Privacy Policy
Version 2.1 ·
In force from Sep 28, 2026
sha256:e1e5b8897c19
This policy explains what personal data we hold, why we hold it, and what you can do about it. It applies to everything we operate (see section 2) and it covers two quite different groups of people:
- people who use our services: visitors, registered users and subscribers (sections 4 to 6);
- people who appear in the information we publish: public office-holders, and named individuals who appear in public registers (section 7).
If you are in the second group and you have found your own name on one of our sites, section 7 is the part you want, and you do not need an account to exercise any of your rights.
1. Who is responsible for your data
The controller of the personal data described in this policy is:
| Controller | Seeders IKE ("Seeders") |
| Registered office | 49 Perikleous Street, 154 51 Neo Psychiko, Greece |
| Company registration (GEMI) | 140912101000 |
| Data protection contact | support@seeders.gr |
| General contact | support@seeders.gr |
2. What this policy covers
- euinstitutions.eu: our free public reference on the institutions, bodies and funding instruments of the European Union, most of which you can use without an account;
- id.euinstitutions.eu: our identity service, which we are introducing as the single place where accounts are created and sign-ins happen;
- every vertical service we run on the same platform, including signal-app.thyreon.eu, and any other host we add later.
One policy, one controller, one account. Because you register once and that account works across all of our services, your account data is held once and shared between them. It is the same company holding it throughout.
This policy does not cover other websites we link to. It also does not cover thyreon.eu and the Thyreon Signal marketing site, which have their own notices.
We are not an EU body. Seeders IKE is a private company, and this service is not published, endorsed or approved by the European Union or by any EU institution, body, office or agency. We say so here as well as in the Terms because it matters most to the people described in section 7, who did not choose to appear on a site they may reasonably assume is official.
3. The short version
- You can use the public pages of euinstitutions.eu without an account.
- We use strictly necessary cookies to make the site work. Those do not need your consent and cannot be switched off.
- We are introducing Google Analytics, and only with your consent. It is not running yet. When it goes live the banner asks first, and if you say no, or ignore it, it never runs. We will run no analytics of our own alongside it.
- Marketing is always opt-in, always separate, and refusing it never reduces your access.
- We never sell personal data, and we never use the names of people who appear in our data for marketing or sales.
4. If you visit without an account
What we collect. When you load a page, our servers automatically receive and record your IP address, the page you asked for, the date and time, your browser and device type, the page that referred you, and whether the request succeeded. We also set the strictly necessary cookies described in our Cookie Policy.
Why, and on what basis. To deliver the pages you asked for, keep the service running, and protect it against attack, scraping and abuse. Our lawful basis is our legitimate interests (Article 6(1)(f) GDPR) in operating and securing a service we make available to the public.
How long. Web server and security logs are kept for 12 months, then deleted. Where a log is part of an active investigation into abuse or a security incident, we keep it until that is closed.
5. If you have an account
5.1 What we hold
| Category | What it is |
|---|---|
| Identity | Your name and email address. If you set a password, we store only a hashed form of it, never the password itself. |
| Sign-in with a third party | If you sign in with Google, Microsoft, Apple, GitHub or Facebook, we receive from them your name, email address and an identifier so we can recognise you next time. We do not receive your password, and we do not post anything or read anything else from those accounts. |
| Organisation and access | The organisation you belong to, your role in it, your plan and what it entitles you to, and your seat. |
| What you build in the service | Your saved searches, watchlists and follows, your own private tags and notes, and your settings. |
| Alerts and notifications | Your notification preferences and alert keywords, and a record of what we sent you and when. |
| Acceptance and consent records | Which version of the Terms and this policy you accepted, the exact wording shown to you, and when, and the same for any optional consent you gave or withdrew. |
| Security records | Sign-in times, IP addresses and devices used to sign in, failed sign-in attempts, and password or email changes. |
| API access | Where you use our API or connect an AI client, the tokens issued to you and a record of the requests made with them. |
| Billing | For paid plans: your billing name and address, VAT number, what you bought, invoices and payment history. We do not receive or store your full card number: our payment provider handles the card itself. |
| Support | Messages you send us and our replies. |
5.2 Why we hold it, and on what basis
| What we do with it | Lawful basis |
|---|---|
| Create and run your account, sign you in across our services, give you the access you are entitled to, and deliver the searches, watchlists, monitoring and alerts you set up | Contract (Art. 6(1)(b)): this is the service you asked us for |
| Take payment, invoice you, and keep accounting records | Contract, and legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Keep the service secure: detect and prevent unauthorised access, abuse, scraping and fraud, and enforce our Terms | Legitimate interests (Art. 6(1)(f)) in protecting the service, our users and ourselves |
| Send you service messages: security alerts, changes to the Terms, billing notices, and things you must know to keep using the service | Contract, and legitimate interests in administering the relationship. These are not marketing and you cannot unsubscribe from them while you hold an account |
| Run Google Analytics, and any other third-party analytics or advertising technology | Consent (Art. 6(1)(a)), and consent under the ePrivacy rules for the cookies involved |
| Send you marketing about our products, events and updates | Consent (Art. 6(1)(a)), except where we may lawfully email an existing customer about similar products, and then always with an unsubscribe link |
| Deal with legal claims, comply with the law, and respond to lawful requests from authorities | Legal obligation, and legitimate interests in establishing or defending legal claims |
5.3 Two things we want to be explicit about
Accepting our Terms is required. Consenting to optional analytics or marketing is not. You must accept the Terms of Use to hold an account: that is the contract under which we give you the account. You do not have to accept optional cookies or marketing, and if you refuse them your access to the service is exactly the same. We will not degrade, limit or nag your account because you said no.
