Privacy Policy

Introduction

The management of A. EPIPHANIOU INDUSTRIES LTD (hereinafter referred to as the "Company", "we", "us", or "our") places great importance on protecting your personal data and respecting your privacy whenever we collect and process information relating to you. We are committed to ensuring that this Privacy Policy (the "Policy") complies fully with the provisions of the General Data Protection Regulation (EU) 2016/679 (GDPR) and Law 125(I)/2018 of the Republic of Cyprus, which governs the protection of natural persons with regard to the processing of personal data.

Key Definitions

Personal Data (also referred to as personal information) means any information relating to an individual that identifies, or can be used to identify, that individual. This includes, but is not limited to, a person's full name, identity card or identification number, location data, online identifiers, or information relating to the individual's physical, genetic, psychological, economic, or social identity, biometric data, and other similar information. The individual (natural person) to whom the personal data relates is referred to as the "Data Subject."data Subject».

Personal Data Breach: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data, as well as any other similar unauthorized processing or handling of such data.

Data Controller: the natural or legal person, public authority, agency, or other body that determines the purposes and means of the processing of personal data, either alone or jointly with others.

Data Processor: the natural or legal person, public authority, agency, or other body that processes personal data on behalf of the Data Controller.

Processing of Personal Data: Any operation or set of operations performed on personal data, whether by automated means or otherwise, including the collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment, combination, restriction, erasure, or destruction of personal data.

Third: any natural or legal person, public authority, agency, or body other than the Data Subject, the Data Controller, the Data Processor, and persons who, under the direct authority of the Data Controller or the Data Processor, are authorized to process personal data.

The Data Controller

In cases where we act as the Data Controller, meaning that we determine the purposes and means of processing in accordance with the definition provided above, the Data Controller is the legal entity A. EPIPHANIOU INDUSTRIES LTD, located at 17 Iapetou Street, Agios Athanasios Industrial Area, 4101 Limassol, Cyprus, Tel: +357 25811144, Fax: +357 25720021, Email: info@epifaniou-group.com.

Principles We Uphold

At A. EPIPHANIOU INDUSTRIES LTD,we are committed to complying with and adhering to the following principles for the processing of Personal Data, in accordance with Article 5 of the Regulation:

  • Lawfulness, Fairness and Transparency – Personal data shall be processed lawfully, fairly, and in a transparent manner in relation to the Data Subject.
  • Purpose Limitation – Personal data shall be collected for specified, explicit, and legitimate purposes and shall not be further processed in a manner that is incompatible with those purposes.
  • Data Minimization – Personal data shall be adequate, relevant, and limited to what is necessary in relation to the purposes for which it is processed.
  • Accuracy and Data Quality – Personal data shall be accurate and, where necessary, kept up to date. The Company shall ensure that any inaccurate personal data is corrected or updated without undue delay once it becomes aware of such inaccuracies.
  • Storage Limitation – Personal data shall be retained for no longer than is necessary for the purposes for which it is processed, or as required by applicable law.
  • Integrity and Confidentiality – We implement appropriate technical and organizational measures to ensure, to the extent possible, the security of your personal data, particularly protection against unauthorized or unlawful processing, accidental loss, destruction, or damage.

Finally, we are able to demonstrate our compliance with the above principles (Principle of Accountability).

Collection of Personal Data

As the Data Controller, we collect data relating to you in the following cases:

  • When you contact us directly, by telephone, or indirectly, for example through our website, email, partners, or social media platforms, in order to obtain information about our services and products, make inquiries regarding our services and products, or request a quotation.
  • If you accept our services or purchase our products by entering into a contract or agreement with us, collaborate with us, or participate in events related to the provision of our services or the sale of our products.
  • If you complete any of our forms or submit a complaint to us.
  • If your personal data is disclosed to us by partners or customers in the context of agreements or business arrangements.
  • If you participate in submitting tenders or offers to third parties.
  • When you consent to receive informational or promotional material from us.
  • When you access our website or wireless network, or when you visit our premises where a legally operated video surveillance system is in place for security purposes.
  • When you apply for employment with us.
  • When you work for us.

In addition, it should be noted that we process personal data which third parties, usually legal entities, disclose to us when we act as Data Processors on their behalf. In such cases, the respective third-party legal entities are responsible for informing you accordingly.

