Privacy Policy

Last updated: 13 August, 2026

This Privacy Policy explains how Veblot Ltd (trading as Veblot) collects, uses, stores, shares, and protects personal data when you visit veblot.com, contact us, or use our web, app, hosting, and digital services.

We are established in the Cyprus. We process personal data in accordance with:

  • the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”);
  • the Protection of Natural Persons with regard to the Processing of Personal Data and for the Free Movement of such Data Law of 2018 (Law 125(I)/2018) of the Republic of Cyprus;
  • applicable ePrivacy / cookie rules for electronic communications; and
  • guidance issued by the Office of the Commissioner for Personal Data Protection of Cyprus.

1. Data controller

The data controller is:

Veblot Ltd
Trading name: Veblot
Address: 25is Martiou 14, Geri-Latsia, Nicosia, Cyprus
Country: Cyprus
Email: [email protected]
Phone: +357 99 518 500
Company registration number: HE470699
VAT number: CY60133350P

For privacy requests, email [email protected] with the subject line “Data Protection Request”.

2. Who this policy covers

This policy applies to:

  • visitors of our website;
  • people who contact us by form, email, phone, or messaging apps;
  • prospective and current clients in Cyprus and worldwide;
  • suppliers and business contacts; and
  • users of websites, apps, or platforms we host or maintain where we act as controller for our own business operations.

When we build or host a client project, we may also act as a processor for that client’s end-user data. In that case, the client’s own privacy notice applies to their users, and our processing is governed by the client agreement / data processing terms.

3. Personal data we collect

3.1 Website and marketing
  • Identity and contact data: name, email, phone, company name, role.
  • Enquiry content: project goals, budgets (if shared), message history, attachments.
  • Technical data: IP address, browser, device, operating system, referring URL, pages viewed, approximate location derived from IP.
  • Cookie and consent data: your cookie choices and consent version.
  • Communication metadata: date/time of contact and channel used.
3.2 Client projects and services
  • Contract and billing data: invoices, payment references, VAT details, service history.
  • Project materials you provide: brand assets, copy, logins you choose to share, content, and feedback.
  • Support data: tickets, maintenance notes, uptime/security logs related to hosted services.
  • Account access data for tools we manage on your behalf (used only to deliver the service).

Please do not send special-category data (for example health, political opinions, or biometric data) unless we expressly ask for it and there is a lawful basis.

4. How we collect data

  • directly from you (forms, email, calls, meetings, proposals);
  • automatically through our website, servers, and security tools;
  • from cookies and similar technologies (see our Cookie Policy); and
  • from publicly available business sources or referrals, where appropriate.

5. Purposes and legal bases

We process personal data only when we have a lawful basis under Article 6 GDPR:

  • Contract / steps before a contract (Art. 6(1)(b)) – to respond to enquiries, prepare proposals, deliver web design, development, apps, hosting, IT support, and related services.
  • Legitimate interests (Art. 6(1)(f)) – to secure our website and infrastructure, prevent fraud/abuse, improve our services, keep business records, and communicate about ongoing work. We balance these interests against your rights.
  • Consent (Art. 6(1)(a)) – for non-essential cookies, analytics, marketing tags, and optional newsletters where used. You can withdraw consent at any time.
  • Legal obligation (Art. 6(1)(c)) – to meet Cyprus tax, accounting, and other legal duties.

6. Cookies and tracking

Necessary cookies are used to operate the site and store your consent choice. Analytics, marketing, and preference cookies are used only after you opt in through our consent banner. You can change or withdraw choices at any time via the Cookies button. Full details are in our Cookie Policy.

7. Who we share data with

We do not sell personal data. We may share data with trusted recipients only as needed to run Veblot, including:

  • hosting, cloud, CDN, DNS, and email providers;
  • website/platform tools (for example CMS, form, analytics, or security services) that we configure;
  • professional advisers (accountants, lawyers, insurers);
  • payment providers when invoices are paid electronically; and
  • authorities where required by Cyprus or EU law.

Where a provider acts as our processor, we use appropriate contracts and only allow processing on our documented instructions.

8. International transfers

Our main business is based in Cyprus (EU). Some tools may process data in other countries, including outside the EEA. When that happens, we use a lawful transfer mechanism such as:

  • an adequacy decision of the European Commission; and/or
  • Standard Contractual Clauses (SCCs), plus transfer risk assessments where required.

9. Retention

We keep personal data only as long as needed for the purpose collected, including legal, accounting, and dispute needs. Typical periods:

  • website enquiries: up to 24 months after the last meaningful contact;
  • client contracts, invoices, and tax records: as required by Cyprus law (often up to 6 years or longer if legally necessary);
  • project files: for the life of the project and a reasonable archive period after handover, unless a contract says otherwise;
  • server/security logs: for a shorter operational period unless needed to investigate incidents;
  • cookie consent records: for the life of the consent version / up to 12 months after expiry, unless a longer record is needed to prove compliance.

10. Security

We use technical and organisational measures appropriate to a Cyprus web/software studio, including access controls, secure hosting practices, least-privilege credentials, backups where applicable, and staff/contractor confidentiality. No online transmission or storage method is fully secure, but we work to reduce risk continuously.

11. Your rights under GDPR

Subject to legal limits, you may request:

  • access to your personal data;
  • rectification of inaccurate data;
  • erasure (“right to be forgotten”);
  • restriction of processing;
  • objection to processing based on legitimate interests;
  • data portability, where applicable; and
  • withdrawal of consent, where processing is consent-based.

To exercise your rights, email [email protected]. We may need to verify your identity before responding. We aim to respond within one month, or as otherwise required by GDPR.

12. Complaints in Cyprus

If you are unhappy with how we handle your data, please contact us first so we can try to resolve it. You also have the right to lodge a complaint with the Cyprus supervisory authority:

Office of the Commissioner for Personal Data Protection
1 Iasonos Street, 1082 Nicosia, Cyprus
Website: www.dataprotection.gov.cy
Email: [email protected]
Phone: +357 22 818 456

13. Children

Our website and business services are directed to businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided data to us, contact [email protected] and we will delete it where appropriate.

14. Changes to this policy

We may update this Privacy Policy when our services, tools, or legal requirements change. The “Last updated” date at the top will change when we do. Important changes may also be highlighted on the website or through our consent version update.

15. Related documents