Skip to content

Hournook · Legal

Privacy policy

Last updated 28 September 2026 · Version 2026-09-28

How Hournook handles personal data under the EU General Data Protection Regulation (GDPR) and Greek law 4624/2019, whether you run a business on Hournook or booked an appointment with one.

1.Who is responsible

Hournook is provided by Theocharis Panagiotis Siozos (ΣΙΩΖΟΣ ΘΕΟΧΑΡΗΣ ΠΑΝΑΓΙΩΤΗΣ), sole proprietor trading as DevTaskHub.com, Markou Mpotsari 83, 546 44 Thessaloniki, Greece. VAT no. (ΑΦΜ) 169481343, General Commercial Registry (Γ.Ε.ΜΗ.) no. 186989906000 (“we”, “us”).

For any question about privacy or to exercise your rights, email devtaskhub@devtaskhub.com. We have not appointed a data protection officer because the law does not require one for our activities; privacy requests are handled directly by the owner of the business.

2.Two roles: controller and processor

Hournook is used by two groups of people, and our role is different for each:

  • Businesses and their team members who have a Hournook account. For their account, billing, support and security data, we are the controller. This policy describes that processing.
  • Customers of those businesses who book through a booking page, or whom a business adds itself. The business decides why and how this data is used, so the business is the controller and we act as its processor under our Data Processing Agreement. The business’s own privacy notice applies to you.

If you booked with a business and want to see, correct or delete your details, please contact the business directly; it can do this from its dashboard. If you write to us, we will forward your request to the business and help it respond.

3.What data is processed

Account data (we are controller)

  • Name, email address, whether the email is verified, language.
  • Your password, stored only as a salted one-way hash, so we cannot read it.
  • When and which version of our terms you accepted at sign-up.
  • Sign-in sessions with IP address and browser type, to keep you signed in and protect your account.

Business data (we are controller for billing; processor for the rest)

  • Business name, category, address, contact details you choose to publish, time zone, booking-page settings, logos and photos.
  • Services, prices, opening hours, closures, booking rules, staff and their roles.

Customer and appointment data (we are processor)

  • Name, email address and phone number of the person booking, any message they add, and private notes the business writes.
  • Service, staff member, date, time, duration, price, status and history of changes (for example rescheduled or cancelled, and by whom), and how the booking was made (booking page, embedded widget or QR code, and a referring site or campaign tag where available).

Billing data (we are controller)

  • Subscription status and Stripe customer and subscription identifiers. Card details are entered on Stripe’s pages; we never receive or store full card numbers.
  • Invoices and payment records required by tax and accounting law.

Security and service records (we are controller)

  • An audit log of significant actions (for example sign-ins, settings changes, exports and deletions) with the IP address and a request identifier.
  • Short-lived rate-limiting counters that block abuse.
  • Technical server logs kept by our hosting provider.
  • Booking-page statistics: counts of booking steps (such as “page viewed” or “booking completed”) with a traffic source. They are cookieless and contain no names, contact details, IP addresses or device identifiers.

Support

  • Emails you send us and our replies.

We do not buy personal data, do not use tracking or advertising cookies, and do not use analytics services that profile visitors.

4.Why we use it and our legal basis

  • Providing the service to businesses: accounts, booking pages, calendar, customer lists, team features, exports and service emails (verification, password reset, invitations, billing notices): necessary to perform our contract with you (GDPR art. 6(1)(b)).
  • Processing customer and appointment data: only on the instructions of the business, under the DPA (GDPR art. 28). The business is responsible for its own legal basis.
  • Billing, invoicing and accounting: contract (art. 6(1)(b)) and our legal obligations under Greek tax and accounting law (art. 6(1)(c)).
  • Security, fraud and abuse prevention: audit logs, rate limits and server logs: our legitimate interest in keeping the service and its users safe (art. 6(1)(f)).
  • Support: answering your messages: contract or, if you are not a customer, our legitimate interest in responding (art. 6(1)(b) or (f)).
  • Improving Hournook: using aggregated, non-identifying information about how features are used: our legitimate interest (art. 6(1)(f)).
  • Legal claims and requests from authorities: where necessary to establish, exercise or defend legal claims or comply with the law (art. 6(1)(c) and (f)).

5.No selling, no advertising, no automated decisions

We do not sell or rent personal data, we do not use customer or account data for advertising, and we do not send marketing emails without your consent. We make no decisions based solely on automated processing, including profiling, that have legal or similarly significant effects on you.

