Published legal statement
Data & Privacy Notice
GDPR-aligned information about personal-data collection, purposes, legal bases, recipients, retention, transfers and individual rights.
1. Controller and contact
Vistanova Global Ltd, trading as Tech Solutions Cyprus, is the controller for personal data described in this notice unless we expressly act only as a processor for a business client. Registered address: 10 Iasonos, Kato Paphos, Apartment 17, 8041, Paphos, Cyprus. Privacy requests: info@techsolutionscyprus.com.
2. Scope
This notice covers visitors, prospective and current customers, account holders, service contacts, suppliers and people who communicate with us. It applies to the website, customer accounts, enquiries, chatbot conversations, service requests, collection and home visits, device work, project briefs, digital projects, quotations, invoices, payments, complaints and security records.
When a business client gives us personal data about its personnel or customers for a digital project, that client is normally the controller and we may act as processor under separate data-processing terms.
3. Data we collect
Depending on the interaction, we may collect:
- identity and contact details, including name, email, telephone, address, company and account identifiers;
- account and security data, including password hashes, verification state, sessions, login events, hashed network identifiers and audit records;
- service data, including device type, model, serial or asset identifiers, reported symptoms, access arrangements, photographs, files, diagnostic observations, repair history and status communications;
- digital-project data, including briefs, requirements, content, designs, domains, integrations, technical contacts and approvals;
- transaction data, including quotations, invoices, VAT information, payment status, processor references, refunds, receipts and accounting records;
- communications, consent records, complaints, support history and chatbot selections or transcript data where retention is clearly offered and accepted;
- technical data, including browser type, device information, request timestamps, security logs and strictly necessary cookies;
- optional marketing preferences and analytics data where valid consent is required and obtained.
We do not ask for passwords, payment-card numbers, private encryption keys or unnecessary sensitive data in ordinary chat, email or web forms. If a device may contain highly sensitive or special-category data, tell us before service so that safer handling can be agreed.
4. Sources
We collect data directly from you; from an authorised person or organisation acting for you; from systems, devices and accounts you authorise us to inspect; from payment, hosting, email, security and identity providers; and from public registers or sources where reasonably necessary to verify a business, protect legal rights or prevent fraud.
5. Purposes and legal bases
We process data only where a legal basis applies:
- steps requested before a contract and performance of a contract: enquiries, quotations, account functions, service delivery, project management, support and billing;
- legal obligations: tax, accounting, consumer, corporate, sanctions and regulatory records;
- legitimate interests: securing systems, preventing fraud and abuse, maintaining audit evidence, improving operations, recovering debts and establishing or defending legal claims, after considering individual rights;
- consent: optional marketing, non-essential analytics, transcript retention or another clearly identified optional purpose. Consent can be withdrawn without affecting earlier lawful processing;
- vital interests or legal claims in exceptional circumstances where recognised by law.
We do not use consent where processing is objectively necessary to perform a requested contract. Refusing optional consent does not prevent essential service delivery unless the information is genuinely necessary for that service.
6. Recipients and processors
Access is limited to authorised personnel and suppliers needing the data for their role. Recipients may include hosting and infrastructure providers, email-delivery and communications providers, security and anti-abuse services, payment processors, professional advisers, accountants, insurers, couriers, specialist subcontractors, domain or platform providers, app stores and public authorities where lawfully required.
Processors must be bound by appropriate confidentiality, security and data-processing terms. We do not sell personal data.
7. International transfers
Some suppliers or project platforms may process data outside the European Economic Area. Where required, we use a recognised safeguard such as an adequacy decision, approved Standard Contractual Clauses and supplementary measures, or a specific lawful derogation. Information about the relevant safeguard may be requested at info@techsolutionscyprus.com, subject to protection of confidential and security-sensitive information.
8. Retention
We keep data only as long as necessary for the stated purpose, legal compliance and claims. Typical periods are:
- unsuccessful general enquiries: normally up to 24 months after the last meaningful contact;
- customer accounts: while active and for a reasonable closure and legal-claims period afterward;
- service and project records: normally for the service relationship, warranty or support period and up to 6 years afterward where needed for contractual claims;
- invoices, receipts, tax and accounting records: normally at least the configured financial-retention period and any longer period required by law;
- security, rate-limit and audit logs: shorter risk-based periods unless needed to investigate misuse or preserve evidence;
- marketing data: until consent is withdrawn or the contact becomes inactive under our review process;
- cookie and analytics data: as listed in the Cookie Policy and provider controls.
Specific data may be kept longer where litigation, a complaint, fraud, a regulatory request or a legal hold applies. Backup copies are deleted or overwritten according to protected backup cycles.
9. Security
We use proportionate technical and organisational safeguards, including access controls, password hashing, session controls, encryption in transit, least-privilege permissions, rate limiting, audit records, backups and supplier review. No system is completely risk free. We maintain procedures to assess security incidents and notify the competent authority and affected individuals where the law requires.
10. Individual rights
Subject to conditions and exceptions in applicable law, you may request access, correction, erasure, restriction, portability and information about processing; object to processing based on legitimate interests or direct marketing; withdraw consent; and ask for human review of a significant decision made solely by automated means.
We may verify identity and authority before acting. We normally respond within one month, subject to lawful extensions for complex or numerous requests. Some data cannot be deleted immediately where retention is required by law, contract, security or legal claims.
11. Automated tools and chatbot
The chatbot is identified as an automated assistant. It recommends service routes and does not perform remote diagnosis or make legal or similarly significant decisions. Private account information requires authenticated access. Free text is minimised by default and conversation details are passed to staff only where the user chooses an available handoff and confirms the included information.
12. Cookies and analytics
Strictly necessary storage supports security, sessions and requested functions. Non-essential analytics or advertising technologies are not loaded until valid consent is obtained where required. Details and controls are in the Cookie Policy.
13. Children
Our services are intended for adults and organisations. A person under 18 should use the service only through a parent, guardian or authorised adult. We do not knowingly use children data for marketing or profiling.
14. Complaints
Contact info@techsolutionscyprus.com first so we can investigate. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus or another competent supervisory authority, particularly in the EU or EEA country of your habitual residence, work or alleged infringement.
15. Changes
We may update this notice to reflect services, suppliers or law. Material changes are dated and, where appropriate, brought to account holders attention. Earlier versions remain in our controlled revision history.
Questions about this document?
Contact info@techsolutionscyprus.com. Please identify the document title and version shown above.