Children’s Personal Data

As a Data Controller, we do not collect personal information relating to minors without verifiable parental consent in cases where we are able to verify such consent. For example, we cannot verify information provided to us without the physical presence of the individual concerned. In any case, if we determine that we have collected any personal information from a minor without verifiable parental consent (in accordance with the provisions of article 8 of the Regulation), we will promptly delete the information from our records. If you believe that we may have collected information from a minor, please contact our Company.

Categories of natural persons

The categories of natural persons whose data we process as Data Controller include:

  • Individuals or representatives of legal entities who are interested in our services and products.
  • Customers or individuals involved in the provision of our services and products, or individuals employed by our suppliers and business partners.
  • Individuals involved in projects in which we participate.
  • Individuals involved in accidents that we are required to investigate.
  • Job applicants.
  • Our employees.
  • Visitors to our facilities, website, and social media accounts that we maintain.

For personal data that we may process when our company acts as a Data Processor, the respective Data Controllers are responsible for providing you with the relevant information.

Personal data that we may collect as a Data Controller

Information from the following categories of data relating to you may be collected and processed, where applicable, when necessary to serve the purpose of collection and in accordance with the appropriate legal basis:

  • Contact information for you or a person you designate (full name, address, telephone or fax number, e-mail address).
  • Professional status information (occupation or employment position).
  • Your CV and relevant information, such as your role, responsibilities, and the duration of your involvement in the project, when you collaborate with us in the context of projects.
  • Information of those involved in agreements, such as the necessary details from the above-mentioned information, terms, and amounts.
  • Payment Information (IBAN or bank account number, tax identification number, preferred payment method, payment terms, depositor details, etc.).
  • Accident details, including information about those involved and related information.
  • Customer history (satisfaction, transactions, complaints, terms and conditions) and information relating to the evaluation of individuals and situations.
  • Application / website / social media data (cookies, full name or username, photograph, publicly available information, and comments when you contact us through social media, or attachments included in email communications).
  • Your image, when it appears with your consent on our social media accounts or website, or when you visit our premises where a video surveillance system operates for security purposes.
  • The information provided in your CV, such as education, work experience, and skills, as well as any supporting documents you may send to us.

It should be noted that, for the company’s employees, additional personal data may also be collected and processed. Employees are informed about such data through documents, manuals, policies, and procedures, as part of the internal information provided within the company.

What Are the Purposes of Processing & the Legal Basis for Data Processing

The processing of personal data is based on one of the “legal bases” as set out in Article 6 of the Regulation (or Article 9 for special categories of data). The legal bases on which the collection and processing of personal data are primarily based include consent, compliance with legal obligations, the performance of our contractual obligations, and the safeguarding of our legitimate interests. For special categories of personal data, the legal bases may include consent, the fulfilment of obligations and the exercise of specific rights of the data controller or the data subject in the field of employment law, social security, and social protection law, as well as explicit consent. The legal basis on which the processing of your personal data is carried out is linked to each processing purpose as follows.

Consent: When you contact us directly or indirectly in any way as an individual interested in our products and services, when you express interest in employment or cooperation with us, when you complete our forms, when we contact you as part of our promotional activities, when you submit a complaint, when you visit our social media accounts, when you expressly consent to the publication of images featuring you, when you connect to our wireless network, or when you provide us with your business card.

Commitments for Performance of our contractual obligations: when you receive services and products from us, when you work or collaborate with us, when we make payments related to our obligations, or when we communicate with you in the context of contractual agreements.

Compliance with our legal obligations: to ensure our compliance with our legal obligations towards various authorities, including, indicatively, labour law authorities, regulatory authorities, tax authorities, accounting authorities, statutory auditors, judicial authorities, and public services.

For the safeguarding of our our legitimate interests : for the improvement of our services, the management of accidents, the processing of our payments, the evaluation of individuals and situations, and the recording of your image through the video surveillance system that we lawfully operate.

Our employees are informed about the legal bases for processing personal data that we collect from them through internal documents and manuals.

Data Retention

We retain personal data for as long as required by the relevant processing purpose and any other permitted related purpose.

Data collected based on contractual and legal obligations is retained after the termination of the contractual and legal obligations for as long as required by the applicable legal and regulatory framework.

Data relating to offers that do not result in a cooperation agreement are retained for 12 months.

