Privacy Policy
Last updated: 2 July 2026
This privacy policy explains how Perkit collects, uses and protects your personal data when you use the Perkit app and the Perkit card programme.
1.Who we are and how to reach us
1.1 This Privacy Policy explains how Ekinox S.A. ("Ekinox", "we", "us"), registered seat Arkadiou 2, 155 62 Cholargos, Attica, Greece, GEMI no. 192338001000 (AFM 803217731), collects, uses and protects your personal data when you use the Perkit app and the Perkit card programme. For these purposes Ekinox is the data controller.
1.2 You can contact us at support@perkit.gr. For questions about this policy or your personal data, or to exercise your rights, contact our data protection contact at privacy@perkit.gr or write to us at our registered seat marked "Data Protection".
1.3 Some parties involved in delivering the Service act as controllers in their own right for parts of the processing — in particular the card issuer (Stripe Technology Europe, Limited) for the regulated payment and anti-money-laundering processing, and your employer for the employment relationship and benefit decisions. Where this is the case, those parties' own privacy notices also apply.
2.Who this policy covers
This policy is for cardholders — employees and other beneficiaries who receive a Perkit card and use the App. Separate notices apply to employer administrators and to merchants. You receive Perkit because your employer (or another organisation) offers it to you as a benefit.
3.The personal data we collect
Depending on how you use the Service, we process the following categories of personal data:
| Category | Examples |
|---|---|
| Identity data | Full name, date of birth. |
| Contact data | Email address and mobile number. |
| Employment / eligibility data | Your employer, your status as an eligible beneficiary, compensation and employment benefits, and which wallets and limits apply to you. |
| Account & card data | Your account identifiers, card identifiers (not the full card number), wallet balances and card status. |
| Transaction data | Amount, date, currency, merchant name and category, and authorisation outcome for each payment. |
| Device & app data | Device type and operating system, app version, language, app settings, push-notification tokens, and security/authentication events (such as biometric login being enabled on your device). |
| Usage & diagnostics | In-app activity, performance and crash diagnostics used to keep the App working and secure. |
| Communications | Messages you send us and records of support interactions. |
4.How we collect your data
- From you — when you register, use the App and contact us.
- From your employer — your eligibility, contact details and the wallets and limits assigned to you.
- From your device and the App — device, usage and diagnostic data, in line with your device permissions.
- From our partners — the card issuer (Stripe), the Card Scheme, and from authorities or registries where required to verify information or meet legal obligations.
5.Why we use your data and our legal bases
We rely on the following legal bases under the EU General Data Protection Regulation (GDPR) and Greek data-protection law:
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Create and manage your account and card; deliver the Service | Contact, employment, account & card data | Performance of a contract / steps at your request (Art. 6(1)(b)); our legitimate interest in administering the programme (Art. 6(1)(f)) |
| Prevent money laundering, fraud and financial crime | Transaction, device data | Legal obligation (Art. 6(1)(c)); legitimate interests in preventing fraud (Art. 6(1)(f)) |
| Process payments and apply wallet rules and limits | Account, card and transaction data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Keep the Service secure and authenticate you | Device, usage, security/authentication data | Legitimate interests in security (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Provide customer support | Contact, account and communications data | Performance of a contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Improve and maintain the App (diagnostics, debugging) | Device, usage and diagnostics data | Legitimate interests in maintaining a reliable App (Art. 6(1)(f)) |
| Optional analytics and service communications | Device and usage data; contact data | Your consent where required (Art. 6(1)(a)); otherwise legitimate interests (Art. 6(1)(f)) |
| Comply with legal, tax, accounting and regulatory duties | Most categories, as required | Legal obligation (Art. 6(1)(c)) |
| Establish, exercise or defend legal claims | As relevant to the matter | Legitimate interests (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
Where we rely on legitimate interests, we have balanced those interests against your rights. You can ask us for more information about that balancing. Where we rely on your consent, you can withdraw it at any time without affecting processing already carried out.
