Personal Data Protection Policy

Contents / Definitions – Abbreviations

  1. Purpose and Scope.
  2. What is Personal Data?
  3. Who does the processing of Personal Data concern?
  4. What Personal Data does THINKCRM LTD collect?
  5. Why does THINKCRM LTD collect Personal Data?
  6. How does THINKCRM LTD process the Personal Data it collects?
  7. How long does THINKCRM LTD retain Personal Data?
  8. How secure is the Personal Data processed by THINKCRM LTD?
  9. To whom does THINKCRM LTD disclose Personal Data, and when?
  10. What are the rights of the Data Subject?
  11. How does THINKCRM LTD handle any Personal Data breaches?
  12. Who is THINKCRM LTD's Data Protection Officer?
  13. Corrections and Changes to the Personal Data Protection Policy.

Definitions – Abbreviations

Personal Data is any information relating to an identified or identifiable living natural person.

Data Controller means any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

Data Processor means any natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller.

Data Subject means the natural person to whom the data relates and whose identity is known or can be identified, directly or indirectly, by reference to an identification number or to specific factors characteristic of their physical, biological, mental, economic, cultural, political or social identity.

Processing means any operation or set of operations performed, whether or not by automated means, on Personal Data or on sets of Personal Data. Such operations may include: collection, recording, organisation, structuring, storage, adaptation/alteration, retrieval, consultation, use, transmission, dissemination/availability, alignment/combination, restriction, and erasure/destruction of Personal Data.

Consent of the Data Subject means a freely given, specific, informed and unambiguous statement/acceptance by the data subject, by which they agree that THINKCRM LTD may process their personal data.

  1. Purpose and Scope

This Personal Data Protection Policy concerns the processing of Personal Data by THINKCRM LTD, which faithfully applies the provisions of the applicable national legislation in force, as amended from time to time, as well as the provisions of Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation).

The protection of Personal Data is the responsibility of both the Board of Directors and the Management of THINKCRM LTD.

Compliance with this Policy applies to all staff of the company, including Management Executives and members of the Board of Directors.

Members of the Board of Directors and all Management Executives act as role models for compliance with this Policy.

 All Departments of the Organisation ensure that the staff under their responsibility comply with this Policy.

  1. What is Personal Data?

Personal Data is any information relating to an identified or identifiable living natural person.

An identified natural person is one whose identity has already been verified.

An identifiable natural person is one whose identity can be verified, directly or indirectly, through information such as:

name, identity card number, passport number, social insurance number, telephone number, geolocation data (GPS), photographs, fingerprints or other data relating to the physical, physiological, genetic, psychological, economic, cultural or social identity of the living natural person.

Aggregated data of a statistical nature, from which data subjects can no longer be identified, are not considered personal data.

  1. Who does the processing of Personal Data concern?

THINKCRM LTD processes Personal Data of natural persons, such as clients, partners, job candidates and existing staff, for lawful purposes.

The processing of Personal Data under this Policy does not concern legal persons such as companies, organisations, associations, foundations, government agencies and other legal entities.

  1. What Personal Data does THINKCRM LTD collect?

THINKCRM LTD collects the following Personal Data, or part thereof, depending on the case:

  1. Clients: full name, identity card number and/or passport number and/or foreign national number and copies thereof, telephone number, postal address, email address and business premises address, etc.
  1. Partners: full name, identity card number and/or passport number, telephone number, fax number, postal address, email address, VAT number, CVs, and other data.
  1. Staff: full name, identity card number and/or passport number, Social Insurance number, birth certificate, telephone number, postal address, email address and business premises address, clean criminal record certificate, military discharge certificate, photographs, copies of academic and professional qualifications, medical data, salary and career progression data, performance evaluations, IBAN, and other data.
  1. Job candidates: full name, identity card number and/or passport number, Social Insurance number, birth certificate, telephone number, postal address, email address and business premises address, occupation, military discharge certificate, copies of academic and professional qualifications, and other data.
  1. Why does THINKCRM LTD collect Personal Data?

THINKCRM LTD collects Personal Data for the following categories of natural persons for the following purposes:

  1. Clients: For the provision of services and goods.
  1. Partners: To achieve the objective of the partnership.
  1. Staff: To achieve the objective of employment.
  1. Job candidates: For the purpose of evaluating the job application against the criteria of the relevant position.
  1. How does THINKCRM LTD process the Personal Data it collects?

