Legal
Privacy Policy
Last updated: 21 July 2026
1. Who we are
Mavromatis Institute | Mi ("the Institute," "we," "us") is a non-profit organization incorporated and established solely in Toronto, Ontario, Canada. The Institute also carries out ongoing activity in Thessaloniki-Macedonia, Greece (including the Thessaloniki Tango Party and related programs), but this does not constitute a formal legal establishment in Greece or the EU. We advance interdisciplinary research and education dedicated to human experience, cognition, culture, creativity, and embodied inquiry.
Because we have no formal EU establishment but direct activity toward EU/EEA residents (through our Greek operations and services offered to EU consumers), GDPR applies to us under Article 3(2), the "targeting" basis, rather than Article 3(1). The Institute is assessing whether it needs to designate an EU representative under GDPR Article 27.
For all privacy questions, requests, or complaints, contact us at the@mavromatisinstitute.org. We aim to respond within one month, as required under GDPR Article 12(3).
2. What personal data we collect
| Source | Data collected | Purpose |
|---|---|---|
| Contact form | Name, email address, enquiry type, message content | Responding to research collaboration, pilot partnership, speaking/workshop, and general enquiries |
| Email / newsletter signup | Email address | Sending updates on Institute research, MAP pilot results, events, and Parousia programs |
| Site analytics | Aggregated, privacy-focused analytics (page views, referrer, approximate location, device type). We do not use Google Analytics or any advertising-network tracking. | Understanding which content is useful, in aggregate; not used to build individual visitor profiles |
| Local device storage | Theme preference (light/dark), whether you've dismissed certain on-page prompts, and your cookie-consent choice. Stored only in your browser (localStorage/sessionStorage), never transmitted to us. | Remembering your display preference and consent choice, and avoiding repeat prompts within one visit |
| Archo / book purchases | Name, billing/delivery details, and payment confirmation (processed by our payment provider: we do not store full card numbers) | Fulfilling paid orders for the Archo product or the Busy Is a Lie series |
We do not knowingly collect government ID numbers or special-category data (health, biometric, religious, political, or similar) through this website. Note: the Thessaloniki Tango Party accepts donations and registrations via a separate third-party site (thessalonikitangoparty.com), not through mavromatisinstitute.org directly. See Section 5.
3. Legal basis for processing
Under GDPR Article 6, we rely on:
- Consent (Art. 6(1)(a)): for the newsletter/email signup and for non-essential analytics.
- Contract / pre-contractual steps (Art. 6(1)(b)): for contact-form enquiries about specific collaborations, bookings, or licensing, and for Archo/book purchases.
- Legitimate interest (Art. 6(1)(f)): for responding to general enquiries and for aggregated, non-profiling analytics.
Under Canadian law, PIPEDA (Personal Information Protection and Electronic Documents Act, SC 2000, c 5) applies to personal information we handle in connection with commercial activity: this covers Archo and book-series data specifically, and we apply the same standard to all personal data we hold rather than segregating by activity type. PIPEDA's ten fair-information principles (Schedule 1), namely accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance, govern how we handle your data regardless of where you're located.
For our email newsletter specifically, Canadian anti-spam law applies: CASL (Canada's Anti-Spam Legislation, SC 2010, c 23) requires express, opt-in consent before we send commercial electronic messages, not implied consent from browsing the site. Every newsletter email includes our name and mailing address plus a working unsubscribe link, honored within 10 business days, and functional for at least 60 days after send (CASL ss. 6โ9).
You may withdraw consent at any time (see Section 8) without affecting the lawfulness of processing carried out before withdrawal.
4. Cookies and local storage
This site does not set advertising or cross-site tracking cookies. It uses:
- Strictly necessary local storage: theme preference, dismissal of on-page prompts, and your consent choice. Exempt from consent requirements under the ePrivacy Directive (2002/58/EC) Art. 5(3), as implemented in Greece by Law 3471/2006, because these are essential to the site functioning as you'd expect.
- Analytics: see Section 2. Any analytics cookie or equivalent identifier is loaded only after you accept via the consent banner shown on your first visit, consistent with Greek Law 3471/2006 and Hellenic Data Protection Authority (HDPA) Recommendation 1/2020 on cookie compliance.
You can manage or withdraw analytics consent at any time using "Manage cookie preferences" in the site footer.
5. Who we share data with
- Service providers acting on our instructions: our email delivery/newsletter provider, our website/image hosting provider (ImageKit), our payment processor, and our analytics provider. Each processes data only as needed to provide their service to us.
