
Privacy Policy
Eptagon Group of Companies Privacy Policy
1. Introduction
At EPTAGON GROUP OF COMPANIES (encompassing Bioland Holdings Ltd, Bioland Energy Cyprus Ltd, and their subsidiaries including EPTAGON RENTAL CARS), we prioritize the protection and confidentiality of your personal data. This Privacy Policy outlines how we collect, use, disclose, and safeguard your information in compliance with the EU 2016/679 General Data Protection Regulation (GDPR) and the Cyprus Law 125(I)/2018.
This policy applies to all our services and products, and to the website operated by EPTAGON GROUP LTD.
2. Purpose of This Privacy Policy
We are committed to transparency regarding the handling of your personal data. This Privacy Policy aims to inform you about:
-
Your rights concerning your personal data.
-
The types of information we collect.
-
The reasons for data collection and how we use it.
-
The measures we take to protect your data.
3. Contact Information for Privacy Inquiries
For any questions or concerns regarding this Privacy Policy or our data handling practices, you can contact our Data Protection Officer at:
-
Phone: +357 24505050
We aim to respond to all privacy-related communications within 30 days.
4. Understanding GDPR
The GDPR General Data Protection Regulation (EU 2016/679) is a regulation designed to enhance and harmonize data protection across the EU, extending its scope to any entity that processes data of EU residents. It emphasizes the protection of individuals' rights regarding their personal data.
5. Collection of Personal Data
At Eptagon Car Rental, we value your privacy and are committed to handling your personal data responsibly and transparently. We collect personal data from you and other sources at various points during our interactions. Below is a detailed outline of how and when we gather your personal data:
a) Personal Data Collected Directly from You
We collect personal data directly from you in the following circumstances:
-
Client Relationships: When you contact us or become a client, including during the booking or rental process.
-
Supplier and Vendor Relationships: When you reach out to us or become our supplier or vendor.
-
Business Relationships: During the establishment and maintenance of business relationships.
-
Service Requests: When you request to receive our products or services.
-
Contractual Engagements: When we perform services for you under a contractual agreement.
-
Agent or Sub-contractor Services: When you provide products or services on our behalf as an agent or sub-contractor.
-
Enquiries and Complaints: When you contact us for inquiries, complaints, or any other reasons, including employment applications.
-
Employment: When you become our employee.
-
Marketing Communications: When you subscribe to our newsletter or other marketing communications.
-
Promotions and Contests: When you participate in our promotions, contests, or giveaways.
-
Social media and Website Interactions: When you engage with or contact us through our social media accounts or websites.
b) Personal Data Collected from Other Sources
We also obtain personal data from other sources, including:
-
Professional Relationships: From legal entities with whom we have a professional relationship. For example, when you are an employee of a customer, partner, subcontractor, or agent company that offers services or support to us.
-
Third Parties: We may receive your personal data from:
-
Our agents who have collected and passed on your personal data to us.
-
Our service providers who facilitate our business operations.
-
Our subcontractors involved in delivering our services.
-
Applicants who intend to use our services or products and provide their data through intermediaries.
-
c) Personal Data Collected from Publicly Available Sources
We may also collect personal data from publicly accessible sources, including:
-
Internet Searches: Data available on public websites and the internet.
-
Corporate Registries: Information from the Department of Registrar of Companies and Official Receiver.
-
Media Sources: Data obtained from the press, media publications, and Google Analytics.
By understanding these various channels through which we collect your personal data, we ensure that your information is managed with the utmost care and in compliance with applicable data protection regulations. Should you have any concerns or queries regarding our data collection practices, please do not hesitate to contact us.
6. TYPES OF PERSONAL DATA COLLECTED
At Eptagon Car Rental, we collect various types of personal data from you, depending on the product or service you require from us or provide to us. We are committed to ensuring the security and confidentiality of your information. Below is a comprehensive list of the types of personal data we may collect:
-
Contact Details: Including your name, address, telephone number, email address, and fax number.
-
Identification Details: Such as a copy of your ID, passport, or driving license. This may be required for various purposes, such as when availing transportation services, applying for employment, or other procedures necessitating document verification.
-
CVs: When you express interest in working with us or applying for a position within our company.
-
Financial Information: Including your bank account number and account details, which may be necessary for conducting financial transactions.
