Privacy Policy
BitNova IT Tech Solutions
Registered office: Nicosia, Cyprus · bitnovait.eu
Last updated: May 2025This Privacy Policy describes how BitNova IT Tech Solutions ("BitNova", "we", "us", "our") collects, uses and protects personal data in accordance with the EU General Data Protection Regulation (GDPR — Regulation 2016/679) and the applicable laws of the Republic of Cyprus. By using our website or engaging our services, you acknowledge this Policy.
1. Who We Are
BitNova IT Tech Solutions is a managed IT and cybersecurity services provider registered in Cyprus, providing IT support, cybersecurity, cloud services and specialised IT solutions to businesses across Cyprus.
- Company: BitNova IT Tech Solutions
- Registered office: Nicosia, Cyprus
- Operations: Nicosia & Larnaca, Cyprus
- Website: www.bitnovait.eu
- Email: info@bitnovait.eu
- Phone: +357 95 192 996
- Business hours: Mon–Fri 09:00–18:00
2. Definitions
The following definitions apply throughout this Policy:
3. Data Protection Officer (DPO)
BitNova has appointed a responsible person for all matters relating to personal data protection:
For any questions, requests or complaints regarding your personal data, contact the DPO directly.
4. Personal Data We Collect
The personal data we collect varies depending on the services you use and your relationship with us. We collect data in the following ways:
- When you submit a contact or assessment request via our website
- When you engage our services and sign a Service Agreement
- During telephone or in-person communication with our team
- Through the use of our remote support and ticketing systems
- Through cookies and website analytics tools (with consent)
- From third parties where lawfully permitted (e.g. for fraud prevention)
| Category | Data Collected | Purpose |
|---|---|---|
| Identity | Name, job title | Service delivery, communication |
| Contact | Email, phone, address | Communication, support |
| Business | Company name, size, sector | Proposal and service scoping |
| Technical | IP address, device info, system data | Remote support, security monitoring |
| Billing | Invoice details, payment records | Billing, accounting (not card data — processed by payment provider) |
| Usage | Website visit data, browsing duration | Analytics, service improvement |
| Communications | Emails, support tickets, call records | Support history, quality assurance |
5. Legal Basis for Processing
We process your personal data under the following legal bases (Article 6 GDPR):
- Contractual necessity (Art. 6(1)(b)): Processing required to deliver services you have engaged us for — e.g. providing remote IT support requires access to your systems
- Legal obligation (Art. 6(1)(c)): Compliance with Cyprus tax law (Law 95(I)/2000, Law 4/1978), accounting requirements and Law 183(I)/2007 for law enforcement requests
- Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, service improvement — balanced against your rights
- Consent (Art. 6(1)(a)): For marketing communications, cookies and automated profiling — you may withdraw consent at any time
6. Automated Processing & Profiling
BitNova may use automated means to analyse how our website is used (e.g. pages visited, time on site) for the purpose of improving our services and personalising content. This profiling does not produce legal effects or significantly affect you.
You have the right to object to automated processing and profiling at any time by contacting our DPO. See Section 9 for your full rights.
7. How We Use Your Data
- To deliver the IT services and managed support you have contracted with us
- To send invoices, payment reminders and service communications
- To provide technical support and resolve issues via remote or on-site assistance
- To communicate relevant service updates, security alerts or renewal notices
- To comply with legal obligations under Cyprus and EU law
- To detect, prevent and investigate security incidents or fraud
- To improve our website and service offerings
We do not sell, rent or transfer your personal data to third parties for marketing purposes.
8. Data Retention
We retain personal data only for as long as necessary for the purposes set out in this Policy, or as required by applicable Cyprus law:
- Contact enquiries: 24 months from last contact
- Client service records: Duration of contract + 7 years (Cyprus tax law — Law 95(I)/2000)
- Accounting & billing records: 7 years (Law 4/1978 and Law 95(I)/2000)
- Law enforcement requests: As required under Law 183(I)/2007
- Support tickets and communications: 3 years
- Website analytics: 14 months
- Job applications / CVs: 6 months
- Marketing consent records: Until withdrawal of consent + 1 year
9. Your Rights Under GDPR
As a data subject, you have the following rights under GDPR and applicable Cyprus law:
- Right of access (Art. 15): Request a copy of the personal data we hold about you
- Right to rectification (Art. 16): Request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): Request deletion of your data in certain circumstances ("right to be forgotten")
- Right to restriction (Art. 18): Request that we limit how we use your data
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing
- Right to object to automated processing (Art. 22): Object to decisions made solely by automated means, including profiling
- Right to withdraw consent: At any time — withdrawal does not affect prior lawful processing
- Right to judicial review: If we refuse a request, we will explain why. You may lodge a complaint with the supervisory authority
To exercise any of these rights, contact our DPO at info@bitnovait.eu. We will respond within 30 days. We may request proof of identity before processing your request.
10. Sharing of Personal Data
We do not sell or share your personal data with third parties for commercial purposes. We may share data with:
- Service providers: Cloud infrastructure, email delivery, IT tools — under strict data processing agreements
- Professional advisors: Legal, accounting or audit purposes where necessary
- Regulatory authorities: Where required by Cyprus law or EU regulation
- Business transfers: In the event of a merger, acquisition or restructuring, your data may be transferred to the acquiring entity under equivalent protections
All third parties are required to maintain confidentiality and comply with applicable data protection laws.
11. International Transfers
Your personal data is processed within the European Economic Area (EEA). Where any transfer outside the EEA is necessary (e.g. certain cloud service providers), we ensure appropriate safeguards are in place in accordance with Article 46 of the GDPR — including Standard Contractual Clauses or adequacy decisions.
12. Data Security
As an IT security company, data protection is fundamental to how we operate. We implement appropriate technical and organisational measures including:
- SSL/TLS encryption for all data in transit
- Access controls and multi-factor authentication
- Regular security assessments and vulnerability monitoring
- Secure remote access protocols for support activities
- Staff training on data protection and information security
13. Cookies
Our website uses cookies to ensure functionality and improve your experience:
- Strictly necessary: Required for the website to function — no consent required
- Analytics: Help us understand website usage — requires your consent
- Marketing: We do not currently use marketing or tracking cookies
You can manage or withdraw cookie consent at any time through your browser settings or our cookie banner.
14. Complaints
If you believe your personal data has not been handled correctly, you have the right to lodge a complaint with the Cyprus Commissioner for Personal Data Protection:
- Website: www.dataprotection.gov.cy
- Email: commissioner@dataprotection.gov.cy
- Phone: +357 22 818 456
- Address: 1 Iasonos Street, 1082 Nicosia, Cyprus
We encourage you to contact us first — we will make every effort to resolve any concern promptly.
15. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will always be available on this page with the date of last update. For significant changes, we will notify existing clients by email with at least 30 days notice. Continued use of our services after that period constitutes acceptance of the updated Policy.
Data Protection Officer: Kyriakos Arnaoutis · info@bitnovait.eu · +357 95 192 996
BitNova IT Tech Solutions · Nicosia, Cyprus · www.bitnovait.eu