We are already fully compliant with the General Data Protection Regulation (GDPR) — the data-protection framework that applies across the European Union and the European Economic Area. GDPR is a single, harmonised standard, so what applies in Greece applies, in substance, across Europe. Our operations meet the obligations of the national implementing law in each country where we work — including Greece’s Law 4624/2019 — and we maintain clear, auditable processes for all data-related activities.
Our current policies and certifications meet the standards set by the Hellenic Data Protection Authority (HDPA) — the supervisory authority for Greece — and the UK’s Information Commissioner’s Office (ICO), under registration ZC024199.
Compliance here is not a checkbox — it follows from how we build. Infrastructure runs on European hardware, outside US jurisdiction, aligned with GDPR and the Schrems II reality. Read our full privacy policy and our position on US technology.
This page describes Vavelio’s GDPR compliance posture as we understand it. It is provided for information and is not legal advice. Clients should seek qualified counsel for their specific circumstances.
Last updated: August 2026