Privacy Policy

Last updated: 12 August 2026

1. Data controller
GISA23 LTD, registration number HE 448879, registered office at 12 Demostheni Severi, Office 601, 1080 Nicosia, Cyprus, is the controller of personal data collected through this website.

Contact for any privacy matter: gisa23ltd.cy@gmail.com

2. What data we collect
Data you provide to us. If you contact us by email or through the contact form on this website, we process the information you choose to send us — typically your name, email address, telephone number and the content of your message.

Technical data. Our hosting provider records standard server log data, including IP address, browser type, operating system, referring page and time of access. This data is generated automatically by the operation of the website.

We do not operate user accounts or user registration on this website. We do not knowingly collect data from children.

3. Why we process it and on what basis
Responding to your enquiry and pre-contractual discussions — steps taken at your request prior to entering into a contract, Article 6(1)(b) GDPR.
Performing a development agreement — performance of a contract, Article 6(1)(b) GDPR.
Security, integrity and operation of the website — our legitimate interests, Article 6(1)(f) GDPR.
Compliance with accounting, tax and other legal obligations — legal obligation, Article 6(1)(c) GDPR.
4. Cookies
This website uses only cookies strictly necessary for its operation. We do not use advertising cookies and do not sell data to third parties.

Where any non-essential cookies or analytics are used, they are deployed only with your consent, which you may withdraw at any time. Most browsers allow you to block or delete cookies through their settings.

5. Who we share data with
We do not sell or rent personal data.

Data may be accessed by service providers acting on our behalf under written agreements, in particular our hosting and email providers. We may also disclose data where required by law or by a competent authority.

6. International transfers
Where a service provider processes data outside the European Economic Area, such transfers are made on the basis of an adequacy decision or appropriate safeguards, including the European Commission’s Standard Contractual Clauses.

7. Retention
Enquiry correspondence is retained for as long as necessary for the purpose for which it was sent, and thereafter for as long as required to establish, exercise or defend legal claims. Records relating to contracts and accounting are retained for the periods prescribed by Cyprus law. Server logs are retained for a limited period for security purposes.

8. Your rights
Under the GDPR you have the right to request access to your personal data, its rectification or erasure, restriction of processing, portability, and to object to processing carried out on the basis of legitimate interests. Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at gisa23ltd.cy@gmail.com. We will respond within one month.

9. Complaints
If you consider that we have not handled your personal data properly, you may lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy), or with the supervisory authority of your country of residence.

10. Security
We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss or disclosure. No method of transmission over the internet is entirely secure, and we cannot guarantee absolute security.

11. Changes to this policy
We may update this policy from time to time. The date of the most recent update is shown at the top of this page.