Privacy Policy
Last updated: 19 September 2026.
This Privacy Policy explains how the Cyprus Inform website (www.kiprinform.com) collects, uses, stores and protects the personal data of its visitors and users.
Personal data is processed in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679 — GDPR), the applicable law of the Republic of Cyprus and other applicable European Union rules on data protection and the privacy of electronic communications.
We aim to describe how the site actually works. If a particular technology or method of processing is not mentioned in this Policy, it means we do not use it as at the date this Policy was last updated.
1. Who is responsible for your data
The data controller within the meaning of the GDPR is:
{{COMPANY}}
Registration number: {{REG_NUMBER}}
Registered address: {{LEGAL_ADDRESS}}
For any matter relating to the processing of personal data or the exercise of your rights, you can contact us at: [email protected]
We handle data subject requests without undue delay and, as a rule, no later than one month from receipt of the request, in accordance with the GDPR. In the cases provided for by the GDPR this period may be extended, and we will inform the applicant accordingly.
Where the appointment of a Data Protection Officer (DPO) is not required by law and no such officer has been appointed by us, the role of contact point for privacy matters is performed through the email address above.
2. What data we process, why and on what legal basis
2.1. Browsing the site
No registration is required to read the content of the site.
When the site is accessed, the server and the infrastructure we use may automatically process technical information necessary to deliver the page, to diagnose problems and to maintain security, including:
- IP address;
- date and time of the request;
- the requested URL;
- browser type and version;
- operating system and User-Agent;
- technical information about the connection and the server response.
This data is used to keep the site running, to diagnose technical problems, to prevent abuse and to protect the site against attacks.
Legal basis: our legitimate interest in the security, stability and availability of the site — Art. 6(1)(f) GDPR.
We do not use server logs to build advertising profiles of visitors.
The counters of content views and advertising impressions keep aggregated statistics and are not intended to identify an individual visitor or their device.
2.2. Submitting a listing request
When you submit a request to publish a company, a service, a property, an event or other material, we may ask for:
- your name;
- a telephone number;
- an email address;
- WhatsApp, if you choose to provide it;
- the address or location of the object;
- the information and materials needed to prepare the publication.
Contact details are available to the editorial staff who need them in order to process the request.
Only those contact and other details that are intended for publication under your request or subsequent agreement are published on the site.
Legal basis: steps taken at your request prior to entering into a contract, and performance of that contract — Art. 6(1)(b) GDPR.
Certain data relating to payment and accounting records may be retained in order to comply with our legal obligations — Art. 6(1)(c) GDPR.
2.3. Protecting the form against automated submissions
To protect the form against spam and automated submissions we may apply rate limiting.
For that purpose the IP address is turned into an irreversible hash used solely to limit the number of submissions for a short time.
Such a hash is kept for approximately one minute and is then deleted.
Within this mechanism we do not separately store the original IP address of the request.
Legal basis: our legitimate interest in protecting the site against spam, abuse and automated attacks — Art. 6(1)(f) GDPR.
2.4. Comments
If you leave a comment, we may process:
- the name you provide;
- your email address;
- the text of the comment;
- your IP address;
- the User-Agent or information about your browser.
The email address is not displayed publicly.
The IP address and browser information are used to prevent spam and abuse and to moderate comments.
Comments may be subject to pre-moderation.
If you voluntarily choose the “Remember me” option, your browser may store the name and email address you entered in a cookie so that you do not have to type them again with your next comment.
Legal bases: your consent — Art. 6(1)(a) GDPR — for the features you choose voluntarily, and our legitimate interest in moderation, spam prevention and security — Art. 6(1)(f) GDPR.
You can delete the relevant cookies through your browser settings, or change your choice through the cookie settings available on the site.
2.5. Paying for a listing
PayPal may be used to pay for services.
Payment details, including bank card or payment account data, are entered directly in the PayPal interface and are not passed to us in full.
We may receive the information needed to confirm and record the payment, for example:
- the payment status;
- the amount;
- the currency;
- the transaction identifier;
- payer details to the extent provided by PayPal.
PayPal processes payment data independently, in accordance with its own privacy policy and applicable law.
Legal bases for our processing: performance of a contract — Art. 6(1)(b) GDPR — and compliance with applicable accounting and tax obligations — Art. 6(1)(c) GDPR.
3. Cookies and similar technologies
The site uses cookies and similar technologies.
Non-essential analytics and advertising technologies must not be activated before the corresponding consent of the user has been obtained.
Until you make a choice in the Complianz interface, only technologies necessary for the operation of the site, for security and for storing your privacy settings are used.
