Last updated: 11 September 2026
Hellenic Talent operates an online platform that connects clients with freelance professionals. In the course of providing its services, Hellenic Talent collects, processes, and stores personal data relating to both clients, professionals who submit applications through the Hellenic Talent website or contact information, and freelancers which are part of the Hellenic Talent Network (together, "Users"). This Data Retention Policy ("Policy") sets out the principles, obligations, and procedures that govern how long Hellenic Talent retains personal data and the steps taken to securely delete or anonymise data once the applicable retention period has expired.
The purpose of this Policy is to:
This Policy should be read alongside the Hellenic Talent Privacy Policy, Cookie Policy, and any applicable data processing agreements.
This Policy applies to:
This Policy does not apply to anonymised data that cannot reasonably be re-linked to any identifiable individual, nor to aggregated statistical data that does not constitute personal data within the meaning of the GDPR.
For the purposes of this Policy, the following terms have the meanings set out below:
Personal Data: Any information relating to an identified or identifiable natural person ("Data Subject") as defined in Article 4(1) GDPR. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or one or more factors specific to that person.
Data Subject: The identified or identifiable natural person to whom personal data relates. In the context of this Policy, Data Subjects include clients, freelancers, platform visitors, and any other individuals whose personal data is processed by Hellenic Talent.
Processing: Any operation or set of operations performed on personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction, as defined in Article 4(2) GDPR.
Retention Period: The defined period of time during which Hellenic Talent is permitted or required to retain personal data, as set out in the Retention Schedule in Section 5 of this Policy, after which the data must be deleted or anonymised.
Anonymisation: The irreversible process of altering personal data in such a manner that the Data Subject can no longer be identified, directly or indirectly, by any means reasonably likely to be used, including by the use of additional information. Data that has been effectively anonymised in accordance with this Policy is no longer considered personal data for the purposes of the GDPR.
Pseudonymisation: The processing of personal data in such a manner that the personal data can no longer be attributed to a specific Data Subject without the use of additional information, provided that such additional information is kept separately and is subject to technical and organisational measures ensuring that the personal data is not attributed to an identified or identifiable natural person, as defined in Article 4(5) GDPR. Pseudonymised data remains personal data.
Data Controller: The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. Hellenic Talent acts as Data Controller in respect of the personal data of its Users.
Data Processor: A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Data Controller.
Legal Hold: An instruction issued by Hellenic Talent's legal or compliance advisors requiring that personal data which would otherwise be subject to deletion or anonymisation be preserved because it is, or is reasonably anticipated to be, relevant to actual or threatened litigation, regulatory investigation, or other legal proceedings.
Secure Deletion: The permanent and irrecoverable removal of personal data from all systems and storage media using methods that prevent reconstruction of the data, as further described in Section 6 of this Policy.
In accordance with Article 5(1)(e) GDPR, personal data must be kept in a form which permits identification of Data Subjects for no longer than is necessary for the purposes for which the personal data is processed. Where personal data is retained for archiving purposes in the public interest, for scientific or historical research, or for statistical purposes, it must be subject to appropriate technical and organisational safeguards.
Hellenic Talent will not retain personal data beyond the applicable retention period specified in the Retention Schedule in Section 5, except where:
In accordance with Article 5(1)(c) GDPR, personal data must be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed. Hellenic Talent will:
Personal data collected for a specific purpose must not be retained and used for incompatible purposes. Where Hellenic Talent intends to use personal data for a purpose other than that for which it was originally collected, a fresh legal basis assessment must be completed in accordance with Article 6 GDPR and, where applicable, Article 9 GDPR.
In accordance with Article 5(1)(f) GDPR, personal data must be processed in a manner that ensures appropriate security, including protection against unauthorised or unlawful processing and against accidental loss, destruction, or damage, using appropriate technical or organisational measures. These obligations continue throughout the entire retention period and up to and including the point of secure deletion or anonymisation.
In accordance with Article 5(2) GDPR, Hellenic Talent, as Data Controller, is responsible for and must be able to demonstrate compliance with the retention principles set out in this Section. Records of retention decisions, retention reviews, and deletion or anonymisation activities will be maintained in accordance with the schedule in Section 5.
