Legal

Legal & Privacy

Legal information, privacy, cookies and terms governing the use of NorthBlue Consulting's website.

Last updated: 27 August 2026

01 — Legal & Privacy

Privacy Policy

Introduction

NorthBlue Consulting ("NorthBlue", "we", "us", "our") respects your privacy and is committed to protecting your personal data.

This Privacy Policy explains how NorthBlue Consulting may collect, use, store, disclose and otherwise process personal data when you:

  • visit or use the NorthBlue Consulting website;
  • contact us through the website, email, social media or another communication channel;
  • submit an enquiry or request information;
  • request or receive a proposal;
  • purchase or use our services;
  • become or consider becoming a client, partner, supplier, contractor or professional associate;
  • participate in a project involving NorthBlue Consulting;
  • subscribe to marketing or business communications where such functionality is available;
  • interact with one of our digital services or products where this Privacy Policy applies; or
  • otherwise interact with NorthBlue Consulting.

Personal data are processed in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — GDPR), applicable Greek data-protection legislation, including Law 4624/2019, and other applicable Greek and European Union legislation.

Data Controller

For the purposes of the GDPR and applicable Greek data-protection legislation, the Data Controller is:

Angeliki Vasileiadou, trading as NorthBlue Consulting

Legal Form
Sole Proprietorship (Ατομική Επιχείρηση)
Registered Office
Amisiana, Kavala, Greece
Tax Identification Number (ΑΦΜ)
171196705
Competent Tax Authority (Δ.Ο.Υ.)
Kavala

Questions concerning this Privacy Policy or the processing of personal data may be submitted to the above email address.

Definitions

"Personal Data" means any information relating to an identified or identifiable natural person.

"Data Subject" means the natural person to whom Personal Data relate.

"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organisation, storage, alteration, retrieval, consultation, use, disclosure, transmission, restriction, deletion or destruction.

"Controller" means the natural or legal person that determines the purposes and means of processing Personal Data.

"Processor" means a natural or legal person that processes Personal Data on behalf of a Controller.

"Consent" means a freely given, specific, informed and unambiguous indication of a Data Subject's wishes by which they signify agreement to the processing of their Personal Data.

"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Personal Data.

"Third Party" means a natural or legal person, public authority, agency or body other than the Data Subject, Controller, Processor or persons authorised to process Personal Data under the authority of the Controller or Processor.

Personal Data We May Collect

Depending on how a person interacts with NorthBlue Consulting, we may process:

Contact Information

  • name and surname;
  • email address;
  • telephone number;
  • business or organisation name;
  • professional title or position;
  • country or location where relevant;
  • information voluntarily provided when contacting us.

Professional and Business Information

  • employer or organisation;
  • professional role;
  • business information;
  • professional correspondence;
  • project participation;
  • information regarding an organisation's requirements;
  • information relating to a potential or existing consulting engagement;
  • other information necessary for the provision of professional services.

Contractual and Financial Information

  • billing details;
  • invoicing information;
  • Tax Identification/VAT information;
  • bank or payment information where required;
  • transaction information;
  • contractual information;
  • payment status;
  • information necessary to fulfil contractual, accounting, taxation or other legal obligations.

Communications

We may retain communications exchanged with users, including enquiries, emails, project communications, meeting-related information and other professional correspondence where reasonably necessary.

Special Categories

NorthBlue Consulting does not intentionally request or collect special categories of Personal Data through its general website.

Where such information becomes necessary in connection with a particular project or service, it will only be processed where an appropriate legal basis and any additional requirements under applicable law are satisfied.

Website and Technical Data

The NorthBlue Consulting website is developed and operated using Lovable and associated technical infrastructure.

When a user accesses the website, certain technical information may be processed automatically by the technologies and service providers necessary to provide, maintain and secure the website.

Depending on the website configuration, this may include:

  • IP address;
  • browser type and version;
  • device type;
  • operating system;
  • date and time of access;
  • pages or resources requested;
  • referring website or source;
  • technical logs;
  • security events;
  • error and diagnostic information;
  • information necessary for the proper operation and security of the website.

Technical information may be processed for website delivery, cybersecurity, troubleshooting, performance monitoring, fraud or abuse prevention and technical maintenance.

NorthBlue Consulting uses reputable technology providers and seeks to apply appropriate technical and organisational safeguards.

No website, cloud platform or internet-based service can guarantee absolute security.

