Policies
Four issued documents, the people and channels they name, and what this website records about a visit.
Documents
Each policy is issued as a PDF and reviewed annually. All four are current in the English edition; a Greek edition is added here when issued.
Applies toEmployees, contractors and third parties processing personal data for or on behalf of TotalView, in any format and on any system.
Covers
- GDPR, Greek Laws 4624/2019 and 3471/2006; the Article 5 principles, accountability included.
- TotalView as controller and as processor: client instructions, authorised sub-processors, Article 28 agreements.
- Record of Processing Activities, impact assessments, privacy by design. Transfers outside the EEA only under an adequacy decision or Standard Contractual Clauses.
- Retention per record type. Role-based access, multi-factor authentication, encryption, access logging, tested backups.
- Data subject requests answered within one month, free of charge. Breaches notified to the Hellenic Data Protection Authority within 72 hours and to clients without undue delay.
Applies toEmployees, contractors, consultants, suppliers, clients and other stakeholders of TotalView, on every project.
Covers
- Directive (EU) 2019/1937 and OLAF guidance on fraud in EU-funded projects.
- What to report: bribery, fraud, corruption, financial malpractice, regulatory breaches, misuse of company assets.
- Three channels: dedicated e-mail, anonymous web form, the Compliance Officer directly.
- Confidentiality of the reporter, protection from retaliation, no sanction for good-faith reports that prove unfounded.
- Initial assessment, investigation team, interim measures, outcome to senior management, secure log reviewed annually.
Applies toEveryone performing services for TotalView, on its premises or as its representative or agent towards customers.
Covers
- Equal opportunities and a workplace free of harassment, intimidation and violence.
- Anti-corruption: no bribes or kickbacks; facilitation payments only as a one-off under coercion, reported to Legal within 24 hours; no gifts or entertainment given or accepted.
- Conflicts of interest, work with family or friends disclosed, commission arrangements pre-approved.
- Company resources, confidentiality of TotalView and third-party information, complete and accurate records.
- Grey market, international trade rules, insider dealing, media contact through the company only, cooperation with audits.
Applies toTotalView O.E. as an employer, at every level of the organisation.
Covers
- Leadership commitment and internal communication.
- Recruitment: gender-neutral descriptions, diverse candidate pools, unconscious-bias training, monitored targets.
- Career development, flexible working, parental leave for both parents, return-to-work support.
- Pay audits, transparent salary bands, annual reporting on pay equity.
- Zero tolerance for harassment and discrimination, safe reporting channels, KPIs and an annual review.
Reporting a concern
Bribery, fraud, corruption, misuse of company assets or any other unlawful or unethical conduct on a TotalView project. Anyone may report: staff, contractors, suppliers, clients. Three channels, set by the Whistleblowing Policy.
- Dedicated mailbox[email protected]
Read by the Compliance Officer only.
- Anonymous formOpen the form ↗
No name or address required. Hosted by Typeform.
- Compliance OfficerGeorge Keradinidis
+30 210 5912644
- What to include
- Dates, names, locations, and any documents or evidence you hold. Enough for an investigation to start.
- Confidentiality
- Your identity stays confidential unless the law requires disclosure, and you are told before any disclosure is made.
- Protection
- Retaliation of any kind is prohibited and is itself a disciplinary matter. A good-faith report that proves unfounded carries no sanction.
- What happens next
- Initial assessment by the Compliance Officer, then a formal investigation where warranted. Personal grievances are redirected to the appropriate channel.
Data protection
Requests about personal data TotalView holds go to the Data Protection Contact, by email or by post. Answered within one month, free of charge.
Your rights
- 01Access to the data held about you.
- 02Rectification of inaccurate data.
- 03Erasure when the data is no longer necessary.
- 04Restriction of processing.
- 05Portability in a machine-readable format.
- 06Objection to processing on legitimate interests or for direct marketing.
- 07No decision based solely on automated processing.
- 08Withdrawal of consent at any time.
- 09Complaint to the Hellenic Data Protection Authority, dpa.gr.
This website
No tag manager, no advertising pixel, no consent banner: the one analytics tool sets no cookie and identifies no one. Everything the site does that touches a visitor is listed below.
- Analytics
- Umami Cloud (umami.is). Page views, referring page, country and city, browser, operating system, device type, screen size and language, and clicks on e-mail and phone links. No cookie, no IP address stored. Visits are counted with an anonymous code that changes every month.
- Cookies
- None.
- Language
- The bare address always opens the English site. Your browser and system language are not read. The EN / ΕΛ switch changes the language.
- Third parties
- One on page load: the Umami analytics script (cloud.umami.is). Fonts, images, other scripts and stylesheets are served from this domain.
- Forms
- None on this site. Contact routes are mailto: and tel: links. The anonymous reporting form above is hosted by Typeform under its own terms.
- Server logs
- Static files on a content delivery network, which keeps the ordinary request logs any host keeps. Not profiled, not joined to anything else.
- MyView
- A separate application on its own domain, with an account and its own terms. Nothing here signs you in or carries anything across to it.