Privacy and Personal Data Protection Policy
Written By noiz
Last updated 14 days ago
Website: noiz.gr Version: 2.0 Last modified: 9 August 2026 Effective from: 9 August 2026
1. Introduction and scope
1.1 This Privacy and Personal Data Protection Policy (the "Policy") describes how NETLAYER ("Noiz", "we", "us" or the "Company") collects, records, organises, stores, uses, transmits and otherwise processes the personal data of visitors, registered members and other users of the Platform.
1.2 The Policy applies to the website noiz.gr, its subdomains (including forum.noiz.gr and support.noiz.gr), the Progressive Web App and any related electronic service provided by Noiz (together, the "Platform").
1.3 The Platform operates as an intermediary service: it provides a technical environment in which users publish and search listings for musical instruments, equipment and related services. Noiz is not a party to the contracts concluded between users and does not act as seller, buyer, broker or guarantor of those transactions.
1.4 Processing is carried out in accordance with:
Regulation (EU) 2016/679 of the European Parliament and of the Council (General Data Protection Regulation – "GDPR");
Law 4624/2019 (measures implementing the GDPR and transposing Directive 2016/680);
Law 3471/2006 on the protection of personal data in the electronic communications sector, as in force;
the decisions, instructions and guidelines of the Hellenic Data Protection Authority and the European Data Protection Board as in force from time to time.
1.5 The Policy supplements and does not replace the Terms of Use of the Platform. In the event of a conflict on data protection matters, this Policy prevails.
1.6 Use of the Platform presupposes that you have read and understood this Policy. If you disagree with any of its terms, you must refrain from using the Platform.
2. Controller and contact details
2.1 The controller within the meaning of Article 4(7) GDPR is:
2.2 For any matter concerning the processing of your data and the exercise of your rights you may contact privacy@noiz.gr or write to the registered address above.
3. Definitions
For the purposes of this Policy, the terms "personal data", "processing", "data subject", "controller", "processor", "recipient", "consent", "personal data breach" and "pseudonymisation" have the meaning given to them in Article 4 GDPR. "Member" means a user who has created an account on the Platform and "Visitor" means a user who browses without an account.
4. Categories of data processed
4.1 Data you provide
Identification and account data: full name, username, email address, password (stored solely as a cryptographic hash), account type (private individual or professional), profile picture.
Contact data: telephone number, region/city, and any additional details you choose to publish on your profile or in your listing.
Content data: listing titles, descriptions, prices and technical specifications, photographs and videos, forum posts and comments, reviews, favourites and saved searches.
Member-to-member communications data: the content of messages you send through the Platform's contact forms.
Support data: the content of requests, complaints and reports you submit through the Help Centre or by email.
4.2 Data collected automatically
IP address, browser type and version, operating system, device identifiers, language, pages visited and time spent, referring website, date and time of access, server logs, and data collected through cookies and similar technologies (see Article 15).
4.3 Transaction data
History of purchases of promotion services and promoted listings, amount, currency, date, payment status, transaction identifier and billing details. Noiz does not collect, view or store full credit or debit card details; those details are submitted directly to the licensed payment service providers (see Article 7).
For the issuance of tax documents, your full name and email address are processed. Where an invoice is issued, additionally your business name, VAT number and address.
4.4 Data from third-party services
If you choose to sign in using a Facebook, Google, Apple or X account, we receive from the relevant provider the data you have approved for sharing, as a rule your full name, email address, public user identifier and profile picture. That collection is also governed by the privacy policy of the provider concerned.
4.5 Special categories of data
Noiz does not request or seek to collect special categories of data within the meaning of Article 9 GDPR (including health data, biometric data, political opinions, religious beliefs, trade union membership, sexual orientation), nor data within the meaning of Article 10 GDPR. Please do not include such data in your listings, profile or messages. Any voluntary publication of such data is made on your own initiative and responsibility.
5. Purposes of processing and legal bases
We process your data solely for specified, explicit and legitimate purposes, on the following legal bases:
5.2 Where processing is based on your consent, that consent is given freely, expressly and by clear affirmative action, and may be withdrawn at any time without justification, without affecting the lawfulness of processing carried out before withdrawal.
