (for example, order confirmations, calibration due notices, invoices).
15. Children
Our websites are addressed to professionals and businesses (B2B) and are not directed at minors. We do not knowingly collect personal data of minors through www.semac.gr or services.semac.gr.
For completeness: where processing is based on consent in relation to information society services, the age of consent is 15 in Greece (art. 21 of Law 4624/2019); below that age, the consent or authorisation of the holder of parental responsibility is required. As a matter of policy, SEMAC does not collect data from minors at all, and any information that comes to our attention concerning a person under 16 is deleted without delay.
If you are a parent or guardian and believe we have received a minor's data, please contact privacy@semac.gr and we will delete it.
16. Users outside the EU/EEA
SEMAC is established in Greece, and the processing described here is governed by the GDPR and by Greek law (see section 3 of this Policy and the "Governing law" section of the Terms of Use).
If you visit our websites or contact us from a country outside the EU/EEA, your data is transferred to and processed in the EU/EEA, where a level of protection different from that of your own country may apply. We apply GDPR standards to all data subjects, regardless of residence or nationality.
You may have additional rights under your national law. We will consider any such request in good faith, to the extent that the relevant legislation applies to SEMAC. The law of the State of California (CCPA/CPRA) does not apply to SEMAC, and the references to it in the previous version of this text have been removed as inaccurate.
17. Links to third-party sites
Our websites contain links to third-party sites — in particular to represented manufacturers, social networks and embedded maps. We do not control those sites and are not responsible for their content or privacy practices. Once you move to a third-party site, that site's own privacy policy applies — we recommend that you read it. Embedded elements that store or read data on your device are activated only with your consent, in accordance with the Cookie Policy.
18. Changes to this Policy
We update this Policy whenever our processing activities, the legal framework or our providers change, and we review it at least once a year.
- Each new version carries a version number, an effective date and an entry in the change log in section 20.
- For material changes — for example, a new processing purpose, a change of legal basis, a new category of recipients, a new transfer to a third country, or a significant extension of a retention period — we post a prominent notice on the websites at least 30 days before the change takes effect and, where we hold your contact details and the change concerns you, we also notify you by email.
- Where a change requires your consent, we do not begin the new processing before we obtain it; silence or continued browsing is not treated as consent.
- Previous versions are retained and are available on request at privacy@semac.gr.
19. How to contact us
19.1 SEMAC
| Semac Construction S.A. and Semac Automation S.A. (E1, E2) | |
|---|---|
| privacy@semac.gr | |
| Postal address | Semac Construction S.A. / Semac Automation S.A., Industrial Area of Sindos, Block 39B, 570 22 Thessaloniki, Greece (attn: Data Protection Contact Point) |
| Branch | Ethnikis Antistaseos 125, 186 48 Drapetsona, Piraeus, Greece |
| Telephone | (+30) 231 056 9823 · (+30) 231 056 9031 · (+30) 210 462 2625 |
| Contact point | Stamatios Evmorfiadis |
19.2 Supervisory authorities
If you consider that the processing of your data infringes the GDPR, you have the right to lodge a complaint with a supervisory authority (Art. 77 GDPR). We would appreciate the chance to address the matter first, but that is not a precondition.
Greece — Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα / HDPA) Kifissias Avenue 1-3, 115 23 Athens Tel.: +30 210 6475600 · Email: contact@dpa.gr · www.dpa.gr
You may also address the supervisory authority of the Member State of your habitual residence, your place of work or the place of the alleged infringement (Art. 77(1) GDPR), and you have the right to an effective judicial remedy against SEMAC or against a decision of a supervisory authority (Arts. 78 and 79 GDPR).