Cookies are retained depending on their type, and you can find further information about them in the dedicated cookie policy available on our website.

CVs and related information of job applicants are retained for 12 months.

Personal data collected through the CCTV system that we lawfully operate is retained for 7 days.

Data that may be required for the protection of our legitimate interests as the Data Controller is retained until the reason for its retention ceases to exist.

Data collected through our Wi-Fi network is retained for 2 hours after disconnection.

Specifically, for data that we process based on your consent, such data is retained from the date the relevant consent is provided until the consent is withdrawn.

Information that is no longer necessary is securely destroyed or anonymised. We restrict access to your data to individuals who need to use it for the specific purpose for which it was collected.

How Do We Ensure the Security of Personal Data

We have implemented reasonable organisational and technical measures to protect the information we collect, particularly any special categories of personal data. We follow international standards and best practices to ensure the security of our networks. We ensure that your personal data is processed securely and lawfully through the implementation of policies and the development and application of procedures. For example, the following security measures are used to protect personal data against misuse or any other form of unauthorised processing:

  • Access to personal data is restricted to a limited number of authorised individuals for specific purposes, and any necessary transfer of data is carried out through secure procedures.
  • Our staff is bound by confidentiality obligations and has restricted, role-based access only to the data that is necessary for the performance of their duties.
  • We select reliable partners who are contractually bound, in accordance with Article 28 of the Regulation, to the same obligations regarding the protection of personal data. We also retain the right to audit and verify their compliance, in accordance with Article 28(3)(h) of the Regulation.
  • All necessary technical measures are implemented in the information systems used for the processing of personal data to prevent loss, unauthorised access, or any other form of unauthorised processing.

In addition, access to these information systems is continuously monitored in order to detect and prevent unlawful use at an early stage. Although the transmission of data via the internet or a website cannot be guaranteed to be fully protected against cyberattacks, we work to maintain physical, electronic, and procedural security measures to protect your data.

Some of the security measures we implement are not disclosed for obvious reasons.

To Whom May Data Be Disclosed

We take all necessary measures to ensure that the recipients of personal data are kept to the minimum possible number. The personal data we collect and process as Data Controllers may be disclosed to third parties, provided that the lawfulness of such disclosure is fully justified. Depending on the circumstances, certain personal data that we lawfully process as Data Controllers may be accessed by (or disclosed to) the following recipients:

  • Any competent supervisory or law enforcement authority, within the scope of its role and responsibilities.
  • Any public or judicial authority, where this is required by law or by a court decision.
  • The IT systems administrator under contract, subject to strict confidentiality obligations.
  • The company’s accountant and auditor, for any financial data that is required, under strict confidentiality obligations.
  • The company’s legal advisor, for any data required in legal matters, under strict confidentiality obligations.
  • Product transport and delivery companies for the products you order, and only for the information necessary to complete the delivery.
  • The collaborating insurance company, and only for the necessary part of the information required.
  • The cooperating banks (of the company, employees, partners, and suppliers), only for data relating to payment matters.
  • The system consultants engaged for system control and audit matters, as well as the trainer and the Human Resource Development Authority (HRDA) for training matters, and only for the necessary parts of information and data required.
Where Does the Processing Take Place

The personal data we collect is processed within the European Economic Area (EEA).    

Your Rights as a Data Subject and How You Can Exercise Them

You have the right to be informed, the right to provide or withdraw your consent where the collection and processing of your personal data is based on consent, the right to request access to your personal data, as well as the rights to rectification and erasure of your personal data where applicable, as described below. You also have the right to restrict processing, the right to object to processing, and/or the right to data portability. If the processing of your personal data is based on your consent, you may withdraw your consent at any time.

Your Right to information is exercised through the publication of this policy or, additionally in certain cases, through the inclusion of relevant information in documents or forms we use when communicating with you. You may request a printed copy of our policy by contacting us.

Your Right to συγκατάθεση is ensured by design, as we have identified the cases where your consent is required and have developed the relevant documents for obtaining it.  

The Company does not use does not use automated decision-making processes, including profiling. More specifically, you have the following additional rights, provided that you exercise them in writing and after your identity as the data subject has been verified.

Right of Access: You have the right to be informed about the data we hold about you and how we process your data. You also have the right to access the personal data relating to you.

