[

legal page

]

Privacy Policy

Last Updated:

25 September 2026

[

legal page

]

Privacy Policy

Last Updated:

25 September 2026

[

legal page

]

Privacy Policy

Last Updated:

25 September 2026

Last updated: 25 September 2026
Version: 1.0


1. Who we are

This Privacy Notice explains how personal data are collected, used, stored, disclosed and otherwise processed when you visit cadenholt.com, contact Caden Holt, request information, enquire about services, become a client, or otherwise interact with the business in connection with its professional activities.

The website and the associated professional activities are operated by:

APOSKITIS FILIPPOS
a sole proprietor established in Greece
trading under the professional name Caden Holt

Registered office: PAPAFLESSA 23, VOULA, ATTICA, 16673
AFM: 181491799
G.E.M.I. number: 196127203000
Professional / trading name: Caden Holt
General contact: [email protected]
Privacy contact: [email protected]
Website: https://cadenholt.com

Caden Holt is the professional, public-facing name and registered distinctive title used by APOSKITIS FILIPPOS . It is not a separate legal entity from the sole proprietorship operated by APOSKITIS FILIPPOS.

At present, Caden Holt is used as a professional and trading name pending completion of its registration as a distinctive title where applicable. Once that registration is completed, this Privacy Notice may be updated to reflect the registered status of the name.

For purposes of applicable data-protection law, APOSKITIS FILIPPOS is the data controller for the personal data covered by this Privacy Notice, except where another party acts as controller or where Caden Holt processes personal data on behalf of a client under a separate contractual arrangement.

The controller is responsible for determining the purposes and means of processing personal data in connection with its own business activities. The GDPR places accountability for controller compliance on the controller.


2. Scope of this Privacy Notice

This Privacy Notice applies to personal data processed through:

  • cadenholt.com;

  • enquiries submitted through the website;

  • email communication with Caden Holt;

  • proposals and pre-contractual discussions;

  • client relationships and project administration;

  • professional business-development activity;

  • prospect and contact-management records;

  • information obtained from publicly available professional or business sources;

  • other interactions directly connected to the operation of the Caden Holt professional practice.

This Privacy Notice does not automatically govern websites operated by clients of Caden Holt, including websites that Caden Holt may design or develop for clients.

Where Caden Holt designs, develops, hosts or maintains a website, application or other system on behalf of a client and processes personal data according to that client's instructions, the client will generally determine the purposes and means of that processing and may therefore act as the data controller. Caden Holt may act as a data processor in such circumstances.

Where Caden Holt acts as a processor for a client, the relevant processing will be governed by the client's instructions and, where required, a separate data-processing agreement or equivalent contractual terms.

The distinction between controller and processor is determined by the actual purposes and means of processing rather than by the label given to the relationship.


3. What is personal data?

“Personal data” means information relating to an identified or identifiable natural person.

This can include information such as:

  • name;

  • email address;

  • telephone number;

  • professional position;

  • business contact details;

  • website or project URL;

  • communications and correspondence;

  • information contained in an enquiry;

  • identifiers and technical information where they can be linked to an individual;

  • records of interactions with Caden Holt.

Information relating solely to a legal entity, such as a company name or generic company information, will not necessarily constitute personal data. However, information about an identifiable individual working for or representing a business can constitute personal data.


4. Personal data we collect directly from you

When you contact Caden Holt through the website or by email, you may provide information including:

  • your name;

  • email address;

  • budget range;

  • website or project URL;

  • information contained in your message;

  • information you voluntarily provide during subsequent correspondence;

  • information necessary to prepare a proposal or provide services.

The current website contact form is intentionally limited to information needed to understand an enquiry and determine whether the requested services may be appropriate.

We do not ask you to provide sensitive personal information through the website.

Please do not submit

You should not submit passwords, authentication credentials, payment-card information, government identification numbers, health information, information about criminal convictions, or other sensitive personal information through the contact form unless Caden Holt specifically requests such information through an appropriate secure process.

If you voluntarily provide information that is not necessary for the relevant purpose, Caden Holt may delete it where appropriate.

This approach follows the GDPR principles of purpose limitation and data minimisation.


5. Information collected automatically when you visit the website

When you visit cadenholt.com, certain technical information may be processed automatically by the website infrastructure and its service providers.

Depending on the technologies active on the website and the circumstances of your visit, this may include:

  • IP address;

  • browser type and version;

  • operating system or device information;

  • date and time of access;

  • requested pages or resources;

  • referral information;

  • security and abuse-prevention signals;

  • diagnostic and performance information.

Caden Holt does not use this information to identify individual visitors for advertising purposes.

Certain technical processing may be necessary to:

  • deliver website content;

  • maintain website security;

  • protect against abuse and automated attacks;

  • diagnose technical problems;

  • maintain availability and performance;

  • establish and defend legal claims where necessary.

Framer's current data-processing documentation identifies categories such as IP address, device information, address information and business contact details among information that may be processed in connection with its services.


6. Website analytics

Caden Holt may use the analytics functionality provided directly by Framer to understand aggregate website usage and improve the site.

Framer currently describes its built-in analytics as a privacy-oriented system that does not use cookies or persistent identifiers and states that its analytics are designed not to identify individual visitors.

Where analytics are used, they are used to understand aggregate measures such as:

  • page views;

  • traffic sources;

  • device categories;

  • browser categories;

  • approximate geographic information;

  • website usage patterns at an aggregate level.

Caden Holt does not use analytics information to make decisions that produce legal or similarly significant effects on individuals.

If additional analytics, advertising or tracking services are introduced, the website's cookie and privacy information will be updated as required before those technologies are deployed.


7. Contact-form processing

When you submit the contact form, the information you provide may be transmitted through Framer's form infrastructure and delivered to the configured destination, such as email or Google Sheets.

The contact information is used to:

  1. receive your enquiry;

  2. understand what you are requesting;

  3. determine whether Caden Holt can provide the requested service;

  4. communicate with you;

  5. prepare or discuss a proposal where appropriate;

  6. follow up on a genuine business enquiry;

  7. maintain an accurate record of the interaction;

  8. protect against spam, abuse and fraudulent submissions.

Framer currently supports native form submissions to email, Google Sheets and custom webhooks, and provides built-in spam protection/rate-limiting functionality.

Legal basis

Where you contact Caden Holt to request information, obtain a quotation, discuss a project or take steps toward entering into a contract, processing may be necessary for the purposes of taking steps at your request before entering into a contract.

The GDPR expressly recognises pre-contractual processing, including processing necessary to respond to a person's request for a quotation or proposed service, as a potential Article 6(1)(b) legal basis.

Caden Holt may also process limited information on the basis of legitimate interests where necessary for:

  • operating and securing the business;

  • preventing spam and abuse;

  • maintaining business records;

  • managing professional relationships;

  • establishing, exercising or defending legal claims.

Where legitimate interests are relied upon, Caden Holt considers the necessity of the processing and balances those interests against the rights and freedoms of the individuals concerned. The GDPR requires such an assessment where Article 6(1)(f) is relied upon.


8. Business and client administration

If an enquiry becomes a client relationship, additional personal data may be processed where necessary to establish and manage the professional relationship.

This may include:

  • name;

  • business role;

  • business contact details;

  • project information;

  • correspondence;

  • proposal and contract information;

  • invoicing and payment information;

  • information necessary to provide the contracted services;

  • records of approvals, instructions and deliverables;

  • records necessary to resolve disputes or enforce contractual rights.

This processing may be based on:

  • performance of a contract;

  • taking steps before entering into a contract;

  • compliance with legal obligations;

  • legitimate interests in managing and protecting the business;

  • establishment, exercise or defence of legal claims.

Where tax, accounting, invoicing or other legislation requires records to be retained, those records will be retained for the period required by applicable law even where ordinary operational retention periods would otherwise have expired.


9. Professional and business-development contacts

Caden Holt may conduct professional business-development activities directed primarily toward businesses and professional contacts.

In connection with these activities, Caden Holt may collect limited professional contact information from:

  • business websites;

  • publicly accessible business directories;

  • public business listings;

  • publicly available professional profiles;

  • publicly listed business telephone numbers;

  • referrals;

  • business correspondence;

  • information provided directly during a professional interaction.

Where information relates to an identifiable individual, it is treated as personal data and processed in accordance with applicable data-protection law.

The fact that information is publicly accessible does not by itself remove it from the scope of the GDPR where it relates to an identifiable individual.

The Hellenic Data Protection Authority specifically recognises that promotional data may be obtained from lawful/public sources, but requires appropriate transparency and respect for objection rights.


10. Information obtained from public sources

Where personal data are obtained from a source other than the individual concerned, the relevant processing may be carried out for legitimate business-development purposes where permitted by applicable law and where the necessary balancing and transparency requirements are satisfied.

The categories of information may include:

  • name;

  • professional role;

  • business;

  • business website;

  • business telephone number;

  • professional email address where lawfully available;

  • publicly available business information relevant to the professional relationship.

Caden Holt seeks to limit such information to what is reasonably necessary for the relevant professional purpose.

The sources of such information may include:

  • the individual's employer or business website;

  • public business directories;

  • public business listings;

  • professional networking or business-profile pages;

  • other publicly accessible professional sources.

Where required by Article 14 GDPR, Caden Holt will provide information about the source of the data and the processing at the relevant time, including no later than the first communication where the applicable law permits processing for that purpose and requires such disclosure.

The GDPR requires additional transparency where personal data are obtained from a source other than the data subject, including information concerning the source of the data.


11. Direct marketing

Caden Holt distinguishes between:

  • responding to an enquiry;

  • maintaining a client relationship;

  • business-development activity;

  • direct marketing communications.

Direct marketing is carried out only where permitted under applicable data-protection and electronic-communications law.

Where processing for direct marketing is based on legitimate interests under the GDPR, individuals have an unconditional right to object to the use of their personal data for direct marketing. Once such an objection is made, the personal data must no longer be processed for that direct-marketing purpose.


12. Promotional telephone calls

Caden Holt may make human-assisted telephone calls for professional or business-development purposes where legally permitted.

For promotional telephone calls, Caden Holt will comply with applicable Greek electronic-communications law, including the rules governing unsolicited promotional calls under Article 11 of Law 3471/2006.

In particular, Caden Holt will:

  • use lawful professional/business contact information;

  • respect applicable provider-level opt-out registers;

  • maintain its own internal do-not-contact records;

  • respect objections made directly to Caden Holt;

  • stop promotional calling where an individual exercises an applicable objection;

  • not use automated calling systems where prior consent is required and has not been obtained.

Under the current Greek framework, unsolicited human-assisted promotional telephone calls operate under an opt-out regime, while automated promotional communications and electronic communications such as email and SMS generally require prior consent, subject to the exceptions provided by law.


13. Promotional email and electronic communications

Caden Holt does not treat a publicly listed email address as blanket permission to send unsolicited promotional email.

Promotional email, SMS and other electronic marketing communications are subject to the applicable rules of Greek Law 3471/2006 and other applicable law.

Where prior consent is legally required, Caden Holt will obtain that consent before sending such communications.

Where a legally recognised existing-customer exception applies, Caden Holt may communicate regarding its own similar services provided all applicable legal requirements are satisfied, including an effective and easy means to object or unsubscribe.

