Legal

Privacy Policy

This Policy explains how DUTT processes personal data across its website, applications, shipments, e-shop integrations and related support operations.

Version 2.0 · Effective August 30, 2026

Current and previous versions

1. Controller and scope

The controller is the sole proprietorship SOURRAS DIMITRIOS EVANGELOS, trading as DUTT, at Koutlimpana 5-7, Larissa, Greece, email info@dutt.gr, telephone +30 241 400 5377.

This Policy covers the DUTT customer app, courier app, website, hosted checkout, WooCommerce and custom website integrations, forms, support, payments and the administration required to provide the service.

2. Data categories

Depending on the person's role and use, we process account and contact details, sender and recipient details, addresses and instructions, shipment and item descriptions, weight and vehicle category, unique number and tracking events, recipient name, signature or other delivery evidence.

We may also process location and route data, business and invoicing details, payment references without storing the full card number, courier application and relationship data such as identity, tax details, IBAN, vehicle and documents, as well as support messages, complaints, attachments, technical events, device tokens, security records and administrative activity history.

3. Data sources

Data is supplied by the user, sender, recipient, merchant or courier, received through an approved e-shop integration or payment and invoicing provider, or generated by operation of the service, such as shipment state, timestamps, route, evidence and technical records.

4. Purposes and legal bases

Processing supports account management, price calculation, formation and performance of shipment agreements, dispatch, tracking and delivery, payment, invoicing, courier remuneration, support, complaints, security, fraud prevention, quality control and compliance with legal duties.

The legal bases are performance of a contract or pre-contractual steps, compliance with a legal obligation, DUTT's legitimate interests in secure and reliable operation and, only where required, consent. A device permission such as location access is a technical control and is not treated as consent where processing relies on another legal basis.

5. Sharing and recipients

Data is disclosed only as necessary to couriers, senders, recipients or merchants involved in the relevant shipment and to infrastructure, identity, mapping, notification, email, payment, invoicing, accounting and technical-support providers. DUTT uses, among others, Google/Firebase, Google Maps, Viva.com and Elorus for the corresponding functions.

Data is disclosed to a public, supervisory, judicial or law-enforcement authority only where required by law or a valid request. We do not sell personal data.

6. Location, automated functions and confidentiality

Courier location is used while the courier is online or performing a shipment for dispatch, routing, tracking, safety and incident review. The customer app uses submitted addresses and coordinates to calculate price and perform the shipment.

Automated rules may support pricing, courier matching, fraud detection and support prioritisation. A materially adverse outcome may be referred for human review. Sender, recipient and postal-communication data is confidential and available only to authorised persons for a defined purpose.

7. Retention periods

The individual agreement, courier consignment note, tracking, collection and delivery evidence and the minimum regulatory shipment record are retained for at least two years after shipment completion or final closure. Complaint material is retained for at least two years after final resolution. Where a dispute, regulatory review, legal hold or court process is pending, related data is retained until completion if that is longer.

An account and operational profile are retained while active. After a deletion request, data that is no longer required is deleted or restricted, while records required by postal, tax, accounting, employment or other legal duties, or needed to establish, exercise or defend legal claims, remain for the applicable period. Tax documents, payments, payouts and accounting records follow statutory retention periods.

Transient automated-support processing material normally expires after 30 days unless incorporated into an active request, complaint, security incident or other record with a longer legal period. Public template agreements and price-list versions are retained for at least two years from their effective date.

8. Security

We use identity and role checks, access restrictions, encrypted transport, protected backend endpoints, administrative audit records, backups, integrity checks and incident-response procedures. No system provides absolute security, and users must protect their devices and credentials.

9. Rights

Where provided by the GDPR, a data subject may request access, rectification, erasure, restriction or portability, object to processing, or withdraw consent without retroactive effect. Identity verification may be required. Erasure does not remove records that DUTT is legally required to retain.

10. Transfers outside the EEA

If a provider processes data outside the European Economic Area, the transfer relies on an adequacy decision, standard contractual clauses or another lawful mechanism together with appropriate safeguards.

11. Third-party and children's data

A sender or merchant entering recipient details must have a lawful basis and provide accurate, necessary information. The service is not intended for account creation by a minor without lawful parent or guardian authorisation.

12. Requests and complaints

Rights requests may be sent to info@dutt.gr or by post to Koutlimpana 5-7, Larissa, Greece. Shipment complaints use the complaints form. A data subject may also complain to the Hellenic Data Protection Authority.

13. Changes and history

Each change is published as a numbered version with an effective date. A new version applies prospectively. Current and previous versions remain available in the Legal document archive.