5.3 Where processing is based on a legitimate interest, the Company has previously balanced that interest against your rights and freedoms. You have the right to object under Article 21 GDPR (see Article 11 of this Policy) and, upon request, you may receive information about that balancing exercise.
5.4 Creating an account requires as mandatory your full name, email address and password; without these, registration is not technically or contractually possible. Purchasing promotion services additionally requires the billing details referred to in paragraph 4.3, which are necessary both for the performance of the contract and for compliance with tax legislation. Any other item (including telephone number, profile picture, region, details you publish in your listing) is provided optionally, at your discretion, and failure to provide it does not affect your ability to use your account.
6. Public nature of certain data
6.1 The Platform is public by nature. Your listings, displayed username, profile picture, general region, photographs and public forum posts are visible to every visitor and may be indexed by search engines and reproduced by third parties beyond our control.
6.2 Please do not publish in your listings, photographs or profile any data that you do not wish to become public, nor data relating to third parties without their express consent.
6.3 All uploaded photographs carry a watermark, as a measure to limit their unauthorised reproduction by third parties. That measure does not prevent the technical possibility of copying them.
6.4 The content of messages you exchange privately with other members is not publicly accessible, but may be reviewed by our administration in the context of investigating a complaint, a security incident or a request from an authority.
7. Recipients of the data
7.1 Noiz does not sell, rent or trade personal data. Access to your data is limited to:
Our authorised personnel and associates (administrators, moderators, technical support), strictly to the extent required for the performance of their duties and under an obligation of confidentiality.
Infrastructure and hosting providers (Datapacket, Cloudflare), as processors under a contract pursuant to Article 28 GDPR.
Payment service providers: Stripe Payments Europe, Ltd. and PayPal (Europe) S.à r.l. et Cie, S.C.A. These providers act as independent controllers in respect of payment data and apply their own privacy policies.
Email and notification service providers (Postmark), as processors.
Customer service and knowledge base providers (Featurebase), as processors.
Statistical analysis providers (Google Analytics), where you have consented to the relevant cookies.
Third-party authentication providers — Meta Platforms Ireland Ltd., Google Ireland Ltd. and X Internet Unlimited Company (formerly Twitter International Unlimited Company) — where you choose to sign in through their services. These providers act as independent controllers in respect of the data they themselves hold.
Epsilon Net S.A., as a processor acting on our behalf, for the issuance and dispatch of tax documents and their transmission to the Independent Authority for Public Revenue through the myDATA platform. Epsilon Net does not use those data for its own purposes or for marketing.
The Independent Authority for Public Revenue, pursuant to tax legislation.
External legal, accounting and tax advisers, within the scope of their duties and under professional secrecy.
Public authorities, judicial authorities and independent authorities, where a corresponding legal obligation or lawful request exists.
7.2 A written contract pursuant to Article 28 GDPR has been concluded with each processor, under which it undertakes to process the data solely on our instructions, to maintain confidentiality and to implement appropriate technical and organisational security measures.
7.3 In the event of a merger, acquisition, transfer of business or reorganisation, the data may be transferred to the successor entity, which will be bound by the same terms. You will be informed in good time of any such change.
8. Transfers to third countries
8.1 As a rule your data are held and processed within the European Economic Area (EEA).
8.2 Some of the above providers may process data in third countries, in particular the United States of America. In such cases the transfer is carried out only where one of the safeguards under Chapter V GDPR applies, namely:
an adequacy decision of the European Commission under Article 45 GDPR (including the EU–US Data Privacy Framework for certified organisations); or
standard contractual clauses approved by the European Commission under Article 46(2)(c) GDPR, accompanied by supplementary technical and organisational measures where required.
8.3 A copy of the safeguards applied is available on request at the address given in paragraph 2.2.
9. Retention periods
9.1 We retain your data only for as long as is necessary to fulfil the purposes set out in Article 5, unless a longer period is required by law.
9.2 After the above periods have elapsed, the data are securely deleted or irreversibly anonymised so that you can no longer be identified.
