Last updated: 29/06/2026
Reg4Tech (“Reg4Tech”, “we”, “us” or “our”) is committed to protecting your privacy and handling your personal data in a transparent, lawful and secure manner.
This Privacy and Cookie Policy explains how we collect, use, disclose, store and otherwise process personal data in connection with our website, our digital products and services, our regulatory technology solutions, our communications, our commercial relationships and our interactions with prospective clients, clients, users, suppliers, partners and other business contacts.
This Policy is intended to comply with Regulation (EU) 2016/679 (the “GDPR”), the Cyprus Law Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data of 2018 (Law 125(I)/2018), and applicable rules implementing Directive 2002/58/EC as amended (the “ePrivacy rules”).
1. Who This Policy Applies To
This Policy applies to natural persons who are, or may become:
- visitors to our website;
- prospective clients or clients;
- users of our products, services, platforms or demos;
- representatives, directors, officers, employees, contractors, beneficial owners, authorised signatories or contact persons of our clients, partners, suppliers or counterparties;
- recipients of our communications, newsletters, updates, invitations or marketing;
- job applicants or persons who otherwise contact us in a business capacity; or
- any other individuals whose personal data we process in the course of our business.
2. Who We Are
Reg4Tech acts as the data controller in relation to the personal data covered by this Policy, except where we expressly notify you otherwise.
Data Controller
REG4TECH LTD
Registered office: 24 Piraeus street, 3rd floor, 2023 Strovolos, Nicosia, Cyprus
Company registration number: ΗΕ 437528
Email: info@reg4tech.com
Telephone: 22277222
If you have any questions about this Policy or wish to exercise your rights, please contact us at the details above.
Data Protection Officer / Privacy Contact: info@reg4tech.com
3. How We Collect Personal Data
We collect personal data directly from you, from third parties, from publicly available sources and automatically through your use of our website, platforms or digital tools.
3.1 Personal data collected directly from you
We may collect personal data directly from you when:
- you visit or use our website, platform or portal;
- you request a demo, proposal, quotation or further information;
- you contact us by email, telephone, contact form, post or in person;
- you register for an event, webinar, newsletter or update;
- you engage with us regarding our regulatory technology, compliance, software, data or advisory solutions;
- you create an account or use credentials for access to our systems where applicable;
- you submit support, onboarding, implementation or customer service requests; or
- you otherwise provide information to us.
3.2 Personal data collected from third parties
We may collect personal data from third parties, including:
- your employer, organisation or principal where you act as a representative or user;
- clients, counterparties, implementation partners, resellers, affiliates or service providers;
- analytics, hosting, communications, software, identity verification and cybersecurity providers;
- public authorities, regulators, law enforcement bodies and courts;
- publicly available databases, registers and lawful information sources; and
- professional advisers and other intermediaries.
3.3 Personal data collected automatically
When you use our website or digital services, we may automatically collect certain technical and usage information, including:
- IP address;
- device identifiers;
- browser type and version;
- operating system;
- referral source;
- pages viewed and navigation paths;
- date, time and duration of visits or sessions;
- language and location data inferred from technical settings;
- user activity logs and system interaction data; and
- cookie identifiers and similar online identifiers.
4. Categories of Personal Data We Collect
Depending on the context, we may collect and process the following categories of personal data:
- identity data, such as name, surname, title, date of birth, nationality, identification details and signature;
- contact data, such as home or business address, email address, telephone number and correspondence details;
- professional and organisational data, such as employer, role, position, department, business affiliation, permissions and authority to act;
- account and access data, such as usernames, login identifiers, authentication data and user permissions;
- communications data, such as correspondence, support requests, meeting notes, enquiries, complaints and feedback;
- technical and usage data, such as IP address, device data, browser information, system logs, user interactions and cookie-related information;
- commercial and transaction data, such as proposals, subscriptions, purchase information, billing details, payment information and service history;
- compliance and due diligence data, where relevant, such as KYC, sanctions screening, tax information or corporate ownership information;
- marketing and preference data, such as subscription choices, event preferences and interaction history; and
- any other personal data relevant to the services, transactions or relationships involved.
We do not intentionally collect special categories of personal data unless this is necessary for a specific lawful purpose and permitted by law. If such data is collected, we will process it only in accordance with GDPR and applicable Cyprus law.
