Legal

Privacy Policy

This Privacy Policy explains how Geofra LTD (“Geofra”, “we”, “us”) collects, uses, stores and protects personal data when you visit geofra.com or contact us by phone, email, or in person. It is issued in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”) and the Cyprus Law 125(I)/2018.

1. Data Controller

The data controller is:

2. Personal Data We Collect

We collect only the data needed to respond to your enquiries, fulfil orders, deliver materials, and comply with our legal obligations.

CategoryExamplesSource
Contact dataname, email, phonecontact form, phone, email, in-store
Order dataproducts, quantities, delivery address, invoice detailsprovided by you when ordering
Financial dataVAT number, bank transfer referenceprovided for invoicing
Technical dataIP address, browser, device, pages visitedcollected via Google Analytics, only with your consent
Language preferenceEN / EL / RU choicestored in browser localStorage

3. Purposes & Legal Bases (Art. 6 GDPR)

PurposeLegal Basis
Respond to enquiriesArt. 6(1)(b) — pre-contractual steps
Process orders, prepare quotes, deliver materialsArt. 6(1)(b) — contract performance
Issue invoices, keep accounting recordsArt. 6(1)(c) — legal obligation (Cyprus tax law)
Site traffic measurement (Google Analytics)Art. 6(1)(a) — consent (via cookie banner)
Defending legal claimsArt. 6(1)(f) — legitimate interest

4. Retention Periods

5. Recipients of Your Data

We do not sell your data. We share it only with:

6. International Transfers

Google Analytics may transfer data to the United States. Such transfers rely on the EU–US Data Privacy Framework and Standard Contractual Clauses approved by the European Commission.

7. Your Rights (Art. 15–22 GDPR)

You have the right to:

To exercise any right, email info@geofra.com. We respond within 30 days.

8. Security

We use reasonable technical and organisational measures (TLS encryption, access controls, secure invoicing software) to protect your data. No system is perfectly secure; we ask you not to send sensitive data (e.g. ID copies) through unencrypted email unless requested.

9. Children

The website is not intended for children under 16. We do not knowingly collect data from minors. If you believe a child has provided us data, contact us and we will delete it.

10. Changes to This Policy

We may update this policy when our practices change or when the law requires. The “Last updated” date at the top reflects the most recent revision. Material changes will be highlighted on the site.