1. Introduction
1.1. PRIONEX LTD ("PRIONEX LTD", "we", "us", or "our") operates in the information technology sector, providing software development services and licensed software solutions. We take the privacy of your Personal Data seriously and are committed to protecting it in accordance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Cyprus national data protection legislation.1.2. This Privacy Policy applies to PRIONEX LTD.1.3. This Policy explains what Personal Data we collect about you, under what circumstances we collect it, how we use and safeguard it, and with whom we may share it. It also outlines your choices and applicable rights concerning your Personal Data that is in our possession or under our control.1.4. We may amend this Privacy Policy at any time. Any updates will become effective upon posting to this site, as indicated by the «Effective Date». Your continued use of PRIONEX LTD's website, services, or applications after such changes will constitute your acceptance of the updated policy. In the event of material changes, we will notify you either via email (sent to the address specified in your account) or by a prominent notice on our site prior to the change taking effect.1.5. This Privacy Policy does not apply to websites owned or operated by third parties, even if they are linked from our platforms. We do not control or have access to those websites. When visiting third-party sites, we encourage you to review their privacy policies to understand how your Personal Data may be collected and processed.1.6. If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy), or with the relevant supervisory authority in your EU Member State of residence or employment.
2. Definitions
2.1. To ensure clarity in the understanding of your rights and our obligations in relation to your Personal Data, the following definitions shall apply throughout this Privacy Policy:2.1.1. Applicable Law
All applicable laws, regulations, and binding industry standards governing the collection, use, processing, and protection of Personal Data by PRIONEX LTD, including the General Data Protection Regulation (EU) 2016/679 (GDPR), the Law 125(I)/2018 of the Republic of Cyprus, and other relevant data protection laws.2.1.2. Personal Data
Any information relating to an identified or identifiable natural person (Data Subject), such as full name, surname, postal address, tax identification number (TIN), email address, and bank account details.2.1.3. Special Categories of Personal Data / Sensitive Personal Data
Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sex life or sexual orientation, or data relating to criminal convictions and offenses; collected only when legally required or with explicit consent.2.1.4. Data Controller
A natural person or legal entity determining the purposes and means of the processing of Personal Data; PRIONEX LTD acts as a Data Controller for the Personal Data of its employees, website users.2.1.5. Data Processor
A natural person or legal entity processing Personal Data on behalf of a Data Controller. PRIONEX LTD acts as a Data Processor when providing services to clients who define the purposes and means of such processing.2.1.6. Data Protection Authority
The independent public authority responsible for enforcing data protection laws and regulations; in Cyprus, this is the Office of the Commissioner for Personal Data Protection (<a href="https://www.dataprotection.gov.cy)." target="_blank" rel="noopener noreferrer" class="text-primary-600 hover:text-primary-700 underline">https://www.dataprotection.gov.cy).</a>
3. Categories of Personal Data Collected and Purposes of Processing
3.1. PRIONEX LTD collects and processes the following data for legitimate purposes:
Name and surname – identification and verification.
Postal address – correspondence and record-keeping.
TIN – tax and legal compliance.
Email address – official communications.
Bank account details – execution of payments and financial record management.3.2. Data is processed lawfully, fairly, and transparently for purposes including:
• Business relationship management, accounting, and internal administration;
• Responding to inquiries or communications;
• Compliance with legal and regulatory obligations.3.3. We do not sell, lease, or share Personal Data for marketing purposes. Data is shared only as legally required.
4. How We Protect Your Personal Data
4.1. PRIONEX LTD implements technical and organizational measures to protect Personal Data, including encryption, secure servers, access controls, audits, and staff training.4.2. Access to data is limited to authorized personnel only.4.3. Measures are regularly reviewed and updated; external audits may be conducted as needed.4.4. In case of a data breach with high risk to individuals, authorities and affected individuals will be notified per GDPR and Cypriot law.
5. How Long We Retain Your Personal Data
5.1. PRIONEX LTD retains Personal Data only for as long as is necessary to fulfill the purposes for which it was originally collected. These purposes may include the provision of services, compliance with legal and regulatory obligations, maintenance of business and financial records, risk management, and the resolution of potential disputes.5.2. The applicable retention period depends on the type of data involved, the legal or contractual obligations in place, and the context in which the data is processed. Once the data is no longer required for the stated purposes, we will securely erase, anonymize, or return it to the data subject or controller, as appropriate.5.3. All retention and deletion practices are carried out in accordance with the General Data Protection Regulation (GDPR), Law 125(I)/2018 of the Republic of Cyprus, and our internal data governance policies. These measures ensure that Personal Data is managed responsibly and remains protected throughout its lifecycle.