Withdrawing marketing consent never switches off your alerts. The follows, watchlists, monitoring and digests you set up are the service you asked for, not our marketing. They are separate switches in our systems, deliberately, so that turning one off cannot turn the other off by accident.
6. Cookies, analytics and measurement
Full detail is in our Cookie Policy. In summary:
6.1 Strictly necessary cookies keep you signed in, protect forms against cross-site request forgery, balance load, and remember your cookie choices. They do not require consent and you cannot turn them off through us, because the service does not work without them.
6.2 Analytics: announced, not yet running. We are introducing Google Analytics, delivered through Google Tag Manager, to understand how our sites are found and used. It will involve cookies and will send data to Google, and Google will act as our processor, with data possibly processed outside the EU, see section 10. We will run no analytics of our own alongside it.
It is not live today. There are no third-party analytics, advertising or tracking cookies on these sites at the moment, and no measurement technology beyond the strictly necessary cookies above and our own server logs (section 4).
It will run only if you consent. We describe it here, in advance, so that the banner is not the first you hear of it. Nothing is set or sent while you have not answered, refusing is as easy as accepting, refusing costs you nothing, and you can change your answer at any time from the link in the footer.
7. If you appear in the information we publish
Our services aggregate information published by European Union institutions, by national company registers and by other public sources. Most of it is about organisations, which is not personal data. Some of it is about people, and this section is about that.
7.1 Public office-holders
We publish who holds, or held, which public office in EU institutions, bodies and agencies, name, official title, the body and unit, and the dates. It comes from official EU publications, principally EU Whoiswho, published as open data by the Publications Office of the European Union.
We hold only facts about the office. We do not hold contact details, photographs, dates of birth, family information, home addresses, or any assessment of a person's performance or influence, and we do not build biographies from news or social media.
Our basis is legitimate interests (Art. 6(1)(f)): the public interest in the transparency and accountability of public administration, which is the purpose for which the EU publishes the directory itself. We assessed this in writing before publishing, including whether the interests of the individuals concerned should override it.
We never use these names for marketing, sales or outreach, we do not sell them, we do not offer them as an export or a contact list, and you cannot follow an individual person on our sites, only a body.
7.2 Named individuals in company registers and other public sources
When we aggregate national company registers and EU funding and procurement records, some of what they contain is personal data even though it is filed about a business:
- sole traders and self-employed people, whose business name is their own name;
- company officers, directors and legal representatives, where a register publishes them;
- named contact points published in a tender or funding record;
- people named in news articles and official documents we collect as evidence for the facts we record.
We hold this because it is part of the public record we are aggregating and because our users need to know who they are dealing with. Our basis is legitimate interests (Art. 6(1)(f)) in providing a reference on organisations built from official sources, balanced against the fact that the information is already public, was published by an official body for a transparency purpose, and concerns a person's business activity rather than their private life.
We do not enrich these records with information about a person's private life, and the prohibition on using any of it for marketing, prospecting or unsolicited contact applies here too, to us and, under our Terms, to our users.
7.3 Accuracy, and the limit of our disclaimer
Our Terms of Use tell our customers that we do not warrant the accuracy of aggregated data, because we reproduce what sources publish.
That does not apply to you if the data is about you. If we hold personal data about you and it is wrong, you have the right to have it corrected or erased, and we will act on it. We will correct our own copy, and if the error came from the source we will tell you where it came from so you can have it corrected there too, but we will not use "the source said so" as a reason to leave something wrong on our own site.
