Privacy Policy
This Privacy Policy explains how DJPI (“DJPI”, “we”, “us”) collects, uses and protects your personal data when you visit djpi.app, buy a DJPI license or Complete Kit, and use the DJPI software and dashboard.
Last updated: 19 June 2026
1. Who we are (Data Controller)
DJPIis the data controller responsible for your personal data. We are based in Greece and process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and Greek Law 4624/2019. You can reach us about any privacy matter at [email protected].
2. The data we collect
We only collect the data we need to sell and support DJPI:
- Account data: your name, email address and a securely hashed password (or a passwordless magic-link token if you sign in via email).
- License & device data:your DJPI license key, plan (Software or Complete Kit), and—when you activate a license—the Raspberry Pi’s hardware serial number and machine identifier. This lets us bind one license to one device and let you move it.
- Payment data: purchases are processed by Stripe. We receive a payment reference, the amount, currency, plan and status; we never see or store your full card number.
- Shipping data (Complete Kit only): the postal address you provide at checkout, used solely to ship your hardware.
- Communications: messages, feedback and support requests you send us, plus email delivery metadata such as whether an email was opened or a link was clicked.
- Usage & technical data: IP address, browser and device information, approximate location and pages viewed, collected via cookies and analytics (see our Cookie Policy).
3. How and why we use your data (legal bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Create your account, issue and validate your license | Performance of a contract |
| Process payments and ship the Complete Kit | Performance of a contract |
| Send transactional emails (license, verification, password reset) | Performance of a contract |
| Provide support and respond to your messages | Legitimate interest / contract |
| Analytics, fraud prevention and improving the product | Consent (analytics cookies) / legitimate interest |
| Marketing or win-back emails | Consent (you can opt out anytime) |
| Meeting legal, accounting and tax obligations | Legal obligation |
4. Service providers (processors)
We share data only with providers who help us run DJPI, under data processing agreements:
- Stripe — payment processing and fraud prevention.
- Brevo (Sendinblue) — transactional and marketing email delivery.
- Google Analytics — website usage analytics (only with your consent).
- MapTiler — map tiles for our visitor map widget.
- Sentry — error monitoring to keep the service stable.
- Google reCAPTCHA — bot and abuse protection on forms.
- Our hosting provider — secure servers and database hosting.
Where a provider processes data outside the European Economic Area, that transfer is protected by an adequacy decision or the EU Standard Contractual Clauses.
5. How long we keep your data
- Account & license data: for as long as your account exists, and afterwards only as needed to support a transferred or reissued license.
- Payment & invoicing records: for the period required by Greek tax and accounting law (generally up to 10 years).
- Analytics data: for a limited period in line with our analytics settings, then aggregated or deleted.
6. Your rights under the GDPR
You have the right to:
- access the personal data we hold about you;
- rectify inaccurate or incomplete data;
- erase your data (“right to be forgotten”);
- restrict or object to certain processing;
- data portability;
- withdraw consent at any time, without affecting prior processing.
To exercise any of these rights, email [email protected]. We will respond within one month.
7. Complaints
If you believe we have mishandled your data, you may lodge a complaint with the Hellenic Data Protection Authority (HDPA / Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), www.dpa.gr, or with the supervisory authority in your EU country of residence.
8. Security
We use encryption in transit, hashed passwords and access controls to protect your data. No system is perfectly secure, but we take reasonable technical and organisational measures appropriate to the risk.
9. Children
DJPI is not directed at children under 16. We do not knowingly collect their personal data.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected by the “Last updated” date above.
11. Contact
Questions about this policy or your data? Email [email protected].