Who we are
Tandem Studios is a two-person design and build studio based in Athens, Greece, run by Manousos Vasilakis and Vaia Ladia. For the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR), Tandem Studios is the data controller for personal data processed through this website.
You can reach us about anything in this policy at manousosvasilakisdesign@gmail.com.
What data we collect
- Contact data you send us: name, email address, company, and anything you write in a message or brief.
- Client and project data: contact details of the people we work with, billing details, and files you share with us during a project.
- Technical data: IP address, browser type, device type, referring page and timestamps, recorded automatically in server logs.
- Analytics data: pages viewed, approximate location at city level and interaction events, collected only if you accept analytics cookies.
Why we process it, and on what legal basis
- To answer enquiries and prepare proposals: performance of a contract or steps taken at your request (Art. 6(1)(b) GDPR).
- To deliver projects, invoice and provide support: performance of a contract (Art. 6(1)(b)).
- To keep the site secure and functioning: our legitimate interest in operating a safe website (Art. 6(1)(f)).
- To understand how the site is used through analytics cookies: your consent (Art. 6(1)(a)), which you can withdraw at any time.
- To meet accounting and tax obligations: legal obligation (Art. 6(1)(c)).
Cookies and similar technologies
Essential cookies and local storage keep the site working and remember your cookie choice. They are set on the basis of our legitimate interest and are strictly necessary, so no consent is required for them.
Analytics cookies are only set after you actively accept them in the cookie banner. If you choose essential only, no analytics script is loaded and no analytics cookies are written.
You can change your decision at any time by clearing this site's data in your browser or by using the cookie settings link in the footer. You can also block or delete cookies through your browser settings.
Who we share data with
We do not sell personal data and we do not use it for advertising profiling. We share it only with service providers who process it on our behalf under a data processing agreement compliant with Art. 28 GDPR:
- Website hosting and content delivery providers.
- Email and productivity providers used to receive and answer your messages.
- Analytics providers, only where you have consented.
- Accountants, and authorities where we are legally required to disclose data.
International transfers
Some providers may process data outside the European Economic Area. Where that happens, transfers are covered by an adequacy decision of the European Commission or by the European Commission's Standard Contractual Clauses together with supplementary measures where needed. You can ask us for a copy of the safeguards in place.
How long we keep it
- Enquiries that do not become projects: up to 12 months after the last contact.
- Client and project records: for the duration of the engagement and up to 5 years afterwards, for warranty, portfolio and dispute purposes.
- Invoices and accounting records: as long as Greek tax law requires, currently up to 10 years.
- Server logs: up to 12 months.
- Analytics data: up to 14 months.
Your rights
Under the GDPR you have the right to access your data, to have it corrected or erased, to restrict or object to processing, to receive it in a portable format, and to withdraw consent at any time without affecting processing carried out before the withdrawal.
To exercise any of these rights, email manousosvasilakisdesign@gmail.com. We answer within one month. If you believe we handle your data unlawfully, you may lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or with the supervisory authority of your country of residence.
Automated decisions and children
We do not carry out automated decision-making or profiling that produces legal effects. This site is not intended for children under 16, and we do not knowingly collect their data.
Security and changes to this policy
We use encrypted connections (HTTPS), access controls and reputable providers to protect personal data. No method of transmission is perfectly secure, but we take reasonable technical and organisational measures as required by Art. 32 GDPR.
If we change this policy we will update the date at the top of this page, and for material changes we will make the update visible on the site.