Privacy Policy
Last updated: 6 August 2026. Version 2.0.
This policy explains what personal data Elicon collects through elicon.io, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written to satisfy Articles 13 and 14 of the General Data Protection Regulation (EU) 2016/679 (GDPR) as applied in the Republic of Cyprus, together with the Cyprus Protection of Natural Persons with Regard to the Processing of Personal Data and for the Free Movement of Such Data Law of 2018 (Law 125(I)/2018).
We have tried to write it in plain language. Where a term has a specific legal meaning under the GDPR — "controller", "processor", "personal data", "processing" — it carries that meaning here.
1. Who we are
Elicon ("Elicon", "we", "us", "our") is a software studio established in the Republic of Cyprus and is the data controller for the personal data described in this policy.
- Website: elicon.io
- Contact for privacy matters: [email protected]
We have not appointed a Data Protection Officer, because we are not required to under Article 37 GDPR: our core activities do not consist of large-scale regular and systematic monitoring of individuals, nor of large-scale processing of special categories of data. Privacy enquiries are handled at the email address above.
2. Scope of this policy
This policy covers personal data processed through:
- the elicon.io website, including the enquiry form;
- email correspondence with us at addresses published on this site;
- our web server's access logs.
It does not cover personal data we process on behalf of our clients when delivering services. In those engagements the client is normally the controller and Elicon acts as a processor under a separate written agreement, including a data processing agreement where Article 28 GDPR requires one. Section 12 says more about this.
It also does not cover third-party websites we link to, which have their own policies.
3. What we collect, and why
3.1 Information you give us through the enquiry form
When you submit the enquiry form on this site, we process:
| Field | Required | Why we need it |
|---|---|---|
| Name | Yes | To address you correctly in our reply |
| Email address | Yes | To reply to you; it is the only channel we use |
| Company | No | To understand the context of your enquiry |
| Message | Yes | To understand what you are asking for |
| Project stage | Yes | To assess whether we are a fit |
| Budget indication | Yes | To assess whether we are a fit |
| Timeline | Yes | To assess whether we can meet it |
The form also contains a hidden field that is invisible to human visitors and is used solely to detect automated spam submissions. If it is filled in, the submission is rejected and nothing is sent to us.
Please do not include special categories of personal data (Article 9 GDPR — health data, biometric data, political opinions, religious beliefs, trade union membership, sexual orientation, and similar), or other people's personal data, in the free-text message field. We do not need it to answer an enquiry.
3.2 Information we collect automatically
Web server access logs. Our web server records standard technical information about requests: IP address, date and time, requested URL, HTTP status code, referrer and user agent string. This is ordinary server operation and is used for security, abuse prevention and diagnosing faults.
Short-term rate limiting. To prevent abuse of the enquiry form, the server keeps a count of recent submissions per IP address in memory only, for a rolling window of 60 seconds. This data is never written to disk, never combined with any other record, and is discarded automatically.
3.3 Information you send us by email
If you email us, we process the content of your message, your email address, and any information you choose to include, for as long as needed to deal with the matter and as described in section 6.
3.4 What we do not collect
- No cookies. This site sets no cookies of any kind — not necessary, not functional, not analytical, not advertising. There is no cookie banner because there is nothing to consent to.
- No browser storage. We do not use localStorage, sessionStorage or similar technologies to store information on your device.
- No analytics. We run no analytics or measurement product on this site — no Google Analytics, no Plausible, no Matomo, no server-side product analytics.
- No advertising, tracking pixels, retargeting, or fingerprinting.
- No third-party requests. Fonts and images are served from our own infrastructure. Loading this site does not cause your browser to contact any CDN, font service, tag manager or social network.
- No social media plug-ins. Links to our social profiles are plain hyperlinks and load nothing until you click them.
- No account system. There is nothing to register for, so we hold no credentials.
- No purchase of personal data, and no enrichment of your details from third-party data brokers.
