Privacy Policy
1. Important Information and Who we are
C Business Advisors (registered name: KCCO C Business Advisors Limited, hereinafter the ‘Company’), is committed to protecting your privacy and making sure that any personal data it collects, are processed in accordance with the European General Data Protection Regulation 2016/679 (the ‘GDPR’), any other European Union legislation relating to personal data and the applicable Cyprus Data Protection Law No. 125(I)/2018 (as amended) as well as any secondary legislation, directives, and all other legislation and regulatory requirements in force from time to time applicable to the use of personal data (collectively the ‘Data Protection Law’).
This Privacy Policy gives you information about how the Company collects, uses, stores and/or otherwise processes personal data of clients, applicants for employment with the Company, suppliers or other service providers as well as website visitors.
References in this policy to “we”, “us” and “our” are references to the Company. References to “you” and “your” are to the individual/s who is/are providing personal data to us.
Our Company acts as its own data controller responsible for processing your personal information in relation to the provision of its Services, unless otherwise stipulated.
2. The types of personal data we collect about you
Personal data means any information about an individual from which that person can be identified.
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together as follows:
- Identity Data including first name, last name, any previous names, username or similar identifier, marital status, title, date of birth and gender.
- Contact Data including billing address, delivery address, email address and telephone numbers.
- Recruitment/Selection Data including academic qualifications, professional background and any other information contained in your CV, application form, record of interview or interview notes and/or any other assessment material.
- Technical Data including internet protocol (IP) address, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform, device ID and other technology on the devices you use to access this website.
- Financial Data including bank account and payment card details.
- Transaction Data including details about payments to and from you and other details of services you have engaged us for.
- Special Categories of personal data (sensitive data): in connection with the provision of services to you. We may on some occasions need to ask for certain sensitive information (e.g. information about your health etc). The processing of such sensitive data will only be carried out by us in full compliance with the GDPR and applicable national legislation.
3. How is your personal data collected?
We use different methods to collect data from and about you including through:
- Your interactions with us (for example when you contact us requesting the provision of services from us, when you make an enquiry via the website or by email, when you apply for employment);
- When you offer to provide or provide services or goods to us;
- From publicly available sources (for example the Registry of Companies);
- In certain cases, from third party sources (for example, we may collect personal data from your organisation, other organisations with whom you have dealings, to include banks and other professional service providers or other organisations in the context of the provision of our services to you or generally in the context of any other dealings we may have with you. In any case, such collection from third parties is always carried out in line with our legal obligations).
4. How we use your personal data
Pursuant to applicable Data Protection Law, we are required to have a legal basis for collecting and using your personal data. We rely on one or more of the following legal bases:
- Performance of a contract with you: where we need to perform the contract we are about to enter into or have entered into with you for the provision of services.
- Legitimate interests: We may use your personal data where it is necessary to conduct our business and pursue our legitimate interests, for example to prevent fraud and to enable us to give you the best and most secure customer experience, or to defend our legal rights. We make sure we consider and balance any potential impact on you and your rights (both positive and negative) before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law).
- Legal obligation: We may use your personal data where it is necessary for compliance with a legal obligation that we are subject to. We will identify the relevant legal obligation when we rely on this legal basis (for example for the purposes of complying with our obligations under applicable anti-money laundering laws).
- Consent: We rely on consent only where we have obtained your active agreement to use your personal data for a specified purpose, for example if you subscribe to an email newsletter.
The Company uses your personal data for the purposes for which you have supplied it to us, to include:
- For the purposes of responding to your requests and providing the services for which you engage us.
- For ensuring compliance with our legal obligations.
- For the purposes of complying with court orders and/or requests by official authorities where we are obliged to under law, and/or defending our legal rights where applicable.
- For the purposes of processing your application if you are a candidate for employment with the Company.
- For any purpose related and/or ancillary to any of the above or any other purpose for which your personal data were provided to us.
- Where you have provided us with your explicit prior consent, we may also use the information to provide you with newsletters, briefings and other publications about legal developments and matters which we believe may be of interest to you.