How We Collect Personal Data

Personal Data may be obtained:

  • directly from the individual;
  • through website forms;
  • through email;
  • through telephone or online communications;
  • through meetings and consultations;
  • through contractual relationships;
  • through professional collaborations;
  • from clients where necessary to provide agreed services;
  • from project partners;
  • from suppliers and professional contractors;
  • from publicly available professional or business sources where legally permitted;
  • automatically through the technical infrastructure supporting the website.

Where another person or organisation provides Personal Data relating to a third party, that person or organisation is responsible for ensuring that it is legally entitled to provide those data to NorthBlue Consulting.

Purposes of Processing

Personal Data may be processed for:

Communication and Enquiries

  • responding to enquiries;
  • providing requested information;
  • arranging meetings;
  • conducting consultations;
  • communicating regarding potential engagements;
  • maintaining professional communications.

Provision of Services

  • Management Consulting;
  • Digital Transformation;
  • Artificial Intelligence and AI solutions;
  • Project Management;
  • European Projects & Innovation;
  • Business Growth and organisational services;
  • related consulting and technology services.

Project Management and Delivery

  • coordinating projects;
  • communicating with stakeholders;
  • managing deliverables;
  • managing project documentation;
  • supporting reporting;
  • monitoring project activities;
  • coordinating contractors and partners;
  • fulfilling agreed project obligations.

Contractual and Financial Administration

  • preparing and administering agreements;
  • issuing invoices;
  • processing or recording payments;
  • maintaining accounting records;
  • managing suppliers and contractors;
  • fulfilling contractual obligations.

Legal and Regulatory Compliance

  • taxation requirements;
  • accounting obligations;
  • regulatory requirements;
  • legal obligations;
  • legally valid requests from competent authorities.

Business Administration

  • client relationships;
  • suppliers;
  • contractors;
  • professional partners;
  • internal operations and records.

Website Operation and Security

  • operating and maintaining the website;
  • maintaining functionality;
  • protecting the website and users;
  • identifying technical problems;
  • preventing misuse or malicious activity;
  • improving performance and reliability.

Marketing and Business Communications

Where permitted by applicable law, NorthBlue Consulting may communicate information concerning services, projects, digital products, business developments, relevant insights and other NorthBlue activities.

Where consent is legally required, communications will only be sent after appropriate consent has been obtained.

Users may withdraw consent or object to direct marketing at any time.

Legal Bases for Processing

Depending on the processing activity, NorthBlue Consulting may rely on:

"Consent" means where clear consent has been provided for a specific purpose.

"Contractual Necessity" means where processing is necessary to perform an agreement or take requested steps before entering into an agreement.

"Legal Obligation" means where processing is necessary to comply with applicable legal obligations.

"Legitimate Interests" means where processing is necessary for legitimate business interests, provided those interests are not overridden by the individual's rights and freedoms.

Where processing relies on consent, consent may be withdrawn at any time. Withdrawal does not affect processing lawfully carried out before withdrawal.

Sharing Personal Data

NorthBlue Consulting does not sell or rent Personal Data.

Personal Data may, where reasonably necessary, be shared with selected third parties including:

  • website development and hosting infrastructure providers;
  • Lovable and associated infrastructure providers;
  • cloud and data-storage providers;
  • email and communication providers;
  • business software providers;
  • accountants and tax advisers;
  • legal advisers;
  • IT and cybersecurity providers;
  • payment providers;
  • contractors and consultants;
  • project partners;
  • European project consortium members where relevant;
  • clients where necessary for project delivery;
  • competent governmental, judicial, regulatory or public authorities where disclosure is legally required.

Disclosure should be limited to information reasonably necessary for the relevant purpose.

Where third parties process Personal Data on behalf of NorthBlue Consulting, appropriate contractual and data-protection arrangements should be used where required by applicable legislation.

International Data Transfers

Some cloud, technology, software or infrastructure providers may process information outside Greece or the European Economic Area.

Where Personal Data are transferred outside the EEA and safeguards are required, NorthBlue Consulting seeks to ensure an appropriate transfer mechanism is available.

These may include:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses approved by the European Commission;
  • another legally recognised transfer mechanism.

Artificial Intelligence and Digital Tools

Artificial Intelligence, automation and Digital Transformation form part of NorthBlue Consulting's professional activities.

NorthBlue Consulting may use AI and automation technologies as part of:

  • internal business operations;
  • research and analysis;
  • productivity workflows;
  • development of digital solutions;
  • consulting engagements;
  • business automation;
  • development and operation of digital products;
  • service delivery where appropriate.

