Who is responsible for your data
The controller of your personal data is Dr. Asterios Diafas, medical doctor, ophthalmologist. Email asterisdiafas@hotmail.com · Phone +30 694 240 6078. Contact these details with any question about this notice or to exercise your rights. As an individual practice, it has not appointed a Data Protection Officer.
What this notice covers
This notice covers this website and any message you send the practice through it. If you become a patient, your medical record is protected by medical confidentiality and Greek law on medical records, and you can ask the practice about it at any time.
The data we collect
The practice only receives the data you choose to send it:
- The contact form: your name, email address and phone number, your country, the reason for your enquiry and your message. If you are a clinician referring a patient, also your name and practice, and the patient’s details you include. Your message may contain information about your health — please include only what is needed to arrange an appointment.
- Email, phone and WhatsApp: whatever you share when you contact the practice directly, including your contact details.
- Technical data: like any website, this one receives your IP address and basic details of your browser and device when you visit. The hosting provider uses them to deliver the pages and to protect the site from attacks. The practice does not use them to identify you and runs no analytics.
Why the data is used, and on what legal basis
- Replying to your enquiry and arranging an appointment, at your request — Article 6(1)(b) GDPR.
- Health information in your message, on your explicit consent, given with the tick box on the form — Article 9(2)(a) GDPR. Once you are under the doctor’s care, it becomes part of your medical record and is processed to provide health care under medical confidentiality — Article 9(2)(h) GDPR and Article 22 of Greek Law 4624/2019.
- Referrals from clinicians, to provide care to the patient referred — Articles 6(1)(f) and 9(2)(h) GDPR. The referring clinician is responsible for having a lawful basis to share the patient’s details.
- Keeping the website secure and working — the practice’s legitimate interest, Article 6(1)(f) GDPR.
Your data is never sold or used for marketing, and no decision about you is made by automated means.
Who receives your data
Only the service providers the website needs in order to work, each using the data solely to provide its service:
- Cloudflare, Inc. (USA) hosts the website and processes the contact form when you send it.
- Resend, Inc. (USA) delivers the form to the practice by email.
- Microsoft, the practice’s email provider, stores the emails the practice sends and receives.
Beyond that, data is disclosed only where the law requires it, for example to a court or a competent public authority.
Transfers outside the European Union
Cloudflare, Resend and Microsoft are US companies. Transfers to them rely on the EU–US Data Privacy Framework, under which the European Commission has recognised that certified US companies protect personal data adequately, and on the Commission’s standard contractual clauses.
How long your data is kept
Enquiries that do not lead to an appointment are deleted within 12 months of the last exchange. If you become a patient, the information becomes part of your medical record, which Greek law requires doctors to keep for ten years after your last visit (Article 14 of Law 3418/2005, the Code of Medical Ethics). Technical data is kept by the hosting provider only for short periods, as needed for security.
Your rights
You can ask for access to your data, for it to be corrected or erased, to restrict or object to its use, and to receive it in a portable format. Where the practice relies on your consent, you can withdraw it at any time, without affecting anything done before. Some rights are limited by law: medical records, for example, cannot be erased before their legal retention period ends. To exercise a right, contact the practice using the details above; you will receive a reply within one month.
Complaints
If you believe your data has been handled unlawfully, you can complain to the Hellenic Data Protection Authority, 1–3 Kifisias Avenue, 115 23 Athens, www.dpa.gr, or to the supervisory authority where you live or work — in the United Kingdom, the Information Commissioner’s Office (ico.org.uk). The practice would welcome the chance to put things right first.
Cookies, storage & analytics
This site sets no cookies of its own and runs no analytics, advertising or tracking of any kind. One small value is kept in your own browser and never leaves your device: the language you chose. It is strictly necessary to give you the site you asked for, so it needs no consent under Article 4(5) of Greek Law 3471/2006, which implements the ePrivacy Directive. Fonts and images are served by this website itself, so viewing a page contacts neither Google nor any other third party.
Maps and other third-party content
The contact page links to Google Maps so you can get directions to each consulting location. The map itself is not embedded on this site — the link opens Google Maps in a new tab, and nothing is sent to Google until you click it, exactly like any other external link (see “Links to other websites” below).
Links to other websites
Links to WhatsApp, Instagram, hospital websites and scientific journals lead to services run by others, under their own privacy policies. Nothing is shared with them unless you follow a link.
Children
The contact form is not meant for children to use on their own. If an enquiry concerns someone under 15, a parent or guardian should send it.
Security
The site is served only over an encrypted connection (HTTPS). Messages sent through the form go straight to the practice by email and are not kept in any website database.
Changes to this notice
This notice is updated when the website or the law changes. The version published here is always the one in force.
Effective from 13 September 2026.
