This Privacy Policy explains how ESMIRA LTD collects, uses, stores, and protects personal data obtained through the Cyprus4People platform (available at https://cyprus4people.com and its subdomains), in full compliance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and the Cypriot Law on the Protection of Natural Persons with regard to the Processing of Personal Data (Law 125(I)/2018).
1. Data Controller
The Data Controller responsible for processing your personal data is:
- Entity Name: ESMIRA LTD
- Department of Registrar of Companies (Cyprus) Registration: HE431241
- VAT / Tax Identification: 10431241Y
- Registered & Operational Office: Lambrou Katsoni, Flora Court, Block A, Office 204, 2nd Floor, 8011 Paphos, Cyprus
- Website: https://cyprus4people.com
- Data Protection Inquiries: mail@esmiraweb.com
- Telephone: +357 94 090 540
- Legal Representative: Antonio D’Onofrio
2. Core Processing Principles
We handle your personal data in strict adherence to Article 5 GDPR principles:
- Lawfulness, Fairness & Transparency: Data is processed only when supported by a valid legal ground, with plain-language explanations of our processing activities.
- Purpose Limitation: Data is collected solely for specified, explicit, and legitimate platform purposes and never further processed in an incompatible manner.
- Data Minimization: We limit our collection strictly to what is adequate, relevant, and necessary for the services provided.
- Accuracy: Reasonable measures are maintained to keep personal records accurate and updated.
- Storage Limitation: Information is retained only for the duration required to fulfill the intended purpose or comply with statutory retention laws.
- Integrity & Confidentiality: Technical and organizational safeguards are continuously applied to prevent security incidents, accidental loss, and unauthorized access.
3. Categories of Data Collected, Purposes & Legal Grounds
Depending on how you engage with Cyprus4People, we process the following categories of personal data:
3.1 Account Registration & Member Profile Management
- Data Collected: Full name, public display username, email address, password hash, and resident district or municipality in Cyprus. For public specialist profiles (such as Talent, Doctors, Professionals, and Community Authors), members may optionally supply professional biographies, contact links, academic degrees, professional council registry numbers, and profile photos.
- Purpose: Account creation, session security, member profile administration, and participation in community features.
- Legal Basis: Performance of a contract / Terms of Service agreed upon registration (Article 6(1)(b) GDPR).
- Retention Period: Retained for the active lifespan of your account. Upon account deletion requests, data is removed promptly, except where required by legal preservation duties.
3.2 Directory Listings & Community Submissions
- Data Collected: Data provided when submitting, managing, or claiming directory listings (e.g., Businesses, Places, Events, Services, Real Estate, Motors, Classifieds, Community Spaces), including physical premises addresses, operational phone lines, business emails, trading hours, GPS coordinates, and media galleries.
- Purpose: Publishing, indexing, and presenting verified directory listings to visitors and residents searching across Cyprus.
- Legal Basis: Performance of a contract and fulfillment of user service requests (Article 6(1)(b) GDPR).
- Public Visibility: By their nature and purpose, directory cards and public event announcements are visible to any platform visitor.
3.3 Contact Inquiries, Messaging & Support Tickets
- Data Collected: Sender identity, verified email address, subject line, message text, submitted screenshots or documentation, and internal support reference IDs submitted through /tickets/ or contact forms.
- Purpose: Answering support requests, resolving technical issues, investigating community guideline violations, and combating fraudulent activity.
- Legal Basis: Performance of a contract and our legitimate interest in delivering dependable member assistance and safeguarding platform integrity (Article 6(1)(b) and (f) GDPR).
- Retention Period: Support tickets and communication correspondence are preserved for 24 months after resolution for quality control and audit history.
3.4 Commercial Transactions, Invoicing & Paid Features
- Data Collected: Billing name, invoice address, company tax/VAT number (if applicable), order timestamp, total amount, and transaction confirmation codes.
- Payment Processing Security: ESMIRA LTD does not collect or store complete credit card numbers, CVV security codes, or bank credentials on our infrastructure. All payments are handled directly by PCI-DSS certified payment processors (such as Stripe) using end-to-end tokenization and encrypted channels.
- Purpose: Administering subscriptions, paid promotional boosts, and fulfilling statutory accounting and corporate tax filings.
- Legal Basis: Performance of a purchase contract (Article 6(1)(b) GDPR) and compliance with legal accounting obligations under Cyprus statutory law (Article 6(1)(c) GDPR).
- Retention Period: Invoices and statutory accounting ledgers are retained for 7 years as mandated by Cyprus tax authorities.
3.5 Newsletters & Editorial Digests
- Data Collected: Email address, delivery preferences, and opt-in timestamps (collected via double opt-in verification).
