We rely on third parties, for example, to provide you our Website (such as a hosting provider). These third parties are only allowed to process your personal data on our behalf and upon our explicit written instruction. We also warrant that all those third parties are selected with due care and are committed to observing the safety and integrity of your personal data.
We may be legally obliged to share your personal data with competent law enforcement agents or representatives, judicial authorities, governmental agencies or bodies, including competent data protection authorities, to comply with a legal obligation.
Your data are exclusively processed within the territory of the Republic of Cyprus.
We do our utmost best to process only those personal data which are necessary to achieve the purposes listed under Article 3 above.
Your personal data are only processed for as long as needed to achieve the purposes listed under Article 3 above. We will de-identify your personal data when they are no longer necessary for the purposes outlined in Article 3 above, unless there is:
- An overriding interest of HIO or any other third party, in keeping your personal data identifiable; or
- A legal or regulatory obligation or a judicial or administrative order that prevents us from de-identifying them.
We will take appropriate technical and organizational measures to keep your personal data safe from unauthorized access or theft as well as accidental loss tampering or destruction. Access by our staff members or third parties’ personnel will only be on a need-to-know basis and be subject to strict confidentiality obligations. You understand, however, that safety and security are best efforts obligations, which can never be guaranteed.
7 What are your rights?
You have the right to request access to all personal data processed by us pertaining to you. We reserve the right to charge a reasonable administrative fee for multiple subsequent requests for access that are clearly submitted for causing nuisance or harm to us. Each request must specify for which processing activity you wish to exercise your right to access and must specify to which data categories you wish to gain access to.
You have the right to rectification, i. e. to ask that any personal data pertaining to you that are inaccurate, are corrected free of charge. If you submit a request for correction, your request needs to be accompanied of proof of the flawed nature of the data for which correction is asked.
You have the right to withdraw your earlier given consent for processing of your personal data.
You have the right to erasure, i. e. to request that personal data pertaining to you be deleted if these data are no longer required in the light of the purposes outlined in Article 3 above. However, you need to keep in mind that a request for deletion will be evaluated by us against:
- Our and a third parties’ interests which may override your interests; or
- Legal or regulatory obligations or administrative or judicial orders which may contradict such deletion.
You have the right to restriction instead of deletion, i. e. to request that we limit the processing of your personal data if:
- We are verifying the accuracy of your personal data; or
- The processing is unlawful and you oppose the deletion of your personal data; or
- You require your personal data to establish, exercise or defend a legal claim, while we no longer need your personal data for the purposes listed under Article 3 above; or
- We are verifying whether our legitimate interests override your interests if you exercise your right to object in accordance with Article 7.6.
You have the right to object to the processing of personal data if:
- The processing is based on our legitimate interest under Article 3 above; and
- You are able to prove that there are serious and justified reasons connected with your particular situation that warrant such objection; and
- Our legitimate interests do not override your interests.
However, if the intended processing qualifies as direct marketing, you have the right to object to such processing free of charge and without justification.
You have the right to data portability, i. e. to receive from us in a structured, commonly-used and machine-readable format all personal data you have provided to us if the processing is based on your consent or a contract with you under Article 3 above.
If you wish to submit a request to exercise one or more of the rights listed above, you can contact our Data Protection Officer by sending an e-mail email@example.com. An e-mail requesting to exercise a right, will not be construed as consent with the processing of your personal data beyond what is required for handling your request. Such request should meet the following conditions:
- State clearly which right you wish to exercise; and
- State clearly the reasons for exercising your right if such is required; and
- Your request should be dated and signed; and
- Your request should be accompanied by a digitally scanned copy of your valid identity card proving your identity. If you use the contact form, we may ask you for your signed confirmation and proof of identity.
We will promptly inform you of having received your request. If the request meets the conditions above and proves valid, we will honor it as soon as reasonably possible and at the latest thirty (30) days after having received your request.
If you have any complaints regarding the processing of your personal data by us, you may always contact our Data Protection Officer by sending an e-mail to firstname.lastname@example.org. If you remain unsatisfied with our response, you are free to file a complaint with the competent data protection authority.