Privacy Policy
Privacy policy and personal data information for SynEnergia Ltd.
Personal Data Protection Policy
Version: May 2020
This Personal Data Protection Policy explains how SynEnergia Ltd (the Company, SynEnergia, or the Data Controller) processes personal data relating to individuals, including customers, intermediaries, third parties with whom the Company has a relationship, and individuals connected with those persons.
This policy has been prepared by the Company in line with applicable legislation in the Republic of Cyprus and Regulation (EU) 2016/679, the General Data Protection Regulation (GDPR), as amended from time to time.
What GDPR Is
The General Data Protection Regulation sets rules for the protection of natural persons with regard to the processing of personal data and the free movement of such data. It protects fundamental rights and freedoms, especially the right to protection of personal data.
Who We Are
SynEnergia Ltd is an energy company based in Limassol, Cyprus. Our aim is to protect the confidentiality of the personal data entrusted to us.
This policy explains what personal data is, how it may be collected by the Company, why it may be processed, how it is protected, and the rights available to individuals.
What Personal Data Is
Personal data is information relating to an identified or identifiable living individual. Different pieces of information which, when combined, can identify a specific person also constitute personal data.
An identifiable living individual may be identified directly or indirectly through information such as:
- name and surname;
- identification numbers, such as social insurance, identity card, or passport numbers;
- bank card identifiers;
- location data, such as a residential address or mobile-device location;
- internet protocol address or email address; and
- data held by a hospital or doctor that could uniquely identify an individual.
How We Collect Personal Data
The Company receives personal data mainly through information provided directly to us, or through information provided by third parties. Personal data may be collected, for example:
- when you become, or contact us to become, a customer of the Company;
- when you register or communicate with us through our social media accounts or websites;
- when you request a quotation for our products or services;
- when you subscribe to a newsletter;
- from legal persons with whom we maintain a professional relationship;
- from our service providers or subcontractors;
- from publicly available sources, including online sources, newspapers, and media; and
- from the Department of Registrar of Companies and Intellectual Property.
Why We Process and Share Personal Data
We may process and disclose personal data where necessary to fulfil our obligations, provide requested services, manage our business relationship, comply with legal or regulatory requirements, or protect legitimate business interests.
Personal data may be disclosed to third parties where necessary, including competent authorities, service providers, legal advisers, government bodies, banks or financial institutions, Company personnel, and external consultants. Such disclosure is limited to what is necessary for the relevant purpose.
We take reasonable steps to ensure that personal data is accessible only to persons who need access for the purposes described in this policy. Except as expressly stated in this policy, or where prior consent has been obtained, personal data collected from an individual will not be disclosed to third parties outside the circumstances described above.
Data Retention
The Company keeps personal data for as long as the contractual or professional relationship remains active and/or until the end of the applicable retention period under the laws of the Republic of Cyprus. A longer retention period may be required where legal action, investigation, or regulatory issues arise in connection with the Company’s products or services.
As a general rule, a ten (10) year period may apply under the Limitation of Actions Law 2012-2017.
Where no contractual or professional relationship has been established and the individual remains a prospective customer, the retention period is one (1) year from the date of the first written communication.
Supplier personal data and other data required for accounting records may be retained for seven (7) years, as provided by applicable tax legislation.
Employee personal data may be retained until the employee reaches the age of eighty-five (85), in accordance with applicable state archives legislation.
Personal data of unsuccessful job applicants may be retained for twelve (12) months after the recruitment process, or for one (1) year after the conclusion of any related legal proceedings or legal settlement.
How We Protect Personal Data
The Company takes appropriate physical and electronic measures to comply with GDPR requirements and to protect personal data. We aim to apply high standards of privacy conduct, security, and communication.
Employees who handle personal data receive appropriate training and are bound by confidentiality obligations, including non-disclosure obligations relating to sensitive information belonging to third parties.
Legal Basis
Unless otherwise stated when personal data is collected, the legal basis for processing may include:
- processing necessary for the performance of a contract or professional relationship with the Company under Article 6(1)(b) GDPR;
- processing necessary for the legitimate interests of the Company under Article 6(1)(f) GDPR; and
- explicit consent for the processing of personal data under Article 6(1)(a) GDPR.
Your Rights
Under GDPR, individuals may have rights including the right to information, access, rectification, erasure, restriction of processing, notification, data portability, objection, withdrawal of consent, and the right not to be subject to certain automated individual decision-making. Individuals also have the right to submit a complaint to the competent supervisory authority.
The Company may request proof of identity before responding to a rights request.
To exercise any of these rights, send a written request to legal@synenergia.com.cy , addressed to the Company’s Data Protection Officer. The Company may ask security questions to confirm that the requester is the person to whom the data relates.
Where consent is withdrawn but the Company has a legitimate interest or legal obligation to retain the relevant data, the Company may be entitled to refuse deletion or continued withdrawal-related action to the extent permitted by law.
The Company aims to respond to such requests within thirty-five (35) calendar days.
Personal Data Breaches
Where required by law, the Company will notify the Commissioner for Personal Data Protection of a personal data breach within seventy-two (72) hours after becoming aware of it. The Company will also notify affected individuals where the breach is likely to result in a high risk to their rights and freedoms.
Changes to This Policy
The Company keeps this policy under review to comply with applicable personal data protection laws. You are advised to review this policy periodically for changes.
This policy was last amended on 1 May 2020.
Contact
Questions about this Privacy Policy or requests relating to personal data should be addressed to the Company’s Data Protection Officer at legal@synenergia.com.cy , or by calling +357 25 248630 and asking to speak with the Data Protection Officer.