Privacy Policy
Last updated: 20 September 2026
1. Who we are
Sirens (sirens.hast.gr) is a media-monitoring portal for organisations invited by HÄST. It is operated by HÄST, based in Athens, Greece (“HÄST”, “we”, “us”). HÄST is the controller of the personal data described in this policy, under the EU General Data Protection Regulation (GDPR) and Greek law 4624/2019.
- Operator
- HÄST
- Address
- Christou Lada 1, Plateia Karytsi, Athens, Greece
- hi@hast.gr
- Phone
- (+30) 210 2022 531
2. Who this policy covers
- People who use Sirens: the users HÄST invites on behalf of a client organisation (“you”).
- People who appear in the media Sirens monitors, such as politicians and other public figures, journalists and presenters, and people who comment publicly on social media (see section 6).
3. Your account
To give you access, we process:
- your email address, and your name if you or your organisation give it to us;
- your organisation, your role (member or administrator) and the tools in your organisation’s plan;
- your password, stored only as a one-way hash, never in readable form;
- if your account uses two-factor sign-in, the secret that links it to your authenticator app;
- the date and time of your last sign-in;
- invitation codes, stored only as one-way hashes; a code works once and expires after 7 days.
This data comes from your organisation, when it asks HÄST to invite you, and from you. We use it to create and run your account, to give you the tools in your organisation’s plan, and to answer you when you contact us. The legal basis is the performance of the agreement for Sirens (GDPR art. 6(1)(b)) or, where the agreement is with your organisation rather than with you, our legitimate interest in providing the service your organisation asked for (art. 6(1)(f)).
4. Security records
When Sirens is used, our systems record technical information about each request: the IP address, the browser (user agent), the time, and the page or file requested. Failed sign-ins are counted per IP address, and after five failures that address is paused for 15 minutes.
We use these records to keep Sirens and your account secure, to prevent abuse, and to find and fix faults. The legal basis is our legitimate interest in the security of the service (GDPR art. 6(1)(f)).
6. The media Sirens monitors
Sirens analyses publicly available media:
- television broadcasts of Greek channels (Airtime and Media Radar);
- articles published on Greek local news websites (Regional Radar);
- public posts by news accounts on Instagram and TikTok, and the public comments on them (Social Radar).
This media contains personal data, mostly about politicians and other public figures acting in their public role: their names, the party they belong to, their statements, and when and where they appeared. Sirens reports counts, rankings, scores, summaries and short excerpts, with links or references to the original source.
Public comments on social media are analysed automatically to measure how audiences react. Sirens reports the results only in aggregate, such as the balance of positive and negative reactions, and does not build profiles of the people who wrote the comments.
Why, and on what legal basis
We process this data for the legitimate interest of HÄST and its clients in monitoring and analysing public media and public debate (GDPR art. 6(1)(f)), with regard to the freedom of expression and information (GDPR art. 85 and Greek law 4624/2019, art. 28). Where content reveals a person’s political opinions, such as a politician’s party, it concerns information that the person has manifestly made public (GDPR art. 9(2)(e)).
Automated analysis
Transcription, classification, sentiment and scoring are done by software, including machine-learning models. Some run on HÄST’s own equipment and some are provided by third parties acting on our instructions. No decision with legal or similarly significant effects on anyone is taken by automated means alone.
If you appear in media that Sirens monitors and want to ask about it or object, write to hi@hast.gr.
7. Who receives data
- HÄST staff who run and support Sirens, on a need-to-know basis.
- Service providers that process data for us, under data processing agreements and only on our instructions: application hosting and content delivery, databases and file storage, collection of public social media data, and machine-learning services used for the analysis.
- Public authorities, where the law requires it.
The users of your organisation see the same figures and reports. We do not sell personal data and do not use it for advertising.
8. Where data is kept
The Sirens application runs in the European Union, in Frankfurt, Germany, and we choose EU locations for storage where our providers offer them. Some providers are established outside the European Economic Area or may access data from there, for example for support or security. In those cases we rely on an adequacy decision of the European Commission, such as the EU–US Data Privacy Framework, or on the Commission’s Standard Contractual Clauses.
9. How long we keep data
- Account data: while your account is active, and after it is closed only for as long as we still need it — to finish and account for our work with your organisation, and to meet our legal obligations. Your organisation can ask us to delete it sooner (see “Your rights” below).
- Security records: only as long as we need them to keep Sirens secure, and longer only while we investigate a specific security incident.
- The session cookie: 12 hours, or until you sign out.
- Messages you send us: as long as needed to deal with them and to keep a record of our work for your organisation.
- Monitored media and the analyses built on it: as long as they are needed for the service, including comparisons over time, and reviewed regularly.
10. How we protect data
All connections to Sirens are encrypted (HTTPS). Passwords and invitation codes are stored only as one-way hashes. Every page and every request checks on our servers who you are and which tools your organisation has, so each client sees only its own account and the tools in its plan. Access to the systems behind Sirens is limited to the HÄST staff who need it.
11. Your rights
Under the GDPR you can ask us to:
- confirm whether we process your personal data, and give you a copy (access);
- correct data that is wrong or incomplete (rectification);
- delete your data (erasure), or limit how we use it (restriction);
- give you the data you provided in a portable format (portability), where this applies;
- stop processing based on our legitimate interests (objection).
Write to hi@hast.gr. We answer within one month, and may ask you to confirm your identity first. If you use Sirens through your organisation, we may deal with some requests together with it.
You can also complain to the Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Kifisias 1–3, 115 23 Athens, Greece, www.dpa.gr.
12. Children
Sirens is a service for organisations and their staff. It is not meant for children, and we do not knowingly give them accounts.
13. Changes to this policy
When this policy changes, we update this page and the date at the top. If a change affects you significantly, we tell you in Sirens or by email before it applies. The Terms of Use explain the rules for using Sirens.
14. Contact
For any question about this policy or your data:
- Operator
- HÄST
- Address
- Christou Lada 1, Plateia Karytsi, Athens, Greece
- hi@hast.gr
- Phone
- (+30) 210 2022 531