Privacy policy
What the PageSender app collects, why, who sees it, and what you can make us do about it.
Last updated: September 14, 2026
1. Who is responsible
PageSender is operated by INNOVIDEN OE (WEB DEVELOPMENT-INTERNET SERVICES), Zalokosta 8, Kolonaki, Athens, Greece ("we", "us"). You can reach us at support@pgsndr.com.
Two different relationships are covered by this policy, and the difference decides who answers to you:
- For your own account details - your name, your email address, your sessions, how you use the app - we are the data controller.
- For the business data you work with inside the app - your employer's customer contacts, the conversations with them, appointments, deals, posts - the business that engaged us, or the provider administering its account, is the controller. We are its processor and act on its instructions. If you want that data corrected or erased, they decide; we carry it out. We will point you to them rather than leave you without an answer.
2. What this covers
The PageSender mobile apps for iOS and Android, this website, and the support correspondence attached to them. It does not cover a provider's own website, contract or marketing, or a third-party service you connect to your account, each of which has its own policy.
3. What we collect
| Category | What it is | Why we have it | Legal basis |
|---|---|---|---|
| Account | Name, email address, phone number, role, the business you belong to | To identify you, sign you in and decide what you may see | Contract |
| Authentication | Password hash, session and refresh tokens, sign-in times, IP address and device model at sign-in | To keep the account yours and to detect attacks on it | Contract; legitimate interest in security |
| Business data | Contacts, conversations and messages, appointments, tasks, deals, social posts and campaign figures belonging to the business | Because showing you this is what the app is for | Processed for the business, on its instructions |
| Content you create | Messages, notes and posts you write, and images you choose to attach | To send, publish or store them as you asked | Contract |
| Assistant conversations | What you type to the in-app assistant and what it replies | To answer you, and to keep the thread readable afterwards | Contract |
| Technical | App version, operating system version, device model, language and time zone, and server-side error logs | To serve the right data, keep old builds from breaking, and fix faults | Legitimate interest in a working product |
| Support | What you send us and our replies | To help you, and to remember we did | Legitimate interest in supporting users |
4. What we do not collect
This list is as much a part of the policy as the one above, and it is precise rather than reassuring. The app contains no advertising identifier, no third-party analytics or attribution SDK, and no crash-reporting SDK. It does not ask for or read your location. It does not read the contact book on your phone - the contacts you see are your employer's customer records, held on the server. It does not record audio or use the camera. We do not sell personal data, we do not share it for cross-context behavioural advertising, and we do not profile you for advertising anywhere.
Permissions the app asks for
- Photo library - only at the moment you pick an image to attach to a post or message, and only the image you pick. Decline it and the rest of the app works.
5. Cookies and this website
This website sets no cookies, runs no analytics and embeds no third-party scripts. Our host records the usual server logs, including IP address, for a short period to keep the site up and turn away attacks.
6. Who else sees it
- The business you work for and the provider administering its account. They see the business data in the account, including what you do with it, as any employer sees work done on its systems.
- Infrastructure and service suppliers who host the servers, store files, deliver email and messages, process payments and provide the language models behind the assistant. They act on our instructions under a written contract, may use the data only to provide their service, and none of them is permitted to use it to train a general-purpose model.
- Services you or your business connect on purpose. When you publish a post or send a message, its content goes to the network or carrier you sent it to, and their terms then apply to it.
- Authorities, where we are legally required, and where we judge a demand to be valid. We tell you unless we are forbidden to.
- A buyer, if the business is sold, under this same policy until it is properly replaced.
We do not sell personal data to anyone.
7. Where it is held
Our servers are in the European Union. Some suppliers process data outside the European Economic Area, in which case the transfer rests on the European Commission's standard contractual clauses or an adequacy decision. Ask us and we will tell you which supplier handles what.
8. How long we keep it
- Account and business data - while the account is open. When it closes, deleted within 30 days, except where a line below says otherwise.
- Security and sign-in logs - up to 12 months.
- Support correspondence - up to 24 months.
- Invoices and accounting records - as long as Greek and EU tax law requires.
- Encrypted backups - rotated out within 90 days. Deleted records are never restored into service from them.
9. Security
Traffic is encrypted in transit. Passwords are stored hashed, never in a form we can read. On your phone, the token that keeps you signed in is held in the iOS keychain or the Android keystore, not in ordinary app storage. Access to production systems is limited to the people who need it and is logged. Accounts are separated so that one business cannot read another's data, and that separation is tested. No system is perfect; if a breach affects you, we will tell you and the Hellenic Data Protection Authority as the law requires.
10. Your rights
Under the GDPR you may ask us for a copy of your personal data, correct it, delete it, restrict or object to how we use it, take it elsewhere in a portable form, and withdraw any consent you gave. Exercising these rights costs nothing and we will not treat you differently for it.
Write to support@pgsndr.com. We answer within 30 days. If your request concerns your employer's business data, we pass it to them and tell you we have. To close your account, see deleting your account and data.
If you think we have handled your data badly, please tell us first - we would rather fix it. You may complain to the Hellenic Data Protection Authority (dpa.gr) or to the supervisory authority where you live.
11. Children
PageSender is a tool for work and is not directed at children. We do not knowingly hold data about anyone under 16. Tell us if we have, and it will be removed.
12. Changes
When this policy changes, the date at the top changes with it. If a change materially affects you, we will say so in the app or by email rather than rely on you noticing.
13. Contact
INNOVIDEN OE (WEB DEVELOPMENT-INTERNET SERVICES)
Zalokosta 8, Kolonaki, Athens, Greece
support@pgsndr.com