Every promotional electronic communication sent where required by law will clearly identify the sender and provide a valid mechanism for stopping further promotional communication.

The Hellenic DPA currently states that unsolicited electronic promotional communications such as email and SMS generally require prior consent, subject to the statutory customer-relationship exception.


14. Do-not-contact and suppression records

When a person objects to direct marketing, Caden Holt may retain a minimal suppression record necessary to ensure that the objection is respected in the future.

This may include:

  • name;

  • business;

  • contact identifier;

  • type of objection;

  • date of objection;

  • source of objection;

  • minimum information required to prevent future marketing communication.

A suppression record is maintained only for the purpose of ensuring that promotional communications are not subsequently directed to the person.

This limited retention may continue for as long as reasonably necessary to ensure the objection is respected.

The Hellenic DPA expressly recognises the need for controllers engaging in direct marketing to maintain mechanisms or records that prevent further promotional use following an objection.


15. Legal bases for processing

Depending on the specific processing activity, Caden Holt may rely on one or more of the following legal bases under Article 6 GDPR.

15.1 Performance of a contract

Processing may be necessary to:

  • provide services;

  • communicate with a client;

  • manage an engagement;

  • deliver agreed work;

  • administer a contract.

15.2 Pre-contractual steps

Processing may be necessary to:

  • respond to a request;

  • discuss a potential project;

  • assess requirements;

  • prepare a proposal;

  • negotiate potential services.

15.3 Legal obligations

Processing may be necessary to comply with legal obligations such as:

  • tax requirements;

  • accounting requirements;

  • invoicing requirements;

  • legal-recordkeeping obligations;

  • lawful requests from competent authorities.

The EDPB recognises compliance with legal obligations as an independent Article 6 legal basis where the relevant obligation is imposed by EU or national law.

15.4 Legitimate interests

Caden Holt may rely on legitimate interests where processing is necessary and the interests are not overridden by the rights and freedoms of the data subject.

Examples may include:

  • maintaining business records;

  • preventing fraud and abuse;

  • protecting website and information systems;

  • managing professional relationships;

  • business development;

  • direct marketing where legally permissible;

  • maintaining do-not-contact records;

  • establishing, exercising or defending legal claims.

Where legitimate interests are used, Caden Holt considers the purpose, necessity, expectations of individuals, impact of the processing, and available safeguards.

15.5 Consent

Where Caden Holt relies on consent, consent will be requested separately and presented in a manner that is:

  • informed;

  • specific;

  • freely given;

  • unambiguous;

  • capable of being withdrawn.

Withdrawal of consent will be made as easy as giving it.

The Hellenic DPA states that valid consent requires an affirmative action and cannot be based on silence, inactivity or pre-ticked boxes.


16. Recipients of personal data

Personal data may be disclosed only where necessary and appropriate for the purposes described in this Privacy Notice.

Depending on the relationship and the services used, recipients or categories of recipients may include:

Technology and hosting providers

Providers used to:

  • host the website;

  • process website requests;

  • process contact-form submissions;

  • provide security and abuse prevention;

  • store business information.

This currently includes Framer B.V. for website hosting and related services. Framer's current DPA identifies Framer as a processor where it processes customer-controlled personal data.

Cloud and productivity providers

Where used, these may include:

  • Google services;

  • email services;

  • cloud storage;

  • document and spreadsheet services.

If Google Sheets is configured as the destination for the website's native contact form, submitted information may be transferred to Google for storage and processing in that service.

CRM and business-management providers

Where used, limited prospect or client information may be transferred to a CRM or business-management platform for:

  • contact management;

  • project management;

  • business-development tracking;

  • follow-up;

  • suppression of unwanted marketing communication.

Professional advisers

Information may be shared with:

  • accountants;

  • lawyers;

  • professional advisers;

  • insurers;

  • auditors;

where necessary for legal, accounting, tax, compliance or risk-management purposes.

Depending on the activity, such advisers may act as independent controllers or processors.

Authorities and other third parties

Personal data may be disclosed where necessary to:

  • comply with law;

  • respond to lawful requests;

  • establish, exercise or defend legal claims;

  • protect the rights, property or security of Caden Holt or others;

  • investigate fraud or abuse.

Caden Holt does not sell personal data.


17. Service providers and processors

Where Caden Holt engages a third party to process personal data on its behalf, the relationship will be governed by the contractual and legal requirements applicable to processors.

Processors may only process personal data for the relevant purposes and in accordance with the applicable instructions and contractual obligations.

The GDPR requires controller-processor relationships to be governed by an appropriate legal instrument and requires processors to implement appropriate safeguards.


18. Google services

Caden Holt may use Google services for business email, document storage, spreadsheets, lead management or other business operations.

Where personal data are processed by Google, the applicable Google privacy terms and contractual data-processing terms will also apply.

For services provided in the European Economic Area, Google commonly operates through Google Ireland Limited, although the applicable Google entity and processing relationship depend on the specific service and account configuration.

Where Google processes personal data as a processor for a business service, the applicable Google data-processing terms govern that processing.

Where Google acts independently as a controller for particular service-related processing, Google's own privacy notice governs that processing.

Google states that it relies on appropriate transfer mechanisms for restricted international transfers, including Standard Contractual Clauses where required.


19. Framer

Caden Holt uses Framer to host and operate cadenholt.com.

Framer's current DPA, effective 16 June 2026, provides contractual data-processing terms intended to satisfy Article 28 GDPR requirements where Framer processes personal data on behalf of its customers. It describes categories of personal data that may include names, email addresses, IP addresses, device information and information relating to end users.

Framer's current privacy statement states that it may transfer personal data to third parties and infrastructure located outside the EEA, including the United States, and states that such transfers are carried out under Chapter V GDPR requirements.

Caden Holt relies on Framer's contractual safeguards and applicable transfer mechanisms in accordance with the GDPR and applicable law.


20. International transfers

Because Caden Holt operates online and uses service providers that may operate internationally, personal data may be processed outside Greece or outside the European Economic Area.

Where personal data are transferred to a country that does not benefit from an applicable adequacy decision, Caden Holt will rely on an applicable legal transfer mechanism under Chapter V GDPR, such as:

  • an adequacy decision;

  • Standard Contractual Clauses;

  • another lawful transfer mechanism recognised under applicable law.

Where required, additional safeguards will be considered based on the circumstances of the transfer.

Caden Holt does not treat the physical location of a server as a substitute for GDPR compliance; the legality of an international transfer depends on the applicable transfer mechanism and safeguards.

Framer currently states that its infrastructure can involve transfers to the United States and other third countries under Chapter V GDPR safeguards. Google likewise states that it uses adequacy mechanisms and SCCs where required.


21. Data retention

Caden Holt retains personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

Retention periods depend on the nature and purpose of the data.

21.1 Website enquiries

Information provided through a general project enquiry is normally retained for up to six months following the last meaningful interaction, unless:

  • the enquiry becomes an active client relationship;

  • a proposal or contract remains relevant;

  • further communication is reasonably expected;

  • a legal claim or dispute exists;

  • a legal or accounting obligation requires longer retention;

  • a person has made a specific request that requires a different handling approach under applicable law.

After the relevant period, the data will be deleted or anonymised where reasonably practicable.

21.2 Prospects and business-development records

Professional prospect information used for business development is normally reviewed periodically and should not be retained indefinitely.

Where there has been no meaningful interaction or ongoing business purpose, records will normally be deleted or anonymised after the applicable retention period.

Caden Holt may retain a minimal suppression record where necessary to ensure a prior objection to marketing is respected.

21.3 Client records

Records relating to projects, contracts, invoices, payments, accounting and legal obligations may need to be retained for longer periods than ordinary enquiry data.

Such records will be retained for the period required or reasonably necessary under applicable tax, accounting, contractual and legal requirements.

21.4 Security and technical records

Technical and security information may be retained for the period reasonably necessary to:

  • detect and investigate security incidents;

  • maintain service integrity;

  • troubleshoot technical problems;

  • establish or defend legal claims.

Where such information is controlled by a third-party service provider, the provider's applicable retention terms may also apply.

The GDPR does not prescribe one universal retention period; controllers are required to establish retention periods appropriate to the purpose and to comply with the storage-limitation principle.


22. Data minimisation

Caden Holt seeks to collect and process only the personal data reasonably necessary for the relevant purpose.

The business does not intentionally collect broad personal profiles of website visitors.

Where a client, prospect or visitor provides additional information voluntarily, Caden Holt will assess whether that information is necessary for the relevant purpose and may delete unnecessary information.

Data minimisation is a core GDPR principle.


23. Accuracy

Caden Holt takes reasonable steps to keep personal data accurate and up to date where the business has ongoing reason to rely on that information.

Individuals may request correction of inaccurate or incomplete information.

The GDPR requires personal data to be accurate and, where necessary, kept up to date.


24. Data security

Caden Holt applies technical and organisational measures appropriate to the nature and risk of the processing.

Depending on the system and service involved, safeguards may include:

  • access controls;

  • multi-factor authentication;

  • strong authentication credentials;

  • least-privilege access;

  • secure HTTPS connections;

  • updated operating systems and software;

  • controlled access to cloud accounts;

  • private access to business spreadsheets and CRM systems;

  • spam and abuse protection;

  • secure device practices;

  • backups where appropriate;

  • procedures for responding to incidents;

  • deletion of unnecessary data;

  • confidentiality obligations where applicable.

No method of transmission or storage can be guaranteed to be completely secure.

Where a security incident results in a personal-data breach, Caden Holt will assess the incident and comply with the applicable GDPR notification and communication requirements.

The GDPR requires security measures proportionate to risk, and qualifying breaches may need to be notified to the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk to individuals; high-risk breaches may also require communication to affected individuals.


25. Data breaches

Caden Holt maintains procedures intended to identify, investigate, contain and document personal-data breaches.

Where a personal-data breach is likely to result in a risk to the rights and freedoms of individuals, Caden Holt will assess whether notification to the competent supervisory authority is required.

Where a personal-data breach is likely to result in a high risk to individuals, Caden Holt will assess whether direct communication to affected individuals is required.

Relevant incidents will be documented in accordance with applicable legal requirements.


26. Your rights

Subject to applicable legal conditions and exceptions, you may have the right to:

Access

Request confirmation of whether Caden Holt processes your personal data and, where applicable, obtain access to that data and related information.

Rectification

Request correction of inaccurate or incomplete personal data.

Erasure

Request deletion of personal data where the legal conditions for erasure are satisfied.

Restriction

Request restriction of processing in circumstances provided by law.

Objection

Object to processing based on legitimate interests where the applicable legal conditions are satisfied.

You have an absolute right to object to the processing of personal data for direct marketing purposes.

Data portability

Where the legal conditions are satisfied, request the personal data you have provided in a structured, commonly used and machine-readable format, or request transmission to another controller.

Withdrawal of consent

Where processing is based on consent, withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

These rights correspond to the rights established by Articles 15–22 GDPR, subject to the specific conditions applicable to each right. The Hellenic DPA provides guidance on access, rectification, erasure, restriction, portability and objection rights.


27. How to exercise your rights

To make a privacy request, contact:

[email protected]

Please provide enough information to allow Caden Holt to understand and verify your request.

