Privacy policy

Dabart values your personal and confidential information. We are committed in protecting the information with adequate protection and use it only for the purposes stipulated in this Privacy Policy. This Privacy Policy will help you understand what personal data is collected and processed, how its protected, how we use it and what rights are made available to you regarding your personal data.

This Privacy Policy explains how the Company (collectively, with its subsidiaries and affiliates, ‘we’, ‘us’, ‘our’) a Company incorporated under the laws of the Republic of Cyprus with registration number HE455392, being a Data Controller, collects and processes your personal information, i.e. information collected online and offline, in accordance with the General Data Protection Regulation (2016/679) and the applicable Data Protection Laws of the Republic of Cyprus (‘the Law’).

The kind of information we collect about you:

The purpose of the Processing of your Personal Data is largely based on each of our services that you have requested, used or intend to use:

  • Information provided when submitting to ‘Get a Quote’ or contacting us through our website e.g. Name, Email Address
  • Information gathered from your use of our website or through Google Analytics, by using cookies e.g. IP Address, Mobile Device Id, Referral Source, Page Views
  • Information gathered from transactions and agreements between us for providing our services and implementing our services e.g. VAT number, Name, Address, ID, Biography

We do not collect or process Personal Data of children.

Who Receives your Personal Data:

Your Personal Data may sometimes be shared or made accessible to the following Third Parties in order for us to perform our services to the highest standard possible:

  1. Employees or affiliates or partners that need access to fulfill the purposes set out above;
  2. Service providers, including but not limited to IT service providers that support our services;
  3. Payment Service Providers.

In case of an absence of your consent, your Personal Data will not be disclosed to any Third Party, other than the above-mentioned, unless the disclosure is required and/or mandatory under the provisions of any legislation, regulation or upon governmental, supervisory, competent authority request.

Our employees have signed a Confidentiality and Non – Disclosure Agreement.

When we enter into agreement with a Third Party that requires your Personal Data to be processed by that Third Party, we enter into a processing agreement with that party in order to ensure that they process the Personal Data strictly according to our instructions and to implement the appropriate administrative, physical and technical measures to protect the Personal Data from unauthorized or accidental use, collection, access, damage, loss or disclosure.

Transferring your Personal Data outside European Union (‘EU’) and European Economic Area (‘EEA’):

We generally do not transfer your Personal Data to countries outside of EU and EEA (‘Third Countries’), except where required by the purposes set out in this Policy. If we need to transfer any Personal Data to Third Countries, we always ensure that the transfer meets the relevant requirements of the Law and we take all steps required to ensure that your Personal Data continues to receive our standards of protection.

Retention of Personal Data:

We will cease to retain your Personal Data or remove the means by which the Personal Data can be associated with you, after seven years (7) where your relationship with us has been terminated and/or as soon as it is reasonable to assume that such retention no longer serves the purposes for which the Personal Data were collected and are no longer necessary for legal or business purposes (except where retention is permitted or required by the Law and/or other applicable laws).

Protection of Personal Data:

To safeguard your Personal Data from unauthorized access, collection, use, damage, loss, disclosure, copying or similar risks, we have introduced appropriate administrative, physical and technical measures such as up to date antivirus protection, encryption and the use of privacy filters to secure all storage and transmission of Personal Data to Third Parties. We also allow access to Personal Data only to those employees who need to know such data and they will only process your Personal Data on our instructions.

However, no method of transmission over the internet or method of electronic storage is completely secure. While security cannot be guarantee, we try to protect the security of the Data Subject’s Personal Data and we constantly review and enhance our information security measures.

Your rights in relation to your Personal Data:

Right to access

Request access to your Personal Data, this enables you to receive a copy of your Personal Data that we hold about you.

Right to rectification

Request to correct or update any of your Personal Data which we hold.

Right to data portability

Request the transfer of your Personal Data to another party.

Right to erasure

Request to delete your Personal Data. However, we may need to retain certain information for legal or administrative purposes, such as record keeping and detect fraudulent activities.

Right to restrict processing

Request to restrict the use of your Personal Data.

Right to object

You have the right to object to the collection and use of your Personal Data.

Right to lodge a complaint

You have the right to lodge a complaint about the use of your Personal Data by contacting the Office of the Commissioner for Personal Data Protection in Cyprus at the contact details below:

Office address: Iasonos 1, 1082 Nicosia, Cyprus

Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus

Tel: +357 22818456

Fax: +357 22304565

Email: commissioner@dataprotection.gov.cy

If you wish to exercise any of your rights, you may contact our team in writing via email at the contact details provided below, with email subject GDPR:

 info@dabartshop.com

The Data Protection Officer has the right to require the individual making the request to provide certain identification documents/information to be able to verify his/her identity.

The Data Protection Officer will respond to your requests within thirty (30) days after receiving your email/letter.

Effect of Policy and Changes to Policy:

We keep this Policy under review, and we may modify it from time to time without any prior notice. You should review our Policy on our website periodically to ensure that you are aware of any such modifications/updates.