MVR19 Patras
Greece
Enquire
Legal · GDPR

Privacy policy

How TPL S.A. handles the personal data you give us through mav19-goldenvisa.com: what we collect, why, who helps us process it, how long we keep it, and how to use your rights under the EU General Data Protection Regulation (GDPR).

Updated 27 September 2026Applies to mav19-goldenvisa.com and its forms

In short. We collect only what you type into our forms, plus a few technical details that come with it. We use it to answer you and, only if you tick the box, to send project updates. We do not sell it. Form submissions are deleted automatically after 24 months. You can ask us to see, correct or delete your data at any time.

Who is responsible for your data

The controller of your personal data is TPL S.A., the owner and developer of MVR 19.

Controller
TPL S.A.
GEMI number
143336716000
Registered office
Ethnomartyron 40, 263 33 Patras, Greece
VAT number
EL800864603
Privacy contact
kotsalidis [at] tpl.gr

Write to that address, or to the registered office, with any question about your data or to use any of the rights described below. Full company details are on our company information page.

What we collect

Investor enquiry form

On the enquiry page we ask for your first name, last name, email address and nationality (required), and optionally your phone number, country of residence, your interest (for example a Golden Visa purchase), your preferred contact method and language, the residences you are interested in, and a message. We also record whether you accepted the privacy notice and whether you opted in to project updates.

Student waitlist form

On the student pages we ask for your first name, last name and email address (required), and optionally your phone number, who is enquiring (for example a student or a parent), the university, your intended start date, the studio size you prefer, your preferred language and a message. We also record your privacy acknowledgement and whether you opted in to updates.

Details that come with a form

When you send a form, we also store the page you sent it from, the website that referred you, the language of the page, the date and time, the country your connection comes from (as detected by our host from your IP address) and your browser's user-agent string. If you arrived through a tagged link, we store its campaign tags (utm_source, utm_medium, utm_campaign, utm_term, utm_content) and any advertising click identifier in it (gclid or fbclid). The cookie policy explains how these tags are remembered during your visit.

Your IP address is used, but not stored with your enquiry, in two ways: it is kept for one hour in a counter that limits repeated submissions, and it is passed to Cloudflare Turnstile to check that the form was sent by a person.

When you contact us directly

If you email, call or message us on WhatsApp, we receive what you choose to send and your contact details. WhatsApp is run by WhatsApp Ireland Limited under its own terms and privacy policy.

Visiting the site

Like any website, our host processes the technical data every visit involves, such as your IP address, the page requested and your browser type, to deliver the site and protect it from attack. We do not use this to identify you, and the site sets no advertising or analytics cookies.

We do not ask for sensitive data such as health, religion or political views. Please do not include it in a message. Our forms are not meant for children; if you are under 18, please ask a parent or guardian to contact us.

Why we use it, and on what legal basis

Purposes of processing and their legal basis under Article 6(1) GDPR
PurposeLegal basis
Answering your enquiry, sending the price list or document pack you ask for, arranging a callSteps taken at your request before entering into a contract, art. 6(1)(b)
Keeping your place on the student waitlist and contacting you when leases openSteps taken at your request before entering into a contract, art. 6(1)(b)
Protecting the forms and the site against spam, abuse and fraud (Turnstile, a hidden spam trap, a submission limit)Our legitimate interest in security, art. 6(1)(f)
Knowing which pages and campaigns lead to enquiries, from the tags listed aboveOur legitimate interest in understanding which of our marketing works, art. 6(1)(f)
Sending occasional project updatesYour consent, art. 6(1)(a), given only by ticking the optional box; withdraw it at any time
Preparing a purchase or lease if you go ahead, including identity and source-of-funds checksContract, art. 6(1)(b), and compliance with legal obligations, art. 6(1)(c)
Keeping records needed to establish, exercise or defend legal claimsOur legitimate interest, art. 6(1)(f)

Where we rely on legitimate interest, we have weighed it against your rights. You can object at any time (see Your rights).