- Purpose: Delivering platform announcements, community digests, and product roadmap updates.
- Legal Basis: Explicit, freely given consent (Article 6(1)(a) GDPR).
- Revocation: You may revoke consent and unsubscribe at any moment using the instant unsubscribe link included in every newsletter footer.
3.6 System Logs, Platform Security & Diagnostics
- Data Collected: Anonymized IP addresses, browser user-agent strings, operating systems, requested URLs, request timestamps, and HTTP response codes.
- Purpose: Detecting automated abuse (brute-force login attempts, DDoS attacks, spam bots), resolving system errors, and ensuring network stability.
- Legal Basis: Legitimate interest in securing our online infrastructure (Article 6(1)(f) GDPR).
- Retention Period: Server access and security logs are purged automatically after 30 days unless required for investigation of a security incident.
4. Cookies & Tracking Technologies
Our website uses functional cookies strictly necessary for core platform operations (login authentication, interface preferences, session tokens). Non-essential cookies, such as analytics or external embeds, are loaded only after you grant consent via our cookie banner. For full details on cookie categories and preference management, please refer to our Cookie Policy (EU) at /legal-hub/cookie-policy/.
5. We Never Sell or Rent Your Personal Data
ESMIRA LTD does not sell, rent, lease, trade, or commercialize member or visitor personal data to data brokers, commercial profiling agencies, or third-party advertisers under any circumstances.
6. Data Recipients & Sub-Processors
We share personal data exclusively with vetted service providers who act as Data Processors under binding Data Processing Agreements (Article 28 GDPR):
- Cloud Infrastructure & Hosting: Secure server facilities located inside the European Economic Area (EEA).
- Transactional Email Infrastructure: Certified delivery providers maintaining strict EU data privacy compliance.
- Payment Infrastructure: PCI-DSS certified financial gateways (e.g., Stripe).
- Legal & Accounting Advisors: Certified corporate accountants and legal counsels in Cyprus for compulsory tax compliance.
- Law Enforcement & Public Authorities: Solely when compelled by a valid court order, warrant, or statutory requirement under European or Cypriot law.
7. International Data Transfers
Your personal data is stored and processed on servers located within the European Economic Area (EEA). If a technical service requires data transfer to a provider operating outside the EEA, ESMIRA LTD ensures that transfers take place exclusively to jurisdictions granted an Adequacy Decision by the European Commission, or pursuant to Standard Contractual Clauses (SCCs) alongside supplementary technical encryption safeguards.
8. Technical & Organizational Security Measures
ESMIRA LTD implements state-of-the-art technical and organizational measures to safeguard personal data against destruction, loss, alteration, and unauthorized access:
- Transport Layer Security (TLS/SSL) encryption across all web traffic and API endpoints.
- Robust cryptographic password hashing (bcrypt/argon2) with zero plaintext credential storage.
- Strict role-based access management ensuring only authorized staff can review operational data.
- Web Application Firewalls (WAF), automated intrusion monitoring, and regular vulnerability patching.
- Encrypted daily database backups ensuring disaster recovery capabilities.
9. Your Rights Under GDPR
Under Articles 15–22 of the GDPR, you have the following enforceable rights:
- Right of Access (Article 15): Confirm whether your personal data is being processed and obtain a copy of that data.
- Right to Rectification (Article 16): Request correction of inaccurate personal data or completion of incomplete records.
- Right to Erasure / “Right to be Forgotten” (Article 17): Request deletion of your personal data when it is no longer necessary or when consent has been withdrawn.
- Right to Restriction of Processing (Article 18): Request that processing be temporarily limited under statutory conditions (such as while data accuracy is contested).
- Right to Data Portability (Article 20): Obtain your personal information in a structured, commonly used, and machine-readable format, or have it transmitted directly to another controller.
- Right to Object (Article 21): Object at any time, on grounds relating to your particular situation, to data processing based on legitimate interests.
- Right to Withdraw Consent (Article 7): Revoke previously granted consent at any time, without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise any of your data protection rights, submit a ticket via our Help Desk (/tickets/) or send a formal request to: mail@esmiraweb.com.
To protect account security and prevent unauthorized disclosure, we may request reasonable verification of your identity before processing requests. We respond to all requests within 30 days as prescribed by the GDPR.
10. Submitting a Complaint
If you are not satisfied with the way in which we handle (a complaint about) the processing of your personal data, you have the right to submit a complaint to the Data Protection Authority.
11. Policy Updates & Notifications
ESMIRA LTD may periodically update this Privacy Policy to reflect platform enhancements, operational changes, or statutory requirements. The effective revision date is always stated at the top of this document. Material updates will be communicated clearly through platform announcements or direct email notifications.