Privacy Notice

February 12, 2026

1. WHO WE ARE AND WHAT THIS PRIVACY NOTICE COVERS

Who is responsible for my personal data?

COVENT IT (CY) LIMITED ("we", "us", "our") is responsible for your personal data. 

We are registered in Cyprus (registration number ΗΕ 465680) and operate the website https://coventit.com/.

How can I contact you?
What does this Privacy Notice cover?

This Privacy Notice explains how we handle your personal information when you:

  • Visit our website;
  • Contact us through our forms;
  • Use our services.

2. WHY WE CAN PROCESS YOUR DATA

On what legal grounds do you collect and use my personal data?

European data protection law requires us to have a valid legal reason to collect and use your personal data. We rely on the following legal grounds:

  • Contract performance: When we need your data to provide the services you've requested or to take steps before entering into a contract with you.
  • Legitimate interests: When using your data is in our legitimate business interests (like improving our services or ensuring website security) and doesn't unfairly impact your rights.
  • Your consent: When you've clearly agreed to our use of your data for a specific purpose.
  • Legal obligations: When we need to process your data to comply with laws that apply to us.

For each way we use your data (described below), we'll tell you which legal basis we're relying on.

3. WHAT INFORMATION WE COLLECT

What information do I provide directly to you?

When you interact with our website or services, you may provide us with:

  • Your name and email address;
  • Your phone number;
  • Information about your project requirements;
  • Messages you send us through contact forms;
  • Any other information you choose to share with us.
What information do you collect automatically?

When you visit our website, we automatically collect:

  • Information about your device (like your IP address, browser type, operating system);
  • How you use our website (pages visited, time spent on pages, links clicked);
  • Log data and error reports.

For more details about cookies and similar technologies we use to collect information automatically, please see our Cookie Policy at https://coventit.com/cookie-policy.

Do you get my information from other sources?

Sometimes we receive information about you from:

  • Our service providers (like analytics providers);
  • Business partners (if we work together to provide services to you).

We don't collect sensitive information about you (like health data, political opinions, or religious beliefs) unless legally required.

4. HOW WE USE YOUR INFORMATION

How do you use my information to provide your services?

When you contact us or use our services, we use your information to:

  • Respond to your inquiries about our services;
  • Prepare proposals and quotes based on your project requirements;
  • Set up and manage our business relationship;
  • Deliver the services you've contracted us for;
  • Keep you updated about your projects.

We do this because it's necessary to perform our contract with you or take steps before entering into a contract (legal basis: Performance of a Contract, GDPR Art. 6(1)(b)).

How do you use my information to run and improve your business?

We use your information to:

  • Protect and manage our website and systems (including troubleshooting, testing, and security);
  • Improve how our website works and the user experience;
  • Develop new services and features;
  • Make our website content more relevant to you.

We do this based on our legitimate business interests that don't override your privacy rights (legal basis: Legitimate Interests, GDPR Art. 6(1)(f)).

Do you use my information for marketing communications?

Yes, in limited ways:

  • We send necessary communications about services you're using;
  • We may send updates about our services that might interest you;
  • We analyze how effective our communications are.

For service-related communications, we do this as part of our contract with you. For marketing communications, we either rely on our legitimate interests or your consent, depending on legal requirements in your location.

Do you use automated decision-making or profiling with my data?

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects as described in GDPR Article 22. 

While we use tools like Google Analytics and Microsoft Clarity to analyze website usage patterns, these analyses:

  • Do not result in automated decisions affecting your rights or interests;
  • Do not involve profiling that evaluates personal aspects about you;
  • Are used solely for website optimization and user experience improvements.

If our practices change in the future to include such processing, we will update this Privacy Notice and seek appropriate consent where required by law.

Are there other ways you use my information?

We sometimes need to use your information to:

  • Comply with laws and regulations that apply to us;
  • Respond to requests from government authorities when legally required;
  • Establish, exercise, or defend legal claims.

We do this to meet our legal obligations (legal basis: Legal Obligation, GDPR Art. 6(1)(c)) and protect our legitimate interests (legal basis: Legitimate Interests, GDPR Art. 6(1)(f)).

5. WHO WE SHARE YOUR INFORMATION WITH

Who within your company can access my information?

Our employees and contractors who need your information to do their jobs may access it. This includes our:

  • Sales representatives who respond to your inquiries;
  • Project managers who oversee your projects;
  • Developers who work on your solutions;
  • Support staff who assist you with questions or issues.
Which service providers might have access to my information?

In case we work with third-party service providers who help us deliver our services. These providers:

  • Can only access your data to perform specific tasks for us;
  • Are contractually required to protect your data and not use it for other purposes.

Our main service providers include:

  • IT providers who host and secure our systems;
  • Tawk.to for the live chat feature on our website;
  • Apollo for sales intelligence and meeting scheduling;
  • Google Analytics and Microsoft Clarity for analyzing how people use our website.
Do you share my information with any business partners?

