FIRMCY Screening is operated by Ioannou & Sharpe LLC, a Cyprus limited liability company (reg. HE 447364), of Griva Digeni, Limassol Center, Block B, 3rd Floor, Office 304, 3095 Limassol, Cyprus, VAT CY60007091D. Our data-protection contact is [email protected].
This policy covers two surfaces: firm.cy (this marketing website, including the contact form) and screening.firm.cy (the service — your account, billing, and the screening of persons you submit). Your role, and ours, differs between them.
Contact-form submissions; training-registration and attendance records (see below); account and billing data; screening subject data (as your processor, under the DPA — not under this policy); usage and technical data (IP, user agent, audit logs); and our email correspondence with you.
Contract (providing your account, responding to enquiries), legal obligation (accounting, tax, AML where applicable), legitimate interests (security, audit, abuse prevention), and consent where you give us information voluntarily. For the people you screen, the lawful basis is yours to establish per run.
All personal data covered by this policy is hosted in the European Union (AWS eu-central-1, Frankfurt; xAI EU endpoint with zero-data-retention; EU payment and email sub-processors; Cloudflare at the EU edge). No Chapter V transfer mechanism is required for the data covered.
Contact-form submissions are kept only as long as needed to respond and for a reasonable period thereafter. Account data is kept for the life of the account and a reasonable period after closure for accounting, tax and dispute purposes. Screening subject data and evidence are retained as your processor per the DPA.
You have the right to access, rectify, erase, restrict, port, object to and (where we rely on consent) withdraw consent to processing, and to lodge a complaint with the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus (www.dataprotection.gov.cy). Contact [email protected] to exercise a right. Requests about the people you screen should go to your own organisation as controller.
This website and the service use only essential cookies (the authenticated session cookie on screening.firm.cy and Cloudflare's edge security/routing). We run no cross-site tracking, advertising or profiling analytics.
We measure how often each page of firm.cy is read using our own counter — there is no analytics provider, no advertising pixel and no third-party script. A small script on each page tells our server two things: which page you opened, and, if you arrived from another website, that website's address (its hostname — never the full link). Nothing else is sent. The script sets no cookies, writes nothing to and reads nothing from your device, and creates no visitor, session or device identifier, so there is nothing that could be linked back to you.
What we store is a daily tally: for each day, each page, and each referring website's hostname, a count of views. There are no individual records and no way to reconstruct one person's visits. Your IP address reaches our server, as it must for any request to any website, and we use it only in the moment — to tell automated traffic from human traffic and to limit abuse. The visit counter never stores it. (One thing on this site does record an IP: a training registration, described below.) Tallies are deleted after 13 months. If your browser sends a “Do Not Track” or “Global Privacy Control” signal, the script sends nothing.
Registering for an in-person training session at firm.cy/trainings is double opt-in: the form records your details as pending and emails you a link, and your place is taken only when you open it. Until then nothing is held, and if the link is never opened the pending record expires within 48 hours — at which point your details are deleted from it, not merely disregarded.
What we record. Your name, your firm or organisation, your email address, the role you select, the session you chose, your registration reference and its status, the time you submitted the form, the time you confirmed, whether you attended, and the IP address the registration came from (kept to limit abuse of the form and to evidence how the consent was given). We do not add you to any mailing list, and registering is not a subscription to anything.
Why, and on what basis. To hold your place, to email you about that session, to keep the attendance register a professional body may expect us to be able to produce, and to issue a certificate of attendance in your name if you attend. The lawful basis is your consent (Article 6(1)(a) GDPR), given by opening the confirmation link — which is why we send one rather than taking a tick-box at face value.
How long. The registration and attendance record is kept for three years from the session, which is the period over which a certificate of attendance may need to be evidenced. A pending registration that is never confirmed expires after 48 hours, and its details are deleted at that point; only a bare reference and the session remain, so the same reference is never issued twice.
Withdrawing, and erasure. You can withdraw your consent at any time, and ask for a copy of what we hold or for it to be erased, by writing to [email protected]. Withdrawal takes effect for the future: it releases your place and stops the emails, and erasure removes your details from the register. Withdrawing does not make the fact that you attended a session that has already happened untrue, but we will erase your details from the record on request.
Who sees it. Only Ioannou & Sharpe LLC. The register is not shared with any professional body, venue or third party, and the confirmation and reminder emails are sent through our own mail provider. It is stored in the EU like everything else covered by this policy.
The current, definitive Privacy Policy is at screening.firm.cy/legal/privacy.