Privacy Policy
Last updated: April 2026 · Effective date: April 2026
This policy applies to all visitors, clients, and counterparties who interact with Delitron Tech Ltd and its websites, products, and services. We process personal data as a controller under EU Regulation 2016/679 (GDPR). Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus.
1. Who we are
Delitron Tech Ltd (“Delitron”, “we”, “us”, “our”) is a company registered in the Republic of Cyprus, with registered office at Athalassas 62, Mezzanine, Strovolos 2012, Nicosia, Cyprus.
We develop and license bespoke B2B software products, including CRM systems, marketing automation platforms, lead management tools, cybersecurity solutions, and cloud-based applications. We deliver these products globally, primarily to business clients.
For data protection enquiries, contact us at: [email protected]
2. Scope
This policy covers personal data we collect and process:
- When you visit delitron.tech or any associated subdomain;
- When you contact us via our website, email, or telephone;
- When you enter into a commercial relationship with us (client, partner, supplier, or contractor);
- When you use any Delitron product or service that involves personal data processing;
- When you apply for a position with us.
This policy does not cover personal data processed by our clients within Delitron-built products — that processing is governed by the relevant client data processing agreement.
3. Data we collect
3.1 Data you provide directly
- Name, job title, company name, email address, telephone number (contact enquiries, contract formation);
- Billing and invoicing details (name, address, VAT number) — no payment card data is collected directly by Delitron;
- CV, professional history, and application materials (recruitment);
- Communications content — emails, messages, meeting notes.
3.2 Data collected automatically
- IP address, browser type, operating system, referring URL, pages visited, time and duration of visits;
- Cookie identifiers (see Section 9);
- Server logs generated during use of Delitron-hosted platforms.
3.3 Data received from third parties
- Publicly available professional information (LinkedIn, company registries) used for prospecting and KYC;
- Referrals from existing clients or partners.
4. Legal bases for processing
| Processing activity | Legal basis (GDPR Art.) |
|---|---|
| Responding to contact and enquiries | Legitimate interest (Art. 6(1)(f)) |
| Contract formation and performance | Necessary for contract (Art. 6(1)(b)) |
| Invoicing and tax compliance | Legal obligation (Art. 6(1)(c)) |
| Sending service updates to existing clients | Legitimate interest (Art. 6(1)(f)) |
| Marketing to prospective clients | Consent (Art. 6(1)(a)) or legitimate interest |
| Website analytics (non-essential cookies) | Consent (Art. 6(1)(a)) |
| Fraud prevention and security | Legitimate interest (Art. 6(1)(f)) |
| Recruitment and hiring | Consent / pre-contractual steps (Art. 6(1)(a)/(b)) |
5. How we use your data
- To respond to enquiries and provide requested information;
- To negotiate, enter into, and perform commercial contracts;
- To deliver, support, and maintain software products and services;
- To issue invoices, manage accounts, and comply with Cyprus and EU tax obligations;
- To communicate product updates, security alerts, and relevant service changes to existing clients;
- To conduct B2B outreach and marketing (subject to applicable opt-out rights);
- To evaluate job applications;
- To analyse website usage and improve our digital presence;
- To comply with legal obligations and respond to lawful requests from regulators or courts.
6. Data sharing and disclosure
We do not sell personal data. We share personal data only:
- Service providers and sub-processors: cloud hosting (e.g. AWS, Azure), email and communication platforms, accounting software, CRM tools — bound by data processing agreements;
- Professional advisors: lawyers, accountants, auditors — under confidentiality obligations;
- Group entities: intra-group transfers subject to intra-group data processing agreements;
- Regulatory and legal compliance: where required by Cyprus, EU, or applicable law;
- Business transfers: in connection with any merger, acquisition, or sale of assets.
7. International transfers
As a Cyprus-based company operating globally, we may transfer personal data outside the EEA. Where we do so, we ensure adequate protection through adequacy decisions, Standard Contractual Clauses (SCCs) per GDPR Art. 46(2), or other approved mechanisms. Contact [email protected] to request a copy of the applicable transfer mechanism.
8. Retention
| Category | Retention period | Basis |
|---|---|---|
| Active client / contract data | Duration of relationship + 7 years | Cyprus tax and commercial law |
| Enquiries (no contract formed) | 2 years from last contact | Legitimate interest |
| Recruitment applications (unsuccessful) | 6 months from rejection | Consent |
| Website analytics (aggregated) | 26 months | ICO/EDPB guidance |
| Marketing consent records | Consent period + 3 years | Accountability obligation |
| Financial / tax records | 7 years minimum | Cyprus Income Tax Law, VAT Law |
9. Cookies
Our website uses the following cookie categories:
- Strictly necessary: Essential for site functionality. No consent required.
- Analytics / performance: Help us understand visitor behaviour (e.g. Google Analytics). Require consent.
- Marketing / tracking: Used for remarketing or measuring campaign effectiveness. Require consent.
Manage your cookie preferences via our cookie consent tool on first visit, or by adjusting your browser settings.
10. Your rights under GDPR
- Access (Art. 15): Request a copy of your personal data;
- Rectification (Art. 16): Correct inaccurate or incomplete data;
- Erasure (Art. 17): Request deletion where data is no longer needed;
- Restriction (Art. 18): Limit processing in certain circumstances;
- Portability (Art. 20): Receive your data in a structured, machine-readable format;
- Objection (Art. 21): Object to processing based on legitimate interests;
- Withdraw consent: At any time, without affecting prior lawful processing.
To exercise any right, contact [email protected]. We respond within one calendar month. You may also lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus.
11. Security
We apply appropriate technical and organisational measures including encryption in transit (TLS) and at rest, access controls, regular security assessments, staff training, and incident response procedures consistent with GDPR Art. 33/34. We will notify the competent supervisory authority within 72 hours of a qualifying breach.
12. Children’s data
Our products and services are directed exclusively at businesses. We do not knowingly collect personal data from individuals under 18. If you believe we have done so inadvertently, contact us immediately.
13. Changes to this policy
We may update this policy periodically. Material changes will be communicated to active clients by email. The “last updated” date at the top reflects the most recent revision.
14. Contact
Delitron Tech Ltd
Athalassas 62, Mezzanine
Strovolos 2012, Nicosia, Cyprus
Email: [email protected]
Tel: +357 99 045616