THINKCRM LTD processes Personal Data:

(a) to the extent necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract.

(b) to the extent necessary for the pursuit of its legitimate interests.

(c) for the purpose of complying with the Legislation, or

(d) where it has obtained explicit consent through the signing of the Personal Data Processing Consent Form.

  1. By what means does THINKCRM LTD collect Personal Data?

The above-mentioned natural persons, or "data subjects", provide their Personal Data to THINKCRM LTD, either themselves, through their authorised representatives, or through the transfer of Personal Data from a competent authority, by the following means: 

  • By letter or application in printed form.
  • By electronic means (email, website, Wi-Fi, software applications, GPS, video cameras, and other means).
  • Verbally and through telephone communication.
  1. How long does THINKCRM LTD retain Personal Data?

THINKCRM LTD retains personal data for as long as required for its lawful processing, and specifically:

For as long as the cooperation and/or employment with the data subjects continues and it is necessary to fulfil the purposes for which the data were collected, or for the period during which liability could arise from the processing, in accordance with the applicable legislation, unless, once those purposes cease to apply, retention is required by law, e.g. for tax reasons. Data is additionally retained until its deletion is requested, or, where it is retained and processed on the basis of consent, until that consent is withdrawn, or until the right to object to its processing is exercised.

In determining the retention period of your personal data, the nature of the data, its volume, the purpose of its processing, its security, etc. are taken into account.

There is also the right to request the deletion of the data.

  1. How secure is the Personal Data processed by THINKCRM LTD?

THINKCRM LTD faithfully applies the provisions of Regulation 2016/679 and takes appropriate technical, organisational and administrative measures to ensure the protection of the personal data it processes against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, or any other form of unlawful processing.

All personal data in electronic form is securely stored and further protected through the use of appropriate access controls.

Documents in printed and electronic form containing personal data are destroyed in a non-recoverable manner, where required.

  1. To whom does THINKCRM LTD disclose Personal Data, and when?

THINKCRM LTD discloses Personal Data in the following cases:

 To a natural or legal person, public authority, agency or other body that THINKCRM LTD has:

  • Assigned to carry out the processing of personal data on its behalf.
  • To a natural or legal person, public authority, agency or other body where required by any Legislation, court decision, or decision of a competent authority.

Except as stated above, THINKCRM LTD does not disclose or publish personal data to any third party without informing the data subject and, where required, obtaining their prior consent.

  1. What are the rights of the Data Subject?

The Data Controller must inform the Data Subject (the individual to whom the data relates) of their rights.

The Regulation grants several rights to the Data Subject, such as: 

Right to be Informed (Article 12): The data subject has the right to concise, transparent, intelligible and easily accessible information, without delay, and in any case a response within one month of receipt of the request.

If the data subject's requests are manifestly unfounded or excessive, in particular because of their repetitive nature, THINKCRM LTD may refuse to act on the request. 

Right to be Informed when Obtaining Consent (Articles 13 & 14): When obtaining consent, THINKCRM LTD informs the Data Subject of the purposes for collecting the Personal Data, the processing period, their rights, the categories of data, and the source of any data not collected directly from THINKCRM LTD. 

Right of Access (Article 15): The data subject has the right to obtain a copy of their data and to be fully informed about their data, the purposes of processing, the categories of data, the retention period and the criteria used to determine it, the recipients to whom the data has been disclosed, and its origin if not collected directly from THINKCRM LTD.

Right to Rectification (Article 16): The data subject has the right to request the correction  or completion of inaccurate personal data, and to have their request fulfilled without undue delay.

Right to Erasure (Article 17): The data subject has the right to request the deletion of their data, and to have their request fulfilled without delay, unless the Data Controller has an overriding legitimate interest.

Right to Restriction of Processing (Article 18): The data subject has the right to request the restriction of processing when the accuracy of the data is contested, or where the processing is unlawful or no longer necessary. 

Right to Notification (Article 19): The Data Controller notifies each recipient to whom the data has been disclosed of any rectification, erasure or restriction of processing, and informs the Data Subject accordingly.

Right to Data Portability (Article 20): The data subject has the right to receive their Data in a digital format and to transmit it to another organisation, or to request its direct transmission to another organisation.

