Legal
Privacy policy
This site collects very little, and this page says exactly what, why and for how long — in the order the GDPR asks the question.
Last updated 7 September 2026
Who is responsible
TWENTYONE WEST COAST TRVL STORIES SINGLE MEMBER P.C. is the data controller for the personal data described here. Registration details are at the foot of this page; write to hello@twenty-one.co for anything on this subject and it reaches the person who can act on it.
We have not appointed a Data Protection Officer — the scale of the processing described below does not require one under Article 37 GDPR.
What this policy covers
It covers twenty-one.co: the enquiry form, the journal subscription, the server logs and the one third-party script the site loads.
It does not cover the systems we build and run for clients. There, the client is the controller and we act as a processor on their written instructions under a data processing agreement; their own privacy notice governs, not this one.
What we collect, and on what basis
- Enquiry form
- Your name, company, email address and — if you fill them in — telephone number, the disciplines you have ticked, budget range, timeline and the message itself. Purpose: to read your briefing and reply to it. Legal basis: Article 6(1)(b) GDPR, steps taken at your request before entering into a contract; and, where you are writing on behalf of a company rather than as an individual, our legitimate interest in responding to business enquiries under Article 6(1)(f).
- Journal subscription
- Your email address, and a note of where you subscribed from. Purpose: to send you the journal. Legal basis: your consent under Article 6(1)(a) GDPR where you typed the address into the subscription field yourself; our legitimate interest in business-to-business direct marketing under Article 6(1)(f), read with Article 11(2) of Law 3471/2006, where the address reached us with a briefing. The section below sets out exactly what that means and how to end it.
- Server and delivery logs
- Your IP address and ordinary request metadata — time, page, browser, referring page — recorded by the web server, and by the rate limiter that stops the contact form being flooded. Purpose: keeping the site up, secure and abuse-free. Legal basis: our legitimate interest in the security and availability of the service, Article 6(1)(f).
- Meta Pixel
- A measurement script from Meta Platforms Ireland Ltd. It records that a browser viewed a page of this site, together with the identifiers and device information described in the cookie policy, and reports it to Meta — which may link it to a Facebook or Instagram account. Purpose: measuring whether our advertising reaches the right audience. Legal basis: your consent under Article 5(3) of the ePrivacy Directive and Article 6(1)(a) GDPR, asked for on the banner before anything is loaded and withdrawable at any time from Cookie settings in the footer, with Meta acting as joint controller for the reporting it performs. Decline and the script never runs.
We do not ask for special-category data, we do not buy lists, we do not build profiles of visitors, and there is no automated decision-making of any kind on this site.
The journal
The journal is a business-to-business publication: it goes to people at work, at a work address, about their professional field. We run no consumer marketing and we do not buy, rent, scrape or append lists. Every address on ours was given to us directly — either typed into the subscription field, which is consent, or left ticked on the contact form alongside a briefing, which is the business-relationship route Article 6(1)(f) GDPR and Article 11(2) of Law 3471/2006 allow.
Both routes end the same way: a one-click unsubscribe at the top of every issue, and erasure on request at hello@twenty-one.co. The full legal basis, and the balancing test behind it, is set out under "Direct marketing" on the GDPR page.
Who else processes it
Only the suppliers that make the site work, each under a contract that binds them to process on our instructions:
- Google Ireland Ltd
- Google Workspace carries the mailbox that receives enquiries, so your message is stored there as an email. Data held in the EU.
- Sendinblue SAS (Brevo)
- Holds the journal subscriber list and sends the emails. Data held in the EU (France).
- DigitalOcean LLC
- Hosts the site and its logs on a server in Frankfurt, Germany. Transfers to the United States, where the parent company is established, are covered by the European Commission's standard contractual clauses.
- Meta Platforms Ireland Ltd
- Receives the pixel measurements described above, and transfers them to the United States under the EU–US Data Privacy Framework and standard contractual clauses.
Beyond those, we disclose personal data only where the law obliges us to, or where it is necessary to establish or defend a legal claim — to our accountants, auditors or lawyers, under professional confidentiality. We never sell it.
How long we keep it
- An enquiry that does not become a project: kept for up to 24 months, so we can pick up the thread if you come back, then deleted.
- An enquiry that becomes a project: kept for the life of the engagement and then for as long as Greek tax and commercial law requires the records of it, currently five years from the end of the financial year.
- Journal subscription: until you unsubscribe, plus a suppression record of the fact that you did — that record exists precisely so we never email you again.
- Server and rate-limiter logs: days, not months. The rate-limiter window is one hour.
Your rights
Under the GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it or erase it, ask us to restrict how we use it, ask for it in a portable form, and object to processing we base on legitimate interests. Where processing rests on consent, you can withdraw that consent at any time — which does not affect what was done lawfully before you did.
Write to hello@twenty-one.co. We answer within one month, free of charge, and we will ask for enough information to be sure it is really you before we act.
If you think we have handled your data wrongly, please tell us first — but you also have the right to complain to the Hellenic Data Protection Authority, Kifissias 1–3, 115 23 Athens, +30 210 6475600, www.dpa.gr.
Security
The site is served only over TLS. Access to the mailbox and to the subscriber list is limited to the people here who need it and protected by two-factor authentication. The contact form is rate-limited and its inputs are sanitised. No system is perfectly secure; if a breach ever puts your rights at risk we will notify the Hellenic DPA and you, as Articles 33 and 34 require.
Children
This is a business site and it is not directed at children. We do not knowingly collect data from anyone under 15, the age of digital consent in Greece. If you believe a child has sent us something, tell us and we will delete it.
Changes
When what the site does changes, this page changes with it, and the date at the top moves. Material changes to processing that relies on your consent will be asked for again rather than assumed.
Questions about any of this go to hello@twenty-one.co, or 210 3000 463, or Plataion 55, 104 35 Athens, Greece. A named person reads that inbox — it is not a ticket queue.
Company details
- Registered name
- TWENTYONE WEST COAST TRVL STORIES ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
- In Latin characters
- TWENTYONE WEST COAST TRVL STORIES SINGLE MEMBER P.C.
- Legal form
- Single-member private company (Ι.Κ.Ε.) incorporated in Greece
- Registered office
- Plataion 55, 104 35 Athens, Greece
- Γ.Ε.ΜΗ. number
- 191601903000 — General Commercial Registry (Γ.Ε.ΜΗ.), Athens Professional Chamber
- VAT number
- EL803186370 (ΚΕΦΟΔΕ Αττικής)
- Manager
- Panagiotis Athanasakopoulos
- Contact
- hello@twenty-one.co · 210 3000 463