Our approach is based on:

  • data minimisation;
  • confidentiality;
  • security;
  • appropriate human oversight;
  • purpose limitation;
  • responsible AI use;
  • compliance with applicable data-protection requirements.

Personal or confidential client information will not intentionally be submitted to AI systems in a manner inconsistent with applicable legal requirements, contractual obligations or agreed client instructions.

Where a project requires Personal Data to be processed through an AI or automated system, additional technical, contractual and organisational measures may be implemented depending on the nature of the processing.

Digital Products and Micro-SaaS

NorthBlue Consulting develops proprietary digital products and Micro-SaaS solutions.

Individual digital products may therefore have separate:

  • Privacy Policies;
  • Terms of Service;
  • Cookie Policies;
  • subscription terms;
  • licensing conditions;
  • acceptable-use policies;
  • Data Processing Agreements where appropriate.

Product-specific legal terms apply where provided.

Data Retention

NorthBlue Consulting retains Personal Data only for as long as reasonably necessary for the purpose for which they were collected.

Retention periods may depend on:

  • the nature of the information;
  • the purpose for which it was collected;
  • duration of a client or contractual relationship;
  • accounting and taxation requirements;
  • legal obligations;
  • limitation periods;
  • contractual obligations;
  • establishment, exercise or defence of legal claims.

Personal Data will be deleted, anonymised or otherwise appropriately handled when no longer required, subject to applicable legal retention requirements.

Data Security

NorthBlue Consulting takes reasonable technical and organisational measures designed to protect Personal Data against:

  • unauthorised access;
  • accidental loss;
  • unlawful processing;
  • alteration;
  • unauthorised disclosure;
  • misuse;
  • destruction.

The NorthBlue Consulting website is developed and operated using Lovable and associated technical infrastructure.

Depending on the systems concerned, measures may include:

  • access controls;
  • secure authentication;
  • multi-factor authentication where available;
  • secure cloud infrastructure;
  • password-management practices;
  • controlled access to client information;
  • data minimisation;
  • appropriate backups;
  • software and infrastructure security measures;
  • review of access and technology providers where appropriate.

No method of internet transmission, website or electronic storage system can be guaranteed to be completely secure.

Personal Data Breaches

Where NorthBlue Consulting becomes aware of a Personal Data Breach, the incident will be assessed and handled in accordance with applicable data-protection legislation.

Where legally required, NorthBlue Consulting will notify the competent supervisory authority and/or affected Data Subjects within the applicable legal timeframes.

Data Protection Rights

Subject to applicable legislation, individuals may have the right to:

  • access Personal Data;
  • request rectification;
  • request erasure;
  • request restriction of processing;
  • request data portability where applicable;
  • object to certain processing;
  • object to direct marketing at any time;
  • withdraw consent where processing is based on consent;
  • exercise applicable rights relating to automated decision-making.

To exercise these rights, contact: northbluewebadm@outlook.com

NorthBlue Consulting may request reasonable information necessary to verify the identity of the person making the request.

Requests will be handled within the timeframes required by applicable data-protection legislation.

Right to Lodge a Complaint

Individuals have the right to lodge a complaint with:

Hellenic Data Protection Authority
Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα (ΑΠΔΠΧ)
Greece

Children's Privacy

The NorthBlue Consulting corporate website and professional consulting services are not directed toward children.

NorthBlue Consulting does not knowingly use its general website to collect Personal Data from children for marketing purposes.

02 — Legal & Privacy

Cookie Policy

Cookies are small pieces of information stored on or accessed through a user's device when visiting a website.

Cookies and similar technologies may be used to provide website functionality, maintain security, remember preferences, understand website performance or provide other digital functionality.

Strictly Necessary Cookies

Strictly necessary cookies or similar technologies may be used where required to:

  • provide essential website functionality;
  • maintain website security;
  • manage sessions;
  • prevent misuse;
  • provide functionality specifically requested by the visitor.

Where permitted by applicable law, strictly necessary cookies may operate without prior consent.

Preference Cookies

Preference technologies may be used to remember visitor choices such as language or website preferences.

Where consent is legally required, these technologies should only operate after the required consent has been provided.

Analytics Cookies

If analytics technologies are implemented, they may be used to understand how visitors interact with the website and improve its functionality, performance and content.

Where prior consent is required under applicable law, analytics cookies or similar technologies must not be activated until the visitor provides consent.

Third-Party Technologies

Certain website functionality may depend on third-party technology or infrastructure providers.

