Privacy Policy
Last Updated: September 2026
his Privacy Policy (“Privacy Policy”) explains how TAXINCY LTD, a company incorporated and existing under the laws of the Republic of Cyprus, with registration number ΗΕ 431080 and registered office at 45 Pentadaktylou Street, Maroni, 7737 Larnaca, Cyprus (the “Company”, “we”, “us” or “our”), collects, uses, stores, discloses and otherwise processes personal data in connection with our website www.taxincy.com (the “Website”), our services, our communications with you and our other business activities.
We are committed to protecting personal data and processing it in accordance with Regulation (EU) 2016/679 (the “GDPR”) and applicable Cyprus data protection legislation.
This Privacy Policy explains what personal data we collect, why and how we use it, the legal bases on which we rely, who we may share it with, how long we retain it, how we protect it and the rights available to you in relation to your personal data.
Please read this Privacy Policy carefully and ensure that you understand it. This Privacy Policy is intended to give you a better understanding of the personal data we collect, the reason why we collect such data, the manner in which we process this data, the entities with whom we share the said personal data, your rights in relation to the collection, processing and sharing of such data and any other pertinent matter relating to privacy and security of your personal data. We understand that your privacy is important to you and that you care about how your personal data is used and shared online. We respect and value the privacy of everyone who visits our Website and will only collect and use personal data in ways that are described here, and in a manner that is consistent with our obligations and your rights under national and international laws and regulations.
Under the applicable laws, we are required to comply with personal data protection and processing procedures to ensure that your data is at all times stored and processed securely and that your rights as a data subject are observed and protected. We take these obligations very seriously and have implemented adequate technical and organizational measures to ensure protection of your privacy.
All processing of your personal data performed by us as envisaged in this Privacy Policy shall be carried out in line with the following laws and regulations, as well as all binding acts amending or implementing the same (hereafter collectively referred to as the “Data Protection Laws”):
- Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).
What Does This Privacy Policy Cover?
This Privacy Policy applies to personal data processed by us in connection with:
- your access to and use of the Website;
- enquiries or requests submitted to us;
- our provision of products and services;
- communications and correspondence with you;
- our business relationships with customers, suppliers, partners and other business contacts;
- recruitment and employment-related activities; and
- other interactions with us where no separate privacy notice applies.
The Website may contain links to websites or services operated by third parties. We are not responsible for the privacy practices of such third parties and recommend that you review their applicable privacy notices before providing them with your personal data.
Legal Basis for Processing
Depending on the circumstances and the nature of our relationship with you, we may process your personal data on one or more of the following legal bases:
- Performance of a contract: where processing is necessary for the performance of a contract with you or to take steps at your request before entering into a contract;
- Legal obligation: where processing is necessary for compliance with a legal or regulatory obligation to which we are subject;
- Legitimate interests: where processing is necessary for our legitimate interests or those of a third party, provided that such interests are not overridden by your interests or fundamental rights and freedoms. Our legitimate interests may include operating and developing our business, managing business relationships, maintaining the security of our systems and Website, preventing fraud and protecting our legal rights;
- Consent: where we rely on your consent for a particular processing activity. Where processing is based on consent, you may withdraw your consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before withdrawal;
- Establishment, exercise or defence of legal claims: where processing is necessary for the establishment, exercise or defence of legal claims, relying on the applicable legal basis under the GDPR, including our legitimate interests where appropriate.
Which Data We Process
The paragraphs below outline the categories of personal data which we process, the purpose for which we process such personal data as well as the corresponding legal basis used for such processing. Note that some categories of personal data may be processed on several legal grounds and/or for several purposes.
We do not currently carry out automated decision-making, including profiling, which produces legal effects or similarly significantly affects individuals.
Sources of Personal Data
We generally collect personal data directly from you. However, depending on the circumstances, we may also obtain personal data from:
- your employer or organisation;
- our customers, suppliers or business partners;
- professional advisers and service providers;
- recruitment agencies and references;
- publicly available sources; and
- other third parties where permitted by applicable law.
Where we obtain personal data from a source other than you, we will process such data in accordance with applicable data protection legislation and the relevant transparency requirements.
Direct Marketing
Where permitted by applicable law, we may use your contact details to provide you with information regarding our services, business developments, industry events and other communications that may be relevant to you.