Right to Object (Article 21): Processing stops following an objection, unless the Data Controller has an overriding legitimate interest. 

Right Not to be Subject to Automated Individual Decision-Making (Article 22): The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.

The Data Subject has the right to lodge a complaint with the Commissioner for Personal Data Protection at any time, if they believe that any of their rights have been violated.

The Data Subject also has the right to withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Where THINKCRM LTD, as Data Controller of Personal Data, has a legitimate interest in retaining the Personal Data concerning them, their request for withdrawal and/or deletion may not be accepted.

  1. How does THINKCRM LTD handle any Personal Data breaches?

It reports, in full detail, any breaches and/or violations to the Commissioner for Personal Data Protection within 72 hours of becoming aware of the breach/violation.

It informs the Data Subject (natural person) when there is a high risk to their rights and freedoms.

  1. Who are the Data Controller and the Data Processor?

 The Data Controller is THINKCRM LTD.

The Data Processor is any natural or legal person, public authority, agency or other body that processes personal data on the  instructions of the company.

  1. Who is THINKCRM LTD's Data Protection Officer?

 In accordance with Regulation 2016/679, THINKCRM LTD has appointed a Data Protection Officer (DPO) who is duly and promptly involved in all matters relating to the protection of personal data. Data subjects may contact the Data Protection Officer regarding any matter related to the processing of their personal data and the exercise of their rights, in accordance with Regulation 2016/679.

The DPO's contact details are also published on the THINKCRM LTD website.

You can contact the DPO at: 49 Panagias Evangelistrias, Kato Polemidia, 4156, Limassol, Cyprus, or by email at info@thinkcrm.net

  1. Corrections and Changes to the Personal Data Protection Policy

THINKCRM LTD reserves the right to revise this Personal Data Protection Policy whenever it deems necessary. You are therefore encouraged to review it periodically. The latest version of this Policy is always published on the THINKCRM LTD website.

 

Privacy and Personal Data Protection Statement

For us at THINKCRM LTD, protecting the Personal Data of our clients and respecting individuals' privacy online is a fundamental commitment. We take all necessary organisational and technical measures required to ensure the security, availability and integrity of our users' and clients' data.

It is very important to us that this strong commitment is clear to all clients and users of our services. For this reason, we have created this "Privacy – Personal Data Protection Statement", which describes and explains what kind of personal data we collect, how we manage it, and how it may be used.

THINKCRM LTD builds software and provides internet services, consulting support, information and training for businesses as well as individuals. This statement applies to all of the software products and services we provide.

Personal data we collect

THINKCRM LTD collects and processes data solely for the purposes of its lawful and proper operation and to offer its clients and internet users the best possible user experience. Some of this data is provided directly by our clients or the users of our online services, for example, when a new user registers for one of our services or when a client submits a support request. Some data is recorded indirectly, and this recording depends on how users use our software products or online services. Data is thus recorded when technologies such as cookies are used, or when error reports or usage statistics are received from our software products for the purpose of diagnosing problems or improving them. In every case of data collection or transmission, this is preceded by clear and explicit acceptance on the part of the user through an appropriate user interface element.

The data we collect may include the following:

  • Name and contact details. We collect our users' first and last names, email address, postal address, telephone number, and other similar contact details.
  • Credentials. We collect passwords, password hints, and similar security information used for authentication and access to our services.
  • Payment data. We collect data necessary to process our clients' payments when they make purchases, such as the payment method number (e.g. credit card number), as well as the security code associated with the payment method.

We collect data relating to the product or service used by the client or user and how they interact with it. For example:

  • Product usage data. We collect anonymous data about the features used by users of our products and our online and other services.
  • Error reports and performance data. We collect information about the performance of our software, as well as any problems users encounter with it. This data helps us diagnose product issues, improve our products, and provide solutions.
  • Troubleshooting and support data. When clients contact THINKCRM LTD for troubleshooting and support, we collect data about the client as well as other details relating to the incident. This data includes contact or authentication data, the content of conversations and other communications with THINKCRM LTD, data about the state of the machine and application at the time the error occurred and during diagnostic checks, as well as system and registry data relating to software installations and hardware configuration settings.