We only share your information with business partners when we collaborate to provide services you've specifically requested. We don't share your data with partners for their marketing purposes.

When might you be legally required to share my information?

We may need to disclose your information:

  • To comply with legal requirements or court orders;
  • To enforce our policies;
  • To respond to claims of rights violations;
  • To protect anyone's rights, property, or safety;
  • To public authorities when legally required.
What happens to my information if your company is sold or merged?

If our company merges with another company or is acquired, or if we sell some assets, your personal data may be transferred as part of that transaction. If this happens:

  • We'll notify you by email or through a notice on our website;
  • We'll explain any changes to how your data will be used;
  • We'll explain what choices you have regarding your data.
Do you sell my personal data?

No. We do not sell, rent, or lease your personal data to third parties.

6. TRANSFERS OF YOUR DATA OUTSIDE EUROPE

How do you protect my data when it's transferred internationally?

Whenever we transfer your data outside the EEA, we make sure it remains protected by using legal safeguards approved by European regulators, such as:

  • EU Standard Contractual Clauses (legal agreements that protect your data);
  • Adequacy decisions (transfers to countries approved as having adequate protection);
  • EU-US Data Privacy Framework (for transfers to certified US organizations).

While we don't directly transfer your personal data to organizations outside the EEA, some of our third-party service providers (like Google Analytics, Microsoft Clarity, and Tawk.to) may process your data in countries outside the EEA, including the United States. These providers have their own certifications under applicable data transfer frameworks and implement appropriate safeguards to protect your data in accordance with GDPR requirements.

7. HOW LONG WE KEEP YOUR DATA

How long do you keep my personal information?

We only keep your personal information for as long as necessary for the purposes we collected it, including any legal, accounting, or reporting requirements we need to meet.

How long do you keep different types of my information?

Different types of information are kept for different periods:

  • Your contact and identification information: For the duration of our business relationship plus up to 5 years afterward. This allows us to maintain records of our interactions and helps if you decide to work with us again.
  • Your project information: For the duration of the project plus up to 7 years after completion. This is necessary for tax and accounting purposes and to address any potential legal claims.
  • Our communications with you: For up to 3 years after our last communication.
  • Usage and technical data: For up to 26 months to help us analyze trends and improve our website and services.
How do you decide how long to keep my data?

When determining how long to keep your information, we consider:

  • What type of information it is and how sensitive it is;
  • The potential risk of harm if the information was misused;
  • Why we need the information and if we could achieve the same goal another way;
  • Legal requirements that tell us how long to keep certain types of information.
What happens to my data when you no longer need it?

When we no longer need your personal data, we either:

  • Securely delete it, or
  • Anonymize it (remove all identifying information).

In some cases, we may convert your personal data into anonymous data (so it can no longer be connected to you) for research or statistical purposes. If we do this, we may use this anonymized information indefinitely.

8. YOUR PRIVACY RIGHTS

What rights do I have regarding my personal data?

Under European data protection law, you have important rights that give you control over your personal data:

  • Right to be informed: You have the right to know how we use your data, which is explained in this Privacy Notice.
  • Right to access: You can ask us for a copy of your personal data.
  • Right to correction: You can ask us to fix incorrect information we have about you.
  • Right to deletion: You can ask us to delete your data in certain circumstances (sometimes called the "right to be forgotten").
  • Right to limit processing: You can ask us to temporarily or permanently stop using some of your data.
  • Right to object: You can tell us to stop using your data for certain purposes, like marketing.
  • Right to data portability: You can ask for a copy of your data in a format that can be transferred to another service.
  • Rights related to automated decisions: You can object to decisions made about you solely by computers without human involvement.
How do I exercise these rights?

To exercise any of these rights, please email us at [email protected]. We'll respond within 30 days. In complex cases, we might need an additional 60 days, but we'll let you know if that's the case.

There's no charge for exercising your rights, unless your requests are clearly unfounded or excessive.

Can I complain to a regulator?

Yes. If you're not satisfied with how we've handled your data, you can complain to your local data protection authority. In Cyprus, that's the Commissioner for Personal Data Protection (https://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/contact_en/contact_en?opendocument)

9. HOW WE PROTECT YOUR DATA

How do you keep my information safe?

We take data security seriously and use industry-standard safeguards to protect your information:

  • We encrypt your data during transmission and storage;
  • We restrict access to your data to only employees who need it;
  • We use firewalls, access controls, and security monitoring;
  • We regularly test our systems for vulnerabilities;
  • We train our staff on data protection.
Is my data 100% secure?

While we use strong security measures, no online method of transmission or storage is completely secure. We continuously work to protect your data, but we cannot guarantee absolute security. If you believe your data with us might be at risk, please contact us immediately.

What happens in case of a data breach?

