Privacy Policy
This policy sets out how Votivus Consulting Limited handles personal information as a controller, with care, discretion, and operational discipline.
Last updated: 17 July 2026
1. Who we are and how to contact us
| Field | Detail |
|---|---|
| Controller | Votivus Consulting Limited |
| Legal form | Private company limited by shares, Republic of Cyprus |
| Contact | info@votivusconsulting.com (all enquiries, including privacy matters) |
We are the sole Votivus contracting entity worldwide; there is no other affiliated entity. Our full statutory particulars (telephone) are maintained at votivusconsulting.com/legal/particulars.
Data Protection Officer. A DPO is mandatory under Article 37 GDPR only for public authorities, large-scale systematic monitoring, or large-scale special-category processing; at our scale this is not mandatory and we have not appointed a DPO. You can raise any privacy matter at info@votivusconsulting.com, which we treat as our privacy point of contact and which our two founders personally monitor. If we appoint a DPO, we will publish their contact details here.
Supervisory authority. Office of the Commissioner for Personal Data Protection, 1 Iasonos Street, 1082 Nicosia, Cyprus. https://www.dataprotection.gov.cy · commissioner@dataprotection.gov.cy. You may complain to the Commissioner or to the authority where you live or work; we would appreciate the chance to resolve your concern first.
2. Controller vs processor
This Policy covers personal data we process as a controller (our website, free tools, consultation flow, portal, marketing and outreach, and the administration of engagements). Where we instead process personal data on a client's behalf (analysing their analytics, advertising, CRM, or email data about their customers or contacts), we are a processor and our Data Processing Agreement governs that processing, not this Policy (section 10).
3. What we collect
From you: contact and enquiry data (name, business email, phone, company, role, message); free-tool inputs (website URL, marketing details, business information you submit); account and engagement data; materials you provide for an engagement (which may contain other people's data; see section 10); and payment data (billing details and transaction references; card data is handled by our payment processor, Stripe, and is not stored by us).
Automatically: technical and usage data (IP address, device/browser, pages viewed, referring URLs, approximate location) via cookies after consent (see Cookie Notice); and security/portal data (login events, sessions, password-reset tokens, rate-limit records).
From other sources, for B2B outreach: limited professional contact information (name, business email, job title, employer, public company information) from third-party business-data and enrichment providers, professional networking platforms, company registries, and public sources. We tell you the source when we first contact you (section 6).
Whether you must provide it: contact data is needed to respond to you; engagement data and access are needed to deliver paid Services (without them we cannot provide those Services); free-tool inputs are voluntary but the tool cannot run without them.
Data we do not want: we do not seek special-category data (health, racial/ethnic origin, political/religious beliefs, trade-union membership, genetic, biometric, sex-life) or criminal-offence data, and ask you not to submit it unless we agree in writing with appropriate safeguards and an Article 9 GDPR condition.
4. Cookies
We use cookies and similar technologies as set out in our Cookie Notice. Strictly necessary technologies run without consent; functional, analytics, and marketing technologies load only after you give prior consent through our banner, consistent with the Cyprus ePrivacy Law (Law 112(I)/2004). You can change your choice at any time.
5. Why we use your data, and our lawful bases
| Purpose | Lawful basis (Art. 6 GDPR) |
|---|---|
| Respond to enquiries and consultation requests | Pre-contractual steps (6(1)(b)) and/or legitimate interests (6(1)(f)) |
| Provide free tools and generate outputs | Legitimate interests (6(1)(f)) |
| Deliver paid engagements and run the portal | Contract (6(1)(b)) |
| Pre-contract steps (quotes, proposals, scoping) | Contract / pre-contractual steps (6(1)(b)) |
| B2B business development and outreach | Legitimate interests (6(1)(f)); see the Cyprus opt-in rule in section 6 |
| Bill, take payment, keep financial records | Contract (6(1)(b)) and legal obligation (6(1)(c)) |
| Secure systems; prevent fraud and abuse | Legitimate interests (6(1)(f)) |
| Improve our services, tools, and content | Legitimate interests (6(1)(f)) |
| Comply with tax, accounting, AML, and legal duties | Legal obligation (6(1)(c)) |
| Non-essential cookies and optional marketing | Consent (6(1)(a)) |
| Establish, exercise, or defend legal claims | Legitimate interests (6(1)(f)) and/or legal obligation (6(1)(c)) |
Legitimate interests. Where we rely on legitimate interests, we keep a documented legitimate-interests assessment on file and provide it to the Commissioner on request. You can object on grounds relating to your situation, and to direct marketing at any time (we then stop, no reason needed).