9.3 Data that are the subject of pending litigation, a complaint or an investigation by a competent authority are retained until its final conclusion.
10. Security of processing
10.1 We implement appropriate technical and organisational measures under Article 32 GDPR, taking into account the state of the art, the costs of implementation and the nature, context and purposes of the processing, as well as the risks to your rights and freedoms. These include:
encryption of communications using the TLS/HTTPS protocol;
storage of passwords solely using a modern salted cryptographic hashing algorithm;
role-based access control and the principle of least privilege;
regular backups and a recovery plan;
log keeping and monitoring for the detection of unusual activity;
periodic review and updating of security measures.
10.2 Notwithstanding the above, no transmission of data over the internet and no storage system is entirely secure. Noiz does not guarantee absolute security and is not liable for damage attributable to events beyond its control, in particular malicious acts by third parties, provided it has exercised due diligence and taken the measures indicated by law.
10.3 You must keep your password confidential, not disclose it to third parties, and notify us without undue delay if you suspect unauthorised access to your account.
10.4 In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority without undue delay and, where feasible, within seventy-two (72) hours of becoming aware of it, under Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also inform you without undue delay, under Article 34 GDPR.
11. Your rights
11.1 As a data subject you have the following rights:
11.2 The rights to erasure and restriction are not absolute. They do not apply, in particular, where processing is necessary for compliance with a legal obligation (for example, retention of tax documents for completed financial transactions), for the establishment, exercise or defence of legal claims, or for the exercise of the right to freedom of expression and information.
12. Exercising your rights and account deletion procedure
12.1 Submitting a request. You may exercise your rights by request to privacy@noiz.gr or in writing to the Company's registered address. For your protection we may request additional information to verify your identity.
12.2 Time limit. We respond without undue delay and in any event within one (1) month of receipt of the request. That period may be extended by a further two (2) months, taking into account the complexity and number of requests; in that case we will inform you within the first month of the extension and the reasons for it.
12.3 Cost. Exercising your rights is free of charge. Where requests are manifestly unfounded or excessive, in particular because of their repetitive character, the Company may either charge a reasonable fee or refuse to act on the request, under Article 12(5) GDPR.
12.4 Self-service – account deletion. You may request deletion of your account and your personal data directly from your account settings at https://noiz.gr/my-profile/, by selecting "Deletion request".
12.5 Time to completion. Following submission and confirmation of the deletion request, your account is deactivated immediately and your publicly accessible profile and listings are withdrawn from the Platform within twenty-four (24) hours. Within the same period the remaining data of your account are deleted, subject to the following limited categories, which are retained for the periods set out in Article 9 and deleted thereafter:
data we are required to retain by law, in particular documents relating to completed transactions (Article 6(1)(c) GDPR);
logs, basic identifiers and breach history, retained for a limited period on the basis of our legitimate interest in the security of the Platform and in preventing re-registration by banned users (Article 6(1)(f) GDPR); you have the right to object under Article 21 GDPR;
messages you have sent to other members, to the extent they form part of the recipient's correspondence;
data necessary for the establishment, exercise or defence of legal claims, or for addressing a pending security or abuse incident;
correspondence relating to the deletion request itself, as evidence of compliance under the accountability principle (Article 5(2) GDPR);
anonymised or aggregate data, which no longer permit your identification and do not constitute personal data.
12.6 Consequences of deletion. Deletion of the account is final and irreversible and entails loss of access to your listings, favourites, history and messages.
13. Right to lodge a complaint with the supervisory authority
13.1 If you consider that the processing of your data infringes applicable legislation, you have the right to lodge a complaint with the competent supervisory authority, without prejudice to any other administrative or judicial remedy:
Hellenic Data Protection Authority Kifissias Avenue 1–3, 115 23 Athens, Greece Telephone: +30 210 6475600 · Fax: +30 210 6475628 Email: contact@dpa.gr Website: https://www.dpa.gr
13.2 We encourage you to contact us first, so that we may resolve the matter directly.
14. Minors
14.1 The Platform is intended exclusively for adults, that is, persons who have reached the age of eighteen (18). This restriction is not based on a data protection provision, but on the fact that creating an account and using the services constitute the conclusion of a contract and presuppose full legal capacity under Articles 127 et seq. of the Greek Civil Code. Registration by minors is not permitted under the Terms of Use.