The following table sets out the retention periods applicable to the principal categories of personal data processed by Hellenic Talent. Where a retention period is expressed as "duration of account + [period]", the retention period commences on the date of account closure, deletion, or deactivation. Where a retention period is expressed in years from a specified event, it commences on the date of that event.
| Data Category | Description | Retention Period | Legal Basis / Justification | Action on Expiry |
|---|---|---|---|---|
| Applicant Data | Name, email address, Skills, portfolio items, work history, certifications, professional biography, profile photographs, interview recordings, interview notes | Duration of application and interviews + 1 year after rejection of applicant | GDPR Art. 6(1)(b) (contract performance) and Art. 6(1)(a) (consent). | Secure deletion; anonymised aggregate statistics may be retained. |
| Enquiries Data | Name, email address | 1 year from the Enquiry submission | GDPR Art. 6(1)(b) (contract performance) and Art. 6(1)(a) (consent). | Secure deletion; anonymised aggregate statistics may be retained. |
| Public Source Data / Outreach / References | Name, email address, Skills, portfolio items, work history, professional role and availability status, certifications, professional biography, profile photographs | 5 years from compiling the data / from receipt of the reference | GDPR Art. 6(1)(f) (legitimate interest). | Secure deletion; anonymised aggregate statistics may be retained. |
| Account / Registration Data | Name, email address, password (hashed), date of registration, account status, identity verification documents, phone number, date/place of birth, address, bank details and tax identification information. | Duration of account + 5 years after account closure | GDPR Art. 6(1)(b) (contract performance); Greek Civil Code general statute of limitations (5 years — Art. 250 GCC as applicable to contractual claims). | Secure deletion; anonymised aggregate statistics may be retained. |
| Professional Profile Data (Freelancers) | Skills, portfolio items, work history, certifications, ratings, reviews, professional biography, profile photographs. | Duration of account + 1 year after account closure | GDPR Art. 6(1)(b) (contract performance); legitimate interest in dispute resolution (GDPR Art. 6(1)(f)). | Secure deletion of identifiable content; anonymised review data may be retained for platform quality metrics. |
| Financial / Payment & Transaction Data | Invoice records, payment amounts, bank transfer references, commission and fee records, transaction IDs, fee records, payout history, bank account details (account holder, IBAN, BIC/SWIFT). | 10 years from date of transaction | Greek Law 4308/2014 (Greek Accounting Standards — mandatory retention of accounting and financial records); GDPR Art. 6(1)(c) (legal obligation). | Secure archival then deletion. |
| Tax-Related Records | VAT invoices, tax identification numbers, withholding tax certificates, income declarations submitted to or generated for tax authorities. | 10 years from the end of the relevant tax year | Greek Tax Code as in force from time to time (Law 5104/2024, Κώδικας Φορολογικής Διαδικασίας); GDPR Art. 6(1)(c) (legal obligation). | Secure archival then deletion following expiry of tax authority audit window. |
| User Communications | Messages exchanged between clients and freelancers, video call recordings, support tickets, dispute correspondence. | Duration of account + 2 years after account closure | GDPR Art. 6(1)(b) (contract performance); legitimate interest in dispute evidence (GDPR Art. 6(1)(f)). | Secure deletion; attachments deleted separately following same schedule. |
| Platform Usage / Log Data | Access logs, IP addresses, browser/device information, security logs, error logs, API call records. | Duration of account or 12 months from date of collection whichever is later | Legitimate interest in platform security, fraud prevention, audit and performance monitoring (GDPR Art. 6(1)(f)). | Automated deletion; anonymised aggregate usage statistics may be retained indefinitely. |
| Cookie / Analytics Data | Strictly Necessary/ Functional cookies, session identifiers. | Per Cookie Policy | Greek Law 3471/2006 implementing ePrivacy Directive. | Automated expiry and deletion. |
| Legal / Compliance Records | Records of data subject requests (access, erasure, portability), DPA correspondence, data breach notifications, DPIAs, legal advice received. | 10 years; or duration of legal proceedings + 5 years, whichever is longer | GDPR Art. 6(1)(c) (legal obligation — accountability principle, Art. 5(2) GDPR); Greek Law 4624/2019. | Secure archival then deletion; records subject to active proceedings retained until final resolution + 5 years. |
| Marketing Consent Records | Records of consent to receive marketing communications, opt-in timestamps, consent withdrawal records, communication preference history. | Duration of consent + 3 years after withdrawal or lapse of consent | GDPR Art. 7(1) (demonstrating consent); legitimate interest in defending against regulatory complaints (GDPR Art. 6(1)(f)). | Secure deletion; aggregate opt-in/opt-out statistics anonymised and retained. |
| Contractual Records | Signed service agreements, freelancer engagement contracts, client platform agreements, terms of service acceptance records, amendments, client briefs, freelancer and client proposals, freelancer shortlists, client, freelancer and HT notes. | 20 years from date of execution or last amendment | Greek Civil Code Art. 249 (general 20-year limitation period for contractual claims); GDPR Art. 6(1)(c) and 6(1)(b). | Secure archival then deletion; electronic originals retained in access-controlled document management system. |
Applicant Data
Description: Name, email address, Skills, portfolio items, work history, certifications, professional biography, profile photographs, interview recordings, interview notes
Retention Period: Duration of application and interviews + 1 year after rejection of applicant
Legal Basis / Justification: GDPR Art. 6(1)(b) (contract performance) and Art. 6(1)(a) (consent).
