Your privacy matters to us. This policy explains in plain language what personal data FixMate collects, why, for how long, and what your rights are under the EU General Data Protection Regulation 2016/679 ("GDPR") and Greek Law 4624/2019.
1. Who is responsible
The data controller is FixMate, —, VAT no. —. Contact for privacy matters: admin@fixmate.mytaxconsultant.gr.
2. What we collect
- Account: full name, email, phone (optional for clients), city, language, password (stored only as a secure hash — nobody can read it), sign-up and last-login dates.
- Professional page (public): business name, trades, description, services, years of experience, city/area, map location and service radius, phone, WhatsApp, website, email (only if you choose to show it), logo, cover and project photos. We automatically remove metadata (such as GPS location) from photos.
- Contact requests: when you message a professional we keep your name, email, phone (if given), message and IP address (for spam protection).
- Jobs & bids: job description, budget, city/area, bids, messages and their status.
- Reviews: rating and comment. Only your first name and last-name initial are shown publicly.
- Page reports: reason, comment and — if you are logged in — who reported.
- In-site notifications about your account.
- Security data: IP address and email of failed log-in attempts, and IP addresses for rate limits (abuse prevention).
- Page statistics: only daily counts (e.g. "12 views, 3 phone clicks"). We do not store who did it or any IP address.
- "Near me" location: only if you allow it in your browser. Coordinates are used for that search only and are not stored in your account.
- Extra page details (optional): Viber and links to your Google, Facebook and Instagram profiles.
- Professional tools (“My projects” — clients, projects, quotes): whatever a professional records about their own clients (name, contact details, site address, notes, quotes). For this data the professional is the controller; FixMate only hosts it on their behalf (processor, Art. 28 GDPR), no other user can see it and we use it for no other purpose. When a client opens a quote from the link they received, we record when it was opened and their answer (accept/decline and an optional comment).
- Company accounts: company name, VAT number, contact details and description (public page, if the company chooses), the private “My crews” list and invitations to professionals.
- Push notifications (only if you turn them on): the address (endpoint) your device's browser provides to receive notifications.
- Notification preferences: e.g. whether you want new-job emails instantly, once a day or never.
- Before & After photos: shown publicly on a professional's page, like project photos.
- Counter-offers & declined bids: amount, optional message and status of the negotiation on a job.
- Messages (chat): the content of the messages you exchange with other users, when they were sent and read, plus blocks and conversation reports.
- VAT number: mandatory for companies, optional for professionals. Used only to verify the business and (if you choose) on the PDF quotes you send — never shown publicly.
- Security history: for every sign-in, sign-out, failed sign-in, password change/reset, 2FA change, account deletion and administrator action we record date and time, IP address, device/browser type (User-Agent) and the account or email used. You can see your recent sign-ins under "My account".
- Firewall: for requests that look like an attack (e.g. scanning for vulnerabilities, malicious URLs, many failed sign-ins) we record the IP address, the requested URL and the browser, and the IP may be blocked temporarily. No other analysis or profiling is done.
- Newsletter preference: whether you want to receive platform newsletter emails.
3. Why we use it (legal basis)
- Contract (Art. 6(1)(b) GDPR): running your account, publishing professional pages, jobs, bids, notifications and essential emails (confirmation, activation, password reset).
- Consent (Art. 6(1)(a)): forwarding your contact request to the professional you chose. You can withdraw consent at any time.
- Legitimate interest (Art. 6(1)(f)): security, spam and fraud prevention, handling reports, anonymous statistics to improve the service.
- Legal obligation (Art. 6(1)(c)): keeping tax records if you buy a subscription plan.
- Consent for push notifications: you turn them on per device and can turn them off at any time (browser settings or logging out).
- Alerts about new jobs in your area: part of the service for professionals (contract) — change or stop them in “My account”.
- Messages, counter-offers and declined bids: performance of the contract — they are part of the service you use.
- Security history, firewall and new-device sign-in alerts: legitimate interest (Art. 6(1)(f) and Recital 49 GDPR) in securing the site and your accounts, preventing attacks and investigating incidents.
