Data Protection

Privacy Policy. GDPR and Cypriot data protection law.

Last updated — September 2026

1. Controller

The controller responsible for the processing of personal data described in this Privacy Policy within the meaning of Article 4(7) GDPR is:

Axiomledger Technologies Ltd
10th Floor, Office 1002
Nicolaou Pentadromos Center
Thessalonikis Street, 3025 Limassol
Republic of Cyprus
Email: hollmann@axiomledger.com
Reg. No. HE 471347

The Company has not appointed a Data Protection Officer, as it is not required to do so under Article 37 GDPR. For all data protection matters, please contact the Company directly at the email address above.

2. Legal framework

This Privacy Policy is issued in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation — “GDPR”) as well as Law 125(I)/2018 of the Republic of Cyprus providing for the Processing of Personal Data (the “Cypriot Data Protection Law”), which supplements the GDPR.

3. Categories of personal data processed

The Company processes the following categories of personal data, depending on how you interact with this website:

  • Briefing requests: name, work email address, organisation, and the content of your message, as submitted through the contact form.
  • Technical data: IP address, browser type and version, operating system, date and time of access, and referrer URL, processed to operate and secure the website.
  • Communication data: records of email correspondence, including confirmations sent in response to briefing requests.

4. Purposes and legal bases of processing

  • Handling briefing requests and pre-contractual communication (Art. 6(1)(b) GDPR — steps prior to entering into a contract, and Art. 6(1)(a) GDPR — your consent where given): Your submission is used solely to respond to your enquiry and to prepare a potential business engagement. A notification email is sent to the Company and a confirmation email to you.
  • Operation and security of the website (Art. 6(1)(f) GDPR — legitimate interest): Technical access data is processed temporarily to deliver the website, detect malfunctions, and defend against attacks.
  • Compliance with legal obligations (Art. 6(1)(c) GDPR in conjunction with Cypriot law): Retention of business records where required.

The Company does not use automated decision-making or profiling pursuant to Article 22 GDPR.

5. Recipients and processors

Personal data is processed by the Company and by carefully selected service providers acting as processors pursuant to Article 28 GDPR, in particular hosting and infrastructure providers (website hosting and database) and email delivery services for transactional correspondence. Where data is transferred outside the European Economic Area, the transfers rely on an adequacy decision of the European Commission or, absent such decision, on the European Commission's Standard Contractual Clauses together with supplementary measures.

Personal data is not sold, rented, or shared with third parties for their own marketing purposes.

6. Retention period

Briefing request data is retained for as long as necessary to handle your enquiry and any follow-up engagement, and thereafter in accordance with the limitation periods under Cypriot law (generally up to six years under the Cyprus Contract Law and Limitation Law, Cap. 9) or statutory commercial record-keeping obligations. Technical access data is deleted or anonymised as soon as it is no longer required for security purposes, normally within a maximum of 90 days.

7. Your rights

You have the following rights under the GDPR:

  • Right of access (Art. 15 GDPR);
  • Right to rectification (Art. 16 GDPR);
  • Right to erasure (“right to be forgotten”, Art. 17 GDPR);
  • Right to restriction of processing (Art. 18 GDPR);
  • Right to data portability (Art. 20 GDPR);
  • Right to object to processing based on legitimate interests (Art. 21 GDPR);
  • Right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal (Art. 7(3) GDPR).

To exercise any of these rights, contact hollmann@axiomledger.com. The Company will respond within one month of receipt of your request, in accordance with Article 12(3) GDPR.

8. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR). The competent supervisory authority for the Republic of Cyprus is:

Office of the Commissioner for Personal Data Protection
Iasonos 1, 1082 Nicosia, Republic of Cyprus
Email: commissioner@dataprotection.gov.cy
Website: www.dataprotection.gov.cy

9. Data security

The Company implements appropriate technical and organisational measures pursuant to Article 32 GDPR, including encrypted connections (TLS), access restrictions, and hosting within a professionally managed infrastructure, to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.

10. Cookies and similar technologies

This website uses only technically necessary storage where strictly required to provide the service expressly requested (Art. 5(3) of Directive 2002/58/EC, as amended by Directive 2009/136/EC, and the Cypriot Processing of Personal Data (Electronic Communications) Regulations). No marketing, analytics, or third-party tracking cookies requiring consent are set by the Company.

11. Amendments

The Company may amend this Privacy Policy to reflect changes in legal requirements or its processing activities. The version published on this website applies. The date of the last revision is stated at the top of this page.