7.4 We did not get this from you
Because we collect it from public sources rather than from you, the law requires us to tell you about it. Given the number of people involved, and because we deliberately hold no contact details for them, telling each person individually would take more effort than the law requires of us and would mean collecting contact data we otherwise have no reason to hold. So we publish this policy instead, we show the source and the date we last checked it against the facts we display, and we put a correction route on the record itself.
8. Automated processing, and decisions
We use software, including machine-learning and large-language-model techniques, to:
- decide that a name in one source refers to the same organisation as a name in another (entity resolution and matching);
- classify organisations, projects and documents into categories and capabilities;
- extract facts from documents and articles;
- calculate scores, indicators and rankings about organisations;
- detect changes and decide when to send you an alert.
Two things follow, and we want to be clear about both:
- These techniques make mistakes, and everything they produce is an inference rather than a fact. Where we can, we label derived values as derived and show a confidence indicator.
- We do not make automated decisions that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22 GDPR. We do not score, rate or rank individual people. Our scores and indicators are about organisations, and any statistics about people (such as how many officials each Member State has) are published only as aggregate figures about countries and institutions.
We do not use your personal data to train machine-learning models that are made available outside our own services.
9. Who we share data with
We do not sell personal data, and we do not share it for anyone else's marketing.
We share it with service providers who process it on our instructions, under a written contract that requires them to protect it and forbids them from using it for their own purposes. The categories are:
| What they do | Who | Where |
|---|---|---|
| Hosting, servers and the database | Hetzner Online GmbH | Finland (European Union) |
| Content delivery, DNS and protection against attack | Cloudflare, Inc. | Global edge network; see section 10 |
| Sending our email to you, including your address | Intuit Mailchimp (Mailchimp Transactional) | United States |
| Signing you in, if you choose "Continue with Google" | Google Ireland Limited | EU, with transfers to the United States |
| Automated analysis of public documents and articles to extract facts | OpenAI, L.L.C. | United States |
| Large-scale analysis of the public news corpus | Google Cloud EMEA Limited (BigQuery) | United States |
We also disclose personal data where we must: to comply with the law or a lawful request from an authority, to enforce our Terms, to protect the rights or safety of anyone, and to our professional advisers. If our business is sold or reorganised, data may transfer to the acquirer, and this policy continues to apply until they tell you otherwise.
We keep an up-to-date list of our processors and will provide it on request at support@seeders.gr.
10. Where your data goes
We host in the European Union (Hetzner Online GmbH, Finland (European Union)) and our intention is to keep personal data there.
Some of the providers above are established outside the EEA or process data outside it. Where that happens, we rely on the safeguards the law provides: the European Commission's adequacy decisions where one covers the country or the provider's certification, and otherwise the Commission's standard contractual clauses, together with additional technical and organisational measures where they are needed.
You can ask us for details of the safeguards that apply to a particular transfer, and we will provide them.
11. How long we keep things
| What | How long |
|---|---|
| Your account and the content in it | For as long as your account is open. Closing it is a request you make and we approve: from our approval there are 30 days in which it can still be reversed, and no earlier than that your account is anonymised and the data we derived about you is deleted. Section 12 explains the whole of it |
| Web server and security logs | 12 months, longer only where part of an open investigation |
| Sign-in and security records | 24 months |
| The email address typed in a failed sign-in attempt | 4 months, then the address is erased. The record that the attempt happened is kept as a sign-in record, without the address |
| Records of acceptance of the Terms, and of consent given or withdrawn | For as long as your account is open, and 6 years afterwards. We keep these deliberately after everything else is deleted: they are the evidence that we were entitled to do what we did, and they are what a regulator or a court asks about the past |
| Invoices, payments and accounting records | As required by Greek tax and accounting law, currently 5 years from the end of the financial year |
| Support correspondence | 5 years from the last message |
| Marketing contact data, where you consented | Until you withdraw consent, or 3 years after your last interaction with us, whichever is first |
| Information about public office-holders and about people named in public registers | Historical entries are kept as a public-interest record and shown as historical rather than current |
When a period ends we delete the data or anonymise it so that it can no longer identify anyone.
12. Your rights
Whether or not you have an account, and whether you are a user or someone who appears in our data, you can ask us to:
- give you a copy of the personal data we hold about you, and tell you what we do with it (Article 15);
- correct anything inaccurate or incomplete (Article 16);
- erase it (Article 17);
- restrict what we do with it while a question about it is being resolved (Article 18);
- give you, or another provider, a portable copy of data you gave us, where we hold it on the basis of your consent or our contract with you (Article 20);
- object to processing we carry out on the basis of legitimate interests, including the publication of information about you (Article 21);
- withdraw consent at any time, where we relied on your consent, which does not affect what we lawfully did before you withdrew it (Article 7(3)).
