Privacy Policy
How we collect, use and protect personal data on marrow.gr and on the Marrow platform, in accordance with Regulation (EU) 2016/679 (GDPR).
- We do not sell data.
- Employee data belongs to the business; we process it on its behalf.
- Location only at the moment of clock-in and clock-out.
- Marrow AI does not train models with your data.
- Request access or deletion at dpo@marrow.gr.
01Who we are
Marrow Ai Systems I.K.E., [address], VAT number (ΑΦΜ) [—]. Data Protection Officer: dpo@marrow.gr.
02Roles
For the data of visitors to the site and the account details of our customers, we are the Data Controller.
For the data a business enters or collects on the platform (e.g. its employees' details and schedules), the business is the Data Controller and we are the Data Processor acting on its behalf.
03What data
Site visitors: contact form details (name, business, phone, email, message) and technical data (IP, browser).
Platform users: name, phone, email, role, department, schedule, clock-in and clock-out times, leave requests, tips.
Business: accounting documents, suppliers, debts, cash register data.
04Location and QR
At clock-in the app checks whether the device is within the business's premises. Location is recorded only at the moment of clock-in and clock-out, not continuously.
05Purposes and legal bases
Providing the service (performance of a contract); meeting the business's obligations under labour and tax legislation (legal obligation); security and prevention of abuse (legitimate interest); responding to contact requests (pre-contractual measures).
06Marrow AI
When you use Marrow AI, your questions and the related data are processed by artificial intelligence model providers acting as sub-processors, under contractual terms that prohibit their use for model training.
07Sub-processors
We use selected providers for hosting, email, SMS/telephony and AI: [list of providers]. The current list is available on request.
08Transfers outside the EEA
Where a provider is located outside the EEA, the transfer is made on the basis of an adequacy decision or the European Commission's Standard Contractual Clauses.
09Retention period
Account data: for as long as the subscription lasts and [30] days after. Data required by law (e.g. schedules, accounting documents): for the period set by legislation. Contact requests: up to [24] months.
10Security
Encryption in transit and at rest, an isolated database per business, roles and permissions, access logging.
11Your rights
Access, rectification, erasure, restriction, portability and objection. If you are an employee of a customer business, contact your employer first; we will support them. You have the right to lodge a complaint with the Hellenic Data Protection Authority (dpa.gr).
12Cookies
The site uses only the cookies necessary for it to function. Analytics cookies are enabled only with your consent.
13Changes
If the Policy changes materially, we will inform users through the app or by email.
14Contact
For any personal data matter: dpo@marrow.gr.