Legal
PRIVACY POLICY
Last updated: 7 July 2026
Who We Are
Auditiams Compliance & Risk Ltd ("Auditiams", "we", "us") is the data controller responsible for personal data processed through audcom.auditiams.com (the "Website") and the AUDCOM compliance management platform (the "Platform").
Controller: Auditiams Compliance & Risk Ltd Registered office: Ground Floor, 59 Nikou Pattichi, 3070 Limassol, Cyprus Contact for privacy matters: info@auditiams.com
This Privacy Policy explains what personal data we collect, why we collect it, the legal bases we rely on, how long we keep it, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR) and Cypriot data protection law.
Personal Data We Collect
We collect the following categories of personal data directly from you:
►Identity and contact data — first name, last name, business email address and phone number, provided when you request access, register, or contact us►Professional data — company name, sector, position, and the products or services you are interested in►Account and security data — hashed password, two-factor authentication settings and backup codes, login sessions►Usage and activity data — actions performed on the Platform, recorded in activity logs for security and audit purposes►Communications — messages you send us, including support requests and marketing preferences►Technical data — IP address, browser type and version, device information, and diagnostic data generated when errors occur
We do not collect special categories of personal data (such as health or biometric data) through the Website, and we ask that you do not submit such data through our forms.
Purposes and Lawful Bases
We process your personal data for the following purposes, relying on the lawful bases set out in Article 6(1) GDPR:
►Assessing and responding to access or registration requests — necessary to take steps at your request prior to entering into a contract (Art. 6(1)(b))►Providing, administering and securing your account and the Platform — performance of a contract (Art. 6(1)(b))►Sending marketing and product communications — your consent, given via the registration form and withdrawable at any time (Art. 6(1)(a))►Security monitoring, activity logging, error diagnostics and abuse prevention — our legitimate interest in keeping the Platform secure and reliable (Art. 6(1)(f))►Complying with legal obligations, including accounting, tax and regulatory requirements under Cypriot and EU law (Art. 6(1)(c))
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may object to such processing at any time (see "Your Rights" below).
Data We Obtain From Other Sources
In the course of providing compliance services, we may process information obtained from publicly available sources, such as company registries, regulatory publications and sanctions or media databases. Where this information includes personal data (for example, the names of company directors or beneficial owners), we process it on the basis of our legitimate interest in delivering the compliance services our customers have engaged us for (Art. 6(1)(f) GDPR). This Privacy Policy constitutes the information notice required by Article 14 GDPR for such processing.
Recipients and Processors
We do not sell personal data. We share personal data only with:
►Infrastructure and hosting providers that operate the servers and databases the Website and Platform run on►E-mail delivery providers used to send transactional and, where you have consented, marketing e-mails►Sentry (Functional Software, Inc.) for application error monitoring and diagnostics►Professional advisers, auditors and public authorities, where required by law
All processors act under data processing agreements pursuant to Article 28 GDPR and process personal data only on our instructions.
International Transfers
Your personal data is stored and processed within the European Economic Area (EEA) wherever possible. Where a service provider processes personal data outside the EEA, we ensure an adequate level of protection through an EU adequacy decision or the European Commission's Standard Contractual Clauses, together with supplementary measures where necessary. You may request a copy of the relevant safeguards by contacting us.
Retention
We keep personal data only as long as necessary for the purposes described above:
►Account data — for the life of your account and up to 12 months after closure►Access or registration requests that are declined — up to 6 months from the decision►Security and activity logs — up to 12 months►Marketing consent records — until you withdraw consent, plus the period needed to evidence compliance
Longer retention applies only where required by law (for example, accounting records under Cypriot law) or for the establishment, exercise or defence of legal claims.
Your Rights
Under the GDPR you have the right to:
►Access the personal data we hold about you►Rectify inaccurate or incomplete data►Erase your data ("right to be forgotten") where there is no overriding reason for us to keep it►Restrict processing in the circumstances set out in Article 18 GDPR►Receive your data in a portable, machine-readable format►Object to processing based on legitimate interests, and to direct marketing at any time►Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal►Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects — we do not carry out such automated decision-making
To exercise any of these rights, contact us at info@auditiams.com. We respond within one month, as required by Article 12 GDPR.
You also have the right to lodge a complaint with the supervisory authority: the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy), or the supervisory authority of your habitual residence.
Cookies
The Website uses only cookies that are strictly necessary for authentication and security. For details, see our Cookie Policy.
Security
We apply appropriate technical and organisational measures to protect personal data, including encryption in transit, hashed password storage, two-factor authentication, role-based access controls and activity logging. No system is completely secure; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the competent supervisory authority and, where required, you, in accordance with Articles 33 and 34 GDPR.
Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top of this page shows when it was last revised. Material changes will be communicated through the Website or by e-mail.
Questions about this policy or our data practices: info@auditiams.com
Auditiams Compliance & Risk Ltd Ground Floor, 59 Nikou Pattichi, 3070 Limassol, Cyprus