Where these technologies involve non-essential cookies or similar tracking technologies requiring consent, they should only operate after the visitor has made the relevant choice.

Technologies Currently Used on This Website

At present, this website does not use analytics cookies, advertising trackers or other non-essential tracking technologies.

It relies only on strictly necessary technologies and local browser storage used to keep your session secure and to remember the language you selected. Because no consent-requiring technology is currently in use, no cookie consent banner is displayed. If non-essential technologies are introduced in the future, a consent mechanism with equally clear Accept, Reject and Manage Preferences options will be implemented, optional categories will not be preselected, and such technologies will remain inactive until consent is given.

03 — Legal & Privacy

Terms of Use

Website Use

By accessing and using the NorthBlue Consulting website, visitors agree to use it lawfully and not to:

  • violate applicable legislation;
  • interfere with website operation;
  • attempt unauthorised access to systems or information;
  • compromise website security;
  • introduce malicious software or code;
  • misuse website content or intellectual property.

No Automatic Professional Relationship

Accessing the website, submitting an enquiry, downloading publicly available material or communicating with NorthBlue Consulting does not by itself create a consultant-client relationship, contractual relationship, partnership, agency or other professional engagement.

A professional engagement exists only when expressly agreed between NorthBlue Consulting and the relevant client or organisation.

Professional Information Disclaimer

Information available through the website is primarily provided for general informational and business purposes.

Unless expressly provided as part of an agreed professional engagement, website content does not constitute legal, tax, accounting, investment or other regulated professional advice.

Business recommendations and consulting outcomes depend on the individual circumstances, objectives, resources, information and operating environment of each organisation.

NorthBlue Consulting does not guarantee specific financial, commercial, operational or other results solely as a result of accessing or relying upon general information published on this website.

Intellectual Property

Unless otherwise expressly stated, the NorthBlue Consulting name, branding, original website content, written materials, graphics, designs, methodologies, frameworks, digital assets and other original intellectual property are owned by or appropriately licensed to Angeliki Vasileiadou / NorthBlue Consulting.

Except where permitted by law, such material may not be:

  • copied;
  • reproduced;
  • republished;
  • distributed;
  • modified;
  • commercially exploited;
  • sold;
  • presented as the work of another person or organisation;
  • used to create substantially derivative commercial materials

without appropriate authorisation.

Separate contractual provisions may govern ownership and licensing of intellectual property created as part of client engagements.

Digital Products — Intellectual Property

NorthBlue Consulting may design, develop, own and commercially provide proprietary software, digital tools, platforms, AI-enabled solutions and Micro-SaaS products.

Unless otherwise stated in product-specific terms, purchasing, subscribing to or accessing a NorthBlue digital product does not transfer ownership of the underlying:

  • software;
  • source code;
  • design;
  • technology;
  • database structure;
  • workflows;
  • methodologies;
  • branding;
  • other intellectual property.

Access may instead be provided under a licence, subscription or other commercial arrangement.

Third-Party Links and Services

The website may contain links to external websites, platforms, social networks, maps, software or other services.

NorthBlue Consulting does not control external services and is not responsible for their content, availability, security, accuracy, terms or privacy practices.

Limitation of Liability

To the extent permitted by applicable law, NorthBlue Consulting shall not be liable for loss or damage arising solely from:

  • reliance on general informational website content;
  • temporary website unavailability;
  • technical interruptions outside reasonable control;
  • external websites;
  • third-party platforms or services;
  • unauthorised third-party activity that could not reasonably have been prevented.

Nothing in these Terms is intended to exclude or limit liability where such exclusion or limitation is prohibited by applicable law.

Governing Law

These website Terms and this Legal page are governed by applicable Greek law and directly applicable European Union law.

Any dispute relating to the website or these Terms shall be subject to the jurisdiction of the competent Greek courts, subject to any mandatory jurisdiction or consumer-protection rules that may apply.

Changes to These Policies

NorthBlue Consulting may periodically amend its Legal information, Privacy Policy, Cookie Policy and Terms of Use to reflect changes to the website, services, Digital Products, technology providers, Personal Data processing, security practices or applicable legislation.

The current version will be published on this page together with its Last Updated date.

Contact

Questions about privacy or legal matters?

For privacy, data protection, cookies, website terms, intellectual property or other legal matters concerning NorthBlue Consulting, contact:

northbluewebadm@outlook.com

© 2026 NorthBlue Consulting. All rights reserved.