GDPR

Last updated: December 2, 2025

1. Introduction

Sabbianco Properties is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679. This document explains how we comply with GDPR requirements and your rights under this regulation.

2. Data Controller

Sabbianco Properties acts as the data controller for the personal data we collect and process. Our contact details are:

  • Company Name: Sabbianco Properties Ltd.
  • Address: 18 Georgiou A Street, Potamos Germasogeias, 4047, Limassol, Cyprus
  • Email: [email protected]
  • Phone: +357 96 112112

3. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: You have given clear consent for us to process your personal data for specific purposes
  • Contract: Processing is necessary for a contract we have with you, or because you have asked us to take specific steps before entering into a contract
  • Legal Obligation: Processing is necessary for us to comply with the law
  • Legitimate Interests: Processing is necessary for our legitimate interests or the legitimate interests of a third party, unless there is a good reason to protect your personal data which overrides those legitimate interests

4. Your Rights Under GDPR

Under GDPR, you have the following rights:

4.1 Right to Access

You have the right to request copies of your personal data. We may charge a small fee for this service.

4.2 Right to Rectification

You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.

4.3 Right to Erasure

You have the right to request that we erase your personal data, under certain conditions.

4.4 Right to Restrict Processing

You have the right to request that we restrict the processing of your personal data, under certain conditions.

4.5 Right to Object to Processing

You have the right to object to our processing of your personal data, under certain conditions.

4.6 Right to Data Portability

You have the right to request that we transfer the data we have collected to another organization, or directly to you, under certain conditions.

4.7 Right to Withdraw Consent

Where we rely on consent to process your personal data, you have the right to withdraw that consent at any time.

5. How to Exercise Your Rights

To exercise any of your rights, please contact us at:

  • Email: [email protected]
  • Phone: +357 96 112112
  • Post: Data Protection Officer, Sabbianco Properties, 18 Georgiou A Street, Potamos Germasogeias, 4047, Limassol, Cyprus

We will respond to your request within one month. If your request is complex or you have made multiple requests, we may extend this period by two further months.

6. Data Protection Principles

We process personal data in accordance with the following GDPR principles:

  • Lawfulness, Fairness, and Transparency: We process data lawfully, fairly, and in a transparent manner
  • Purpose Limitation: We collect data for specified, explicit, and legitimate purposes
  • Data Minimization: We only collect data that is adequate, relevant, and limited to what is necessary
  • Accuracy: We keep personal data accurate and up to date
  • Storage Limitation: We keep personal data only for as long as necessary
  • Integrity and Confidentiality: We process data securely
  • Accountability: We are responsible for and can demonstrate compliance with these principles

7. Data Security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:

  • Encryption of personal data
  • Regular security assessments
  • Access controls and authentication
  • Regular backups
  • Staff training on data protection
  • Incident response procedures

8. Data Breach Notification

In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.

9. International Data Transfers

When we transfer personal data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Transfers to countries with an adequacy decision
  • Binding Corporate Rules

10. Data Retention

We retain personal data for different periods depending on the purpose:

  • Customer Data: 7 years after the last transaction (for legal and tax purposes)
  • Marketing Data: Until you withdraw consent or 3 years of inactivity
  • Website Analytics: 26 months
  • CCTV Footage: 30 days (if applicable)

11. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you.

12. Children's Privacy

Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children under 16. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.

13. Complaints

If you believe we have not complied with GDPR, you have the right to lodge a complaint with a supervisory authority. In Cyprus, the supervisory authority is:

  • Office of the Commissioner for Personal Data Protection
  • Address: 1 Iasonos Street, 1082 Nicosia, Cyprus
  • Phone: +357 22 818 456
  • Email: [email protected]
  • Website: www.dataprotection.gov.cy

14. Updates to This Policy

We may update this GDPR compliance document from time to time. We will notify you of any significant changes by posting the new document on our website and updating the "Last updated" date.

15. Contact Us

If you have any questions about our GDPR compliance or wish to exercise your rights, please contact:

  • Data Protection Officer
  • Email: [email protected]
  • Phone: +357 96 112112
  • Address: 18 Georgiou A Street, Potamos Germasogeias, 4047, Limassol, Cyprus