Privacy Policy
Last Updated: July 2026
General
OMNITOUCH CYPRUS LTD, hereinafter “the “Company”, is committed to privacy and secure processing of the Personal data it maintains for its customers and collaborators, in an open and transparent manner. It is also committed to the collection and processing of this Personal data in full compliance with the General Regulation on the Protection of Personal Data of the European Union (Regulation 2016/679), hereafter referred to as "the Regulation", and the legislation in force in Cyprus, providing for the Protection of Natural Persons with regard to
the Processing of Personal Data and for the Free Movement of such Data of 2018 (Law 125(I)/2018), that govern the collection and processing of Personal Data of Individuals.
Thus, we have developed this Privacy Policy that provides information for the collection, use, disclosure, transfer and storage of Personal data by the Company.
Our Services (the “Services”) might include, but are not limited to Inbound / Outbound Call Center, Web Support, Interactive Voice Response, and Back Office Support.
Definitions
“Personal data” means any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
“Processing” means any operation or set of operations which is performed on Personal data or on sets of Personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of Personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
“Processor” means a natural or legal person, public authority, agency or other body which processes Personal data on behalf of the controller.
Our role under the Regulation
Under the Regulation, the Company in most cases operates as a Data Controller or Data Processor for the Personal data it maintains and processes.
As a Data Controller, the Company, processes Personal data for the purposes presented in this Policy. In such situations the Company decides for the means of processing.
As a Data Processor, the Company, acting on behalf of its Clients (Data Controller), may process your Personal Data for the purpose of servicing those Clients. The nature and categories of your Personal Data, and the purposes of the processing are determined by the Data Controller and will vary depending on both their instructions and the Services provided by the Company.
If you are an individual who interacts with a customer of the Company using our Services, that customer is the Data Controller of your Personal data and you should contact them directly for assistance with any requests or inquires to your Personal data. The Company will work hard to ensure that its clients are fully GDPR compliant.
How are Personal Data Collected
This privacy policy applies to Personal Data we collect:
• directly from you when we collaborate, or you use our Services;
• through third parties in the standard course of the business we do in order to provide you with the service you requested;
• through our Clients while providing our Services;
• through our website, through cookies and/or online forms used to contact us or to apply for an employment opportunity;
• when you subscribe to our Newsletter
Types of Personal data collected
We collect and use several types of Personal data, including Personal data by which subjects may be identified. Such Personal data might include your first and surname, identity number, e-mail address, address and post code, telephone contact number and training records, employment data, financial and/or banking data, photographs and videos.
In cases where the Company acts as a Data Processor, the categories of Personal data processed depend on the relevant Client, the scope of the Services provided and the documented instructions of the respective Data Controller.
Where the Company provides call center and /or related services, Personal data may also include call recordings, SMS messages and quality monitoring records created in the course of providing the said services.
Where the Company acts as a Data Processor, the categories of Personal data processed depend on the relevant Client, the scope of the Services provided and the documented instructions of the respective Data Controller.
Further to other media of collection, we collect and use data, on or through our website, including but not limited to:
• Data that you provide by filling in forms, at the time of first contact with us;
• Data when you report a problem related to our website or service;
• Employment data when you fill out our “Join us” online form on our website or contact us through email for an employment opportunity;
• Records and copies of your correspondence (including e-mail addresses);
Purposes for which we use your Personal data
In general, we might process your Personal data for the following purposes:
• Provision of services: to provide you with data, products or services that you request from us;
• Customer management: to manage your account, to provide you with customer support, notices about your account and information about changes and/or updates to
any products or services we offer to you;
• Employment opportunities: to communicate with you in respond to your application or inquiry for an employment opportunity;
• Quality assurance: to analyze and assess your use of our services;
• Functionality and security: to detect, prevent, and respond to actual or potential fraud, illegal activities, or intellectual property infringement;
• Compliance: to enforce our terms and conditions and to comply with our legal obligations as these derive from the applicable laws or our regulators;
• For any other purpose with your consent;
Disclosure of your Personal data
We do not share your Personal data with third parties except in cases as indicated below:
• Affiliates. We share Personal data with our subsidiaries and affiliates to the extent this is necessary for the purposes of provision of services, customer management, customization of content, advertising (if you have consented), security and compliance, or to the extent you have provided your consent.
• Service providers. To our authorized service providers that perform certain services on our behalf, including for purposes of provision of the services you requested from us, customer management and security. These service providers may have access to Personal data needed to perform their functions but are not permitted to share or use such data for any other purposes. We have taken all reasonable steps to ensure that they comply with the current data protection regulations.
