Scope
- Issued by Wayfor S.A. under the EU GDPR (Regulation 2016/679) and other applicable data protection law.
- Covers only personal data from the website contact form and technical data collected automatically on nadifor.ai.
- Cookies are covered in a separate Cookie Policy, and platform data in a separate Platform Privacy Policy.
- Third-party sites linked from nadifor.ai fall under their own privacy policies.
1. Data Controller and DPO
- Controller: Wayfor S.A.
- Registration number: ELGEMI.180456803000
- Address: Vasilissis Sofias 90, Athens, 11528, Greece
- General email: info@wayfor.ai
- Data Protection Officer: Antonios Fix, dpo@wayfor.ai
Wayfor acts as data controller under Article 4 GDPR. It sets the purposes and means of processing and is accountable for lawful, fair and transparent handling.
2. Personal Data Collected
- Contact form, required fields: name, email address, phone number, company name, message content.
- Contact form, optional field: company size.
- Collected automatically through server logs: IP address, browser type, device information.
Wayfor cannot process an enquiry if required fields are missing. It collects no special category data and does not knowingly collect data from anyone under 16.
3. Legal Basis and Purpose of Processing
- Responding to contact form submissions: answering enquiries, sharing service information and sales follow-up. Legal basis is consent, Article 6(1)(a).
- Customer relationship management: managing the relationship arising from an enquiry. Legal basis is consent, plus performance of a contract under Article 6(1)(b) where a pre-contractual relationship arises.
- Website security and performance: protecting site integrity and preventing misuse, fraud and cyber threats. Legal basis is legitimate interests, Article 6(1)(f).
- Legal compliance: meeting statutory obligations. Legal basis is legal obligation, Article 6(1)(c).
Wayfor does not use website data for automated decision-making or profiling under Article 22. Consent can be withdrawn at any time by emailing dpo@wayfor.ai; withdrawal does not affect earlier lawful processing.
4. Data Retention and Storage
Retention
- Contact form data is kept for 12 months from the last interaction, then securely deleted.
- The period can be extended to meet legal or regulatory obligations, resolve disputes, enforce agreements or respond to rights requests.
- Where immediate deletion is not technically feasible, the data is isolated from further processing, stored securely and deleted as soon as practicable.
Storage location
- Data is primarily stored within the EU/EEA, including on EU-region infrastructure.
- The named providers are Amazon Web Services EMEA SARL, AC PM LLC, Google LLC and Amplitude, Inc.
- Data may be stored or transferred outside the EU/EEA using Chapter V GDPR transfer tools.
- All named providers are on the EU-U.S. Data Privacy Framework list, so transfers to them fall under the Article 45 adequacy decision.
Data sharing
- Wayfor does not sell, rent or share personal data with third parties for their own purposes.
- The named providers act as processors under GDPR-compliant data processing agreements.
- Disclosure can occur where required by law, a court order or a competent authority, or to protect the rights, property or safety of Wayfor, its users or others.
5. Data Subject Rights
- Access, Article 15: a copy of personal data in a structured, machine-readable format.
- Rectification, Article 16: correction of inaccurate or incomplete data.
- Erasure, Article 17: deletion where data is no longer needed or consent is withdrawn, subject to legal retention obligations.
- Restriction, Article 18: limiting processing in specific circumstances, such as a disputed accuracy claim.
- Objection, Article 21: objecting to processing based on legitimate interests. Processing stops unless Wayfor shows compelling overriding grounds.
- Portability, Article 20: receiving or transferring consent-based data in a machine-readable format, where technically feasible.
- Withdrawal of consent, Article 7(3): at any time, without affecting earlier lawful processing.
- Automated decision-making, Article 22: Wayfor makes no solely automated decisions, so this right has no current practical application for the website.
How to exercise rights
- Email dpo@wayfor.ai with your name, email address and a description of the request.
- Wayfor responds within one month, free of charge, and may verify identity first.
- Wayfor commits to no discrimination for exercising data protection rights.
6. Right to Complain
Wayfor asks individuals to contact dpo@wayfor.ai first. Complaints can also go to the Greek supervisory authority, the Hellenic Data Protection Authority (HDPA):
- Email: contact@dpa.gr
- Telephone: +30 210 6475 600
- Website: www.dpa.gr
7. Data Security
Wayfor states it applies appropriate technical and organisational measures:
- SSL/TLS encryption of data in transit.
- Access limited to authorised personnel on a need-to-know basis.
- Regular security assessments and vulnerability reviews.
- Confidentiality obligations and data protection awareness for personnel with access to personal data.
The policy notes that no transmission or storage system is fully secure and that users submit data at their own risk.
8. Data Breach Notification
- Breaches likely to create a risk to individuals are reported to the HDPA within 72 hours, under Article 33.
- Breaches likely to create a high risk are also reported to affected individuals without undue delay, under Article 34. The notice covers the nature of the breach, likely consequences and remedial measures.
9. Changes to This Policy
- Updates are published on the same page with a revised "Last modified" date.
- Material changes are flagged through a prominent website notice or, where contact details are held, by email.
- Users are advised to review the policy periodically.
10. Contact
- General privacy enquiries: Wayfor S.A., info@wayfor.ai
- Data protection matters and rights requests: Antonios Fix, dpo@wayfor.ai