Where reasonably necessary to protect personal data against unauthorised disclosure, Caden Holt may request additional information to verify the identity of the person making the request.

Requests concerning privacy rights are handled without charge unless applicable law permits a reasonable charge or refusal because a request is manifestly unfounded or excessive.

Caden Holt will generally respond without undue delay and, in any event, within one month of receiving a valid request, subject to the statutory rules allowing an extension where necessary because of the complexity or number of requests. Where an extension applies, the requester will be informed within the initial response period.

The Hellenic DPA likewise states that data-subject requests are generally answered within one month and may be extended in accordance with the GDPR.


28. Objections to marketing

You may object to direct marketing at any time.

You can do this by:

  • emailing [email protected];

  • replying to a promotional email where an unsubscribe mechanism is provided;

  • telling the caller directly during a promotional telephone call;

  • using any other objection mechanism specifically provided in the communication.

A direct-marketing objection will be recorded and applied to the relevant contact information so that future promotional use can be prevented.

Under Article 21(2)–(3) GDPR, an objection to direct marketing requires cessation of processing for that purpose.


29. Complaints

If you believe that your personal data have been processed unlawfully or that your privacy rights have not been respected, you are encouraged to contact Caden Holt first at:

[email protected]

You also have the right to lodge a complaint with the competent data-protection supervisory authority.

For the purposes of processing carried out in Greece, the competent authority is:

Hellenic Data Protection Authority (HDPA)
1–3 Kifisias
115 23 Athens
Greece
Email: [email protected]

The Hellenic DPA accepts complaints concerning alleged GDPR violations and matters relating to unsolicited promotional telephone calls and electronic communications.


30. Automated decision-making and profiling

Caden Holt does not currently make decisions concerning individuals based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.

The business does not currently use personal-data scoring systems to determine whether an individual can purchase services, receive different prices, obtain different contractual terms, or otherwise receive materially different treatment based solely on automated processing.

If this changes, the relevant processing and information provided to individuals will be reviewed before implementation.


31. Special categories of personal data

Caden Holt does not intentionally seek to collect or process special categories of personal data through the website.

Special categories include information such as:

  • health information;

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade-union membership;

  • genetic data;

  • biometric data used for identification;

  • information concerning sex life or sexual orientation.

Caden Holt does not request such information through the website contact form.

Where special-category information is voluntarily provided, Caden Holt will assess whether there is a lawful reason to retain or process it and will otherwise delete it where appropriate.

The GDPR provides additional restrictions for special-category data.


32. Criminal-conviction and offence data

Caden Holt does not intentionally collect information relating to criminal convictions or offences through the website.

Such information will not be requested through the ordinary contact form.


33. Children's data

Caden Holt's website and professional services are not specifically directed at children.

Caden Holt does not intentionally collect personal data from children through the website as part of a child-focused service.

If personal data relating to a child are unexpectedly provided, the information will be handled in accordance with applicable law and deleted where there is no lawful reason to retain it.

Greek law sets the relevant age for a child's own consent to processing under Article 8 GDPR in information-society services at 15 years, subject to the conditions specified by Law 4624/2019.


34. Cookies and similar technologies

cadenholt.com may use technologies that are necessary to:

  • operate the website;

  • maintain security;

  • remember necessary technical preferences;

  • support requested functionality.

Where a technology is strictly necessary for the requested service or transmission of communications, consent is not required under the applicable ePrivacy exception.

Non-essential cookies or technologies that require consent will not be activated before the relevant consent has been obtained.

The Hellenic DPA states that Article 4(5) of Law 3471/2006 generally requires prior consent for storing or accessing information on a user's terminal equipment, subject to the narrowly defined exception for technically necessary functionality.

Caden Holt currently does not use advertising cookies.

Where applicable, a separate Cookie Notice will identify the cookies and similar technologies actually used on the website, their purpose, provider, duration and consent requirements.

If third-party technologies such as Google Analytics, advertising pixels, video embeds or behavioural-tracking tools are introduced, the website's cookie controls and privacy information will be updated accordingly.

The Hellenic DPA specifically distinguishes analytics cookies from technically necessary cookies and states that third-party analytics cookies such as Google Analytics require consent under the applicable rules.


35. Embedded third-party content

cadenholt.com may from time to time include links to or, where technically necessary, content provided by third parties.

Third-party content may cause the relevant provider to process information about your visit.

Where such functionality is introduced, the relevant privacy and cookie implications will be reviewed and disclosed appropriately.


36. External links

The website may contain links to third-party websites, including websites of clients, project partners, service providers and other organisations.

Caden Holt is not responsible for the privacy practices, security or content of third-party websites.

You should review the privacy information of any external website before providing personal data to that website.


37. Client projects and third-party personal data

When Caden Holt provides design, website, branding or related services to a client, project materials may contain personal data controlled by that client.

Where Caden Holt processes such information solely on the client's instructions, the client's privacy notice and the applicable contractual data-processing terms govern that processing.

Caden Holt will not use client-controlled personal data for its own unrelated purposes unless a separate lawful basis exists.

Where required, Caden Holt will enter into a data-processing agreement or equivalent terms addressing:

  • processing instructions;

  • confidentiality;

  • security;

  • subprocessors;

  • assistance with data-subject requests;

  • breach handling;

  • deletion or return of data;

  • audit or compliance obligations.

The GDPR requires processors to process data only on documented instructions and to implement appropriate safeguards.

This distinction is particularly important as Caden Holt's client work expands from simple websites into systems that collect customer data.


38. No sale or rental of personal data

Caden Holt does not sell, rent or trade personal data for monetary consideration.

Personal data may be disclosed to service providers where necessary to operate the business or provide services, subject to the applicable contractual and legal safeguards.


39. No use of personal data for unrelated purposes

Personal data collected for one purpose will not be repurposed for an incompatible purpose.

Where Caden Holt proposes a materially different use of personal data, the business will assess whether the new processing is compatible with the original purpose and whether additional transparency or a separate legal basis is required.

Purpose limitation is a fundamental GDPR principle.


40. Law enforcement and legal requests

Caden Holt may disclose personal data where required by applicable law or where reasonably necessary to:

  • respond to a valid legal request;

  • comply with a court order or lawful authority request;

  • establish, exercise or defend legal claims;

  • investigate fraud;

  • protect the safety, rights or property of the business or another person.

Where legally permitted, Caden Holt will seek to limit disclosure to information reasonably necessary for the relevant purpose.


41. Changes to this Privacy Notice

Caden Holt may update this Privacy Notice when the business:

  • introduces a new service;

  • changes the technologies used by the website;

  • adds or removes data processors;

  • introduces analytics, advertising or marketing technologies;

  • changes its data-retention practices;

  • changes the way contact information is collected;

  • changes its legal or business identity;

  • is required to update its disclosures by law.

The latest version will be published on this page with an updated “Last updated” date.

Where a change materially affects how existing personal data are processed and applicable law requires additional notice or consent, Caden Holt will take the required steps.


42. Contact

For questions about this Privacy Notice or the processing of personal data:

Caden Holt
Professional/trading name of APOSKITIS FILIPPOS

Privacy: [email protected]
General support: [email protected]


43. Legal framework

This Privacy Notice is intended to describe processing carried out in accordance with applicable data-protection law, including, where applicable:

  • Regulation (EU) 2016/679 (General Data Protection Regulation);

  • Greek Law 4624/2019;

  • Greek Law 3471/2006 concerning privacy in electronic communications;

  • other applicable Greek and European legislation.

Nothing in this Privacy Notice limits any mandatory right or protection granted to an individual under applicable law.


44. Version history

Version 1.0
Effective: 25 September 2026

Last updated: 25 September 2026
Version: 1.0


1. Who we are

This Privacy Notice explains how personal data are collected, used, stored, disclosed and otherwise processed when you visit cadenholt.com, contact Caden Holt, request information, enquire about services, become a client, or otherwise interact with the business in connection with its professional activities.

The website and the associated professional activities are operated by:

APOSKITIS FILIPPOS
a sole proprietor established in Greece
trading under the professional name Caden Holt

Registered office: PAPAFLESSA 23, VOULA, ATTICA, 16673
AFM: 181491799
G.E.M.I. number: 196127203000
Professional / trading name: Caden Holt
General contact: [email protected]
Privacy contact: [email protected]
Website: https://cadenholt.com

Caden Holt is the professional, public-facing name and registered distinctive title used by APOSKITIS FILIPPOS . It is not a separate legal entity from the sole proprietorship operated by APOSKITIS FILIPPOS.

At present, Caden Holt is used as a professional and trading name pending completion of its registration as a distinctive title where applicable. Once that registration is completed, this Privacy Notice may be updated to reflect the registered status of the name.

For purposes of applicable data-protection law, APOSKITIS FILIPPOS is the data controller for the personal data covered by this Privacy Notice, except where another party acts as controller or where Caden Holt processes personal data on behalf of a client under a separate contractual arrangement.

The controller is responsible for determining the purposes and means of processing personal data in connection with its own business activities. The GDPR places accountability for controller compliance on the controller.


2. Scope of this Privacy Notice

This Privacy Notice applies to personal data processed through:

  • cadenholt.com;

  • enquiries submitted through the website;

  • email communication with Caden Holt;

  • proposals and pre-contractual discussions;

  • client relationships and project administration;

  • professional business-development activity;

  • prospect and contact-management records;

  • information obtained from publicly available professional or business sources;

  • other interactions directly connected to the operation of the Caden Holt professional practice.

This Privacy Notice does not automatically govern websites operated by clients of Caden Holt, including websites that Caden Holt may design or develop for clients.

Where Caden Holt designs, develops, hosts or maintains a website, application or other system on behalf of a client and processes personal data according to that client's instructions, the client will generally determine the purposes and means of that processing and may therefore act as the data controller. Caden Holt may act as a data processor in such circumstances.

Where Caden Holt acts as a processor for a client, the relevant processing will be governed by the client's instructions and, where required, a separate data-processing agreement or equivalent contractual terms.

The distinction between controller and processor is determined by the actual purposes and means of processing rather than by the label given to the relationship.


3. What is personal data?

“Personal data” means information relating to an identified or identifiable natural person.

This can include information such as:

  • name;

  • email address;

  • telephone number;

  • professional position;

  • business contact details;

  • website or project URL;

  • communications and correspondence;

  • information contained in an enquiry;

  • identifiers and technical information where they can be linked to an individual;

  • records of interactions with Caden Holt.

Information relating solely to a legal entity, such as a company name or generic company information, will not necessarily constitute personal data. However, information about an identifiable individual working for or representing a business can constitute personal data.


4. Personal data we collect directly from you

When you contact Caden Holt through the website or by email, you may provide information including:

  • your name;

  • email address;

  • budget range;

  • website or project URL;

  • information contained in your message;

  • information you voluntarily provide during subsequent correspondence;

  • information necessary to prepare a proposal or provide services.

The current website contact form is intentionally limited to information needed to understand an enquiry and determine whether the requested services may be appropriate.

We do not ask you to provide sensitive personal information through the website.

Please do not submit

You should not submit passwords, authentication credentials, payment-card information, government identification numbers, health information, information about criminal convictions, or other sensitive personal information through the contact form unless Caden Holt specifically requests such information through an appropriate secure process.

