Legal

Privacy Policy

Last updated: 1 July 2026

This Privacy Policy explains how Cookie Tech (legal entity PANCHENKOV LAHAV ΟΕ) processes personal data through the Road map roi platform (roadmap-roi.com). It is written to comply with the EU General Data Protection Regulation (Regulation 2016/679, "GDPR"), Greek Law 4624/2019, and the ePrivacy Directive as transposed into Greek law.

1. Data Controller

  • Trading name: Cookie Tech
  • Legal entity: PANCHENKOV LAHAV ΟΕ
  • Registered address: Kon/nou Paleologou 45, 3rd Floor, Apt. C1, 73131 Chania, Crete, Greece
  • Contact / data-protection requests: hello@gideonlahav.com

2. Scope

This policy applies to visitors of our website, users of the Road map roi application, and anyone who contacts us. By using the service you acknowledge the processing described here.

3. Data we collect

  • Account data: name, email, organization name, role, password hash.
  • Workspace content you enter: projects, features, sub-features, ROI inputs (NPV, RICE, ICE, MoSCoW, Kano, FVI scores), notes, comments, activity logs, shared scenarios, bug reports.
  • Billing metadata: Stripe customer ID, subscription status, plan and invoice history. We never store card numbers, CVCs or raw payment data. All payments are handled by Stripe (PCI-DSS Level 1).
  • Product telemetry: anonymized events in analytics_events(route, session identifier, funnel step) used only to improve conversion and reliability.
  • AI memo inputs and outputs: prompts you submit to the AI memo feature and the generated response, retained in your workspace.
  • Technical data: IP address, browser type, timestamps in server logs for security and abuse-prevention.

4. Legal bases (GDPR Art. 6)

  • Contract: to provide the service you subscribed to.
  • Legitimate interest: security, fraud prevention, service improvement, and low-risk product analytics.
  • Consent: optional analytics/marketing cookies and any marketing email you opt in to; you may withdraw at any time.
  • Legal obligation: Greek tax and accounting law for invoices.

5. Your rights

Under GDPR and Law 4624/2019 you have the right to:

  • access, rectify, or erase your personal data,
  • restrict or object to processing,
  • data portability (machine-readable export),
  • withdraw consent at any time,
  • lodge a complaint with the Hellenic Data Protection Authority (HDPA, dpa.gr, Kifissias 1-3, 115 23 Athens, Greece).

You can exercise most of these rights directly from Settings. For anything else, email hello@gideonlahav.com and we will respond within 30 days.

6. Retention

  • Workspace data is retained for as long as your account is active.
  • On verified deletion request we erase workspace data within 30 days.
  • Invoices and billing records are retained for 10 years as required by Greek tax law (Κώδικας Φορολογικής Απεικόνισης Συναλλαγών).
  • Server logs and analytics events are retained for up to 12 months.

7. Sub-processors

The following providers process personal data on our behalf under GDPR-compliant Data Processing Agreements:

  • Supabase: Postgres database, authentication, storage, edge functions (EU region, Frankfurt).
  • Lovable / Cloudflare: web hosting, CDN, DDoS protection.
  • Stripe: subscription payments (PCI-DSS Level 1).
  • Resend: transactional email delivery via notify.roadmap-roi.com (name + email only).
  • Google Gemini via Lovable AI Gateway: inference for AI memos. Prompt content is processed to generate a response and is not used to train third-party models.

8. International transfers

We host primary infrastructure inside the European Economic Area. Where a sub-processor operates outside the EEA (e.g. Stripe, Resend), transfers rely on European Commission adequacy decisions or Standard Contractual Clauses (SCCs).

9. Security

  • TLS 1.2+ for all traffic; HTTP requests are redirected to HTTPS.
  • AES-256 encryption at rest for database and file storage.
  • PostgreSQL Row-Level Security enforces strict per-organization isolation.
  • Incoming webhooks (Stripe) are verified with HMAC signatures.
  • Secrets are stored in a server-side secret manager, never in client code.
  • Continuous automated security scanning of the codebase.

10. Children

Road map roi is not intended for users under 16, the age of digital consent under Greek law. We do not knowingly collect data from children.

11. Breach notification

In the event of a personal-data breach we will notify the HDPA and affected users within 72 hours as required by GDPR Article 33.

12. Cookies

See our Cookie Policy for the full list of cookies and similar technologies we use.

13. Changes to this policy

We will notify you by email or in-app at least 30 days before any material change. Continued use of the service after the effective date constitutes acceptance.

14. Contact

PANCHENKOV LAHAV ΟΕ, Kon/nou Paleologou 45, 3rd Floor, Apt. C1, 73131 Chania, Crete, Greece, hello@gideonlahav.com.

A Greek-language translation of this policy is available on request.

← Back to home