How we collect, use, and protect your personal data in compliance with GDPR. Last updated: July 2026.
G. Adamides Audit Ltd ("we", "us", "our") is committed to protecting your privacy in full compliance with GDPR and Cyprus Law 125(I)/2018. This policy explains how we collect, use, store, and protect your personal information.
Identity data: Full name, title, job title, company name
Contact data: Email address, telephone number, postal address
Enquiry data: Service requirements and correspondence via our contact form
Recruitment data: CV, cover notes, qualification status (for job applicants)
KYC/AML data: Identity documents, proof of address, UBO information (required by law)
Technical data: IP address, browser type, pages visited (via cookies — see Section 7)
Financial data: Information necessary to provide audit, tax, and advisory services
3. Legal Basis for Processing
Purpose
Legal Basis
Responding to enquiries
Legitimate interests / Pre-contractual steps
Delivering professional services
Performance of a contract
KYC/AML compliance
Legal obligation (AML Directive / Cyprus Law)
Processing job applications
Legitimate interests / Consent
Website analytics
Consent (via cookie banner)
Legal and regulatory compliance
Legal obligation
4. Data Retention
Enquiry data: Up to 2 years from last contact
Client engagement data: 7 years from end of engagement (ICPAC requirement)
KYC/AML records: 5 years from end of business relationship (Cyprus AML Law)
Recruitment data: Up to 12 months from application date
Analytics data: As set by individual cookie providers
5. Who We Share Your Data With
We do not sell your personal data. We may share it only with:
ICPAC and regulatory bodies — where required by our professional obligations
Cyprus Tax Department — for tax filing and compliance on behalf of clients
Registrar of Companies — for corporate services filings on behalf of clients
Professional co-advisors — under strict confidentiality agreements
IT and service providers — cloud storage, email, practice management software (under DPAs)
Analytics providers — Google, LinkedIn, Meta (anonymised, if cookies accepted)
6. Your Rights Under GDPR
Right of access: Request a copy of personal data we hold about you
Right to rectification: Ask us to correct inaccurate or incomplete data
Right to erasure: Request deletion of your data (subject to legal retention obligations)
Right to restriction: Ask us to limit how we use your data
Right to data portability: Receive your data in a machine-readable format
Right to object: Object to processing based on legitimate interests
Right to withdraw consent: At any time where processing is consent-based
To exercise any right, email info@gadamides.com. We will respond within 30 days. You may also lodge a complaint with the Commissioner for Personal Data Protection Cyprus: dataprotection.gov.cy
7. Cookies
We use essential, analytics, and marketing cookies. You can control your preferences via our cookie banner or your browser settings. For full details, see our Cookie Policy.
8. Professional Confidentiality
As an ICPAC-regulated firm, we are bound by strict professional confidentiality obligations. All client information is treated as strictly confidential and will not be disclosed except as required by law, regulatory obligation, or with your explicit consent.
9. Security
We implement appropriate technical and organisational security measures — including encrypted communications and access controls — to protect your data against unauthorised access, loss, or alteration. In the event of a data breach affecting your rights, we will notify you and the relevant authority within 72 hours as required by GDPR Article 33.