Skip to content
SZ S.Z. ISTAY
Home Privacy Terms EULA Contacts

Privacy Policy

How S.Z. ISTAY LIMITED collects, uses and protects personal information when you visit this website, contact us, or engage us as a client.

Effective1 July 2026
Version1.0
JurisdictionCyprus · EU GDPR

Contents

  1. 01Who we are
  2. 02What we collect
  3. 03How we use data
  4. 04Legal basis
  5. 05Sharing & processors
  6. 06International transfers
  7. 07Retention
  8. 08Your rights
  9. 09Cookies
  10. 10Security
  11. 11Children
  12. 12Changes
  13. 13Contact

01 Who we are

S.Z. ISTAY LIMITED (“S.Z. ISTAY”, “we”, “us”) is a private company incorporated under the laws of the Republic of Cyprus, with its registered office at 15A Gordiou Desmou, Larnaca 6045, Cyprus. For matters relating to this policy we act as the data controller of the personal data we collect about you.

This policy applies to our website, our email and other direct communication channels, and to the services we provide to our clients. It does not apply to the apps and products we build for our clients — those are governed by the privacy notices of the respective publishers.

02 What information we collect

2.1 Information you give us

When you contact us by email or through any channel listed on this site, we receive whatever information you choose to share — typically your name, email address, the company you represent, and the contents of your message.

When we sign an engagement with you, we may additionally process billing information (company name, VAT/tax ID, address) and signatory contact details, as needed to issue invoices and perform the contract.

2.2 Information collected automatically

Our web server keeps standard access logs for security and operational diagnostics. These logs contain your IP address, user agent, requested URL and a timestamp. We do not run third-party analytics that profile visitors, and we do not place advertising cookies.

2.3 Information we receive during projects

During an engagement we may process personal data your organisation provides — for example test accounts, sample datasets, screenshots, or production data necessary to reproduce an issue. In that case we act as a processor on your behalf, subject to a separate written Data Processing Agreement (DPA).

03 How we use personal data

  • To respond to enquiries and provide the services you request.
  • To negotiate and perform contracts, including invoicing and accounting.
  • To operate, secure and improve our website and internal tooling.
  • To comply with legal obligations — for example tax and accounting record-keeping under Cyprus law.
  • To establish, exercise or defend legal claims where strictly necessary.

We do not sell personal data, and we do not use it to train machine-learning models.

04 Legal basis (GDPR)

We process personal data under the EU General Data Protection Regulation (Regulation (EU) 2016/679) and the Cyprus law that implements it (Law 125(I)/2018). We rely on the following bases under Article 6:

  • Performance of a contract (Art. 6(1)(b)) — to answer your enquiry, prepare a proposal, or deliver agreed services.
  • Legitimate interests (Art. 6(1)(f)) — to keep the website secure, prevent abuse, and maintain reasonable business records. We balance these interests against your rights.
  • Legal obligation (Art. 6(1)(c)) — to keep accounting records and respond to lawful requests from public authorities.
  • Consent (Art. 6(1)(a)) — only where required and clearly requested, e.g. for any future newsletter. Consent can be withdrawn at any time.

05 Sharing & sub-processors

We share personal data only with vetted service providers strictly necessary to operate our business:

  • Email and productivity infrastructure (e.g. Google Workspace, Gmail).
  • Hosting and DNS providers.
  • Accounting and tax services contracted in Cyprus.
  • Payment processors where applicable to a specific engagement.

For client engagements, sub-processors used to deliver the services are listed in the relevant DPA. We do not disclose personal data to third parties for their own marketing purposes.

06 International transfers

Some of our service providers are located outside the European Economic Area (most notably in the United States). Where data is transferred internationally, we rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism, and we apply additional technical safeguards (transport encryption, access controls) where appropriate.

07 Retention

We keep personal data only as long as needed for the purposes it was collected, then delete or anonymise it. Indicative periods:

  • Enquiry correspondence — up to 24 months after last contact, unless a contract is signed.
  • Contractual records and invoices — for the period required by Cyprus tax and accounting law (currently up to 6 years).
  • Server logs — up to 30 days, except where retained longer to investigate a specific incident.

08 Your rights

Subject to the GDPR and applicable Cyprus law, you have the right to:

  • Access the personal data we hold about you;
  • Request correction of inaccurate data;
  • Request erasure (the “right to be forgotten”);
  • Restrict or object to certain processing;
  • Receive your data in a portable format;
  • Withdraw consent at any time where processing is based on consent;
  • Lodge a complaint with the supervisory authority — in Cyprus, the Office of the Commissioner for Personal Data Protection.

To exercise any of these rights, write to us at the contact details in Section 13. We will respond within one month.

09 Cookies and tracking

This website uses only the cookies strictly necessary for it to function and to remain secure. We do not use advertising cookies, cross-site tracking, or third-party analytics that profile you. If we ever add optional analytics or marketing cookies, we will request your consent first through a clear banner.

10 Security

We apply commercially reasonable technical and organisational measures to protect personal data — including transport encryption (TLS), access controls, regular software updates, and the principle of least privilege. No method of transmission or storage on the internet is perfectly secure; if a breach affecting your data occurs, we will act in line with applicable law and notify you and the supervisory authority where required.

11 Children

Our website and services are directed to businesses and adult professionals. We do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us with personal data, contact us and we will delete it.

12 Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected here with an updated effective date. Continued use of our website or services after a change becomes effective constitutes acceptance of the revised policy.

13 Contact

For any question about this policy or to exercise your rights, write to us:

S.Z. ISTAY LIMITED
15A Gordiou Desmou, Larnaca 6045, Cyprus
Email: s.z.istay@gmail.com

Last updated 1 July 2026 · Version 1.0

SZ S.Z. ISTAY LIMITED
15A Gordiou Desmou
Larnaca 6045, Cyprus
s.z.istay@gmail.com
Menu Home Privacy Terms EULA Contacts
© 2026 S.Z. ISTAY LIMITED Larnaca, Cyprus