Privacy Policy
Last updated 10 August 2026
This policy explains what personal data Keltikos Software Ltd collects, why we collect it, who we share it with, and what rights you have. We are established in Cyprus, so we are regulated under the EU General Data Protection Regulation (GDPR) and Cyprus Law 125(I)/2018.
1. Who is responsible
The data controller is Keltikos Software Ltd, registered in Cyprus under registration number HE 496195, registered office Onisiforou Center, Floor 2, Neofytou Nikolaidi & Theodorou Kolokotroni, Agios Theodoros, 8011 Paphos, Cyprus. For anything in this policy, contact info@keltikos.com.
We are not required to appoint a Data Protection Officer, and have not appointed one. Privacy questions go to the address above and are handled by us directly.
2. What we collect and why
Visiting this website
This site is static. It sets no cookies, embeds nothing from third parties, and runs no analytics. Our hosting provider processes standard server and network information — such as IP address, user agent and requested URL — in order to deliver the site and to protect it from attack and abuse. Our lawful basis is our legitimate interest in operating a secure, working website (GDPR Art. 6(1)(f)).
Contacting us
If you email us we receive your address, your message, and anything you choose to include. We use it to answer you and to keep a record of the correspondence. Lawful basis: legitimate interest in responding to enquiries (Art. 6(1)(f)), or steps taken at your request before entering a contract (Art. 6(1)(b)).
Buying from us
When you purchase a subscription, licence or service we collect your name, email address, billing address, country, VAT number where relevant, and a record of what you bought. Payment card details go directly to our payment provider — we never receive or store them.
Lawful basis: performance of our contract with you (Art. 6(1)(b)) for account and delivery data, and legal obligation (Art. 6(1)(c)) for invoicing, VAT and accounting records.
Using our software
Where you use a hosted product, we process the account data and the content you put into it in order to provide the service, and we keep operational logs for security, debugging and abuse prevention. Lawful basis: performance of contract (Art. 6(1)(b)) and legitimate interest in service security (Art. 6(1)(f)).
Support
Support requests may include technical detail about your site or environment, and occasionally credentials you choose to share with us. Please send credentials only when asked, and change them afterwards. Lawful basis: performance of contract (Art. 6(1)(b)).
Marketing email
We only send product or marketing email to people who have asked for it, or to existing customers about products similar to what they already bought. Every such email has a one-click unsubscribe, and we act on it. Lawful basis: consent (Art. 6(1)(a)) or legitimate interest (Art. 6(1)(f)) as applicable.
3. Cookies and tracking
This website sets no cookies and uses no analytics, advertising or tracking technology. That is why you are not being asked to accept anything.
Products behind a login may use strictly necessary cookies to keep you signed in. If we ever add analytics or any non-essential cookie to this site, we will update this policy and ask for your consent first.
4. Who we share data with
We do not sell personal data and we do not share it for anyone else's marketing. We use a small number of service providers who process data on our behalf under contract:
| Provider | Purpose | Where |
|---|---|---|
| Cloudflare | Website hosting, CDN and security | EU / global |
| Stripe | Card payments and subscription billing | EU / United States |
| Revolut | Banking and payment processing | EU |
| Cloudflare (Email Routing) | Business email and correspondence | EU / global |
We may also disclose data where we are legally required to, or to establish or defend legal claims. If the business is ever sold or reorganised, data may transfer to the acquirer, who would remain bound by this policy.
5. International transfers
Some providers process data outside the European Economic Area, principally in the United States. Where that happens we rely on an adequacy decision where one applies — including certification under the EU–US Data Privacy Framework — or on the European Commission's Standard Contractual Clauses together with additional safeguards. You can ask us for details of the mechanism used for a specific provider.
6. How long we keep it
- Email correspondence — up to 3 years after our last exchange.
- Customer account data — for the life of the account, then up to 12 months.
- Invoices, tax and accounting records — 7 years, as Cyprus tax law requires.
- Hosted product content — available for export for 30 days after termination, then deleted.
- Security and server logs — typically 30 to 90 days.
- Marketing consent records — until you unsubscribe, plus a suppression record so we do not email you again.
7. Security
We take security seriously — it is part of what we do for a living. Data is encrypted in transit, access is limited to those who need it, and we apply the principle of least privilege to production systems. No system is perfectly secure, but where a breach is likely to result in a risk to your rights we will notify the Cyprus supervisory authority within 72 hours and tell you directly where the risk is high.
If you believe you have found a vulnerability in our software or systems, please tell us at info@keltikos.com. We welcome good-faith reports and will not pursue researchers who disclose responsibly.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where we have no overriding reason to keep it;
- restrict or object to processing, including direct marketing at any time;
- receive your data in a portable, machine-readable format;
- withdraw consent at any time, where we relied on consent;
- not be subject to solely automated decisions with legal or similarly significant effects — we do not make any.
Email info@keltikos.com and we will respond within one month. Exercising these rights is free; we may charge only where a request is manifestly unfounded or excessive.
9. When we act as a processor
When we build or support software for a client, we often handle personal data belonging to their users. In that situation the client is the controller and we act as a processor on their documented instructions. We enter into a data processing agreement covering confidentiality, security, sub-processors, assistance with data subject requests and deletion at the end of the engagement. If you are one of our clients and need a DPA, ask us.
10. Children
Our products are for businesses and adults. We do not knowingly collect personal data from children under 16. If you believe a child has given us data, tell us and we will delete it.
11. Changes to this policy
We will update this policy when our practices change — for example if we add analytics or a new sub-processor. The "last updated" date shows the current version, and we will notify customers directly of significant changes.
12. Contact and complaints
Privacy questions and requests: info@keltikos.com.
If you are unhappy with how we have handled your data, please raise it with us first — we would rather fix it. You also have the right to complain to the Cyprus supervisory authority:
Office of the Commissioner for Personal Data Protection
15 Kypranoros Street, 1061 Nicosia, Cyprus
www.dataprotection.gov.cy
If you live in another EU member state, you may instead complain to your own national data protection authority.