20. Version, effect and change log
| Item | Value |
|---|---|
| Document title | Privacy Policy — SEMAC Group (Greece) |
| Version | 2.3 |
| Published | 14 September 2026 |
| Effective date | 14 September 2026 (clarifying version, no new processing — the 30 days' notice of section 18 does not apply; the announcements of versions 2.1 and 2.2 take effect on their own dates, 17.09.2026 and 01.10.2026) |
| Previous versions | 2.2 — published 1 September 2026 · 2.1 — published 17 August 2026 · 2.0 — 15 August 2026 · 1.0 — Privacy Policy dated 21 September 2021 (repealed and wholly replaced) |
| Scope | www.semac.gr · services.semac.gr · automation.semac.gr |
| Languages | Greek (primary for all three websites) and English; the two texts are substantively identical |
| Related documents | Cookie Policy · Employee / Internal Users Privacy Notice · DSAR Procedure · Terms of Use |
| Next scheduled review | At least annually |
Change log
| Version | Date | Changes |
|---|---|---|
| 1.0 | 21.09.2021 | Original Privacy Policy; covered www.semac.gr only; no legal bases, retention periods, transfer information, supervisory authorities or processors; contained an inapplicable CCPA section |
| 2.0 | 15.08.2026 | Complete rewrite. Covers all three properties of the SEMAC Group (Greece) and both Greek controllers; Semac International Ltd (Cyprus) is no longer a controller under this Policy and appears only as an affiliated third-party recipient and separate controller with its own privacy policy. Added: "At a glance" summary and table of contents; identification of the controllers and of the data protection contact point; detailed tables of data collected per property; master table of purposes, legal bases and retention; sources of data; categories of recipients with named examples and an Art. 28 commitment; joint controllership for page insights; international transfers with SCCs (Decision 2021/914) and the DPF; express statement that no automated decision-making takes place; detailed security measures; Art. 33/34 commitments; full list of rights with deadlines and proportionate identification; direct marketing and soft opt-in section; children's section; 30-day change notification mechanism; version and change log. Removed: the CCPA / California section; the statement that data is shared with "advertisers, contest sponsors and marketing partners"; the blanket refusal to erase data because of backups |
| 2.1 | 17.09.2026 (published 17.08.2026) |
Advertising measurement on services.semac.gr. Added: Google Ads (Google Ireland Ltd) as a named recipient and processor in section 8.1 — it was already in use for conversion measurement and named in the Cookie Policy, but was missing from the recipients table here; a row in the section 5.2 table for the data used in that measurement; purpose 20 in the master table of section 6, covering the matching of an enquiry to the advertisement click that produced it ("enhanced conversions") by means of an irreversibly hashed (SHA-256) email address, phone number and name, on the basis of consent only. Clarified: the two statements that we do not make personal data available to advertisers for their own purposes now say expressly why that measurement is not an exception — Google acts as our processor, receives no readable contact details for the purpose, and receives nothing at all where marketing consent is refused. Published 30 days in advance under section 18; the new purpose does not operate before the effective date, and consent is requested again before it starts |
| 2.2 | 01.10.2026 (published 01.09.2026) |
A new named recipient for advertising measurement on services.semac.gr. Added: OpenAI Ads (OpenAI Ireland Ltd) as a named recipient and processor in section 8.1, for measuring which advertisement shown inside ChatGPT produced an enquiry; advertising measurement is added to the categories of provider in section 9.1 that may maintain infrastructure outside the EEA. No new category of data and no new purpose: the measurement uses only the advertisement click identifier and the fact that an enquiry was submitted; no contact details are sent, neither readable nor hashed, and purpose 20 (enhanced conversions) does not extend to this provider. The legal basis is consent only (the "Marketing" category of the cookie banner), which is requested again before it starts, this being a material change under section 18; published 30 days in advance and not operating before the effective date. Technical difference recorded: the provider offers no equivalent of Consent Mode, so the script is not placed on the page at all without consent, rather than being placed there in a denied state (§4.3.2 of the Cookie Policy) |
| 2.3 | 14.09.2026 | Clarifying version — no new processing. automation.semac.gr, the product website of Semac Automation S.A., had been named in the opening scope (§1) since version 2.2 but was missing from the controller table (§3.2) and from the scope section (§4.1), which still named two websites — that is, the text contradicted itself. A row was added to §3.2 and §4.1 and the details table of section 20 were corrected. The processing carried out on that website (contact form, statistics with consent) is already covered by the existing purposes, legal bases and retention periods; no purpose, legal basis, recipient or data category is added, and for that reason there is no material change under section 18. The announcements of versions 2.1 (Google Ads, from 17.09.2026) and 2.2 (OpenAI Ads, from 01.10.2026) are unchanged. |
