Privacy policy
1. Introduction
Taurus SA and Taurus (Europe) Ltd (hereinafter collectively mentioned as Taurus) is committed to providing you with the highest
quality service. This includes maintaining your privacy and protecting your personal information. This Privacy Policy is issued by Taurus, identified as data controller, and, in some cases, both Taurus entities may act as joint controllers or processors, depending on the processing activity. This privacy policy is directed to individuals outside our organization with whom we interact, including our (existing and former) clients, prospective clients, direct service providers, affiliated companies, job applicants, visitors to our websites (our “Website”), and in general any recipients of our services or individuals in direct relationship with Taurus. Please read this Privacy Policy carefully before using the Website. For Taurus clients, this Policy is to be read in addition to the Terms and Conditions.
As a data controller, we are in charge of gathering and using your personal information in connection with the services we provide. Taurus is committed to protecting your data in compliance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR) and/or the Swiss Federal Act on Data Protection (FADP). We adhere to the principles of lawfulness, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability as required by these regulations.
a. Taurus
-
Taurus (Europe) Ltd: The entity responsible for the data processing and regulatory compliance within the European Economic Area (EEA). Taurus (Europe) Ltd abides by and is bound by the regulation 2016/679, General Data Protection Regulation (hereinafter the
GDPR). -
Taurus SA: The entity based in Switzerland, responsible for operations and compliance under the Swiss Federal Act on Data Protection (FADP).
b. Data Controller
The entities that determine the purposes and means of processing personal data. In this Policy, Taurus may act as Data Controllers depending on the jurisdiction and nature of the data processing activities.
c. Definitions
“Applicable Law” means any and all current and future laws, regulations, and legal requirements—including but not limited to data protection, privacy, and electronic communications legislation—that govern the collection, use, disclosure, and processing of personal data by Taurus. “Country of Residence” means:
- The country where an individual primarily resides or maintains a permanent address, as determined by objective criteria such as domicile or the center of one’s personal and economic interests. This term is used to identify the jurisdiction whose laws apply to the processing of that individual’s data.
- The country in which a legal entity is either legally incorporated or, if not incorporated, where its principal place of
business is located. This definition ensures that, for business clients, the determination of the applicable law is based on the jurisdiction most relevant to the entity’s legal and operational status.
“GDPR” means the General Data Protection Regulation, an EU regulation that governs the processing of personal data of individuals residing in the European Union and the European Economic Area. The GDPR establishes strict guidelines for consent, data security, rights of data subjects, and the lawful transfer of personal data.
“Swiss FADP” means the Swiss Federal Act on Data Protection, which regulates the processing of personal data within Switzerland. This law aims to protect privacy and the rights of individuals by mandating that personal data be processed in a lawful, fair, and transparent manner.
“TOM” means Technical and Organizational Measures
2. Why have a Privacy Policy?
Regulation (EU) 2016/679 on the protection of natural persons about the processing of personal data and on the free movement of such data, which was transposed into national law, i.e., Law 125(I)/2018, sets out important standards regarding information that identifies an individual. This is known as “personal data.” All organizations processing personal data must do so fairly and lawfully. At Taurus, we treat all our obligations seriously and take all the necessary steps to comply with these obligations when we store and process your data. Given the above, Taurus has a privacy policy in place to advise clients of their rights and outline its own responsibilities in order to adhere to all applicable laws and regulations.
3. Acceptance of Privacy Policy
By accessing and using the Website and/or Taurus’ services, you acknowledge that you have read and agree to this Privacy Policy. In compliance with Regulation (EU) 2016/679 (GDPR) and the Swiss Federal Data Protection Act (FADP), we will seek your explicit consent for certain processing activities, such as marketing communications, through an active opt-in mechanism. Unless required by law, no data collection will begin until you have provided explicit consent. If consent is not given or is subsequently withdrawn, any personal information already collected, including IP addresses, will be promptly deleted in accordance with GDPR Article 7(3) and FADP requirements.
For the avoidance of doubt, signing a specific agreement to use Taurus’ services will only be interpreted as explicit consent for the personal data required and/or necessary to carry out that agreement. However, separate and explicit consent through an active opt-in process will always be required and needed for extra data processing activities, including marketing or analytics. Withdrawal of your consent can be done at any time in the cookie settings.
