Privacy

Privacy Policy

1. Controller and Contact Details

Welcome to the privacy policy of S. F. Custos Global Reach Ltd. This document outlines how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable national data protection frameworks. The designated data controller responsible for the processing of your personal information is S. F. Custos Global Reach Ltd, managed by Director Benjamin Traunecker.

Our official company registration number is HE 490688, and our registered VAT number is 60348430E. Our primary place of business is located at Lordou Vyronos 61-63, 6th floor, Flat/Office 602, Larnaca 6023, Cyprus. For any enquiries regarding your privacy, data protection practices, or to exercise your rights under the GDPR, you may reach our office by telephone at +357 or via email at office@custosglobal.com.

2. Scope and Purpose

This privacy policy applies to all personal data collected through our website, communications, and the course of our business operations. The primary purpose of processing your data is to provide secure, professional security consulting services, ensure the functional operation of our digital platforms, and communicate with you effectively. We are committed to the principle of data minimization, meaning we only collect and process the personal information that is strictly necessary for the stated operational and legal purposes.

3. Categories of Personal Data

Depending on your interaction with our company, we may process various categories of personal data. These generally include identity information such as your first name, last name, and professional title. We also process contact data, which encompasses your email address, telephone number, and physical billing or operational address. Furthermore, when you navigate our digital platforms, we may collect technical data, including your internet protocol (IP) address, browser type, device information, and time zone settings. For ongoing consulting relationships, we additionally process financial and transaction data strictly to facilitate billing, administration, and service fulfillment.

4. Sources of Data

The vast majority of the personal data we process is provided directly by you during active interactions, such as filling out contact forms, booking appointments, subscribing to our communications, or engaging our consulting services. Additionally, some technical data is gathered automatically as you navigate our website through the use of server logs and consent-managed cookies. In limited professional circumstances, we may receive basic contact information from public registers, verified business partners, or referrals, strictly subject to applicable legal safeguards.

5. Legal Bases under Article 6 GDPR

All processing of personal data by our company is founded on a valid legal basis as defined by Article 6 of the GDPR. We process data primarily on the following legal grounds:

  • Consent (Art. 6(1)(a)): Used when you actively opt-in to non-essential cookies, newsletters, or specific marketing communications.
  • Contractual Necessity (Art. 6(1)(b)): Relied upon when processing is required to deliver our security consulting services or take pre-contractual steps at your request.
  • Legal Obligation (Art. 6(1)(c)): Applied when we must retain records to comply with statutory accounting, tax, and corporate regulations in Cyprus.
  • Legitimate Interests (Art. 6(1)(f)): Utilized for securing our website infrastructure, preventing fraud, and optimizing basic operational workflows, provided your fundamental rights do not override these interests.

6. Contact Requests and Business Enquiries

When you contact us via email, phone, or direct correspondence, we process your submitted information solely to review, route, and respond to your specific enquiry. We treat all incoming requests with strict confidentiality. The legal basis for processing this information is our legitimate interest in managing corporate communications effectively, or, if your request pertains to a potential service engagement, the necessity to perform pre-contractual measures.

7. Client Relationship and Service Delivery

Once a formal client relationship is established, we process your personal and corporate data to fulfill our advisory and security consulting obligations. This includes project management, communication, delivering strategic assessments, and subsequent administrative tasks such as invoicing and payment processing. Data processed within this context is kept strictly confidential and is maintained exclusively on a need-to-know basis within our organization to protect client integrity.

8. Appointment Booking through LatePoint

To facilitate efficient scheduling, our website utilizes the LatePoint appointment booking system. When you schedule a consultation, you will be asked to provide your name, contact details, and the preferred time of your meeting. This information is processed strictly to secure your time slot, send automated calendar invitations, and prepare for our discussion. By utilizing this booking tool, your data is processed based on the necessity to execute pre-contractual measures prior to engaging our consulting services.

9. Contact Forms through SureForms

Our digital infrastructure utilizes SureForms to power secure contact forms. Information submitted through these specific forms is compiled and securely transmitted to our centralized operational inbox. We capture only the fields you deliberately complete, alongside standard submission timestamps. The system is designed to facilitate direct, structured communication without unnecessarily retaining the data beyond the active lifecycle of your professional enquiry or resulting client relationship.

10. Newsletter and Email Marketing through Brevo

If you choose to receive updates, insights, and service announcements from our company, we manage these communications using the Brevo platform. We will only add you to our active mailing lists where explicit, verifiable consent is obtained, typically via a secure double opt-in procedure. Where consent applies, Brevo may utilize tracking mechanisms to analyze email open rates and engagement metrics. These analytics help us improve our content. You retain the absolute right to revoke your consent and unsubscribe at any time.

11. Transactional Email / SureMail

To ensure the reliable delivery of critical system notifications—such as appointment confirmations, administrative alerts, and necessary account communications—we utilize SureMail. Unlike marketing communications, these transactional emails do not rely on consent; they are processed under contractual necessity or our legitimate interest in ensuring you receive vital information regarding your service requests and digital interactions with our platform promptly and securely.

12. Website Hosting, Security and Server Logs

Our website is hosted on secure servers engineered to maintain high availability and systemic integrity. To ensure digital security and defend against malicious activities, the hosting environment automatically collects routine server log files. These logs temporarily capture IP addresses, browser agents, referring URLs, and timestamps. We review this data solely for cybersecurity diagnostics, error resolution, and fraud prevention. This processing is founded squarely upon our legitimate interest in safeguarding our infrastructure.

13. Cookies and Consent Management via Complianz

Our website employs cookies and similar tracking technologies to ensure core functionality and optimize user experience. To ensure total GDPR compliance, we utilize Complianz as our dedicated consent management platform. Upon your first visit, a comprehensive banner allows you to accept or decline non-essential cookies categorized by purpose. We rely on your active consent for analytical or marketing cookies, while strictly essential operational cookies function based on our legitimate interest in delivering a secure and usable website.

