Privacy Notice
ESearchCy — Cyprus Company Records Service
DRAFT TEMPLATE — NOT LEGAL ADVICE. This document is a draft template. It must be reviewed, adapted, and approved by qualified legal counsel (and checked against your actual data flows) before launch.
Effective date: 27 August 2026 Last updated: 27 August 2026 Version: 1.0
1. Who is responsible for your data
The controller of your personal data is:
Tortera Holdings Ltd (trading as ESearchCy), a private company limited by shares registered in the Republic of Cyprus, registration number HE 496600, registered office at [[TO CONFIRM: registered office — street and number, postcode, town, Cyprus]].
- General contact: info@esearchcy.com · [[TO CONFIRM: telephone number]]
- Privacy requests / Data Protection contact: info@esearchcy.com
- Data Protection Officer: [[TO CONFIRM: whether a DPO has been appointed — if so, name and contact details; if not, state "we have not appointed a Data Protection Officer, as we are not required to"]]
Full company and contact details, including our postal address and telephone number, are on our Company Details and Contact page.
This notice explains how we process personal data when you use the ESearchCy platform at esearchcy.com (the "Platform"), in accordance with the EU General Data Protection Regulation (GDPR) and the Cyprus data protection law (Law 125(I)/2018).
2. What personal data we collect
a. Account information — name, email address, password (stored as a cryptographic hash), organisation name, account settings, language preference.
b. Contact details and communications — email address, phone number (if provided), and the content of messages you send us (support requests, enquiries, complaints).
c. Order and payment data — companies you search for, orders placed, order history, invoices, billing name and address, VAT number (if provided), payment status. Full card details are collected and processed directly by our payment provider, Stripe; we receive only confirmation of payment and limited metadata (e.g. last four digits, card brand).
d. Usage data — pages viewed, searches performed, features used, downloads, timestamps, referral pages.
e. Uploaded content — any files, text, or other content you upload or enter into the Platform (see the User Content and Uploaded Data Notice).
f. AI inputs and outputs (if applicable) — where features use AI processing (e.g. document OCR, translation, summarisation), the inputs submitted to and outputs generated by those features. Provider: none — AI features are not currently used.
g. Device, browser, and log data — IP address, browser type and version, operating system, device identifiers, access times, error logs, and security logs.
h. Cookies and similar technologies — see our Cookie Policy. Analytics data is collected via none currently in use only with your consent.
i. Policy acceptance records — the policy versions you accepted, the date and time of acceptance, and the IP address and browser identifier at the time of acceptance.
j. Personal data contained in registry records. The company files we retrieve and deliver may contain personal data of third parties appearing in public registers (e.g. names and roles of directors, secretaries, and shareholders). We process this data only to fulfil your order. This data originates from public sources, principally the Department of the Registrar of Companies and Intellectual Property of Cyprus (Art. 14(5)(b) GDPR — the data is obtained from publicly available official sources and providing individual notice to each data subject would involve disproportionate effort; this notice serves as public information about that processing). If you are a company officer whose data appears in records we have processed, you may exercise the rights in section 8.
k. Your own government registry (gov.cy CyLogin) credentials — only if you choose to supply them. Most accounts do not need this: by default we carry out the file-study search at the Registrar using registry logins we hold ourselves, and you supply nothing. Some accounts — chiefly older ones set up before that became the default — instead use the customer's own gov.cy CyLogin. If you are one of them, we store the CyLogin username and password you entered, together with the registry session cookies produced when we sign in with them.
- Purpose: to sign in to the Registrar's systems as you, so that the file-study you ordered is placed and paid under your own registry identity and the resulting documents can be downloaded and delivered to you. We use them for nothing else — no other account, service or purpose.
- Legal basis: Art. 6(1)(b) GDPR — necessary to perform the contract you have asked us to perform in this mode. Supplying your own credentials is entirely optional; if you would rather not, switch your account to an ESearchCy-held registry login, or ask us to.
- Safeguards: the username and password are encrypted at rest with AES-256-GCM before being written to our database, using a key held separately as a platform secret. They are decrypted only in memory, only for the duration of an order you have placed, and they are never shown back to you in full, sent to any third party other than the Registrar's own systems, or used for any automated decision-making. See the Security Overview.
- Retention and removal: stored credentials are kept only while your account is set to use them. You can replace or delete them at any time from your account settings, or ask us to remove them at info@esearchcy.com; they are deleted along with the rest of your account if you close it. If you change your gov.cy password, change or remove it here too — otherwise we will keep presenting a password that no longer works.
We do not intentionally collect special categories of data (e.g. health, political opinions) and ask that you do not submit such data.