6. Legal Basis for Processing
6.1. We process Personal Data in accordance with the legal bases provided under Regulation (EU) 2016/679 (General Data Protection Regulation – «GDPR») and Cypriot Law 125(I)/2018 on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data. Depending on the context, we may rely on one or more of the following legal grounds:
• Performance of a contract: when the processing is necessary for the performance of a contract to which you or your organization is a party, or in order to take steps at your request prior to entering into such a contract.
• Compliance with legal obligations: when the processing is necessary to comply with legal obligations under applicable EU or national laws, including but not limited to tax regulations, anti-fraud requirements, and accounting rules.
• Legitimate interests: when the processing is necessary for the purposes of our legitimate interests or those of a third party, provided that such interests are not overridden by your fundamental rights and freedoms. These may include business operations, service improvement, information security, and fraud prevention.
• Consent: where required by law or where no other legal basis is applicable, we will seek your prior, informed, and explicit consent for processing. You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
7. Sharing of Personal Data
7.1. We do not sell, rent, or otherwise commercially distribute your Personal Data to third parties. However, in the course of our business activities and strictly in line with applicable data protection laws, we may share your Personal Data with the following categories of recipients:
• Third-party service providers, acting on our behalf and under our instructions, for the provision of services such as data hosting, IT support, analytics, payment processing, communications, or other operational functions. These parties are contractually bound by confidentiality and data protection obligations consistent with GDPR requirements.
• Clients or business partners, when such disclosure is necessary for the delivery of our services, and only within the scope of valid contractual relationships and applicable legal obligations.
• Public authorities or regulatory bodies, including the Office of the Commissioner for Personal Data Protection in Cyprus, where required by applicable law, court order, or regulatory obligation, or where necessary to defend our legal rights or comply with legal duties.
• Legal, tax, and professional advisors, such as auditors, external consultants, or legal representatives, to the extent necessary for legal compliance, dispute resolution, audits, or corporate governance matters.7.2. Whenever we share Personal Data, we implement appropriate technical, organizational, and contractual safeguards to protect your information. These safeguards include Data Processing Agreements (DPAs) with service providers in accordance with Articles 28 and 32 of the GDPR, ensuring confidentiality, integrity, and availability of the data shared.
8. Your Rights Under Applicable Data Protection Law
8.1. In accordance with the GDPR and Cypriot Law 125(I)/2018, you have the following rights in respect of your Personal Data:
• Right of access – to obtain confirmation as to whether we process your data and access to that data.
• Right to rectification – to request correction of inaccurate or incomplete personal data.
• Right to erasure – to request the deletion of your data under certain conditions ("right to be forgotten").
• Right to restriction of processing – to limit the way we use your data under specific circumstances.
• Right to data portability – to receive your data in a structured, commonly used and machine-readable format and to transmit it to another controller, where applicable.
• Right to object – to object to the processing of your data based on our legitimate interests, including profiling.
• Right to withdraw consent – where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
• Right to lodge a complaint – you may file a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (<a href="https://www.dataprotection.gov.cy)" target="_blank" rel="noopener noreferrer" class="text-primary-600 hover:text-primary-700 underline">https://www.dataprotection.gov.cy)</a> if you believe your rights have been violated.8.2. To exercise any of these rights, you may contact us using the details provided in Section 10 of this Policy. We will respond in accordance with applicable legal requirements and within the timeframes set by law.
9. Use of Cookies and Similar Technologies
9.1. Our website uses cookies for functionality, analytics, and user preferences.9.2. Cookie types
• Strictly Necessary – essential for website function.
• Performance/Analytics – anonymous usage data.
• Functionality – remembers user settings.
• Marketing/Third-party – only with explicit consent.9.3. Users can manage cookie preferences via browser settings or the consent banner.
10. Contact Information
10.1. If you have any questions, concerns, or requests regarding this Privacy Policy or the processing of your Personal Data, you may contact us at:
PRIONEX LTD
14 Georgiou A, office/flat 15, 4047 Germasogeia, Limassol, Cyprus
Email: prionex.ltd@gmail.com10.2. If you are located in the European Economic Area and believe that your rights have not been respected, you may also contact the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus: <a href="https://www.dataprotection.gov.cy." target="_blank" rel="noopener noreferrer" class="text-primary-600 hover:text-primary-700 underline">https://www.dataprotection.gov.cy.</a>
In addition, you may consider contacting the data protection authority in your own EU member state. A full list of national data protection authorities within the EU is available at the European Data Protection Board website: <a href="https://edpb.europa.eu/about-edpb/board/members_en." target="_blank" rel="noopener noreferrer" class="text-primary-600 hover:text-primary-700 underline">https://edpb.europa.eu/about-edpb/board/members_en.</a>