4. Collection of data
Taurus collects non-personally-identifying information of the sort that web browsers and servers typically make available, such as the operating system, the browser type, language preference, referring site, and the date and time of each request to the Website. Taurus’s purpose in collecting non-personally identifying information is to better understand how a person uses the Website, which poses a legitimate interest. These data can be collected with the help of analytics tools. Such technologies can tell Taurus things like how a person arrived on the Website, if this person visited the Website before, how long this person stays on the Website, and which pages this person visits. In particular, the Website uses Google Analytics. To learn more about it, visit: here. If you do not wish to be tracked, you can opt out via Google’s tool here by following these steps: Turn cookies on or off - Computer - Google Account Help.
Taurus also collects potentially personally-identifying information like Internet Protocol (IP) addresses. Taurus will only use these information in order to provide its service in line with regulatory requirements and does not disclose such information under this Privacy Policy for any reason that is not permitted by law.
The access and use of the Website and the provision of Taurus’ services require Taurus to gather personal data, i.e., all information relating to an identified or identifiable person. The amount and type of information that Taurus gathers will depend on the nature of the interaction. In each case, Taurus collects such information necessary or appropriate to fulfil the purpose of the person’s interaction with the Website, e.g., to provide the online products and/or services. You may choose to refuse to supply personal data to us. Taurus might not be in a position to serve you as effectively or offer you some or all of Taurus’ services or products when you choose not to share certain personal information with us.
We do not collect personal data related to your health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, or data concerning your sex life or sexual orientation. If and when sensitive data is to be collected (for instance, legal requirements as per customer identification), explicit consent from you is required for the processing of such data unless another legal basis applies (e.g., vital interests, legal claims, etc.).
5. How do we collect personal data?
In most cases, you provide us with the personal data that we process. You may provide us with information:
- when entering into and during the business relationship;
- when you visit our Website;
- when you log into our Website and/or use our mobile application;
- when you call us or send us an e-mail, or letter;
- when you visit our premises;
- when you request and/or subscribe to new products or services;
- when you voluntarily participate in a survey, provide feedback, apply for special offers and promotions, enter into competitions, or register for our events (such as webinars); and
- when you fill in one of our forms or sign a contract with Taurus.
However, we may also obtain personal data from other sources such as official authority databases and databases made publicly available to third parties. We also obtain personal information from websites/social media pages. We work closely with third parties (e.g. business partners, technical, payment and delivery service providers, advertising networks, tracking and analytics providers (including Google), data aggregators, lead generation agencies, public sources, third party social networking sites and search information providers) and may receive information about you from them. We may also receive personal data about you when we acquire other companies.
6. Why do we collect personal data?
Taurus’ primary purpose in collecting personal information is legitimate interest; to provide you with a secure, smooth, efficient, and customized experience. In general, Taurus uses personal information to create, develop, operate, deliver, and improve its services, including but not limited to the following:
- To provide you with Taurus’ services and customer support that you may request;
- To process transactions and send you notices about your transactions;
- To verify your identity;
- To send administrative or account-related information to you;
- To better understand Taurus’ customers and end users and the way they interact with the Website and Taurus’ services;
- To implement the preferences you opt for;
- To customize, measure, and improve Taurus’ services and layout of the Website;
- To enhance security, prevent fraud, monitor and verify identity or services access, combat spam or other malware or security risks;
- To deliver targeted marketing, services update notices, and promotional offers based on your communication preferences;
- To communicate with you;
- To prevent and investigate potentially prohibited or illegal activities, and/or violations of Taurus’ T&C;
- To resolve disputes and collect fees;
- To comply with legal obligations;
- For quality control and staff training.
Taurus will not use your personal information without your permission for purposes other than the purposes it has disclosed to you. From time to time, Taurus may request your permission to allow us to share your personal information with third parties. You may choose not to have your personal information shared with third parties where Taurus relies on consent as the lawful basis for processing your personal information. You may also choose not to allow Taurus to use your personal information for any purpose that is incompatible with the purposes for which Taurus originally collected it or subsequently obtained your authorization. If you choose to limit the use of your personal information, some or all features of Taurus’ services may not be available to you.
We process personal data based on the following legal bases:
- Contractual necessity (e.g., providing services, transactions).
- Legal obligations (e.g., AML/KYC requirements).