If you voluntarily provide information that is not necessary for the relevant purpose, Caden Holt may delete it where appropriate.

This approach follows the GDPR principles of purpose limitation and data minimisation.


5. Information collected automatically when you visit the website

When you visit cadenholt.com, certain technical information may be processed automatically by the website infrastructure and its service providers.

Depending on the technologies active on the website and the circumstances of your visit, this may include:

  • IP address;

  • browser type and version;

  • operating system or device information;

  • date and time of access;

  • requested pages or resources;

  • referral information;

  • security and abuse-prevention signals;

  • diagnostic and performance information.

Caden Holt does not use this information to identify individual visitors for advertising purposes.

Certain technical processing may be necessary to:

  • deliver website content;

  • maintain website security;

  • protect against abuse and automated attacks;

  • diagnose technical problems;

  • maintain availability and performance;

  • establish and defend legal claims where necessary.

Framer's current data-processing documentation identifies categories such as IP address, device information, address information and business contact details among information that may be processed in connection with its services.


6. Website analytics

Caden Holt may use the analytics functionality provided directly by Framer to understand aggregate website usage and improve the site.

Framer currently describes its built-in analytics as a privacy-oriented system that does not use cookies or persistent identifiers and states that its analytics are designed not to identify individual visitors.

Where analytics are used, they are used to understand aggregate measures such as:

  • page views;

  • traffic sources;

  • device categories;

  • browser categories;

  • approximate geographic information;

  • website usage patterns at an aggregate level.

Caden Holt does not use analytics information to make decisions that produce legal or similarly significant effects on individuals.

If additional analytics, advertising or tracking services are introduced, the website's cookie and privacy information will be updated as required before those technologies are deployed.


7. Contact-form processing

When you submit the contact form, the information you provide may be transmitted through Framer's form infrastructure and delivered to the configured destination, such as email or Google Sheets.

The contact information is used to:

  1. receive your enquiry;

  2. understand what you are requesting;

  3. determine whether Caden Holt can provide the requested service;

  4. communicate with you;

  5. prepare or discuss a proposal where appropriate;

  6. follow up on a genuine business enquiry;

  7. maintain an accurate record of the interaction;

  8. protect against spam, abuse and fraudulent submissions.

Framer currently supports native form submissions to email, Google Sheets and custom webhooks, and provides built-in spam protection/rate-limiting functionality.

Legal basis

Where you contact Caden Holt to request information, obtain a quotation, discuss a project or take steps toward entering into a contract, processing may be necessary for the purposes of taking steps at your request before entering into a contract.

The GDPR expressly recognises pre-contractual processing, including processing necessary to respond to a person's request for a quotation or proposed service, as a potential Article 6(1)(b) legal basis.

Caden Holt may also process limited information on the basis of legitimate interests where necessary for:

  • operating and securing the business;

  • preventing spam and abuse;

  • maintaining business records;

  • managing professional relationships;

  • establishing, exercising or defending legal claims.

Where legitimate interests are relied upon, Caden Holt considers the necessity of the processing and balances those interests against the rights and freedoms of the individuals concerned. The GDPR requires such an assessment where Article 6(1)(f) is relied upon.


8. Business and client administration

If an enquiry becomes a client relationship, additional personal data may be processed where necessary to establish and manage the professional relationship.

This may include:

  • name;

  • business role;

  • business contact details;

  • project information;

  • correspondence;

  • proposal and contract information;

  • invoicing and payment information;

  • information necessary to provide the contracted services;

  • records of approvals, instructions and deliverables;

  • records necessary to resolve disputes or enforce contractual rights.

This processing may be based on:

  • performance of a contract;

  • taking steps before entering into a contract;

  • compliance with legal obligations;

  • legitimate interests in managing and protecting the business;

  • establishment, exercise or defence of legal claims.

Where tax, accounting, invoicing or other legislation requires records to be retained, those records will be retained for the period required by applicable law even where ordinary operational retention periods would otherwise have expired.


9. Professional and business-development contacts

Caden Holt may conduct professional business-development activities directed primarily toward businesses and professional contacts.

In connection with these activities, Caden Holt may collect limited professional contact information from:

  • business websites;

  • publicly accessible business directories;

  • public business listings;

  • publicly available professional profiles;

  • publicly listed business telephone numbers;

  • referrals;

  • business correspondence;

  • information provided directly during a professional interaction.

Where information relates to an identifiable individual, it is treated as personal data and processed in accordance with applicable data-protection law.

The fact that information is publicly accessible does not by itself remove it from the scope of the GDPR where it relates to an identifiable individual.

The Hellenic Data Protection Authority specifically recognises that promotional data may be obtained from lawful/public sources, but requires appropriate transparency and respect for objection rights.


10. Information obtained from public sources

Where personal data are obtained from a source other than the individual concerned, the relevant processing may be carried out for legitimate business-development purposes where permitted by applicable law and where the necessary balancing and transparency requirements are satisfied.

The categories of information may include:

  • name;

  • professional role;

  • business;

  • business website;

  • business telephone number;

  • professional email address where lawfully available;

  • publicly available business information relevant to the professional relationship.

Caden Holt seeks to limit such information to what is reasonably necessary for the relevant professional purpose.

The sources of such information may include:

  • the individual's employer or business website;

  • public business directories;

  • public business listings;

  • professional networking or business-profile pages;

  • other publicly accessible professional sources.

Where required by Article 14 GDPR, Caden Holt will provide information about the source of the data and the processing at the relevant time, including no later than the first communication where the applicable law permits processing for that purpose and requires such disclosure.

The GDPR requires additional transparency where personal data are obtained from a source other than the data subject, including information concerning the source of the data.


11. Direct marketing

Caden Holt distinguishes between:

  • responding to an enquiry;

  • maintaining a client relationship;

  • business-development activity;

  • direct marketing communications.

Direct marketing is carried out only where permitted under applicable data-protection and electronic-communications law.

Where processing for direct marketing is based on legitimate interests under the GDPR, individuals have an unconditional right to object to the use of their personal data for direct marketing. Once such an objection is made, the personal data must no longer be processed for that direct-marketing purpose.


12. Promotional telephone calls

Caden Holt may make human-assisted telephone calls for professional or business-development purposes where legally permitted.

For promotional telephone calls, Caden Holt will comply with applicable Greek electronic-communications law, including the rules governing unsolicited promotional calls under Article 11 of Law 3471/2006.

In particular, Caden Holt will:

  • use lawful professional/business contact information;

  • respect applicable provider-level opt-out registers;

  • maintain its own internal do-not-contact records;

  • respect objections made directly to Caden Holt;

  • stop promotional calling where an individual exercises an applicable objection;

  • not use automated calling systems where prior consent is required and has not been obtained.

Under the current Greek framework, unsolicited human-assisted promotional telephone calls operate under an opt-out regime, while automated promotional communications and electronic communications such as email and SMS generally require prior consent, subject to the exceptions provided by law.


13. Promotional email and electronic communications

Caden Holt does not treat a publicly listed email address as blanket permission to send unsolicited promotional email.

Promotional email, SMS and other electronic marketing communications are subject to the applicable rules of Greek Law 3471/2006 and other applicable law.

Where prior consent is legally required, Caden Holt will obtain that consent before sending such communications.

Where a legally recognised existing-customer exception applies, Caden Holt may communicate regarding its own similar services provided all applicable legal requirements are satisfied, including an effective and easy means to object or unsubscribe.

Every promotional electronic communication sent where required by law will clearly identify the sender and provide a valid mechanism for stopping further promotional communication.

The Hellenic DPA currently states that unsolicited electronic promotional communications such as email and SMS generally require prior consent, subject to the statutory customer-relationship exception.


14. Do-not-contact and suppression records

When a person objects to direct marketing, Caden Holt may retain a minimal suppression record necessary to ensure that the objection is respected in the future.

This may include:

  • name;

  • business;

  • contact identifier;

  • type of objection;

  • date of objection;

  • source of objection;

  • minimum information required to prevent future marketing communication.

A suppression record is maintained only for the purpose of ensuring that promotional communications are not subsequently directed to the person.

This limited retention may continue for as long as reasonably necessary to ensure the objection is respected.

The Hellenic DPA expressly recognises the need for controllers engaging in direct marketing to maintain mechanisms or records that prevent further promotional use following an objection.


15. Legal bases for processing

Depending on the specific processing activity, Caden Holt may rely on one or more of the following legal bases under Article 6 GDPR.

15.1 Performance of a contract

Processing may be necessary to:

  • provide services;

  • communicate with a client;

  • manage an engagement;

  • deliver agreed work;

  • administer a contract.

15.2 Pre-contractual steps

Processing may be necessary to:

  • respond to a request;

  • discuss a potential project;

  • assess requirements;

  • prepare a proposal;

  • negotiate potential services.

15.3 Legal obligations

Processing may be necessary to comply with legal obligations such as:

  • tax requirements;

  • accounting requirements;

  • invoicing requirements;

  • legal-recordkeeping obligations;

  • lawful requests from competent authorities.

The EDPB recognises compliance with legal obligations as an independent Article 6 legal basis where the relevant obligation is imposed by EU or national law.

15.4 Legitimate interests

Caden Holt may rely on legitimate interests where processing is necessary and the interests are not overridden by the rights and freedoms of the data subject.

Examples may include:

  • maintaining business records;

  • preventing fraud and abuse;

  • protecting website and information systems;

  • managing professional relationships;

  • business development;

  • direct marketing where legally permissible;

  • maintaining do-not-contact records;

  • establishing, exercising or defending legal claims.

Where legitimate interests are used, Caden Holt considers the purpose, necessity, expectations of individuals, impact of the processing, and available safeguards.

15.5 Consent

Where Caden Holt relies on consent, consent will be requested separately and presented in a manner that is:

  • informed;

  • specific;

  • freely given;

  • unambiguous;

  • capable of being withdrawn.

Withdrawal of consent will be made as easy as giving it.

The Hellenic DPA states that valid consent requires an affirmative action and cannot be based on silence, inactivity or pre-ticked boxes.


16. Recipients of personal data

Personal data may be disclosed only where necessary and appropriate for the purposes described in this Privacy Notice.

Depending on the relationship and the services used, recipients or categories of recipients may include:

Technology and hosting providers

Providers used to:

  • host the website;

  • process website requests;

  • process contact-form submissions;

  • provide security and abuse prevention;

  • store business information.

This currently includes Framer B.V. for website hosting and related services. Framer's current DPA identifies Framer as a processor where it processes customer-controlled personal data.

Cloud and productivity providers

Where used, these may include:

  • Google services;

  • email services;

  • cloud storage;

  • document and spreadsheet services.

If Google Sheets is configured as the destination for the website's native contact form, submitted information may be transferred to Google for storage and processing in that service.

CRM and business-management providers

Where used, limited prospect or client information may be transferred to a CRM or business-management platform for:

  • contact management;

  • project management;

  • business-development tracking;

  • follow-up;

  • suppression of unwanted marketing communication.

Professional advisers

Information may be shared with:

  • accountants;

  • lawyers;

  • professional advisers;

  • insurers;

  • auditors;

where necessary for legal, accounting, tax, compliance or risk-management purposes.

Depending on the activity, such advisers may act as independent controllers or processors.