-
Annual Energy Consumption Statement: Required if you intend to utilize our energy services or products.
-
Transaction Details: Records of any transactions conducted with us.
-
Property Details: Such as building permits and title deeds, particularly relevant if you intend to utilize our services or products for property-related purposes.
-
Closed Circuit Television (CCTV) Recordings: In the event that you visit our office, warehouse premises, or any of our PV parks, CCTV recordings may be captured for security purposes.
-
Driving Behaviour Data: Obtained through GPS systems or tachographs installed in our vehicles, if applicable.
-
Health Information: When you become an employee and enrol in our company's medical insurance scheme, or when your health condition is crucial for fulfilling specific job requirements.
-
Website Visit Details: Information collected through cookies and other tracking technologies, including your IP address, domain name, browser version, operating system, location data, and browsing behaviour on our website.
-
Correspondence Records: Details of any communications or correspondence exchanged between you and us.
-
Contractual Details: Information pertaining to contracts entered between you and our company.
-
Marketing Preferences: Your preferences regarding marketing communications from us.
-
Other Information Provided: Any additional information you provide to us through forms, face-to-face interactions, phone calls, emails, online communication, or other channels.
-
Website Data: Data collected from our website, including internet protocol (IP) addresses, web browser and operating system information, device type, communication language and region, basic server connection details, and information obtained through cookies.
-
Photographs: In case you are present at one of our events where we capture photos.
We handle all personal data collected with the utmost care and in compliance with applicable data protection laws and regulations. Your privacy and security are of paramount importance to us.
7. PURPOSE OF DATA COLLECTION
At Eptagon Car Rental, we are committed to ensuring the confidentiality and security of the personal data entrusted to us. We collect and process your information in accordance with applicable data protection laws and regulations. The following outlines the various circumstances under which we collect and utilize your personal data:
a) Performance of Contractual Obligations:
We process your personal data when it is necessary for the performance of a contract or arrangement we have entered into or agreed upon with you. This includes:
(i) Providing Products or Services: Reviewing any proposals made by you and providing you with quotations, performing necessary licensing procedures, preparing installation or leasing contracts, communicating with you to manage our business relationship, and notifying you about changes to our products or services.
(ii) Employment Contracts: Processing is necessary when you become an employee to enter into a contractual agreement with us.
(iii) Services or Product Provision: Processing is necessary when you provide services or products to us to enter into a contractual agreement.
b) Compliance with Legal Obligations:
We collect and process your personal data to comply with legal obligations imposed on us by governmental regulatory bodies, court orders, tax laws, and other reporting obligations. This includes ensuring compliance with regulatory requirements relevant to our business operations.
c) Legitimate Interests:
In certain cases, we may process your personal data to pursue legitimate interests of our own or those of third parties, provided that your fundamental rights and interests are not overridden. This includes:
-
Maintaining accounts and records.
-
Enhancing the security of our network and information systems.
-
Identifying, preventing, and investigating fraud and other unlawful activities.
-
Safeguarding the security of our people, premises, and assets.
-
Managing our infrastructure, business operations, and internal policies and procedures.
-
Complying with procedures of other organizations and public authorities.
-
Improving our products, services, and communications.
-
Defending, investigating, or prosecuting legal claims.
-
Receiving professional advice.
-
Performing data analytics for market research, trend analysis, and customer segmentation.
-
Providing after-sales support, assistance with product claims, and enrolment in online monitoring platforms.
-
Offering benefits such as health insurance to employees.
d) Consent:
In cases where you have given us your consent, we process your personal data for specific purposes outlined in our privacy policy, such as communicating with you for job openings or marketing purposes. You have the right to withdraw your consent at any time, although this does not affect the legality of processing based on consent prior to withdrawal.
We are committed to handling your personal data responsibly and transparently, ensuring that it is used only for legitimate purposes outlined above and in accordance with applicable laws and regulations.
8. Children’s Privacy
We may collect personal data from individuals under 18 years old only with explicit parental consent, particularly for specific services like grants or property-related transactions.
9. Sharing of Personal Data
At Eptagon Car Rental, safeguarding your personal data is of utmost importance to us. We may share your personal data with the following third parties, ensuring that appropriate technical and organizational measures are in place to protect your information:
-
Competent Authorities and Governmental Services: We may share your personal data with governmental bodies such as the land registry, department of town planning and housing, district administrations, Cyprus Energy Regulatory Authority, and Ministry of Energy. This is done as part of necessary procedures related to services you may be applying for or to comply with legislation concerning health and safety issues.