6.Automated checks and fraud monitoring
To keep the Service safe we use automated processes to authorise transactions, apply wallet and merchant-category rules, and detect possible fraud or misuse. These may result in a payment being declined or a card being temporarily blocked. These checks are necessary to perform the contract and to meet our legal obligations. If an automated decision significantly affects you, you have the right to ask for human review, to express your point of view and to contest the decision, as set out in Section 11.
7.Who we share your data with
We share personal data only as needed to run the Service and meet our obligations, with:
- The card issuer — Stripe Technology Europe, Limited — to issue cards, hold funds, process payments and meet regulatory obligations.
- The Card Scheme — the international card payment network on which the Card is issued, to route and settle transactions across the payments network.
- Your employer — limited information needed to administer your benefit (for example, that a card is active and aggregate or programme-level usage). We do not share your individual purchase details with your employer beyond what is necessary and lawful.
- Service providers (processors) acting on our instructions — including cloud-hosting and infrastructure providers, card-production and fulfilment providers, communications/push-notification providers, and analytics and diagnostics providers.
- Authorities and registries — including tax, supervisory, law-enforcement and anti-money-laundering authorities, and Greek business registries (such as AADE / GEMI) where needed to meet legal duties.
- Professional advisers and potential successors — auditors and lawyers, and parties to a corporate transaction affecting the programme, under confidentiality.
We require our processors to protect your data and to use it only as we instruct, under a written data-processing agreement.
8.International data transfers
Some of our partners and providers — including Stripe and certain technology providers — may process data outside the European Economic Area, for example in the United States. Where data is transferred outside the EEA, we rely on appropriate safeguards under the GDPR, such as an adequacy decision of the European Commission or the EU Standard Contractual Clauses, together with any additional measures needed to protect your data. You can ask us for a copy of the relevant safeguards using the contact details in Section 1.
9.How long we keep your data
We keep your data only as long as necessary for the purposes above and to meet our legal obligations. In particular, anti-money-laundering and identity-verification records, and transaction and accounting records, are kept for the periods required by Greek and EU law (typically several years after the end of the relationship — for AML records, generally five years, which may be extended where the law requires). After the applicable period we delete or anonymise your data.
10.How we protect your data
We use technical and organisational measures appropriate to the risk, including encryption in transit, access controls and least-privilege access, strong authentication, monitoring and logging, secure software-development practices, and contractual controls over our providers. The handling of card numbers is performed within a PCI-DSS-compliant environment by the issuer and its processors. No system is completely secure, so we also rely on you to keep your credentials, PIN and device safe (see the Terms & Conditions).
11.Your rights
Subject to the conditions in the GDPR, you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate or incomplete data corrected;
- have your data erased in certain circumstances;
- restrict or object to certain processing, including processing based on legitimate interests;
- receive certain data in a portable, machine-readable format and have it transmitted to another controller;
- withdraw consent at any time where we rely on it; and
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, and to obtain human intervention (see Section 6).
To exercise your rights, contact us at privacy@perkit.gr. We will respond within the time limits set by law (normally one month). Some rights are limited where we must keep data to meet legal obligations, such as anti-money-laundering record-keeping.
12.Cookies, SDKs and analytics in the App
The App uses software tools and SDKs that are necessary to deliver and secure the Service (for example, authentication, fraud-prevention, push notifications and crash diagnostics). Where we use optional analytics or non-essential tracking, we ask for your consent in line with applicable law, and you can change your choice in the App settings or your device settings.
13.Changes to this policy
We may update this policy from time to time. We will post the updated version in the App and at www.perkit.gr and, where changes are material, we will notify you by appropriate means. The "last updated" date shows when it last changed.
14.Complaints
If you have concerns about how we handle your data, please contact us first at privacy@perkit.gr so we can address them. You also have the right to lodge a complaint with the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias Ave. 1-3, 115 23 Athens, Greece, tel. +30 210 6475600, www.dpa.gr, or with the supervisory authority in your country of residence.