Data Security

THE COMPANY created the e-shop steelseal.cy with the sole purpose of serving their customers. The website www.steelseal.cy, which corresponds to our online store, has been designed to meet the specific needs of each user. In order to best serve you, it is important that you, our customer, understand that you must provide us with certain information related to the processing of your order that is kept by us.

The processing of personal data is carried out in accordance with the provisions of the General Data Protection Regulation (GDPR 2016/679), the applicable Cyprus legislation (Law 125(I)/2018) for the protection of natural persons with regard to the processing of personal data, as well as the legislation on privacy in the field of electronic communications, and the decisions of the Office of the Commissioner for Personal Data Protection.

steelseal.cy conducts its business actions in accordance with privacy principles, applying ethical and responsible practices.

The established legal frameworks dictate the high standards we maintain regarding data security. These protective guidelines apply across all aspects of our business operations—from marketing and promotional sales to customer support, product delivery, and corporate administration.

For example, this Policy applies to: This Policy applies to all natural persons whose data we process including clients, candidates and partners. Accordingly, every employee of the Company, and third parties who process data for our company, are responsible for understanding and complying with their obligations towards this Policy and existing laws. The privacy principles described below summarize the standards and basic conditions for the collection and processing of individuals’ personal data by our company.

Personal data: a) are lawfully and legitimately processed in a transparent manner in relation to the data subject (“lawfulness, objectivity and transparency”), b) are collected for specified, explicit and legitimate purposes and are not further processed in a manner incompatible with these purposes (“purpose limitation”), c) are appropriate, relevant and limited to what is necessary for the purposes for which they are processed (“data minimization”), d) are accurate and, where necessary, updated (“accuracy”), e) are kept in a form that allows the identification of the data subjects only for the period necessary for the purposes of the processing of the personal data; (“limitation of the storage period”), f) are processed in a way that guarantees the appropriate security of personal data, including their protection against unauthorized or illegal processing and accidental loss, destruction or deterioration, using appropriate technical or organizational measures (“integrity and confidentiality”).

Necessity–minimize data Legitimacy, Objectivity and Transparency We do not process Personal Data in ways that are unfair to data subjects. We do not process Personal Data in ways or for purposes that are not transparent.

– the identity and contact details of the controller – the purposes of the processing -if the processing is based on legitimate interests of the controller, what those interests are. – the recipients of the personal data -any data transfer – the period of time for which the data will be stored – the existence of the right to submit a request to the controller for access and correction or deletion of personal data or restriction of processing -when the processing is based on the consent of the subject, the existence of the right to withdraw his consent at any time, without prejudice to the legality of the processing based on the consent before its withdrawal – the right to submit a complaint to the Office of the Commissioner for Personal Data Protection – the legal nature of the provision -the possibility of automated decision-making

We are responsible for maintaining the security and privacy of Personal Data when it is transferred to or from other organizations. We transfer Personal Data or allow them to be processed by third parties only if the following conditions are met, for which we are responsible. (a) we complete a legal audit to assess the privacy practices and risks associated with these third parties; (b) we attempt to obtain written contractual guarantees from these third parties that they will process Personal Data in accordance with our company’s instructions, and in accordance with this Policy. (c) We ensure that they notify us promptly of any Security Incident and that they agree to cooperate when deemed necessary. (d) If the role of the third party is to provide Personal Data to our company, before we obtain the Personal Data from the third party, we ensure that the requirements of Transparency are met for the collection of Personal Data from other sources and not specifically under the supervision of the company us, and we obtain guarantees through an agreement document from the third party that it does not violate any Law or the rights of any third party by providing Personal Data to our company. (e) If the third party’s role is to receive data from our company for processing that is not specifically under our company’s supervision, before we deliver the data to the third party, we ensure that the third party will only use the data for the operational purposes defined by the agreement and in accordance with existing legislation.

Data Quality, Integrity and Confidentiality We keep Personal Data accurate, complete and up-to-date, and consistent with its intended use. We incorporate security safeguards to protect Personal Data and Sensitive Data.

Rights of Access, Correction, Erasure, Portability, Restriction of Processing and Objection to Processing. You have the right to access your personal data. This means that you have the right to be informed by us if we are processing your Data. If we process your Data, you can ask to be informed about the purpose of the processing, the type of your Data we keep, to whom we give it, how long we store it, whether automated decision-making takes place, but also about your other rights, such as correction, deletion of data, restriction of processing and filing a complaint with the Office of the Commissioner for Personal Data Protection.

You have the right to correct inaccurate personal data. If you find that there is an error in your Data you can submit a request to us to correct it (eg correct a name or update a change of address).

You have a right to erasure/right to be forgotten. You can ask us to delete your data if it is no longer necessary for the aforementioned processing purposes.

You have the right to portability of your Data. You can ask us to receive the Data you have provided in human readable form or ask us to transfer it to another controller.

You have the right to restrict processing. You can ask us to restrict the processing of your Data pending the consideration of your objections to the processing.

You have the right to object to the processing of your Data. You can object to the processing of your Data or withdraw your consent and we will stop processing your Data, unless there are other compelling and legitimate reasons that override your right.

To exercise your rights you can send us a relevant request, describing the right you wish to exercise either to the postal address of the Company with the indication “Exercise of the right of access/correction/deletion/restriction/objection”, or to the e-mail address  with the title “Exercise of the right of access/rectification/deletion/restriction/objection”, with a description of your request and we will take care to examine it and answer you as soon as possible.

We respond to your requests free of charge without delay, and in any case within (1) one month of receiving your request. However, if your request is complex or there are a large number of your requests, we will inform you within the month if we need to obtain an extension of another (2) two months, within which we will respond to you.

If your requests are manifestly unfounded or excessive especially due to their repeated nature, steelseal.cy may charge a reasonable fee, taking into account the administrative costs for providing the information or performing the requested action, or refuse to provide follow up on the request. You have the right to file a complaint with the Office of the Commissioner for Personal Data Protection (Iasonos 1, 1082 Nicosia / www.dataprotection.gov.cy), if you consider that the processing of your Personal Data violates the applicable national and regulatory legal framework for the protection of personal data.

SteelSeal
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.