Legal
Privacy Policy
How we collect, process and protect personal data, and what your rights are in relation to it.
Version 1.0 · In effect from 1 September 2025
This policy describes the processing of personal data by AMSHA ALCYONE14 LTD, a private company limited by shares incorporated in Cyprus, whose registered office is at 16 Evangelistrias Street, Malema Court, 4th Floor, Office 41, 3031 Limassol, Cyprus (the "Company"), in accordance with Regulation (EU) 2016/679 (the "GDPR") and applicable law.
For any privacy matter, including the exercise of rights: hello@alcyone14.com.
Scope and roles of the parties. In relation to site visitors, enquirers and client representatives, the Company acts as data controller, and this policy applies in full.
In relation to personal data of our clients' own end users, processed within systems the Company develops and operates for them, the business client is the controller and the Company acts as processor on its behalf and on its documented instructions, subject to a data-processing agreement.
A data-subject request concerning data described in the Scope and roles of the parties clause shall be directed to the relevant business client; the Company shall assist that client in responding, as required by Article 28 GDPR.
When the Company is controller and when it is processor. The Company acts as controller in respect of the personal data of its own prospects, clients' representatives, correspondents and website visitors: the contact details of the people it deals with, the record of its dealings with them, enquiries submitted through this website, and the technical data generated when a person visits it. In that capacity it determines the purposes and means of the processing and answers directly to the data subject.
The Company acts as processor in respect of the personal data contained within a system it builds and operates for a business client: that client's own customers, patients, leads, employees and counterparties, and the content of communications with them. In that capacity the business client is the controller, it determines why and how the data is processed, and the Company acts only on its documented instructions.
The distinction matters to a data subject because it determines who must answer a request. A request concerning data held in a client's system is a matter for that client, and the Company will say so and pass the request on rather than answer it itself. A request concerning the Company's own dealings is answered by the Company.
Where the Company acts as processor it does so under a data-processing agreement containing the terms required by Article 28 GDPR, including the obligation to process only on instructions, to impose confidentiality on its personnel, to implement the measures required by Article 32, to engage a further processor only under equivalent terms, to assist the controller with data-subject requests and with its obligations under Articles 32 to 36, and to delete or return the data at the end of the engagement.
Categories of data collected. Data provided at the initiative of the enquirer: name, telephone number, email address and the content of the enquiry. The consent wording approved by the enquirer is retained verbatim as evidence of consent.
Technical and usage data collected through cookies and similar technologies, to the extent of the preferences set by the user in the cookie-management interface. Non-essential cookies are not loaded in the absence of consent.
From business clients: business contact and billing details, including legal name, registration or tax identification number, address and contact person — for the purposes of invoicing and managing the engagement.
The Company does not knowingly collect special categories of personal data within the meaning of Article 9 GDPR, and does not direct its services to minors.
Purposes and legal bases. The Company processes personal data in order to provide the Services and to manage the engagement with each client, and the lawful basis for that processing is the performance of a contract to which the data subject is party, or the taking of steps at their request before entering into one, under Article 6(1)(b) GDPR. That same basis covers the administration of billing, the issuing of invoices and the correspondence which necessarily accompanies an engagement.
The Company further processes personal data in order to respond to enquiries, to operate and secure this website, to protect its systems against misuse and automated abuse, and to establish, exercise or defend legal claims. The lawful basis is the legitimate interests of the Company under Article 6(1)(f) GDPR, each such interest having been balanced against the rights and freedoms of the data subject before the processing was undertaken, and the outcome of that balancing being available on request.
Non-essential cookies and marketing communications are processed on the basis of consent under Article 6(1)(a) GDPR. Consent is sought before any such processing begins, is recorded, and may be withdrawn at any time and as easily as it was given, whereupon the processing ceases; withdrawal does not affect the lawfulness of processing carried out in reliance on the consent before it was withdrawn.
Where the Company is obliged by accounting, tax or other regulatory law to retain or produce personal data, the lawful basis is compliance with a legal obligation to which the Company is subject, under Article 6(1)(c) GDPR, and the data is retained for the period that law prescribes irrespective of any request to erase it.
Payment-instrument data. Card details are provided directly to Stripe Payments Europe, Ltd. and its group companies, on payment pages secured by it and subject to the PCI-DSS standard.
Payment-instrument details neither pass through nor are stored on the Company's servers in any form. The Company receives transaction data only, including payment status and the last four digits.