14. Elementor and Website Operation

We utilize the Elementor page builder to construct and operate the visual layout of our website. Generally, Elementor functions as a structural framework and processes data locally on our hosting servers. Unless specific third-party dynamic widgets are actively embedded and utilized by you, the core operation of Elementor does not independently harvest or transmit your personal data to external unverified third parties.

15. Automations via OttoKit

To streamline specific internal workflows and ensure prompt handling of your requests, we employ OttoKit automations where relevant. This tool helps orchestrate internal data routing—such as linking a form submission to our secure inbox. We configure these automations carefully to ensure your personal data remains within our defined secure operational boundaries and is processed exclusively for the intended administrative purpose without unnecessary external proliferation.

16. Recipients and Processors

To deliver our services efficiently, we occasionally engage trusted external IT providers, cloud hosting environments, and specialized software vendors. These entities act as data processors on our behalf. We utilize external processors subject to appropriate contractual safeguards and data processing agreements where legally required. These agreements legally bind our partners to process your data strictly according to our instructions, ensuring an equivalent standard of data security and strict confidentiality.

17. International Data Transfers

S. F. Custos Global Reach Ltd is based in Cyprus, within the European Economic Area (EEA). We prioritize processing your data within the EEA. However, certain technical processors, such as Brevo or secure communication providers, may maintain infrastructure globally. We do not state that a particular provider necessarily transfers data outside the EEA unless their internal architecture dictates it. Should international transfers occur, we ensure they are protected by legally robust mechanisms, such as European Commission adequacy decisions or Standard Contractual Clauses (SCCs).

18. Retention Periods

We adhere to strict data retention practices, keeping your personal data only for as long as is strictly necessary to fulfill the purposes outlined in this policy. Contact enquiries are deleted once resolved unless they evolve into an active contract. Client files and billing documentation are retained for longer durations strictly to comply with mandatory Cypriot commercial and tax laws, which generally mandate the retention of financial records for a cautious period, typically several years following the conclusion of the fiscal relationship.

19. Data Subject Rights

Under the GDPR, you possess extensive rights concerning your personal information. You have the right to request access to the data we hold about you, enabling you to verify the lawfulness of our processing. If your information is inaccurate or incomplete, you hold the right to immediate rectification. Furthermore, you may request the complete erasure of your data—often referred to as the right to be forgotten—provided there are no overriding legal obligations requiring its retention.

You also possess the right to restrict processing under certain conditions, such as during a dispute over data accuracy. Additionally, you have the right to data portability, allowing you to receive your data in a structured, commonly used machine-readable format. Finally, you retain the right to object to processing based on legitimate interests, specifically concerning circumstances unique to your particular situation.

20. Right to Withdraw Consent

Where any processing of your personal data is based upon your explicit consent—such as subscribing to our newsletter or accepting non-essential tracking cookies—you maintain the absolute right to withdraw this consent at any time. The withdrawal of consent applies exclusively to future processing and does not affect the lawfulness of any data processing that occurred prior to your formal revocation.

21. Right to Lodge a Complaint

We are highly committed to resolving any privacy concerns directly and transparently. However, if you believe that our processing of your personal data violates GDPR regulations, you possess the formal right to lodge a formal complaint with a supervisory authority. In our jurisdiction, this authority is the Cyprus Commissioner for Personal Data Protection. You may also lodge a complaint in the European Union member state of your habitual residence or place of work.

22. Children

Our security consulting services and corresponding digital platforms are strictly directed at corporate entities, professionals, and adults. We do not intentionally design our services for, nor do we knowingly collect personal data from, children under the age of majority. If we become aware that we have inadvertently collected data from a minor, we will take immediate steps to systematically delete that information from our records.

23. Special Warning Regarding Sensitive and Security-Relevant Information

Due to the specific and highly confidential nature of our security consulting operations, we must strictly advise against transmitting highly sensitive data through standard digital channels. Please be explicitly warned: our standard website contact forms, booking plugins, and general email addresses should absolutely not be used to transmit sensitive security incidents, detailed travel itineraries, classified operational intelligence, passport data, medical data, or highly confidential operational information.

Standard web forms are not constructed to handle data of an actively classified or life-safety nature. If your enquiry involves sensitive, high-risk, or heavily classified circumstances, please provide only your name and a basic, non-descriptive contact method. You must explicitly request a secure communication channel first. Following basic verification, our team will establish an encrypted, highly secure communication protocol properly suited to the precise risk profile and confidentiality requirements of your specific operational scenario.

24. Security Measures

We take the protection of your digital and operational data exceptionally seriously. We implement robust, risk-based technical and organizational measures designed to protect personal data from accidental loss, unauthorized access, illicit alteration, and unauthorized disclosure. While we utilize modern encryption and strict access control limitations internally, we acknowledge that no internet-based transmission system can be guaranteed completely secure. Therefore, we evaluate and adapt our protective protocols constantly to respond to emerging technological threats.

25. Changes to this Privacy Policy

As legal frameworks evolve, technology advances, and our consulting operations expand, it may become necessary to update this privacy policy. We continuously review our data protection practices and will publish any revised versions directly on this page. We encourage visitors and ongoing clients to periodically review this document to remain fully informed regarding how S. F. Custos Global Reach Ltd secures and manages personal data.

26. Contact

Should you have any questions, require further clarification regarding the handling of your personal data, or wish to exercise any of your statutory data protection rights, please do not hesitate to reach out. You can contact our data protection team directly via email at office@custosglobal.com or by utilizing the contact details provided in Section 1 of this document.

 
Scroll to Top