Privacy Policy

Last updated: September 17, 2026

This Privacy Policy explains what personal data PageOn ("PageOn", "we", "us") collects through https://pageon.eu (the "Service"), why, for how long, and what rights you have over it — in line with Regulation (EU) 2016/679 ("GDPR") and Greek Law 4624/2019.

1. Who is the data controller

Eleni Filippi, VAT EL158918275, registered at Kourtaki 0, Argos, Argolida, Greece, Greece ("the Company"), operating PageOn. For anything relating to this policy, contact us at hello@pageon.eu. The Company has not appointed a formal Data Protection Officer (DPO) — the contact above handles all data-protection requests directly.

2. What data we collect

2.1 Account data

When you register, we store your name, email address, and a securely hashed password (we never store or can see your actual password). We also generate a public slug for your account, used in your public profile URL.

2.2 The PDF files you upload

The original file you upload is used only to produce the version the Service actually serves: it is processed (compressed, split into page images for the viewer, its text extracted for search) in a temporary working directory that is deleted once processing finishes. Whether the original itself is kept afterwards depends on your plan:

  • Free / Pro: the original is not retained once a viewable version exists — only the processed file and page images are kept.
  • Business (or Pro with "allow original download" enabled): the original is kept alongside the processed version, specifically so it can be offered as a download.

The processed file, page images, extracted page text, and any title/description/pins/ bookmarks you add are kept for as long as the document exists in your account, on access-controlled storage that is not directly reachable by URL — the Service's own access rules (public/private, password, expiry) are what decide whether a request for a given file is served.

2.3 Document passwords and expiry

If you set a password on a document, it is stored hashed, the same way your account password is — we cannot recover or view it. If you set an expiry date, the document stops being served once that date passes.

2.4 Payment and billing data

Card payments themselves are handled entirely by our payment processor, Viva Payments S.A. ("Viva Wallet") — we never receive or store your card number. We do store the outcome: which plan you paid for, the amount, currency, Viva's order/transaction reference codes, and the payment's status and date. If you ask for a VAT invoice instead of a plain receipt, we additionally store the company name, VAT number, tax office, and address you provide for that purpose. Receipts and invoices themselves are issued manually and sent to you by email with the document attached; they are also listed in your payment history for you to download again at any time.

2.5 Usage & analytics data

For each document you publish, we count total page views, a separate count of unique visitors, per-page view counts, search-result hit counts, and pin hover/click counts — purely as aggregate numbers, to give you insight into how your documents are used. We deliberately do not build visitor profiles or track anyone across documents or sessions. The "unique visitor" count works without cookies or accounts: for 24 hours after a first visit, we keep a one-way cryptographic hash of that visitor's IP address, browser type, and the document ID in a short-lived cache entry, purely to recognize "this is the same visitor viewing again" — the hash cannot be reversed back into an IP address, is never stored in a database or log we keep, and is automatically discarded after 24 hours.

2.6 Cookies

The Service uses only strictly necessary cookies: a session cookie that keeps you logged in, and a CSRF-protection cookie that guards form submissions against forgery. Neither is used for advertising, cross-site tracking, or building a profile of you, and under Greek/EU e-privacy rules neither requires cookie-banner consent, since both are strictly necessary for the Service you've asked to use. We do not use third-party analytics or advertising cookies.

2.7 Communications

If you contact us through the Contact page, we receive your name, email, and message to be able to reply. We also send transactional emails tied to your use of the Service: email verification, password reset, renewal reminders before a paid plan expires (10, 3, and 1 day out), a notice once a plan actually lapses, and payment receipts/invoices. None of these are marketing emails, and none require separate opt-in — they exist to run the Service you're using.

3. Why we process this data (legal basis)

  • Performance of a contract (Art. 6(1)(b) GDPR) — creating your account, hosting and serving your documents, processing payments, sending the transactional emails above.
  • Legal obligation (Art. 6(1)(c)) — retaining payment/invoice records for the period Greek tax law requires.
  • Legitimate interest (Art. 6(1)(f)) — the aggregate, non-identifying usage analytics described in §2.5, and keeping the Service secure and abuse-free.
  • Consent (Art. 6(1)(a)) — only where you actively choose to provide something extra, such as invoice/VAT details.

4. Who we share data with

We don't sell your data. It's shared only with the processors that make the Service work:

  • Viva Payments S.A. ("Viva Wallet") — processes card payments (PCI-DSS certified, EU-based).
  • Our hosting provider — stores the application, database, and your files.
  • Our email delivery provider — sends the transactional emails described in §2.7.

Where any of the above is located outside the European Economic Area, we rely on the appropriate safeguard under Chapter V GDPR (e.g. Standard Contractual Clauses) before any data is transferred there.

5. How long we keep it

  • Account data: until you delete your account.
  • Original uploaded file: deleted after processing on Free/Pro (see §2.2); retained alongside the processed version on Business/Pro-with-original-download.
  • Processed document, page images, pins, bookmarks: until you delete the document.
  • Unique-visitor fingerprint hash: 24 hours, automatically.
  • Payment/invoice records: retained for the period required under Greek tax law (currently five years from the end of the relevant tax year), even after account deletion — this is a legal obligation, not a choice.
  • Contact-form messages: kept only as long as needed to handle your enquiry.

6. Your rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate data — most account fields you can already edit yourself.
  • Erase your account and data ("right to be forgotten") — you can delete your account yourself from your Profile page at any time, which removes your account and all your documents; payment records are kept only as long as §5 requires by law.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα, www.dpa.gr) if you believe your rights have been violated.

To exercise any of these rights, email hello@pageon.eu. We respond within one month, as required by Art. 12(3) GDPR.

7. Public documents and links

PageOn works on a link-sharing model: a document is either private (visible only to you) or public. A public document is viewable by anyone who has its link — it is not further access-controlled unless you also set a password — and, if marked public, is also listed on your public profile page. If a document you upload contains personal data belonging to someone else, you are responsible, as the uploader, for having a lawful basis to share it and for setting it private or password-protected if it shouldn't be openly accessible.

8. Security

Passwords (both account and document passwords) are stored using one-way hashing, never in plain text. The Service is served over HTTPS. Files are stored on access-controlled storage, not a publicly browsable location — a request for a given file is only served after the Service's own access checks (ownership, public/private, password, expiry) pass. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.

9. Children

The Service is not directed at, and not knowingly used by, anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.

10. Changes to this policy

We may update this policy as the Service changes. The date at the top shows the last revision; material changes will be communicated by email or a notice on the Service.

11. Contact

Questions about this policy or your data: hello@pageon.eu.