- Legitimate interest (e.g., fraud prevention, service improvement).
- Consent (e.g., marketing communications).
Taurus maintains an up-to-date data processing register.
7. Who do we share your personal data with and why?
Within Taurus, your personal data will only be accessed by people who need them for business purposes such as third party service providers, affiliates, banks, payment services providers etc.
To improve the efficiency and quality of the products and services requested by you or to which you have subscribed and to ensure the best possible service and high-quality standard, we may disclose, in accordance with applicable law and for legitimate business purposes, certain personal data to our parent company and/or a partner and/or business affiliate.
In some cases, we are obliged by law to disclose personal data to third parties, such as market and regulatory authorities, including tax authorities, regulators and supervisory bodies, public and judicial authorities (such as the police, prosecutors, law courts).
Our Website may use third-party plugins or content. If you choose to interact with any such plugins or content, your personal data may be shared with the third-party provider of the relevant social media platform. We recommend that you review that third party’s privacy policy before interacting with its plugins or content. In some cases, Taurus also entrusts third parties to provide you with services to which you have subscribed in order to process your personal data, to carry out our contractual relationship with you.
If Taurus is acquired by a third party, personal data held by it about its customers and direct relationships will be one of the transferred assets.
When we work with data processors or transmit personal data to data controllers located in countries outside the country of incorporation of Taurus, we ensure that the countries concerned have been recognized as ensuring adequate protection of personal data. In such cases, we take action (for example, through contractual measures) to guarantee that your personal data are properly secured in the country of destination. More information can be found in our Privacy Notice.
8. Third Party providers
Taurus may transfer or disclose the personal data it collects to its affiliates or third-party contractors, for the purpose of the provision of Taurus’ services to you, for the purposes for which the information has been submitted, and for the purposes listed in section 6 above. Taurus may also transfer personal data to third-party providers of data backup, security, and storage services. All third-party providers shall only use the personal information in connection with the services they perform for Taurus and shall be bound by contracts offering the same degree of protection as what is specified in the present Privacy Policy.
It is Taurus’ policy to use only third-party providers that are bound to maintain appropriate levels of security and confidentiality, to process personal information only as instructed by Taurus and to impose the same obligations on to their own sub-processors, in accordance with applicable laws and regulations.
We will inform you of the recipients or categories of recipients of data transfers, and ensure that any processor meets the requirements we impose on ourselves through this policy regarding the protection of your personal data. Please refer to section 14 for an overview of our TOMs.
9. How do we treat electronic messages sent to and from Taurus?
All electronic messages sent to and from Taurus are protected by reasonable TOMs and may only be accessed in justified cases in line with applicable laws and regulations (e.g. court order, suspicion of criminal conduct, violation of regulatory obligations, material breach of employment contract) to specific persons in defined functions (e.g. Legal, Compliance, Risk). Every step of the process, as well as the search criteria used, are logged in an audit trail.
10. Direct marketing
From time to time, Taurus may use your personal data (including your name and contact details) to send you news, offers, promotions, and joint marketing offers about Taurus’ products and services, per the level of consent you have expressed when registering with Taurus.
Unless you have previously indicated that you do not wish to receive marketing materials from Taurus, your consent to use and disclose your personal data for the above direct marketing purposes has been obtained in accordance with applicable laws under existing privacy notices, agreements, and/or Taurus’ T&C, as part of your ongoing relationship with Taurus.
Even if you have previously given Taurus your express consent to use and disclose your personal data for the above direct marketing purposes, you may withdraw your consent at any time free of charge by contacting Taurus as indicated in annexes below. The withdrawal of your consent will be processed and will take effect as soon as reasonably possible.
11. Links to third party sites
This Privacy Policy only applies to information collected by Taurus. This Privacy Policy does not apply to the practices of companies that Taurus does not own or control. The Website contains links to third party websites. Any information a person provides to, or that is collected by, third-party sites may be subject to the privacy policies of those sites, if any. Taurus encourages each person to read such privacy policies of any third-party sites that such person visits. It is the sole responsibility of such third parties to adhere to any applicable legal or other applicable restrictions on the disclosure of a person’s personal data, and Taurus and its affiliated corporate entities shall not be liable for wrongful use or disclosure of any person’s personal data by any third party.