- Platform newsletter emails: legitimate interest towards our members (Art. 11(3) Greek Law 3471/2006). You can object at any time, free of charge, via the "unsubscribe" link in every such email or from "My account". Essential service messages (e.g. security, changes to the terms) are sent to everyone as part of the contract.
4. Who sees your data
- The public: whatever you publish on your professional page, and reviews.
- The professional you contact receives your request. When a bid is accepted, client and professional can see each other's contact details.
- Service providers: our web hosting company and email provider, strictly on our behalf.
- Content services: to load fonts, styling and maps, your browser connects to Google Fonts, cdnjs (Cloudflare) and OpenStreetMap (map tiles and address search). These services receive your IP address in order to deliver the files.
- Security check (Cloudflare Turnstile): some forms (sign-up, login, password reset, quote request, report) may run an automatic check that you are not a bot. Cloudflare receives your IP address and technical browser data solely for this purpose (legitimate interest: protection against spam and attacks).
- WhatsApp, Viber, Google, Facebook, Instagram: only if you tap a professional's corresponding button (those services' own terms then apply).
- Authorities: only when required by law.
We never sell or rent data. We use no advertising cookies or tracking tools.
- Browser push services (Google, Mozilla, Apple): if you turn on push notifications, we send them only an empty “signal” with no content; your device fetches the notification text directly from us.
- A professional's clients only see the quotes sent to them, through a secret link.
- Companies: see your public page like everyone else. If they invite you to a job you get a notification; nothing else is shared.
- Messages: visible only to the two participants. Our team reviews a conversation only if a participant reports it or to investigate abuse/fraud.
- Investigating attacks: for a suspicious IP we may consult public databases (e.g. ipinfo.io) to see its country or provider.
5. Transfers outside the EU
Some content services (e.g. Google, Cloudflare) may process your IP address outside the EU under the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses.
6. How long we keep data
- Account, page, jobs, reviews: while your account exists. Deleting your account permanently removes them, including your photos.
- Accounts never confirmed: may be deleted after 30 days.
- Contact requests: until the professional deletes them or their account is deleted.
- Failed log-ins: 24 hours. Rate-limit records: 2 days.
- Read notifications: up to 90 days.
- Confirmation/reset links: expire after 48 and 2 hours respectively.
- Subscription tax records: as required by tax law.
- “My projects” data (clients, projects, quotes): until the professional deletes it or their account is deleted. A quote link stops working when the quote is deleted.
- Devices for push notifications: until you turn them off, log out on that device or the browser subscription expires.
- Security history and firewall records: 180 days, then deleted automatically (after an account is deleted they are kept only for that period, for security reasons).
- Blocked IPs: until the block expires (usually 24 hours) or we lift it.
- Messages (chat): until your account or the other participant's account is deleted.
- A quote link expires automatically 6 months after the quote's validity date (or 1 year after issue if it has none) and stops working immediately if the quote is deleted. The link is unique, unguessable and not indexed by search engines.
- Email sending queue: up to 30 days after sending.
7. Your rights
You have the right of access, rectification, erasure, restriction, objection and portability, and to withdraw consent. Most can be done instantly from your account:
- Rectify: My account → Account details / Edit my page.
- Export (portability): My account → "Download my data".
- Erase: My account → "Delete account".
For anything else email admin@fixmate.mytaxconsultant.gr. We reply within one month. You may also lodge a complaint with the Hellenic Data Protection Authority (Kifisias 1-3, 115 23 Athens, www.dpa.gr).
- Sign-in history: My account → "Recent security activity" (also included in the data export).
- Objecting to newsletter emails: the "unsubscribe" link in every email or My account → Settings.
8. Security
We use password hashing (bcrypt), form protection (CSRF), log-in attempt limits, secure cookies and HTTPS. No system is 100% secure. If a breach affects you, we will inform you as required by law.
We also use optional two-step verification (mandatory for administrators), a firewall that automatically blocks malicious IP addresses, a security history, alerts for sign-ins from new devices and a daily integrity check of the site's files.
9. Minors
The service is intended for adults (18+). We do not knowingly collect data from minors.
10. Changes
If we make material changes to this policy, we will announce them on the site or by email.
Last updated: 28 Sep 2026