In the unlikely event of a personal data breach that might pose a risk to your rights and freedoms, we will:

  • Notify the relevant supervisory authority (Cyprus Commissioner for Personal Data Protection) within 72 hours of becoming aware of the breach, as required by GDPR Article 33;
  • Inform affected individuals without undue delay when the breach is likely to result in a high risk to their rights and freedoms;
  • Provide information on the nature of the breach, likely consequences, and measures taken to address it and mitigate potential adverse effects;
  • Document all breaches, including facts, effects, and remedial actions taken.

We regularly test and evaluate our security measures to minimize the risk of such incidents occurring.

10. OTHER IMPORTANT INFORMATION

Do you collect information from children?

Our services are not intended for children under 16 years of age. We don't knowingly collect personal information from children under 16. If you're under 16, please don't provide any personal information to us.

If we discover we've collected personal information from a child under 16 without parental consent, we'll promptly remove that information from our systems. If you believe we might have collected information from or about a child under 16, please contact us.

What about links to other websites?

Our website contains links to other websites, plugins, and applications that we don't control. If you click these links or enable these connections, third parties may collect or share data about you.

We're not responsible for the privacy practices of these third-party websites. When you leave our website, we recommend reading the privacy policy of each website you visit.

How will I know if you change this Privacy Notice?

We may update this Privacy Notice periodically to reflect changes in our practices or to comply with legal requirements. You can always find the latest version with the "Last Updated" date at the top of this document.

If we make significant changes that affect your rights or how we use your data, we'll notify you either through the email address you've provided or by posting a prominent notice on our website.

Your continued use of our services after we post changes means you accept those changes.

Should I also read your Cookie Policy?

Yes, this Privacy Notice works together with our Cookie Policy which explains in detail how we use cookies and similar technologies on our website. We recommend reading both documents to fully understand how we handle your information.

11. LEGAL MATTERS AND CONTACT INFORMATION

Which laws govern this Privacy Notice?

This Privacy Notice is primarily based on the EU General Data Protection Regulation (GDPR). However, we recognize that visitors to our website may come from various jurisdictions with different data protection requirements.

If you access our services from outside the European Economic Area (EEA), additional or different data protection frameworks may apply to your data, such as:

  • UK GDPR for visitors from the United Kingdom;
  • LGPD for visitors from Brazil;
  • CCPA/CPRA for visitors from California.

While we primarily operate under Cyprus and EU law, we strive to respect the core principles of data protection that are common across these frameworks. If you have specific questions about how your local data protection laws apply to your interaction with us, please contact our Data Protection Coordinator.

What happens if part of this Privacy Notice is found to be invalid?

If any part of this Privacy Notice is found to be invalid or unenforceable, the rest of the document will remain valid and in effect. Any invalid provision will be replaced with a valid one that best matches the original intention.

How can I contact you with questions or concerns?

If you have any questions, concerns, or requests about this Privacy Notice or how we handle your personal data, please contact us:

COVENT IT (CY) LIMITED 

Registered Address: Omonoias, 81

Floor 3, Flat/Office 32 

3048, Limassol, Cyprus


Business Address: 

4 Iridos Street, 

office 201, 2028 Strovolos, 

Nicosia, Cyprus


Email: [email protected]

Phone: +(357) 22 552074, +(357) 97 551074


For data protection inquiries, you can contact our Data Protection Coordinator at: 

Email: [email protected]


We're committed to working with you to address any concerns you might have about your privacy. If you feel we haven't adequately addressed your complaint, you have the right to contact your local data protection authority, as described in the "Can I complain to a regulator?" section above.

certificate

Why we use cookies and other tracking technologies?

Our site enables script (e.g. cookies) that is able to read, store, and write information on your browser and in your device. The information processed by this script includes data relating to you which may include personal identifiers (e.g. IP address and session details) and browsing activity. We use this information for various purposes - e.g. to deliver content, maintain security, enable user choice, improve our sites, and for marketing purposes. You can reject all non-essential processing by choosing to accept only necessary cookies. To personalize your choice and learn more click here to adjust your preferences.

COOKIE PREFERENCES

Please select which cookies you allow us to use on our website:

  • Strictly Necessary Cookies (cannot be disabled)

    Essential for basic website functionality

    • Enable site navigation and secure areas
    • Remember items in your shopping cart
    • Provide secure authentication

    These cookies don't store personally identifiable information and are active only during your session.

  • Functional Cookies

    Enhance your experience and provide additional features

    • Remember your preferences and settings
    • Store language and region preferences
    • Enable chat functionality via Tawk.to
    • Store form information for future correspondence

    These cookies may remain on your device for up to 12 months.

  • Analytics and Performance Cookies

    Help us understand how visitors use our website

    • Track which pages you visit most frequently
    • Measure how long you spend on our site
    • Analyze which links you click and your navigation patterns
    • Google Analytics cookies (stays for up to 2 years)
    • Microsoft Clarity cookies (stays for up to 1 year)

    These cookies help us improve our website design and content.

For more detailed information about the specific cookies we use, their purposes, and how long they remain on your device, please see our Cookie Policy.