Personal Data Protection Policy

Last updated: June 2026

This is a courtesy English translation of the official Greek document. In the event of any discrepancy, the Greek version prevails.

This statement is made in accordance with Articles 13 and 14 of EU General Data Protection Regulation 679/2016 (the “Regulation”), to the visitors and users (all hereinafter “Users” or “User”) of the Website (desktop and mobile version) and of any mobile application related to the service (hereinafter: “Website and Applications”) belonging to ZB IKE, as Controller of personal data (the “Controller”), and is intended to describe the methods of managing the Website and the Applications with reference to the processing of personal data.

For ZB IKE, privacy and the protection of your personal data are very important, and for this reason we collect and manage your personal data with the utmost care and take specific measures to keep it safe. Data processing is based on the principles of fairness, lawfulness, transparency and protection of confidentiality.

As set out in the website’s “Terms & Conditions”, the services offered by the Controller are addressed to persons over 18 years of age. If the Controller becomes aware of the processing of data of persons under 18 without the valid consent of their parents or legal guardian, it reserves the right to unilaterally discontinue the use of the service offered, as well as the right to delete the data obtained.

We also ask you to read the Website’s “Terms & Conditions”, which contain detailed information on the terms relating to our services.

We are obliged to protect your personal data (fulfilment of a legal obligation) in order to protect the interests of our business and to comply with the applicable legislation (legitimate interest).

This statement may be subject to changes at any time without an obligation of prior notice to the User. In order for the User to always be informed, the Controller invites them to visit this page periodically. If any changes affect the data concerning the User, the Controller will inform the User before those changes take effect, publishing them with maximum transparency on its Website and Applications.

Definitions

The term “User” refers to all natural persons who access the Website and the Applications for any purpose, whether a simple visit, consultation, booking or purchase of services. Mere use of the Website and the Applications confers the status of “User”, and allows the User to access the search and appointment-booking service. “Partners” are the professionals (businesses) who offer appointments at their premises for the provision of their products and services on the Controller’s Website and Applications.

“Processing” of personal data means any kind of activity (processing operation) performed on, or concerning, personal data of natural persons. It includes the collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, research, use, disclosure by transmission, dissemination or any other form of making available, alignment or combination, restriction, erasure or destruction of personal data.

What personal data we collect

(a) Identification data: full name, father’s name, mother’s name, ID card number, tax identification number (ΑΦΜ), social security number (ΑΜΚΑ), Personal Number. This data is collected directly from the Customer and/or from publicly accessible sources and/or from publicly accessible social networks through the KYC (Know Your Customer) process, i.e. the digital submission of State documents.

(b) Contact data: postal and e-mail address, landline and mobile telephone. The data is collected directly from the Customer via login and the entry of a personal password of the Customer’s choice.

(c) Financial data: information, details and in general data on financial, asset and family status, occupation, earnings, dependants, E1 and E9 forms, tax clearance certificate (εκκαθαριστικό). Such financial and tax data is collected either directly from the Customer, or on their instruction, or from publicly accessible sources, and its validity is cross-checked via AI.

(d) Data relating to the digital or physical signing of applications and documents addressed to the banking institutions and for compliance with the GDPR.

(e) Data requested when granting consent for a check by the “Tiresias” system or for carrying out credit and creditworthiness checks in general for Greece and abroad.

The personal data necessary for User Registration (login) which we collect is currently only the following:

  • First name
  • Surname
  • E-mail address
  • Telephone number

It is noted that the data requested and collected is strictly necessary for any transactional or contractual relationship of the Customer with ZB IKE. The type and volume of the data collected depends in each case on the type of contract that either will be concluded or exists with the banking institution and the service offered. It is further noted that data is also collected through ZB IKE’s website during the use of the platform, directly from the customer following their identification by the General Secretariat of Information Systems (Γ.Γ.Π.Σ.). This data may be used by the Controller for the sole and exclusive purpose of obtaining anonymous statistical information on the use of the Website and the platform, in order to process Customers’ applications. If requested by a competent Authority, e.g. by Court Decision, the data could be used to establish liability in the event of hypothetical cybercrimes against the Website, the platform, their Partners or Users.

With your express consent, through the analysis of your personal data, we may process information about your creditworthiness in order to present you with proposals and offers for loans and loan products in line with your preferences.

Where the processing of the above personal data is based on the Customer’s consent, ZB IKE follows the procedures provided by legislation for informing the Customer and obtaining their consent.

Information about your profile, search engines and location data

We collect information about your navigation on our website or the Application, such as the pages/windows you visit and how you interact on a single page/window, and we store this information on our servers. Only with your consent may the Controller personalise your experience as a registered user using this information, and proceed to analysis through automated processes such as profiling, recommending Partners according to your preferences and sending you commercial updates tailored to your interests. These updates will be made only through the means you have chosen.

