1. Who this policy concerns

Athenian Rider is the name used for this editorial website at athenianrider.gr. Contact us using the email below about personal data, this policy or an article that concerns you. Reading the site does not require a reader account.

This notice covers browsing and direct correspondence now, and describes the intended handling of features still being built. It does not ask you to consent to every use of data simply by visiting.

2. Information, purposes and legal grounds

  • Browsing and security: the web server and relevant providers receive connection information, such as IP address, request time, requested URL and browser information. Logs, where retained, help operate the site, investigate failures and prevent abuse. The basis is the legitimate interest in providing a reliable, secure service, balanced against visitors’ rights. Search terms in URLs may appear in server logs; do not enter private information in search.
  • Language: ar_lang stores el or en to remember the edition you visit. It supports the requested language preference; details and duration appear in the Cookie policy.
  • Correspondence: if you email us, we receive your address, message and any information you choose to include. We use these to respond, assess a correction or handle a request. Ordinary correspondence relies on our legitimate interest in responding; handling statutory data-rights requests also serves our legal obligations. Contract-related enquiries may require steps at your request before an agreement.
  • Contact form: name, reply email, reason, message and an optional article or source link support the same purposes. The article link is required for corrections. Required fields are marked; without enough contact information we may be unable to reply. What you send is stored in our own database, encrypted, and read in the editorial panel — it is not forwarded to any mailbox or third-party helpdesk. Anti-abuse checks use limited technical information to protect the form: a signed timestamp on the form, a hidden field, and a rate limit keyed to a one-way hash of your IP address rather than to the address itself.
  • News notifications: only after you allow them, a subscription endpoint, encryption keys, your chosen language and consent/subscription records are used to deliver new-article alerts to your browser. Consent is the basis, and you can withdraw it from the notification settings page or in your browser at any time. The endpoint and keys are sealed before they are stored, so they can be used to send you an alert and cannot be read back out. No marketing subscription is created by contacting us.
  • Audience measurement: we count page views, article reads, shares and guide actions in our own database. Among them are the words typed into the site’s search and the buying guide’s search, and the website a visitor arrived from, each kept only as a daily count with its language, never kept with who typed or followed it; search text with an @ or with seven or more digits in a row is not kept. A daily value derived from the connection address, browser user-agent and a separate random secret estimates readers without storing a browser identifier. This is a pseudonymous estimate, not a verified person. Raw connection details are not saved in these measurement records. So that an automated program cannot flood these counts, each connection address — for IPv6, each /64 network — can add at most thirty searches, thirty guide searches and thirty arrivals from other websites to them an hour, and anything past that is not counted. Of each kind, at most ten a day from one address, and a hundred a day for the whole site, may be words or a website nobody had used in that language in the last thirty days; past that, the search or arrival is still counted, but without its words or the website’s name. These counts are kept under one-way values made with the day’s secret, and expire after the hour or at the end of the UTC day. The secret and daily values are removed on the next request or scheduled cleanup after that UTC day ends; analytics does not link them across days. Aggregate counts, the words and websites among them, remain for two years. The basis is our legitimate interest in understanding readership, balanced against your rights. This describes audience measurement only; the optional assistant’s separate processing and access records are explained in section 2.2.
  • Readership and countries: a visible public page sends a small first-party check-in with only its Greek or English edition, then renews about every 20 seconds while visible. The first check-in qualifies a daily pseudonymous reader and country count; merely requesting the HTML does not. Repeat check-ins do not add page views or reader-days. No page path, form answers or browser-stored identifier are sent. Server page-request and article-delivery statistics remain separate. The panel estimates readers active in the last minute, not a verified headcount: scripts running a browser can still count, and blocked JavaScript or network failures can omit readers. The presence record contains only its daily value, UTC day, latest time and approximate country. It becomes eligible for deletion after 30 minutes of inactivity or the end of its UTC day and is removed by subsequent check-ins or scheduled cleanup. The server accepts at most 300 check-ins in five minutes from each connection address — for IPv6, each /64 network — and 1,200 from each IPv6 /48 network; those counts are kept under one-way values of the network and the day’s secret, and expire after the five minutes. Each address or IPv6 /64 network can add at most ten new readers a day, and each IPv6 /48 network thirty, and after an extreme surge no more are counted that day; these counts, and how many new readers came from each IPv4 /24 network, are kept the same way and expire when the UTC day ends. Only the day’s totals remain, such as the most new readers one network brought. A browser that reports itself as automated sends no check-in, and our own test visits are not counted as reads or readers. We also count, per day and kind of browser, how many new readers came with the request headers their browser sends and how many without; that count identifies no one. Shared connections and matching browsers can merge readers; different devices can count separately.
  • We estimate country locally from the connection address using the free DB-IP Lite country database. We do not send visitor addresses to DB-IP, use browser geolocation or retain city or precise location. VPNs, mobile networks and incomplete or outdated data can produce a different or unknown country. Daily country totals contain no visitor value, are kept for two years and are counted as reader-days across a period, not distinct people across days. These limited statistics serve the same legitimate interest in understanding readership and remain separate from optional Google Analytics.
  • Promotion links: we count activations of homepage promotion buttons and their category-menu links separately, by promotion and Greek or English edition. The daily aggregates contain the promotion identifier, edition and click totals, without the destination URL or an individual reader history. A visitor’s repeated clicks on the same promotion and link count once a day, recognised by the same daily value that estimates readers; like that estimate, it is pseudonymous, not a verified person. Past totals remain when a promotion is unpublished, archived or deleted, under the same two-year aggregate retention described above. These first-party counters add no browser cookies and continue when optional Google Analytics is disabled.
  • Google Analytics is disabled: its code and measurement requests do not load on new pages. If it is enabled again, it loads only after a valid acceptance; the Cookie policy explains saved choices and withdrawal. Our own server-side audience counts continue independently. Any future advertising that requires consent needs a separate choice.

