Legal
Privacy Policy
Last updated 12 September 2026.
1. Data controller
Cyprus Automotive Growth Agency ("CAGA", "we", "us") is the data controller for the personal data described in this policy, within the meaning of Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR") and the Cyprus Law Providing for the Protection of Natural Persons with Regard to the Processing of Personal Data (Law 125(I)/2018).
- Registered name: Cyprus Automotive Growth Agency
- Company registration number: to be confirmed
- VAT number: to be confirmed
- Registered address: Limassol, Cyprus
- Data protection contact: to be confirmed
2. Personal data we collect
- Enquiry and growth audit data you submit: name, business name, email address, phone or WhatsApp number, website, social handle, business type, budget range, goals and the content of your message.
- Campaign attribution data: the page you submitted from, the referring website and any UTM parameters in the link you arrived through.
- Analytics and advertising data, only if you accept non-essential cookies: pages viewed, approximate location derived from a truncated IP address, device and browser type, and interactions such as form submissions and WhatsApp clicks. See our Cookie Policy.
- Client relationship data if you engage us: contact details, contractual documents, invoices and campaign performance records.
We apply data minimisation and do not ask for information we do not need. We do not knowingly collect data from children and do not process special categories of personal data.
3. Purposes and legal bases
- Responding to your enquiry and preparing a growth audit or proposal — legal basis: your consent, given when you tick the consent box and submit the form (Article 6(1)(a) GDPR), and steps taken at your request prior to entering a contract (Article 6(1)(b)).
- Providing and administering our services to clients — performance of a contract (Article 6(1)(b)).
- Accounting, tax and record keeping — compliance with a legal obligation under Cyprus law (Article 6(1)(c)).
- Securing our website and preventing form abuse or spam — our legitimate interests (Article 6(1)(f)).
- Analytics and advertising measurement — your consent (Article 6(1)(a)), which you may withdraw at any time.
4. Recipients and processors
We do not sell your personal data. We share it only with service providers acting as processors under written agreements that meet Article 28 GDPR:
- Website hosting and database storage (managed cloud infrastructure).
- Email and communication tools used to reply to you.
- Google Analytics, for website measurement, where you have consented.
- Meta (Facebook/Instagram) advertising measurement, where you have consented.
An up-to-date list of processors is available on request from to be confirmed.
5. International transfers
Some providers, including Google and Meta, may process data outside the European Economic Area, primarily in the United States. Where that happens we rely on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with the supplementary measures those providers apply. You may request further information about these safeguards.
6. Retention
- Enquiries and audit requests: 24 months from the last contact, unless you become a client.
- Client records, contracts and invoices: 7 years after the end of the engagement, to meet Cyprus tax and accounting law.
- Analytics data: retained according to the retention period set in the analytics tool, and no longer than 26 months.
Data is deleted or anonymised at the end of the applicable period.
7. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and receive a copy;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing, including processing based on legitimate interests;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, without affecting processing already carried out;
- not be subject to decisions based solely on automated processing — we do not carry out such decision-making.
To exercise any right, email to be confirmed. We respond within one month, as required by Article 12 GDPR. Requests are free of charge unless they are manifestly excessive.
8. Security
Enquiries are stored in a managed database protected by row-level access rules, with access limited to authorised personnel. All traffic to this website is encrypted with HTTPS. Forms are protected against automated abuse. In the event of a personal data breach likely to result in a risk to your rights, we notify the Commissioner within 72 hours and inform affected individuals where required by Articles 33 and 34 GDPR.
9. Complaints
If you believe your data has been handled unlawfully, please contact us first at to be confirmed. You also have the right to lodge a complaint with the Office of the Commissioner for Personal Data Protection, 15 Kypranoros Street, 1061 Nicosia, Cyprus (https://www.dataprotection.gov.cy).
10. Changes
We may update this policy to reflect changes in our services or the law. The date at the top of this page shows when it was last revised.