Authorities and other third parties

Personal data may be disclosed where necessary to:

  • comply with law;

  • respond to lawful requests;

  • establish, exercise or defend legal claims;

  • protect the rights, property or security of Caden Holt or others;

  • investigate fraud or abuse.

Caden Holt does not sell personal data.


17. Service providers and processors

Where Caden Holt engages a third party to process personal data on its behalf, the relationship will be governed by the contractual and legal requirements applicable to processors.

Processors may only process personal data for the relevant purposes and in accordance with the applicable instructions and contractual obligations.

The GDPR requires controller-processor relationships to be governed by an appropriate legal instrument and requires processors to implement appropriate safeguards.


18. Google services

Caden Holt may use Google services for business email, document storage, spreadsheets, lead management or other business operations.

Where personal data are processed by Google, the applicable Google privacy terms and contractual data-processing terms will also apply.

For services provided in the European Economic Area, Google commonly operates through Google Ireland Limited, although the applicable Google entity and processing relationship depend on the specific service and account configuration.

Where Google processes personal data as a processor for a business service, the applicable Google data-processing terms govern that processing.

Where Google acts independently as a controller for particular service-related processing, Google's own privacy notice governs that processing.

Google states that it relies on appropriate transfer mechanisms for restricted international transfers, including Standard Contractual Clauses where required.


19. Framer

Caden Holt uses Framer to host and operate cadenholt.com.

Framer's current DPA, effective 16 June 2026, provides contractual data-processing terms intended to satisfy Article 28 GDPR requirements where Framer processes personal data on behalf of its customers. It describes categories of personal data that may include names, email addresses, IP addresses, device information and information relating to end users.

Framer's current privacy statement states that it may transfer personal data to third parties and infrastructure located outside the EEA, including the United States, and states that such transfers are carried out under Chapter V GDPR requirements.

Caden Holt relies on Framer's contractual safeguards and applicable transfer mechanisms in accordance with the GDPR and applicable law.


20. International transfers

Because Caden Holt operates online and uses service providers that may operate internationally, personal data may be processed outside Greece or outside the European Economic Area.

Where personal data are transferred to a country that does not benefit from an applicable adequacy decision, Caden Holt will rely on an applicable legal transfer mechanism under Chapter V GDPR, such as:

  • an adequacy decision;

  • Standard Contractual Clauses;

  • another lawful transfer mechanism recognised under applicable law.

Where required, additional safeguards will be considered based on the circumstances of the transfer.

Caden Holt does not treat the physical location of a server as a substitute for GDPR compliance; the legality of an international transfer depends on the applicable transfer mechanism and safeguards.

Framer currently states that its infrastructure can involve transfers to the United States and other third countries under Chapter V GDPR safeguards. Google likewise states that it uses adequacy mechanisms and SCCs where required.


21. Data retention

Caden Holt retains personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

Retention periods depend on the nature and purpose of the data.

21.1 Website enquiries

Information provided through a general project enquiry is normally retained for up to six months following the last meaningful interaction, unless:

  • the enquiry becomes an active client relationship;

  • a proposal or contract remains relevant;

  • further communication is reasonably expected;

  • a legal claim or dispute exists;

  • a legal or accounting obligation requires longer retention;

  • a person has made a specific request that requires a different handling approach under applicable law.

After the relevant period, the data will be deleted or anonymised where reasonably practicable.

21.2 Prospects and business-development records

Professional prospect information used for business development is normally reviewed periodically and should not be retained indefinitely.

Where there has been no meaningful interaction or ongoing business purpose, records will normally be deleted or anonymised after the applicable retention period.

Caden Holt may retain a minimal suppression record where necessary to ensure a prior objection to marketing is respected.

21.3 Client records

Records relating to projects, contracts, invoices, payments, accounting and legal obligations may need to be retained for longer periods than ordinary enquiry data.

Such records will be retained for the period required or reasonably necessary under applicable tax, accounting, contractual and legal requirements.

21.4 Security and technical records

Technical and security information may be retained for the period reasonably necessary to:

  • detect and investigate security incidents;

  • maintain service integrity;

  • troubleshoot technical problems;

  • establish or defend legal claims.

Where such information is controlled by a third-party service provider, the provider's applicable retention terms may also apply.

The GDPR does not prescribe one universal retention period; controllers are required to establish retention periods appropriate to the purpose and to comply with the storage-limitation principle.


22. Data minimisation

Caden Holt seeks to collect and process only the personal data reasonably necessary for the relevant purpose.

The business does not intentionally collect broad personal profiles of website visitors.

Where a client, prospect or visitor provides additional information voluntarily, Caden Holt will assess whether that information is necessary for the relevant purpose and may delete unnecessary information.

Data minimisation is a core GDPR principle.


23. Accuracy

Caden Holt takes reasonable steps to keep personal data accurate and up to date where the business has ongoing reason to rely on that information.

Individuals may request correction of inaccurate or incomplete information.

The GDPR requires personal data to be accurate and, where necessary, kept up to date.


24. Data security

Caden Holt applies technical and organisational measures appropriate to the nature and risk of the processing.

Depending on the system and service involved, safeguards may include:

  • access controls;

  • multi-factor authentication;

  • strong authentication credentials;

  • least-privilege access;

  • secure HTTPS connections;

  • updated operating systems and software;

  • controlled access to cloud accounts;

  • private access to business spreadsheets and CRM systems;

  • spam and abuse protection;

  • secure device practices;

  • backups where appropriate;

  • procedures for responding to incidents;

  • deletion of unnecessary data;

  • confidentiality obligations where applicable.

No method of transmission or storage can be guaranteed to be completely secure.

Where a security incident results in a personal-data breach, Caden Holt will assess the incident and comply with the applicable GDPR notification and communication requirements.

The GDPR requires security measures proportionate to risk, and qualifying breaches may need to be notified to the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk to individuals; high-risk breaches may also require communication to affected individuals.


25. Data breaches

Caden Holt maintains procedures intended to identify, investigate, contain and document personal-data breaches.

Where a personal-data breach is likely to result in a risk to the rights and freedoms of individuals, Caden Holt will assess whether notification to the competent supervisory authority is required.

Where a personal-data breach is likely to result in a high risk to individuals, Caden Holt will assess whether direct communication to affected individuals is required.

Relevant incidents will be documented in accordance with applicable legal requirements.


26. Your rights

Subject to applicable legal conditions and exceptions, you may have the right to:

Access

Request confirmation of whether Caden Holt processes your personal data and, where applicable, obtain access to that data and related information.

Rectification

Request correction of inaccurate or incomplete personal data.

Erasure

Request deletion of personal data where the legal conditions for erasure are satisfied.

Restriction

Request restriction of processing in circumstances provided by law.

Objection

Object to processing based on legitimate interests where the applicable legal conditions are satisfied.

You have an absolute right to object to the processing of personal data for direct marketing purposes.

Data portability

Where the legal conditions are satisfied, request the personal data you have provided in a structured, commonly used and machine-readable format, or request transmission to another controller.

Withdrawal of consent

Where processing is based on consent, withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

These rights correspond to the rights established by Articles 15–22 GDPR, subject to the specific conditions applicable to each right. The Hellenic DPA provides guidance on access, rectification, erasure, restriction, portability and objection rights.


27. How to exercise your rights

To make a privacy request, contact:

[email protected]

Please provide enough information to allow Caden Holt to understand and verify your request.

Where reasonably necessary to protect personal data against unauthorised disclosure, Caden Holt may request additional information to verify the identity of the person making the request.

Requests concerning privacy rights are handled without charge unless applicable law permits a reasonable charge or refusal because a request is manifestly unfounded or excessive.

Caden Holt will generally respond without undue delay and, in any event, within one month of receiving a valid request, subject to the statutory rules allowing an extension where necessary because of the complexity or number of requests. Where an extension applies, the requester will be informed within the initial response period.

The Hellenic DPA likewise states that data-subject requests are generally answered within one month and may be extended in accordance with the GDPR.


28. Objections to marketing

You may object to direct marketing at any time.

You can do this by:

  • emailing [email protected];

  • replying to a promotional email where an unsubscribe mechanism is provided;

  • telling the caller directly during a promotional telephone call;

  • using any other objection mechanism specifically provided in the communication.

A direct-marketing objection will be recorded and applied to the relevant contact information so that future promotional use can be prevented.

Under Article 21(2)–(3) GDPR, an objection to direct marketing requires cessation of processing for that purpose.


29. Complaints

If you believe that your personal data have been processed unlawfully or that your privacy rights have not been respected, you are encouraged to contact Caden Holt first at:

[email protected]

You also have the right to lodge a complaint with the competent data-protection supervisory authority.

For the purposes of processing carried out in Greece, the competent authority is:

Hellenic Data Protection Authority (HDPA)
1–3 Kifisias
115 23 Athens
Greece
Email: [email protected]

The Hellenic DPA accepts complaints concerning alleged GDPR violations and matters relating to unsolicited promotional telephone calls and electronic communications.


30. Automated decision-making and profiling

Caden Holt does not currently make decisions concerning individuals based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.

The business does not currently use personal-data scoring systems to determine whether an individual can purchase services, receive different prices, obtain different contractual terms, or otherwise receive materially different treatment based solely on automated processing.

If this changes, the relevant processing and information provided to individuals will be reviewed before implementation.


31. Special categories of personal data

Caden Holt does not intentionally seek to collect or process special categories of personal data through the website.

Special categories include information such as:

  • health information;

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade-union membership;

  • genetic data;

  • biometric data used for identification;

  • information concerning sex life or sexual orientation.

Caden Holt does not request such information through the website contact form.

Where special-category information is voluntarily provided, Caden Holt will assess whether there is a lawful reason to retain or process it and will otherwise delete it where appropriate.

The GDPR provides additional restrictions for special-category data.


32. Criminal-conviction and offence data

Caden Holt does not intentionally collect information relating to criminal convictions or offences through the website.

Such information will not be requested through the ordinary contact form.


33. Children's data

Caden Holt's website and professional services are not specifically directed at children.

Caden Holt does not intentionally collect personal data from children through the website as part of a child-focused service.

If personal data relating to a child are unexpectedly provided, the information will be handled in accordance with applicable law and deleted where there is no lawful reason to retain it.

Greek law sets the relevant age for a child's own consent to processing under Article 8 GDPR in information-society services at 15 years, subject to the conditions specified by Law 4624/2019.


34. Cookies and similar technologies

cadenholt.com may use technologies that are necessary to:

  • operate the website;

  • maintain security;

  • remember necessary technical preferences;

  • support requested functionality.

Where a technology is strictly necessary for the requested service or transmission of communications, consent is not required under the applicable ePrivacy exception.

Non-essential cookies or technologies that require consent will not be activated before the relevant consent has been obtained.

The Hellenic DPA states that Article 4(5) of Law 3471/2006 generally requires prior consent for storing or accessing information on a user's terminal equipment, subject to the narrowly defined exception for technically necessary functionality.

Caden Holt currently does not use advertising cookies.

Where applicable, a separate Cookie Notice will identify the cookies and similar technologies actually used on the website, their purpose, provider, duration and consent requirements.

If third-party technologies such as Google Analytics, advertising pixels, video embeds or behavioural-tracking tools are introduced, the website's cookie controls and privacy information will be updated accordingly.

