Personal Data is any information relating to an identified or identifiable living natural person.
Data Controller means any natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
Data Processor means any natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller.
Data Subject means the natural person to whom the data relates and whose identity is known or can be identified, directly or indirectly, by reference to an identification number or to specific factors characteristic of their physical, biological, mental, economic, cultural, political or social identity.
Processing means any operation or set of operations performed, whether or not by automated means, on Personal Data or on sets of Personal Data. Such operations may include: collection, recording, organisation, structuring, storage, adaptation/alteration, retrieval, consultation, use, transmission, dissemination/availability, alignment/combination, restriction, and erasure/destruction of Personal Data.
Consent of the Data Subject means a freely given, specific, informed and unambiguous statement/acceptance by the data subject, by which they agree that THINKCRM LTD may process their personal data.
This Personal Data Protection Policy concerns the processing of Personal Data by THINKCRM LTD, which faithfully applies the provisions of the applicable national legislation in force, as amended from time to time, as well as the provisions of Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data (General Data Protection Regulation).
The protection of Personal Data is the responsibility of both the Board of Directors and the Management of THINKCRM LTD.
Compliance with this Policy applies to all staff of the company, including Management Executives and members of the Board of Directors.
Members of the Board of Directors and all Management Executives act as role models for compliance with this Policy.
All Departments of the Organisation ensure that the staff under their responsibility comply with this Policy.
Personal Data is any information relating to an identified or identifiable living natural person.
An identified natural person is one whose identity has already been verified.
An identifiable natural person is one whose identity can be verified, directly or indirectly, through information such as:
name, identity card number, passport number, social insurance number, telephone number, geolocation data (GPS), photographs, fingerprints or other data relating to the physical, physiological, genetic, psychological, economic, cultural or social identity of the living natural person.
Aggregated data of a statistical nature, from which data subjects can no longer be identified, are not considered personal data.
THINKCRM LTD processes Personal Data of natural persons, such as clients, partners, job candidates and existing staff, for lawful purposes.
The processing of Personal Data under this Policy does not concern legal persons such as companies, organisations, associations, foundations, government agencies and other legal entities.
THINKCRM LTD collects the following Personal Data, or part thereof, depending on the case:
THINKCRM LTD collects Personal Data for the following categories of natural persons for the following purposes:
THINKCRM LTD processes Personal Data:
(a) to the extent necessary for the performance of a contract or to take steps at the request of the data subject prior to entering into a contract.
(b) to the extent necessary for the pursuit of its legitimate interests.
(c) for the purpose of complying with the Legislation, or
(d) where it has obtained explicit consent through the signing of the Personal Data Processing Consent Form.
The above-mentioned natural persons, or "data subjects", provide their Personal Data to THINKCRM LTD, either themselves, through their authorised representatives, or through the transfer of Personal Data from a competent authority, by the following means:
THINKCRM LTD retains personal data for as long as required for its lawful processing, and specifically:
For as long as the cooperation and/or employment with the data subjects continues and it is necessary to fulfil the purposes for which the data were collected, or for the period during which liability could arise from the processing, in accordance with the applicable legislation, unless, once those purposes cease to apply, retention is required by law, e.g. for tax reasons. Data is additionally retained until its deletion is requested, or, where it is retained and processed on the basis of consent, until that consent is withdrawn, or until the right to object to its processing is exercised.
In determining the retention period of your personal data, the nature of the data, its volume, the purpose of its processing, its security, etc. are taken into account.
There is also the right to request the deletion of the data.
THINKCRM LTD faithfully applies the provisions of Regulation 2016/679 and takes appropriate technical, organisational and administrative measures to ensure the protection of the personal data it processes against accidental or unlawful destruction, accidental loss, alteration, unauthorised disclosure or access, or any other form of unlawful processing.
All personal data in electronic form is securely stored and further protected through the use of appropriate access controls.
Documents in printed and electronic form containing personal data are destroyed in a non-recoverable manner, where required.
THINKCRM LTD discloses Personal Data in the following cases:
To a natural or legal person, public authority, agency or other body that THINKCRM LTD has:
Except as stated above, THINKCRM LTD does not disclose or publish personal data to any third party without informing the data subject and, where required, obtaining their prior consent.
The Data Controller must inform the Data Subject (the individual to whom the data relates) of their rights.