-
Service Providers: We engage with selected service providers who offer technical expertise to support and enhance our activities or fulfill legal obligations.
-
Training Centres and Governmental Organizations: If you are one of our employees, we may share your personal data with training centers and governmental organizations, such as the Human Resource Development Authority, which subsidize employee training.
-
Benefit Providers: For our employees, we may share personal data with benefit providers such as insurance providers, pension administrators, and payroll administrators to manage employee benefits effectively.
-
Auditors and Accountants: Personal data may be shared with auditors and accountants as part of our financial reporting and compliance obligations.
-
External Consultants: We may engage external consultants for specialized expertise, and personal data may be shared with them as necessary.
-
Members of the Eptagon Group of Companies: Personal data may be shared within the Eptagon Group of Companies, affiliates, and subsidiaries for internal administrative purposes and to optimize business operations.
-
Suppliers: We share personal data with suppliers who provide product guarantees for the products we purchase, some of which may be European or international companies.
Rest assured, we do not share your personal data for any purpose other than those described in this privacy statement, nor do we sell your personal data to anyone.
10. Data Retention Period
At Eptagon Car Rental, we prioritize responsible data management practices, including clear guidelines for data retention. Unless longer retention periods are mandated by applicable laws, we retain your information for the duration of our business relationship with you. Here's an overview of our data retention policies:
(a) End of Business Relationship:
-
Following the termination or cancellation of our contractual agreement with you, we may retain your personal data for the longest of the following periods:
-
The retention period prescribed by the Limitation of Actionable Rights Law 66(I)/2012.
-
Until the expiration of the period during which legal action or investigations related to the products and services provided or received might arise. This ensures compliance with legal and regulatory obligations and enables us to address any disputes or claims concerning our services or products.
-
(b) Quotations and Agreements:
-
For individuals who have received a quotation from us:
-
As a potential home client, your personal data will be retained for 2 years after receiving our quotation. Should your property be unsuitable for PV Installation or lack necessary documentation, your data will be promptly discarded.
-
As a landowner considering leasing contracts, your data will be retained until an agreement is reached. If no agreement is reached or if the land is unsuitable for PV Park development, your data will be immediately deleted.
-
(c) HR-Related Data:
-
Personal data pertaining to HR matters is managed as follows:
-
CVs submitted by job applicants will be retained for a maximum of 12 months if the applicant is unsuccessful, with the possibility of earlier deletion if deemed unnecessary.
-
Annual leave records are retained for 2 years after the conclusion of each financial year.
-
Employee files, including employment contracts, are retained for a period defined in paragraph (a) above.
-
CCTV recordings are automatically deleted after 7 days.
-
Training applications to the HRDA are kept for 7 years in accordance with tax laws.
-
Time sheet details are retained for 12 months.
-
Investigations into Health and Safety Incidents and Accidents are preserved for 10 years as mandated by law.
-
(d) Supplier Personal Data and Bookkeeping:
-
Personal data of suppliers and any other data relevant to bookkeeping purposes are retained for 7 years in compliance with tax laws.
We may extend the retention period when necessary to meet regulatory or legal requirements or to safeguard legitimate company interests, such as statute of limitations periods. Rest assured, our data retention policies are designed to uphold confidentiality and security while ensuring compliance with applicable laws and regulations.
11. Rights of the data subject
At Eptagon Car Rental, we uphold the rights of data subjects as outlined in the General Data Protection Regulation (GDPR). These rights afford individuals control over their personal data and ensure transparent and fair data processing practices. Here are the rights of the data subject:
• Right to Information (Article 12):
-
Data subjects have the right to receive concise, transparent, and easily accessible information regarding the processing of their personal data. This information should be provided free of charge and without undue delay, except in cases of malicious or excessive requests.
• Right to Information during Consent (Articles 13 & 14):
-
During the consent process, data subjects are informed of the purpose of data collection, storage duration, their rights, data categories, and the data source.
• Right of Access (Article 15):
-
Data subjects have the right to obtain a copy of their personal data and be fully informed about its processing, including purposes, categories, storage period, recipients, and data sources.
