GDPR Compliance |

GDPR Compliance

This website is not intended for children (individuals under 18 years old) and we do not knowingly collect data relating to children.

EXT LTD (“EXT”) and any of its dependent and fully-controlled affiliates and subsidiaries (“EXT Entities”), are strongly committed towards international compliance with data protection laws.  Ensuring data protection is the foundation of trustworthy business relationships and is the cornerstone of EXT’s reputation. The success of our business depends on our ability to maintain the trust of our clients. We would like to inform you about the type of information we gather, what we do with it and how you can correct or modify the information you entrust us with.

Scope

This Policy applies to EXT, EXT Entities and their employees and extends to all processing of personal data, relating to an identified or identifiable person. Anonymised or pseudonymised data is not subject to this Policy.

National Laws

This Policy comprises the accepted international and European data privacy principles without replacing existing national laws. It supplements national data privacy laws in each jurisdiction where EXT operates. The relevant national law will take precedence in the event of conflict with this Policy or where it has stricter requirements. The Policy must also be observed in the absence of corresponding national legislation.

Principles for Processing

All processing carried out by EXT or its employees shall be carried out in accordance with the principles enshrined in the GDPR, being the following:

  1. Fairness and lawfulness
  2. Limited to purpose of collection (Purpose Limitation)
  3. Transparency
  4. Data minimisation
  5. Storage Limitation & Deletion
  6. Factual accuracy
  7. Confidentiality and integrity of Personal Data
  8. Accountability

Data processing

Processing personal data is permitted only under the following legal bases. One of these legal bases is also required if the purpose of processing personal data is to be changed from the original purpose.

  1. Processing connected to contractual relationships:
    • DPersonal data of the clients can be processed to establish, execute or terminate a contract.
  2. Data processing for advertising purposes<
    • DPersonal data can be processed for advertising purposes or market and opinion research, provided that this is consistent with the purpose for which the data was originally collected. Providing data for this purpose is voluntary and data subjects have an absolute right to object to such processing.
  3. Consent to data processing
    • Data processing pursuant to legal authorisation
  4. Data processing pursuant to legitimate interests
    • Before data is processed on this basis, it is necessary to determine whether there are any data subject interests that merit protection and whether these override EXT’s legitimate interests.
  5. Processing of sensitive data
    • Sensitive personal data can be processed only if the law authorises it or the data subject has given explicit consent.
  6. User data and internet
    • Data subjects are informed of all personal data collected, processed and used on websites or in software or where user profiles (tracking) are created. Such may only be effected if permitted by law or with data subject consent.

Use of cookies

EXT uses cookies to collect information for record-keeping, comfort of use and website improvement and optimisation.

Disclosure of Data

EXT’s employees, directors, officers and representatives treat personal data as confidential and may not pass on or use any such data without valid legal grounds; as indicated under Section IV.

Transmission of Personal Data

Transmission of personal data to recipients by EXT, both internally or externally, is subject to the authorisation requirements and pursuant to defined purposes. Personal data transmitted to a recipient outside the EEA must be subject to protection at least equivalent to that sought by the GDPR. Intragroup transfers of personal data to third countries are subject to the safeguards provided by EXT’s Binding Corporate Rules (the “BCRs”).

Data Subject Rights

Every data subject has the following rights in relation to the processing of their personal data:

  1. Right of Access
  2. Right of Rectification
  3. Data Portability
  4. Right to Erasure
  5. Right to Restrict Processing
  6. Right to Object to Processing

A client who has any questions or concerns in this regard can contact the DPO as indicated in Section X

Security Measures

Personal data is safeguarded from unauthorised access and unlawful processing or disclosure, as well as accidental loss, modification or destruction; through state-of-the-art technical and organisational measures. These are adjusted and updated continuously in tandem with technical developments and organizational changes. Additionally, data protection audits and other controls are carried out on a regular basis.

Data Protection Officer (the “DPO”)

Data subjects may contact the EXT Data Protection Officer (the “DPO”) at dpo@ext.com.cy regarding any queries relating to issues of data protection, to exercise any of their rights indicated under Section VIII or to request a copy of the full EXT Data Protection Policy.

Created by professionals. For professionals.
Version 1.3.2