12. Period for which your personal data is stored
Taurus stores your personal data in accordance with its legal obligations and will only retain your personal data for as long as it is necessary for the stated purposes and in compliance with applicable data protection laws, including the General Data Protection Regulation (EU) 2016/679 (GDPR) and/or the Swiss Federal Act on Data Protection (FADP).
This means that we may retain your personal data for a reasonable and in line with the regulatory framework and/or a reasonable period after your last interaction with us. When the personal data that we collect is no longer required in this way, we destroy or delete it in a secure manner. To comply with the requirements of the applicable regulations, Taurus maintains an up-to-date Data Processing Register. This register provides a detailed overview of all personal data processing activities, including the purpose of processing, categories of personal data, data recipients, and security measures.
Additionally, we have implemented data retention policies that are regularly reviewed and updated to ensure that personal data is retained only for as long as necessary to fulfill the purposes for which it was collected. Once the retention period expires, personal data is securely deleted or anonymized.
13. Data accuracy
We take reasonable steps designed to ensure that:
- your personal data that we process are accurate and, where necessary, kept up to date and
- any of your personal data that we process that are inaccurate (having regard to the purposes for which they are processed) are erased or rectified without delay.
From time to time, we will ask you to confirm the accuracy of your personal data or, as the case may be, to update them, including by providing us with evidences.
14. Security of your personal data
Taurus understands how important your privacy is, which is why Taurus maintains (and requires its service providers to maintain) appropriate physical, technical and administrative safeguards to protect the security and confidentiality of the personal information you entrust to us.
a. ISO 27001:2022 certified
At Taurus, the security and confidentiality of your personal data are our top priorities. To ensure the highest level of protection, we have implemented rigorous security measures and Taurus SA is proud to be ISO/IEC 27001:2022 certified. This certification demonstrates our commitment to maintaining an effective Information Security Management System (ISMS) that safeguards your personal data against unauthorized access, loss, or misuse.
Our compliance with ISO 27001:2022 means that we follow international best practices for information security, including risk management, access control, data encryption, and regular security audits. This certification is a testament to our ongoing dedication to protecting your personal data in full compliance with the GDPR and the FADP.
b. Technical and Organizational Measures (TOMs)
Taurus ensures that a number of TOMs are in place to protect your data regardless of the measures outlined above. Key aspects of our policies are described below and are not to be regarded as an exhaustive list but rather a complementary overview of our baselines.
All personal data transmitted between your device and our servers is protected by industry standard encryption mechanisms in-transit and additionally at-rest.
Access to personal data is strictly limited to authorized personnel on a need-to-know basis. We enforce role-based access controls, and work with multi-factor authentication methods to add additional layers of security to authentication and authorization in our systems.
To maintain a high level of quality in regards to security, we conduct periodic vulnerability assessments, penetration test, and security audits by independent third-party experts.
Our reactions to incident response follow tested response plans that are kept up to date for our systems. Regular backups of critical date are performed and securely stored to ensure data integrity and availability. Our disaster recovery and business continuity plans are thoroughly tested and updated to ensure that, in the event of any disruption, personal data can be restored quickly and effectively.
As an additional layer of defense we provide trainings and awareness programs for our employees covering data protection best practices on how to secure personal data and best practices on how to securely handle it, and the identification of phishing and other cyber threats.
Despite Taurus’ measures to protect personal information, it cannot guarantee that loss, misuse, unauthorized acquisition or alteration of your data will not occur. Your attention is drawn to the fact that you play a vital role in protecting your information. To get the most out of our services, please keep your personal data (including your email address) accurate and up to date.
c. Locations
We may process all or part of your personal and transactional information, including certain payment information, in the Republic of Cyprus, in Switzerland, and elsewhere in the world where Taurus facilities or service providers are located. Taurus protects your personal information by maintaining physical, electronic, and procedural safeguards in compliance with the applicable laws and regulations.
For example, Taurus uses computer safeguards such as firewalls and data encryption, and all personal data is stored on secure database servers with restricted access. Please note that any personal data transferred to the Website may be transferred out of the person’s country of origin or residence. You expressly consent to such transfer and storage through the use of the Website. You also warrant that you have the right to transfer such information outside the country where they originated from.
