This Privacy Policy explains how the professional practice trading as Easy Audit Cyprus, led by Alexandros Prodromou ("Easy Audit", "we", "us"), handles personal data when you visit this website, contact us or enquire about our professional services. We process personal data in accordance with the EU General Data Protection Regulation (GDPR), Cyprus Law 125(I)/2018 and other applicable data protection and professional obligations.
1. Who is responsible for your data?
Easy Audit Cyprus is the controller of the personal data described in this Policy, unless an engagement expressly states that we act as a processor on a client's instructions.
- Contact: Alexandros Prodromou / Easy Audit Cyprus
- Email: info@easyauditcy.com
- Telephone: +357 99 337936
- Address: Kappadokias str. 9, Office No. 205, 2028 Dassoupoli, Nicosia, Cyprus
2. Personal data we may collect
Information you provide
- identity and contact details, such as your name, email address, telephone number, position and organisation;
- the contents of messages, enquiries, correspondence and appointment requests;
- identity, financial, employment, tax, accounting, payroll, corporate and transaction information needed for an agreed professional engagement;
- documents and information required for client acceptance, conflict checks, anti-money-laundering, sanctions and other legal or professional checks.
Information collected automatically
Our hosting and security systems may record limited technical information, including IP address, browser and device type, requested pages, date and time, referring page and security events. We do not use this website for automated decision-making or profiling that produces legal or similarly significant effects.
Please do not send sensitive documents through the general contact form. Contact us first so that an appropriate secure channel can be agreed.
3. Why we use personal data and our legal bases
- To respond to enquiries and take steps requested before an engagement: performance of a contract or pre-contractual steps (Article 6(1)(b) GDPR).
- To provide audit, accounting, tax, payroll and advisory services: performance of a contract and, where applicable, compliance with legal or professional obligations.
- Client acceptance, regulatory reporting and record keeping: compliance with legal obligations (Article 6(1)(c)).
- Website operation, security, fraud prevention, business administration and legal claims: our legitimate interests (Article 6(1)(f)), balanced against your rights.
- Optional marketing or non-essential technologies, if introduced: your consent (Article 6(1)(a)), which you may withdraw at any time.
Where special-category or criminal-offence data must be processed, we do so only where an additional lawful condition applies. We will not use personal data for a materially incompatible purpose without giving further information and, where required, obtaining consent.
4. Recipients and service providers
We do not sell personal data. Access is limited to people who need it for the relevant purpose. Depending on the circumstances, data may be disclosed to:
- website, email, cloud, secure file storage, IT support and cybersecurity providers acting under appropriate terms;
- professional advisers, auditors, insurers, banks or subcontractors subject to confidentiality duties;
- tax, regulatory, law-enforcement, judicial or other public authorities where disclosure is required or permitted by law;
- Google, only when you actively choose to load the embedded Google Map. Google then processes technical data under its own privacy terms;
- Google Fonts and jsDelivr, from which the website currently retrieves fonts and software files; those providers may receive technical request data such as your IP address.
5. International transfers
Some technology providers may process data outside Cyprus or the European Economic Area. Where a transfer is subject to the GDPR, we use or require an approved safeguard, such as an adequacy decision, Standard Contractual Clauses and supplementary measures where appropriate. You may contact us for information about the safeguard relevant to a particular transfer.
6. How long we keep data
We keep personal data only for as long as necessary for the purpose collected and to meet legal, regulatory, professional, insurance and dispute-resolution requirements. In general:
- enquiries that do not become an engagement are normally retained for up to 24 months after the last meaningful contact;
- basic website security logs are normally retained for up to 12 months, unless an incident requires longer retention;
- client files and business records are retained for the period required by applicable audit, tax, accounting, anti-money-laundering and limitation rules, and then securely deleted or anonymised.
When several periods apply, we use the longest mandatory period. We may preserve relevant records longer where reasonably necessary for an actual or anticipated legal claim.
7. Cookies and embedded content
The site does not currently use analytics or advertising cookies. Technologies strictly necessary to deliver and secure the site may operate without consent. The embedded Google Map is blocked by default and loads only after you press the relevant button. If analytics, advertising or other non-essential technologies are added later, they must remain disabled until valid consent is obtained and this Policy is updated.
8. Security
We use reasonable technical and organisational measures designed to protect personal data, including access controls, confidentiality duties, appropriate backups and secure service providers. No internet transmission or storage system can be guaranteed to be completely secure. If a personal-data breach creates a legal notification duty, we will notify the competent authority and affected persons as required.
9. Your rights
Subject to the conditions and exceptions in applicable law, you may request:
- access to and a copy of your personal data;
- correction of inaccurate or incomplete data;
- deletion or restriction of processing;
- objection to processing based on legitimate interests or to direct marketing;
- data portability where the legal requirements apply;
- withdrawal of consent, without affecting processing carried out before withdrawal.
Send a request to info@easyauditcy.com. We may ask for information necessary to verify your identity and will normally respond within one month. Rights may be limited where another person's rights, professional confidentiality or a legal retention duty applies.
10. Complaints
Please contact us first so we can try to resolve your concern. You also have the right to complain to the Office of the Commissioner for Personal Data Protection of Cyprus or, where applicable, another competent supervisory authority.
11. Children, external links and client engagements
This website is intended for business and professional users and is not directed to children. External websites are governed by their own privacy notices. An engagement letter, statutory notice or client-specific privacy information may supplement this Policy; where Easy Audit acts solely as a processor, the relevant client's instructions and notice apply.
12. Changes to this Policy
We may update this Policy to reflect changes in law, services or technology. The effective date above identifies the current version. Material changes will be highlighted where appropriate.
