Privacy & cookies
Clear choices, minimal collection.
This notice explains how RGRA handles personal data sent through the written contact route and how optional Google Analytics is used on this website.
Controller
Who is responsible for this site
Controller: Thanasis Lagoudakos, Founder, RGRA.
Contact: tl@rgra30.com
RGRA is currently presented on this site as a founder-led practice. If the legal entity responsible for the site changes, this notice must be updated before that new entity is presented as controller.
Written enquiries
If you send a written fit-check or other email, RGRA receives the information you choose to provide, such as your name, business contact details, organisation, role and the non-sensitive background contained in your message.
Purpose: to respond to the enquiry, assess whether the request fits the RGRA service boundary, take requested pre-contract steps where relevant, and maintain necessary business correspondence.
Legal basis: Article 6(1)(b) GDPR where the processing is necessary to take steps at your request before a possible engagement; Article 6(1)(f) GDPR for ordinary business correspondence and proportionate administration where those legitimate interests apply.
Retention: if no engagement follows, ordinary enquiry correspondence is normally deleted or reviewed for deletion within 12 months after the last substantive contact. If an engagement follows, the applicable engagement, legal, accounting, insurance or record-retention requirements may require a different period.
Initial-contact boundary: do not send confidential, privileged or full-file material at first contact. If a matter progresses, the permitted information route is confirmed separately.
Optional Google Analytics
RGRA uses Google Analytics 4 only after you actively choose Accept analytics. If you reject analytics, the Google Analytics tag is not loaded and access to the site is unaffected.
Purpose and legal basis: website measurement and improvement, based on your consent under Article 6(1)(a) GDPR. For visitors covered by Greek cookie rules, optional analytics cookies are not activated before consent.
Provider / recipient: Google Analytics is a Google service. For EEA services, Google publicly identifies Google Ireland Limited as a relevant Google entity; processing may also involve Google affiliates and international transfers under Google's published transfer mechanisms.
Data categories: when analytics is accepted, Google Analytics may process online identifiers and first-party analytics cookies, device/browser information, page and interaction data, and network information used for measurement. RGRA does not use this implementation for Google Ads, remarketing or ad personalisation.
| Cookie / control | Purpose | Duration |
|---|---|---|
rgra_analytics_consent | Necessary first-party preference recording whether analytics was accepted or rejected. | 6 months for either choice. |
_ga and related GA4 analytics cookies | Distinguish users/sessions for analytics after consent. | Site-side configuration: up to 6 months from first set, without renewal on every page load. |
Analytics data retention: event and user-level analytics information is subject to the retention configuration and product rules of the RGRA GA4 property. RGRA uses analytics only for site measurement and reviews the retention setting against that purpose; aggregated reporting may be retained differently by the service.
Your choice: rejecting analytics does not restrict the site. You can change or withdraw your choice at any time using . Withdrawal stops future optional analytics collection from this site and the implementation removes accessible RGRA-domain GA cookies where possible.
Recipients, transfers and security
Written enquiries are handled through the communication and hosting/service providers needed to operate RGRA's email and website. Optional analytics data is sent to Google only after analytics consent. Some service providers may process data outside the EEA. Where required, transfers rely on the safeguards applicable to the relevant provider and service, such as adequacy mechanisms or standard contractual clauses.
Your rights
Subject to the GDPR and the circumstances of the processing, you may have rights of access, rectification, erasure, restriction, data portability and objection. Where processing is based on consent, you may withdraw consent at any time without affecting processing that was lawful before withdrawal.
You may also lodge a complaint with the competent supervisory authority. In Greece, the supervisory authority is the Hellenic Data Protection Authority.
For privacy requests, contact tl@rgra30.com.
