Privacy Policy

Effective Date: Effective Date: 20/02/2025


E.G.C. Olorin Services Ltd ("EGC Olorin," "we," "us," or "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share and protect personal data when you visit our website, egc-olorin.com (the "Website"), or use our services, in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the applicable data protection laws of the Republic of Cyprus.


1. Who We Are

The data controller responsible for your personal data is:

E.G.C. Olorin Services Ltd
15, Kalamatas Str., 3086 Limassol, Cyprus
Email: [info@egc-olorin.com]


For any questions about this Privacy Policy or how we handle your personal data, please contact us at [info@egc-olorin.com].


2. Our Services

EGC Olorin provides professional education and training, business consulting, payroll services, IT and cybersecurity services, and hospitality and corporate experiences. The personal data we process depends on how you interact with us.


3. Personal Data We Collect

A. Data you provide to us

  • Contact details: name, email address, phone number, company name and job title
  • Enquiry details: the information you include in messages sent through our contact form or by email
  • Training and course data: registration details, attendance records, assessment results and certificates issued
  • Client and contract data: billing details and information needed to deliver our services
  • Event and experience data: details needed to organise corporate events, tastings or team-building activities
  • Special requirements: where you choose to tell us about dietary requirements, allergies or accessibility needs (see Section 5)

B. Data collected automatically
When you visit the Website, our hosting provider automatically records technical information in server log files, including your IP address, browser type and version, operating system, referring URL, and the date and time of access. This data is used only to operate and secure the Website and is not combined with other data sources.

C. Cookies
Our Website does not use analytics, advertising or tracking cookies. We use only cookies that are strictly necessary for the Website to function, if any. These do not require your consent. If this changes, we will update this policy and request your consent where required.

4. Legal Basis for Processing

We process personal data only where we have a lawful basis under Article 6 GDPR:

  • Performance of a contract (Art. 6(1)(b)): to provide the services you request, including training, consulting, payroll and IT services, or to take steps at your request before entering into a contract
  • Legal obligation (Art. 6(1)(c)): to comply with tax, accounting, employment and regulatory requirements
  • Legitimate interests (Art. 6(1)(f)): to respond to enquiries, operate and secure our Website, prevent fraud and improve our services, provided these interests are not overridden by your rights
  • Consent (Art. 6(1)(a)): where we ask for your consent, for example for optional communications. You may withdraw consent at any time without affecting processing carried out before withdrawal

5. Special Category Data

Information about allergies, dietary needs or accessibility requirements may be considered health data. We collect this only when you provide it voluntarily for a specific event or course, and we process it only with your explicit consent (Art. 9(2)(a) GDPR) and only for that purpose. It is deleted once the event or course has concluded.

6. Contact Form

When you contact us through our Website's contact form, we collect the information you enter, such as your name, email address, phone number and message, to respond to your enquiry and any follow-up questions. Submissions are delivered to our business email account [hosted by: email provider]. We process this data on the basis of our legitimate interest in responding to enquiries, or to take steps before entering into a contract with you. We do not share this information with third parties for marketing purposes.

7. Payroll Services: Our Role as Processor

When we provide payroll services to a business, we process personal data of that business's employees on the client's behalf. In these cases, the client is the data controller and we act as a data processor under a written data processing agreement. Employees who have questions about their payroll data should contact their employer in the first instance.

8. How We Share Your Data

We do not sell or rent personal data. We share it only where necessary with:

  • Hosting provider: Namecheap, Inc., which hosts our Website and server log files
  • Service providers: trusted providers who support our operations, such as email, IT, accounting and payment services, under appropriate confidentiality and data protection obligations
  • Training funding bodies: where a course is subsidised, such as by the Human Resource Development Authority of Cyprus (HRDA), we may share participant and attendance data as required by the funding programme
  • Certification or awarding bodies: where needed to issue certificates or accreditations
  • Public authorities: where required by law, such as tax, social insurance or regulatory authorities, or by court order
  • Business transfers: in the event of a merger, acquisition or sale of assets, subject to the same protections

9. International Data Transfers

Namecheap, Inc. is based in the United States. Where personal data is transferred outside the European Economic Area, we ensure appropriate safeguards are in place, such as the European Commission's Standard Contractual Clauses or an adequacy decision, including the EU–US Data Privacy Framework where applicable. You may contact us to request more information about these safeguards.

10. Data Retention

We keep personal data only for as long as necessary for the purposes described in this policy:

  • Contact form enquiries: up to [12 months] after our last communication, unless the enquiry leads to a business relationship
  • Client and contract records: for the duration of the relationship and afterwards for the period required by Cypriot tax and accounting legislation
  • Payroll records: for the period required by Cypriot tax, social insurance and employment legislation, or as instructed by the client
  • Training records and certificates: for as long as required by certification bodies or funding programmes, and in any case no longer than [x years]
  • Server log files: for a limited period set by our hosting provider, for security purposes only

When data is no longer needed, we securely delete or anonymise it.

11. Data Security

We apply appropriate technical and organisational measures to protect personal data against unauthorised access, loss, alteration or disclosure, including encrypted (HTTPS) connections to our Website and access controls on our systems. However, no method of transmission over the internet is completely secure.

12. Your Rights

Under the GDPR, you have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data, subject to legal retention requirements
  • Restrict the processing of your data in certain circumstances
  • Object to processing based on our legitimate interests
  • Data portability: receive your data in a structured, machine-readable format
  • Withdraw consent at any time, where processing is based on consent

To exercise any of these rights, contact us at [info@egc-olorin.com]. We will respond within one month. We may ask you to verify your identity before acting on your request.

13. Right to Lodge a Complaint

If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the supervisory authority in Cyprus:

Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Cyprus
Tel: +357 22 818456
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy

14. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.

15. Third-Party Links

Our Website may contain links to third-party websites. We are not responsible for their privacy practices, and we encourage you to read their privacy policies.

16. Children's Privacy

Our services are intended for adults and businesses. We do not knowingly collect personal data from individuals under 18. If we become aware that we have done so, we will delete it promptly.

17. Changes to This Policy

We may update this Privacy Policy from time to time. The latest version will always be available on this page, with the updated effective date shown at the top.