1. Who is responsible for your data
The data controller for the personal data described in this policy is:
HALDIR LTD
Filippou, 11 Agios Dometios, 2363, Nicosia, Cyprus
Registration number: HE 459882
Email: [email protected]
HALDIR LTD is established in the Republic of Cyprus, a Member State of the European Union, and processes personal data in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable Cypriot data protection legislation.
We are not required to appoint a Data Protection Officer under Article 37 GDPR. All privacy matters are handled directly by the company at the address above.
2. Scope of this policy
This policy applies to personal data we process:
- when you visit haldir.info or any of its pages;
- when you contact us by email or other written means;
- in the course of a business relationship with a client, supplier or partner, in respect of the individuals involved.
It does not apply to personal data that we process on behalf of a client while providing software development services — see section 16.
3. The short version
This is an ordinary corporate website. It has no analytics, no tracking pixels, no advertising networks and no third-party scripts. Fonts and every other asset are served from our own domain, so loading a page does not tell any other company that you were here.
The only thing this site stores in your browser is a small preference recording whether you chose the light or dark theme. It is not an identifier and is never sent to us.
If you email us, we process what you write in order to answer it. That is the whole of it. The sections below set out the detail required by the GDPR.
4. Personal data we process
4.1 Information you provide to us
When you write to us — by email, or by using the enquiry form on our contact page, which composes a message in your own email application — we receive whatever you choose to include. Typically:
- your name;
- your email address;
- the name of your organisation and your role;
- the content of your message and any attachments;
- any other contact details you volunteer.
Please do not send us special categories of personal data (Article 9 GDPR) or confidential material by unencrypted email unless we have agreed a secure channel first.
4.2 Information collected automatically
Like every web server, the server hosting this Site records technical details of the requests it receives. These logs may contain:
- your IP address;
- the date and time of the request;
- the page or file requested and the HTTP status returned;
- the referring URL, where your browser sends one;
- your browser user-agent string.
These logs are generated by our hosting provider for security and operational purposes. They are not used to build a profile of you, are not combined with any other data set, and are not used for marketing.
4.3 What we do not collect
- We do not operate analytics or measurement tools on this Site.
- We do not use advertising, remarketing or social media tracking pixels.
- We do not load fonts, scripts, stylesheets or images from third-party servers.
- We do not operate a newsletter or maintain a marketing mailing list.
- We do not buy, sell or rent personal data.
4.4 The enquiry form
The form on our contact page is not submitted to any server. It assembles the text you have typed into a draft email in your own mail application, which you then review and send yourself. Nothing you type is transmitted to this Site, and there is no database of form submissions.
5. Purposes and legal bases
Article 6 GDPR requires a lawful basis for each processing activity. Ours are as follows.
| Purpose | Data involved | Legal basis |
|---|---|---|
| Responding to your enquiry and any follow-up correspondence | Name, email address, organisation, message content | Article 6(1)(b) — steps at your request prior to entering into a contract; or Article 6(1)(f) — our legitimate interest in answering business correspondence |
| Negotiating, concluding and performing a contract for our services | Contact and business details of the individuals involved | Article 6(1)(b) — performance of a contract |
| Issuing invoices and meeting accounting and tax obligations | Billing contact details, transaction records | Article 6(1)(c) — compliance with a legal obligation under Cypriot law |
| Keeping the Site available and secure; investigating abuse | Server log data, including IP address | Article 6(1)(f) — our legitimate interest in network and information security |
| Establishing, exercising or defending legal claims | Correspondence and contract records as relevant | Article 6(1)(f) — our legitimate interest in protecting our legal position |
| Remembering your light or dark theme preference | A single value stored in your browser; no personal data reaches us | Strictly necessary to provide a function you requested; no consent required |
Where we rely on legitimate interests, we have assessed that our interest in operating an ordinary business website and answering correspondence does not override your rights and freedoms. You may object to this processing at any time — see section 11.
7. Who we share data with
We do not sell or rent personal data. We disclose it only in these situations:
- Hosting provider. The company hosting this Site processes server log data on our behalf as a processor under Article 28 GDPR.
- Email provider. Our corporate email is operated by a business email provider that processes the content of correspondence on our behalf as a processor.
- Professional advisers. Accountants, auditors and lawyers, where necessary and subject to professional confidentiality obligations.
- Public authorities. Where we are required to disclose data by law, by a court order, or by a competent regulator.
- Business transfer. In the event of a merger, acquisition or sale of assets, subject to the acquirer being bound by equivalent protections.
Every processor acts only on our documented instructions and under a written contract containing the terms required by Article 28 GDPR. We will identify our current processors on request to [email protected].