The Hellenic DPA specifically distinguishes analytics cookies from technically necessary cookies and states that third-party analytics cookies such as Google Analytics require consent under the applicable rules.


35. Embedded third-party content

cadenholt.com may from time to time include links to or, where technically necessary, content provided by third parties.

Third-party content may cause the relevant provider to process information about your visit.

Where such functionality is introduced, the relevant privacy and cookie implications will be reviewed and disclosed appropriately.


36. External links

The website may contain links to third-party websites, including websites of clients, project partners, service providers and other organisations.

Caden Holt is not responsible for the privacy practices, security or content of third-party websites.

You should review the privacy information of any external website before providing personal data to that website.


37. Client projects and third-party personal data

When Caden Holt provides design, website, branding or related services to a client, project materials may contain personal data controlled by that client.

Where Caden Holt processes such information solely on the client's instructions, the client's privacy notice and the applicable contractual data-processing terms govern that processing.

Caden Holt will not use client-controlled personal data for its own unrelated purposes unless a separate lawful basis exists.

Where required, Caden Holt will enter into a data-processing agreement or equivalent terms addressing:

  • processing instructions;

  • confidentiality;

  • security;

  • subprocessors;

  • assistance with data-subject requests;

  • breach handling;

  • deletion or return of data;

  • audit or compliance obligations.

The GDPR requires processors to process data only on documented instructions and to implement appropriate safeguards.

This distinction is particularly important as Caden Holt's client work expands from simple websites into systems that collect customer data.


38. No sale or rental of personal data

Caden Holt does not sell, rent or trade personal data for monetary consideration.

Personal data may be disclosed to service providers where necessary to operate the business or provide services, subject to the applicable contractual and legal safeguards.


39. No use of personal data for unrelated purposes

Personal data collected for one purpose will not be repurposed for an incompatible purpose.

Where Caden Holt proposes a materially different use of personal data, the business will assess whether the new processing is compatible with the original purpose and whether additional transparency or a separate legal basis is required.

Purpose limitation is a fundamental GDPR principle.


40. Law enforcement and legal requests

Caden Holt may disclose personal data where required by applicable law or where reasonably necessary to:

  • respond to a valid legal request;

  • comply with a court order or lawful authority request;

  • establish, exercise or defend legal claims;

  • investigate fraud;

  • protect the safety, rights or property of the business or another person.

Where legally permitted, Caden Holt will seek to limit disclosure to information reasonably necessary for the relevant purpose.


41. Changes to this Privacy Notice

Caden Holt may update this Privacy Notice when the business:

  • introduces a new service;

  • changes the technologies used by the website;

  • adds or removes data processors;

  • introduces analytics, advertising or marketing technologies;

  • changes its data-retention practices;

  • changes the way contact information is collected;

  • changes its legal or business identity;

  • is required to update its disclosures by law.

The latest version will be published on this page with an updated “Last updated” date.

Where a change materially affects how existing personal data are processed and applicable law requires additional notice or consent, Caden Holt will take the required steps.


42. Contact

For questions about this Privacy Notice or the processing of personal data:

Caden Holt
Professional/trading name of APOSKITIS FILIPPOS

Privacy: [email protected]
General support: [email protected]


43. Legal framework

This Privacy Notice is intended to describe processing carried out in accordance with applicable data-protection law, including, where applicable:

  • Regulation (EU) 2016/679 (General Data Protection Regulation);

  • Greek Law 4624/2019;

  • Greek Law 3471/2006 concerning privacy in electronic communications;

  • other applicable Greek and European legislation.

Nothing in this Privacy Notice limits any mandatory right or protection granted to an individual under applicable law.


44. Version history

Version 1.0
Effective: 25 September 2026

Last updated: 25 September 2026
Version: 1.0


1. Who we are

This Privacy Notice explains how personal data are collected, used, stored, disclosed and otherwise processed when you visit cadenholt.com, contact Caden Holt, request information, enquire about services, become a client, or otherwise interact with the business in connection with its professional activities.

The website and the associated professional activities are operated by:

APOSKITIS FILIPPOS
a sole proprietor established in Greece
trading under the professional name Caden Holt

Registered office: PAPAFLESSA 23, VOULA, ATTICA, 16673
AFM: 181491799
G.E.M.I. number: 196127203000
Professional / trading name: Caden Holt
General contact: [email protected]
Privacy contact: [email protected]
Website: https://cadenholt.com

Caden Holt is the professional, public-facing name and registered distinctive title used by APOSKITIS FILIPPOS . It is not a separate legal entity from the sole proprietorship operated by APOSKITIS FILIPPOS.

At present, Caden Holt is used as a professional and trading name pending completion of its registration as a distinctive title where applicable. Once that registration is completed, this Privacy Notice may be updated to reflect the registered status of the name.

For purposes of applicable data-protection law, APOSKITIS FILIPPOS is the data controller for the personal data covered by this Privacy Notice, except where another party acts as controller or where Caden Holt processes personal data on behalf of a client under a separate contractual arrangement.

The controller is responsible for determining the purposes and means of processing personal data in connection with its own business activities. The GDPR places accountability for controller compliance on the controller.


2. Scope of this Privacy Notice

This Privacy Notice applies to personal data processed through:

  • cadenholt.com;

  • enquiries submitted through the website;

  • email communication with Caden Holt;

  • proposals and pre-contractual discussions;

  • client relationships and project administration;

  • professional business-development activity;

  • prospect and contact-management records;

  • information obtained from publicly available professional or business sources;

  • other interactions directly connected to the operation of the Caden Holt professional practice.

This Privacy Notice does not automatically govern websites operated by clients of Caden Holt, including websites that Caden Holt may design or develop for clients.

Where Caden Holt designs, develops, hosts or maintains a website, application or other system on behalf of a client and processes personal data according to that client's instructions, the client will generally determine the purposes and means of that processing and may therefore act as the data controller. Caden Holt may act as a data processor in such circumstances.

Where Caden Holt acts as a processor for a client, the relevant processing will be governed by the client's instructions and, where required, a separate data-processing agreement or equivalent contractual terms.

The distinction between controller and processor is determined by the actual purposes and means of processing rather than by the label given to the relationship.


3. What is personal data?

“Personal data” means information relating to an identified or identifiable natural person.

This can include information such as:

  • name;

  • email address;

  • telephone number;

  • professional position;

  • business contact details;

  • website or project URL;

  • communications and correspondence;

  • information contained in an enquiry;

  • identifiers and technical information where they can be linked to an individual;

  • records of interactions with Caden Holt.

Information relating solely to a legal entity, such as a company name or generic company information, will not necessarily constitute personal data. However, information about an identifiable individual working for or representing a business can constitute personal data.


4. Personal data we collect directly from you

When you contact Caden Holt through the website or by email, you may provide information including:

  • your name;

  • email address;

  • budget range;

  • website or project URL;

  • information contained in your message;

  • information you voluntarily provide during subsequent correspondence;

  • information necessary to prepare a proposal or provide services.

The current website contact form is intentionally limited to information needed to understand an enquiry and determine whether the requested services may be appropriate.

We do not ask you to provide sensitive personal information through the website.

Please do not submit

You should not submit passwords, authentication credentials, payment-card information, government identification numbers, health information, information about criminal convictions, or other sensitive personal information through the contact form unless Caden Holt specifically requests such information through an appropriate secure process.

If you voluntarily provide information that is not necessary for the relevant purpose, Caden Holt may delete it where appropriate.

This approach follows the GDPR principles of purpose limitation and data minimisation.


5. Information collected automatically when you visit the website

When you visit cadenholt.com, certain technical information may be processed automatically by the website infrastructure and its service providers.

Depending on the technologies active on the website and the circumstances of your visit, this may include:

  • IP address;

  • browser type and version;

  • operating system or device information;

  • date and time of access;

  • requested pages or resources;

  • referral information;

  • security and abuse-prevention signals;

  • diagnostic and performance information.

Caden Holt does not use this information to identify individual visitors for advertising purposes.

Certain technical processing may be necessary to:

  • deliver website content;

  • maintain website security;

  • protect against abuse and automated attacks;

  • diagnose technical problems;

  • maintain availability and performance;

  • establish and defend legal claims where necessary.

Framer's current data-processing documentation identifies categories such as IP address, device information, address information and business contact details among information that may be processed in connection with its services.


6. Website analytics

Caden Holt may use the analytics functionality provided directly by Framer to understand aggregate website usage and improve the site.

Framer currently describes its built-in analytics as a privacy-oriented system that does not use cookies or persistent identifiers and states that its analytics are designed not to identify individual visitors.

Where analytics are used, they are used to understand aggregate measures such as:

  • page views;

  • traffic sources;

  • device categories;

  • browser categories;

  • approximate geographic information;

  • website usage patterns at an aggregate level.

Caden Holt does not use analytics information to make decisions that produce legal or similarly significant effects on individuals.

If additional analytics, advertising or tracking services are introduced, the website's cookie and privacy information will be updated as required before those technologies are deployed.


7. Contact-form processing

When you submit the contact form, the information you provide may be transmitted through Framer's form infrastructure and delivered to the configured destination, such as email or Google Sheets.

The contact information is used to:

  1. receive your enquiry;

  2. understand what you are requesting;

  3. determine whether Caden Holt can provide the requested service;

  4. communicate with you;

  5. prepare or discuss a proposal where appropriate;

  6. follow up on a genuine business enquiry;

  7. maintain an accurate record of the interaction;

  8. protect against spam, abuse and fraudulent submissions.

Framer currently supports native form submissions to email, Google Sheets and custom webhooks, and provides built-in spam protection/rate-limiting functionality.

Legal basis

Where you contact Caden Holt to request information, obtain a quotation, discuss a project or take steps toward entering into a contract, processing may be necessary for the purposes of taking steps at your request before entering into a contract.

The GDPR expressly recognises pre-contractual processing, including processing necessary to respond to a person's request for a quotation or proposed service, as a potential Article 6(1)(b) legal basis.

Caden Holt may also process limited information on the basis of legitimate interests where necessary for:

  • operating and securing the business;

  • preventing spam and abuse;

  • maintaining business records;

  • managing professional relationships;

  • establishing, exercising or defending legal claims.

Where legitimate interests are relied upon, Caden Holt considers the necessity of the processing and balances those interests against the rights and freedoms of the individuals concerned. The GDPR requires such an assessment where Article 6(1)(f) is relied upon.


8. Business and client administration

If an enquiry becomes a client relationship, additional personal data may be processed where necessary to establish and manage the professional relationship.

This may include:

  • name;

  • business role;

  • business contact details;

  • project information;

  • correspondence;

  • proposal and contract information;

  • invoicing and payment information;

  • information necessary to provide the contracted services;

  • records of approvals, instructions and deliverables;

  • records necessary to resolve disputes or enforce contractual rights.

This processing may be based on:

  • performance of a contract;

  • taking steps before entering into a contract;

  • compliance with legal obligations;

  • legitimate interests in managing and protecting the business;

  • establishment, exercise or defence of legal claims.

Where tax, accounting, invoicing or other legislation requires records to be retained, those records will be retained for the period required by applicable law even where ordinary operational retention periods would otherwise have expired.


