Legal

Privacy Policy

Last updated: 2 July 2026

This privacy policy explains how Perkit collects, uses and protects your personal data when you use the Perkit app and the Perkit card programme.

1.Who we are and how to reach us

1.1 This Privacy Policy explains how Ekinox S.A. ("Ekinox", "we", "us"), registered seat Arkadiou 2, 155 62 Cholargos, Attica, Greece, GEMI no. 192338001000 (AFM 803217731), collects, uses and protects your personal data when you use the Perkit app and the Perkit card programme. For these purposes Ekinox is the data controller.

1.2 You can contact us at support@perkit.gr. For questions about this policy or your personal data, or to exercise your rights, contact our data protection contact at privacy@perkit.gr or write to us at our registered seat marked "Data Protection".

1.3 Some parties involved in delivering the Service act as controllers in their own right for parts of the processing — in particular the card issuer (Stripe Technology Europe, Limited) for the regulated payment and anti-money-laundering processing, and your employer for the employment relationship and benefit decisions. Where this is the case, those parties' own privacy notices also apply.

2.Who this policy covers

This policy is for cardholders — employees and other beneficiaries who receive a Perkit card and use the App. Separate notices apply to employer administrators and to merchants. You receive Perkit because your employer (or another organisation) offers it to you as a benefit.

3.The personal data we collect

Depending on how you use the Service, we process the following categories of personal data:

CategoryExamples
Identity dataFull name, date of birth.
Contact dataEmail address and mobile number.
Employment / eligibility dataYour employer, your status as an eligible beneficiary, compensation and employment benefits, and which wallets and limits apply to you.
Account & card dataYour account identifiers, card identifiers (not the full card number), wallet balances and card status.
Transaction dataAmount, date, currency, merchant name and category, and authorisation outcome for each payment.
Device & app dataDevice type and operating system, app version, language, app settings, push-notification tokens, and security/authentication events (such as biometric login being enabled on your device).
Usage & diagnosticsIn-app activity, performance and crash diagnostics used to keep the App working and secure.
CommunicationsMessages you send us and records of support interactions.
Biometrics If you enable Face ID, fingerprint or similar login, the biometric data stays on your device and is handled by your device's operating system. We receive only confirmation that authentication succeeded — we do not collect or store your biometric data.
Children The Service is only for adults (18+). We do not knowingly process the data of anyone under 18.

4.How we collect your data

5.Why we use your data and our legal bases

We rely on the following legal bases under the EU General Data Protection Regulation (GDPR) and Greek data-protection law:

PurposeData usedLegal basis (GDPR)
Create and manage your account and card; deliver the ServiceContact, employment, account & card dataPerformance of a contract / steps at your request (Art. 6(1)(b)); our legitimate interest in administering the programme (Art. 6(1)(f))
Prevent money laundering, fraud and financial crimeTransaction, device dataLegal obligation (Art. 6(1)(c)); legitimate interests in preventing fraud (Art. 6(1)(f))
Process payments and apply wallet rules and limitsAccount, card and transaction dataPerformance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c))
Keep the Service secure and authenticate youDevice, usage, security/authentication dataLegitimate interests in security (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))
Provide customer supportContact, account and communications dataPerformance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f))
Improve and maintain the App (diagnostics, debugging)Device, usage and diagnostics dataLegitimate interests in maintaining a reliable App (Art. 6(1)(f))
Optional analytics and service communicationsDevice and usage data; contact dataYour consent where required (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f))
Comply with legal, tax, accounting and regulatory dutiesMost categories, as requiredLegal obligation (Art. 6(1)(c))
Establish, exercise or defend legal claimsAs relevant to the matterLegitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have balanced those interests against your rights. You can ask us for more information about that balancing. Where we rely on your consent, you can withdraw it at any time without affecting processing already carried out.

6.Automated checks and fraud monitoring

To keep the Service safe we use automated processes to authorise transactions, apply wallet and merchant-category rules, and detect possible fraud or misuse. These may result in a payment being declined or a card being temporarily blocked. These checks are necessary to perform the contract and to meet our legal obligations. If an automated decision significantly affects you, you have the right to ask for human review, to express your point of view and to contest the decision, as set out in Section 11.

7.Who we share your data with

We share personal data only as needed to run the Service and meet our obligations, with:

We require our processors to protect your data and to use it only as we instruct, under a written data-processing agreement.

8.International data transfers

Some of our partners and providers — including Stripe and certain technology providers — may process data outside the European Economic Area, for example in the United States. Where data is transferred outside the EEA, we rely on appropriate safeguards under the GDPR, such as an adequacy decision of the European Commission or the EU Standard Contractual Clauses, together with any additional measures needed to protect your data. You can ask us for a copy of the relevant safeguards using the contact details in Section 1.

9.How long we keep your data

We keep your data only as long as necessary for the purposes above and to meet our legal obligations. In particular, anti-money-laundering and identity-verification records, and transaction and accounting records, are kept for the periods required by Greek and EU law (typically several years after the end of the relationship — for AML records, generally five years, which may be extended where the law requires). After the applicable period we delete or anonymise your data.

10.How we protect your data

We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege access, strong authentication, monitoring and logging, secure software-development practices, and contractual controls over our providers. The handling of card numbers is performed within a PCI-DSS-compliant environment by the issuer and its processors. No system is completely secure, so we also rely on you to keep your credentials, PIN and device safe (see the Terms & Conditions).

11.Your rights

Subject to the conditions in the GDPR, you have the right to:

To exercise your rights, contact us at privacy@perkit.gr. We will respond within the time limits set by law (normally one month). Some rights are limited where we must keep data to meet legal obligations, such as anti-money-laundering record-keeping.

12.Cookies, SDKs and analytics in the App

The App uses software tools and SDKs that are necessary to deliver and secure the Service (for example, authentication, fraud-prevention, push notifications and crash diagnostics). Where we use optional analytics or non-essential tracking, we ask for your consent in line with applicable law, and you can change your choice in the App settings or your device settings.

13.Changes to this policy

We may update this policy from time to time. We will post the updated version in the App and at www.perkit.gr and, where changes are material, we will notify you by appropriate means. The "last updated" date shows when it last changed.

14.Complaints

If you have concerns about how we handle your data, please contact us first at privacy@perkit.gr so we can address them. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias Ave. 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, www.dpa.gr, or with the supervisory authority in your country of residence.