Cookies and Similar Technologies

THINKCRM LTD uses cookies (small text files placed on your device) and similar technologies and services that use your IP address to deliver its websites, mobile applications and electronic services. Among other things, cookies allow us to store your preferences and settings, allow you to log in, provide interest-based advertising, provide notifications, help combat fraud, and also allow us to analyse the performance of our websites and electronic services. For these purposes, we also use services such as Google Analytics, Google Firebase and OneSignal, which are fully compliant with the GDPR.

We also use web beacons to deliver cookies and to collect usage and performance data. Our websites may also include web beacons and cookies from third-party service providers.

You have a variety of tools available to control cookies, web beacons and other similar technologies, such as browser controls for blocking and deleting cookies, and opt-out controls offered by certain third-party analytics providers for excluding data collection via web beacons and similar technologies. Your browser and other settings may affect your experience with our products.

Use of Personal Data

THINKCRM LTD uses the data it collects solely for the following purposes:

  • To conduct its business activities and to provide (including improving and personalising) the products and services it offers.
  • To send communications, including promotional material by email or telephone (marketing, offers, etc.).

We do not share the data we collect with legal or natural persons except with the client's consent, for the completion of any transaction, or for the provision of a service; for example, payment data required to complete a purchase will be shared with banks and other entities that process payment transactions or provide other financial services, and for the purposes of fraud prevention and credit risk reduction.

Finally, we may access, transfer, disclose and retain personal data when we believe in good faith that this is necessary for the following reasons:

  • To comply with applicable law or to respond to a valid legal process, which may also originate from police authorities or other government agencies.
  • To operate and maintain the security of our products, including preventing or stopping an attack on our computer systems or networks, or to protect the rights or property of THINKCRM LTD.

Processing period of Personal Data

The storage and processing of the data of our clients and service users is carried out solely as permitted by law or in accordance with the users' explicit consent, only for as long as necessary to fulfil the purposes of the processing (as defined above), or until the user objects to the use of their Personal Data by THINKCRM LTD, or until they withdraw their consent. However, whenever required by mandatory law, THINKCRM LTD will retain Personal Data for a longer period, or whenever Personal Data is required in order for THINKCRM LTD to assert or defend itself against legal claims.

Place of data processing

THINKCRM LTD is headquartered in Limassol, and therefore all processing carried out at our premises takes place within the territory of Cyprus. To provide better services, THINKCRM LTD uses cloud infrastructure at Cypriot data centres and on Microsoft Azure. In the case of Microsoft Azure, only data centres within the European Union are used.

How to access and control your personal data

Users of THINKCRM LTD's products and services may, at any time, request information about their Personal Data from THINKCRM LTD, as well as request its correction or deletion. THINKCRM LTD may delete the data only if there is no legal obligation or other legitimate right for it to retain them. Naturally, if a user's data is deleted, THINKCRM LTD will not be able to continue providing its services to that user where such services require the use of that data.

Where THINKCRM LTD uses personal data based on the user's consent or in order to enter into a contract with them, the user may request a copy of their personal data.

Finally, users may ask THINKCRM LTD to restrict any processing of their Personal Data in the following cases:

  • The Personal Data held by THINKCRM LTD is incorrect.
  • There is no legal basis for THINKCRM LTD to process the Personal Data, and the user requires that its processing be restricted.

For any request or clarification needed, users may contact us via the email address below, specifying the information or processing activities related to their request, the format in which they would like that information, and whether the Personal Data should be sent to them or to another recipient. The request will be carefully reviewed, and we will discuss with the user the best way to fulfil it.

Contact information

The Controller of Processing is THINKCRM LTD, address: 49 Panagias Evangelistrias, Kato Polemidia, 4156, Limassol, Cyprus, tel. 25251948, or you can contact us by email at info@thinkcrm.net

Changes to this policy

THINKCRM LTD may amend this Personal Data Protection Statement from time to time in order to reflect current personal data protection practices. When we make changes to this statement, we will update the "last updated" date at the bottom of this page. We encourage you to review this Personal Data Protection Statement periodically in order to stay informed about how THINKCRM LTD protects your data.

Questions about this policy and its application

THINKCRM LTD is committed to protecting your personal data online. If you have any questions or comments regarding how we manage your personal data, please contact us at the address and details listed above, under contact information. You may also use this address to notify us of any concerns you may have regarding our compliance with our Online Personal Data Protection Statement.

 

footer-seperator

THINKCRM © . All Rights Reserved.