- Collaborators named on this site (Pablito Greco, Tango Secrets, Music Galore, Schedule Success) do not receive your personal data through this website unless you contact them directly via their own linked sites, which have their own privacy practices.
- Thessaloniki Tango Party donations/registrations are processed entirely on thessalonikitangoparty.com, a third-party site outside our control. That transaction and any data you provide there is governed by that site's own privacy practices, not this policy.
- We do not sell personal data. We do not share it with advertisers.
- We may disclose data if required by law, court order, or to protect the rights, property, or safety of the Institute, our users, or the public.
6. International data transfers
Because the Institute operates in both Canada and Greece (EU/EEA), your data may be transferred between these jurisdictions and processed by service providers located elsewhere. Where we transfer personal data out of the EU/EEA, we rely on adequacy decisions or Standard Contractual Clauses as required under GDPR Articles 44โ49.
7. Consumer purchases (Archo, book series)
If you purchase Archo or a book from the Busy Is a Lie series as an EU/EEA consumer, EU consumer-protection law, specifically Directive 2011/83/EU as implemented in Greece via Law 2251/1994, gives you a 14-day right of withdrawal from most online purchases, along with mandatory pre-contract disclosures. If you purchase as an Ontario consumer and the price exceeds $50 CAD, Ontario's Consumer Protection Act, 2002 (SO 2002, c 30, Sch A, Part IV, "Internet Agreements") requires us to give you clear pre-contract disclosure (price, payment terms, delivery, cancellation rights) and to deliver a copy of the agreement within 15 days of your purchase; we do this via order-confirmation email. See our Terms & Conditions for full purchase terms.
8. Your rights
If GDPR applies to you (EU/EEA/UK residents), you have the right under GDPR Articles 12โ23 to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request erasure ("right to be forgotten")
- Restrict or object to processing
- Receive your data in a portable format
- Withdraw consent at any time
- Lodge a complaint with a data protection authority
As the Institute has no formal EU establishment (see Section 1), we do not have a single "lead" supervisory authority under GDPR's one-stop-shop mechanism. EU/EEA data subjects may lodge a complaint with the data protection authority of their own member state, or, given the Institute's ongoing activity in Greece, with the Hellenic Data Protection Authority (HDPA): Kifissias 1–3, 115 23 Athens, Greece; complaints: complaints@dpa.gr; phone +30 210 6475600. Note their online complaint portal is Greek-language.
Canadian residents have comparable rights under PIPEDA, including access to and correction of personal information, and may complain to the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca if unsatisfied with our response. We ask that you contact us first at the@mavromatisinstitute.org so we can try to resolve it directly.
9. Data retention
Contact-form enquiries are retained for as long as needed to address the enquiry and for a reasonable period afterward for record-keeping, then deleted or anonymized. Newsletter email addresses are retained until you unsubscribe or request deletion. Purchase records are retained as required for tax and accounting purposes under applicable Ontario and Greek law. Aggregated analytics data is retained in non-identifiable form.
10. Children's privacy
This site is not directed at children. Under GDPR, the minimum age for a child to consent to information-society services without parental consent is set by each member state (GDPR Art. 8): Greece sets this at 15 (Greek Law 4624/2019, Art. 21); other EU member states may set a different age between 13 and 16. We do not knowingly collect personal data from anyone below the applicable age without parental consent. If you believe a child has provided us with personal data, contact us and we will delete it.
11. Security
We take reasonable technical and organizational measures to protect personal data, including encrypted transmission (HTTPS) and restricted access to stored data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
12. Changes to this policy
We may update this policy as our practices change. Material changes will be reflected by an updated "Last updated" date above. Continued use of the site after changes take effect constitutes acceptance of the revised policy.
13. Contact
Mavromatis Institute | Mi
Incorporated in Toronto, Ontario, Canada · also active in Thessaloniki-Macedonia, Greece
Email: the@mavromatisinstitute.org
Sources
- Personal Information Protection and Electronic Documents Act, SC 2000, c 5 (PIPEDA)
- An Act to promote the efficiency and adaptability of the Canadian economy..., SC 2010, c 23 (CASL)
- Consumer Protection Act, 2002, SO 2002, c 30, Sch A
- Regulation (EU) 2016/679 (GDPR)
- Greek Law 4624/2019 (GDPR implementation, HDPA)
- Greek Law 3471/2006, as amended (ePrivacy)
- Greek Law 2251/1994 (consumer protection); Directive 2011/83/EU (Consumer Rights)