Skip to content
Services
  • Penetration testingApplications, networks and cloud
  • Red teaming & adversary simulationObjective-led attack simulation
MorpheusAbout usOur VisionResearchTalk with an expert
Talk with an expert

Privacy Policy

CENOBE SA

Legal documents

  • Privacy Policy
  • Cookies Policy
  • Website Terms
  • Terms of Service
  • Acceptable Use Policy
  • DPA
  • Morpheus Terms

1. INTRODUCTION

CENOBE SA ("CENOBE", "we", "us" or "our"), a company incorporated under Greek law, with registered seat at Karneadou 25-29, 10675 Athens, Greece, VAT EL801188366 ("CENOBE"), is committed to protecting your personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 ("GDPR"), Greek Law 4624/2019 and any other applicable data protection legislation.

This Privacy Policy explains what personal data we collect about you, why we collect it, how we use it, how long we keep it, and what rights you have in relation to it. It applies to personal data collected through our website, our services and our products, including the Morpheus cybersecurity platform.

This Privacy Policy applies only when CENOBE acts as a data controller. Where CENOBE acts as a data processor on behalf of our clients - including in the course of providing penetration testing or cybersecurity services - the processing of personal data is governed by the applicable Data Processing Agreement ("DPA") concluded between CENOBE and the relevant client. Please refer to Section 4 for further details on the distinction between our roles.

2. DATA CONTROLLER - CONTACT DETAILS

Details Information
Data Controller CENOBE SA
Registered address Karneadou 25-29, 10675 Athens, Greece
VAT number EL801188366
Email info@cenobe.com
Phone +30 211 333 7149
Data Protection Officer (DPO) dpo@cenobe.com

For any questions or concerns regarding this Privacy Policy or the processing of your personal data, please contact us at the above details or at info@cenobe.com.

3. PERSONAL DATA WE COLLECT

Depending on your relationship with CENOBE, we may collect the following categories of personal data:

3.1 Data you provide directly

  • Identity data: name, surname, job title, organisation name
  • Contact data: email address, phone number, postal address
  • Account data: username, password (stored in hashed form), account preferences
  • Billing and payment data: invoicing details, bank account information
  • Communications data: content of emails, support requests or other correspondence with us

3.2 Data collected automatically

  • Technical data: IP address, browser type and version, operating system, device identifiers
  • Usage data: pages visited, time spent on our website, links clicked, referral source
  • Log data: timestamps, access logs, system configuration data
  • Cookie data: as described in our Cookies Policy, available at www.cenobe.com

3.3 Data collected in the course of providing our services

Where you use the Morpheus platform or engage CENOBE for penetration testing or other cybersecurity services, CENOBE may incidentally access personal data residing in your systems in the course of performing those services. Such access is not intentional and is a consequence of the services being performed on live systems. This processing is governed by the DPA concluded between you and CENOBE and not by this Privacy Policy. Please refer to Section 4 below.

4. CENOBE AS DATA CONTROLLER AND DATA PROCESSOR

CENOBE acts in different roles depending on the context of the processing:

CENOBE's role When it applies
Data Controller When processing personal data of website visitors, registered account users, contacts and marketing recipients for CENOBE's own purposes as described in Section 5 of this Policy.
Data Processor When processing personal data on behalf of a client in the course of providing cybersecurity services - including penetration testing, attack surface management, breach and attack simulation and the Morpheus platform. In this case, processing is governed exclusively by the DPA concluded between CENOBE and the relevant client, available at https://cenobe.com/dpa.

This Privacy Policy applies exclusively to processing activities where CENOBE acts as a data controller. If you are a client of CENOBE and wish to understand how your data is processed in the context of the services, please refer to the applicable DPA.

5. PURPOSES, LEGAL BASIS AND RETENTION PERIODS

The table below sets out, for each processing activity where CENOBE acts as data controller, the purpose of processing, the categories of data involved, the legal basis under Article 6 GDPR and the applicable retention period.