The Regulation grants several rights to the Data Subject, such as:
Right to be Informed (Article 12): The data subject has the right to concise, transparent, intelligible and easily accessible information, without delay, and in any case a response within one month of receipt of the request.
If the data subject's requests are manifestly unfounded or excessive, in particular because of their repetitive nature, THINKCRM LTD may refuse to act on the request.
Right to be Informed when Obtaining Consent (Articles 13 & 14): When obtaining consent, THINKCRM LTD informs the Data Subject of the purposes for collecting the Personal Data, the processing period, their rights, the categories of data, and the source of any data not collected directly from THINKCRM LTD.
Right of Access (Article 15): The data subject has the right to obtain a copy of their data and to be fully informed about their data, the purposes of processing, the categories of data, the retention period and the criteria used to determine it, the recipients to whom the data has been disclosed, and its origin if not collected directly from THINKCRM LTD.
Right to Rectification (Article 16): The data subject has the right to request the correction or completion of inaccurate personal data, and to have their request fulfilled without undue delay.
Right to Erasure (Article 17): The data subject has the right to request the deletion of their data, and to have their request fulfilled without delay, unless the Data Controller has an overriding legitimate interest.
Right to Restriction of Processing (Article 18): The data subject has the right to request the restriction of processing when the accuracy of the data is contested, or where the processing is unlawful or no longer necessary.
Right to Notification (Article 19): The Data Controller notifies each recipient to whom the data has been disclosed of any rectification, erasure or restriction of processing, and informs the Data Subject accordingly.
Right to Data Portability (Article 20): The data subject has the right to receive their Data in a digital format and to transmit it to another organisation, or to request its direct transmission to another organisation.
Right to Object (Article 21): Processing stops following an objection, unless the Data Controller has an overriding legitimate interest.
Right Not to be Subject to Automated Individual Decision-Making (Article 22): The data subject has the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning them or similarly significantly affects them.
The Data Subject has the right to lodge a complaint with the Commissioner for Personal Data Protection at any time, if they believe that any of their rights have been violated.
The Data Subject also has the right to withdraw their consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. Where THINKCRM LTD, as Data Controller of Personal Data, has a legitimate interest in retaining the Personal Data concerning them, their request for withdrawal and/or deletion may not be accepted.
It reports, in full detail, any breaches and/or violations to the Commissioner for Personal Data Protection within 72 hours of becoming aware of the breach/violation.
It informs the Data Subject (natural person) when there is a high risk to their rights and freedoms.
The Data Controller is THINKCRM LTD.
The Data Processor is any natural or legal person, public authority, agency or other body that processes personal data on the instructions of the company.
In accordance with Regulation 2016/679, THINKCRM LTD has appointed a Data Protection Officer (DPO) who is duly and promptly involved in all matters relating to the protection of personal data. Data subjects may contact the Data Protection Officer regarding any matter related to the processing of their personal data and the exercise of their rights, in accordance with Regulation 2016/679.
The DPO's contact details are also published on the THINKCRM LTD website.
You can contact the DPO at: 49 Panagias Evangelistrias, Kato Polemidia, 4156, Limassol, Cyprus, or by email at info@thinkcrm.net
THINKCRM LTD reserves the right to revise this Personal Data Protection Policy whenever it deems necessary. You are therefore encouraged to review it periodically. The latest version of this Policy is always published on the THINKCRM LTD website.
Privacy and Personal Data Protection Statement
For us at THINKCRM LTD, protecting the Personal Data of our clients and respecting individuals' privacy online is a fundamental commitment. We take all necessary organisational and technical measures required to ensure the security, availability and integrity of our users' and clients' data.
It is very important to us that this strong commitment is clear to all clients and users of our services. For this reason, we have created this "Privacy – Personal Data Protection Statement", which describes and explains what kind of personal data we collect, how we manage it, and how it may be used.
THINKCRM LTD builds software and provides internet services, consulting support, information and training for businesses as well as individuals. This statement applies to all of the software products and services we provide.
