Share their contact details (e.g., via business cards, emails)
Register for webinars or events
Subscribe to newsletters
Visit our offices
Apply for employment
Engage us for services
Indirectly: We may collect data from:
Public registers (e.g., Registrar of Companies)
News articles and sanctions lists
Social and professional networking sites (e.g., LinkedIn)
Clients sharing data for the purposes of service provision (e.g., audits or payroll)
Recruitment agencies
3. What categories of personal data do we collect? Personal Data Examples:
Full name, email, phone, address
Professional background and qualifications
Financial information (e.g., payroll, bank details, tax)
Information from client systems during service delivery
Images via CCTV (retained for 15 days)
Special Categories (only when necessary):
Health data (for workplace safety)
Biometric data (if needed for ID verification)
Political, union, or religious affiliation (only if explicitly disclosed in documentation)
Children’s Data: We do not knowingly collect data about children under 14, unless strictly necessary and with appropriate consent (e.g., at events with parents). 4. Legal bases for processing data We rely on the following legal grounds:
Contractual necessity (for service delivery)
Legal obligations (e.g., compliance with AML regulations)
Legitimate interest (e.g., marketing, IT security)
Consent (e.g., subscription to newsletters)
Vital interest or public interest (in rare cases such as health emergencies)
5. Why do we need personal data? We use your data for purposes including:
Delivering audit, accounting, payroll and consulting services
Client communication and relationship management
Internal administration and security
Recruitment and candidate evaluation
Legal and regulatory compliance
Event and webinar organisation
6. Do we share personal data with third parties? We may share data with:
Professional advisers (e.g., lawyers, auditors)
IT and cloud service providers
Recruitment platforms and payroll processors
Government authorities or regulators where legally required (e.g., CyPAOB, ICPAC)
In the case of business transfers or mergers
We do not sell or share your data for third-party marketing purposes. 7. Do we transfer data outside the EEA? YOURSHIELD stores data primarily within the EEA. Any transfers outside the EEA will be protected with appropriate safeguards in line with GDPR, including standard contractual clauses. 8. Use of cookies Our website may use cookies for user experience, analytics, or functionality. Please refer to our [Cookies Notice] for details. 9. Your rights You have the right to:
Access your data
Request correction or deletion
Restrict or object to processing
Withdraw consent (where applicable)
Request data portability
Object to direct marketing
Submit a complaint to the Cyprus Data Protection Commissioner
To exercise any rights, please contact: privacy@yourshield.com.cy 10. Data Security We implement appropriate technical and organisational measures to:
Protect data against unauthorised access or disclosure
Maintain confidentiality and integrity
Control physical and digital access
Transmission over the internet is not 100% secure, and we recommend caution when sharing sensitive information online. 11. Data Retention We retain data as long as necessary for:
Legal and regulatory compliance
Service provision
Legitimate business purposes
Unless otherwise required, we retain data for 7 years. 12. External websites Our website may contain links to third-party websites. We are not responsible for their content or privacy practices. Please consult their respective privacy notices. 13. Contact us privacy@yourshield.com.cy In case we do not reply within 30 working days, you might contact the Cyprus Data Protection Commissioner: https://www.dataprotection.gov.cy 14. Updates to this Privacy Statement We regularly update this policy to reflect changes in law or services. Last updated: July 2025