5. Why We Process Personal Data and Our Legal Bases
We process personal data only where we have a lawful basis to do so under Article 6 GDPR and, where relevant, an additional lawful basis or condition under Article 9 GDPR.
|
Purpose of processing |
Categories of personal data |
Legal basis |
|
To operate, maintain, host, monitor and secure our website, platform and digital services |
Technical and usage data, device data, system logs, cookie data and online identifiers |
Legitimate interests; consent where required for non-essential cookies |
|
To respond to enquiries, demo requests, proposals, support tickets and other communications |
Identity data, contact data and communications data |
Legitimate interests; steps prior to entering into a contract |
|
To assess and onboard clients, users, suppliers, partners and other business contacts |
Identity data, contact data, professional data, account data, financial data and due diligence data |
Steps prior to entering into a contract; performance of a contract; legal obligation |
|
To provide, configure, administer and support our products, platforms, services and commercial relationships |
Identity data, contact data, professional data, account data, communications data, technical data and transaction data |
Performance of a contract; legitimate interests |
|
To manage access rights, authentication, account security and user permissions |
Identity data, account data, access data, technical data and security-related data |
Performance of a contract; legitimate interests |
|
To carry out compliance checks, sanctions screening, fraud prevention and regulatory compliance where applicable |
Identity data, compliance data, due diligence data, screening data, tax data and beneficial ownership data |
Legal obligation; legitimate interests; substantial public interest where applicable |
|
To manage payments, invoicing, subscriptions, accounting, reporting and record-keeping |
Identity data, contact data, financial data, billing data and transaction data |
Performance of a contract; legal obligation; legitimate interests |
|
To protect our legal rights and to establish, exercise or defend legal claims |
Relevant categories depending on the matter, including identity, contact, communications, financial, technical and compliance data |
Legitimate interests; legal obligation |
|
To maintain the security of our systems, premises, personnel and operations, and to detect and prevent misuse |
Technical data, access data, identity data, device data, log data and security-related data |
Legitimate interests; legal obligation where applicable |
|
To improve our website, products, services, communications, analytics and user experience |
Technical data, website usage data, communications data, feedback data, preference data and cookie data |
Legitimate interests; consent where required |
|
To send newsletters, product updates, invitations, alerts and marketing communications |
Identity data, contact data, marketing preference data, interaction data and website engagement data |
Consent where required; legitimate interests where permitted by law |
Where we rely on legitimate interests, those interests typically include operating our business efficiently, administering and improving our products and services, maintaining security, managing relationships, detecting abuse or misuse, protecting our legal rights and communicating with relevant business contacts.
Where we rely on consent, you may withdraw your consent at any time. Withdrawal will not affect the lawfulness of processing carried out before withdrawal.
If you do not provide personal data that we require for a contract, legal obligation or due diligence process, we may be unable to engage with you, provide services, activate or support an account, process a transaction, continue a business relationship or comply with our obligations.
6. Who We Share Personal Data With
We may disclose personal data on a need-to-know basis to:
- our directors, officers, employees and authorised personnel;
- affiliated entities within our group, where applicable;
- IT, cloud hosting, cybersecurity, software, analytics, CRM, communications, payment, support and document management providers;
- implementation partners, subcontractors, consultants and professional advisers;
- legal advisers, auditors, accountants, tax advisers and insurers;
- banks, payment processors and other financial institutions;
- verification, KYC, AML, sanctions screening, fraud prevention and compliance service providers;
- regulators, supervisory authorities, governmental bodies, law enforcement agencies, courts and tribunals; and
- any other person where disclosure is required by law, regulation, court order or necessary for the establishment, exercise or defence of legal claims.
Where third parties process personal data on our behalf, we require them to do so under appropriate contractual protections and security obligations.
7. International Transfers
Personal data may be transferred to and processed in countries outside the European Economic Area (“EEA”) where our service providers, advisers, group entities or other recipients are located.
Where we transfer personal data outside the EEA to a country that is not subject to an adequacy decision by the European Commission, we will implement appropriate safeguards as required by GDPR. These may include:
- the European Commission’s standard contractual clauses;
- an adequacy decision;
- binding corporate rules, where applicable; or
- another lawful transfer mechanism recognised under GDPR.
You may request further information about applicable transfer safeguards by contacting us.
8. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, reporting and record-keeping obligations, resolve disputes and enforce our rights.
Retention periods may vary depending on the data, the purpose of processing and applicable legal requirements. In determining retention periods, we consider:
- the nature, sensitivity and volume of the personal data;
- the purpose for which the personal data was collected and processed;
- whether the purpose can be achieved by other means;
- applicable statutory and regulatory retention periods; and
- limitation periods and evidential needs.
