Privacy Policy

Last Updated: July 16, 2026

AGNÓDOS SINGLE MEMBER P.C. (“AGNÓDOS,” “we,” “our,” or “us”) is committed to protecting the privacy of our website visitors, customers, and pre-launch subscribers. This Privacy Policy explains how we collect, use, process, disclose, and safeguard your personal data in strict compliance with the General Data Protection Regulation (GDPR) [EU Regulation 2016/679], Greek Law 4624/2019, and the guidelines of the Hellenic Data Protection Authority (HDPA).

Please read this policy carefully. If you do not agree with any part of this Privacy Policy, please refrain from using our website or providing your personal data. By interacting with our website, subscribing to our launch list, or purchasing our products, you acknowledge and agree to the practices described herein.

1. Data Controller Information

The legal entity responsible for the processing of your personal data is:

  • Legal Corporate Name: AGNÓDOS ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
  • International Title: AGNÓDOS SINGLE MEMBER P.C.
  • General Commercial Registry (GEMI) No: 194842901000
  • Tax Identification Number (TIN/ΑΦΜ): EL803336340
  • Tax Office (ΔΟΥ): KEFODE Attikis
  • Registered Headquarters: Ermou 1, Metamorfosi Attikis, Postal Code 14452, Athens, Greece
  • Telephone: +30 210 220 3941
  • Primary Compliance Contact: info@agnodos.gr

2. Personal Data We Collect

We collect personal data directly from you when you interact with agnodos.gr, register for our pre-launch waitlist, or purchase our products. This data includes:

  • Identity & Contact Data: First name, last name, email address, telephone number, billing address, and shipping address.
  • Transaction & Financial Data: Order history, cart selections, and secure payment processing data. (Note: We do not store credit card details on our servers; all payments are processed securely by PCI-compliant third-party payment gateways).
  • Technical & Browsing Data: IP address, browser type, operating system, geolocation details, and data collected via cookies or tracking pixels.
  • Marketing & Communication Data: Your preferences in receiving updates, newsletter subscriptions, feedback, and customer support inquiries.

3. Purposes and Legal Bases for Processing

We process your personal data under the following legal bases of the GDPR:

  • Consent (Art. 6(1)(a) GDPR): To send you pre-launch updates, marketing newsletters (such as our "Founder's Batch" announcements), and promotional emails. You have the right to withdraw this consent at any time.
  • Performance of a Contract (Art. 6(1)(b) GDPR): To process and deliver your orders, manage your subscription plans, coordinate shipments with our logistics partners, and provide customer support.
  • Compliance with a Legal Obligation (Art. 6(1)(c) GDPR): To comply with statutory accounting and tax regulations in Greece, issue valid commercial invoices, and maintain our required registry files with GEMI.
  • Legitimate Interests (Art. 6(1)(f) GDPR): To maintain website security, prevent fraudulent transactions, analyze website performance, and optimize our direct-to-consumer user experience.

4. Security & Data Protection Measures

We implement rigorous technical, administrative, and physical security controls to safeguard your personal data against unauthorized access, loss, alteration, or disclosure. Our website utilizes secure socket layer (SSL) encryption for all transmitted data. Access to personal data is strictly limited to authorized personnel who require access to fulfill their professional duties.

5. Third-Party Data Disclosures & Subprocessors

We do not sell, rent, or trade your personal data. We share your data strictly with trusted service providers who enable our direct-to-consumer (D2C) business model under strict Data Processing Agreements (DPAs):

  • E-Commerce Platform: Shopify Inc. (hosting, website infrastructure, and checkout data processing). 
  • Email & Marketing Automation: Klaviyo / Mailchimp (management of pre-launch subscriber lists and transactional emails). All direct marketing utilizes double opt-in verification.
  • Fulfillment & Logistics: Our contract manufacturing and third-party logistics (3PL) partners based in Greece (for picking, packing, and dispatching your product orders).
  • Professional Services: Our registered Greek accounting and regulatory consulting partners.
  • Government & Law Enforcement: When required by law, we may disclose transaction records to the Hellenic National Organization for Medicines (EOF) or the Greek tax authorities (AADE).

6. Your Data Subject Rights

Under the GDPR, you have the following enforceable rights:

  • Right of Access: Request a copy of the personal data we hold about you. 
  • Right of Rectification: Request correction of inaccurate or incomplete personal data.
  • Right of Erasure ("Right to be Forgotten"): Request deletion of your data when it is no longer required for legal or contractual purposes.
  • Right to Restrict Processing: Limit how we process your data under specific conditions.
  • Right to Data Portability: Request a copy of your data in a structured, machine-readable format.
  • Right to Object: Object to processing activities based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Where processing is based on consent (such as email waitlist signups), you may withdraw consent at any time without penalty.

To exercise any of these rights, please contact our compliance desk directly at info@agnodos.gr. We will respond to your verified request within thirty (30) calendar days.

7. Cookies & Marketing Tracking

We use standard website cookies to improve your browsing experience, manage shopping cart memory, and analyze traffic. We will not use tracking pixels for social media custom marketing audiences unless you provide explicit opt-in consent through our site's cookie consent banner. For details on how we manage these technologies, please consult our separate Cookies Policy.

8. Regulatory Complaints & Supervisory Authorities

If you believe your data protection rights have been compromised, you have the right to lodge a formal complaint with the competent supervisory authority in Greece:

  • Hellenic Data Protection Authority (HDPA): Kifissias 1-3, PC 115 23, Athens, Greece (www.dpa.gr).