Recipients and subprocessors. The Company uses a limited set of infrastructure and service providers which process data on its behalf, subject to data-processing agreements and to confidentiality and security undertakings, namely: Stripe, for payment processing, billing and the generation of billing documents; Supabase, for databases and backend infrastructure; Vercel, for website hosting and content delivery; Twilio, for WhatsApp channel communication and messaging; and Resend, for transactional email delivery.
Limited error-monitoring and usage-analysis services are also used. A complete and current list of subprocessors is available on request at the address at the head of this document.
The Company does not sell personal data and does not transfer it to third parties for their own marketing purposes.
Data may be disclosed to a competent authority where required by law or judicial order.
Transfers outside the European Economic Area. Certain subprocessors process data in countries outside the European Economic Area, including the United States.
Any such transfer is made on the basis of a lawful transfer mechanism under Chapter V GDPR — an adequacy decision of the European Commission, or Standard Contractual Clauses together with supplementary measures where required.
A copy of the relevant transfer mechanisms is available on request at the address at the head of this document.
Sources, accuracy and derived data. Personal data processed by the Company is obtained from the data subject directly, from the business client on whose behalf the Company acts, from the data subject's interaction with a system operated by the Company, and from publicly available sources where the Company verifies business details. Where data originates with a business client, that client warrants to the Company that it has a lawful basis for the disclosure.
The Company relies upon the accuracy of personal data as supplied to it and does not independently verify it. A data subject who considers that data held about them is inaccurate or incomplete may say so, and the Company shall correct or complete it, or shall pass the request to the business client which controls it, without undue delay.
The Company derives aggregated and statistical information from the data it processes, including counts, volumes, response times, error rates and usage patterns. Where such information has been aggregated or anonymised so that no data subject is identifiable from it, and cannot reasonably be re-identified, it is no longer personal data, and the Company uses it to operate, secure, measure and improve its services without restriction under this policy.
The Company does not sell personal data, does not disclose it for the independent marketing purposes of any third party, and does not combine data received from one business client with that received from another save in aggregated or anonymised form as described above.
Marketing and communications. The Company sends commercial communications to a business contact only where that person has requested them, has given a business card or enquiry in circumstances where such communication is expected, or where the communication concerns services similar to those already discussed and the recipient was given the opportunity to object when their details were collected. Every such communication carries a means of unsubscribing, and an unsubscribe request is acted upon without delay and without asking why.
The Company does not send commercial communications to the customers of its business clients on its own account. Where a system built by the Company sends a message to such a person, it does so on the client's instruction and in the client's name; the client is the controller of that communication and is responsible for its lawful basis, its consent record, and its unsubscribe handling.
Operational messages are not marketing. A message which confirms an appointment, notifies an invoice, reports an incident, answers a support request or is otherwise necessary to perform the engagement is sent on the basis of contractual necessity and continues to be sent to a person who has unsubscribed from marketing.
The Company does not use personal data for advertising, does not build advertising profiles, does not sell or rent contact lists, and does not enrich its records by purchasing personal data from a data broker.
Retention periods. Personal data is kept only for as long as the purpose for which it was collected requires. An enquiry or a lead which does not become an engagement is retained for up to twenty-four months from the last contact and is then deleted or irreversibly anonymised, that period reflecting the ordinary length of a business conversation in this market rather than an intention to retain indefinitely.
The personal data within a client's system is retained for the term of the engagement, and upon its termination the export, deletion and backup-purge provisions of the Terms of Service apply: the data is available for export for thirty days, is then removed from production environments, and is purged from backups on a rolling basis not exceeding ninety days thereafter.
Billing records, invoices and accounting documents are retained for the period which applicable tax and accounting law requires, which is longer than the operational need for them and is not shortened by a request for erasure. Records of cookie consent are retained for a period sufficient to prove that consent was given, and no longer.
Children. The Company's services are directed at businesses and are not intended for children. The Company does not knowingly collect personal data from a child in its capacity as controller, and this website is not designed to appeal to or be used by one.
Where a system built by the Company processes the data of a person under the age of majority — as may occur in a clinic, a school or a service business dealing with families — the business client is the controller of that data and is responsible for establishing the lawful basis, for obtaining consent from a holder of parental responsibility where one is required, and for satisfying itself that the age threshold applicable in its own jurisdiction is met. Cyprus sets the age of consent for information-society services at fourteen.
