Legal
Privacy Policy
This policy explains what personal data we collect when you use this website or contact us, why we process it, who receives it, how long we keep it, and the rights you can exercise at any time.
Last updated
1. Who is responsible
The controller responsible for processing your personal data on this website is:
- SecretBrand Solutions LTD, trading as “Cyprus VIP Estates”
- Palaion Patron Germanou 11, 8011 Paphos, Cyprus
- Email: office@cyprusvipestates.com
- Phone: +357 99 278 285
For any question about your data — access, correction, deletion or anything else in this policy — write to the address above and your request will reach the person responsible.
2. What we collect and why
- Server log files
- Each time a page is requested, our server records the browser type and version, the operating system, the referring URL, the hostname of the requesting device, the time of the request and the IP address. This is technically necessary to deliver the site and to detect abuse. It is not combined with other data sources. Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in a secure, functioning website).
- Contact forms and enquiries
- When you send us an enquiry, we store the details you provide — typically name, contact details, your preferred contact channel and your message — in order to answer you and to handle any follow-up. Enquiries are stored in our customer relationship system so that the colleague looking after you can see the history of your request. Legal basis: Art. 6 (1) (b) GDPR (pre-contractual measures at your request).
- Appointments
- If you propose or confirm an appointment through our booking page, we process the times you propose, your time zone and your contact details in order to arrange and confirm the meeting. Legal basis: Art. 6 (1) (b) GDPR.
- Newsletter
- If you subscribe, we process your email address to send you our newsletter. Legal basis: Art. 6 (1) (a) GDPR (consent), which you can withdraw at any time.
- Site analytics (cookieless)
- We count page views using a daily-rotating, irreversible hash derived from your IP address and browser string. The hash changes every day, is never stored alongside your IP address, and cannot be used to identify you or to recognise you across days. Legal basis: Art. 6 (1) (f) GDPR (our legitimate interest in understanding which content is useful), balanced by the fact that no identifier persists.
- Google Tag Manager, Google Analytics and Google Ads
- Only if you consent to analytics and marketing cookies, we load Google Tag Manager (Google Ireland Limited), which in turn activates Google Analytics 4 for reach measurement and Google Ads for conversion measurement and remarketing. Google Tag Manager itself only manages the other tags; it is the tags it loads that process your data. Legal basis: Art. 6 (1) (a) GDPR (consent).
- Meta Pixel
- Only with your consent. Provider: Meta Platforms Ireland Limited. It measures whether a visit followed one of our advertisements and lets us reach comparable audiences. Legal basis: Art. 6 (1) (a) GDPR (consent).
- LinkedIn Insight Tag
- Only with your consent. Provider: LinkedIn Ireland Unlimited Company. It measures the performance of our LinkedIn campaigns and allows audience targeting there. Legal basis: Art. 6 (1) (a) GDPR (consent).
- Microsoft Clarity — including session recording
- Clarity (Microsoft Ireland Operations Limited) shows us how pages are actually used: mouse movement, scrolling, clicks and page interactions, which it can replay as an anonymised session recording and aggregate into heatmaps. This is more far-reaching than plain visit counting, which is why we name it separately here. The Clarity script is loaded on every page, but it is told whether you have consented: without your consent it runs in Microsoft's restricted mode, which does not set cookies and does not build a profile; with your consent it records the full session. Legal basis: Art. 6 (1) (a) GDPR (consent) for the full mode, and Art. 6 (1) (f) GDPR (our legitimate interest in seeing where the site confuses people) for the restricted mode. You can object to the latter at any time under Art. 21.
3. Who receives your data
Passing your details to a developer or a lawyer is a core part of what we do. It only ever happens for the specific property interest you have told us about.
Depending on your enquiry, your contact details may be shared with:
- Property developers in Cyprus — to arrange viewings and prepare offers for the properties you are interested in. Legal basis: Art. 6 (1) (b) GDPR.
