Privacy Policy

1. Introduction

C. Topouzis & Associates (“we”, “us”, “our”) is committed to protecting your personal data and to processing it lawfully, fairly and transparently. This Privacy Policy explains how we collect, use, store, disclose and safeguard your personal data when you visit our website, contact us, or engage our legal services. It also explains your rights and how to exercise them.

We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (the “GDPR”) and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data of 2018 (Law 125(I)/2018).

2. Who We Are (Data Controller)

The data controller responsible for your personal data is:

C. Topouzis & Associates

Nikis Avenue 23, 1st Floor, Office 101

1086 Nicosia, Cyprus

Telephone: +357 22 262454 / +357 99 272983

Email: info@topouzislegal.com

Website: www.topouzislegal.com

We are a firm of advocates regulated by the Cyprus Bar Association (registration no. 6137) and are subject to the Advocates Law (Cap. 2) and to the professional conduct and anti-money-laundering rules made under it. If you have any question about this Policy or about how we handle your personal data, please contact us using the details above.

3. Scope of This Policy

This Policy applies to personal data we process about: visitors to our website; prospective clients who contact us; clients who engage our services; and other individuals whose data we process in the course of our work — for example, the representatives or beneficial owners of corporate clients, counterparties, and witnesses.

In most of our professional work we act as an independent data controller of the personal data we hold. In some engagements, where we process personal data strictly on a client’s instructions, the client may be the controller and we the processor. If you apply for a position with us, a separate recruitment privacy notice applies to that process.

4. Information We Collect

We may collect and process the following categories of personal data:

  • Contact information: name, email address, phone number, and the content of any message you send to us by email, telephone or post.
  • Technical data: IP address, browser type and version, operating system, and referring URL, collected automatically when you visit our website.
  • Professional engagement data: information provided in connection with our legal services, including identification and verification documents required for anti-money-laundering (AML) and know-your-client (KYC) compliance, and information relating to your matter (which may include personal data about third parties).

We do not seek to collect special categories of personal data (such as health data, political opinions, or biometric data) through this website. Where the nature of a matter requires us to process special-category data — for example, health data in a personal-injury claim — we do so on an appropriate condition under Article 9 GDPR, typically the establishment, exercise or defence of legal claims.

5. How We Collect Your Data

  • Directly from you: when you email us, instruct us, or communicate with us by telephone, post or in person. Our website does not operate a contact form: an enquiry reaches us as an ordinary email sent from your own email account.
  • Automatically: through essential cookies required for the website to function. Third-party content (such as Google Maps) is loaded only with your explicit consent.
  • From other sources: in the course of a matter we may also receive personal data from third parties, such as your other professional advisers, public registries, courts, and counterparties.

6. Legal Bases for Processing

We process your personal data on the following legal bases under Article 6(1) GDPR:

  • Consent (Art. 6(1)(a)): when you consent to the loading of third-party content, such as Google Maps on our contact page. You may withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal.
  • Contractual necessity (Art. 6(1)(b)): when processing is necessary to perform a contract with you, or to take steps at your request before entering into one.
  • Legal obligation (Art. 6(1)(c)): when we must process your data to comply with a legal obligation, including AML/KYC requirements under Cyprus and EU law.
  • Legitimate interests (Art. 6(1)(f)): when processing is necessary for our legitimate interests — such as the security and administration of our practice, the conduct and defence of legal claims, and improving our website — provided those interests are not overridden by your fundamental rights and freedoms.

7. How We Use Your Data

We use your personal data to:

  • respond to your enquiries and provide information about our services;
  • provide legal services and fulfil our contractual obligations;
  • comply with our legal, regulatory and professional obligations, including AML/KYC requirements;
  • establish, exercise or defend legal claims and protect our rights and interests as permitted by law;
  • maintain and improve the functionality and security of our website.

8. Cookies and Tracking Technologies

Our website uses only essential cookies required for its basic operation. We do not use analytics, advertising, or tracking cookies.

Our contact page may embed Google Maps to display our office location. This content loads only after you provide explicit consent via our cookie banner or the “Load Map” button. When loaded, Google Maps may set its own cookies and collect data in accordance with Google’s privacy policy. You may withdraw your cookie consent at any time by clearing your browser’s local storage for this website.

9. Disclosure of Your Data (Recipients)

We do not sell, rent or trade your personal data. We may disclose it to:

  • Service providers: third parties that host our website and our email, bound by appropriate data-processing agreements. In particular, our website and our email service are provided by Namecheap, Inc. (including its Private Email service), and we access our mailboxes using Microsoft Outlook software supplied by Microsoft Corporation. Depending on the Outlook application and device used, message content may be synchronised or cached on infrastructure operated by Microsoft.
  • Professional advisers and experts: accountants, auditors, counsel, translators and other professionals engaged in connection with your matter.
  • Courts and parties to a matter: courts, tribunals, counterparties and their advisers, and other parties, where necessary to conduct your matter.
  • Authorities: regulatory, supervisory and law-enforcement authorities where required or permitted by law — including, where applicable, the Unit for Combating Money Laundering (MOKAS) and the Cyprus Bar Association.