4. Legal bases for processing
We rely on the following legal bases under Article 6(1) GDPR:
| Processing | Legal basis |
|---|---|
| Responding to your enquiry | Article 6(1)(b) — steps taken at your request prior to entering a contract; and where no contract is contemplated, Article 6(1)(f) legitimate interests in responding to business correspondence |
| Email correspondence | Article 6(1)(b) or Article 6(1)(f) as above |
| Server access logs and rate limiting | Article 6(1)(f) — our legitimate interest in keeping the site secure, available and free from abuse |
| Retaining enquiry records after the conversation ends | Article 6(1)(f) — our legitimate interest in maintaining a record of business discussions and in establishing, exercising or defending legal claims |
| Keeping accounting records for engagements | Article 6(1)(c) — compliance with Cyprus tax and accounting law |
Where we rely on legitimate interests, we have considered whether those interests are overridden by your interests or fundamental rights, and concluded that they are not, because the processing is limited, expected in a business context, and involves no profiling or marketing. You may object to legitimate-interest processing at any time — see section 7.
We do not rely on consent for anything on this site, and we do not send marketing email. If we ever introduce marketing communications, they will be opt-in and separately consented to.
5. Who we share personal data with
We do not sell personal data. We do not share it for anyone else's marketing. We do not disclose it to third parties except as set out here.
Processors acting on our instructions:
| Recipient | Purpose | Location |
|---|---|---|
| Resend (Plus Five Five, Inc.) | Transactional email delivery — the enquiry form's contents are transmitted through Resend to reach our mailbox | United States |
| Our hosting provider | Operating the server on which elicon.io runs | Disclosed on request |
| Our email provider | The mailbox in which we receive and store enquiries | Disclosed on request |
Each processor is bound by a contract meeting the requirements of Article 28 GDPR and may process personal data only on our documented instructions. We will identify the specific providers we use, and the countries in which they process personal data, on request — write to us at the email address in section 1.
Other disclosures. We may disclose personal data where we are legally required to do so — for example in response to a lawful order from a court or competent authority — or where necessary to establish, exercise or defend legal claims. We may also disclose it to our professional advisers (lawyers, accountants, auditors) under a duty of confidentiality. If Elicon's business is transferred to another entity, personal data may transfer with it; you would be informed before that took effect.
6. International transfers
Some of our processors are established outside the European Economic Area, notably in the United States. Where personal data is transferred outside the EEA, we rely on the safeguards permitted by Chapter V GDPR — principally the European Commission's Standard Contractual Clauses under Article 46(2)(c), supplemented where appropriate by the EU–US Data Privacy Framework where the recipient is certified under it.
You may request a copy of the safeguards applying to a specific transfer by writing to us at the email address in section 1.
7. How long we keep personal data
We keep personal data only as long as we need it, and then delete it.
| Data | Retention |
|---|---|
| Rate-limiting counters | 60 seconds, in memory only |
| Web server access logs | No longer than 90 days |
| Enquiries that do not lead to an engagement | Up to 24 months from last contact, then deleted |
| Enquiries that lead to an engagement | For the duration of the engagement, then as below |
| Contracts and engagement correspondence | 6 years after the engagement ends, to establish, exercise or defend legal claims |
| Accounting and tax records | 6 years, as required by Cyprus tax legislation |
The enquiry form does not write to any database on this website. Its contents exist as an email in our mailbox, and the retention periods above apply to that email.
Where a retention period has expired, data is deleted or irreversibly anonymised at the next routine review.
8. Your rights
Under the GDPR you have the following rights in relation to personal data we hold about you. They are not absolute, and some apply only in particular circumstances.
- Right of access (Article 15). To be told whether we process your personal data and, if so, to receive a copy of it together with information about how we use it.
- Right to rectification (Article 16). To have inaccurate personal data corrected and incomplete data completed.