Refusing non-essential cookies must not prevent ordinary access to the content of the site, except for features that technically depend on the corresponding external service.
3.1. Strictly necessary cookies
No separate consent is requested for strictly necessary cookies, since they are used to provide a feature requested by the user or are required for the functioning and security of the site.
These may include:
- cyp_beacon_visitor — contains a signed anonymous technical identifier used to protect aggregate view and impression counters against replay. It is a session cookie; the identifier remains valid for no more than 12 hours 6 minutes.
- WordPress service cookies — used, for example, to authenticate editorial staff and for other technically necessary WordPress functions.
- Comment form cookies — may be stored if the user chooses the option to remember the details they entered.
- Cloudflare — may use strictly necessary technologies for security and for protection against malicious traffic, bots and attacks.
Complianz stores the user’s choice in its own consent data and cookies, including the selected categories, banner status and policy version. This data is used to retain and apply privacy settings; its composition and retention period are determined by the site’s Complianz configuration.
3.2. Analytics
Only after your consent has been obtained may the site activate:
Google Analytics 4 — helps us analyse how the site is used, for example page traffic, referral sources, device type and how visitors interact with the site.
Yandex Metrica — may be used to analyse traffic and how users interact with the content of the site.
We must not deliberately send to analytics systems a name, email address, telephone number, payment data or other data that directly identifies a user, unless the relevant feature is separately provided for, configured and has an appropriate legal basis.
Analytics technologies are used only after your consent.
Legal basis: consent — Art. 6(1)(a) GDPR.
You can refuse analytics, or withdraw your consent later, through the Complianz interface.
3.3. Advertising technologies
Once the corresponding consent has been obtained, Meta Pixel (Facebook Pixel) may be used.
Meta Pixel makes it possible to measure the effectiveness of advertising campaigns, to analyse what visitors do after arriving from an advertisement and, depending on the settings and the user’s consent, to use data for advertising and marketing purposes.
For visitors outside the Russian geographic segment the site uses Google AdSense in order to select and display advertisements, limit their frequency, measure effectiveness, prevent fraud and maintain the security of the advertising service. The advertising code is loaded regardless of your answer to the consent banner, but that answer is passed to Google through the standard IAB TCF and Google Consent Mode mechanisms: without consent to marketing technologies advertisements are selected without personalisation, and advertising cookies and identifiers are neither written nor read.
When Google AdSense is activated, the user’s browser establishes a connection with Google and the advertising technology providers involved in serving the advertisement. Google and those providers may process the URL of the requested page and ad-slot parameters, the IP address, request date, time and referrer, cookies and browser or device identifiers, browser, device and operating-system information, approximate location, advertisements displayed and interaction data. This data is shared with Google and, depending on the advertising auction, participating providers; personalisation is permitted only in accordance with the user’s choices and settings.
Further information is available on the Google Business Data Responsibility site, the page on how Google uses cookies in advertising and the Google Privacy Policy. Google states that it maintains servers around the world, so data may be processed outside the EEA and the user’s country of residence; for international transfers Google states that it uses applicable mechanisms, including adequacy decisions, the Data Privacy Framework and standard contractual clauses. The general conditions governing international transfers are also described in section 6 of this Policy.
For visitors assigned to the Russian geographic segment the site uses the Yandex Advertising Network (YAN) in order to select and display advertisements, measure their effectiveness, prevent fraud and maintain the security of the advertising service. Its advertising code is likewise loaded regardless of your answer to the consent banner. Yandex does not take part in the IAB TCF and its advertising code accepts no consent signal from the site, so your choice in the banner does not reach it; processing on the Yandex side is governed by its own policies linked below.
When YAN is activated, the user’s browser establishes a connection with Yandex. Yandex may process the IP address, cookies, browser or device identifiers, browser and operating system information, internet connection parameters, the requested page, advertisements displayed and data about interactions with them. Depending on the settings and consent, this data may also be used to personalise advertising.
Further information about this processing, recipients and user rights is available in the Yandex Ads Privacy Policy. According to that published policy, data may be transferred to Russia and other third countries; the general conditions governing international transfers are also described in section 6 of this Policy.
Legal basis: consent — Art. 6(1)(a) GDPR — for Meta Pixel, for the personalisation of advertising and for storing advertising identifiers; our legitimate interest in funding the publication — Art. 6(1)(f) GDPR — for loading the advertising code and displaying non-personalised advertisements.
Meta Pixel is not activated before consent to marketing technologies has been given, and withdrawal of consent prevents its subsequent activation. The Google AdSense and YAN advertising code is loaded on the pages of the corresponding segment regardless of the answer: for Google, refusal and withdrawal mean non-personalised advertisements and no advertising cookies, while in relation to Yandex the settings and tools provided by Yandex itself apply.
