Pelekanos (“Pelekanos”, “we”, “us”) operates the Pelekanos mobile application, which connects volunteers with non-governmental organisations (“NGOs”) and their volunteering events. This policy explains what personal data we collect, why, how we protect it, and the rights you have under the EU General Data Protection Regulation (GDPR) and Greek data-protection law.
Questions or requests about your data: hello@pelekanos.org.
1. Data we collect
| Data | Why we collect it |
|---|---|
| Email address and name | To create and secure your account, sign you in, and contact you about the service. |
| Account identifier (user ID) | To link your activity (registrations, reviews, favourites) to your account. |
| Precise location (only with your permission) | To recommend volunteering events near you and show them on the map. You can use the app without granting location access. |
| Photos you upload (only with your permission) | So NGOs and volunteers can add and view event images. |
| Event registration details — and, for some events, sensitive information such as date of birth, identification number, allergies, or medical conditions | When you register for an event, the organising NGO receives the details needed to manage participation and safety. Sensitive details are only collected where an NGO requires them for a specific event, and are shared only with that NGO. |
| Push notification token and language | To deliver notifications (e.g. event reminders, updates) to your device in your language. You can disable notifications at any time. |
| Usage and analytics data (e.g. screens viewed, actions taken) | To understand how the app is used and improve it. |
| Diagnostics (crash and performance data) | To detect, diagnose and fix problems and keep the app stable. |
We do not use your data to track you across other companies’ apps or websites, and we do not sell your personal data.
2. Legal bases (GDPR Article 6 / 9)
- Performance of a contract — to provide the account and core features you ask for.
- Consent — for location access, photo access, push notifications, and any sensitive (special-category) data such as health/medical information for an event. You can withdraw consent at any time.
- Legitimate interests — to keep the service secure, prevent abuse, and improve the product through privacy-respecting analytics.
- Legal obligation — where we must retain or disclose data to comply with the law.
3. Who processes your data
We share data only with service providers (“processors”) who help us run Pelekanos, under data-processing agreements. They are configured to store data in the European Union where applicable:
- Supabase — authentication, database and file storage (EU region).
- Sentry — crash and performance diagnostics (EU region).
- PostHog — product analytics (EU region).
- Expo — delivery of push notifications.
- Apple and Google — only if you choose “Sign in with Apple” or “Sign in with Google”.
NGOs you register with act as independent controllers for the registration details they receive, and are responsible for their own handling of that data.
4. How long we keep it
We keep your account data for as long as your account is active. Diagnostics and analytics data are retained for a limited period and then deleted or aggregated. When you delete your account (see below), we delete or anonymise your personal data, except where we must keep it to meet a legal obligation.
5. Deleting your account
You can delete your account and associated personal data directly in the app: Profile → Delete account. This removes your profile and associated data from our systems.
6. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent at any time. To exercise these rights, contact hello@pelekanos.org. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr) or your local supervisory authority.
7. Children
Pelekanos is not directed to children under 15. If you believe a child has provided us personal data without appropriate consent, contact us and we will delete it.
8. Security
We use industry-standard measures — including encryption in transit and access controls — to protect your data. No method of transmission or storage is completely secure, but we work to protect your information and review our practices regularly.
9. Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, where appropriate, notify you in the app.