This Privacy Notice explains how A.V. Premiersoft Ltd (hereinafter referred to as the “Company”, “we”, “us” or “our”) collects, uses and otherwise processes information about you, including your personal data, and how we protect your privacy.
We are committed to protecting your personal data and processing it in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation or “GDPR”), Law 125(I)/2018 of the Republic of Cyprus, as amended, and any other applicable data protection legislation.
Personal Data means any information relating to an identified or identifiable natural person (“data subject”). An identifiable natural person is a person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to that person’s physical, physiological, genetic, mental, economic, cultural or social identity.
Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed.
Controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of processing personal data.
Processor means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Controller.
Processing means any operation or set of operations performed on personal data or sets of personal data, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination or otherwise making available, alignment, combination, restriction, erasure or destruction.
Third Party means a natural or legal person, public authority, agency or body other than the data subject, Controller, Processor and persons who, under the direct authority of the Controller or Processor, are authorised to process personal data.
Where we determine the purposes and means of processing personal data, A.V. Premiersoft Ltd acts as the Data Controller.
A.V. Premiersoft Ltd
116 Nicou Pattichi Street
Chrisafiliotissa Building
Block A, 2nd Floor
3070 Limassol, Cyprus
Telephone: +357 25 818 929
Email: info@premiersoft.com.cy
Website: www.premiersoft.com.cy
In certain circumstances, particularly when providing software, technical, support or other services to our clients, we may process personal data on behalf of another organisation. In such circumstances, that organisation acts as the Data Controller and A.V. Premiersoft Ltd acts as the Data Processor.
At A.V. Premiersoft Ltd, we are committed to processing personal data in accordance with the principles set out in Article 5 of the GDPR.
Personal data shall be:
Processed lawfully, fairly and transparently in relation to the data subject (lawfulness, fairness and transparency);
Collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes (purpose limitation);
Adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed (data minimisation);
Accurate and, where necessary, kept up to date. We take reasonable steps to ensure that inaccurate personal data is erased or rectified without undue delay (accuracy);
Kept in a form which permits identification of data subjects for no longer than necessary for the purposes for which the data is processed, subject to applicable legal retention requirements (storage limitation); and
Processed securely, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures (integrity and confidentiality).
We are also responsible for, and must be able to demonstrate, compliance with these principles (accountability).
When acting as the Data Controller, we may collect your personal data in circumstances including the following:
When you contact us directly or indirectly, including through our website, email, telephone, social media accounts, representatives or business partners, to obtain information about our products or services, request assistance or request a quotation;
When you purchase, subscribe to, receive or otherwise use our products or services;
During pre-contractual discussions and negotiations;
When you enter into a contract or other agreement with us;
When you cooperate with us as a supplier, partner, consultant or other business associate;
When you complete any of our documents, applications, forms or questionnaires;
When you submit a complaint, enquiry, support request or other communication to us;
When your personal data is lawfully disclosed to us by third parties, business partners or organisations with which we have a contractual relationship;
When you use our website or connect to a network or service made available by us;
When you visit our premises;
When you apply for employment with us; or
When you are employed by us.
We may also process personal data provided to us by clients or other organisations where we act as a Data Processor on their behalf. In those circumstances, the relevant Data Controller is responsible for providing the appropriate privacy information to the individuals concerned.
Our products and services are not generally directed at minors, and we do not knowingly collect or process minors’ personal data where parental or guardian consent is legally required without obtaining the necessary consent.
Where information is communicated to us electronically or without physical interaction, it may not always be possible to determine the age of the individual providing the information.
If we become aware that we have collected personal data relating to a minor without an appropriate lawful basis or required parental or guardian consent, we will take appropriate steps to delete or otherwise lawfully handle that information.
If you believe that we may hold personal data relating to a minor inappropriately, please contact us using the details provided in this Policy.