Purpose Categories of data Legal basis Retention period
Account registration and management
Creating and managing user accounts, providing access to our services and platform.
Name, email, username, password (hashed), account preferences Article 6(1)(b) GDPR - performance of contract For the duration of the active account + 3 years after account closure, unless a longer period is required by law
Provision of services
Providing, maintaining and improving our cybersecurity services and the Morpheus platform.
Name, contact details, IP address, usage data, log data, system configuration data Article 6(1)(b) GDPR - performance of contract For the duration of the contract + 5 years after termination
Billing and payment
Issuing invoices, processing payments and managing financial records.
Name, company name, billing address, bank/payment details Article 6(1)(b) GDPR - performance of contract
Article 6(1)(c) GDPR - legal obligation (accounting legislation)
5 years from the end of the relevant financial year
Customer support
Responding to queries, complaints and support requests.
Name, contact details, content of communications Article 6(1)(b) GDPR - performance of contract
Article 6(1)(f) GDPR - legitimate interest (providing support and maintaining customer relations)
2 years from closure of the support request, unless the matter gives rise to a legal claim
Security and fraud prevention
Monitoring use of our platform and services to detect misuse, fraud or security incidents.
IP address, log data, usage data, account data Article 6(1)(f) GDPR - legitimate interest (security of our systems and services) 12 months from collection, unless a security incident requires longer retention for investigation or legal purposes
Website analytics
Understanding how visitors use our website in order to improve it.
Browser and device information, pages visited, time spent, referral source Article 6(1)(a) GDPR - consent 13 months from collection (anonymised aggregated data retained indefinitely)
Direct marketing
Sending promotional communications, event invitations and service updates to existing clients and contacts.
Name, email address, job title, organisation name, communication preferences Article 6(1)(f) GDPR - legitimate interest (maintaining client relations and promoting our services) for existing clients
Article 6(1)(a) GDPR - consent for individuals not in a commercial relationship with CENOBE
Until the recipient opts out or withdraws consent.
Legal claims
Establishing, exercising or defending legal claims.
All categories of data relevant to the claim Article 6(1)(f) GDPR - legitimate interest (protecting CENOBE's legal rights) For the duration of the applicable limitation period under Greek law
Compliance with legal obligations
Complying with applicable laws, regulations and orders from competent authorities.
All categories of data required by the relevant legal obligation Article 6(1)(c) GDPR - legal obligation As required by the applicable legal obligation

6. SPECIAL CATEGORIES OF PERSONAL DATA

CENOBE does not intentionally collect or process special categories of personal data (as defined under Article 9 GDPR, including health data, biometric data, data revealing racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal records) in the course of its own business activities.

In the context of providing cybersecurity services (penetration testing, Morpheus platform), CENOBE may incidentally access special categories of personal data residing in client systems during the performance of security tests. Such access is governed by the DPA and the Responsible Disclosure Procedure described therein, and not by this Privacy Policy. The client bears responsibility for notifying CENOBE prior to the commencement of testing where special categories of data are present.

7. COOKIES

CENOBE uses optional Google Analytics cookies on its website only after the visitor gives consent. Google Analytics remains disabled until that choice is made. Visitors can withdraw consent at any time through the “Cookie settings” control in the website footer.

For detailed information on the cookies we use, their purpose, legal basis and how to manage your preferences, please refer to our Cookies Policy, available at www.cenobe.com

8. DATA SHARING AND DISCLOSURE

CENOBE does not sell personal data to third parties. We may share personal data with the following categories of recipients, strictly to the extent necessary and on the basis of appropriate safeguards:

Recipient Basis and purpose
IT and infrastructure service providers
(e.g. cloud hosting, email, security monitoring)
Contractual necessity - processing on CENOBE's instructions under data processing agreements. Providers located in the EU/EEA only, or subject to appropriate safeguards under Article 46 GDPR.
Website analytics provider
(Google Analytics)
Consent - Google processes website usage and device data on CENOBE's behalf to provide audience measurement after the visitor opts in. Google Analytics is governed by Google's applicable data processing terms and privacy safeguards.
Payment service providers Contractual necessity - processing payment transactions. Subject to their own privacy policies and PCI DSS compliance.
Professional advisers
(lawyers, accountants, auditors)
Legitimate interest / legal obligation - subject to strict confidentiality obligations.
Competent authorities
(courts, regulators, tax authorities, law enforcement)
Legal obligation - where required by applicable law or court order.
CENOBE group companies and affiliates Legitimate interest / contractual necessity - for internal administrative and operational purposes, subject to intragroup data sharing agreements.
Prospective buyers or investors Legitimate interest - in connection with a merger, acquisition or sale of assets, subject to appropriate confidentiality obligations.

9. INTERNATIONAL TRANSFERS

CENOBE primarily processes personal data within the European Union / European Economic Area (EU/EEA). Google Analytics data may be processed by Google Ireland Limited and its affiliates or subprocessors in countries outside the EU/EEA. Where a transfer is not covered by an adequacy decision, CENOBE relies on Google's applicable data processing terms and the European Commission's Standard Contractual Clauses, together with any supplementary safeguards required by law. For other transfers outside the EU/EEA, CENOBE ensures that appropriate safeguards are in place in accordance with Chapter V GDPR, including:

  • Transfers to countries that have received an adequacy decision from the European Commission under Article 45 GDPR;
  • Transfers subject to Standard Contractual Clauses (SCCs) adopted by the European Commission under Article 46(2)(c) GDPR;
  • Other appropriate safeguards as permitted under Article 46 GDPR.

