Legal
GDPR compliance
Where we stand under the General Data Protection Regulation: as the controller of this site, as the processor behind the platforms we build for clients, and in what we are entitled to send you.
Last updated 7 September 2026
The two hats we wear
TWENTYONE WEST COAST TRVL STORIES SINGLE MEMBER P.C. processes personal data in two distinct capacities, and the Regulation treats them very differently.
- Controller — this website and our own business
- Enquiries, the journal list, supplier and client contact records, server logs. We decide why and how these are processed, so the obligations of Articles 12 to 22 fall on us directly. The privacy policy is the notice required by Articles 13 and 14 for that processing.
- Processor — the platforms we build and run
- Every website, e-commerce system, application and database we deliver holds our client's data, not ours. The client is the controller; we act only on their documented instructions under a written data processing agreement meeting Article 28(3). We do not use client data for our own purposes, we do not mine it, and we do not carry it from one engagement into another.
The principles we work to
Article 5 sets six of them, and they are engineering constraints here rather than a statement of intent:
- Lawfulness, fairness and transparency — every collection point on this site says what it is for at the point it asks.
- Purpose limitation — an address given for a briefing is not repurposed into something unrelated.
- Data minimisation — the contact form asks for four required fields, because that is what a reply needs. We build client systems the same way: a field nobody uses is a liability, not a feature.
- Accuracy — corrections are made on request, and passed on to anyone we shared the data with.
- Storage limitation — everything has a stated retention period, and it is enforced rather than aspirational.
- Integrity and confidentiality — TLS everywhere, access on a need-to-have basis, two-factor authentication on every account that touches personal data.
Article 5(2) adds accountability: being able to demonstrate the above. We keep the record of processing activities required by Article 30, and the retention and access decisions behind it are written down rather than remembered.
Direct marketing: why we may write to you
The journal is a business-to-business publication, and it is sent lawfully. This is the part of the Regulation most often got wrong, so it is worth stating precisely.
It goes to people at work, at a work address, about their professional field. We run no consumer marketing. We do not buy, rent, scrape or append lists — every address on ours was given to us directly, by one of exactly two routes:
- Consent
- You typed your address into the subscription field yourself. That is the unambiguous affirmative act Article 4(11) GDPR requires, and the prior consent required by Article 11(1) of Greek Law 3471/2006.
- Legitimate interest, in a business relationship
- You sent us a briefing with the journal box — which sits in plain language immediately above the Send button — left ticked. Article 6(1)(f) GDPR permits processing necessary for our legitimate interests, and Recital 47 states in terms that processing for direct marketing purposes may be regarded as such. The balancing test comes out our way for a narrow set of reasons: the interest engaged is professional rather than private, the address was given to us for business correspondence about exactly this subject, the contact is one email a month, and refusing costs a single click. Article 11(2) of Law 3471/2006 — Greece's transposition of Article 13(2) of the ePrivacy Directive — permits the same thing on the electronic communications side, for an address obtained in the course of a business transaction, used for similar services, with a clear and free opportunity to object both when it is collected and in every message after.
Under Article 21(2) you may object to direct marketing at any time and for any reason, and unlike other objections it is absolute: there is no balancing exercise and no interest we may weigh against it. We honour it immediately.
Leaving, and being deleted
These are two different things and you are entitled to either. Both are free, neither requires a reason, and neither requires an account.
- Unsubscribe
- A one-click link at the top of every issue. No login, no confirmation step, no preference centre designed to slow you down. The address stops receiving the journal from that moment.
- Erasure, Article 17
- Write to hello@twenty-one.co and the address is deleted from our mailing platform and from our own records, within one month and normally within days. What remains is a suppression entry — the minimum note that this address must never be contacted again — kept for the sole purpose of making the erasure hold, which is what Article 21(3) requires of us.
The same applies to a briefing you have sent us. Ask and it is deleted, subject only to what Greek tax and commercial law obliges us to retain once an invoice exists.