Your right to object deserves its own paragraph, because the law requires us to bring it to your attention separately. Where we process your personal data on the basis of our legitimate interests (which includes publishing information about public office-holders and about people named in public registers) you have the right to object at any time, on grounds relating to your particular situation. If you object, we stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. If you object to marketing, we stop, always, with no assessment and no exceptions.
Closing your account. You can ask us to close your account from your account page.
Closing is a request, not a switch, and we would rather say so plainly. We review it first, because an account can hold membership of an organisation and records we keep for reasons of our own, and because a review means a mistaken or a hostile request cannot remove an organisation's history on its own. While we are reviewing, nothing is deleted and you keep full access.
If we approve it, the 30 days run from our approval and not from your request. During them you can change your mind from the same page and keep your account, with nothing lost. We start deleting no earlier than the end of those 30 days. If we do not approve, we tell you on your account page and your account is unchanged; ask us and we will explain why.
What closing then means, in detail, because not everything is simply deleted. Your account record is anonymised: your name and contact details are replaced with values that cannot identify anyone, and your password and sign-in tokens are destroyed. Data we derived about you, such as your saved searches and watchlists, is deleted. Material published by somebody else in which you appear is not edited or removed: we stop using it to surface you, and it stays where its publisher put it, because altering somebody else's document would corrupt the record for everyone else named in it and it remains published at its source whatever we do. And your records of accepting the Terms and of consent you gave or withdrew are kept, because they are the evidence that we were entitled to do what we did.
How to ask. Write to support@seeders.gr, or use the correction link on the record itself if your request is about something published about you. You do not need an account.
What happens then. We acknowledge within 3 working days and give you a reference. A straightforward factual correction is checked against the source and applied within 10 working days. Everything else gets a full answer within one month; if a request is complex we will tell you inside that month and may take up to two further months. If we refuse, we tell you why, who decided, and how to challenge it. We do not charge for any of this unless a request is manifestly unfounded or excessive.
We may need to check who you are before acting on a request about an account, so that we do not disclose your data to somebody else. We will not ask you for identity documents to correct a public role fact.
13. Complaints
If you are unhappy with how we have handled your personal data, please tell us first: we would rather fix it.
You also have the right to complain to a data protection supervisory authority. Ours is the Hellenic Data Protection Authority (Arxi Prostasias Dedomenon Prosopikou Xaraktira), Kifissias 1-3, 115 23 Athens, Greece, dpa.gr. You may also complain to the authority in the EU country where you live or work, or where you think the problem happened, and you can go to court.
14. Security
We protect personal data with technical and organisational measures appropriate to the risk: encryption in transit, hashed passwords, access limited to staff who need it, separation between our public services and our internal systems, logging of administrative access, and regular review.
No service is perfectly secure, and we do not claim otherwise. If a breach occurs that is likely to result in a risk to your rights, we will notify the supervisory authority within 72 hours as the law requires, and we will tell you directly where the risk to you is high.
15. Children
Our services are not intended for children. You must be at least 16 to hold an account, and we do not knowingly collect personal data from children. If you believe a child has given us personal data, tell us and we will delete it.
16. Changes to this policy
We may update this policy. We change the version number and the date at the top, and we keep previous versions available so you can see what changed and when.
Where a change materially affects you (a new purpose, a new category of recipient, a change of lawful basis), we will tell registered users by email and put a notice on the service before it takes effect. We will never start using data we already hold for a materially different purpose without telling you first, and where that new purpose needs your consent, we will ask for it.
17. Contact
Seeders IKE 49 Perikleous Street, 154 51 Neo Psychiko, Greece Data protection: support@seeders.gr · General: support@seeders.gr
- Version 2.1, in force from Sep 28, 2026 (this page)
- Version 1.2 in force from Sep 6, 2026 · Corrections only. Analytics described in advance rather than denied; the consent record no longer claims to hold a scrambled IP address, because it holds none; the email provider added to the processor list; the rate limit floors reworded from higher than to at or above; and the six retention periods now stated from configured values with jobs that enforce them. No change to anybody's rights or obligations.
- Version 1.1 in force from Sep 5, 2026 · Non-endorsement statement, corrected sign-in wording, published rate-limit floor
- Version 1.0 in force from Sep 5, 2026