1. Introduction
Cycom Business Solutions Ltd. (Cycom) is committed to protecting your privacy and handling personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and the applicable data protection laws of the Republic of Cyprus.
This Privacy Policy explains how we collect, use, disclose, and protect personal data when you:
- visit our website;
- contact us;
- purchase or subscribe to our software products;
- use our software;
- request technical support.
2. About Cycom
Cycom Business Solutions Ltd. develops and supplies business software solutions, including:
- Accounting
- Inventory Management
- Payroll
- Human Resources (HR)
- Customer Relationship Management (CRM)
- Other business management applications
Our software is primarily supplied under a software licence for installation and operation within the customer’s own IT environment. We also offer certain products as hosted Software-as-a-Service (SaaS).
3. Personal Data We Collect
We may collect the following categories of personal information:
Contact Information
- Name
- Company name
- Job title
- Business address
- Telephone number
- Email address
Customer Information
- Licence or subscription details
- Billing information
- Customer account information
- Communications with our staff
- Technical support records
Website and Technical Information
When you visit our website or use our online services, we may collect:
- IP address
- Browser type
- Device information
- Operating system
- Website usage information
- Cookies and similar technologies (where applicable)
4. Customer Business Data
Licensed (On-Premises) Software
Our primary business is the development and licensing of software.
In most cases, our customers install and operate our software within their own IT environment. The customer is solely responsible for all business data entered into or processed by the software, including any personal data.
Cycom does not routinely access, host, store, monitor, or process customer business data.
Customers remain responsible for:
- compliance with applicable data protection laws;
- determining what personal data is processed;
- managing user access;
- maintaining backups;
- implementing appropriate security measures.
SaaS (Hosted Software)
Some customers choose to use our software as a hosted Software-as-a-Service (SaaS) solution.
In these cases, customer data is stored within infrastructure managed on behalf of Cycom. For Customer Data processed within our SaaS platform:
- the customer remains the Data Controller;
- Cycom acts as the Data Processor, processing Customer Data solely for the purpose of providing the hosted software service and in accordance with the customer’s documented instructions and applicable agreements.
Cycom does not use Customer Data for marketing or any purpose unrelated to providing the contracted services.
5. Technical Support
Customers may request technical assistance from Cycom.
For customers using licensed software, technical support may require temporary remote access to the customer’s systems. Such access:
- occurs only with the customer’s knowledge and permission;
- is limited to the time necessary to investigate and resolve the reported issue;
- is performed only for the purpose of providing the requested support;
- may be observed and terminated by the customer at any time.
Where Customer Data becomes visible during a support session, access is limited to what is reasonably necessary to diagnose and resolve the reported issue.
For customers using our SaaS platform, authorised Cycom personnel may access Customer Data only where necessary to provide technical support, maintain the service, or fulfil our contractual obligations.
All Cycom personnel are bound by confidentiality obligations.
6. How We Use Personal Information
We use personal information to:
- provide software licences and subscriptions;
- create and manage customer accounts;
- provide technical support;
- process orders and payments;
- communicate with customers;
- improve our products and services;
- maintain software licensing;
- protect the security and integrity of our systems;
- comply with legal and regulatory obligations.
7. Legal Basis for Processing
We process personal data on one or more of the following legal bases:
- performance of a contract;
- compliance with legal obligations;
- our legitimate business interests;
- consent, where required.
Where Cycom processes Customer Data within our SaaS environment, such processing is carried out on behalf of the customer in accordance with applicable contractual arrangements.
8. Sharing Personal Data
We do not sell personal information.
We may disclose personal information where necessary to:
- payment service providers;
- professional advisers;
- IT service providers;
- cloud infrastructure providers (for SaaS services);
- regulatory or governmental authorities where required by law.
All third-party service providers who process personal data on our behalf are required to implement appropriate security measures and maintain confidentiality.
9. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), Cycom ensures that appropriate safeguards are implemented in accordance with GDPR, including the use of European Commission approved Standard Contractual Clauses or other lawful transfer mechanisms where required.
10. Security
Cycom implements appropriate technical and organisational measures designed to protect personal data against:
- unauthorised access;
- accidental loss;
- alteration;
- destruction;
- unauthorised disclosure.
Depending on the services provided, these measures may include:
- encrypted communications;
- secure hosting environments;
- role-based access controls;
- authentication mechanisms;
- audit logging;
- regular software updates;
- backup and disaster recovery procedures;
- staff confidentiality obligations.