Other than to its employees and affiliated corporate entities or as described above, Taurus discloses personal data only when required to do so by law, or when Taurus believes in good faith that disclosure is reasonably necessary to protect the property or rights of Taurus, third parties, investors or the public at large. Taurus takes all measures reasonably necessary to protect against the unauthorized access, use, alteration, or destruction of personal data.
Please note that these data protection measures do not apply to personal data you choose to share in public areas such as on community websites. You can also help to protect your personal data, by following the guidelines below:
- Choose a password that you will be able to remember but that would be hard for someone to guess. Ideally it should include special characters (such as “?” or “#” for example) and numbers. We recommend that you change it regularly and if you need to write it down, always keep it in a safe place;
- Make sure that no-one can see the details you are entering when you log-in;
- Remember to close your browser each time you log-off and end your session and, if possible, clear any history of the websites you have visited and that your browser may have saved or “cached”; and never disclose your account details to anyone;
- Ensure that you use software with the latest security settings;
- Do not leave your IT equipment unattended;
- Log off from your online account when you are not using it;
- Be vigilant and learn how to detect unusual activity, such as new website addresses or phishing emails requesting personal information. You can let us know about any phishing attempts using [email protected]. Taurus will never ask you for your account numbers, debit or credit card numbers, passwords or codes via e-mail.
15. Notification
In the event of a personal data breach, Taurus will notify the Commissioner for Personal Data Protection in accordance with the requirements of the applicable regulation (see annexes).
16. Cookies
Taurus and their third-party providers may use cookies to collect information about you. This helps us to provide you with optimized experience while you use our Website.
It has been designed to protect online privacy, by making you aware of how information about you is collected by websites, what it is used for, and enable you to choose whether or not to allow it to take place.
You can find more information about the cookies we use and the purposes for which we use them below. You can at any time change or withdraw your consent from the Cookie Declaration on our Website.
16.1 What is a cookie
A cookie is a small file, typically a string of information of letters and numbers, downloaded to a device when a person accesses certain websites. Cookies are then sent back to the originating website on each subsequent visit. Cookies can allow a website to recognize a person’s device.
16.2 Types of cookies used by Taurus
Taurus uses several types of cookies. Some are essential, while others you can opt out of or block. Opting out or blocking some cookies may affect the functionality of the online products and/or services, and of the Website. The below explanations shall help each person to make informed choices about the information a person provides to Taurus and third parties when a person visits the Website.
16.3 Why and how Taurus uses cookies
There are broadly four reasons why a cookie might be stored on your device when visiting the Website:
- Cookies that make the Website works properly for you and enable you to make use of the secure online products and/or services that Taurus provides;
- Cookies that collect data about your use of the Website which is then anonymized and used to help Taurus improve online products and/or services;
- Cookies that remember your preferences and make the Website easier for you to use;
- Cookies that are placed by third party services Taurus makes use of to enhance the information Taurus presents online. Taurus has no control over these third party cookies.
These cookies are placed on your device either by Taurus or by the third parties whose services we use as part of the Website. Some cookies are retained in your browser for only as long as you visit the Website, while others persist for a longer specified or unspecified period.
16.4 How to block cookies
You can restrict or block cookies which are set during your use of the Website by changing your browser’s settings. For more detailed information, see http://www.allaboutcookies.org/. Some pages may not work if you completely disable cookies, but many third party cookies can be safely blocked.
Check information in your browser’s help section for specific instructions on how to manage cookies.
16.5 Strictly necessary cookies
Some cookies Taurus places on your browser ensure that the Website, the online products and/or services, deliver information and products and/or services securely and optimally to you. You must accept these cookies to be able to make use of Taurus’ online systems.
16.6 Functionality cookies
Some cookies enable websites to remember choices persons make, for example, user name, and language or text size. These cookies are known as “functionality cookies” and help to improve a person’s experience of a website by providing a more personalized service.
16.7 Performance cookies
Taurus uses a number of tools that monitor your behavior on the Website to help Taurus improve and customize the provided information and online products and/or services. In particular the Website uses the Cookie Google Analytics which collects information and reports website usage statistics without personally identifying individual visitors to Google.
You can opt out of providing Taurus with this information if you wish, with no impact on your experience of the Website. To opt out of being tracked by Google Analytics when using this Website.
16.8 Third party cookies
The Website, some online products and/or services use third party services or software. Many of these services may set cookies on your device.