Action on Expiry: Secure deletion; anonymised aggregate statistics may be retained.
Enquiries Data
Description: Name, email address
Retention Period: 1 year from the Enquiry submission
Legal Basis / Justification: GDPR Art. 6(1)(b) (contract performance) and Art. 6(1)(a) (consent).
Action on Expiry: Secure deletion; anonymised aggregate statistics may be retained.
Public Source Data / Outreach / References
Description: Name, email address, Skills, portfolio items, work history, professional role and availability status, certifications, professional biography, profile photographs
Retention Period: 5 years from compiling the data / from receipt of the reference
Legal Basis / Justification: GDPR Art. 6(1)(f) (legitimate interest).
Action on Expiry: Secure deletion; anonymised aggregate statistics may be retained.
Account / Registration Data
Description: Name, email address, password (hashed), date of registration, account status, identity verification documents, phone number, date/place of birth, address, bank details and tax identification information.
Retention Period: Duration of account + 5 years after account closure
Legal Basis / Justification: GDPR Art. 6(1)(b) (contract performance); Greek Civil Code general statute of limitations (5 years — Art. 250 GCC as applicable to contractual claims).
Action on Expiry: Secure deletion; anonymised aggregate statistics may be retained.
Professional Profile Data (Freelancers)
Description: Skills, portfolio items, work history, certifications, ratings, reviews, professional biography, profile photographs.
Retention Period: Duration of account + 1 year after account closure
Legal Basis / Justification: GDPR Art. 6(1)(b) (contract performance); legitimate interest in dispute resolution (GDPR Art. 6(1)(f)).
Action on Expiry: Secure deletion of identifiable content; anonymised review data may be retained for platform quality metrics.
Financial / Payment & Transaction Data
Description: Invoice records, payment amounts, bank transfer references, commission and fee records, transaction IDs, fee records, payout history, bank account details (account holder, IBAN, BIC/SWIFT).
Retention Period: 10 years from date of transaction
Legal Basis / Justification: Greek Law 4308/2014 (Greek Accounting Standards — mandatory retention of accounting and financial records); GDPR Art. 6(1)(c) (legal obligation).
Action on Expiry: Secure archival then deletion.
Tax-Related Records
Description: VAT invoices, tax identification numbers, withholding tax certificates, income declarations submitted to or generated for tax authorities.
Retention Period: 10 years from the end of the relevant tax year
Legal Basis / Justification: Greek Tax Code as in force from time to time (Law 5104/2024, Κώδικας Φορολογικής Διαδικασίας); GDPR Art. 6(1)(c) (legal obligation).
Action on Expiry: Secure archival then deletion following expiry of tax authority audit window.
User Communications
Description: Messages exchanged between clients and freelancers, video call recordings, support tickets, dispute correspondence.
Retention Period: Duration of account + 2 years after account closure
Legal Basis / Justification: GDPR Art. 6(1)(b) (contract performance); legitimate interest in dispute evidence (GDPR Art. 6(1)(f)).
Action on Expiry: Secure deletion; attachments deleted separately following same schedule.
Platform Usage / Log Data
Description: Access logs, IP addresses, browser/device information, security logs, error logs, API call records.
Retention Period: Duration of account or 12 months from date of collection whichever is later
Legal Basis / Justification: Legitimate interest in platform security, fraud prevention, audit and performance monitoring (GDPR Art. 6(1)(f)).
Action on Expiry: Automated deletion; anonymised aggregate usage statistics may be retained indefinitely.
Cookie / Analytics Data
Description: Strictly Necessary/ Functional cookies, session identifiers.
Retention Period: Per Cookie Policy
Legal Basis / Justification: Greek Law 3471/2006 implementing ePrivacy Directive.
Action on Expiry: Automated expiry and deletion.