3.4. Google Tag Manager
Google Tag Manager may be used for the technical management of the site’s tags and scripts.
The mere presence of Google Tag Manager does not mean that the user has consented to analytics or advertising. Yandex Metrica and Meta Pixel are launched through it only after the corresponding consent. The Google AdSense loader is launched regardless of the answer, and the user’s decision is passed to it through Google Consent Mode and the IAB TCF.
3.5. Managing consent
The site’s only consent management interface is Complianz. It allows users to accept, reject or change their choices for functional, preference, analytics and marketing technologies. The user’s choice is translated into Google Consent Mode signals and an IAB TCF string for the relevant tags; it governs the personalisation of advertising and the launch of non-essential tags, but not the loading of the Google AdSense and YAN advertising code itself.
Change privacy and cookie settings
Withdrawal of consent takes effect for the future and does not affect the lawfulness of processing carried out on the basis of consent before its withdrawal.
Accepting and rejecting non-essential technologies must be available to the user without any pressure to consent.
4. External content and maps
Some pages may use content or functionality provided by external suppliers.
OpenStreetMap. If a page contains a map or other resources loaded directly from OpenStreetMap servers or from associated infrastructure providers, the user’s browser may establish a direct connection to the relevant server.
As a result, the provider of such a resource may receive the technical data required for the connection, including the user’s IP address.
If the map or external resource is not loaded, no such connection takes place.
Where technically and legally necessary, the loading of external content may be made dependent on the user’s consent.
5. Who data may be shared with
We do not sell users’ personal data and do not provide it to third parties for their own direct marketing, except where the user has given the corresponding consent or another lawful basis exists.
Data may be accessed by the service providers needed to operate the site, in particular:
- hosting providers and providers of server infrastructure;
- Cloudflare — site protection, content delivery and network infrastructure;
- Google and advertising technology providers involved in serving ads through AdSense — advertising, Google Analytics and Google Tag Manager;
- Meta — Meta Pixel;
- Yandex — Yandex Metrica and the Yandex Advertising Network (YAN);
- PayPal — payment processing;
- OpenStreetMap and associated infrastructure providers — when maps and related resources are loaded;
- providers of technical support and IT infrastructure, where such access is necessary for them to perform their functions;
- accounting, legal and other professional advisers, to the extent necessary;
- public authorities, courts and law enforcement bodies where disclosure is required by applicable law.
Where a provider processes data on our behalf, we seek to put in place the contractual and organisational measures provided for by Art. 28 GDPR.
Where a provider independently determines the purposes and means of processing certain data, it may act as a separate controller in respect of that processing.
6. Transfers outside the European Economic Area
Some of the service providers we use are international organisations or may process data outside the European Economic Area (EEA).
Where personal data is transferred to a country for which the European Commission has adopted an adequacy decision, the transfer may take place on the basis of that decision in accordance with Art. 45 GDPR.
In other cases the safeguards provided for by the GDPR may be used, including the European Commission’s Standard Contractual Clauses (SCC) under Art. 46 GDPR and, where necessary, additional technical and organisational measures.
For relevant US organisations, a transfer may also rely on the EU–US Data Privacy Framework, provided that the particular organisation holds a valid certification under that framework.
We seek to transfer to external providers only the volume of data necessary for the relevant purpose.
Information about the international transfer mechanism applied to a particular provider can be requested at [email protected].
7. Retention periods
We do not keep personal data longer than necessary for the purposes of the processing, unless longer retention is required by law.
In particular:
- Listing requests and materials — for as long as the request is being processed, the corresponding listing or contractual relationship is in effect, and thereafter for the period needed to resolve possible claims and to comply with applicable legal obligations.
- Accounting and payment records — for the period established by the applicable accounting and tax legislation of the Republic of Cyprus.
- Comments — for as long as the related material exists and the comment is needed to preserve the context of the discussion, or until it is deleted in accordance with the applicable rules and the user’s rights.
- The cyp_beacon_visitor cookie — until the browser session ends, while the technical identifier remains valid for no more than 12 hours 6 minutes.
- The consent record in Complianz — for the period set by the site’s consent-interface configuration.
- The IP hash used for form rate limiting — approximately one minute.
- Server logs — for a limited period needed for security, investigating technical problems and preventing abuse.
- Analytics data — in accordance with the retention period we configure in the relevant analytics service and its technical limitations.
Where data is needed to establish, exercise or defend legal claims, the relevant information may be retained until the expiry of the applicable limitation period or the conclusion of the relevant proceedings.