Where the Company becomes aware that it holds, as controller, data of a child collected without a proper basis, it deletes that data without undue delay.
Security. The Company implements appropriate technical and organisational measures under Article 32 GDPR, including encryption in transit and at rest, role- and need-based access controls, separation between client environments, backups, and continuous logging and monitoring.
In the event of a security incident presenting a risk to the rights and freedoms of data subjects, the Company shall notify the competent supervisory authority within 72 hours and inform the relevant controllers or data subjects, as required by Articles 33-34 GDPR.
Data-subject rights. Subject to the conditions of applicable law, data subjects have the following rights: access; rectification; erasure; restriction of processing; data portability; objection to processing based on legitimate interests; and withdrawal of consent at any time.
Requests should be addressed to hello@alcyone14.com. The Company shall respond within 30 days; in complex cases this period may be extended in accordance with law, on notice to the requester.
A data subject may lodge a complaint with the competent supervisory authority — in Cyprus, the Commissioner for Personal Data Protection — or with the supervisory authority of their place of residence.
The Company does not take decisions based solely on automated processing, including profiling, which produce legal effects concerning the data subject or similarly significantly affect them.
Automated processing and artificial intelligence. Certain features of the systems operated by the Company use machine-learning or large-language models in order to classify, summarise, draft, translate or route content, which may include personal data contained in messages, tickets, documents and business records. Where the Company acts as processor, it does so only on the documented instructions of the client which is the controller of that data.
Content transmitted to a model provider is sent only to providers contractually bound not to use it to train, fine-tune or otherwise improve their models, and the Company's integrations are configured to that effect. Such content is not used by the Company to train any model of its own.
No decision producing legal effects concerning a data subject, or similarly significantly affecting them, is taken solely by automated means. Output is presented for human review and any consequent decision is taken by a person.
A data subject who wishes to understand whether their personal data has been processed in this way may make a request under the rights clause below, and the Company shall respond in accordance with it.
Legal claims, enforcement and disclosure. The Company may process personal data where necessary to establish, exercise or defend a legal claim, including in correspondence with a client's advisers, in recovery of a debt, in response to a chargeback, and in proceedings before a court or tribunal. The lawful basis for that processing is the Company's legitimate interest in the conduct of its own affairs, and such data is retained for as long as the claim or the limitation period applicable to it subsists.
The Company discloses personal data to a public authority only where it is legally obliged to do so, and where it is permitted to do so it will tell the affected controller or data subject unless prohibited from doing so by law or by the terms of the demand. The Company does not grant any authority direct or unfettered access to any system it operates.
Where the Company is party to a merger, an acquisition, a reorganisation or a sale of assets, personal data may be transferred as part of that transaction, subject to the recipient being bound to observe this policy or a policy no less protective, and subject to affected data subjects being informed.
The Company maintains a record of its processing activities as required by Article 30 GDPR, and makes that record available to a supervisory authority on request.
Cookies. The website uses essential cookies necessary for its operation and, subject to consent, analytics and marketing cookies.
Measurement services are not activated unless consent has been given. Consent may be changed or withdrawn at any time through the 'Cookie settings' link in the footer of every page.
Complaints and supervisory authority. A data subject who considers that the processing of their personal data infringes the GDPR may lodge a complaint with the Office of the Commissioner for Personal Data Protection of Cyprus, being the Company's lead supervisory authority, or with the supervisory authority of the member state of their habitual residence or place of work.
The Company asks, without prejudice to that right, to be given the opportunity to address the matter first, and undertakes to respond substantively to any complaint addressed to it within thirty days of receipt.
The Company has not appointed a Data Protection Officer, its processing not being of a kind which requires one under Article 37 GDPR, and enquiries should accordingly be addressed to the contact point stated in this policy.
Governing law. The Company is incorporated in Cyprus, and its processing is governed by the GDPR together with the Cypriot law supplementing it, Law 125(I)/2018. The competent supervisory authority is the Commissioner for Personal Data Protection of Cyprus.
Clients of the Company may be subject to further laws in their own jurisdiction, including the Israeli Protection of Privacy Law and Amendment 13 thereto. Those obligations rest with them as the controller of their database; the Company acts as a processor on their behalf in accordance with the engagement agreement.
Policy updates. This policy is updated from time to time. The binding version is that published on this page, with its effective date stated at the top. Notice of material changes will be given in advance through customary channels.