8. International transfers
We prefer service providers that process data within the European Economic Area. Where a transfer outside the EEA is unavoidable, we ensure an appropriate safeguard under Chapter V GDPR is in place — normally an adequacy decision of the European Commission, or the European Commission's Standard Contractual Clauses supplemented where necessary by additional technical measures.
You may request a copy of the safeguard applying to a particular transfer by writing to us.
9. How long we keep data
We keep personal data only as long as there is a reason to:
| Category | Retention period |
|---|---|
| Enquiries that do not lead to a business relationship | Up to 24 months from the last message, then deleted |
| Correspondence with clients and suppliers | For the duration of the relationship and 6 years afterwards, in line with limitation periods for contractual claims |
| Accounting and tax records | 6 years, as required by Cypriot law |
| Server access logs | Typically no longer than 12 months, unless retained for the investigation of a specific security incident |
| Theme preference in your browser | Until you clear your browser storage; never held by us |
When a retention period expires, data is deleted or irreversibly anonymised.
10. Security
We apply technical and organisational measures appropriate to the risk, as required by Article 32 GDPR. These include:
- encryption of the Site in transit using HTTPS/TLS;
- access to correspondence and business systems restricted to the individuals who need it, protected by strong authentication;
- credentials held in a managed secret store and rotated when personnel or providers change;
- timely application of security updates to the systems we operate;
- a deliberately minimal attack surface — this Site is a set of static files with no database, no login and no server-side form processing.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Commissioner for Personal Data Protection within 72 hours and inform you without undue delay where the law requires it.
11. Your rights
Subject to the conditions and exceptions in the GDPR, you have the following rights in relation to your personal data:
- Access (Article 15) — to be told whether we process data about you, and to receive a copy of it.
- Rectification (Article 16) — to have inaccurate data corrected and incomplete data completed.
- Erasure (Article 17) — to have your data deleted where there is no overriding reason for us to keep it.
- Restriction (Article 18) — to have processing limited in certain circumstances, for example while accuracy is being verified.
- Portability (Article 20) — to receive data you provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.
- Objection (Article 21) — to object at any time to processing based on our legitimate interests, on grounds relating to your particular situation.
- Withdrawal of consent (Article 7(3)) — where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing before withdrawal.
12. Exercising your rights
Write to [email protected] and tell us what you would like us to do. There is no form to fill in.
- We respond within one month of receiving your request. Where a request is complex or where several have been received, we may extend that period by up to two further months and will tell you if we do.
- Exercising your rights is free of charge. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive.
- We may ask for information to confirm your identity where we have reasonable doubts about it. We will not ask for more than is necessary.
13. Complaints
If you are not satisfied with how we have handled your data or your request, we would prefer to hear from you first at [email protected] so that we can put it right.
You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). Our lead supervisory authority is:
Office of the Commissioner for Personal Data Protection
Republic of Cyprus
Website: www.dataprotection.gov.cy
If you are resident in another EU or EEA country, you may instead complain to the supervisory authority of that country or of the place where the alleged infringement occurred.
14. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR, and we do not carry out profiling.
15. Children
This Site and our services are directed at businesses and professionals. They are not intended for children, and we do not knowingly collect personal data relating to children. If you believe a child has provided us with personal data, please contact us and we will delete it.
16. Personal data we process for clients
When we develop, integrate or maintain software for a client, that client's systems may contain personal data belonging to their own customers, employees or users. In relation to that data, the client is the controller and HALDIR LTD acts as a processor.
In that role:
- we process personal data only on the client's documented instructions;
- we work under a written data processing agreement containing the terms required by Article 28 GDPR;
- we prefer to work with anonymised, pseudonymised or synthetic data in development and testing environments, and recommend this wherever it is workable;
- our personnel are bound by confidentiality obligations;
- we engage a sub-processor only with the client's prior authorisation;
- we assist the client with data subject requests, breach notification and impact assessments as required;
- on termination we delete or return the personal data, at the client's choice.
If you are an individual whose data is held in a system we maintain for a client, please direct your request to that client as controller. We will forward any request we receive directly and assist them in responding.
17. Changes to this policy
We may update this policy to reflect changes in our practices, our providers or the law. The current version is always published on this page with its effective date shown at the top.
Where a change materially affects how we process your personal data, we will take reasonable steps to inform you — for example by email, where we hold an address for you and the change warrants it.
18. Contact
For any question about this policy, about how we process personal data, or to exercise your rights:
HALDIR LTD
Filippou, 11 Agios Dometios, 2363, Nicosia, Cyprus
Registration number: HE 459882
Email: [email protected]
See also our Terms and Conditions and Cookie Policy.