As a general guide:
- enquiry and general contact data is typically retained for 5 years after the last substantive interaction, unless a longer period is required;
- client, account, subscription and transaction data is retained for the period required by applicable contractual, tax, accounting and regulatory rules and internal retention policies;
- marketing data is retained until you unsubscribe or object, and for a limited suppression period afterwards to maintain opt-out records; and
- website logs, technical records and cookie data are retained for the periods described in our cookie tool or internal retention schedules.
9. Security
We maintain appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
These measures may include access controls, encryption, vendor due diligence, network and application security, logging and monitoring, authentication controls, confidentiality obligations, incident response procedures and staff training.
10. Your Rights
Subject to the conditions and limitations in GDPR and applicable law, you may have the following rights:
- the right to be informed about how your personal data is used;
- the right to request access to your personal data;
- the right to request rectification of inaccurate or incomplete personal data;
- the right to request erasure of your personal data in certain circumstances;
- the right to request restriction of processing in certain circumstances;
- the right to object to processing based on legitimate interests;
- the right to object at any time to direct marketing;
- the right to data portability where applicable;
- where processing is based on consent, the right to withdraw consent at any time; and
- the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you, except where permitted by law.
To exercise your rights, please contact us using the details set out in this Policy. We may request information to verify your identity before responding.
11. Right to Complain
If you have concerns about how we process your personal data, we encourage you to contact us first.
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus:
Office of the Commissioner for Personal Data Protection
Iasonos 1, 1082 Nicosia, Cyprus
Website: https://www.dataprotection.gov.cy
If applicable, you may also complain to another competent supervisory authority.
12. Cookies and Similar Technologies
Our website uses cookies and similar technologies, including pixels, tags, scripts and local storage objects, to operate the website, improve user experience, remember preferences, analyse traffic and, where applicable, support marketing activities.
A cookie is a small text file placed on your device when you visit a website. Some cookies are set by us and some are set by third parties.
12.1 Categories of cookies
We may use the following categories of cookies:
(a) Strictly necessary cookies
These cookies are necessary for the website or platform to function properly and cannot be switched off in our systems.
Legal basis: legitimate interests and, where applicable, processing necessary to provide a service expressly requested by the user.
(b) Preference or functionality cookies
These cookies remember choices you make and provide enhanced functionality.
Legal basis: your consent, where required.
(c) Analytics or performance cookies
These cookies help us understand how visitors or users interact with our website or platform and improve performance and content.
Legal basis: your consent, where required.
(d) Marketing or targeting cookies
These cookies may track browsing activity, support audience measurement or help us provide relevant communications and advertising.
Legal basis: your consent.
12.2 Cookie consent
Except for strictly necessary cookies, we will place cookies on your device only where we have obtained your prior consent through our cookie banner or preference management tool.
You can withdraw or change your consent at any time using the cookie settings available on our website.
12.3 Browser controls and third-party technologies
Most browsers allow you to block or delete cookies through settings. However, browser controls alone may not be sufficient to manage all consent preferences, so you should also use our cookie settings tool where available.
If our website or platform uses third-party services such as analytics tools, maps, embedded content, social media plugins, chat tools, advertising tags or video embeds, those providers may set their own cookies and process personal data under their own privacy notices.
13. Marketing Communications
Where permitted by law, we may send newsletters, updates, invitations, product information, insights or other communications about our services.
Where consent is required, we will do so only if you have opted in. Where permitted by law, we may rely on legitimate interests or a lawful soft opt-in rule, subject always to your right to opt out.
You can opt out of marketing communications at any time by using the unsubscribe mechanism in the communication or by contacting us.
14. Automated Decision-Making
We do not ordinarily make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals.
If this changes, we will provide any additional information required by law.
15. Changes to This Policy
We may amend this Privacy and Cookie Policy from time to time to reflect changes in law, regulation, technology, our services or our processing activities.
Any updated version will be posted on our website and the “Last updated” date will be amended accordingly. We encourage you to review this Policy periodically.
16. Contact Us
If you have questions about this Policy or our processing of your personal data, or if you wish to exercise your rights, please contact us at:
REG4TECH LTD
Address: 24 Piraeus street, 3rd floor, 2023 Strovolos, Nicosia, Cyprus
Email: info@reg4tech.com
Telephone: 22277222
Data Protection Officer / Privacy Contact: info@reg4tech.com