Legal / Compliance Records
Description: Records of data subject requests (access, erasure, portability), DPA correspondence, data breach notifications, DPIAs, legal advice received.
Retention Period: 10 years; or duration of legal proceedings + 5 years, whichever is longer
Legal Basis / Justification: GDPR Art. 6(1)(c) (legal obligation — accountability principle, Art. 5(2) GDPR); Greek Law 4624/2019.
Action on Expiry: Secure archival then deletion; records subject to active proceedings retained until final resolution + 5 years.
Marketing Consent Records
Description: Records of consent to receive marketing communications, opt-in timestamps, consent withdrawal records, communication preference history.
Retention Period: Duration of consent + 3 years after withdrawal or lapse of consent
Legal Basis / Justification: GDPR Art. 7(1) (demonstrating consent); legitimate interest in defending against regulatory complaints (GDPR Art. 6(1)(f)).
Action on Expiry: Secure deletion; aggregate opt-in/opt-out statistics anonymised and retained.
Contractual Records
Description: Signed service agreements, freelancer engagement contracts, client platform agreements, terms of service acceptance records, amendments, client briefs, freelancer and client proposals, freelancer shortlists, client, freelancer and HT notes.
Retention Period: 20 years from date of execution or last amendment
Legal Basis / Justification: Greek Civil Code Art. 249 (general 20-year limitation period for contractual claims); GDPR Art. 6(1)(c) and 6(1)(b).
Action on Expiry: Secure archival then deletion; electronic originals retained in access-controlled document management system.
The above schedule is subject to review regularly and will be updated to reflect changes in applicable law, regulatory guidance, or operational requirements. Where a specific statutory provision is cited, the retention period tracks any amendment to that provision.
Hellenic Talent's IT and data management systems will, where technically feasible, be configured to flag personal data automatically when it approaches or reaches the end of the applicable retention period. Where automated flagging is not available, manual review processes will be conducted on a regular basis.
The following methods will be used to effect secure deletion of personal data, selected according to the storage medium and sensitivity of the data concerned:
Where the complete deletion of personal data is not practicable due to technical constraints (for example, the presence of data within deeply embedded logs or aggregated datasets), Hellenic Talent may instead apply anonymisation techniques, provided that:
Anonymisation techniques that may be employed include, but are not limited to: data aggregation, noise addition, data generalisation, data suppression, and tokenisation with secure key destruction.
Following the completion of any deletion or anonymisation exercise, the responsible team member will:
Where Hellenic Talent's legal or compliance function becomes aware of actual or reasonably anticipated litigation, regulatory investigation, or other legal proceedings in which personal data may be relevant, a Legal Hold notice will be issued to the relevant data custodians. Data subject to a Legal Hold must not be deleted or anonymised until the Legal Hold is formally lifted in writing by the issuing function, regardless of whether the standard retention period has expired.
Legal Hold notices will be issued in writing, will identify the categories of data to be preserved, the systems in which that data is held, and the reason for the hold. A register of active Legal Holds will be maintained by the Legal / Compliance team.
Where Hellenic Talent receives a request, notice, or indication from a supervisory authority (including the Hellenic Data Protection Authority ("HDPA") or any other competent authority) that it is or may be subject to regulatory investigation, any personal data that is or may be relevant to that investigation must be preserved until the investigation is concluded and any applicable appeal period has elapsed, or until the supervisory authority confirms in writing that the data need no longer be retained.
Where a User or third party has notified Hellenic Talent of an unresolved dispute, claim, or complaint (whether formal or informal) involving personal data, the relevant data may be retained beyond the standard retention period until the dispute is resolved and any applicable statutory limitation period has expired.
Where a Data Subject has submitted a request under the GDPR (including a request for erasure under Article 17 GDPR), Hellenic Talent must consider whether any exception to the right of erasure applies, including obligations under Article 17(3) GDPR, before deleting data. Records of data subject requests and the responses thereto will be retained in accordance with the Legal / Compliance Records schedule in Section 5.
HT shall undertake actions to:
HT shall undertake actions to:
All employees, contractors, and third parties with access to personal data are responsible for:
This Policy will be reviewed as required from time to time. Any amendments to this Policy will be advised by the legal consultants of Hellenic Talent and approved by senior management, before coming into force. The version history and effective date of each revision will be recorded. Users will be notified of material changes to this Policy in accordance with Hellenic Talent's privacy notice obligations under Article 13 and Article 14 GDPR.
This Policy is governed by, and should be interpreted in accordance with, Greek Law and the relevant applicable laws of the European Union.