Personal data we collect
THINKCRM LTD collects and processes data solely for the purposes of its lawful and proper operation and to offer its clients and internet users the best possible user experience. Some of this data is provided directly by our clients or the users of our online services, for example, when a new user registers for one of our services or when a client submits a support request. Some data is recorded indirectly, and this recording depends on how users use our software products or online services. Data is thus recorded when technologies such as cookies are used, or when error reports or usage statistics are received from our software products for the purpose of diagnosing problems or improving them. In every case of data collection or transmission, this is preceded by clear and explicit acceptance on the part of the user through an appropriate user interface element.
The data we collect may include the following:
We collect data relating to the product or service used by the client or user and how they interact with it. For example:
Cookies and Similar Technologies
THINKCRM LTD uses cookies (small text files placed on your device) and similar technologies and services that use your IP address to deliver its websites, mobile applications and electronic services. Among other things, cookies allow us to store your preferences and settings, allow you to log in, provide interest-based advertising, provide notifications, help combat fraud, and also allow us to analyse the performance of our websites and electronic services. For these purposes, we also use services such as Google Analytics, Google Firebase and OneSignal, which are fully compliant with the GDPR.
We also use web beacons to deliver cookies and to collect usage and performance data. Our websites may also include web beacons and cookies from third-party service providers.
You have a variety of tools available to control cookies, web beacons and other similar technologies, such as browser controls for blocking and deleting cookies, and opt-out controls offered by certain third-party analytics providers for excluding data collection via web beacons and similar technologies. Your browser and other settings may affect your experience with our products.
Use of Personal Data
THINKCRM LTD uses the data it collects solely for the following purposes:
We do not share the data we collect with legal or natural persons except with the client's consent, for the completion of any transaction, or for the provision of a service; for example, payment data required to complete a purchase will be shared with banks and other entities that process payment transactions or provide other financial services, and for the purposes of fraud prevention and credit risk reduction.
Finally, we may access, transfer, disclose and retain personal data when we believe in good faith that this is necessary for the following reasons:
Processing period of Personal Data
The storage and processing of the data of our clients and service users is carried out solely as permitted by law or in accordance with the users' explicit consent, only for as long as necessary to fulfil the purposes of the processing (as defined above), or until the user objects to the use of their Personal Data by THINKCRM LTD, or until they withdraw their consent. However, whenever required by mandatory law, THINKCRM LTD will retain Personal Data for a longer period, or whenever Personal Data is required in order for THINKCRM LTD to assert or defend itself against legal claims.
Place of data processing
THINKCRM LTD is headquartered in Limassol, and therefore all processing carried out at our premises takes place within the territory of Cyprus. To provide better services, THINKCRM LTD uses cloud infrastructure at Cypriot data centres and on Microsoft Azure. In the case of Microsoft Azure, only data centres within the European Union are used.
How to access and control your personal data
Users of THINKCRM LTD's products and services may, at any time, request information about their Personal Data from THINKCRM LTD, as well as request its correction or deletion. THINKCRM LTD may delete the data only if there is no legal obligation or other legitimate right for it to retain them. Naturally, if a user's data is deleted, THINKCRM LTD will not be able to continue providing its services to that user where such services require the use of that data.
Where THINKCRM LTD uses personal data based on the user's consent or in order to enter into a contract with them, the user may request a copy of their personal data.
Finally, users may ask THINKCRM LTD to restrict any processing of their Personal Data in the following cases:
For any request or clarification needed, users may contact us via the email address below, specifying the information or processing activities related to their request, the format in which they would like that information, and whether the Personal Data should be sent to them or to another recipient. The request will be carefully reviewed, and we will discuss with the user the best way to fulfil it.
Contact information
The Controller of Processing is THINKCRM LTD, address: 49 Panagias Evangelistrias, Kato Polemidia, 4156, Limassol, Cyprus, tel. 25251948, or you can contact us by email at info@thinkcrm.net
Changes to this policy
THINKCRM LTD may amend this Personal Data Protection Statement from time to time in order to reflect current personal data protection practices. When we make changes to this statement, we will update the "last updated" date at the bottom of this page. We encourage you to review this Personal Data Protection Statement periodically in order to stay informed about how THINKCRM LTD protects your data.
Questions about this policy and its application
THINKCRM LTD is committed to protecting your personal data online. If you have any questions or comments regarding how we manage your personal data, please contact us at the address and details listed above, under contact information. You may also use this address to notify us of any concerns you may have regarding our compliance with our Online Personal Data Protection Statement.
THINKCRM © . All Rights Reserved.