Country data: DB-IP Lite ↗

Its licence: Creative Commons Attribution 4.0 (CC BY 4.0) ↗

2.1 Newsletter

Newsletter signup collects email addresses. We use your email, your selected newsletter language and a record of your consent to maintain the subscriber list and to send you selected Athenian Rider articles, reviews and news. The basis is your optional consent, given by ticking the consent box. Reading the site, contacting us or enabling browser notifications does not subscribe you.

A subscription is active as soon as the form is submitted; we do not send a confirmation email first. This means we do not verify that an address belongs to the person who entered it, so if you have been subscribed without asking, use the unsubscribe link and choose “I did not sign up myself”, or write to the privacy contact below, and we will remove the address and keep it blocked, so that the signup form cannot add it again. An address we remove from the list ourselves is kept blocked the same way, until its owner asks us to allow it again. Every newsletter carries a free unsubscribe link that needs no account, no password and no explanation: it opens a page that removes the address immediately and offers an optional reason you are free to ignore. Withdrawing consent stops future newsletters and does not affect the lawfulness of earlier processing. We will not sell the list, enroll you in third-party marketing or use subscriber addresses as inputs to editorial AI.

Subscriber information is held privately in the website database, where it is readable only by the editorial panel. The newsletter is sent by the site itself: no third-party email-delivery provider is given your address. If that ever changes, the provider and any transfer safeguards will be named here before it does.

A subscription is kept while it lasts and for no other purpose. Unsubscribing removes the address from delivery immediately and records that the choice was made; a limited record of consent and withdrawal may be kept where necessary to demonstrate that choice or to prevent an address being resubscribed against its owner’s wishes. Fixed retention periods for withdrawn records, review of inactive lists and deletion from backups are not yet settled and will be stated here once they are. You can ask us to delete your record at any time using the privacy contact below.

2.2 Buying Guide digital assistant

The optional assistant uses the riding needs you choose: intended use, licence category and restrictions, budget, experience, route frequency and distance, riding position and handling preferences, bike type and style, priorities, passenger journeys and luggage needs, power and transmission preferences, charging and distance requirements, brand preferences and exclusions. Any note is optional. Do not include names, contact details, licence numbers, health information or other private information about yourself or anyone else. You can browse the catalogue without using the assistant.

Your answers and progress, and a random reference to your latest request, are saved in this browser tab so you can move between questions or reload, and so that only this tab can reopen that request's results. The browser normally removes this session storage when the tab session ends, although restoring a session may restore it. Start again resets the saved questionnaire and forgets that reference; browser site-data controls also let you remove it. The collapsed assistant invitation is remembered in the same way. These functional preferences are not advertising identifiers; the Cookie policy explains the storage.

When you request suggestions, our server screens the current catalogue and sends the relevant answers, optional note and eligible catalogue facts to an external artificial-intelligence provider to select up to three models and write Greek and English explanations. We do not add your IP address, browser identifier or access-control hash to that model request.

We retain each submitted questionnaire, its exact budget, optional note, submission time, language, outcome and returned catalogue/result snapshot for market research and improvement of the guide. These independent records are encrypted at rest and available only in the owner’s protected analytics panel. They include no IP address, user-agent, visitor hash or account identifier, are not linked to each other and are not linked into a history of one rider. Beyond a daily limit on these records, further submissions are answered but not kept.