11. Data Retention
We retain personal information only for as long as necessary to:
- provide our products and services;
- maintain customer records;
- comply with legal, accounting, and taxation obligations;
- resolve disputes;
- enforce contractual rights.
For SaaS customers, Customer Data is retained in accordance with the applicable service agreement and deleted or returned following termination of the service, unless retention is required by law.
12. Your Rights
Under the GDPR, individuals may have the right to:
- access their personal data;
- request correction of inaccurate data;
- request erasure;
- request restriction of processing;
- object to processing;
- request data portability;
- withdraw consent where processing is based on consent;
- lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus.
Where Cycom processes Customer Data on behalf of a customer, requests relating to that data should generally be directed to the relevant customer, who acts as the Data Controller.
13. Cookies
Our website may use cookies and similar technologies to improve functionality, analyse website usage, and enhance the user experience.
Where required by law, consent will be obtained before non-essential cookies are placed on your device.
14. Third-Party Websites
Our website may contain links to third-party websites. Cycom is not responsible for the privacy practices or content of external websites.
15. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be published on our website together with the revised effective date.
16. Contact Us
If you have any questions regarding this Privacy Policy or the processing of personal data, please contact:
Cycom Business Solutions Ltd.
117 Strovolos Avenue, 3rd Floor, Strovolos 2093, Nicosia
Email: info@cycom.com.cy
Telephone: +357 22 470 000
Website: www.cycom.com.cy
Data Processing Statement
1. Purpose
This Data Processing Statement explains the role of Cycom Business Solutions Ltd. (“Cycom”) in relation to the data processed within the software applications that we develop and license.
Our software includes business management applications such as Accounting, Inventory Management, Payroll, Human Resources, and other related solutions.
2. Customer Ownership of Data
Customers who license Cycom software remain solely responsible for all data entered, stored, or processed using our software. This includes, but is not limited to:
- employee records;
- payroll information;
- customer information;
- supplier information;
- accounting records;
- inventory records;
- financial information;
- any personal data processed through the software.
The customer determines:
- what data is collected;
- how it is used;
- how long it is retained;
- who has access to it;
- how it is secured.
Cycom does not determine the purposes or means of processing customer data.
3. Software Provider
Cycom develops and licenses software applications. Our software is generally installed and operated within the customer’s own IT environment or infrastructure under the customer’s control.
Cycom does not routinely host, store, manage, monitor, or process customer business data as part of providing software licences.
4. Technical Support
From time to time, customers may request technical support. Where necessary, customers may grant Cycom temporary remote access to their systems to diagnose or resolve a reported issue.
Such access is:
- initiated only at the customer’s request;
- granted with the customer’s knowledge and permission;
- limited to the duration necessary to resolve the reported issue;
- carried out only for the specific support purpose requested.
Customers can terminate remote access at any time.
5. Limited Access to Customer Data
During a support session, Cycom personnel may incidentally view customer information where necessary to investigate or resolve a software issue.
Cycom:
- does not access customer data unless authorised by the customer;
- does not use customer data for any purpose other than providing the requested support;
- does not copy, analyse, or exploit customer data for commercial purposes;
- does not disclose customer data to third parties except where required by law.
Access to customer information is limited to the minimum reasonably necessary to provide support.
6. Confidentiality
All Cycom personnel providing customer support are subject to confidentiality obligations. Customer information accessed during support activities is treated as confidential and is used solely for the purpose of providing the requested technical assistance.
7. Security
Cycom implements appropriate technical and organisational measures to protect any information that may be accessed during a support session. Support personnel are authorised only to perform activities necessary to resolve the reported issue.
8. Customer Responsibilities
Customers remain responsible for:
- complying with the General Data Protection Regulation (GDPR) and other applicable data protection laws;
- maintaining appropriate security measures;
- managing user permissions;
- maintaining backups of their data;
- determining who may access their systems.
9. GDPR Roles
In most circumstances:
- the customer acts as the Data Controller in respect of the personal data processed within the software; and
- Cycom acts solely as the software supplier.
Where Cycom is granted temporary access to customer systems for support purposes, any processing of personal data is incidental, limited to the customer’s instructions, and performed solely for the purpose of providing the requested technical support.
10. Contact
If you have any questions regarding this Data Processing Statement, please contact:
Cycom Business Solutions Ltd.
117 Strovolos Avenue, 3rd Floor, Strovolos 2093, Nicosia
Email: info@cycom.com.cy
Telephone: +357 22 470 000
Website: www.cycom.com.cy