Compliance & Legal
Privacy Policy (GDPR Compliance)
Effective date: September 10, 2026
1. Data Controller
RantevouOS operates as a Data Processor on behalf of appointment businesses in Greece (Data Controllers). For platform account management, RantevouOS is the Data Controller.
2. Information We Collect
- Business Owners & Staff: Name, email address, phone number, and password hashes (Argon2id encrypted).
- End Customers: Name, phone number, email address, and appointment records submitted during public booking.
- System Metadata: Session cookies (HttpOnly, SameSite), IP addresses, and standard audit logs.
3. Legal Basis for Processing
Processing is conducted under Article 6(1)(b) of the GDPR (performance of a contract to deliver appointment scheduling services) and Article 6(1)(f) (legitimate interests in platform security).
4. Your Rights under GDPR
Greek and EU residents maintain the following rights regarding their personal data:
- Right to Access & Rectification: Request a copy of your stored records or correct inaccuracies.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of personal customer records.
- Data Portability: Export appointment and customer history in structured JSON or CSV formats.
5. Tenant Isolation & Security
Every business account operates within strict database multi-tenant isolation. No Business entity can view, query, or extract data belonging to another business entity.