Our basis for this limited research is our legitimate interest in understanding riding needs and improving the service, balanced against readers’ rights. We do not use these records for individual advertising, sell them or add them to marketing lists. You can object or request erasure using the privacy contact below; please give the approximate submission date and enough detail to locate the record.

The AI is instructed not to repeat private details, but generated explanations can reflect what you wrote, so optional notes must contain riding preferences only.

The basis for providing these requested suggestions and briefly preserving access to them is our legitimate interest in operating an optional, useful motorcycle guide. Separate legitimate interests are preventing abuse and controlling shared service costs. We limit the data, do not require a reader account and provide the ordinary catalogue as an alternative. The assistant makes suggestions; it does not approve a licence, decide an entitlement or make a decision with legal or similarly significant effects on you.

To apply the configured hours between uses, the server derives a short access value from your IP address and browser user-agent using separate daily secrets. It stores that value, the date and time, a one-way hash of the random reference your browser tab sent with the request, and the result text and catalogue facts; those results reopen only for the tab that holds the reference. It does not store the original address or browser string in this access record. Separate finder secrets cover the current day and previous seven UTC dates; access records become eligible for deletion after eight days and are removed by subsequent requests or scheduled cleanup. The value is pseudonymous, not proof of one person: shared connection/browser characteristics can share a limit, though not its saved results. This record is independent of the audience-measurement identity that expires daily. Separately, an hourly limit on submissions is keyed to a one-way hash of your IP address rather than to the address itself, and each count expires after an hour.

Where it is offered, you can also have the results on the page sent to an email address you type below them. The address is used to send that one email, from noreply@athenianrider.gr and in the same way as the newsletter; unless you also tick the newsletter box, it is not saved in our database or added to any list, although, as with any email, the mail server’s delivery log records it. To limit repeat sending we keep counts under one-way keyed values that cannot be turned back into what they were made from — of the address and of your IP address for up to a day, and of the result for eight days — which are then deleted by later requests or scheduled cleanup. One result can be sent only a limited number of times, and one address can receive only a limited number of such emails a day. The email carries the recommended models, their prices and links to them, the reasons the page gives for each, and your answers on use, licence, budget and gearbox — never your optional note. As said above, the assistant’s explanations can reflect what you wrote, so one that contains a phone number, an email address or a web address is replaced by the guide’s standard reason. The newsletter box under the address is not ticked; ticking it subscribes the address exactly as the newsletter form does, as described in 2.1. Because anyone can type any address, an email of this kind you did not ask for can simply be ignored: nothing further is sent unless the newsletter box was ticked as well, and then the unsubscribe link in any issue, or the privacy contact below, removes the address.

We also count questionnaire steps, bounded answer categories, outcomes and displayed models to improve the guide. These aggregate counters do not contain exact budgets or notes; the separate research records described above do. These aggregate counts use the audience-measurement retention described below. Separate spending records keep request references, model, token counts, outcome and cost; they contain no visitor access hash, questionnaire, note or generated explanation. They are retained for operating, reconciling and auditing the service budget, without an automatic deletion period currently configured.

The artificial-intelligence provider processes requests through its API. Its published default is not to use API data for model training unless the customer opts in. Our requests disable storage for later response retrieval; that is not a zero-retention promise. The provider may retain content in abuse-monitoring records, normally for up to 30 days and longer for specified legal or safety reasons, and may retain temporary prompt-cache data for up to 24 hours. Provider processing can occur outside the EEA. The service does not promise EU-only processing or zero retention by the provider.

AI provider data controls and retention ↗

3. Editorial sources and AI

The newsroom uses selected source material to prepare original Greek and English coverage, and keeps the evidence behind an article for verification and corrections. Publicly available names, roles, quotations or other relevant facts can still be personal data. Editorial processing must have an appropriate legal basis and respect the applicable balance between privacy and freedom of expression; public availability is not unlimited permission to reuse information.

AI assistance prepares editorial drafts from that evidence. Some of those drafts are then published automatically — without a person having read them first — and only when they pass every one of a fixed set of automated checks; section 2 of the Terms of use sets out what the checks are and what happens to a draft that fails one. Others wait for the editor. Either way a published article can be corrected, updated or withdrawn afterwards, and you can ask us to look at one using the contact details below.

Reader correspondence, newsletter addresses and notification subscription records are never inputs to that workflow. Automatic publication decides whether an article about a subject goes out; it makes no decision about you as a reader, and we do not use the site to make solely automated decisions producing legal or similarly significant effects on readers.

