Legal
Privacy Policy
Last updated: 24 July 2026
Template notice. This document is a starting-point template and does not constitute legal advice. Items in [square brackets] must be completed, and the whole document reviewed by a qualified lawyer, before publication.
This Privacy Policy explains how C.E. Chrysanthou Architects & Associates ("we", "us", "our") collects, uses and protects your personal data when you visit www.cechrysanthou.com (the "website") or contact us. We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR") and Cyprus Law 125(I)/2018.
On this page
1. Who we are (data controller)
The controller responsible for your personal data is:
Akropoli, 2003, Nicosia, Cyprus
Email: info@cechrysanthou.com
Telephone: (+357) 22 446 111
[If applicable, add company registration number and VAT number.] We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. For any privacy question you may contact us using the details above.
2. What personal data we collect
2.1 Information you give us
When you complete our contact form, or contact us by email or telephone, we collect the details you choose to provide, namely: your first and last name, email address, telephone number (optional) and the content of your message.
2.2 Information collected automatically
Like most websites, our hosting provider automatically records limited technical data needed to serve and secure the site, which may include your IP address, browser type and version (user-agent), the pages you request, and the date and time of your visit. This is processed in server and security logs.
2.3 Cookies and local storage
We use only strictly necessary storage plus, with your consent, optional analytics. See section 4 for details. We do not use advertising or cross-site tracking cookies.
3. How and why we use your data (legal bases)
| Purpose | Data used | Legal basis (GDPR Art. 6) |
|---|---|---|
| Respond to your enquiry and provide the information or services you request | Name, email, phone, message | Taking steps at your request prior to entering a contract (Art. 6(1)(b)); and/or your consent (Art. 6(1)(a)) |
| Operate, maintain and secure the website; prevent abuse and fraud | Technical/log data | Our legitimate interests in running a secure website (Art. 6(1)(f)) |
| Remember your cookie preferences | Consent record | Compliance with our legal obligations and your consent (Art. 6(1)(c)/(a)) |
| Understand how the site is used (only if you allow analytics) | Aggregated, privacy-friendly usage data | Your consent (Art. 6(1)(a)) |
We will not use your data for automated decision-making that produces legal effects, nor for profiling.
4. Cookies & local storage
A cookie is a small file stored on your device; "local storage" works similarly. We use them in two categories:
- Strictly necessary - required for the site to function and to remember your cookie choice. These are exempt from consent under the ePrivacy rules. This includes a first-party record of your consent (kept in a cookie and in your browser's local storage for up to 180 days).
- Analytics (optional, off by default) - aggregated, privacy-friendly usage statistics that only run if you switch them on. No analytics cookies are set unless you consent.
We do not currently run advertising, marketing or social-media tracking cookies. You can review or change your choice at any time via Cookie Settings or the "Cookie Settings" link in the footer.
The contact page also shows a map from OpenStreetMap. We chose OpenStreetMap specifically because, unlike a typical Google Maps embed, it does not set advertising or tracking cookies. Your browser does request map images from OpenStreetMap's servers, which necessarily involves your IP address.
5. Who we share your data with
We do not sell your personal data. We share it only with service providers ("processors") who help us run the website, under contracts that require them to protect it and use it only on our instructions:
| Provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting and delivery; server/security logs | USA / EU |
| Resend (Plus Five Five, Inc.) | Delivery of contact-form emails to us | USA |
| OpenStreetMap Foundation | Map tiles on the contact page | United Kingdom / EU |
| Amazon Web Services (CloudFront CDN) | Serving the jQuery library | USA / global CDN |
| Cloudflare (cdnjs) and jsDelivr | Serving other website scripts (waypoints, counter, slider) | Global CDN |
We may also disclose data where required by law, or to establish, exercise or defend legal claims. [Confirm this list matches your live deployment and add any other tools you use, e.g. an analytics provider.]
6. International transfers
Some of our processors are located outside the European Economic Area (for example in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards recognised under the GDPR, such as the European Commission's Standard Contractual Clauses or an adequacy decision, to ensure your data receives an equivalent level of protection. You may request a copy of the relevant safeguards using the contact details below.
7. How long we keep your data
- Contact-form and email enquiries: for as long as necessary to deal with your enquiry and, where a business relationship follows, for the duration of that relationship plus [retention period, e.g. up to 6 years] to meet legal and accounting obligations.
- Server and security logs: retained for a short period by our hosting provider [confirm period, e.g. up to 30 days].
- Cookie-consent record: up to 180 days, after which you will be asked again.
When data is no longer needed we delete it or anonymise it.
8. Your rights
Under the GDPR you have the right to: access your data; have inaccurate data corrected; have your data erased; restrict or object to processing; data portability; and, where processing is based on consent, to withdraw that consent at any time (without affecting processing carried out before withdrawal).
To exercise any of these rights, please contact us using the details in section 13. We will respond within one month.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Cyprus supervisory authority:
P.O. Box 23378, 1682 Nicosia
Telephone: (+357) 22 818 456
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy
9. Security
We take appropriate technical and organisational measures to protect your personal data against loss, misuse and unauthorised access, including serving the website over encrypted HTTPS connections and limiting access to your data. No method of transmission over the internet is completely secure, however, and we cannot guarantee absolute security.
10. Children
Our website is intended for a general, professional audience and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us so we can delete it.
11. Third-party links
Our website and social-media icons link to third-party sites (for example Instagram, Facebook and LinkedIn). We are not responsible for the privacy practices of those sites; please review their own privacy policies.
12. Changes to this policy
We may update this Privacy Policy from time to time. The current version is always published on this page with its "last updated" date. Material changes will be highlighted where appropriate.
13. Contact us
For any question about this Privacy Policy or your personal data, please contact us:
Akropoli, 2003, Nicosia, Cyprus
Email: info@cechrysanthou.com
Telephone: (+357) 22 446 111
See also our Terms & Conditions.
Back to home