6.Who receives data

Personal data is shared only with the providers below, which process it on our instructions under data processing agreements, and only as far as each needs to:

Sub-processors
ProviderWhat it does for usLocation
Netlify, Inc.Application hosting, serverless functions, content delivery, scheduled jobs, application logs and storage of uploaded imagesUnited States
Neon, Inc.PostgreSQL database: accounts, businesses, customers, appointments and backups of themUnited States (database hosted on Amazon Web Services)
ResendDelivery of transactional emails: booking confirmations, changes and reminders; account and security emailsUnited States (emails sent from its EU region, Ireland)
Stripe Payments Europe, Ltd.Subscription payments, invoices and the billing portal for businesses (never receives End Customer data)Ireland

Stripe also processes payment data as an independent controller under its own privacy policy (for example for fraud prevention and to meet financial regulations). We may also disclose data to authorities, courts or professional advisers (such as our accountant or lawyer) where the law requires or allows it.

7.Transfers outside the EEA

Some of our providers are based in the United States or may access data from there. Where personal data is transferred outside the European Economic Area, we rely on an adequacy decision of the European Commission (for providers certified under the EU–U.S. Data Privacy Framework) or on the European Commission’s Standard Contractual Clauses, together with the additional safeguards our providers offer, such as encryption in transit and at rest. You can ask us for more information about these safeguards.

8.How long we keep data

  • Account and business data: while the account exists. When a business or user account is deleted, its data is deleted from our live systems immediately, and from our database provider’s backups within 30 days.
  • Customer and appointment data: for as long as the business keeps it, until the business erases the customer, or until the business is deleted.
  • Sign-in sessions: expire after 30 days without activity and are then deleted.
  • Email verification and password-reset links: deleted 7 days after they expire.
  • Emails we send: the content is cleared after 180 days. For appointment emails a delivery record (recipient, type, status and date) stays with the appointment; records of account emails are deleted after 180 days.
  • Audit log: IP addresses are removed after 180 days and entries are deleted after two years.
  • Rate-limiting counters: deleted within an hour of expiring.
  • Booking-page statistics (anonymous): deleted after about 13 months.
  • Invoices and billing records: for as long as Greek tax and accounting law requires: generally five years from the end of the tax year, longer if the law extends that period.
  • Support emails: for as long as needed to handle your request and for up to two years afterwards, unless a longer period is needed for a legal claim.

9.Your rights

Under the GDPR you have the right to:

  • access your personal data and receive a copy;
  • have inaccurate data corrected;
  • have your data erased where there is no longer a reason to keep it;
  • restrict processing in certain cases;
  • receive the data you gave us in a structured, machine-readable format (portability);
  • object at any time to processing based on our legitimate interests, for reasons relating to your particular situation; and
  • withdraw any consent you gave, without affecting processing before the withdrawal.

Businesses can do most of this themselves: edit details in settings, export data from the dashboard, and delete the business or user account in settings. For anything else, email devtaskhub@devtaskhub.com. We answer within one month (extendable by two further months for complex requests, in which case we tell you why). We may ask you to confirm your identity first.

You also have the right to lodge a complaint with a supervisory authority, in particular in the EU country where you live or work or where an infringement took place. In Greece this is the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias Avenue 1–3, 115 23 Athens, www.dpa.gr. We would appreciate the chance to address your concern first.

10.Do you have to give us your data?

To create an account we need your name, email address and a password; without them we cannot provide the service. Everything else is optional or is information your business chooses to add.

11.Security

We use encrypted connections (HTTPS with HSTS), encrypted database connections, strong one-way password hashing, sign-in cookies that page scripts cannot read, strict separation of each business’s data, role-based permissions for team members, rate limiting of sensitive actions, a content security policy and an audit log. Our providers encrypt data at rest. No online service is perfectly secure; if a personal data breach occurs, we will notify the supervisory authority within 72 hours where required, inform affected businesses without undue delay, and inform you directly where the law requires it.

12.Cookies

We only use cookies that are strictly necessary to sign you in and keep your session secure, and your browser’s local storage to remember your light/dark theme choice. We use no analytics, advertising or social-media cookies, so we do not show a cookie banner. See the cookie policy for details.

13.Children

Hournook accounts are for businesses and may only be created by adults. We do not knowingly collect data from children for our own purposes. Businesses that take bookings for children (for example tutoring) are responsible, as controllers, for collecting their data lawfully.

14.Changes to this policy

We will update this policy when our processing changes. The date and version at the top show when it last changed; for material changes we also email account owners in advance.

15.Contact

Theocharis Panagiotis Siozos (ΣΙΩΖΟΣ ΘΕΟΧΑΡΗΣ ΠΑΝΑΓΙΩΤΗΣ), sole proprietor trading as DevTaskHub.com, Markou Mpotsari 83, 546 44 Thessaloniki, Greece. VAT no. (ΑΦΜ) 169481343, General Commercial Registry (Γ.Ε.ΜΗ.) no. 186989906000. Email: devtaskhub@devtaskhub.com.