1. Introduction

At Cyntrix AI ("we," "our," or "us"), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us in any way.

This policy complies with the General Data Protection Regulation (GDPR) and other applicable data protection laws in Cyprus and Greece.

2. Information We Collect

2.1 Information You Provide Directly

  • Contact Information: Name, email address, phone number, company name
  • Business Information: Industry, company size, location, project requirements
  • Communication Data: Messages, inquiries, and correspondence with us
  • Consultation Data: Information shared during consultations and assessments

2.2 Information Automatically Collected

  • Website Usage Data: Pages visited, time spent, browser type, device information
  • Technical Data: IP address, browser settings, operating system
  • Cookies and Tracking: Website preferences, session data, analytics

2.3 Information from Third Parties

  • Publicly available business information
  • Referral information from business partners
  • Social media interactions and profiles

3. How We Use Your Information

3.1 Primary Purposes

  • Service Delivery: Providing AI consulting and implementation services
  • Communication: Responding to inquiries and providing customer support
  • Business Analysis: Conducting process audits and creating automation strategies
  • Project Management: Managing and delivering your AI implementation projects

3.2 Secondary Purposes

  • Marketing: Sending relevant information about our services (with consent)
  • Website Improvement: Analyzing usage to enhance user experience
  • Legal Compliance: Meeting regulatory and legal obligations
  • Security: Protecting our systems and preventing fraud

4. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contract Performance: Processing necessary to fulfill our service agreements
  • Legitimate Interest: Business operations, security, and service improvement
  • Consent: Marketing communications and optional data collection
  • Legal Obligation: Compliance with applicable laws and regulations

5. Information Sharing and Disclosure

5.1 We May Share Information With:

  • Service Providers: Trusted third parties who assist in service delivery
  • Technology Partners: Cloud providers, software vendors, and integration partners
  • Professional Advisors: Legal, accounting, and consulting professionals
  • Regulatory Bodies: When required by law or legal process

5.2 We Do NOT:

  • Sell your personal data to third parties
  • Share data for advertising purposes without consent
  • Disclose confidential business information
  • Transfer data outside EU/EEA without adequate protection

6. Data Security

We implement comprehensive security measures to protect your information:

6.1 Technical Safeguards

  • SSL/TLS encryption for data transmission
  • Encrypted data storage and databases
  • Multi-factor authentication for system access
  • Regular security audits and vulnerability assessments

6.2 Organizational Safeguards

  • Access controls and role-based permissions
  • Employee training on data protection
  • Confidentiality agreements with staff and partners
  • Incident response and breach notification procedures

7. Data Retention

We retain your personal data only as long as necessary for the purposes outlined in this policy:

  • Active Clients: For the duration of our business relationship plus 7 years for legal compliance
  • Prospects: Up to 3 years from last contact, unless you request earlier deletion
  • Website Data: Analytics data for 2 years, cookies per your browser settings
  • Legal Records: As required by applicable laws and regulations

8. Your Rights Under GDPR

As a data subject, you have the following rights:

Access

Request a copy of the personal data we hold about you

Rectification

Correct inaccurate or incomplete personal data

Erasure

Request deletion of your personal data (right to be forgotten)

Restriction

Limit how we process your personal data

Portability

Receive your data in a machine-readable format

Objection

Object to processing based on legitimate interest

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.

9. Cookies and Tracking Technologies

9.1 Types of Cookies We Use:

  • Essential Cookies: Required for website functionality
  • Performance Cookies: Help us understand how visitors use our site
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Used to deliver relevant content (with consent)

9.2 Managing Cookies:

You can control cookies through your browser settings. Note that disabling certain cookies may affect website functionality.

10. International Data Transfers

Your data is primarily processed within the European Union. If we need to transfer data outside the EU/EEA, we ensure adequate protection through:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Binding Corporate Rules
  • Your explicit consent

11. Children's Privacy

Our services are designed for businesses and are not intended for individuals under 16 years of age. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will take steps to delete it promptly.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by:

  • Posting the updated policy on our website
  • Sending an email notification to registered users
  • Providing notice during your next interaction with our services

Your continued use of our services after any changes constitutes acceptance of the updated policy.

13. Contact Information

For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:

Postal Address

Cyntrix AI - Data Protection Officer
28 Oktovriou Street
Nicosia 1096, Cyprus

Phone

+357 99 123 456

Supervisory Authority

If you believe we have not handled your personal data in accordance with this policy, you have the right to lodge a complaint with the relevant supervisory authority:

  • Cyprus: Commissioner for Personal Data Protection
  • Greece: Hellenic Data Protection Authority