Privacy Policy – Merokam
Version: 2.0 • Effective date: June 7, 2026
This Privacy Policy explains how Merokam (the "Platform") collects, uses, stores and discloses personal data, in accordance with the General Data Protection Regulation (GDPR – EU Regulation 2016/679) and applicable Greek legislation.
1. Identity of the Data Controller
The Data Controller is the company that operates the merokam.gr platform. For any matter concerning your personal data, contact us:
- Email: [email protected]
- Subject: "GDPR – Request"
2. Who this applies to
The Platform is intended exclusively for adults (≥18 years old) in the following roles:
- Workers – looking for agricultural jobs
- Employers – post listings and look for staff
- Merchants – manage stores on the Marketplace
- Agronomists – provide consulting services
3. Data we collect
3.1 Registration & account data
- Full name, email, phone number
- Account type (worker / employer / merchant / agronomist)
- Region / location (text)
- Registration date, last login
3.2 Profile data
- Worker: profile photo (stored encrypted in private storage), geographic coordinates (latitude/longitude) for proximity alerts, availability, application history
- Employer: company name, business type, rating, main region
- Merchant: company name, contact email, Stripe Connect details
- Agronomist: professional profile, contact details
3.3 Transaction & payment data
- Job listings: title, description, location, dates, working conditions, Stripe checkout session
- Worker subscriptions: Stripe Customer ID, Stripe Subscription ID, payment status, dates
- Marketplace: product listings, orders, merchant Stripe Connect details, Stripe Payment Intent
- Invoices / receipts issued through the Platform
Merokam does not store card numbers or full payment details. Transactions are processed exclusively through Stripe. Stripe Privacy Policy: stripe.com/privacy
3.4 Geolocation data (workers)
If a worker voluntarily provides their coordinates (via the browser or manually), these are stored to send proximity job alerts. The worker can delete their geographic data at any time from their profile.
3.5 Automatic / technical data
- IP address, browser, operating system, language
- Server and application log files
- Functional cookies, analytics (with consent), marketing (with consent)
3.6 Communications & user content
- Chatbot messages (stored temporarily for service improvement)
- User reviews / ratings
- Reports of policy-violating behavior
- Role change requests (role switch)
4. Legal basis & purpose of processing
| Purpose | Legal basis (GDPR) |
|---|---|
| Account creation & management | Performance of contract (Art. 6(1)(b)) |
| Posting listings, applications, marketplace | Performance of contract (Art. 6(1)(b)) |
| Payment processing (Stripe) | Performance of contract (Art. 6(1)(b)) |
| Proximity notifications (geolocation) | Consent (Art. 6(1)(a)) |
| Analytics & service improvement | Legitimate interest / Consent (Art. 6(1)(f) / (1)(a)) |
| Marketing, newsletters | Consent (Art. 6(1)(a)) |
| Security, fraud prevention, blacklisting | Legitimate interest (Art. 6(1)(f)) |
| Compliance with legal obligations (tax, etc.) | Legal obligation (Art. 6(1)(c)) |
5. Data retention period
- Active account: retained for the entire duration of use + 24 months of inactivity
- Job listings: publication duration + 24 months (for tax reasons)
- Transaction data (Stripe, invoices): 10 years (tax legislation)
- Geographic coordinates: until deleted by the user or account deletion
- Server logs: up to 12 months
- Marketing / newsletters: until consent is withdrawn
- Minor's data (if identified): immediate deletion
6. Recipients & data disclosure
We do not sell your data. We only disclose it in the following contexts:
- Data processors: hosting providers (AWS S3), email/SMS (e.g. Mailgun), analytics (e.g. Google Analytics – with consent)
- Stripe Inc.: for payment processing and subscription management. stripe.com/privacy
- Other users: worker details (without phone number) are disclosed to an employer only after an application is accepted. Merchant details are disclosed to a buyer after an order is completed.
- Authorities / courts: where required by law or court order
- Business transfer: in the event of an acquisition or merger, with notice to you
7. International transfers
Some of our providers (e.g. AWS, Stripe, Google) are based or process data outside the EEA. These transfers are safeguarded through Standard Contractual Clauses (SCCs) or equivalent mechanisms in accordance with Art. 46-49 GDPR.
8. Data security
- Encryption in transit (HTTPS/TLS) and at rest (AES-256 for S3 files)
- Profile photos are stored in private storage with signed URLs
- Passwords are stored hashed (PBKDF2)
- Access control: each user sees only their own data
- Regular software and security updates
- In the event of a breach: notification to the Hellenic Data Protection Authority within 72 hours and notification to users where required (Art. 33-34 GDPR)
9. Cookies & tracking technologies
| Category | Purpose | Basis |
|---|---|---|
| Necessary | Login, session, CSRF | Legitimate interest |
| Analytics | Traffic measurement | Consent |
| Marketing | Targeted advertising | Consent |
You can manage or withdraw your consent for cookies via the cookie banner shown on your first visit or from your browser settings.
10. Your rights (GDPR)
You have the following rights regarding your personal data:
- Access (Art. 15): to know what data we hold about you
- Rectification (Art. 16): to correct inaccurate or incomplete data
- Erasure (Art. 17): to request deletion of your account and data, unless there is a legal obligation to retain them
- Restriction of processing (Art. 18): under certain conditions
- Portability (Art. 20): receiving your data in JSON/CSV format
- Objection (Art. 21): objecting to processing based on legitimate interest or for marketing
- Withdrawal of consent: without retroactive effect, at any time
- Complaint: to the Hellenic Data Protection Authority (HDPA) — www.dpa.gr
To exercise a right: [email protected] — Subject: "GDPR – Request". We respond within 30 days.
11. Automated decision-making
We do not make decisions that have legal or similarly significant effects on you based solely on automated processing or profiling. The proximity alerts system is based on geographic filtering without human decision-making to the detriment of the user.
12. Minors
The Platform is not intended for minors under 18 years old. If we become aware that we have collected a minor's data, we will delete it immediately and deactivate the account.
13. Third-party links & integrations
The Platform may include third-party links or integrations (e.g. maps, Google fonts, social media scripts). These services operate under their own privacy policies, for which we are not responsible.
14. Changes to the Policy
We may update this Policy. The updated version is always published at merokam.gr/privacy-policy/ with its effective date. For material changes, we will notify you by email or platform notification at least 15 days before they take effect.
15. Contact
For any question or request regarding this Policy:
- Email: [email protected]
- Subject: "GDPR – Request"