• Right to Rectification/Amendment (Article 16):
-
Data subjects can demand the correction or completion of inaccurate personal data without undue delay.
• Right to Erasure “Right to be Forgotten” (Article 17):
-
Data subjects have the right to request the erasure of their personal data without undue delay, unless there are overriding legitimate interests.
• Right to Restriction of Processing (Article 18):
-
Data subjects can demand the restriction of data processing under certain circumstances, such as questioning data accuracy or legality.
• Right to Notification (Article 19):
-
Data controllers must inform data subjects and recipients of any rectification, erasure, or restriction of processing.
• Right to Data Portability (Article 20):
-
Data subjects can receive their personal data in a structured, commonly used, and machine-readable format, and transmit it to another organization or request direct transmission.
• Right to Object (Article 21):
-
Data subjects can object to data processing, which must cease unless there are overriding legitimate interests.
• Right to Non-Automated Individual Decision-Making (Article 22):
-
Data subjects have the right not to be subject to decisions based solely on automated processing if such decisions have legal or significant effects on them.
Data subjects can lodge complaints with the Commissioner for Personal Data Protection if they believe their rights have been violated. Additionally, they can withdraw consent at any time, although withdrawal does not affect the legality of prior processing based on consent. Requests to delete data may be denied if there are legitimate interests in retaining it. To withdraw consent, contact our Data Protection Officer at 3 Eleftherias Ave., 7102, Aradippou, Cyprus, or via email at dataprotection@biolandenergy.com
12. Data Breach Notification
In the event of a data breach, we will notify the relevant regulatory authorities within 72 hours. If the breach poses a high risk to your rights and freedoms, we will also inform you promptly.
13. Data Security Measures/Data Protection
We employ robust administrative, technical, and physical security measures to protect your data. This includes encryption, access controls, and secure storage. We also require our staff and partners to comply with strict data protection standards.
14. Statistical Analysis
We may use anonymized, aggregated data for statistical analysis to improve our services and website functionality. This data does not identify individuals and is used solely for enhancing user experience and operational efficiency.
15. Cookies and Other Technologies
Automated collection of certain information about you is facilitated through the use of cookies and similar technologies. Below is an overview of cookies and their functionalities:
a) Definition of Cookies: Cookies are small text files that websites store on your computer or device. They serve various functions and do not cause any harm to your device.
b) Purpose of Using Cookies: Our utilization of cookies aims to enhance the browsing experience of our website visitors and tailor web pages to meet their specific needs and interests. Additionally, cookies enable us to gather anonymous, aggregated statistics, aiding us in understanding visitor behaviour and improving website structure and content. These cookies do not reveal the identity of individual visitors.
c) Types and Categories of Cookies: Cookies can be categorized into two types: session cookies and persistent cookies. Session cookies expire upon closing the browser, while persistent cookies remain on the device until manually deleted or until they expire.
d) Distinction and Categories of Cookies:
-
Functionality Cookies: Functionality cookies enable the website to remember user preferences, such as language or region, and provide enhanced, personalized features.
-
Performance/Analytics Cookies: Performance or analytics cookies gather aggregated data anonymously, aiding in website improvement by identifying visitor challenges and understanding page visits.
-
Targeting Cookies: Targeting cookies are utilized to deliver advertisements that are more relevant to user interests. They track website visits and share this information with other marketing channels.
e) Disabling Cookies: Users have the option to adjust their browser settings to reject some or all cookies. However, disabling cookies may result in certain website features becoming unavailable.
Adjusting cookie settings should be done with the understanding that it may impact the functionality and accessibility of our website.
16. Policy Updates
We may update this Privacy Policy from time to time without notice. Any changes will be posted on our website, and we encourage you to review the policy periodically.
17. Language
This Privacy Policy is provided in English. In the event of any inconsistency between the English version and translations, the English version will prevail.
*IMPORTANT INFORMATION
Eptagon Rental Cars reserves the right to amend or update this Privacy Policy at any time at its sole discretion. Any changes will be effective immediately upon posting on our website or through other means of communication. It is the responsibility of the renter to review the Privacy Policy periodically to stay informed of any updates. Continued use of Company’s services after any changes to the Privacy Policy constitutes the Renter's acceptance of the updated Privacy Policy.