Consent. Where we rely on consent, you can withdraw it at any time (without affecting prior processing), as easily as you gave it.
6. B2B outreach and the Cyprus opt-in rule
For outreach we collect limited professional contact information from the sources in section 3. Our GDPR basis for processing it is legitimate interest in business development (6(1)(f)), supported by a documented legitimate-interests assessment; when we first contact you we tell you where we obtained your details and how to object, and every message has an unsubscribe option.
Separately, the act of sending unsolicited commercial email is governed by the Cyprus ePrivacy Law (Law 112(I)/2004) and the Electronic Commerce Law (Law 156(I)/2004). Cyprus operates an opt-in regime: unsolicited commercial communications generally require prior consent (or, for existing customers, a soft opt-in for similar services with an easy objection route), and every message must identify the sender and give a valid opt-out address. We design our outreach to meet these requirements and segment by the recipient's country, because rules vary by jurisdiction. To stop contact, use the unsubscribe link or email info@votivusconsulting.com; we keep only a minimal suppression record to honour your objection.
7. AI and automated processing
We use AI and automated tools to help generate audits, analyse submitted business data, and support outreach, using a combination of our own self-hosted AI infrastructure and vetted third-party AI providers (section 8). A person reviews AI-assisted outputs before they are relied on, and meaningful human judgement is applied to the advice and decisions we deliver. We do not make decisions producing legal or similarly significant effects about you based solely on automated processing (Article 22 GDPR); our automated tools (such as the free Snapshot) produce general informational output and do not, by themselves, determine whether you are offered Services or at what price. Where any AI processing would involve systematic evaluation of individuals, or where transparency obligations under the EU AI Act (Regulation (EU) 2024/1689) apply, we will assess and meet those obligations, including any Data Protection Impact Assessment (Article 35 GDPR).
8. Who we share data with
We share personal data only as needed, and where a recipient processes on our behalf it does so under an Article 28 GDPR contract or equivalent terms. Recipient categories and how we use them:
- Cloudflare: hosts our website and client portal and provides security/CDN services (technical and usage data, account and engagement data).
- Stripe: our payment processor (billing and transaction data; card data is handled by Stripe and not stored by us).
- Google Analytics: website analytics (technical and usage data, subject to cookie consent).
- Attio: our CRM, for managing prospect and client contact data.
- Our application/data platform: the platform we use to build and run our website and store related account and engagement data.
- Third-party AI providers (Anthropic, Perplexity): used, on a business/commercial-tier basis with a contractual no-training-on-our-data commitment, only to process information that is already publicly available (for example, public website content or public company information). Any data you give us that is not independently publicly available is processed exclusively on our own self-hosted AI infrastructure and is never shared with these or any other third-party AI provider.
- Business-data/enrichment providers: sources for the outreach data described in sections 3 and 6.
- Professional advisers: accountants, auditors, lawyers, and insurers, where reasonably necessary.
- Authorities or legal recipients: where required by law or to establish, exercise, or defend claims.
Our current key providers are also listed in the Subprocessor List, available on request. We do not sell personal data and do not share it for third-party advertising in exchange for payment.
9. International transfers
Some of the providers in section 8, and our own self-hosted AI infrastructure described there, operate outside the EEA (our self-hosted AI infrastructure currently operates from the United States). Where this occurs, we rely on an EU adequacy decision (including the EU–US Data Privacy Framework where the recipient is certified), the European Commission's Standard Contractual Clauses with any required supplementary measures, or another Chapter V GDPR mechanism, as described in more detail in our Data Processing Agreement (section 13), including for our own infrastructure. Where special-category data is transferred outside the EEA under Article 46/47 safeguards, we inform the Commissioner before the transfer where Cyprus law requires it. Request a copy of the safeguards at info@votivusconsulting.com.