You can block or remove cookies yourself by altering the settings of your browser. Blocking these cookies is unlikely to impact your experience of the Website.
16.9 Cookies set across the website
The cookies set across the Website are strictly necessary cookies.
5. Links to other websites
Our Sites may, from time to time, contain links to and from other websites. If you follow a link to any of these websites, please be aware that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites. Taurus is not responsible for the privacy policies or the content of the sites you link to, nor do we have control over the use or security of information provided by you or collected by those sites. If you choose to link to one of these websites, you may be asked to supply registration or other information. It is important that you realize this information is going to a third-party, and you should become familiar with the privacy policy provided by that third-party.
6. Your rights and how to exercise them
Please refer to Annex I and Annex II
7. Change to the Privacy Policy
Taurus may update and amend this Privacy Policy from time to time, and in Taurus’ sole discretion. If Taurus does, then Taurus will post the amended policy on the Website. In all cases, use of information Taurus collects is subject to the Privacy Policy in effect at the time such information is collected. You are therefore encouraged to review this Privacy Policy periodically to be informed about how Taurus is protecting your personal information.
ANNEX I
Information relating to Taurus SA and people that these rules shall extend to:
Your rights in relation to personal information
In accordance with application regulations, you have a set of rights over your personal information:
- Right to be informed: You have the right to be informed about what we do with your personal data, which is why we have made this Privacy Policy available to you on our Website.
- Right to object: You have the right to ask us not to process your personal data. You can exercise your right to object by contacting our Data Protection Officer at [email protected]. If you wish to opt out of marketing communications, our emails will also have an ‘unsubscribe’ option.
- Rights to access: Upon your written request, we will send you a copy of the information that we hold about you.
- Rights to correct: We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is incomplete or incorrect.
- Right to delete: If we hold personal information about you and you want it to be removed from our database or inactivated, please contact our Data Protection Officer at [email protected]. You can request that we erase your personal data if there is no reason for us to continue using it. This right only applies in certain circumstances, and it is not a guaranteed or absolute right, as we have regulatory and legal obligations in certain circumstances to continue holding personal data for the retention period mentioned above.
- Right to request a limited processing: You have the right in certain circumstances to request that we suspend our processing of your personal data. For example, you have the right to opt out of marketing emails. Where we suspend our processing of your personal data we will still be permitted to store your personal data, but any other processing of this information will require your consent, subject to certain exemptions.
- Right to the portability of some personal information: When we send a copy of the information that we hold about you, this will be provided to you without undue delay in a structured, commonly used and machine-readable form.
- Rights not to be subject to automated decision making and profiling: Unless you have previously consented, we will inform you of any decision that is made solely on the basis of automated processing of personal data. If you request it, we will give you the opportunity to express your point of view. You can request that the automated individual decision be reviewed by a natural person.
- Right to complaint: Should you not be satisfied with the way we have responded to your concerns, you have the right to submit a complaint to our Data Protection Officer. You are also entitled to lodge a complaint with the local judicial authorities.
Notification
As a controller, Taurus shall notify the Federal Data Protection and Information Commissioner of any breach of data security that is likely to lead to a high risk to the data subject’s personality or fundamental rights as soon as possible.
If you have any queries regarding this notice or the way in which we process your personal data, please contact us at:
Email: [email protected] Telephone: +41(0) 22 518 90 49 Address: Taurus SA, Place Ruth-Bösiger 6, 1201 Geneva, Switzerland
We will answer your request within a maximum of one month.
This Privacy Policy and all matters arising out of or relating to this Privacy Policy shall be governed by and construed in accordance with the laws of Switzerland, excluding its conflict of law provision.
All disputes arising out of or in connection with this Privacy Policy shall be submitted to the competent courts of the Republic and Canton of Geneva, Switzerland, an appeal to the Swiss federal court in Lausanne being reserved.
ANNEX II
Information relating to Taurus (Europe) Ltd and people that these rules shall extend to:
YOUR RIGHTS AND HOW TO EXERCISE THEM
This Privacy Policy and all matters arising out of or relating to this Privacy Policy shall be governed by and construed in accordance with the laws of Cyprus, excluding its conflict of law provision. The EU Privacy and Electronic Communications Directive (Amendment) Regulations 2011, known as the Cookie Legislation, transposed in Cyprus through the amendments in the Law 112(I)/2004, requires all businesses operating websites to collect informed consent from visitors for the use of cookies on their equipment before placing cookies or reading cookies on a computer or any other web connected device, like a smartphone or tablet.