When acting as Data Controller, the individuals whose personal data we may process include:
Individuals and representatives of organisations interested in our products and services;
Customers and users of our products and services;
Employees, officers and representatives of our customers;
Suppliers, contractors, consultants, service providers, partners and their employees or representatives;
Individuals involved in the delivery or support of our products and services;
Employment candidates;
Visitors to our premises;
Visitors to our website and users of our social media accounts; and
Our employees and other members of staff.
Where we act as a Data Processor, the relevant Data Controller is responsible for determining the categories of data subjects and providing the necessary privacy information.
Depending on our relationship with you, the purpose of the processing and the applicable legal basis, we may collect and process the following categories of personal data:
Name and surname;
Postal or business address;
Telephone and fax numbers;
Email address;
Contact person details; and
Information concerning the purpose of your enquiry or area of interest.
Occupation;
Employer or company;
Job title or position;
Department; and
Other business-related information.
Where necessary and lawful, this may include:
Identity card details;
Passport details;
Alien Registration Certificate (ARC) number;
Date and place of birth;
Document issue date; and
Document expiry date.
This may include:
Contract terms and conditions;
Agreements;
Accepted quotations and offers;
Signatures;
Relevant dates;
Product and service information;
Subscription or licence details; and
Other information relating to our commercial relationship with you.
This may include:
IBAN and bank account details;
Tax-related information;
Payment methods;
Payment terms;
Transaction dates;
Names and signatures;
Authorisations; and
Other information necessary for invoicing, payments and accounting purposes.
This may include:
Details of an incident, complaint or support request;
Details concerning individuals involved;
Communications relating to the matter;
Technical information necessary to investigate a problem; and
Information concerning the resolution of an incident or request.
Where appropriate and subject to an applicable legal basis, including consent where required, we may process photographs or other media relating to you, including material published on our website or social media accounts.
This may include:
Customer history;
Products and services used;
Transaction details;
Complaints and claims;
Support history;
Contractual terms;
Customer satisfaction information; and
Information relevant to the management of our business relationship.
Depending on how you interact with us, this may include:
IP address;
Cookies and similar technologies;
Device and browser information;
Name or social media username;
Information that you make publicly available;
Comments and messages;
Email attachments; and
Other information generated through your interaction with our digital services.
Where you connect to a wireless or other network operated by us, we may process technical information such as:
IP address;
MAC address;
Device name;
Device type; and
Operating system.
Where CCTV is operated at our premises for security and safety purposes, video images of individuals visiting those premises may be processed.
Where you apply for employment with us, we may process information contained in your CV or application, including:
Educational qualifications;
Professional qualifications;
Skills and competencies;
Employment history;
Professional experience; and
Other information voluntarily provided as part of your application.
Additional categories of personal data may be processed in relation to our employees. Employees are separately informed about such processing through appropriate internal documents, policies, procedures and notices.
When acting as the Data Controller, we process personal data only where a valid legal basis exists under Article 6 of the GDPR and, where special categories of personal data are concerned, where a condition under Article 9 of the GDPR is satisfied.
Depending on the circumstances, our legal bases may include:
We may rely on your consent where you have freely provided specific, informed and unambiguous consent to a particular processing activity.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
We may process personal data where processing is necessary:
To enter into a contract with you;
To provide products or services requested by you;
To administer our contractual relationship;
To provide customer support;
To manage subscriptions, licences or maintenance arrangements;
To process payments or fulfil financial obligations; or
To take steps requested by you before entering into a contract.
We may process personal data where necessary to comply with legal or regulatory obligations, including obligations relating to:
Taxation;
Accounting;
Auditing;
Employment and labour legislation;
Social insurance;
Regulatory requirements;
Court orders;
Judicial proceedings; and
Requests from competent public authorities.
We may process personal data where necessary for our legitimate business interests or the legitimate interests of a third party, provided that those interests are not overridden by your interests, fundamental rights or freedoms.
These interests may include:
Operating and improving our products and services;
Providing effective customer and technical support;
Managing customer and supplier relationships;
Maintaining the security of our systems and premises;
Preventing and investigating fraud, misuse and security incidents;
Protecting our property, employees, customers and visitors;
Recovering amounts lawfully owed to us;
Establishing, exercising or defending legal claims; and
Managing and improving our business operations.