10. When you provide data about other people
If you provide materials containing personal data about your customers, prospects, staff, or contacts, you are the controller and we are your processor, under our Article 28 GDPR Data Processing Agreement. You are responsible for having a lawful basis and for giving any notices required to those individuals.
11. How long we keep data
We keep personal data only as long as necessary, then delete or irreversibly anonymise it. Client personal data we process for an engagement (including personal data inside Deliverables) is deleted or returned at the end of the engagement under our DPA; we do not retain it beyond that except where law requires. Our own business records (which may be limited or anonymised) are kept as below.
| Type of data | Retention |
|---|---|
| Enquiry / unconverted prospect data | Up to 18 months from last contact, then deleted |
| Outreach suppression records | As long as needed to keep honouring your objection |
| Our engagement, billing, invoice, and accounting records | 6 years (Cyprus tax and accounting record-keeping) |
| AML / due-diligence records (where applicable) | 5 years after the relationship or transaction ends |
| Portal sessions, password-reset tokens, rate-limit records | Hours to days |
| Security logs | 90 days, unless needed longer for an investigation |
| Cookie-consent records | 12 months, then re-prompted |
12. How we protect data and handle breaches
We maintain technical and organisational measures proportionate to risk. In practice, at our current size (two founders, no other staff or contractors with access to client data): access is limited to us; multi-factor authentication is enabled on our hosting/security provider (Cloudflare) and email; our self-hosted AI device has full-disk encryption; our website and portal run behind Cloudflare's security layer; backups of our self-hosted AI infrastructure have been established as a standing practice from 17 July 2026; and we rely on our providers (Cloudflare, Stripe, Google Analytics, Attio, our application/data platform, Anthropic, Perplexity) for the security of their own systems, selected with reasonable care. Where we act as a processor for a client, the detailed measures are set out in Annex 2 of our Data Processing Agreement, which describes these practices in more depth.
Breaches. Where a breach is likely to risk your rights and freedoms, we notify the Commissioner without undue delay and, where feasible, within 72 hours (Article 33). Where it is likely to result in high risk to you, we notify you without undue delay (Article 34). Where we act as a processor, we notify the affected controller without undue delay and no later than 24 hours after becoming aware (see the DPA). We have not experienced a personal-data breach to date.
13. Your rights
Subject to GDPR and Cyprus-law conditions, you have the rights to access; rectification; erasure; restriction; objection (to legitimate-interests processing, and to direct marketing at any time); portability; withdraw consent; not be subject to solely automated decisions with legal or similarly significant effects; and to complain to the Commissioner or your local authority.
How to make a request. Email info@votivusconsulting.com, telling us which right you wish to exercise and enough detail to locate your data.
What happens next. (1) We may ask for information to verify your identity, so we do not disclose data to the wrong person; the response time runs from when we have what we reasonably need to verify and act. (2) We respond within one month, which we may extend by up to two further months for complex or numerous requests, telling you within the first month and explaining why. (3) Requests are handled free of charge, except that we may charge a reasonable fee or decline a request that is manifestly unfounded or excessive, and we will explain our reasons if we do. (4) Some rights are qualified (for example, we may be unable to erase data we must keep by law, or to act on a request that would adversely affect others' rights), and we will tell you if an exception applies and why. (5) If we are processing the data as a processor for one of our clients, we will direct your request to that client (the controller) and assist them in responding. (6) You can complain to us first; you also have the right to complain to the Office of the Commissioner for Personal Data Protection or your local supervisory authority at any time.
14. Children
Our services are for businesses and users aged 18+. Under Cyprus law (Law 125(I)/2018) the age of digital consent is 14; below it, processing based on a child's consent needs a parental holder's consent. We do not knowingly collect children's data; tell us if you believe we have, and we will delete it.
15. Changes and document relationships
We may update this Policy; the "last updated" date shows when. For material changes we give reasonable advance notice (a "material" change has the meaning given in our Terms of Service). This Policy governs controller processing; the Terms of Service govern use of the Services; the Cookie Notice covers cookies; the DPA governs processor processing. On a conflict about personal data, this Policy (controller) or the DPA (processor) prevails over the Terms; otherwise the Terms prevail.
Votivus Consulting Limited: Privacy Policy.