• Services provided by the Company. While the Company provides services on behalf of a Client, Personal data is processed in the course of providing those Services, including call recordings and related quality monitoring records where applicable, may be disclosed to that Client where necessary for the provision of the Services, quality assurance, complaint handling, contractual compliance or otherwise in accordance with the applicable contractual arrangements and the documented instructions of the Data Controller.
• Legal successors. To a buyer or other successor in the event of a merger, divestiture, restructuring, reorganization, dissolution or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation or similar proceeding, in which Personal data held by is among the assets transferred. Should such a sale or transfer occur, we will use reasonable efforts to try to ensure that the entity to which we transfer your Personal data uses it in a manner that is consistent with this privacy policy.
We also disclose your Personal data to other third parties, including official authorities, courts, or other public bodies:
• In response to a subpoena or similar investigative demand, a court order or other judicial or administrative order, or a request for cooperation from a law enforcement or other government agency; to establish or exercise our legal rights; to defend against legal claims; to comply with applicable law or cooperate with law enforcement, government or regulatory agencies; or to enforce our Website terms and conditions or other agreements or policies; or as otherwise required by law (including responding to any government or regulatory request). In such cases, we may raise or waive any legal objection or right available to us, in our sole discretion
• To the extent a disclosure is necessary in connection with efforts to investigate, prevent, report or take other action regarding illegal activity, suspected fraud or other wrongdoing; to protect and defend the rights, property or safety of our company, our users, our employees, or others; to maintain and protect the security and integrity of our Website or infrastructure.
We may disclose aggregated Data about subjects, and Data that does not identify any individual, without restriction. In particular, we may transfer non-Personal data and process it outside your country of residence. We may combine non-Personal data we collect with additional non-Personal data collected from other sources. We also may share aggregated data with third parties, including advisors, advertisers and investors, for the purpose of conducting general business analysis.
Upon request we can provide the list of entities to which we have shared your data.
How we store your Personal data
The Data that we collect about you, including Personal data, is stored and processed within the European Union. Where processing takes place outside the EU, the relevant provisions of the GDPR are adhered to.
Retention and deletion of Personal data
The period for which we keep your Personal data that is necessary for compliance and legal enforcement purposes varies and depends on the nature of our legal obligations and claims in the individual case.
To the extent we have collected your Personal data for the purposes mentioned in Section 6, we keep your Personal data for as long as you have an active relationship with us, as needed to provide you with our respective Services and in compliance with relevant laws of Cyprus.In the case that we act as a Data Processor and process your Personal data on behalf of a Data Controller, we keep your Personal data for the period determined by the Data Controller which vary depending on the Data Controller and the Services provided to the Data Controller by the Company .
The period for which we retain Personal data varies depending on the purpose of the processing, our legal obligations and the nature of the Services provided.
For further information regarding specific retention period please contact us at dpo@omnitouch.com.cy
Legal basis for collection, use and disclosure of your Personal data
There are different legal bases that we rely on to collect, use and disclose your Personal data, namely:
• Consent: We will rely on your consent to use (i) your Personal data for marketing and advertising purposes; (ii) your Personal data for other purposes when we ask for your consent and for which the purpose of the process does not relate to the Services, we offer to you.
• Performance of contract: The use of your Personal data for purposes of providing the Services, customer management and functionality and security as described above is necessary to perform the Services provided to you under our term and conditions and any other contract that you have with us.
• Compliance with legal obligation: We are permitted to use your Personal data in to the extent this is required to comply with a legal obligation to which we are subject.
• Protection of your vital interests: The processing of your Personal data is necessary to protect your vital interests, if you are physically or legally incapable of giving consent.
• Protection of our legitimate interests: The processing of your Personal data is necessary for the purposes of the legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal data.
How we protect the security of your Personal data
We take appropriate security technical and organisational measures (including physical, electronic and procedural measures) to safeguard your Personal data from unauthorized access, unlawful use, intervention, modification or disclosure under the requirements of the Regulation. For example, only authorized employees are permitted to access Personal data, and they may do so only for permitted business functions. In addition, we have trained our employees on how to handle, manage and process Personal data, applied upgraded technical measures and transformed our policies and procedures in a way that will comply with the General Data Protection Regulation.
Children’s use of the services
Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal information, we will take steps to delete such information. If you become aware that a child has provided us with personal information, please contact us at the address listed below.
Automated decision-making, including profiling
We reserve the right to use automated decision-making in the following cases: When deemed necessary to provide services to you, with your written, express consent, and if the appropriate measures have been taken to safeguard your rights.