In accordance with application regulations, you have a set of rights over your personal information:
- Right to be informed: You have the right to be informed about what we do with your personal data, which is why we have made this Privacy Policy available to you on our Website.
- Right to object: You have the right to ask us not to process your personal data. You can exercise your right to object by contacting our Data Protection Officer at [email protected]. If you wish to opt out of marketing communications, our emails will also have an ‘unsubscribe’ option.
- Rights to access: Upon your written request, we will send you a copy of the information that we hold about you.
- Rights to correct: We want to make sure that your personal information is accurate and up to date. You may ask us to correct or remove information you think is incomplete or incorrect.
- Right to delete: If we hold personal information about you and you want it to be removed from our database or inactivated, please contact our Data Protection Officer at [email protected]. You can request that we erase your personal data if there is no reason for us to continue using it. This right only applies in certain circumstances, and it is not a guaranteed or absolute right, as we have regulatory and legal obligations in certain circumstances to continue holding personal data for the retention period mentioned above, i.e. maximum seven (7) years.
- Right to request a limited processing: You have the right in certain circumstances to request that we suspend our processing of your personal data. For example, you have the right to opt out of marketing emails. Where we suspend our processing of your personal data we will still be permitted to store your personal data, but any other processing of this information will require your consent, subject to certain exemptions.
- Right to the portability of some personal information: When we send a copy of the information that we hold about you, this will be provided to you without undue delay in a structured, commonly used and machine-readable form.
- Rights not to be subject to automated decision making and profiling: You have the right not to be subject to a decision which is based solely on automated processing (without human involvement) where that decision produces a legal effect or otherwise significantly affects you. Therefore Taurus has procedures in place to involve one of our employees or representatives in the decision-making process.
- Right to complaint: Should you not be satisfied with the way we have responded to your concerns, you have the right to submit a complaint to us in respect to personal data matters. Please refer to our Complaints Handling Notice. If you are still unhappy with our reaction to your complaint, you can escalate it to our Data Protection Officer. You are also entitled to lodge a complaint with the local data protection authority, the “Commissioner for Personal Data Protection”.
Notification
In the event of a personal data breach, Taurus will notify the Commissioner for Personal Data Protection promptly and, when possible, no later than 72 hours after Taurus becomes aware of the data breach. If the breach is likely to result in a high risk to your rights and freedoms, or your personal data is affected through a data breach, Taurus shall inform you of it promptly.
If you would like to exercise the rights listed above, please submit a request in writing with a copy of your Identification Documentation to Taurus. We will answer your request within a maximum of one month. You may also submit your request to:
The commissioner
Should you not be satisfied with the way we have responded to your concerns, you have the right to submit a complaint to us in respect to personal data matters. Please refer to our Complaints Handling Notice. If you are still unhappy with our reaction to your complaint, you can escalate it to our Data Protection Officer. You are also entitled to lodge a complaint with the local data protection authority, the “Commissioner for Personal Data Protection” :
- Office address: Kypranoros 15, Nicosia 1061 , Cyprus
- Postal address: P.O. Box 23378, 1682 Nicosia, Cyprus
- Tel: +357 22818456
- Email: [email protected]
If you would like to exercise the rights listed in the Privacy Policy, please submit a request in writing with a copy of your Identification Documentation to:
Taurus (Europe) Ltd
Data Protection Officer
Themistokli Dervi 40
Agion Omologiton
1066 Nicosia
- 1. Introduction
- 2. Why have a Privacy Policy?
- 3. Acceptance of Privacy Policy
- 4. Collection of data
- 5. How do we collect personal data?
- 6. Why do we collect personal data?
- 7. Who do we share your personal data with and why?
- 8. Third Party providers
- 9. How do we treat electronic messages sent to and from Taurus?
- 10. Direct marketing
- 11. Links to third party sites
- 12. Period for which your personal data is stored
- 13. Data accuracy
- 14. Security of your personal data
- 15. Notification
- 16. Cookies
- 5. Links to other websites
- 6. Your rights and how to exercise them
- 7. Change to the Privacy Policy
- ANNEX I
- ANNEX II