10. INFORMATION SECURITY

CENOBE implements appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction or alteration, in accordance with Article 32 GDPR and CENOBE's ISO/IEC 27001 certification.

Such measures include, without limitation: encryption of data in transit and at rest using industry-standard protocols, access controls based on the principle of least privilege, multi-factor authentication, regular security assessments and staff training.

However, no method of transmission over the internet or method of electronic storage is completely secure. While we strive to protect your personal data, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you in accordance with Article 34 GDPR without undue delay.

11. YOUR RIGHTS AS A DATA SUBJECT

Under the GDPR, you have the following rights in relation to the personal data we hold about you. These rights are not absolute and are subject to certain conditions and limitations under applicable law.

Right Description
Right of access
(Article 15 GDPR)
You have the right to obtain confirmation as to whether we process personal data about you and, if so, to receive a copy of that data and information about how it is processed.
Right to rectification
(Article 16 GDPR)
You have the right to obtain rectification of inaccurate personal data and completion of incomplete personal data without undue delay.
Right to erasure
(Article 17 GDPR)
You have the right to request the deletion of your personal data in certain circumstances — for example, where the data is no longer necessary for the purposes for which it was collected, or where you withdraw your consent and there is no other legal basis for processing. This right is not unconditional.
Right to restriction of processing
(Article 18 GDPR)
You have the right to request that we restrict the processing of your personal data in certain circumstances — for example, where you contest the accuracy of the data or where the processing is unlawful.
Right to data portability
(Article 20 GDPR)
Where processing is based on your consent or on the performance of a contract, you have the right to receive your personal data in a structured, commonly used and machine-readable format and to have it transmitted directly to another controller where technically feasible.
Right to object
(Article 21 GDPR)
You have the right to object to processing based on legitimate interests (Article 6(1)(f) GDPR), including profiling, and to processing for direct marketing purposes. Where you object to direct marketing, we will cease such processing immediately.
Right to withdraw consent
(Article 7(3) GDPR)
Where processing is based on your consent, you have the right to withdraw your consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal.
Right to lodge a complaint
(Article 77 GDPR)
You have the right to lodge a complaint with the Greek competent supervisory authority:
Hellenic Data Protection Authority (HDPA)
Kifissias 1-3, 115 23 Athens
Tel: +30 210 6475600
Email: contact@dpa.gr
Website: www.dpa.gr

To exercise any of the above rights, please contact us at dpo@cenobe.com. We will respond to your request within one (1) month of receipt. This period may be extended by a further two (2) months where necessary, taking into account the complexity and number of requests, in which case we will notify you within one month of receipt of the request.

We may ask you to verify your identity before responding to your request in order to ensure the security of your personal data.

12. CHANGES TO THIS PRIVACY POLICY

CENOBE may update this Privacy Policy from time to time to reflect changes in our processing activities, legal requirements or for other operational reasons. The updated version will be posted on our website with the date of the last update.

Where changes are material - in particular where they relate to the purposes of processing, the legal basis, the categories of data collected or the exercise of your rights - we will notify you by email or through a prominent notice on our website at least thirty (30) days before the changes take effect, and we will seek your consent where required by applicable law.

If you have any questions, concerns or requests regarding this Privacy Policy or the processing of your personal data, please contact us at info@cenobe.com.

Last updated: 5 August 2026

Offensive security for a more resilient tomorrow.

Services

  • Penetration Testing
  • Red teaming & adversary simulation

Platform

  • Morpheus

Company

  • About Us
  • Our Vision
  • Research

Legal

  • Privacy Policy
  • Cookies Policy
  • Website Terms
  • Terms of Service
  • Acceptable Use Policy
  • DPA
  • Morpheus Terms

Email

info@cenobe.com

Phone

+30 210 722 0648

Primary Office

25 Karneadou
106 75 Attiki
Athens, Greece

Marousi Office

Leof. Kifisias 66
151 25 Marousi
Athens, Greece

© 2026 Cenobe

Choose whether we measure visits

We use optional Google Analytics cookies to understand how the site is used. Nothing is sent to Google unless you allow analytics. You can change this choice at any time inour Cookies Policy.