1. Introduction
At Cyntrix AI ("we," "our," or "us"), we are committed to protecting your privacy and personal data.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you
visit our website, use our services, or interact with us in any way.
This policy complies with the General Data Protection Regulation (GDPR) and other applicable
data protection laws in Cyprus and Greece.
2. Information We Collect
2.1 Information You Provide Directly
- Contact Information: Name, email address, phone number, company name
- Business Information: Industry, company size, location, project requirements
- Communication Data: Messages, inquiries, and correspondence with us
- Consultation Data: Information shared during consultations and assessments
2.2 Information Automatically Collected
- Website Usage Data: Pages visited, time spent, browser type, device information
- Technical Data: IP address, browser settings, operating system
- Cookies and Tracking: Website preferences, session data, analytics
2.3 Information from Third Parties
- Publicly available business information
- Referral information from business partners
- Social media interactions and profiles
3. How We Use Your Information
3.1 Primary Purposes
- Service Delivery: Providing AI consulting and implementation services
- Communication: Responding to inquiries and providing customer support
- Business Analysis: Conducting process audits and creating automation strategies
- Project Management: Managing and delivering your AI implementation projects
3.2 Secondary Purposes
- Marketing: Sending relevant information about our services (with consent)
- Website Improvement: Analyzing usage to enhance user experience
- Legal Compliance: Meeting regulatory and legal obligations
- Security: Protecting our systems and preventing fraud
4. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our service agreements
- Legitimate Interest: Business operations, security, and service improvement
- Consent: Marketing communications and optional data collection
- Legal Obligation: Compliance with applicable laws and regulations
5. Information Sharing and Disclosure
5.1 We May Share Information With:
- Service Providers: Trusted third parties who assist in service delivery
- Technology Partners: Cloud providers, software vendors, and integration partners
- Professional Advisors: Legal, accounting, and consulting professionals
- Regulatory Bodies: When required by law or legal process
5.2 We Do NOT:
- Sell your personal data to third parties
- Share data for advertising purposes without consent
- Disclose confidential business information
- Transfer data outside EU/EEA without adequate protection
6. Data Security
We implement comprehensive security measures to protect your information:
6.1 Technical Safeguards
- SSL/TLS encryption for data transmission
- Encrypted data storage and databases
- Multi-factor authentication for system access
- Regular security audits and vulnerability assessments
6.2 Organizational Safeguards
- Access controls and role-based permissions
- Employee training on data protection
- Confidentiality agreements with staff and partners
- Incident response and breach notification procedures
7. Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy:
- Active Clients: For the duration of our business relationship plus 7 years for legal compliance
- Prospects: Up to 3 years from last contact, unless you request earlier deletion
- Website Data: Analytics data for 2 years, cookies per your browser settings
- Legal Records: As required by applicable laws and regulations
8. Your Rights Under GDPR
As a data subject, you have the following rights:
Access
Request a copy of the personal data we hold about you
Rectification
Correct inaccurate or incomplete personal data
Erasure
Request deletion of your personal data (right to be forgotten)
Restriction
Limit how we process your personal data
Portability
Receive your data in a machine-readable format
Objection
Object to processing based on legitimate interest
To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days.
9. Cookies and Tracking Technologies
9.1 Types of Cookies We Use:
- Essential Cookies: Required for website functionality
- Performance Cookies: Help us understand how visitors use our site
- Functional Cookies: Remember your preferences and settings
- Marketing Cookies: Used to deliver relevant content (with consent)
9.2 Managing Cookies:
You can control cookies through your browser settings. Note that disabling certain cookies may affect website functionality.
10. International Data Transfers
Your data is primarily processed within the European Union. If we need to transfer data outside the EU/EEA,
we ensure adequate protection through:
- European Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules
- Your explicit consent
11. Children's Privacy
Our services are designed for businesses and are not intended for individuals under 16 years of age.
We do not knowingly collect personal data from children under 16. If we become aware that we have
collected such data, we will take steps to delete it promptly.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements.
We will notify you of any material changes by:
- Posting the updated policy on our website
- Sending an email notification to registered users
- Providing notice during your next interaction with our services
Your continued use of our services after any changes constitutes acceptance of the updated policy.
13. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact:
Supervisory Authority
If you believe we have not handled your personal data in accordance with this policy,
you have the right to lodge a complaint with the relevant supervisory authority:
- Cyprus: Commissioner for Personal Data Protection
- Greece: Hellenic Data Protection Authority