9. Professional and business-development contacts

Caden Holt may conduct professional business-development activities directed primarily toward businesses and professional contacts.

In connection with these activities, Caden Holt may collect limited professional contact information from:

  • business websites;

  • publicly accessible business directories;

  • public business listings;

  • publicly available professional profiles;

  • publicly listed business telephone numbers;

  • referrals;

  • business correspondence;

  • information provided directly during a professional interaction.

Where information relates to an identifiable individual, it is treated as personal data and processed in accordance with applicable data-protection law.

The fact that information is publicly accessible does not by itself remove it from the scope of the GDPR where it relates to an identifiable individual.

The Hellenic Data Protection Authority specifically recognises that promotional data may be obtained from lawful/public sources, but requires appropriate transparency and respect for objection rights.


10. Information obtained from public sources

Where personal data are obtained from a source other than the individual concerned, the relevant processing may be carried out for legitimate business-development purposes where permitted by applicable law and where the necessary balancing and transparency requirements are satisfied.

The categories of information may include:

  • name;

  • professional role;

  • business;

  • business website;

  • business telephone number;

  • professional email address where lawfully available;

  • publicly available business information relevant to the professional relationship.

Caden Holt seeks to limit such information to what is reasonably necessary for the relevant professional purpose.

The sources of such information may include:

  • the individual's employer or business website;

  • public business directories;

  • public business listings;

  • professional networking or business-profile pages;

  • other publicly accessible professional sources.

Where required by Article 14 GDPR, Caden Holt will provide information about the source of the data and the processing at the relevant time, including no later than the first communication where the applicable law permits processing for that purpose and requires such disclosure.

The GDPR requires additional transparency where personal data are obtained from a source other than the data subject, including information concerning the source of the data.


11. Direct marketing

Caden Holt distinguishes between:

  • responding to an enquiry;

  • maintaining a client relationship;

  • business-development activity;

  • direct marketing communications.

Direct marketing is carried out only where permitted under applicable data-protection and electronic-communications law.

Where processing for direct marketing is based on legitimate interests under the GDPR, individuals have an unconditional right to object to the use of their personal data for direct marketing. Once such an objection is made, the personal data must no longer be processed for that direct-marketing purpose.


12. Promotional telephone calls

Caden Holt may make human-assisted telephone calls for professional or business-development purposes where legally permitted.

For promotional telephone calls, Caden Holt will comply with applicable Greek electronic-communications law, including the rules governing unsolicited promotional calls under Article 11 of Law 3471/2006.

In particular, Caden Holt will:

  • use lawful professional/business contact information;

  • respect applicable provider-level opt-out registers;

  • maintain its own internal do-not-contact records;

  • respect objections made directly to Caden Holt;

  • stop promotional calling where an individual exercises an applicable objection;

  • not use automated calling systems where prior consent is required and has not been obtained.

Under the current Greek framework, unsolicited human-assisted promotional telephone calls operate under an opt-out regime, while automated promotional communications and electronic communications such as email and SMS generally require prior consent, subject to the exceptions provided by law.


13. Promotional email and electronic communications

Caden Holt does not treat a publicly listed email address as blanket permission to send unsolicited promotional email.

Promotional email, SMS and other electronic marketing communications are subject to the applicable rules of Greek Law 3471/2006 and other applicable law.

Where prior consent is legally required, Caden Holt will obtain that consent before sending such communications.

Where a legally recognised existing-customer exception applies, Caden Holt may communicate regarding its own similar services provided all applicable legal requirements are satisfied, including an effective and easy means to object or unsubscribe.

Every promotional electronic communication sent where required by law will clearly identify the sender and provide a valid mechanism for stopping further promotional communication.

The Hellenic DPA currently states that unsolicited electronic promotional communications such as email and SMS generally require prior consent, subject to the statutory customer-relationship exception.


14. Do-not-contact and suppression records

When a person objects to direct marketing, Caden Holt may retain a minimal suppression record necessary to ensure that the objection is respected in the future.

This may include:

  • name;

  • business;

  • contact identifier;

  • type of objection;

  • date of objection;

  • source of objection;

  • minimum information required to prevent future marketing communication.

A suppression record is maintained only for the purpose of ensuring that promotional communications are not subsequently directed to the person.

This limited retention may continue for as long as reasonably necessary to ensure the objection is respected.

The Hellenic DPA expressly recognises the need for controllers engaging in direct marketing to maintain mechanisms or records that prevent further promotional use following an objection.


15. Legal bases for processing

Depending on the specific processing activity, Caden Holt may rely on one or more of the following legal bases under Article 6 GDPR.

15.1 Performance of a contract

Processing may be necessary to:

  • provide services;

  • communicate with a client;

  • manage an engagement;

  • deliver agreed work;

  • administer a contract.

15.2 Pre-contractual steps

Processing may be necessary to:

  • respond to a request;

  • discuss a potential project;

  • assess requirements;

  • prepare a proposal;

  • negotiate potential services.

15.3 Legal obligations

Processing may be necessary to comply with legal obligations such as:

  • tax requirements;

  • accounting requirements;

  • invoicing requirements;

  • legal-recordkeeping obligations;

  • lawful requests from competent authorities.

The EDPB recognises compliance with legal obligations as an independent Article 6 legal basis where the relevant obligation is imposed by EU or national law.

15.4 Legitimate interests

Caden Holt may rely on legitimate interests where processing is necessary and the interests are not overridden by the rights and freedoms of the data subject.

Examples may include:

  • maintaining business records;

  • preventing fraud and abuse;

  • protecting website and information systems;

  • managing professional relationships;

  • business development;

  • direct marketing where legally permissible;

  • maintaining do-not-contact records;

  • establishing, exercising or defending legal claims.

Where legitimate interests are used, Caden Holt considers the purpose, necessity, expectations of individuals, impact of the processing, and available safeguards.

15.5 Consent

Where Caden Holt relies on consent, consent will be requested separately and presented in a manner that is:

  • informed;

  • specific;

  • freely given;

  • unambiguous;

  • capable of being withdrawn.

Withdrawal of consent will be made as easy as giving it.

The Hellenic DPA states that valid consent requires an affirmative action and cannot be based on silence, inactivity or pre-ticked boxes.


16. Recipients of personal data

Personal data may be disclosed only where necessary and appropriate for the purposes described in this Privacy Notice.

Depending on the relationship and the services used, recipients or categories of recipients may include:

Technology and hosting providers

Providers used to:

  • host the website;

  • process website requests;

  • process contact-form submissions;

  • provide security and abuse prevention;

  • store business information.

This currently includes Framer B.V. for website hosting and related services. Framer's current DPA identifies Framer as a processor where it processes customer-controlled personal data.

Cloud and productivity providers

Where used, these may include:

  • Google services;

  • email services;

  • cloud storage;

  • document and spreadsheet services.

If Google Sheets is configured as the destination for the website's native contact form, submitted information may be transferred to Google for storage and processing in that service.

CRM and business-management providers

Where used, limited prospect or client information may be transferred to a CRM or business-management platform for:

  • contact management;

  • project management;

  • business-development tracking;

  • follow-up;

  • suppression of unwanted marketing communication.

Professional advisers

Information may be shared with:

  • accountants;

  • lawyers;

  • professional advisers;

  • insurers;

  • auditors;

where necessary for legal, accounting, tax, compliance or risk-management purposes.

Depending on the activity, such advisers may act as independent controllers or processors.

Authorities and other third parties

Personal data may be disclosed where necessary to:

  • comply with law;

  • respond to lawful requests;

  • establish, exercise or defend legal claims;

  • protect the rights, property or security of Caden Holt or others;

  • investigate fraud or abuse.

Caden Holt does not sell personal data.


17. Service providers and processors

Where Caden Holt engages a third party to process personal data on its behalf, the relationship will be governed by the contractual and legal requirements applicable to processors.

Processors may only process personal data for the relevant purposes and in accordance with the applicable instructions and contractual obligations.

The GDPR requires controller-processor relationships to be governed by an appropriate legal instrument and requires processors to implement appropriate safeguards.


18. Google services

Caden Holt may use Google services for business email, document storage, spreadsheets, lead management or other business operations.

Where personal data are processed by Google, the applicable Google privacy terms and contractual data-processing terms will also apply.

For services provided in the European Economic Area, Google commonly operates through Google Ireland Limited, although the applicable Google entity and processing relationship depend on the specific service and account configuration.

Where Google processes personal data as a processor for a business service, the applicable Google data-processing terms govern that processing.

Where Google acts independently as a controller for particular service-related processing, Google's own privacy notice governs that processing.

Google states that it relies on appropriate transfer mechanisms for restricted international transfers, including Standard Contractual Clauses where required.


19. Framer

Caden Holt uses Framer to host and operate cadenholt.com.

Framer's current DPA, effective 16 June 2026, provides contractual data-processing terms intended to satisfy Article 28 GDPR requirements where Framer processes personal data on behalf of its customers. It describes categories of personal data that may include names, email addresses, IP addresses, device information and information relating to end users.

Framer's current privacy statement states that it may transfer personal data to third parties and infrastructure located outside the EEA, including the United States, and states that such transfers are carried out under Chapter V GDPR requirements.

Caden Holt relies on Framer's contractual safeguards and applicable transfer mechanisms in accordance with the GDPR and applicable law.


20. International transfers

Because Caden Holt operates online and uses service providers that may operate internationally, personal data may be processed outside Greece or outside the European Economic Area.

Where personal data are transferred to a country that does not benefit from an applicable adequacy decision, Caden Holt will rely on an applicable legal transfer mechanism under Chapter V GDPR, such as:

  • an adequacy decision;

  • Standard Contractual Clauses;

  • another lawful transfer mechanism recognised under applicable law.

Where required, additional safeguards will be considered based on the circumstances of the transfer.

Caden Holt does not treat the physical location of a server as a substitute for GDPR compliance; the legality of an international transfer depends on the applicable transfer mechanism and safeguards.

Framer currently states that its infrastructure can involve transfers to the United States and other third countries under Chapter V GDPR safeguards. Google likewise states that it uses adequacy mechanisms and SCCs where required.


21. Data retention

Caden Holt retains personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

Retention periods depend on the nature and purpose of the data.

21.1 Website enquiries

Information provided through a general project enquiry is normally retained for up to six months following the last meaningful interaction, unless:

  • the enquiry becomes an active client relationship;

  • a proposal or contract remains relevant;

  • further communication is reasonably expected;

  • a legal claim or dispute exists;

  • a legal or accounting obligation requires longer retention;

  • a person has made a specific request that requires a different handling approach under applicable law.

After the relevant period, the data will be deleted or anonymised where reasonably practicable.

21.2 Prospects and business-development records

Professional prospect information used for business development is normally reviewed periodically and should not be retained indefinitely.

Where there has been no meaningful interaction or ongoing business purpose, records will normally be deleted or anonymised after the applicable retention period.

Caden Holt may retain a minimal suppression record where necessary to ensure a prior objection to marketing is respected.

21.3 Client records

Records relating to projects, contracts, invoices, payments, accounting and legal obligations may need to be retained for longer periods than ordinary enquiry data.

Such records will be retained for the period required or reasonably necessary under applicable tax, accounting, contractual and legal requirements.