3. Why we process your data and on what legal basis
| Purpose | Data | Legal basis (Art. 6 GDPR) |
|---|---|---|
| Creating and managing your account; providing the Service; fulfilling orders and delivering documents | a, b, c, e, f, j | Performance of a contract (6(1)(b)) |
| Processing payments, invoicing, tax and accounting records | c | Contract (6(1)(b)); legal obligation (6(1)(c)) |
| Recording your acceptance of Terms and policies; enforcing our Terms | i, g | Legitimate interests (6(1)(f)) — proving consent/acceptance and defending legal claims; legal obligation (6(1)(c)) where applicable |
| Service communications (order confirmations, delivery, security and policy notices) | a, b | Contract (6(1)(b)); legitimate interests (6(1)(f)) |
| Security, fraud prevention, abuse detection, logging | d, g | Legitimate interests (6(1)(f)) — keeping the Service secure |
| Improving the Service; aggregate analytics | d, h | Consent (6(1)(a)) for analytics cookies; legitimate interests (6(1)(f)) for aggregated, privacy-preserving statistics |
| Marketing emails (if any) | a, b | Consent (6(1)(a)); you can withdraw at any time / unsubscribe |
| Responding to legal requests and establishing, exercising, or defending legal claims | any | Legal obligation (6(1)(c)); legitimate interests (6(1)(f)) |
Where we rely on legitimate interests, we have balanced those interests against your rights; you may object at any time (section 8).
4. Who has access to your data
Access within our organisation is limited to personnel who need it to operate the Service. We share personal data with:
- Service providers (processors): hosting and infrastructure (Google Cloud / Firebase), payment processing (Stripe), email delivery (Resend), analytics (none currently in use), AI processing (none — AI features are not currently used), customer support tooling (none — support is handled directly by email). A current list of subprocessors is maintained at /legal/third-parties.html.
- Public registries and authorities to the extent necessary to fulfil orders (e.g. submitting a search request to the Registrar).
- Professional advisers (lawyers, accountants, auditors) under confidentiality obligations.
- Authorities where required by law or to protect rights, safety, or property.
- Business transfers: if we are involved in a merger, acquisition, or asset sale, personal data may be transferred as part of that transaction, subject to this notice.
We do not sell personal data.
5. International transfers
Our providers may process data outside the EU/EEA (for example, Google Firebase, Stripe and Resend may use infrastructure in the United States). Where personal data is transferred outside the EEA, we rely on an adequacy decision of the European Commission or appropriate safeguards, in particular the EU Standard Contractual Clauses, together with supplementary measures where needed. You may request a copy of the relevant safeguards via info@esearchcy.com.
6. How long we keep your data
Indicative retention periods (full detail in the Data Retention and Deletion Notice):
| Data | Retention period |
|---|---|
| Account data | While the account is active + 12 months after closure |
| Orders, invoices, payment records | 6 years (tax/company law obligations) |
| Delivered document bundles held for re-download | 30 days after delivery, then deleted |
| Policy acceptance and consent records | Duration of the account + 6 years |
| Server and security logs | 12 months |
| Support correspondence | 24 months |
| Analytics data | Not applicable — no analytics in use |
When retention ends, data is deleted or irreversibly anonymised.
7. How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest where supported by our infrastructure, access controls and least-privilege permissions, authentication via Firebase Authentication (Google sign-in) and our own session tokens, logging and monitoring, backups, and vendor due diligence. See the Security and Data Protection Overview. No system is completely secure; please use a strong, unique password.
8. Your rights
Under the GDPR you have the right to:
- Access your personal data and receive a copy;
- Rectify inaccurate or incomplete data;
- Erase data ("right to be forgotten") in certain circumstances;
- Restrict processing in certain circumstances;
- Object to processing based on legitimate interests, and to direct marketing at any time;
- Data portability — receive data you provided in a structured, commonly used, machine-readable format;
- Withdraw consent at any time where processing is based on consent (this does not affect processing before withdrawal). Cookie preferences can be changed at any time via the "Cookie settings" link on the Platform;
- Not be subject to solely automated decisions producing legal or similarly significant effects; we do not carry out such decision-making.
To exercise any right, contact info@esearchcy.com or use the privacy request form in your account settings. We may need to verify your identity. We respond within one month (extendable by two further months for complex requests, in which case we will inform you).
Complaints: you may lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus (www.dataprotection.gov.cy) or the supervisory authority of your habitual residence.
9. Children
The Service is not directed at children under 18, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact info@esearchcy.com.
10. Changes to this notice
We may update this notice from time to time. Material changes will be announced on the Platform or by email, and where required you will be asked to acknowledge the new version at your next login. Earlier versions are available on request.
Privacy contact: info@esearchcy.com · Republic of Cyprus