Right to Rectification: You have the right to request the correction or completion of your personal data if it is inaccurate or incomplete.

Note: As we are unable to know of any changes to your personal data unless you inform us, we kindly ask you to help us keep your information accurate by notifying us of any changes to your personal data.

Right to Erasure: You have the right to request the deletion of your personal data.

We can fulfil this right if:

  • The data is no longer necessary for the purposes for which it was collected.
  • If there is no other legal basis for processing other than your consent.
  • If you exercise your right to object (see this right below).
  • If the data has been processed in violation of the applicable legal provisions.
  • If the data was collected in the context of Information Society services.

We reserve the right to refuse the fulfilment of the above right if the processing of the data is necessary for compliance with a legal or contractual obligation, for reasons of public interest, or for the establishment, exercise, or defence of our legal claims (Article 17(3)).

Right to Restriction of Processing: You have the right to request the restriction of processing of your personal data when:

  • You dispute the accuracy of the data, for the period required for us to verify their accuracy.
  • The processing was unlawful and, instead of requesting the deletion of your data, you request the restriction of their processing.
  • We no longer need the data for the purposes for which it was collected, but you require it for the establishment, exercise, or defence of your legal claims.
  • You object to the processing, and until it is verified whether our legitimate rights override your rights.

Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, as well as to request the transfer of your data either to you or to another person who will process it.

Right to ObjectYou have the right to object at any time to the processing of your personal data, including profiling, as well as when the purpose of the processing relates to direct marketing.

All of the above applies when we act as the Data Controller. In cases where we act as a Data Processor, the respective Data Controller is responsible for providing you with information and handling your requests.

Our Company, in case you submit in writing any relevant request in writing, will review your request and respond within one month of receiving it, either by fulfilling your request, informing you of the objective reasons preventing its fulfilment, or, taking into account the possible complexity of the request and the number of requests received at that time, by requesting an extension of up to two additional months for the response (Article 12(3)).

The exercise of the above-mentioned rights is carried out at no cost to you, by sending a relevant request, letter, or email to the Company using the contact details provided below. The abusive exercise of the above rights (Article 12(5)) may result in the imposition of a reasonable fee.

If you are not satisfied with the way we use your data, or with our response to the exercise of your above-mentioned rights, you have the right to submit a complaint to the Personal Data Protection Authority.

Personal Data Breach

In case of a breach of the security and integrity of the data in our possession relating to personal data for which our Company acts as the Data Controller, we will take the following measures (in accordance with Articles 33 and 34 of the Regulation):

  • We will examine, assess, and implement the necessary procedures required to contain and mitigate the breach.
  • We will assess the risk and its impact on the rights and freedoms of the data subjects.
  • We will make every effort to minimise the damage that has occurred or may occur.
  • We will notify the Personal Data Protection Authority within 72 hours from the moment we become aware of the breach, where required (or, within a short period of time, the Data Controller if we act as Data Processors).
  • We will assess the impact on your privacy and take appropriate measures to prevent the recurrence of the breach.

In case that we act as the Data Processor, we will notify the Data Controller as soon as possible.

Links to Other Websites

Our Website may contain links to other websites that are not operated or controlled by us. If you click on a third-party link, you will be directed to that third party’s website. We recommend that you review the Privacy Policy of every website you visit. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party websites or services.

Cookies

By following this link, you will be redirected to our Cookie Policy.  

Contact Details of the Personal Data Protection Authority

Cyprus Data Protection Authority, 1 Iasonos Street, 1082 Nicosia, Tel.: +357 22 818456, Email: commissioner@dataprotection.gov.cy

Additional information and terminology regarding the Regulation can be found on the following website: EUR-Lex – Regulation (EU) 2016/679 (GDPR)

Contact Details for Personal Data Matters

If you wish to contact us or exercise any of your rights, please contact our Company’s Data Protection Officer during office hours at the following address: 17 Iapetou Street, Agios Athanasios Industrial Area, 4101 Limassol, Cyprus. Tel.: +357 25 811144, Fax: +357 25 720021, Email: athina.epiphaniou@epiphaniou-group.com

Policy Updates

This policy was last revised on 17 May 2021 and may be revised again if any significant changes occur. Any revision will be made available on our website, together with an indication of its effective date. A printed copy of this policy is available at our offices or can be provided to you upon request.

Scroll to Top