21.4 Security and technical records

Technical and security information may be retained for the period reasonably necessary to:

  • detect and investigate security incidents;

  • maintain service integrity;

  • troubleshoot technical problems;

  • establish or defend legal claims.

Where such information is controlled by a third-party service provider, the provider's applicable retention terms may also apply.

The GDPR does not prescribe one universal retention period; controllers are required to establish retention periods appropriate to the purpose and to comply with the storage-limitation principle.


22. Data minimisation

Caden Holt seeks to collect and process only the personal data reasonably necessary for the relevant purpose.

The business does not intentionally collect broad personal profiles of website visitors.

Where a client, prospect or visitor provides additional information voluntarily, Caden Holt will assess whether that information is necessary for the relevant purpose and may delete unnecessary information.

Data minimisation is a core GDPR principle.


23. Accuracy

Caden Holt takes reasonable steps to keep personal data accurate and up to date where the business has ongoing reason to rely on that information.

Individuals may request correction of inaccurate or incomplete information.

The GDPR requires personal data to be accurate and, where necessary, kept up to date.


24. Data security

Caden Holt applies technical and organisational measures appropriate to the nature and risk of the processing.

Depending on the system and service involved, safeguards may include:

  • access controls;

  • multi-factor authentication;

  • strong authentication credentials;

  • least-privilege access;

  • secure HTTPS connections;

  • updated operating systems and software;

  • controlled access to cloud accounts;

  • private access to business spreadsheets and CRM systems;

  • spam and abuse protection;

  • secure device practices;

  • backups where appropriate;

  • procedures for responding to incidents;

  • deletion of unnecessary data;

  • confidentiality obligations where applicable.

No method of transmission or storage can be guaranteed to be completely secure.

Where a security incident results in a personal-data breach, Caden Holt will assess the incident and comply with the applicable GDPR notification and communication requirements.

The GDPR requires security measures proportionate to risk, and qualifying breaches may need to be notified to the competent supervisory authority within 72 hours unless the breach is unlikely to result in a risk to individuals; high-risk breaches may also require communication to affected individuals.


25. Data breaches

Caden Holt maintains procedures intended to identify, investigate, contain and document personal-data breaches.

Where a personal-data breach is likely to result in a risk to the rights and freedoms of individuals, Caden Holt will assess whether notification to the competent supervisory authority is required.

Where a personal-data breach is likely to result in a high risk to individuals, Caden Holt will assess whether direct communication to affected individuals is required.

Relevant incidents will be documented in accordance with applicable legal requirements.


26. Your rights

Subject to applicable legal conditions and exceptions, you may have the right to:

Access

Request confirmation of whether Caden Holt processes your personal data and, where applicable, obtain access to that data and related information.

Rectification

Request correction of inaccurate or incomplete personal data.

Erasure

Request deletion of personal data where the legal conditions for erasure are satisfied.

Restriction

Request restriction of processing in circumstances provided by law.

Objection

Object to processing based on legitimate interests where the applicable legal conditions are satisfied.

You have an absolute right to object to the processing of personal data for direct marketing purposes.

Data portability

Where the legal conditions are satisfied, request the personal data you have provided in a structured, commonly used and machine-readable format, or request transmission to another controller.

Withdrawal of consent

Where processing is based on consent, withdraw that consent at any time.

Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

These rights correspond to the rights established by Articles 15–22 GDPR, subject to the specific conditions applicable to each right. The Hellenic DPA provides guidance on access, rectification, erasure, restriction, portability and objection rights.


27. How to exercise your rights

To make a privacy request, contact:

[email protected]

Please provide enough information to allow Caden Holt to understand and verify your request.

Where reasonably necessary to protect personal data against unauthorised disclosure, Caden Holt may request additional information to verify the identity of the person making the request.

Requests concerning privacy rights are handled without charge unless applicable law permits a reasonable charge or refusal because a request is manifestly unfounded or excessive.

Caden Holt will generally respond without undue delay and, in any event, within one month of receiving a valid request, subject to the statutory rules allowing an extension where necessary because of the complexity or number of requests. Where an extension applies, the requester will be informed within the initial response period.

The Hellenic DPA likewise states that data-subject requests are generally answered within one month and may be extended in accordance with the GDPR.


28. Objections to marketing

You may object to direct marketing at any time.

You can do this by:

  • emailing [email protected];

  • replying to a promotional email where an unsubscribe mechanism is provided;

  • telling the caller directly during a promotional telephone call;

  • using any other objection mechanism specifically provided in the communication.

A direct-marketing objection will be recorded and applied to the relevant contact information so that future promotional use can be prevented.

Under Article 21(2)–(3) GDPR, an objection to direct marketing requires cessation of processing for that purpose.


29. Complaints

If you believe that your personal data have been processed unlawfully or that your privacy rights have not been respected, you are encouraged to contact Caden Holt first at:

[email protected]

You also have the right to lodge a complaint with the competent data-protection supervisory authority.

For the purposes of processing carried out in Greece, the competent authority is:

Hellenic Data Protection Authority (HDPA)
1–3 Kifisias
115 23 Athens
Greece
Email: [email protected]

The Hellenic DPA accepts complaints concerning alleged GDPR violations and matters relating to unsolicited promotional telephone calls and electronic communications.


30. Automated decision-making and profiling

Caden Holt does not currently make decisions concerning individuals based solely on automated processing, including profiling, that produce legal effects or similarly significant effects.

The business does not currently use personal-data scoring systems to determine whether an individual can purchase services, receive different prices, obtain different contractual terms, or otherwise receive materially different treatment based solely on automated processing.

If this changes, the relevant processing and information provided to individuals will be reviewed before implementation.


31. Special categories of personal data

Caden Holt does not intentionally seek to collect or process special categories of personal data through the website.

Special categories include information such as:

  • health information;

  • racial or ethnic origin;

  • political opinions;

  • religious or philosophical beliefs;

  • trade-union membership;

  • genetic data;

  • biometric data used for identification;

  • information concerning sex life or sexual orientation.

Caden Holt does not request such information through the website contact form.

Where special-category information is voluntarily provided, Caden Holt will assess whether there is a lawful reason to retain or process it and will otherwise delete it where appropriate.

The GDPR provides additional restrictions for special-category data.


32. Criminal-conviction and offence data

Caden Holt does not intentionally collect information relating to criminal convictions or offences through the website.

Such information will not be requested through the ordinary contact form.


33. Children's data

Caden Holt's website and professional services are not specifically directed at children.

Caden Holt does not intentionally collect personal data from children through the website as part of a child-focused service.

If personal data relating to a child are unexpectedly provided, the information will be handled in accordance with applicable law and deleted where there is no lawful reason to retain it.

Greek law sets the relevant age for a child's own consent to processing under Article 8 GDPR in information-society services at 15 years, subject to the conditions specified by Law 4624/2019.


34. Cookies and similar technologies

cadenholt.com may use technologies that are necessary to:

  • operate the website;

  • maintain security;

  • remember necessary technical preferences;

  • support requested functionality.

Where a technology is strictly necessary for the requested service or transmission of communications, consent is not required under the applicable ePrivacy exception.

Non-essential cookies or technologies that require consent will not be activated before the relevant consent has been obtained.

The Hellenic DPA states that Article 4(5) of Law 3471/2006 generally requires prior consent for storing or accessing information on a user's terminal equipment, subject to the narrowly defined exception for technically necessary functionality.

Caden Holt currently does not use advertising cookies.

Where applicable, a separate Cookie Notice will identify the cookies and similar technologies actually used on the website, their purpose, provider, duration and consent requirements.

If third-party technologies such as Google Analytics, advertising pixels, video embeds or behavioural-tracking tools are introduced, the website's cookie controls and privacy information will be updated accordingly.

The Hellenic DPA specifically distinguishes analytics cookies from technically necessary cookies and states that third-party analytics cookies such as Google Analytics require consent under the applicable rules.


35. Embedded third-party content

cadenholt.com may from time to time include links to or, where technically necessary, content provided by third parties.

Third-party content may cause the relevant provider to process information about your visit.

Where such functionality is introduced, the relevant privacy and cookie implications will be reviewed and disclosed appropriately.


36. External links

The website may contain links to third-party websites, including websites of clients, project partners, service providers and other organisations.

Caden Holt is not responsible for the privacy practices, security or content of third-party websites.

You should review the privacy information of any external website before providing personal data to that website.


37. Client projects and third-party personal data

When Caden Holt provides design, website, branding or related services to a client, project materials may contain personal data controlled by that client.

Where Caden Holt processes such information solely on the client's instructions, the client's privacy notice and the applicable contractual data-processing terms govern that processing.

Caden Holt will not use client-controlled personal data for its own unrelated purposes unless a separate lawful basis exists.

Where required, Caden Holt will enter into a data-processing agreement or equivalent terms addressing:

  • processing instructions;

  • confidentiality;

  • security;

  • subprocessors;

  • assistance with data-subject requests;

  • breach handling;

  • deletion or return of data;

  • audit or compliance obligations.

The GDPR requires processors to process data only on documented instructions and to implement appropriate safeguards.

This distinction is particularly important as Caden Holt's client work expands from simple websites into systems that collect customer data.


38. No sale or rental of personal data

Caden Holt does not sell, rent or trade personal data for monetary consideration.

Personal data may be disclosed to service providers where necessary to operate the business or provide services, subject to the applicable contractual and legal safeguards.


39. No use of personal data for unrelated purposes

Personal data collected for one purpose will not be repurposed for an incompatible purpose.

Where Caden Holt proposes a materially different use of personal data, the business will assess whether the new processing is compatible with the original purpose and whether additional transparency or a separate legal basis is required.

Purpose limitation is a fundamental GDPR principle.


40. Law enforcement and legal requests

Caden Holt may disclose personal data where required by applicable law or where reasonably necessary to:

  • respond to a valid legal request;

  • comply with a court order or lawful authority request;

  • establish, exercise or defend legal claims;

  • investigate fraud;

  • protect the safety, rights or property of the business or another person.

Where legally permitted, Caden Holt will seek to limit disclosure to information reasonably necessary for the relevant purpose.


41. Changes to this Privacy Notice

Caden Holt may update this Privacy Notice when the business:

  • introduces a new service;

  • changes the technologies used by the website;

  • adds or removes data processors;

  • introduces analytics, advertising or marketing technologies;

  • changes its data-retention practices;

  • changes the way contact information is collected;

  • changes its legal or business identity;

  • is required to update its disclosures by law.

The latest version will be published on this page with an updated “Last updated” date.

Where a change materially affects how existing personal data are processed and applicable law requires additional notice or consent, Caden Holt will take the required steps.


42. Contact

For questions about this Privacy Notice or the processing of personal data:

Caden Holt
Professional/trading name of APOSKITIS FILIPPOS

Privacy: [email protected]
General support: [email protected]


43. Legal framework

This Privacy Notice is intended to describe processing carried out in accordance with applicable data-protection law, including, where applicable:

  • Regulation (EU) 2016/679 (General Data Protection Regulation);

  • Greek Law 4624/2019;

  • Greek Law 3471/2006 concerning privacy in electronic communications;

  • other applicable Greek and European legislation.

Nothing in this Privacy Notice limits any mandatory right or protection granted to an individual under applicable law.


44. Version history

Version 1.0
Effective: 25 September 2026