This Privacy Notice explains how MK Compliance Limited (a company incorporated in the Republic of Cyprus, with registered number HE 455482) and all its affiliates collect, use and disclose your personal data, and your rights in relation to the personal data as these are held. Keeping your data secure and private is part of our philosophy for delivering high standards of services.
In this Privacy Notice, “us’, “we’, “our” is the data controller of your personal data and is subject to the EU General Data Protection Regulation 2016/679 (“GDPR”) and any locally applicable data protection laws.
We also have established offices (including our affiliated entities) in Greece, Malta, Israel, Poland, Ukraine, the United Kingdom, Germany and Dubai (UAE). This Notice applies to the processing of personal data for all entities.
How we collect your data
We collect your personal data in the manner described below:
Data we collect
We collect the following categories of personal data about you:
Processing your personal data
1. Performance of a contract with you
We process your personal data because it is necessary for the performance of a services provision agreement to which you are a party or in order to take steps at your request prior to entering into such agreement.
In this respect, we use your personal data for the following:
In this respect, we may share your personal data with or transfer it to the following:
The courts of the Republic of Cyprus and/or any other public authorities of the Republic of Cyprus, or where requested, either by Law or in the court of providing our services to you.
2. Legitimate interests
We also process your personal data because it is necessary for our legitimate interests, or sometimes where it is necessary for the legitimate interests of another person.
In this respect, we use your personal data for the following:
In this respect we will share your personal data with the following:
3. Consent
We may rely on your freely given consent at the time you provided your personal data to us for a purpose of the process other than for the purposes set out hereinabove, then the lawfulness of such processing is based on that consent. You have the right to withdraw consent at any time. However, any processing of personal data will not be affected prior to the receipt of the withdrawal.
4. Compliance with legal obligations
We also process your personal data for our compliance with a legal obligation which we are under.
In this respect, we will use your personal data for the following:
In this respect, we will share your personal data with the following:
Marketing
We will send you marketing about services we provide which may be of interest to you, as well as other information in the form of alerts, newsletters and invitations to events or functions which we believe might be of interest to you or in order to update you with information (such as legal or commercial news) which we believe may be relevant to you.
Your data is not shared outside of MK Compliance Limited.
We will communicate this to you in a number of ways including by post, telephone, email or other digital channels.
If you object to receiving marketing from us at any time, please contact us by email: dpocyprus@kyprianou.com
If you have given consent and you wish to withdraw it at any time, please contact us on the above e-mail.
Transfer and processing of your personal data outside the European Union
When sharing your personal data with third parties as set out in this Privacy Notice, it may be transferred outside the European Union. Such third parties have access to personal data solely for the purpose of performing the services specified in the applicable service agreement, and not for any other purpose. In these circumstances, your personal data will only be transferred on one of the following bases:
Retention of your data
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for and where we have a lawful reason to do so. In particular:
Your contact information and personal data are stored securely, using a mixture of encryption, password protection, and servers/back-ups all kept with multiple lock protection.
We have put in place appropriate technical and organisational measures including physical, electronic and procedural measures to protect personal data from loss, misuse, alteration or destruction. We restrict access to information at our offices so that only officers and/or employees who need to know the information have access to it. Those individuals who have access to the data are required to maintain the confidentiality of such information. Please be aware that users should also take care with how they handle and disclose their personal data and should avoid sending personal data through insecure email.
Security of Processing:
We take the security of your personal data seriously and have implemented appropriate technical and organizational measures to protect it from unauthorized access, loss, misuse, alteration, or disclosure.
We also have in place procedures so we can address any suspected personal data breach incident and we will notify you and the relevant supervisory authority where we are required by law to do so.
Processing Data as Controller for Agents and Intermediaries
You, in a capacity of an agent or intermediary, will bring the attention of any individuals that you make our services available to any privacy notices or policies we make available for those services.
You confirm that any personal data of any individual provided to us by you or on your behalf has been collected and disclosed in accordance with the applicable Data Protection legislation. When using our services, you will take reasonable steps to ensure that you and your employees, agents and contractors do not input, upload or disclose to us any irrelevant or unnecessary information about individuals.
You will maintain appropriate physical, technical and organisational measurers to protect personal data against accidental, unauthorised or unlawful destruction, loss, alteration, disclosure or access.
You will without delay, tell us of any actual or suspected data breach relating to personal data that may impact us or the individuals.
Your rights under GDPR
Under the GDPR you have the following rights:
Please note that the above rights are not absolute, and we may be entitled to refuse requests where exceptions apply.
Data Protection Officer
We have designated a Data Protection Officer (“DPO”), who is responsible to monitor compliance with this Privacy Notice as well as the applicable Laws and liaise with the relevant authorities.
The DPO may be contacted directly with regards to all matters concerning this notice and the processing of your personal data including the enforcement of all applicable and available rights.
Official requests may be made electronically at: dpocyprus@kyprianou.com
The Right to Complaint:
If you have any concerns regarding the processing of your personal data, or our compliance with the GDPR and relevant data protection legislation, you should contact the Data Protection Officer at dpocyprus@kyprianou.com.
You also have the right to lodge a complaint with the relevant supervisory authority.
For any complaints you may have for Cyprus you may contact the Data Commissioner of the Republic of Cyprus at:
http://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/home_en/home_en?opendocument