Published legal statement
B2B Data Processing Terms
Controller-processor terms for business projects involving personal data, subject to a completed processing schedule.
1. When these terms apply
These terms apply where a business customer acts as controller and Vistanova Global Ltd, trading as Tech Solutions Cyprus, processes personal data solely on documented instructions to deliver a digital or managed service. They do not apply to data we process as an independent controller for billing, security, legal compliance or our own customer relationship.
These terms must be completed by a project processing schedule stating the subject matter, duration, nature, purposes, data subjects, data categories, special-category data, security measures, authorised sub-processors, locations, return or deletion requirements and controller contacts. Production personal data should not be supplied until that schedule is agreed.
2. Instructions and compliance
We process personal data only on documented controller instructions, including agreed transfers, unless applicable law requires processing. If law permits, we will inform the controller of that requirement before processing. We will promptly notify the controller if an instruction appears to infringe applicable data-protection law.
The controller is responsible for the lawfulness, fairness and transparency of collection and instructions; legal bases; notices; rights handling; data accuracy; retention decisions; and ensuring that the service is appropriate for the sensitivity and risk.
3. Confidentiality and personnel
Access is limited to authorised persons who need it for the service and are bound by confidentiality. We maintain proportionate access control and security awareness appropriate to their roles.
4. Security
Taking account of current technology, implementation costs, scope, context, purposes and risk, we implement appropriate technical and organisational measures described in the processing schedule. Measures may include encryption in transit, access control, logging, backups, vulnerability management, environment separation and incident procedures.
The controller must use security features correctly, manage its users and credentials, avoid unnecessary data, maintain lawful backups and notify us of risk changes. No measure makes a system risk free.
5. Sub-processors
The controller gives the form of specific or general written authorisation stated in the processing schedule. Where general authorisation applies, we will provide reasonable advance notice of a material new sub-processor so the controller can object on reasonable data-protection grounds. Sub-processors must be bound by materially equivalent data-protection obligations. We remain responsible for our obligations to the controller as required by law.
6. International transfers
Personal data is transferred outside the EEA only on documented instructions and with a valid transfer mechanism where required, such as an adequacy decision or applicable European Commission Standard Contractual Clauses with necessary assessments and supplementary measures. The parties will complete and sign any required modules and annexes; this summary does not replace the official clauses.
7. Individual rights
Considering the nature of processing, we provide reasonable assistance through appropriate measures for access, correction, erasure, restriction, portability, objection and automated-decision requests. The controller remains responsible for responding. Additional work beyond ordinary product functions may be chargeable where permitted and agreed.
8. Incidents
We notify the controller without undue delay after becoming aware of a personal-data breach affecting controller data and provide available information reasonably needed for assessment and notification. Notification is not an admission of fault. The controller decides whether it must notify an authority or individual, unless law allocates the obligation differently.
9. Compliance assistance and audits
We provide information reasonably necessary to demonstrate compliance with applicable processor duties and assist with security, breach, impact-assessment and prior-consultation obligations, taking account of the service and available information. Audits must protect other customers, confidentiality and security, use existing independent reports first where suitable, occur on reasonable notice and avoid unnecessary disruption. Costs are allocated in the project agreement unless an audit identifies our material breach.
10. Return and deletion
At the end of processing, we return or delete personal data as chosen by the controller and stated in the schedule, unless law requires retention. Protected backups may remain until overwritten under the backup cycle and remain subject to these protections. Independent controller records are retained under our Data & Privacy Notice.
11. Priority, liability and termination
If these terms conflict with general service terms on personal-data processing, these terms prevail. Official Standard Contractual Clauses prevail where applicable. Liability follows the main agreement subject to mandatory GDPR allocation and data-subject rights. A material unresolved data-protection breach may permit suspension or termination.
12. Contact and completion requirement
Data-processing enquiries should be sent to info@techsolutionscyprus.com. These standard terms are not complete for a project until the processing schedule and any transfer annexes are filled in and accepted by authorised representatives.
Questions about this document?
Contact info@techsolutionscyprus.com. Please identify the document title and version shown above.