8. Your rights
Under the GDPR, and depending on the circumstances of the processing, you may have the right to:
- obtain confirmation as to whether we process your personal data;
- obtain access to your personal data and a copy of it;
- have inaccurate data corrected or incomplete data completed;
- request the erasure of your personal data;
- request the restriction of processing;
- object to processing based on our legitimate interest;
- receive the data you provided in a structured, commonly used and machine-readable format and, where applicable, transmit it to another controller;
- withdraw any consent previously given, at any time;
- not be subject to a decision based solely on automated processing that produces legal or similarly significant effects, in the cases provided for by the GDPR.
To exercise these rights, write to: [email protected]
To protect data against unlawful disclosure, we may request information reasonably necessary to verify the identity of the applicant.
Requests are handled within the time limits laid down by the GDPR.
As a rule, exercising these rights is free of charge. Where requests are manifestly unfounded or excessive, in particular repetitive, the GDPR permits charging a reasonable fee or refusing to act on the request in the cases provided for by law.
9. Right to object
Where personal data is processed on the basis of our legitimate interest under Art. 6(1)(f) GDPR, you have the right to object to that processing on grounds relating to your particular situation.
Upon receiving an objection we will stop the processing concerned unless we can demonstrate compelling legitimate grounds for continuing it which override your interests, rights and freedoms, or unless the processing is necessary for the establishment, exercise or defence of legal claims.
10. Complaint to a supervisory authority
If you believe that your personal data is being processed in breach of the GDPR, you have the right to lodge a complaint with the competent supervisory authority.
For a controller registered in Cyprus that authority is the Office of the Commissioner for Personal Data Protection (Γραφείο Επιτρόπου Προστασίας Δεδομένων Προσωπικού Χαρακτήρα), Republic of Cyprus.
You may also have the right to contact the supervisory authority of the EU Member State of your habitual residence, place of work or the place of the alleged infringement, in accordance with the GDPR.
Contacting a supervisory authority does not deprive you of any other legal remedy.
11. Automated decision-making and profiling
We do not use the personal data provided directly to us to take decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them within the meaning of Art. 22 GDPR.
Certain external advertising or analytics platforms may carry out their own processing, segmentation or profiling in accordance with their own terms and privacy policies. Such non-essential technologies are activated on our site only where the required consent is present.
12. Children
The site is aimed primarily at an adult audience and is not specifically intended for children.
We do not knowingly request children’s personal data in order to create children’s profiles or to provide services specifically intended for children.
If a parent or legal guardian believes that a child has provided us with personal data without a proper basis, they may contact us at [email protected].
We will review such a request and, if there is no lawful basis for the processing, take the necessary steps to delete the data.
13. Security
We apply technical and organisational measures appropriate to the nature of the site and to the risks of processing personal data.
In particular:
- the site uses HTTPS;
- access to administrative functions is restricted;
- staff access to personal data is granted on a need-to-know basis;
- technical means of protecting the site and the server infrastructure are used;
- bank card payment details are not stored on our servers;
- measures against spam and automated attacks are applied.
When choosing security measures we take into account the nature, scope, context and purposes of the processing, as well as the corresponding risks to the rights and freedoms of natural persons.
That said, no method of transmitting or storing information can guarantee absolute security.
14. Sources of personal data
In most cases we obtain personal data directly from you — for example when you submit a request, leave a comment or contact the editorial team.
In some cases information for publication may be provided by a company, an agency or a representative of an organisation, or obtained from a publicly available source.
Where the GDPR requires that a specific person be informed that their personal data has been obtained other than from them, we provide the information required by Art. 14 GDPR within the prescribed time limits, unless an exemption provided for by the GDPR applies.
15. Whether providing data is mandatory
Ordinary reading of the site does not require you to provide personal data through forms.
When submitting a request, certain details are necessary in order to process the request and to perform the corresponding contract. If such data is not provided, we may be unable to process the request or to provide the service you asked for.
Fields that are not mandatory are provided voluntarily.
16. Changes to this Policy
We may update this Policy if there are changes in:
- the technologies used by the site;
- the ways personal data is processed;
- the service providers;
- the requirements of legislation or supervisory authorities;
- the functionality of the site.
The date of the last update is shown at the beginning of the document.
If a change materially affects processing based on the user’s consent, we may ask for consent again or notify the user through the site interface.
The new version of the Policy applies from the moment it is published, unless stated otherwise in it.
17. Contact
For questions about privacy, the processing of personal data and the exercise of rights under the GDPR: [email protected]
Controller:
{{COMPANY}}
Registration number: {{REG_NUMBER}}
Registered address: {{LEGAL_ADDRESS}}