- Independent lawyers — for legal checks and contract drafting, where you ask us to introduce you. They act as separate controllers and are bound by their own professional confidentiality.
- Our IT service providers — hosting, email delivery and the systems we use to manage enquiries. These act as processors under Art. 28 GDPR and only on our documented instructions.
We do not sell your personal data, and we do not pass it on for anyone else's advertising purposes.
4. Transfers outside the EEA
Google, Meta, Microsoft and LinkedIn are contracted through their Irish entities, but processing on their infrastructure can involve transfers to the United States. Those transfers rely on the EU Commission's adequacy decision for the EU–US Data Privacy Framework where the recipient is certified under it, and otherwise on Standard Contractual Clauses under Art. 46 (2) (c) GDPR.
You can ask us for a copy of the safeguards that apply, using the contact details in section 1.
5. How long we keep it
We keep personal data only for as long as the purpose it was collected for requires, and after that only where a legal retention duty applies.
- Server log files: only as long as needed to operate the site securely and to investigate faults or abuse, then deleted or anonymised.
- Enquiries and the related correspondence: while we are in contact with you about your enquiry, and afterwards only for as long as it may still lead to a follow-up conversation.
- Data connected to a concluded transaction: for the period Cypriot commercial and tax law requires us to retain it.
- Newsletter subscriptions: until you unsubscribe.
- Consent records: for as long as we must be able to demonstrate that consent was given.
- Cookieless analytics: aggregate counts only — the daily hash cannot be traced back to a person at any point.
If you want to know how long we are holding a particular category of your data, ask us and we will tell you.
6. Cookies and consent
Our cookie banner offers the same three categories used throughout this policy:
- Necessary
- Required for the site to work — for example remembering your language and your cookie choice itself. Set on the basis of Art. 6 (1) (f) GDPR; these cannot be switched off.
- Analytics
- Google Analytics 4 (via Google Tag Manager) and Microsoft Clarity in its full mode. Only set once you have agreed.
- Marketing
- Google Ads, the Meta Pixel and the LinkedIn Insight Tag. Only set once you have agreed.
You can change or withdraw your choice at any time through the cookie banner; withdrawal does not affect the lawfulness of processing carried out beforehand. You can also block or delete cookies in your browser settings, though parts of the site may then not work as intended.
7. Your rights
Under the GDPR you have the right to:
- Access — obtain confirmation of whether we process your data, and a copy of it (Art. 15).
- Rectification — have inaccurate or incomplete data corrected (Art. 16).
- Erasure — have your data deleted where one of the grounds in Art. 17 applies.
- Restriction — require that we only store your data while a dispute about it is resolved (Art. 18).
- Data portability — receive the data you gave us in a structured, machine-readable format, or have it sent to another controller (Art. 20).
- Object — object at any time to processing based on our legitimate interests, and absolutely to processing for direct marketing (Art. 21).
- Withdraw consent — at any time, with effect for the future (Art. 7 (3)).
To exercise any of these, write to office@cyprusvipestates.com. We answer within one month; if a request is complex we may extend that by two further months and will tell you why.
You also have the right to complain to a supervisory authority. In Cyprus this is the Office of the Commissioner for Personal Data Protection, Iasonos 1, 1082 Nicosia (commissioner@dataprotection.gov.cy). You may also complain to the authority where you live or work.
8. Security
This site is served over TLS, so the content you send us is encrypted in transit — your browser shows “https://” and a padlock. We apply technical and organisational measures appropriate to the risk, and restrict access to enquiry data to the colleagues who need it to look after you.
9. Automated decision-making
We do not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22 GDPR. Where we use software to help sort or summarise enquiries, a person always decides what happens next.
10. Changes to this policy
We update this policy when our services or the legal requirements change. The current version always applies, and the date at the top tells you when it was last revised.
Questions about your data?
Write to office@cyprusvipestates.com or call +357 99 278 285. We are happy to explain anything in this policy in plain language.

