Legal
Privacy Notice · Nightshift Scan
Last updated: 9 October 2026
Who we are
Nightshift Scan (nightshiftscan.com) is operated by Christos Alexandropoulos, an individual based in Greece, who is the data controller for the personal data described here.
Contact: [email protected]
What this notice covers
This notice covers only the data you send us by email, and basic technical data (such as your IP address) that our hosting provider processes when you visit the site. Our website uses no cookies, analytics or trackers.
What we collect
Whatever you include in your email, typically:
- Your app's URL
- Your business email address
- Your name, if you choose to give it
- Your confirmation that you own the app or are authorized by its owner to request a test
- Anything else you write to us
Please don't send passwords, access keys or customer data.
Why we use it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Replying to your enquiry and arranging a free scan you asked for | Art. 6(1)(b): steps taken at your request before entering into an agreement |
| Keeping a record of your ownership/authorization confirmation, so we can show that every test was authorized | Art. 6(1)(f): our legitimate interest in proving that we act lawfully and in defending legal claims |
We don't use your data for newsletters or marketing, and we never sell or rent it.
Who receives it
We use two service providers, who process data only on our instructions:
- Zoho Corporation (email hosting, EU data center). This is where emails are stored.
- Cloudflare, Inc. (website hosting and delivery). Cloudflare may process technical connection data, such as IP addresses, in the United States. These transfers rely on Cloudflare's certification under the EU–US Data Privacy Framework (Art. 45 GDPR adequacy decision).
We don't share your data with anyone else, unless the law requires us to.
How long we keep it
- Enquiries that don't lead to a scan: up to 12 months after our last exchange, then deleted.
- Authorization confirmations and related scan correspondence: 5 years after the scan, the limitation period for claims under Greek law (Art. 937 of the Greek Civil Code). They are then deleted.
- If you become a paying client, we keep accounting records for as long as Greek tax law requires.
Your rights
You can ask us to:
- access your data and get a copy;
- correct inaccurate data;
- delete your data;
- restrict how we use it;
- send your data to you or another provider in a portable format (portability);
- stop processing based on legitimate interest (object).
Email [email protected]. We'll reply within one month. Some rights have legal limits. For example, we may need to keep authorization records while a claim could still arise.
You can also complain to the Hellenic Data Protection Authority (ΑΠΔΠΧ), Kifisias 1-3, 115 23 Athens, www.dpa.gr.
Do you have to give us this data?
No. But without your app's URL, a contact email and your authorization confirmation, we can't arrange a scan.
We don't make automated decisions about you.