Where required by applicable law, we will obtain your consent before sending electronic direct marketing communications.
You may unsubscribe from marketing communications at any time by using the unsubscribe mechanism included in the relevant communication or by contacting us at info@taxincy.com.
Your Rights
As a data subject, you have the following rights under the GDPR, which this Privacy Policy and our use of personal data have been designed to uphold. Please contact us at info@taxincy.com for more information, or to exercise these rights.
Subject to the conditions and limitations provided under applicable data protection legislation, you may have the following rights in relation to your personal data:
- the right to access your personal data;
- the right to request rectification of inaccurate or incomplete personal data;
- the right to request erasure of your personal data;
- the right to request restriction of processing;
- the right to object to processing, including processing based on our legitimate interests and processing for direct marketing purposes;
- the right to data portability, where applicable; and
- the right to withdraw consent where processing is based on consent.
You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection in Cyprus or another competent supervisory authority, where applicable.
Personal Data Storage, Security and Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, regulatory, accounting or reporting requirements, and for the establishment, exercise or defence of legal claims.
The applicable retention period will depend on the nature of the personal data and the purpose for which it is processed. In determining retention periods, we take into account the amount, nature and sensitivity of the personal data, the purposes for which it is processed, applicable legal and regulatory requirements and whether the purposes can be achieved through other means.
When personal data is no longer required, we will securely delete or anonymise it, where appropriate.
We implement appropriate technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access or other unlawful forms of processing.
These measures may include access controls, authentication mechanisms, encryption where appropriate, network and system security measures, backup procedures, monitoring and other organisational and technical safeguards appropriate to the nature and risks of the processing.
However, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure.
Sharing Your Personal Data
We may disclose personal data where necessary for the purposes described in this Privacy Policy and in accordance with applicable law. Recipients may include:
- companies within our corporate group, where necessary for the operation and management of our business;
- IT, hosting, cloud, software and other technology service providers;
- website analytics and digital service providers;
- professional advisers, including lawyers, auditors, accountants and consultants;
- payment, banking or other financial service providers, where relevant;
- competent authorities, regulators, courts and law enforcement bodies where required or permitted by law; and
- other service providers or third parties where disclosure is necessary for the provision of our services or otherwise permitted by law.
Where a third party processes personal data on our behalf, we will take appropriate steps to ensure that the processing is carried out in accordance with applicable data protection legislation and that appropriate contractual safeguards are in place.
Where we transfer personal data outside the European Economic Area (“EEA”), we will ensure that the transfer is carried out in accordance with applicable data protection legislation and that an appropriate transfer mechanism and safeguards are in place where required, such as an adequacy decision, Standard Contractual Clauses or another lawful transfer mechanism.
Our Use of Cookies
We use cookies and similar technologies on our Website. Some cookies are necessary for the operation, security and functionality of the Website, while others may be used for analytics, performance and marketing purposes.
Where required by applicable law, we will obtain your consent before placing or accessing non-essential cookies or similar technologies on your device.
You can manage your cookie preferences through our cookie consent mechanism and, where applicable, through your browser settings.
Further information about the cookies and similar technologies we use, including their purposes, providers and retention periods, is provided below.
You can at any time deactivate and delete cookies through your browser settings.
Used by Meta to deliver a series of advertisement products such as real-time bidding from third-party advertisers and to track traffic sources.
Contacting Us
If you have any questions about the Website or this Privacy Policy, please contact us by email at info@taxincy.com.
Changes to Our Privacy Policy
We may change this Privacy Policy from time to time. Changes will be immediately posted on the Website and will be deemed to have been accepted on your first use of the Website following the alterations in the Privacy Policy. We recommend that you check this page regularly to remain up to date with any changes. Where appropriate, we will also notify you by e-mail. In the event that you do not agree with any changes, you must stop using the Website.
Definitions
In this Privacy Policy, the following terms shall have the following meanings:
data controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by European Union or Member State law, the controller or the specific criteria for its nomination may be provided for by European Union or Member State law.
data processor: means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
processing: means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
personal data: means any and all data that relates to you as an identifiable person who can be directly or indirectly identified from that data. In this case, it means personal data that you give to us via the Website or that we collect via the Website. This definition shall, where applicable, incorporate the definitions provided in the GDPR.
you/your: means you, the individual using the Website.