Privacy Policy

Last updated: 30 April 2026

This Privacy Policy explains what personal data bestdigitalbuyers.com (the “Site”, “we”, “us”) collects when you visit, why we collect it, how we use it, with whom we share it, and the rights you have under the EU General Data Protection Regulation 2016/679 (“GDPR”) and Greek law 4624/2019.

1. Data Controller

The data controller for this Site is Majdinel Hima, based in Greece. Privacy contact: contact page.

2. What we collect and why

We collect only the data we genuinely need to operate the Site, comply with the law, and improve user experience.

2.1 Visit / log data

What: IP address, browser type and version, operating system, referring URL, requested pages, timestamps, approximate country derived from IP.
Purpose: security, abuse prevention, debugging, aggregated statistics.
Legal basis: our legitimate interest (Art. 6(1)(f) GDPR) in keeping the Site secure and operational.
Retention: server access logs up to 30 days; security events up to 12 months.

2.2 Comments

What: name and email you submit with a comment, the comment text, IP address, and an anonymized hash sent to the Gravatar service to display your avatar (see Automattic’s policy at automattic.com/privacy).
Purpose: publish your comment, prevent spam.
Legal basis: your consent (Art. 6(1)(a)) and our legitimate interest in moderation.
Retention: for as long as the comment remains published, or until you request deletion.

2.3 Newsletter / contact form

What: email address (and any other information you choose to include in a contact message).
Purpose: respond to your enquiry, deliver the weekly buying digest if you subscribed.
Legal basis: your consent (Art. 6(1)(a)) for marketing emails; performance of pre-contractual measures or legitimate interest (Art. 6(1)(b)/(f)) for replying to direct enquiries.
Retention: until you unsubscribe or request deletion. Every newsletter contains a one-click unsubscribe link.

2.4 Analytics

If we use a web-analytics service (such as Google Analytics 4) we do so with IP-anonymisation and aggregate, non-identifying reports.
Legal basis: your consent via the cookie banner (Art. 6(1)(a)). You can revoke consent at any time.
Retention: typically 14 months, governed by the analytics provider.

2.5 Affiliate-link tracking

When you click an outbound affiliate link (e.g. to Amazon), the destination retailer may set its own cookies and read information about your visit to attribute commissions. We do not receive your name, email, or payment details from these clicks — only aggregated commission reports. The destination retailer’s privacy policy applies to that interaction.

2.6 Advertising (Google AdSense, when active)

If we display Google AdSense ads, Google and its partners may use cookies and similar identifiers to serve interest-based advertising and measure ad performance. You can manage your preferences via the EU consent framework presented in our cookie banner, and via Google’s Ads Settings at adssettings.google.com.
Legal basis: your consent (Art. 6(1)(a)).

2.7 Hosting and security infrastructure

The Site is hosted by Hostinger International Ltd. (Cyprus / Lithuania). The web-application firewall and security plugin (Wordfence) and the page-cache CDN (LiteSpeed / QUIC.cloud) process visit data on our behalf as data processors under Art. 28 GDPR. Their respective privacy notices govern the processing they perform.

3. Cookies and similar technologies

For full detail on the cookies used and how to manage them, see our Cookie Policy.

4. Recipients of your data

We do not sell your personal data. We share data only with the following categories of recipients, strictly to operate the Site:

  • Hosting and security providers (Hostinger, Wordfence, QUIC.cloud / LiteSpeed)
  • Email-delivery service for newsletter and contact replies
  • Analytics provider, if active (Google Analytics)
  • Advertising provider, if active (Google AdSense and its certified partners)
  • Affiliate networks for click attribution (Amazon Associates and similar)
  • Translation service, if you use a non-default language (TranslatePress with DeepL or Google Translate)
  • Public authorities, where legally required

5. International transfers

Some of our processors are located outside the European Economic Area (notably the United States). Where such transfers occur, we rely on the EU–US Data Privacy Framework, the European Commission’s Standard Contractual Clauses (Decision 2021/914), or other lawful safeguards under Chapter V GDPR.

6. Your rights

Under GDPR you have the right to:

  • Access — request a copy of the personal data we hold about you (Art. 15)
  • Rectification — correct inaccurate or incomplete data (Art. 16)
  • Erasure — ask us to delete your data, “right to be forgotten” (Art. 17)
  • Restriction — limit how we use your data (Art. 18)
  • Portability — receive your data in a machine-readable format (Art. 20)
  • Object — object to processing based on legitimate interest, including direct marketing (Art. 21)
  • Withdraw consent — at any time, without affecting processing already carried out
  • Lodge a complaint — with the Greek Data Protection Authority (Hellenic DPA), Kifissias 1-3, 11523 Athens, www.dpa.gr, or with the supervisory authority of your country of residence

To exercise any of these rights, contact us via the contact page. We respond within one month (extendable to three months for complex requests, with notice).

7. Children

The Site is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.

8. Automated decision-making

We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you (Art. 22 GDPR).

9. Security

We use industry-standard technical and organisational measures — including HTTPS/TLS, a web-application firewall, login-rate limiting, daily off-site backups, and least-privilege access — to protect personal data against accidental loss, unauthorised access, alteration, or disclosure. No internet transmission can be guaranteed 100% secure.

10. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be indicated by updating the “Last updated” date at the top of this page, and where appropriate by an in-Site notice. Continued use of the Site after such changes constitutes acceptance of the revised policy.

11. Contact

For privacy questions, requests under GDPR, or concerns about how your data is handled, contact us via the contact page.