No action of the User or Visitor on ZB IKE’s website and Application is visible or accessible to third parties.

When using the Website and the application while the location function is active, the Website and the application may collect and process information about the user’s current location. This data is processed in a manner that allows the personal identification of the registered User and is used to send personalised advertising updates based on the locations recorded by the location function. This information about the user’s location is not shared with third parties and can be activated or deactivated by the user at any time from their device settings. Location data used for advertising purposes to registered users, concerning their areas of interest, is stored strictly temporarily and only for the strictly limited period of the User’s/Visitor’s browsing or stay on the Website or the Application.

For what purposes we process personal data

ZB IKE processes your personal data as required for the following purposes:

(i) Provision of services — includes appointment booking / reservation (legal basis: processing necessary for the performance of the contract or for the implementation of measures taken prior to entering into the contract).

(ii) Marketing activities — this includes providing personalised content, targeting advertising or sending newsletters, provided that we have obtained your prior consent (legal basis: legitimate interest).

(iii) Compliance with legislation.

Why we collect your personal data and how we process it

The personal data collected as above, either upon your entry to the Web Portal and the start of a transactional relationship, or subsequently during the processing of your application and after its completion, is processed for the following purposes:

(a) The identification of the Customer and communication with them in any case of a transactional or contractual relationship with them, for the fulfilment of contractual or statutory obligations of ZB IKE.

(b) In the case of concluding a loan, and in the context of compliance with legal obligations or the defence of a legitimate interest of ZB IKE: i. to assess the credit risk that ZB IKE is either called upon to assume or has already assumed; ii. to monitor the progress of the relevant contract; iii. to prevent or limit the possibility of default on the resulting obligations; iv. to pursue the collection of amounts due in the event of default on the relevant obligation — which constitute obligations of ZB IKE under the law and/or the regulatory decisions of the supervisory authorities (in ZB IKE’s case, the Bank of Greece (BoG)), as well as towards all of ZB IKE’s Customers.

(c) The conclusion of a contract with the Customer, its performance and generally its smooth operation, and the fulfilment of ZB IKE’s resulting obligations towards the Customer.

(d) The documentation of a request submitted by the Customer (such as, indicatively, a request to restructure their debt due to hardship for health reasons) and its examination by ZB IKE.

(e) The prevention and suppression of money laundering and terrorist financing, and the prevention of fraud against ZB IKE or its Customers, as well as of any other unlawful act.

(f) ZB IKE’s compliance with the obligations imposed by the applicable legislative and regulatory framework and supervisory requirements, as well as with decisions of authorities or courts.

(g) The defence of ZB IKE’s rights and legitimate interests and the protection of the transacting public, such as, indicatively, safeguarding ZB IKE’s security procedures, crime prevention, and the detection and ability to collect evidence of unlawful conduct (fraud incidents, etc.).

To whom we transfer your personal data

In order to provide you with the services you request, your personal data may be provided to:

(i) Selected employees of ZB IKE who are responsible for assessing your requests, managing and operating your intended contract(s) with the banking institutions, fulfilling the obligations arising therefrom, as well as the related obligations imposed by law.

(ii) Entities to which ZB IKE assigns the performance of specific tasks on its behalf (processors), such as lawyers, notaries and bailiffs, experts, surveyors, natural or legal persons, as well as IT application maintenance service providers, always subject to the observance of confidentiality.

(iii) Credit and/or financial institutions, established in Greece or abroad, which hold the required operating licence and operate lawfully, as well as special-purpose companies or entities within the meaning of Law 3156/2003 on the securitisation of receivables, as in force.

(iv) Credit institutions and/or payment service providers in Greece or abroad, for the conclusion of the intended loan agreement with the Customer or of transactions requested or carried out by the Customer.

(v) Supervisory, independent, judicial, public and/or other authorities within the scope of their competences.

The recipients of data for information that ZB IKE is obliged or entitled to disclose under a contract, the law, or a judicial or regulatory decision may include public and independent administrative authorities, judicial authorities and public officials.

ZB IKE will not disclose, exchange, grant or otherwise provide your personal data to third parties, natural or legal persons, without your consent, except in the cases mentioned above, within the framework of the legislation.

How long is your data retained?

We retain your data for a period of 5 years, which is necessary for the fulfilment of the processing purposes defined above. The 5-year period restarts from each most recent consent/use by the Visitor/User. However, this data will be deleted when you cease interacting with ZB IKE — that is, after the conclusion or the definitive abandonment of the loan agreement — unless ZB IKE has a legitimate interest in retaining the personal data for longer, for example in order to protect its legal claims. This is the case where ZB IKE has a legal obligation to retain your data for a longer period (for example, under the applicable accounting rules) or in other cases where the legislation obliges us to keep those records for a longer period. Documents bearing your signature in which your personal data has been recorded may, at ZB IKE’s sole discretion, be kept in electronic/digital form after the lapse of five (5) years.

