Privacy Policy
Last updated: July 10, 2026
This Privacy Policy describes how the GREEK LIFESAVING SPORTS ASSOCIATION ("we", "us", or "our") collects, uses, and processes personal data of visitors and registered users of the Leucothea platform, accessible from https://www.leucothea.app, in compliance with the General Data Protection Regulation (GDPR).
Data Controller & Children's Privacy
The entity responsible for processing your personal data is:
Name: GREEK LIFESAVING SPORTS ASSOCIATION
Address: PO Box 30015, PC 19001, Kouvaras, Municipality of Saronikos, Greece
Email: elagreece@gmail.com
Data We Collect and Why
A. Account Information (Provided by You or Your Parent/Coach)
When an account is created to join the Leucothea Community, we collect: First name, Last name, Email address, Nationality, Country of Residence, Date of Birth, and Gender. Passwords are encrypted automatically via our database servic provider.
- Purpose: To manage the user profile, generate personal certificates, and provide access to the platform's educational materials.
- Legal Basis: Performance of a Contract / Terms of Service (Article 6(1)(b) GDPR).
B. Technical & Usage Data (Collected Automatically)
When you browse our platform, our infrastructure automatically processes technical logs: Internet Protocol (IP) address, browser type, and timestamps.
- Purpose: To ensure network security, database integrity, and prevent fraudulent account creations.
- Legal Basis: Legitimate Interest (Article 6(1)(f) GDPR).
Data Processors & International Data Transfers
We do not sell, rent, or share personal data with any third-party marketing companies. To host and operate our website, we use trusted third-party infrastructure providers acting as Data Processors on our behalf:
- Supabase Inc. (Database and Authentication)
- Vercel Inc. (Frontend Hosting)
To comply with GDPR requirements for international transfers (as these entities are US-based), we ensure that these transfers are protected by appropriate safeguards, including Data Processing Addendums (DPAs) incorporating Standard Contractual Clauses (SCCs) approved by the European Commission and/or compliance with the EU-U.S. Data Privacy Framework.
Cookies and Local Storage
We use exclusively strictly necessary functional session tokens (managed via Supabase Auth) solely to keep you logged in and secure your session. These do not track your behavior across the web and do not require prior consent under the ePrivacy Directive.
Data Retention
- Account Data: Retained for as long as the account remains active. Upon account deletion requests, data is permanently removed from our active databases within 30 days.
- Server Logs & IP Addresses: Retained for security monitoring and troubleshooting for a maximum of 90 days, after which they are automatically deleted or anonymized.
Your Rights Under GDPR
As an EU resident, you (or your parents/legal guardians if you are a minor) possess the following rights:
- Right of Access & Rectification: To view or update your profile data.
- Right to Erasure: To request total deletion of your account.
- Right to Restrict Processing: To request that we limit how we use your data.
- Right to Object: To object to the processing of your data based on our Legitimate Interests (such as server logs).
- Right to Data Portability: To receive your data in a structured, machine-readable format.
Note on Automated Decisions: We do not use automated decision-making or profiling on this platform.
Right to Lodge a Complaint
If you believe that our processing of your personal data infringes on the GDPR or Greek data protection laws, you have the right to file a complaint with the supervisory authority.
Supervisory Authority: Hellenic Data Protection Authority (HDPA)
Address: Kifissias 1-3, PC 115 23, Athens, Greece
Website: http://www.dpa.gr
Email: contact@dpa.gr
To exercise any of these rights, please contact us at: elagreece@gmail.com