Where we rely on legitimate interests, we consider the nature and impact of the processing and the rights and expectations of the individuals concerned.
Where special categories of personal data are processed, we will ensure that an appropriate condition under Article 9 of the GDPR applies. Depending on the circumstances, this may include:
Explicit consent;
Processing of personal data manifestly made public by the data subject;
Processing necessary for the establishment, exercise or defence of legal claims; or
Another applicable condition provided by law.
Our employees are provided with additional information concerning the purposes and legal bases applicable to the processing of employee data through internal policies and notices.
We retain personal data only for as long as necessary for the purpose for which it was collected, taking into account applicable contractual, legal, regulatory, accounting and operational requirements.
Personal data collected in connection with contractual or legal obligations may be retained after the end of the relevant contractual relationship where required by applicable legislation or where necessary for the establishment, exercise or defence of legal claims.
Unless a different retention period is required by law or justified by the circumstances:
Personal data contained in quotations or offers that do not result in a contractual relationship may be retained for up to 24 months;
Technical information collected in connection with our Wi-Fi or similar network services may be retained for up to 90 days;
Personal data submitted by unsuccessful employment candidates may be retained for up to 12 months, after which it will be securely deleted or destroyed unless a longer period has been agreed or is otherwise legally justified;
CCTV recordings may generally be retained for up to 15 days, unless a longer period is required in connection with a security incident, investigation, legal claim or legal obligation;
Personal data required for the protection of our legitimate interests may be retained for as long as the relevant legitimate purpose continues; and
Where processing is based solely on consent, personal data will generally be retained until consent is withdrawn or the purpose for which consent was given no longer applies, subject to any legal requirements permitting or requiring continued retention.
Personal data that is no longer required will be securely deleted, destroyed or anonymised, as appropriate.
Access to retained personal data is restricted to authorised persons who require access for legitimate business or legal purposes.
We implement appropriate technical and organisational measures designed to protect the personal data we collect and process against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or other unlawful processing.
Our measures are designed according to the nature, scope, context and purposes of processing and the risks presented to individuals.
Measures may include:
Restricting access to personal data to authorised employees and other persons with a legitimate need to access it;
Applying appropriate access controls and user permissions;
Requiring employees and other authorised persons to comply with confidentiality obligations;
Using appropriate procedures for the secure transfer and handling of personal data;
Selecting service providers and processors that provide appropriate data-protection safeguards;
Entering into appropriate data-processing arrangements with processors in accordance with Article 28 of the GDPR;
Maintaining appropriate technical safeguards within our ICT systems;
Monitoring access to systems where appropriate;
Maintaining backup, security and recovery procedures where appropriate;
Providing staff with data-protection and information-security guidance; and
Reviewing our security measures and procedures as appropriate.
Where third-party processors process personal data on our behalf, we require them to provide appropriate contractual, organisational and technical safeguards.
While no transmission of information over the Internet or electronic storage system can be guaranteed to be completely secure, we take reasonable and appropriate measures to protect personal data against the risks associated with such processing.
Certain details concerning our security measures are not publicly disclosed where doing so could compromise their effectiveness.
We take reasonable steps to limit the disclosure of personal data to what is necessary and lawful.
Where we act as Data Controller, personal data may, where appropriate and subject to an applicable legal basis, be disclosed to:
Competent supervisory, regulatory or governmental authorities acting within their legal powers;
Public authorities, law-enforcement authorities or judicial authorities where disclosure is required or permitted by law;
Our auditors, where access to relevant financial or business information is necessary;
Lawyers and other professional advisers where information is required for legal advice, proceedings, claims or other legitimate professional purposes;
Banks and payment-service providers where necessary to process payments or financial transactions;
IT, hosting, cloud, communications and other service providers where they process information on our behalf;
Professional consultants, contractors, suppliers or business partners where access is necessary for a legitimate and lawful business purpose; and
Other recipients where you have authorised the disclosure or where disclosure is otherwise required or permitted by law.