Exercising your rights
Articles 15 to 22 give you the right to access the data we hold about you, to have it corrected, to have it erased, to restrict how it is used, to receive it in a portable machine-readable form, to object to processing based on legitimate interests, and to withdraw consent where consent is what we relied on.
Send the request to hello@twenty-one.co. There is no form to fill in and no fee. We answer within one month, as Article 12(3) requires, and if a request is genuinely complex we will tell you inside that month that we are extending it and why. We will ask for enough to be confident it is really you — no more.
If the data sits in a system we built for a client, we are the processor: we will pass the request to that client, who is the controller and the party that must answer it, and we will help them do so as Article 28(3)(e) obliges us to.
You may also complain to the Hellenic Data Protection Authority, Kifissias 1–3, 115 23 Athens, +30 210 6475600, www.dpa.gr — or to the supervisory authority of the EU country you live or work in. We would rather you came to us first, but the right is yours either way.
When we build for a client
What a client's procurement or legal team usually needs to know, in the order they usually ask it:
- We sign a data processing agreement on Article 28(3) terms before any personal data is touched — ours or yours, whichever your counsel prefers.
- We process only on documented instructions, and we say so if an instruction looks to us like it breaches the Regulation.
- Everyone with access is under a written duty of confidentiality that outlives the engagement.
- Sub-processors — hosting, mail delivery, error reporting — are named before they are used, and you may object to a new one.
- Data stays in the EEA by default. Where a specific tool requires otherwise, we say so before it is chosen, and it is covered by standard contractual clauses or an adequacy decision.
- We assist with data subject requests, with breach notification, and with any DPIA the system requires under Article 35.
- At the end of the engagement your data is returned or deleted, at your choice, and backups age out on a stated schedule.
- We do not subcontract development offshore. The people writing the code are in Athens, and personal data does not leave that boundary for the convenience of a cheaper resource.
Security and breaches
Article 32 asks for measures appropriate to the risk. On our own estate that means TLS on every connection, two-factor authentication on every account, least-privilege access, rate limiting and input sanitisation on public endpoints, dependency updates as routine work rather than as a project, and backups that are actually restored from time to time to prove they work.
If a breach occurs on our own systems we notify the Hellenic DPA within 72 hours where Article 33 requires it, and the people affected without undue delay where Article 34 does. If it occurs on a system we run for a client, we notify that client without undue delay so they can meet the same deadlines — the clock is theirs, and our job is not to burn it.
What we do not do
- No automated decision-making or profiling with legal or similarly significant effects, on this site or in what we send.
- No sale of personal data, ever, in any form, to anyone.
- No special-category data collected through this site.
- No dark patterns in the collection points: no pre-selected consent for tracking, no unsubscribe buried behind a login, no cost to saying no.
We have not appointed a Data Protection Officer, and are not required to: our core activity is building software, not large-scale monitoring or large-scale processing of special categories, so Article 37(1) does not bite. Responsibility sits with the manager named below, who answers the mail personally.
Questions about any of this go to hello@twenty-one.co, or 210 3000 463, or Plataion 55, 104 35 Athens, Greece. A named person reads that inbox — it is not a ticket queue.
Company details
- Registered name
- TWENTYONE WEST COAST TRVL STORIES ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
- In Latin characters
- TWENTYONE WEST COAST TRVL STORIES SINGLE MEMBER P.C.
- Legal form
- Single-member private company (Ι.Κ.Ε.) incorporated in Greece
- Registered office
- Plataion 55, 104 35 Athens, Greece
- Γ.Ε.ΜΗ. number
- 191601903000 — General Commercial Registry (Γ.Ε.ΜΗ.), Athens Professional Chamber
- VAT number
- EL803186370 (ΚΕΦΟΔΕ Αττικής)
- Manager
- Panagiotis Athanasakopoulos
- Contact
- hello@twenty-one.co · 210 3000 463