Legal

Privacy Policy

Last updated: 10 July 2026

CYVORA ("we", "us", "our") is a cybersecurity advisory and managed defence company. We respect your privacy and are committed to protecting your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Cyprus Data Protection Law. This Privacy Policy explains how we collect, use and safeguard your information when you interact with our website and services.

1. Information We Collect

We collect the following categories of information:

  • Contact details — name, email address, phone number and company information you provide via our consultation request form.
  • Business context — industry, company size and security concerns you share with us during enquiries and engagements.
  • Technical data — IP address, browser type and usage analytics collected automatically when you visit our site.
  • Engagement data — information generated during the delivery of our services, including assessment findings and security telemetry, processed under contract and applicable data processing agreements.

2. How We Use Your Information

We process your personal data for the following purposes:

  • To respond to your enquiries and arrange cybersecurity consultations.
  • To deliver and manage the cybersecurity services you engage us to provide.
  • To fulfil our legal and regulatory obligations, including those under NIS2 and DORA.
  • To improve our website, services and client experience.
  • To communicate with you about relevant cybersecurity insights, where you have consented.

3. Legal Basis for Processing

We process your personal data based on: (a) your consent when you submit an enquiry; (b) the performance of a contract when we deliver services; and (c) our legitimate interests in operating and improving our business, where these do not override your rights.

4. Data Sharing and Sub-Processors

Certain managed and specialist cybersecurity capabilities may be delivered in collaboration with carefully selected technology and cybersecurity partners, under our strategic oversight. We only share personal data with partners where necessary to deliver the agreed services, and always under written data processing agreements that meet GDPR requirements. We never sell your personal data.

5. International Transfers

Where your data is transferred outside the EU/EEA, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to protect your data.

6. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting or regulatory requirements. Enquiry data is retained for up to 24 months unless a longer period is required. Engagement data is retained for the duration of the contract and thereafter as required by law.

7. Your Rights

Under the GDPR, you have the right to:

  • Access, rectify or erase your personal data.
  • Restrict or object to the processing of your data.
  • Data portability.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Lodge a complaint with the Cyprus Data Protection Authority or your local supervisory authority.

8. Security

As a cybersecurity company, we apply industry-standard technical and organisational measures to protect your personal data, including encryption, access controls and regular security reviews, aligned with recognised frameworks such as NIST CSF and ISO 27001.

9. Cookies

Our website uses essential cookies to function correctly and analytics cookies to understand usage. You can control cookie preferences through your browser settings.

10. Contact

For any privacy-related questions or to exercise your rights, contact us at info@cyvora.com.

© 2026 CYVORA. All rights reserved.