Your personal data is safe

In accordance with best practices, we implement the necessary security measures to protect your data from accidental or intentional manipulation, loss or destruction and from unauthorised access. ZB IKE stores information subject to data protection only on servers located within the European Union. A minimal number of authorised individuals and persons, committed to improving data protection and involved in the technical, administrative or editorial supervision of the data, may have access to this data.

Website cookies

ZB IKE may use cookies to enable or facilitate the transmission of a communication between ZB IKE and the users of its website. These cookies, if you have chosen to accept them based on your computer’s settings, are small text files stored locally in the cache of the page visitor’s browser.

Data concerning users’ behaviour on our website is collected anonymously for marketing and optimisation purposes. This data will not be used to personally identify a visitor and will not be collected together with personal data. The collection and storage of data may be refused at any time for these services.

You can configure your computer’s browser settings so that you are either notified of the use of cookies in specific areas of this website, or so that the use of cookies is not accepted in any case.

What are your rights regarding the protection of your personal data and how can you exercise them?

With regard to your data, as Customers, you have the following rights:

(a) To know which personal data concerning you ZB IKE holds and processes, as well as its origin (right of access).

(b) To request its rectification and/or completion so that it is complete and accurate, submitting any necessary document evidencing the need for completion or correction (right to rectification), which is at the same time also an obligation of the Customer.

(c) To request the restriction of the processing of your data (right to restriction).

(d) To refuse and/or object to any further processing of your personal data held by ZB IKE (right to object).

(e) To request the erasure of your data from ZB IKE’s records (right to be forgotten).

(f) To request that ZB IKE transfer the data it has been provided with to any other controller (right to data portability).

It is noted that satisfying the requests under (c), (d) and (e), insofar as they concern data necessary for the conclusion or the continuation and operation of the contract, regardless of whether the data was provided by the Customer or obtained from any public source, entails the automatic termination by the Customer of the relevant contract or contracts, in accordance with their respective terms, or the impossibility of examining the data subject’s request.

Beyond the above rights, you may also take the following actions:

(i) Withdraw your consent to the processing of your data.

(ii) Be removed from the contact lists to which you have subscribed, so that you no longer receive e-mails and/or telephone calls from us.

(iii) Request access to your data in order to check, correct, update or delete your personal data, and to restrict its processing.

(iv) The right to lodge a complaint with the supervisory authority — the right to file a complaint against the Company with the Hellenic Data Protection Authority, or any other authority designated by the Greek state, or any supervisory authority for personal data of an EU Member State, if you consider that your rights are being infringed in any way.

The supervisory Authority for the Company is:

Hellenic Data Protection Authority
Kifissias 1-3, 115 23, Athens
Call centre: +30-210 6475600
Fax: +30-210 6475628
E-mail: contact@dpa.gr

To exercise the above rights, the Customer may contact:

  • ZB IKE, by completing the Rights Request form (in Greek) and sending it by physical mail to ZB IKE’s address: 107-109 Vasileos Pavlou Avenue, Voula, Attica, 16673
  • online on the company’s websites www.mystegastiko.gr / www.neuvel-trust.gr, by completing the contact form
  • by e-mail at info@neuvel.gr

ZB IKE is in any case entitled to refuse a request for restriction of processing or erasure of the Customer’s data if the processing or retention of the data is necessary for the establishment, exercise or defence of its legitimate interest or its legal rights, or for its compliance with its legal obligations, in accordance with chapters (1) and (2) above.

The exercise of the right to portability (under (f) above) does not entail the erasure of the data from ZB IKE’s records, which remains subject to the terms of the immediately preceding paragraph.

The exercise of the above rights operates for the future and does not concern data processing already performed.

Data controller and data protection officer

To exercise the rights of the preceding point, the data subject may contact the Data Controller and/or the Data Protection Officer at any time, for any communication regarding the processing of their personal data, or to be informed of the updated list of the data Processors designated by the company, at the following addresses:

Data Controller:
ELLI KOUGENTAKI
107-109 Vasileos Pavlou St.
Voula, 16673
elli@neuvel.gr

For any request concerning the protection of personal data and its processing, you may contact our data protection officer (DPO), writing to “Data Protection Officer” at the Controller’s address, or by e-mail to the DPO at elli@neuvel.gr

The data protection officer (DPO):
ELLI KOUGENTAKI
107-109 Vasileos Pavlou St.
Voula, 16673
elli@neuvel.gr

The above information to the Customer is provided pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council and the provisions of Greek personal data protection legislation adopted and applied in its context, and replaces any earlier information provided in the context of Law 4624/2019 which may be referred to in contractual or other documents of ZB IKE.


Neuvel — Mortgage Credit Intermediary, supervised by the Bank of Greece.