Privacy Policy (GDPR)

Version 2026-08 · Last updated: 5 August 2026
Data Controller. DEFFINTECH PCC (Private Company), the company responsible for your personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”).
Registered office: Anoixeos 23 & Grigoriou E’, 13451 Kamatero, Attica, Greece.
Contact for privacy and data-protection matters: security@deffintech.com.
DEFFINTECH PCC operates the Dreamful Life platform at dreamfullife.org and the EPICUROS sub-site at epicuros.dreamfullife.org (together, the “Platform”).

1. About this policy

This Privacy Policy explains how DEFFINTECH PCC (“we”, “us”, “our”) collects, uses, shares and protects personal data when you use the Platform, and describes the rights you have over your data. It applies to visitors, registered users, coaches, and organizations that use our services. Where a specific service has its own notice (for example the paid self-assessment tests), that notice supplements this policy.

2. Personal data we collect

Data you provide

  • Account & identity: name, email address, password (stored only as a secure hash), preferred language, and role (client, coach, organization administrator).
  • Organization data: where you register on behalf of an organization — organization name, contact details and the members you invite.
  • Coaching & questionnaire content: answers to intake questionnaires and evaluations, goals, development-plan entries, session notes and messages you choose to store on the Platform.
  • Coach applications: professional background and certification information submitted by prospective coaches.
  • Payment data: when you buy a paid item, payment is processed by our payment provider (Stripe). We receive confirmation of payment and limited transaction metadata; we do not receive or store your full card number.
  • Support & communications: the content of messages you send us.

Data collected automatically

  • Technical & usage data: IP address, device and browser type, pages viewed, and access timestamps, recorded in server logs for security and reliability.
  • Local storage: a session/authentication token and your language preference are stored in your browser to keep you signed in and remember your settings. See our Cookie Policy.

3. Special-category data and ephemeral assessments

We do not seek to collect special categories of personal data (such as health, religious or political data). Our questionnaires are designed as non-clinical, wellbeing-oriented instruments. The public paid self-assessments (for example the €5 self-evaluation and the €3 “Meet Yourself” test) are computed in your browser or transiently on our server and their answers and results are not stored — nothing about your responses is retained after the result is shown to you.

4. Legal bases for processing (GDPR Art. 6)

PurposeLegal basis
Creating and managing your account; providing the coaching and evaluation services you requestPerformance of a contract (Art. 6(1)(b))
Processing payments and keeping accounting/tax recordsContract, and legal obligation (Art. 6(1)(b) and (c))
Securing the Platform, preventing abuse, and improving reliabilityLegitimate interests (Art. 6(1)(f))
Optional analytics and non-essential cookies; marketing emailsConsent (Art. 6(1)(a)), which you may withdraw at any time
Complying with legal requests and defending legal claimsLegal obligation and legitimate interests (Art. 6(1)(c) and (f))

5. How we use your data

We use personal data to: provide and personalise coaching content, questionnaires and evaluations; connect clients with coaches; manage certifications and course progress; process payments; communicate with you about your account and support requests; keep the Platform secure and functioning; and comply with our legal obligations.

6. Sharing and processors

We do not sell your personal data. We share it only with service providers (“processors”) who act on our instructions under a data-processing agreement, and where required by law. These include:

  • Hosting infrastructure — our servers, which host the Platform and its database.
  • Payments — Stripe, which processes card payments as an independent controller for payment purposes and is PCI-DSS compliant.
  • Content delivery / DNS — a network provider that routes and secures traffic to the Platform.
  • Email delivery — where we send transactional messages.

We may also disclose data to competent authorities where legally required, or to protect our rights, users and the security of the Platform.

7. International transfers

We aim to keep processing within the European Economic Area (EEA). Where a processor (such as a payment or infrastructure provider) processes data outside the EEA, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and adequacy decisions where available.

8. Retention

  • Account and coaching data: kept while your account is active and deleted, or anonymised, on request or within a reasonable period after the account is closed, unless a longer period is required by law.
  • Payment and accounting records: retained for the period required by applicable Greek tax and accounting law.
  • Server/security logs: retained for a limited period for security and diagnostics.
  • Public paid self-assessments: not stored.

9. Your rights

Subject to the conditions in the GDPR, you have the right to: access your data; have inaccurate data corrected; have your data erased; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw that consent at any time without affecting prior processing. To exercise any right, email security@deffintech.com. We will respond within one month, as required by the GDPR. You will not be charged for a first, reasonable request.

10. Right to complain

If you believe we have handled your data unlawfully, you may lodge a complaint with the Greek supervisory authority:

Hellenic Data Protection Authority (HDPA) — Kifisias 1-3, 115 23 Athens, Greece · tel. +30 210 6475600 · www.dpa.gr · complaints@dpa.gr. You may also complain to the authority in your EU country of residence.

11. Automated decision-making

Our evaluations and development plans are decision-support tools intended to be reviewed with a coach. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

12. Children

Accounts and paid adult assessments are intended for users aged 18 and over. The EPICUROS free youth test is designed to be age-appropriate and does not store personal answers; where a user is a minor, it should be used with the awareness and, where appropriate, the consent of a parent or guardian.

13. Changes to this policy

We may update this policy to reflect changes in our services or the law. The “last updated” date above shows the current version; material changes will be communicated through the Platform.

14. Contact

DEFFINTECH PCC — Anoixeos 23 & Grigoriou E’, 13451 Kamatero, Attica, Greece · security@deffintech.com.

This policy is provided for transparency and general information about our data practices and is not a substitute for individual legal advice.