Privacy Policy
Last updated: 6 July 2026
1. Controller
The controller for data collected by the Coffr Platform is CANNA AMS Single Member P.C. (see Imprint & Company Identity). Privacy contact: menidi@gmail.com. No Data Protection Officer (DPO) has been appointed; please direct any personal-data matter to the address above.
2. Whose data, and our role
- Members/payers (parents/guardians): Coffr processes your data to collect dues on behalf of the Club. For member data, the Club is generally the controller and Coffr acts as processor (under a GDPR Art. 28 DPA).
- Minors: the minor is a linked beneficiary; the account holder/payer is the adult. Greece's digital consent age of 15 is taken into account.
3. Data categories
Payer name, contact details (phone/email), minor beneficiary's name, dues and payment details, technical data (IP, timestamp, device/session identifiers), and the consent/mandate record. We do not store full card details — these are handled solely by Viva.com.
4. Legal basis
- Performance of contract / legitimate interest for processing and collecting dues and for transactional SMS to existing members (with an opt-out).
- Consent for promotional messages or Viber messages where required by channel policy (opt-in) — revocable at any time.
- Legal obligation for retaining fiscal documents/receipts.
5. Recipients / processors
- Viva.com — payment provider; an independent/separate controller for payment-execution data (a regulated institution, not a sub-processor).
- Yuboto / Octapush — SMS/Viber delivery (sub-processor, ISO 27001).
- Clerk — authentication/accounts (sub-processor).
- Convex, Vercel — hosting/infrastructure (sub-processors).
6. International transfers
We aim to keep data within the EU/EEA. Where a transfer outside the EEA is required, appropriate safeguards (e.g. Standard Contractual Clauses) apply.
7. Retention
Data is kept as long as necessary for its purpose. Fiscal/accounting documents and numbered receipts are retained for the statutory period (as a rule 5–6 years), and this obligation overrides an erasure request for those records (GDPR Art. 17(3)(b)).
8. Your rights
You have rights of access, rectification, erasure, restriction, objection, and portability, and to withdraw consent. Requests: menidi@gmail.com. You may also lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
9. Security
We apply encryption in transit and at rest, least-privilege access, and an immutable audit log of money and consent actions.