We are subject to duties of legal professional confidentiality and privilege. Where the law requires or permits us to make a disclosure (for example, a suspicious-transaction report under AML legislation), we will do so strictly in accordance with our legal and professional obligations.

10. International Data Transfers

Our client and matter files are held within the European Economic Area (EEA).

Our website hosting and our email service are provided by Namecheap, Inc., and the Outlook software we use to access our mailboxes is supplied by Microsoft Corporation. Both are established in the United States. Correspondence you send us by email — including the content of your message and any attachments — is therefore stored and processed using services provided by companies established outside the EEA, and may be subject to access under the laws of that country.

Where personal data is transferred outside the EEA, we rely on the safeguards required by Chapter V GDPR — in particular the Standard Contractual Clauses approved by the European Commission, together with the data-processing terms of the providers concerned.

Email is a convenient but inherently insecure medium. If you would prefer not to send confidential or sensitive information by email, you are welcome to telephone us on +357 22 262454, or to deliver documents to our office in person or by post.

11. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected and to meet our legal, regulatory and professional obligations:

Category

Retention period

Email enquiries

Up to 12 months from your enquiry, unless an engagement follows.

AML/KYC and transaction records

Minimum of five (5) years after the end of the business relationship (Law 188(I)/2007, as amended); extendable where a competent authority so requires.

Client and matter files

Retained for six (6) years after a matter is concluded, having regard to limitation periods for legal claims under the Limitation of Actionable Rights Law (Cap. 15) and to our professional obligations.

Cookie-consent preferences

Stored in your browser until you withdraw consent or clear your browser data.

When personal data is no longer required, we securely delete or anonymise it.

12. Data Security

We maintain appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access (Article 32 GDPR). Access to personal data is limited to those who need it for the purposes described in this Policy, and our personnel are bound by duties of confidentiality.

13. Personal Data Breaches

We have procedures to detect, investigate and respond to suspected personal-data breaches. Where a breach is likely to result in a risk to your rights and freedoms, we will notify the Commissioner for Personal Data Protection, and you, to the extent and within the timeframes required by Articles 33 and 34 GDPR.

14. Automated Decision-Making and Profiling

We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or that similarly significantly affect you (Article 22 GDPR).

15. Is the Provision of Your Data Mandatory?

You are not required to provide personal data simply to browse our website. However, where you ask us to act for you, the provision of certain data is a statutory and contractual requirement — in particular the identification and verification data required under AML/KYC law. If you do not provide it, we will not be able to accept your instructions or act on your behalf.

16. Your Rights Under the GDPR

Under the GDPR and Law 125(I)/2018, you have the following rights:

Right

What it means

Access (Art. 15)

Confirmation of whether we process your data, and a copy of it.

Rectification (Art. 16)

Correction of inaccurate or incomplete data.

Erasure (Art. 17)

Deletion of your data where there is no overriding reason to keep it.

Restriction (Art. 18)

Restriction of processing in certain circumstances.

Portability (Art. 20)

Receipt of your data in a structured, commonly used, machine-readable format.

Objection (Art. 21)

To object to processing based on legitimate interests or to direct marketing.

Automated decisions (Art. 22)

Not to be subject to a decision based solely on automated processing (see section 14).

Withdraw consent

To withdraw consent at any time, without affecting prior lawful processing.

These rights are not always absolute. In particular, where we are required to retain or process data to comply with a legal or regulatory obligation (such as AML record-keeping), or for the establishment, exercise or defence of legal claims, or where legal professional privilege or confidentiality applies, we may be unable to give full effect to a request — in which case we will explain our reasons.

To exercise any of these rights, contact us at info@topouzislegal.com. We will respond within one month. That period may be extended by up to two further months where a request is complex or numerous, in which case we will inform you. We will not charge a fee unless a request is manifestly unfounded or excessive.

17. Supervisory Authority

If you believe our processing of your personal data infringes your rights, you may lodge a complaint with the Cyprus supervisory authority:

Commissioner for Personal Data Protection

1 Iasonos Street, 1082 Nicosia, Cyprus

P.O. Box 23378, 1682 Nicosia

Tel: +357 22 818 456 · Fax: +357 22 304 565

Email: commissioner@dataprotection.gov.cy

Website: www.dataprotection.gov.cy

We would welcome the opportunity to address your concerns directly, so please consider contacting us first.

18. Children’s Data

Our website and services are not directed at children. We do not knowingly collect personal data from individuals under the age of 14 — the age of digital consent in Cyprus under Law 125(I)/2018. If we become aware that we have collected a child’s data without appropriate parental consent, we will take steps to delete it promptly.

19. Legal Framework

This Policy is governed by, and should be read together with:

  • The General Data Protection Regulation (EU) 2016/679 (GDPR);
  • The Processing of Personal Data (Protection of Individuals) Law of 2018 (Law 125(I)/2018);
  • Where relevant to our processing, the Prevention and Suppression of Money Laundering Activities Law (Law 188(I)/2007, as amended) and the Advocates Law (Cap. 2).

20. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. The current version will always be available on this page, with the “Last updated” date shown above.

Call