Who receives your data

We use a small number of service providers. They act as our processors, on our written instructions and under data processing terms that meet Article 28 GDPR.

  • Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) hosts the site, runs the code that receives our forms, stores enquiries and waitlist entries in Cloudflare Workers KV, provides the Turnstile anti-spam check and protects the site against attacks.
  • Our email provider processes our messages when we reply to you by email.
  • Our internal team messaging tool may receive a short notice of each new enquiry, so that we can answer within one business day.

If you go ahead with a purchase or a lease, the people who must take part receive what they need: your own lawyer, the notary, our lawyer, the banks handling payment, the land registry and cadastre, the tax authority, and for a Golden Visa the Ministry of Migration and Asylum. Each acts under its own legal duties. We also disclose data when the law or a court requires it.

We do not sell or rent your personal data, and we do not give it to anyone for their own marketing.

International transfers

Cloudflare runs a global network, so your data may be processed outside the European Economic Area, including in the United States. Cloudflare, Inc. is certified under the EU-US Data Privacy Framework, which the European Commission has found to give adequate protection. Where the Framework does not apply, Cloudflare's data processing addendum uses the Commission's Standard Contractual Clauses. Any transfer by our email provider relies on the same kinds of safeguards. Ask us for a copy of the safeguards that apply.

How long we keep it

  • Enquiries and waitlist entries: each form submission carries an automatic expiry and is deleted 24 months after you send it. If we stay in contact, we keep our correspondence with you for 24 months from our last contact, then delete it.
  • The submission counter holding your IP address: one hour.
  • Marketing: until you withdraw your consent or unsubscribe. After that we keep only a note that you opted out, so that we do not write to you again.
  • If you buy or rent: contracts, payment records and anti-money-laundering records are kept for as long as Greek tax and anti-money-laundering law require.

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and get a copy;
  • rectification of data that is wrong or incomplete;
  • erasure of your data, where there is no longer a reason to keep it;
  • restriction of processing while a question about your data is resolved;
  • portability: receiving the data you gave us in a common machine-readable format;
  • objection to processing based on our legitimate interest, and to direct marketing at any time;
  • withdraw consent at any time, without affecting what we did before you withdrew it.

To use a right, write to kotsalidis [at] tpl.gr. It is free. We reply within one month; for complex requests we may extend this by two further months and will tell you why. We may ask you to confirm your identity first.

You may also complain to the Hellenic Data Protection Authority, Kifisias 1–3, 115 23 Athens, Greece, www.dpa.gr, or to the data protection authority where you live or work in the EU. We would welcome the chance to put things right first.

No automated decisions

We make no decisions about you based solely on automated processing, including profiling, that have legal or similarly significant effects. The only automated step is the Turnstile check, which decides whether a form submission looks like spam. If it ever blocks you, email or message us instead and a person will reply.

If you go on to buy

A property purchase in Greece involves identity and anti-money-laundering checks. If you decide to buy, you will be asked for identity documents, proof of address and evidence of the source of your funds. The notary, the lawyers and the banks involved must carry out these checks under Greek anti-money-laundering law (Law 4557/2018), and they process that data under their own legal obligations. We process what the sale contract and the payment require. Your Golden Visa application itself is handled by the Ministry of Migration and Asylum, under its own privacy notice.

Security

The site is served only over encrypted connections (HTTPS). Form data is checked and length-limited when it arrives, and stored enquiries can be read only by the people at TPL S.A. who answer them. No system is perfectly secure; if we learn of a breach that puts your rights at risk, we will tell you and the authority as the GDPR requires.

Changes to this notice

If we change how we handle personal data, we will update this page and its date before the change takes effect. If we ever add analytics or any other non-essential technology, we will say so here and on the cookie policy first.

Updated 27 September 2026Controller: TPL S.A., Patras