Where a third party acts as a processor on our behalf, appropriate contractual safeguards will be put in place where required by the GDPR.
We do not disclose personal data to third parties merely for their own independent marketing purposes unless there is an appropriate legal basis to do so.
We aim to process personal data within the European Economic Area (EEA) wherever practicable.
Where personal data is transferred or made accessible outside the EEA, we will ensure that the transfer is carried out in accordance with applicable data-protection law.
Depending on the circumstances, appropriate safeguards may include:
A European Commission adequacy decision;
Standard Contractual Clauses approved by the European Commission;
Another legally recognised transfer mechanism; or
A specific exception permitted by the GDPR.
Where required, additional technical, contractual or organisational safeguards may also be applied.
Subject to the conditions and limitations provided by applicable data-protection legislation, you may have the following rights in relation to your personal data:
Right to be informed about how your personal data is processed;
Right of access to your personal data;
Right to rectification of inaccurate or incomplete personal data;
Right to erasure of personal data in certain circumstances;
Right to restriction of processing in certain circumstances;
Right to data portability where the applicable legal requirements are satisfied;
Right to object to certain processing;
Right to withdraw consent at any time where processing is based on consent; and
Rights relating to automated decision-making, where applicable.
You have the right to receive information concerning the collection and use of your personal data.
This Policy is intended to provide that information. Additional privacy information may also be provided through particular forms, documents, contracts, notices or services where appropriate.
You may request a copy of this Policy by contacting us.
You have the right to obtain confirmation as to whether we process personal data concerning you and, where applicable, to obtain access to that data together with other information required under applicable data-protection legislation.
You have the right to request the correction of inaccurate personal data concerning you and to request that incomplete personal data be completed.
Because we may not otherwise become aware that your information has changed, we encourage you to inform us when personal data that we hold about you requires updating.
You may have the right to request the deletion of your personal data where, among other circumstances:
The personal data is no longer necessary for the purposes for which it was collected or processed;
You withdraw consent where consent is the legal basis and no other legal basis applies;
You successfully object to the processing;
The personal data has been unlawfully processed; or
The personal data must be erased to comply with a legal obligation.
The right to erasure is not absolute.
We may continue to process personal data where processing is necessary, for example, to comply with a legal obligation, for certain public-interest purposes, or for the establishment, exercise or defence of legal claims.
You may have the right to request restriction of processing where:
You contest the accuracy of the personal data, for the period necessary for us to verify its accuracy;
Processing is unlawful and you oppose deletion and request restriction instead;
We no longer require the personal data for our processing purposes, but you require it for the establishment, exercise or defence of legal claims; or
You have objected to processing and verification is pending as to whether our legitimate grounds override your interests, rights and freedoms.
Where processing is based on consent or a contract and is carried out by automated means, you may have the right to receive personal data you have provided to us in a structured, commonly used and machine-readable format.
Where technically feasible and legally applicable, you may also request that such personal data be transmitted directly to another Data Controller.
This right is subject to the conditions and restrictions set out in Article 20 of the GDPR.
You may have the right to object at any time, on grounds relating to your particular situation, to processing based on our legitimate interests or another legal basis to which the right of objection applies.
Where personal data is processed for direct marketing purposes, you have the right to object at any time to such processing, including related profiling. Where you object to processing for direct marketing purposes, your personal data will no longer be processed for those purposes.
Where processing is based on your consent, you may withdraw that consent at any time.
Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn.
Where applicable, you have rights relating to decisions based solely on automated processing, including profiling, where such decisions produce legal effects concerning you or similarly significantly affect you.
Requests concerning your data-protection rights should be submitted to us in writing or electronically using the contact details provided in this Policy.
We may request reasonable information necessary to verify your identity before responding to a request. Where a request is made through an authorised representative, we may also require evidence of that person’s authority to act on your behalf.