4. Providers, disclosures and transfers

Hosting and email providers necessarily handle the requests or messages sent through their services. Video lists come from our Cloudflare-hosted feed. On the homepage and Reviews page the lists load automatically, along with approved thumbnail images from YouTube/Google. These requests send normal connection information, including your IP address, to the respective provider. Thumbnail requests omit the referring page. Playing an embedded video also connects to YouTube/Google, which may use its own storage or identifiers. Fonts are served with the site.

Cloudflare Turnstile protects the contact form, the newsletter signup and the buying guide assistant’s last step. When the check runs, your browser contacts Cloudflare and our server asks Cloudflare to verify the result, which sends Cloudflare your IP address and the token from the check. Firebase Authentication handles the single editor’s login. A model provider serves the editorial draft workflow. No provider delivers contact messages: they are stored here instead. Reader accounts are not planned.

Offers: following an offer link takes you to the partner’s own website with a referral parameter identifying Athenian Rider as the source, so a commission can be attributed to us. That request sends the partner the ordinary connection information any visit carries, and their privacy policy applies from that point. What comes back to us is totals and commission — we are not shown individual orders, and the partner does not tell us who you are or what you bought.

Access to private information must be limited to people and providers who need it for the stated purpose. Information may also need to be disclosed to meet a legal obligation or establish, exercise or defend a legal claim, with disclosure limited to what is necessary.

Some providers may process information outside the European Economic Area. The final provider list, processing locations, contracts and any required adequacy decision or other transfer safeguards must be verified and disclosed before the relevant planned service starts. This policy does not claim that all processing stays in the EU or that safeguards have already been verified.

5. How long information is kept

The ar_lang cookie lasts one year from the most recent visit to an explicit language URL or valid language selection. You can remove it earlier in your browser.

Correspondence should be kept only as long as needed to resolve the matter and reasonably handle follow-up, legal duties or a specific dispute. The reason, sensitivity and continuing need determine retention; unnecessary copies should be removed. Hosting, mailbox and backup retention periods are not yet verified for this build and must be documented before launch.

Notification records are removed or disabled when you unsubscribe or a subscription expires, with only limited records retained where needed to demonstrate a choice, prevent abuse or meet an obligation. A registration that is no longer active — turned off by you, reported gone by your browser’s push service, or refused by that service without ever having been accepted — is deleted ninety days later, with the record of the alerts sent to it. Editorial evidence may remain necessary to support published reporting, but immutable snapshots do not justify indefinite retention of unnecessary personal data.

Audience measurement uses different retention periods. Live presence rows become eligible for deletion after 30 minutes of inactivity or at the end of their UTC day, on a later request or scheduled cleanup. Its daily reader value and secret are deleted on the next request or scheduled cleanup after that UTC day ends; they are not used to recognise a reader on another day. Aggregate counts, including the assistant’s bounded choices and outcomes, contain no reader identity and are deleted after two years. The assistant’s separate access records and result snapshots follow the eight-day cleanup described in section 2.2, not the analytics midnight rule.

The assistant’s research records have no deletion date. They carry no reader identity and are not linked to each other or to a rider, so there is nothing for a clock to expire. You can still ask us to erase a particular submission using the route in section 2.2.

6. Your choices and rights

Depending on the processing and applicable law, you may request access, correction, erasure or restriction, object to processing based on legitimate interests, and exercise your right to data portability where the relevant conditions apply. These rights have limits, including relevant obligations and protections for journalism and freedom of expression; we will explain the grounds for a refusal.

You may withdraw consent for an optional service at any time, without affecting the lawfulness of earlier processing. The notification settings page, linked from the footer, lets you change the language of your alerts, reconnect a browser or stop them altogether; your browser’s own site permissions can also be changed and will override ours. Newsletter withdrawal has its own unsubscribe link. Cookie choices remain separate from both.

Use the email below and describe your request. Where identity needs verifying we will ask only for the information that is necessary to do it; do not send identity documents unless we ask you to provide them through an appropriate, secure channel. We normally respond within one month of receiving a rights request. Where the law allows an extension because of the complexity or number of requests, we will explain it within that month; the extension may be up to two further months.

You may complain to a competent data-protection authority, including the Hellenic Data Protection Authority or the authority in the EU country where you live, work or believe an infringement occurred. You may contact us first to seek a resolution; this does not remove your right to complain.

Hellenic Data Protection Authority: complaints ↗

7. Security, sensitive information and updates

Access controls, secure connections and proportionate operational safeguards are required for live services. No internet service can promise absolute security. Please avoid sending passwords, login details for financial accounts or unnecessary sensitive information about yourself or others. This site does not offer services directed specifically at children.

We will date policy revisions and explain material changes when appropriate. A new purpose or optional technology may require fresh information and consent; updating this page alone will not substitute for that process.