This Privacy Policy explains how Sanpro Service Ltd collects and uses personal data when you visit sanpro-service.com, contact us, or work with us on a project.
Sanpro Service Ltd is a company registered in Cyprus with registration number HE 409456. For this policy, “Sanpro”, “we”, “us”, and “our” mean Sanpro Service Ltd.
1. Who controls your personal data
Sanpro Service Ltd is the data controller for the personal data described in this policy under the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018.
Controller details:
- Sanpro Service Ltd
- Registration number: HE 409456
- Country: Cyprus
- Website: sanpro-service.com
- Privacy contact: privacy@sanpro-service.com
2. What we collect
We collect only the personal data we need to review, launch, support, and administer projects.
We may collect:
- Identity details, such as your name and business name.
- Contact details, such as email address, phone number, and postal address.
- Project details, such as your project idea, app concept, DIY gadget kit information, plans, files, prototypes, budgets, timelines, and messages with us.
- Commercial and contract details, such as agreed profit-share terms, project status, invoices, payments, and creator records.
- Payment and bank details needed to distribute profits or make payments to you.
- Website and device data, such as IP address, browser type, pages visited, cookie identifiers, and basic analytics data.
- Consent records, such as whether you accepted optional cookies or marketing messages.
Some project details may include confidential business information. Please do not send special category personal data unless we specifically ask for it and explain why it is needed.
3. Why we use your data and our legal basis
We use your personal data for the purposes below.
- To review your project submission and communicate with you. We use your name, contact details, and project details. Our legal basis is steps before a contract and our legitimate interest in assessing potential projects.
- To provide our project launchpad services. We use project, contact, contract, and payment details. Our legal basis is performance of a contract.
- To manage profit-share arrangements and payments. We use identity, contract, invoice, payment, bank, and address details. Our legal basis is performance of a contract and compliance with legal obligations such as accounting and tax rules.
- To protect our business, website, users, and creators. We may use account, communication, technical, and project records. Our legal basis is legitimate interest in security, fraud prevention, dispute handling, and service improvement.
- To send service messages. We use your contact details to send project updates, payment notices, and important changes. Our legal basis is performance of a contract or legitimate interest.
- To send optional marketing or use optional analytics cookies. We rely on your consent where required by GDPR and the ePrivacy Directive.
- To keep legal and accounting records. We use contract, invoice, payment, and correspondence records. Our legal basis is compliance with legal obligations.
Where we rely on legitimate interest, we balance our interest against your rights and freedoms.
4. Cookies and electronic communications
We may use cookies and similar technologies on sanpro-service.com.
Essential cookies are used to make the website work, keep it secure, remember privacy choices, and manage forms. These cookies do not require consent when they are strictly necessary.
Optional cookies, such as analytics or marketing cookies, are used only with your consent where required by the ePrivacy Directive and Cyprus rules. You can refuse or withdraw consent through the cookie banner or your browser settings.
We do not sell cookie data.
5. How we store and protect data
We use reasonable technical and organisational measures to protect personal data. These may include access controls, secure hosting, encryption in transit, backups, staff confidentiality duties, and limited access based on need.
No system is completely secure. If a personal data breach creates a risk to your rights, we will handle it under GDPR rules and notify the Cyprus supervisory authority or affected people where required.
6. Who we share data with
We do not sell your personal data.
We may share data with:
- Hosting, cloud, email, analytics, and security providers that help us run the website and services.
- Payment processors, banks, accounting providers, and tax advisers that help us process payments and keep records.
- Professional advisers, such as lawyers or auditors, when needed.
- Authorities, courts, regulators, or law enforcement where required by law.
- Business partners or suppliers involved in a specific project, but only where needed for that project and subject to suitable confidentiality or data protection terms.
Where a service provider processes personal data for us, we use data processing agreements and require appropriate safeguards under GDPR Article 28.
7. International transfers
We try to use providers located in the European Economic Area where practical. If personal data is transferred outside the EEA, we use safeguards required by GDPR. These may include an adequacy decision, the European Commission Standard Contractual Clauses, transfer impact checks, or other lawful safeguards.
8. How long we keep data
We keep personal data only as long as needed for the purpose collected, unless law requires a longer period.
Typical retention periods are:
- Project enquiries not accepted: up to 24 months after the last contact.
- Active project and creator records: for the project term and up to 10 years after the end of the relationship.
- Contract, invoice, payment, bank, accounting, and tax records: up to 7 years, or longer if required by law or an active dispute.
- Website analytics data: up to 26 months, unless anonymised earlier.
- Cookie consent records: up to 12 months, then we may ask again.
- Legal claims and dispute records: until the claim is resolved and any limitation period has expired.
We may anonymise data so it no longer identifies you. Anonymised data may be kept for statistics and business planning.
9. Your GDPR rights
You have the following rights under GDPR, subject to legal limits:
- Access: you can ask for a copy of your personal data.
- Rectification: you can ask us to correct inaccurate or incomplete data.
- Erasure: you can ask us to delete your data in certain cases.
- Restriction: you can ask us to limit how we use your data in certain cases.
- Portability: you can ask for data you gave us in a structured, commonly used, machine-readable format.
- Objection: you can object to processing based on legitimate interests or direct marketing.
- Automated decision-making: you can ask not to be subject to decisions based only on automated processing that have legal or similarly significant effects. We do not use such decisions for project acceptance or profit-share payments.
- Withdrawal of consent: where we rely on consent, you can withdraw it at any time. This does not affect processing done before withdrawal.
To exercise your rights, contact privacy@sanpro-service.com. We may need to verify your identity before responding. We normally respond within one month.
10. Complaints
You can contact us first so we can try to resolve your concern.
You also have the right to lodge a complaint with the Cyprus supervisory authority:
Office of the Commissioner for Personal Data Protection
1 Iasonos Street
1082 Nicosia
Cyprus
11. Changes to this policy
We may update this Privacy Policy when our services, website, or legal duties change. The updated version will be posted on sanpro-service.com with a new “Last updated” date.