Legal

PRIVACY POLICY

Last updated: 7 July 2026

Who We Are

Auditiams Compliance & Risk Ltd ("Auditiams", "we", "us") is the data controller responsible for personal data processed through audcom.auditiams.com (the "Website") and the AUDCOM compliance management platform (the "Platform").

Controller: Auditiams Compliance & Risk Ltd Registered office: Ground Floor, 59 Nikou Pattichi, 3070 Limassol, Cyprus Contact for privacy matters: info@auditiams.com

This Privacy Policy explains what personal data we collect, why we collect it, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cypriot data protection law.

Personal Data We Collect

We collect the following categories of personal data directly from you:

Identity and contact data — first name, last name, business email address and phone number, provided when you request access, register, or contact usProfessional data — company name, sector, position, and the products or services you are interested inAccount and security data — hashed password, two-factor authentication settings and backup codes, login sessionsUsage and activity data — actions performed on the Platform, recorded in activity logs for security and audit purposesCommunications — messages you send us, including support requests and marketing preferencesTechnical data — IP address, browser type and version, device information, and diagnostic data generated when errors occur

We do not collect special categories of personal data (such as health or biometric data) through the Website, and we ask that you do not submit such data through our forms.

Purposes and Lawful Bases

We process your personal data for the following purposes, relying on the lawful bases set out in Article 6(1) GDPR:

Assessing and responding to access or registration requests — necessary to take steps at your request prior to entering into a contract (Art. 6(1)(b))Providing, administering and securing your account and the Platform — performance of a contract (Art. 6(1)(b))Sending marketing and product communications — your consent, given via the registration form and withdrawable at any time (Art. 6(1)(a))Security monitoring, activity logging, error diagnostics and abuse prevention — our legitimate interest in keeping the Platform secure and reliable (Art. 6(1)(f))Complying with legal obligations, including accounting, tax and regulatory requirements under Cypriot and EU law (Art. 6(1)(c))

Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time (see "Your Rights" below).

Data We Obtain From Other Sources

In the course of providing compliance services, we may process information obtained from publicly available sources, such as company registries, regulatory publications and sanctions or media databases. Where this information includes personal data (for example, the names of company directors or beneficial owners), we process it on the basis of our legitimate interest in delivering the compliance services our customers have engaged us for (Art. 6(1)(f) GDPR). This Privacy Policy constitutes the information notice required by Article 14 GDPR for such processing.

Recipients and Processors

We do not sell personal data. We share personal data only with:

Infrastructure and hosting providers that operate the servers and databases the Website and Platform run onE-mail delivery providers used to send transactional and, where you have consented, marketing e-mailsSentry (Functional Software, Inc.) for application error monitoring and diagnosticsProfessional advisers, auditors and public authorities, where required by law

All processors act under data processing agreements pursuant to Article 28 GDPR and process personal data only on our instructions.

International Transfers

Your personal data is stored and processed within the European Economic Area (EEA) wherever possible. Where a service provider processes personal data outside the EEA, we ensure an adequate level of protection through an EU adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where necessary. You may request a copy of the relevant safeguards by contacting us.

Retention

We keep personal data only as long as necessary for the purposes described above:

Account data — for the life of your account and up to 12 months after closureAccess or registration requests that are declined — up to 6 months from the decisionSecurity and activity logs — up to 12 monthsMarketing consent records — until you withdraw consent, plus the period needed to evidence compliance

Longer retention applies only where required by law (for example, accounting records under Cypriot law) or for the establishment, exercise or defence of legal claims.

Your Rights

Under the GDPR you have the right to:

Access the personal data we hold about youRectify inaccurate or incomplete dataErase your data ("right to be forgotten") where there is no overriding reason for us to keep itRestrict processing in the circumstances set out in Article 18 GDPRReceive your data in a portable, machine-readable formatObject to processing based on legitimate interests, and to direct marketing at any timeWithdraw consent at any time, without affecting the lawfulness of processing before withdrawalNot be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we do not carry out such automated decision-making

To exercise any of these rights, contact us at info@auditiams.com. We respond within one month, as required by Article 12 GDPR.

You also have the right to lodge a complaint with the supervisory authority: the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy), or the supervisory authority of your habitual residence.

Cookies

The Website uses only cookies that are strictly necessary for authentication and security. For details, see our Cookie Policy.

Security

We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed password storage, two-factor authentication, role-based access controls and activity logging. No system is completely secure; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you, in accordance with Articles 33 and 34 GDPR.

Changes to This Policy

We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when it was last revised. Material changes will be communicated through the Website or by e-mail.

Questions about this policy or our data practices: info@auditiams.com

Auditiams Compliance & Risk Ltd Ground Floor, 59 Nikou Pattichi, 3070 Limassol, Cyprus