We will respond to valid requests without undue delay and, in principle, within one month of receipt, in accordance with Article 12 of the GDPR.
Where necessary, taking into account the complexity and number of requests, this period may be extended by up to a further two months. Where an extension is required, we will inform you within the initial one-month period and provide the reasons for the delay.
Exercising your rights is generally free of charge.
Where a request is manifestly unfounded or excessive, particularly because of its repetitive nature, we may, where permitted by law:
Charge a reasonable administrative fee; or
Refuse to act on the request.
Where A.V. Premiersoft Ltd acts solely as a Data Processor on behalf of another organisation, requests concerning your rights should normally be directed to the relevant Data Controller. Where appropriate, we will assist the Data Controller in responding to such requests in accordance with our legal and contractual obligations.
Communications concerning data-protection matters may be made in Greek or English.
If you are dissatisfied with how we process your personal data or with our response to a request concerning your data-protection rights, you have the right to lodge a complaint with the competent supervisory authority.
In Cyprus, the competent supervisory authority is the:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street
1082 Nicosia
Cyprus
Telephone: +357 22 818456
Email: commissioner@dataprotection.gov.cy
You may also have the right to complain to another competent supervisory authority where applicable under the GDPR.
If a personal data breach occurs, we will assess and manage the incident in accordance with applicable data-protection legislation.
Where A.V. Premiersoft Ltd acts as Data Controller, we will, as appropriate:
Investigate and assess the nature and circumstances of the breach;
Take appropriate steps to contain and mitigate the breach;
Assess the categories and volume of personal data affected;
Assess the potential consequences for the rights and freedoms of affected individuals;
Take appropriate measures to reduce or prevent harm;
Document the breach and our response;
Notify the competent supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of the breach, where notification is required under Article 33 of the GDPR;
Notify affected individuals without undue delay where required under Article 34 of the GDPR; and
Take reasonable measures to reduce the likelihood of a similar incident occurring again.
Where A.V. Premiersoft Ltd acts as a Data Processor, we will notify the relevant Data Controller without undue delay after becoming aware of a personal data breach, in accordance with our applicable legal and contractual obligations.
Our website may contain links to websites, platforms or services that are not operated or controlled by A.V. Premiersoft Ltd.
When you follow a link to a third-party website, the privacy practices of that third party will apply.
We encourage you to review the privacy notices or policies of third-party websites and services that you use.
We are not responsible for the privacy policies, content or practices of third-party websites or services that are outside our control.
Our website may use cookies and similar technologies for purposes such as:
Enabling the website to function correctly;
Remembering preferences;
Maintaining website security;
Understanding how visitors interact with our website;
Improving website performance and functionality; and
Providing other features where permitted by law.
Where consent is legally required for a particular cookie or similar technology, it will be used only after the required consent has been obtained.
Further information concerning cookies, including the categories of cookies used and available choices, may be provided through our website’s cookie notice or cookie-management tool.
For further information concerning data protection in Cyprus, you may contact:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street
1082 Nicosia
Cyprus
Telephone: +357 22 818456
Email: commissioner@dataprotection.gov.cy
Additional information concerning the GDPR is available through the official websites of the European Union and the Office of the Commissioner for Personal Data Protection.
If you have any questions about this Policy, the processing of your personal data, or wish to exercise any of your data-protection rights, you may contact:
A.V. Premiersoft Ltd
116 Nicou Pattichi Street
Chrisafiliotissa Building
Block A, 2nd Floor
3070 Limassol, Cyprus
Telephone: +357 25 818 929
Email: info@premiersoft.com.cy
Website: www.premiersoft.com.cy
Please provide sufficient information to enable us to identify and appropriately respond to your request.
We may review and update this Privacy and Personal Data Protection Policy periodically, particularly where there are changes to:
Applicable legislation or regulatory guidance;
Our products or services;
The ways in which we process personal data;
Technologies used by us; or
Our organisational or operational arrangements.
The latest version of this Policy will be made available on our website together with the applicable effective or revision date.
Last updated: August 2026