Choices about how we collect, use and disclose your Personal data
We strive to provide you with choices regarding the Personal data you provide to us. You can choose not to provide us with certain Personal data, but that may result in you being unable to use certain Services.
If you provided Personal data, you may terminate your relationship with us at any time as per the provision of the between us agreement or engagement. If you choose to do so, your Personal data will be deleted in accordance with our retention policy.
Your rights
Subject to the provisions of the General Data Protection Regulation, you have the following rights in regard to your Personal data: (Please note, these rights are not absolute and in some
cases, they are subjected to conditions as defined by law)
• Right of Access – You have the right to access your own Personal data, as well as the right to request a copy of your personal data that is maintained and processed by our Company.
• Right of Rectification - You have the right to request the correction of any incomplete and / or inaccurate Personal data we hold for you.
• Right to Erasure - You have the right to request the deletion of Personal data only if one of the following reasons is true:
(i) Personal data are no longer necessary in relation to the purposes for which they were collected or processed.
(ii) If the processing is based on your consent and you have withdrawn this consent (on which processing is based) in accordance with Articles 6.1.a and 9.2.a of the
Regulation and if no other legal basis, for processing, applies.
(iii)If you object to processing in accordance with Article 21.1 of the Regulation and there are no compelling and legitimate reasons for processing
(iv)If Personal data have been processed illegally.
(v) If Personal data should be deleted in compliance with a legal obligation under Union law to which our Company is subject to.
(vi)If the Personal data have been collected in relation to the provision of referred to in Article 8.1 of the Regulation.
• Right to Object - You have the right to oppose the processing of your Personal data at any time and for reasons related to a specific situation, unless there are compelling legitimate reasons for processing that override your interests, rights and freedoms.
• Right to Restriction of Processing - You reserve the right to request the restriction of processing on your Personal data so that we may no longer process the specific Datauntil the restriction is lifted (for example, the data have been corrected).
• Right to Data Portability - You have the right to request the transfer of your Personal data, that you have provided to our Company. These data will be given to you in a format that is structured, widely used and machine readable and, in certain cases you may also have the right to request for us to send the Data to another organization, provided that such a transfer is technically feasible.
• Right to Object and Automated Individual Decision-Making (Including Profiling) - You have the right to request that we do not make any decision, regarding you, solely on the basis of automated processing, including profiling, only in the case that this decision has legal or significant consequences on you.
If you have any questions about the kind of Personal data we keep for you or if you want to exercise any of your Personal data rights, please send a written request to the email dpo@omnitouch.com.cy or to the postal address provided in this Privacy Policy. However, we reserve the right to reject any requests for access or for imposing restrictions or other claims
if required or permitted by the law.
Changes to our privacy policy
We may modify or revise our privacy policy from time to time. Although we may attempt to notify you when major changes are made to this privacy policy, you are expected to periodically review the most up-to-date version found at our website https://omnitouch.com.cy/ so you are aware of any changes, as they are binding on you.
If we change anything in our privacy policy, the date of change will be reflected in the “last modified date” below. You agree that you will periodically review this privacy policy and refresh the page when doing so. You agree to note the date of the last revision to our privacy policy. If the “last modified” date is unchanged from the last time you reviewed our privacy policy, then it is unchanged. On the other hand, if the date has changed, then there have been changes, and you agree to re-review our privacy policy, and you agree to the new ones.
By continuing to use the Website, subsequent to us making available an amended version of our privacy policy in a way that you can easily take notice of it, you thereby consent to such
amendment.
No rights of third parties
This privacy policy does not create rights enforceable by third parties or require disclosure of any Personal data relating to users of the Website.
No error free performance
We do not guarantee error-free performance under this privacy policy. We will use reasonable efforts to comply with this privacy policy and will take prompt corrective action when we learn
of any failure to comply with our privacy policy. We shall not be liable for any incidental, consequential or punitive damages relating to this privacy policy.
Contact information
If you have any questions about this privacy policy or our Data-handling practices, please contact us at dpo@omnitouch.com.cy
You may also contact us at:
OMNITOUCH CYPRUS LTD
1 Megalou Alexandrou 2235 Latsia, Nicosia, Cyprus
Submission of a Complaint:
If you feel that your concerns in regard to the use of your Personal data or any of your data protection rights have not been addressed by us, you have the right to contact us at dpo@omnitouch.com.cy and submit a complaint.
You also have the right to submit a complaint with the Personal Data Protection Commissioner’s Office at http://www.dataprotection.gov.cy.
Last Updated July 2026