14.2 For clarity, Article 8 GDPR and Article 21 of Law 4624/2019, which set the age threshold of fifteen (15) years for the provision of valid consent to information society services, apply solely where processing is based on consent (Article 6(1)(a) GDPR). Since the creation and operation of your account is based on the performance of a contract (Article 6(1)(b) GDPR), those provisions do not constitute the legal basis for the age limit in paragraph 14.1.
14.3 We do not knowingly collect data relating to minors. If it is established that an account has been created by a minor, the account is deactivated and the relevant data deleted without undue delay, unless there is a lawful ground for retaining them. Parents or guardians who become aware of such a case are asked to contact us at the address given in paragraph 2.2.
15. Cookies and similar technologies
15.1 What cookies are. Cookies are small text files that a website stores on your computer or mobile device when you visit it. They allow the website to "remember" your actions and preferences (such as login details, language, font size and other display settings) for a period of time, so that you do not have to re-enter them on each visit or page.
15.2 Categories of cookies we use.
15.3 Consent. With the exception of strictly necessary cookies, the placing and reading of cookies requires your prior express consent, given through the relevant pop-up tool on your first visit.
15.4 Withdrawal and management. You may withdraw or modify your consent at any time, including through your browser settings, where you can delete or block cookies. Disabling strictly necessary cookies may render part of the Platform non-functional.
15.5 The cookies used by the sign-in system do not contain the details you enter on the Platform and serve solely to maintain the session and improve your browsing experience.
16. Automated decision-making and profiling
16.1 Noiz does not take decisions producing legal effects or similarly significantly affecting you based solely on automated processing, within the meaning of Article 22 GDPR.
16.2 Automated filters are used to detect spam, duplicate or infringing listings and suspicious activity. Any measure with a material consequence for your account (such as suspension or banning) is subject to human review, and you have the right to express your point of view and to request a review at the address given in paragraph 2.2.
17. Newsletters and commercial communications
17.1 We send newsletters and commercial communications only where you have given your express consent, or where the conditions of Article 11(3) of Law 3471/2006 are met (communication to existing customers regarding similar products or services).
17.2 Every such message includes a clear and free means of unsubscribing (opt-out). You may also manage your preferences from your account settings.
17.3 Operational notifications (registration confirmation, password reset, updates concerning your listings and transactions, security alerts and notices of changes to the Terms of Use or this Policy) are necessary for the provision of the service and do not constitute commercial communications; they cannot be disabled while your account remains active.
18. Links to third-party websites
The Platform may contain links to third-party websites and services. Noiz does not control and is not responsible for the content, privacy practices or security of those websites. We recommend that you review the relevant privacy policies before providing your data.
19. Amendments to this Policy
19.1 The Company reserves the right to amend this Policy, in particular in order to comply with changes in legislation, case law, the guidelines of supervisory authorities or the services provided.
19.2 The version in force from time to time is published at https://noiz.gr/privacy-policy/ with an indication of the date of last amendment.
19.3 In the event of a material amendment, you will be informed by appropriate means (including by email or by a prominent notice within the Platform) at least 3 days before it takes effect. Where the amendment requires fresh consent, that consent will be requested again.
20. Governing law and jurisdiction
20.1 This Policy is governed by Greek law and the law of the European Union.
20.2 This Policy constitutes an information notice under Articles 13 and 14 GDPR and does not constitute a contract; it therefore contains no choice-of-forum clause. Under Article 79(2) GDPR, you have the right to bring proceedings eitherbefore the courts of the Member State where the Company is established or before the courts of the Member State of your habitual residence. The right to compensation under Article 82 GDPR and the right to lodge a complaint under Article 13 of this Policy are unaffected.
20.3 If any provision of this Policy is held to be invalid or unenforceable, that invalidity does not affect the validity of the remaining provisions.
This Policy was drafted in the Greek language. Any translations are provided for the convenience of users; in the event of divergence, the Greek text prevails.