5. Personal data about other individuals which you provide to us
If you provide us with personal data about another individual, you must ensure that you are entitled to disclose such personal data to us and that you have provided the relevant data subjects of all mandatory data privacy notifications and information under the GDPR and applicable legislation and regulations, to include a notification as to their legal rights as data subjects. For that purpose, you must also ensure that the individual concerned is aware of the contents of the present Privacy Policy, as those matters relate to that individual, to include our identity, how to contact us, the purposes of collection of the data, how we may use and/or share the data and his/her relevant rights.
6. Disclosures of your personal data
We may share your personal data where necessary with the parties set out below for the purposes set out above:
- Affiliate companies of the Company for the purposes of providing the requested services.
- Third parties that we sub-contract in our efforts to provide the highest quality of services to our clients (for example information storage vendors or software developers).
- Where we are required to do so by law or where it is necessary for the purposes of, or in connection with, legal proceedings or in order to exercise or defend legal rights.
- Upon your instructions or your express consent.
- With any third party to whom we assign or novate any of our rights or obligations.
We require all third parties to respect the security of your Personal Data and to treat it in accordance with the law. We do not allow our third-party service providers to use your Personal Data for their own purposes and only permit them to process your Personal Data for specified purposes and in accordance with our instructions.
Any third parties that we may share your information with are located within the EU/EEA area and are obliged by written contract to keep your details confidentially and securely and to use them only to fulfil the service they provide on our behalf. When they no longer need your information to fulfil this service, they will dispose of the details in line with our policies/procedures.
7. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In cases where processing of personal data is carried out by third parties on our behalf, we require them to do the same.
In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have additionally put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
8. Data Retention
The Company will generally retain personal data for the period necessary to fulfil the purposes for which it was originally collected and thereafter as required or permitted by law or as is necessary in order for the Company to be able to defend, respond to or conduct prospective or actual legal claims or proceedings.
In light of the above general rule:
- Client data shall generally be retained for the duration of their business relationship with the Company and thereafter for a further period of 6 years.
- Personal data in the context of other contractual relations or dealings with you shall be retained for the duration of our contractual relationship or dealings and thereafter for a further period of 6 years.
9. Your Rights
You have a number of rights under Data Protection Law in relation to your personal data. Please note that some of these rights may not be applicable to your situation.
- You have the right to gain access to the personal data that we hold about you.
- You have the right of rectification, that is, to request the correction, without undue delay, of any personal data that we hold about you and are either inaccurate or incomplete.
- You have the right to obtain the erasure of your personal data, without undue delay, provided, amongst others, the personal data in question are no longer necessary in relation to the purposes for which they were collected.
- You have the right to restrict our processing activities or to object to the processing of your personal data.
- You have the right to data portability, that is, to request from us that we send your personal data in a structured, commonly used and machine-readable format, and to transmit those data to another controller.
- If we rely on your consent as our legal basis for the processing of your personal data, you have the right to withdraw that consent at any time.
If you wish to exercise any of your above-mentioned rights or have any questions or comments with regard to this Privacy Policy, you may contact:
Name: Alexandros Georgiades
Email address: ageorgiades@cbusinessadvisors.com or info@cbusinessadvisors.com
Telephone at number: 22777000
In addition to the above, you also have the right to lodge a complaint to the Office of the Commissioner for Personal Data Protection in Cyprus, at the following postal and email address:
15 Kypranoros, 1061 Nicosia
P.O.Box 23378, 1682 Nicosia
Tel: +357 22818456
Fax: +357 22304565
Email: commissioner@dataprotection.gov.cy
10. Changes to the Privacy Policy and your duty to inform us of any changes
We may amend or update this Privacy Policy from time to time. All amendments or updates will be posted on the Company’s website at: https://www.cbusinessadvisors.com/privacy-policy/ (the ‘Website’) and/or in our standard terms of business and/or in any other appropriate communication or document exchanged between us. We encourage you to periodically review our Privacy Policy to be informed of how we are committed to protecting personal data.
It is important that the personal data we hold about you is accurate and current. Please keep us informed if your personal data changes during your relationship with us, for example a new address or email address.