- Right to erasure (Article 17). To have personal data deleted where it is no longer necessary, where you withdraw consent that we relied on, where you object and there is no overriding ground, or where it has been processed unlawfully.
- Right to restriction (Article 18). To have processing limited while a dispute about accuracy or our legitimate grounds is resolved.
- Right to data portability (Article 20). Where processing is based on consent or on a contract and carried out by automated means, to receive your data in a structured, commonly used, machine-readable format and to have it transmitted to another controller where technically feasible.
- Right to object (Article 21). To object at any time to processing based on our legitimate interests. We will stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is for legal claims. Where processing is for direct marketing, your objection is absolute and we will stop immediately.
- Right to withdraw consent (Article 7(3)). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right not to be subject to automated decision-making (Article 22). See section 11 — we do not carry out automated decision-making producing legal or similarly significant effects.
How to exercise them
Email [email protected] describing what you want. We may ask for information to confirm your identity, so that we do not disclose personal data to the wrong person. We will respond within one month of receiving your request. Where a request is complex or you have made several, we may extend that period by up to two further months and will tell you why within the first month.
Exercising these rights is free. We may charge a reasonable fee, or refuse to act, only where a request is manifestly unfounded or excessive — and we will explain our reasoning if that ever arises.
9. Complaints
If you believe we have handled your personal data unlawfully, please tell us first — we would rather fix it. You also have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or the place of the alleged infringement.
The supervisory authority for Cyprus is:
Office of the Commissioner for Personal Data Protection 1 Iasonos Street, 1082 Nicosia, Cyprus www.dataprotection.gov.cy
10. Security
We take appropriate technical and organisational measures under Article 32 GDPR, proportionate to the risk. For this website these include:
- Encryption in transit. The site is served over HTTPS with modern TLS; HTTP requests are redirected to HTTPS.
- Data minimisation. The enquiry form collects the minimum needed to reply, and the website stores no personal data in a database of its own.
- Abuse controls. Rate limiting per IP address and a hidden anti-spam field on the enquiry form.
- Input validation. Submissions are validated against a strict schema server-side, and malformed input is rejected rather than processed.
- Access control. Access to the mailbox receiving enquiries and to the server is limited to personnel who need it, and protected by strong authentication.
- Secret management. API credentials are held in server-side environment configuration and are never exposed to the browser.
- Patching. Dependencies and server software are kept up to date.
No system is perfectly secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Commissioner within 72 hours as required by Article 33, and will notify you directly where Article 34 requires it.
11. Automated decision-making and profiling
We do not carry out automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Article 22 GDPR. Enquiries are read and answered by a person.
12. Artificial intelligence, agents, and how we work
Elicon builds AI systems and uses AI tooling in its own delivery work. Because that is unusual enough to be worth stating plainly:
- We do not feed enquiry-form submissions or your correspondence into third-party AI services for training or for any other purpose. Your enquiry is read by a person.
- No personal data collected through this website is used to train any machine learning model, ours or anyone else's.
- In client engagements, any use of AI tooling on client data is governed by the engagement contract and the data processing agreement, which specify what may be processed, by which sub-processors, and under what safeguards. Where we act as a processor, we act only on the client's documented instructions.
- Where we use AI-assisted tooling to write software, that is an internal engineering practice; it does not change who has access to your personal data or where it is processed.
13. Children
This site is directed at businesses and is not intended for children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Links to other sites
This site links to third-party websites, including source-code repositories and social media profiles. We are not responsible for their content or their privacy practices, and this policy does not apply to them. Read their policies before providing personal data.
15. Changes to this policy
We may update this policy to reflect changes in how we operate or in the law. The version number and date at the top of the page will change. Where a change materially affects how we process your personal data, we will take reasonable steps to bring it to your attention. Continued use of the site after a change takes effect indicates that you are aware of the current version.
16. Contact
Questions about this policy or about how we handle personal data:
Email: [email protected]